libWiiSharp/CertificateChain.cs

585 lines
20 KiB
C#
Raw Permalink Normal View History

2021-02-06 18:09:13 -06:00
/* This file is part of libWiiSharp
* Copyright (C) 2009 Leathl
* Copyright (C) 2020 - 2022 TheShadowEevee, Github Contributors
2021-02-06 18:09:13 -06:00
*
* libWiiSharp is free software: you can redistribute it and/or
* modify it under the terms of the GNU General Public License as published
* by the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* libWiiSharp is distributed in the hope that it will be
* useful, but WITHOUT ANY WARRANTY; without even the implied warranty
* of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
using System;
using System.IO;
using System.Security.Cryptography;
namespace libWiiSharp
{
2021-02-06 18:09:13 -06:00
public class CertificateChain : IDisposable
{
//private const string certCaHash = "5B7D3EE28706AD8DA2CBD5A6B75C15D0F9B6F318";
//private const string certCpHash = "6824D6DA4C25184F0D6DAF6EDB9C0FC57522A41C";
//private const string certXsHash = "09787045037121477824BC6A3E5E076156573F8A";
2021-02-06 18:09:13 -06:00
private SHA1 sha = SHA1.Create();
private bool[] certsComplete = new bool[3];
private byte[] certCa = new byte[1024];
private byte[] certCp = new byte[768];
private byte[] certXs = new byte[768];
private bool isDisposed;
/// <summary>
/// If false, the Certificate Chain is not complete (i.e. at least one certificate is missing).
/// </summary>
public bool CertsComplete => certsComplete[0] && certsComplete[1] && certsComplete[2];
#region IDisposable Members
~CertificateChain() => Dispose(false);
2021-02-06 18:09:13 -06:00
public void Dispose()
{
Dispose(true);
GC.SuppressFinalize(this);
2021-02-06 18:09:13 -06:00
}
2021-02-06 18:09:13 -06:00
protected virtual void Dispose(bool disposing)
{
if (disposing && !isDisposed)
2021-02-06 18:09:13 -06:00
{
sha.Clear();
sha = null;
certsComplete = null;
certCa = null;
certCp = null;
certXs = null;
2021-02-06 18:09:13 -06:00
}
isDisposed = true;
2021-02-06 18:09:13 -06:00
}
#endregion
#region Public Functions
/// <summary>
/// Loads a cert file.
/// </summary>
/// <param name="pathToCert"></param>
/// <returns></returns>
public static CertificateChain Load(string pathToCert)
{
return Load(File.ReadAllBytes(pathToCert));
}
/// <summary>
/// Loads a cert file.
/// </summary>
/// <param name="certFile"></param>
/// <returns></returns>
2021-02-06 18:09:13 -06:00
public static CertificateChain Load(byte[] certFile)
{
CertificateChain certificateChain = new CertificateChain();
MemoryStream memoryStream = new MemoryStream(certFile);
try
{
certificateChain.ParseCert(memoryStream);
2021-02-06 18:09:13 -06:00
}
catch
{
memoryStream.Dispose();
throw;
}
memoryStream.Dispose();
return certificateChain;
}
/// <summary>
/// Loads a cert file.
/// </summary>
/// <param name="cert"></param>
/// <returns></returns>
2021-02-06 18:09:13 -06:00
public static CertificateChain Load(Stream cert)
{
CertificateChain certificateChain = new CertificateChain();
certificateChain.ParseCert(cert);
2021-02-06 18:09:13 -06:00
return certificateChain;
}
/// <summary>
/// Grabs certificates from Ticket and Tmd.
/// Ticket and Tmd must contain certs! (They do when they're downloaded from NUS!)
/// </summary>
/// <param name="pathToTik"></param>
/// <param name="pathToTmd"></param>
/// <returns></returns>
public static CertificateChain FromTikTmd(string pathToTik, string pathToTmd)
{
return FromTikTmd(File.ReadAllBytes(pathToTik), File.ReadAllBytes(pathToTmd));
}
/// <summary>
/// Grabs certificates from Ticket and Tmd.
