# -e /etc/userdir-ldap/templtes/error-reply -- test.sh
import sys, traceback, time, os;
-import string, pwd, getopt;
+import pwd, getopt;
+import email, email.parser
from userdir_gpg import *;
EX_TEMPFAIL = 75;
ErrType = EX_TEMPFAIL;
ErrMsg = "An error occurred while performing the LDAP lookup:";
global l;
- l = ldap.open(LDAPServer);
+ l = connectLDAP(LDAPServer);
l.simple_bind_s("","");
# Search for the matching key fingerprint
if (switch == '-r'):
ReplayCacheFile = val;
elif (switch == '-k'):
- SetKeyrings(string.split(val,":"));
+ SetKeyrings(val.split(":"));
elif (switch == '-d'):
LDAPDn = val;
elif (switch == '-l'):
if ReplayCacheFile != None:
ErrMsg = "Failed to initialize the replay cache:";
RC = ReplayCache(ReplayCacheFile);
- RC.Clean();
-
+
# Get the email
ErrType = EX_PERMFAIL;
ErrMsg = "Failed to understand the email or find a signature:";
- Email = mimetools.Message(sys.stdin,0);
- MsgID = Email.getheader("Message-ID");
+ mail = email.parser.Parser().parse(sys.stdin);
+ MsgID = mail["Message-ID"]
+
print "Inspecting message %s"%MsgID;
verbmsg("Processing message %s" % MsgID)
- Msg = GetClearSig(Email,1);
- # print Msg
+ Msg = GetClearSig(mail,1);
if AllowMIME == 0 and Msg[1] != 0:
raise Error, "PGP/MIME disallowed";
ErrMsg = "Message is not PGP signed:"
- if string.find(Msg[0],"-----BEGIN PGP SIGNED MESSAGE-----") == -1:
+ if Msg[0].find("-----BEGIN PGP SIGNED MESSAGE-----") == -1:
raise Error, "No PGP signature";
# Check the signature
ErrMsg = "Unable to check the signature or the signature was invalid:";
- Res = GPGCheckSig(Msg[0]);
+ pgp = GPGCheckSig2(Msg[0])
- if Res[0] != None:
- raise Error, Res[0];
-
- if Res[3] == None:
- raise Error, "Null signature text";
+ if not pgp.ok:
+ raise UDFormatError, pgp.why
+ if pgp.text is None:
+ raise UDFormatError, "Null signature text"
# Check the signature against the replay cache
if ReplayCacheFile != None:
- ErrMsg = "The replay cache rejected your message. Check your clock!";
- Rply = RC.Check(Res[1]);
- if Rply != None:
- raise Error, Rply;
- RC.Add(Res[1]);
- RC.close();
+ RC.process(pgp.sig_info)
# Do LDAP stuff
if LDAPDn != None:
- CheckLDAP(Res[2][1]);
-
+ CheckLDAP(pgp.key_fpr)
+
ErrMsg = "Verifying message:";
if Phrases != None:
F = open(Phrases,"r");
while 1:
Line = F.readline();
if Line == "": break;
- if string.find(Res[3],string.strip(Line)) == -1:
- raise Error,"Phrase '%s' was not found"%(string.strip(Line));
+ if pgp.text.find(Line.strip()) == -1:
+ raise Error,"Phrase '%s' was not found" % (Line.strip())
except:
ErrMsg = "[%s] \"%s\" \"%s %s\"\n"%(Now,MsgID,ErrMsg,sys.exc_value);