/// Ticket and Tmd must contain certs! (They do when they're downloaded from NUS!)
/// </summary>
/// <param name="tikFile"></param>
/// <param name="tmdFile"></param>
/// <returns></returns>
2021-02-06 18:09:13 -06:00
public static CertificateChain FromTikTmd(byte[] tikFile, byte[] tmdFile)
{
CertificateChain certificateChain = new CertificateChain();
MemoryStream memoryStream1 = new MemoryStream(tikFile);
try
{
certificateChain.GrabFromTik(memoryStream1);
2021-02-06 18:09:13 -06:00
}
catch
{
memoryStream1.Dispose();
throw;
}
MemoryStream memoryStream2 = new MemoryStream(tmdFile);
try
{
certificateChain.GrabFromTmd(memoryStream2);
2021-02-06 18:09:13 -06:00
}
catch
{
memoryStream2.Dispose();
throw;
}
memoryStream2.Dispose();
return certificateChain.CertsComplete ? certificateChain : throw new Exception("Couldn't locate all certs!");
}
/// <summary>
/// Grabs certificates from Ticket and Tmd.
/// Ticket and Tmd must contain certs! (They do when they're downloaded from NUS!)
/// </summary>
/// <param name="tik"></param>
/// <param name="tmd"></param>
/// <returns></returns>
2021-02-06 18:09:13 -06:00
public static CertificateChain FromTikTmd(Stream tik, Stream tmd)
{
CertificateChain certificateChain = new CertificateChain();
certificateChain.GrabFromTik(tik);
certificateChain.GrabFromTmd(tmd);
2021-02-06 18:09:13 -06:00
return certificateChain;
}
/// <summary>
/// Loads a cert file.
/// </summary>
/// <param name="pathToCert"></param>
public void LoadFile(string pathToCert)
{
LoadFile(File.ReadAllBytes(pathToCert));
}
/// <summary>
/// Loads a cert file.
/// </summary>
/// <param name="certFile"></param>
2021-02-06 18:09:13 -06:00
public void LoadFile(byte[] certFile)
{
MemoryStream memoryStream = new MemoryStream(certFile);
try
{
ParseCert(memoryStream);
2021-02-06 18:09:13 -06:00
}
catch
{
memoryStream.Dispose();
throw;
}
memoryStream.Dispose();
}
/// <summary>
/// Loads a cert file.
/// </summary>
/// <param name="cert"></param>
public void LoadFile(Stream cert)
{
ParseCert(cert);
}
/// <summary>
/// Grabs certificates from Ticket and Tmd.
/// Ticket and Tmd must contain certs! (They do when they're downloaded from NUS!)
/// </summary>
/// <param name="pathToTik"></param>
/// <param name="pathToTmd"></param>
/// <returns></returns>
public void LoadFromTikTmd(string pathToTik, string pathToTmd)
{
LoadFromTikTmd(File.ReadAllBytes(pathToTik), File.ReadAllBytes(pathToTmd));
}
/// <summary>
/// Grabs certificates from Ticket and Tmd.
/// Ticket and Tmd must contain certs! (They do when they're downloaded from NUS!)
/// </summary>
/// <param name="tikFile"></param>
/// <param name="tmdFile"></param>
2021-02-06 18:09:13 -06:00
public void LoadFromTikTmd(byte[] tikFile, byte[] tmdFile)
{
MemoryStream memoryStream1 = new MemoryStream(tikFile);
try
{
GrabFromTik(memoryStream1);
2021-02-06 18:09:13 -06:00
}
catch
{
memoryStream1.Dispose();
throw;
}
MemoryStream memoryStream2 = new MemoryStream(tmdFile);
try
{
GrabFromTmd(memoryStream2);
2021-02-06 18:09:13 -06:00
}
catch
{
memoryStream2.Dispose();
throw;
}
memoryStream2.Dispose();
if (!CertsComplete)
{
2021-02-06 18:09:13 -06:00
throw new Exception("Couldn't locate all certs!");
}
2021-02-06 18:09:13 -06:00
}
/// <summary>
/// Grabs certificates from Ticket and Tmd.
/// Ticket and Tmd must contain certs! (They do when they're downloaded from NUS!)
/// </summary>
/// <param name="tik"></param>
/// <param name="tmd"></param>
2021-02-06 18:09:13 -06:00
public void LoadFromTikTmd(Stream tik, Stream tmd)
{
GrabFromTik(tik);
GrabFromTmd(tmd);
2021-02-06 18:09:13 -06:00
}
/// <summary>
/// Saves the Certificate Chain.
/// </summary>
/// <param name="savePath"></param>
2021-02-06 18:09:13 -06:00
public void Save(string savePath)
{
if (File.Exists(savePath))
{
2021-02-06 18:09:13 -06:00
File.Delete(savePath);
}
using FileStream fileStream = new FileStream(savePath, FileMode.Create);
WriteToStream(fileStream);
2021-02-06 18:09:13 -06:00
}
/// <summary>
/// Returns the Certificate Chain as a memory stream.
/// </summary>
/// <returns></returns>
2021-02-06 18:09:13 -06:00
public MemoryStream ToMemoryStream()
{
2021-02-06 18:09:13 -06:00
MemoryStream memoryStream = new MemoryStream();
try
{
WriteToStream(memoryStream);
2021-02-06 18:09:13 -06:00
return memoryStream;
}
catch
{
memoryStream.Dispose();
throw;
}
}
2021-02-06 18:09:13 -06:00
/// <summary>
/// Returns the Certificate Chain as a byte array.
/// </summary>
/// <returns></returns>
2021-02-06 18:09:13 -06:00
public byte[] ToByteArray()
{
2021-02-06 18:09:13 -06:00
MemoryStream memoryStream = new MemoryStream();
try
{
WriteToStream(memoryStream);
2021-02-06 18:09:13 -06:00
}
catch
{
memoryStream.Dispose();
throw;
}
byte[] array = memoryStream.ToArray();
memoryStream.Dispose();
return array;
}
#endregion
#region Private Functions
private void WriteToStream(Stream writeStream)
{
FireDebug("Writing Certificate Chain...");
if (!CertsComplete)
{
FireDebug(" Certificate Chain incomplete...");
2021-02-06 18:09:13 -06:00
throw new Exception("At least one certificate is missing!");
}
2021-02-06 18:09:13 -06:00
writeStream.Seek(0L, SeekOrigin.Begin);
object[] objArray1 = new object[1];
long position = writeStream.Position;
objArray1[0] = position.ToString("x8");
FireDebug(" Writing Certificate CA... (Offset: 0x{0})", objArray1);
writeStream.Write(certCa, 0, certCa.Length);
2021-02-06 18:09:13 -06:00
object[] objArray2 = new object[1];
position = writeStream.Position;
objArray2[0] = position.ToString("x8");
FireDebug(" Writing Certificate CP... (Offset: 0x{0})", objArray2);
writeStream.Write(certCp, 0, certCp.Length);
2021-02-06 18:09:13 -06:00
object[] objArray3 = new object[1];
position = writeStream.Position;
objArray3[0] = position.ToString("x8");
FireDebug(" Writing Certificate XS... (Offset: 0x{0})", objArray3);
writeStream.Write(certXs, 0, certXs.Length);
FireDebug("Writing Certificate Chain Finished...");
}
2021-02-06 18:09:13 -06:00
private void ParseCert(Stream certFile)
{
FireDebug("Parsing Certificate Chain...");
2021-02-06 18:09:13 -06:00
int num = 0;
for (int index = 0; index < 3; ++index)
{
FireDebug(" Scanning at Offset 0x{0}:", (object)num.ToString("x8"));
2021-02-06 18:09:13 -06:00
try
{
certFile.Seek(num, SeekOrigin.Begin);
2021-02-06 18:09:13 -06:00
byte[] array = new byte[1024];
certFile.Read(array, 0, array.Length);
FireDebug(" Checking for Certificate CA...");
if (IsCertCa(array) && !certsComplete[1])
2021-02-06 18:09:13 -06:00
{
FireDebug(" Certificate CA detected...");
certCa = array;
certsComplete[1] = true;
2021-02-06 18:09:13 -06:00
num += 1024;
continue;
}
FireDebug(" Checking for Certificate CP...");
if (IsCertCp(array) && !certsComplete[2])
2021-02-06 18:09:13 -06:00
{
FireDebug(" Certificate CP detected...");
2021-02-06 18:09:13 -06:00
Array.Resize<byte>(ref array, 768);
certCp = array;
certsComplete[2] = true;
2021-02-06 18:09:13 -06:00
num += 768;
continue;
}
FireDebug(" Checking for Certificate XS...");
if (IsCertXs(array))
2021-02-06 18:09:13 -06:00
{
if (!certsComplete[0])
2021-02-06 18:09:13 -06:00
{
FireDebug(" Certificate XS detected...");
2021-02-06 18:09:13 -06:00
Array.Resize<byte>(ref array, 768);
certXs = array;
certsComplete[0] = true;
2021-02-06 18:09:13 -06:00
num += 768;
continue;
}
}
}
catch (Exception ex)
{
FireDebug("Error: {0}", (object)ex.Message);
2021-02-06 18:09:13 -06:00
}
num += 768;
2021-02-06 18:09:13 -06:00
}
if (!CertsComplete)
2021-02-06 18:09:13 -06:00
{
FireDebug(" Couldn't locate all Certificates...");
2021-02-06 18:09:13 -06:00
throw new Exception("Couldn't locate all certs!");
}
FireDebug("Parsing Certificate Chain Finished...");
}
private void GrabFromTik(Stream tik)
{
FireDebug("Scanning Ticket for Certificates...");
2021-02-06 18:09:13 -06:00
int num = 676;
for (int index = 0; index < 3; ++index)
{
FireDebug(" Scanning at Offset 0x{0}:", (object)num.ToString("x8"));
2021-02-06 18:09:13 -06:00
try
{
tik.Seek(num, SeekOrigin.Begin);
2021-02-06 18:09:13 -06:00
byte[] array = new byte[1024];
tik.Read(array, 0, array.Length);
FireDebug(" Checking for Certificate CA...");
if (IsCertCa(array) && !certsComplete[1])
2021-02-06 18:09:13 -06:00
{
FireDebug(" Certificate CA detected...");
certCa = array;
certsComplete[1] = true;
2021-02-06 18:09:13 -06:00
num += 1024;
continue;
}
FireDebug(" Checking for Certificate CP...");
if (IsCertCp(array) && !certsComplete[2])
2021-02-06 18:09:13 -06:00
{
FireDebug(" Certificate CP detected...");
2021-02-06 18:09:13 -06:00
Array.Resize<byte>(ref array, 768);
certCp = array;
certsComplete[2] = true;
2021-02-06 18:09:13 -06:00
num += 768;
continue;
}
FireDebug(" Checking for Certificate XS...");
if (IsCertXs(array))
2021-02-06 18:09:13 -06:00
{
if (!certsComplete[0])
2021-02-06 18:09:13 -06:00
{
FireDebug(" Certificate XS detected...");
2021-02-06 18:09:13 -06:00
Array.Resize<byte>(ref array, 768);
certXs = array;
certsComplete[0] = true;
2021-02-06 18:09:13 -06:00
num += 768;
continue;
}
}
}
catch
{
}
num += 768;
}
FireDebug("Scanning Ticket for Certificates Finished...");
}
2021-02-06 18:09:13 -06:00
private void GrabFromTmd(Stream tmd)
{
FireDebug("Scanning TMD for Certificates...");
2021-02-06 18:09:13 -06:00
byte[] buffer = new byte[2];
tmd.Seek(478L, SeekOrigin.Begin);
tmd.Read(buffer, 0, 2);
int num = 484 + Shared.Swap(BitConverter.ToUInt16(buffer, 0)) * 36;
2021-02-06 18:09:13 -06:00
for (int index = 0; index < 3; ++index)
{
FireDebug(" Scanning at Offset 0x{0}:", (object)num.ToString("x8"));
2021-02-06 18:09:13 -06:00
try
{
tmd.Seek(num, SeekOrigin.Begin);
2021-02-06 18:09:13 -06:00
byte[] array = new byte[1024];
tmd.Read(array, 0, array.Length);
FireDebug(" Checking for Certificate CA...");
if (IsCertCa(array) && !certsComplete[1])
2021-02-06 18:09:13 -06:00
{
FireDebug(" Certificate CA detected...");
certCa = array;
certsComplete[1] = true;
2021-02-06 18:09:13 -06:00
num += 1024;
continue;
}
FireDebug(" Checking for Certificate CP...");
if (IsCertCp(array) && !certsComplete[2])
2021-02-06 18:09:13 -06:00
{
FireDebug(" Certificate CP detected...");
2021-02-06 18:09:13 -06:00
Array.Resize<byte>(ref array, 768);
certCp = array;
certsComplete[2] = true;
2021-02-06 18:09:13 -06:00
num += 768;
continue;
}
FireDebug(" Checking for Certificate XS...");
if (IsCertXs(array))
2021-02-06 18:09:13 -06:00
{
if (!certsComplete[0])
2021-02-06 18:09:13 -06:00
{
FireDebug(" Certificate XS detected...");
2021-02-06 18:09:13 -06:00
Array.Resize<byte>(ref array, 768);
certXs = array;
certsComplete[0] = true;
2021-02-06 18:09:13 -06:00
num += 768;
continue;
}
}
}
catch
{
}
num += 768;
}
FireDebug("Scanning TMD for Certificates Finished...");
}
private bool IsCertXs(byte[] part)
2021-02-06 18:09:13 -06:00
{
if (part.Length < 768)
{
2021-02-06 18:09:13 -06:00
return false;
}
2021-02-06 18:09:13 -06:00
if (part.Length > 768)
{
2021-02-06 18:09:13 -06:00
Array.Resize<byte>(ref part, 768);
}
return part[388] == 88 && part[389] == 83 && Shared.CompareByteArrays(sha.ComputeHash(part), Shared.HexStringToByteArray("09787045037121477824BC6A3E5E076156573F8A"));
2021-02-06 18:09:13 -06:00
}
private bool IsCertCa(byte[] part)
2021-02-06 18:09:13 -06:00
{
if (part.Length < 1024)
{
2021-02-06 18:09:13 -06:00
return false;
}
2021-02-06 18:09:13 -06:00
if (part.Length > 1024)
{
2021-02-06 18:09:13 -06:00
Array.Resize<byte>(ref part, 1024);
}
return part[644] == 67 && part[645] == 65 && Shared.CompareByteArrays(sha.ComputeHash(part), Shared.HexStringToByteArray("5B7D3EE28706AD8DA2CBD5A6B75C15D0F9B6F318"));
2021-02-06 18:09:13 -06:00
}
private bool IsCertCp(byte[] part)
2021-02-06 18:09:13 -06:00
{
if (part.Length < 768)
{
2021-02-06 18:09:13 -06:00
return false;
}
2021-02-06 18:09:13 -06:00
if (part.Length > 768)
{
2021-02-06 18:09:13 -06:00
Array.Resize<byte>(ref part, 768);
}
return part[388] == 67 && part[389] == 80 && Shared.CompareByteArrays(sha.ComputeHash(part), Shared.HexStringToByteArray("6824D6DA4C25184F0D6DAF6EDB9C0FC57522A41C"));
2021-02-06 18:09:13 -06:00
}
#endregion
#region Events
/// <summary>
/// Fires debugging messages. You may write them into a log file or log textbox.
/// </summary>
public event EventHandler<MessageEventArgs> Debug;
private void FireDebug(string debugMessage, params object[] args)
2021-02-06 18:09:13 -06:00
{
EventHandler<MessageEventArgs> debug = Debug;
2021-02-06 18:09:13 -06:00
if (debug == null)
{
2021-02-06 18:09:13 -06:00
return;
}
2021-02-06 18:09:13 -06:00
debug(new object(), new MessageEventArgs(string.Format(debugMessage, args)));
}
#endregion
}
}