2 # Copyright (C) 2012 Wizards Internet Ltd
3 # License GPLv2: GNU GPL version 2 <http://www.gnu.org/licenses/old-licenses/gpl-2.0.html>
5 BEGIN { pop @INC if $INC[-1] eq '.' };
7 $Getopt::Std::STANDARD_HELP_VERSION=1;
10 my ($o,$i,$s,$f,$t,$u,$VERSION);
13 getopts("c:i:u:a:o:m:fv",$o);
14 usage('No issuer specified') if ! $o->{'i'} && ! -f $o->{'i'};
15 usage('No certificate specified') if ! $o->{'c'} && ! -f $o->{'c'};
16 usage('No CA chain specified') if ! $o->{'a'} && ! -f $o->{'a'};
17 usage('No OCSP file specified') if ! $o->{'o'};
18 usage('No URL specified') if ! $o->{'u'};
19 $o->{'t'}=$o->{'o'}.'.tmp';
24 || ( -M $o->{'o'} > 0 )
28 open( $i, "openssl ocsp -issuer $o->{'i'} -cert $o->{'c'} -url $o->{'u'} -CAfile $o->{'a'} -respout $o->{'t'} 2>/dev/null |" ) || die 'Unable to execute ocsp command';
29 $s = <$i> || die 'Unable to read status';
30 $f = <$i> || die 'Unable to read update time';
31 $t = <$i> || die 'Unable to read next update time';
41 die "OCSP status is $s" if $s ne 'good';
42 warn "Next Update $t" if $o->{'v'};
43 # response is good, adjust mod time and move into place.
44 $u = $t - $o->{'m'} * (($t - time)/100);
45 utime $u,$u,$o->{'t'};
46 rename $o->{'t'},$o->{'o'};
54 print STDERR "$m\n" if $m;
55 HELP_MESSAGE(\*STDERR);
63 Usage: $0 -i issuer -c certificate -u ocsp_url -a ca_certs -o response [-v] [-f]
65 For a certificate "www.example.com.pem"
66 signed by "signing.example.net.pem"
67 signed by root CA "ca.example.net.pem"
68 with OCSP server http://ocsp.example.net/
70 Ensure there is a file with the signing chain
72 cat ca.example.net.pem signing.example.net.pem >chain.pem
74 The update procedure would be
76 ocsp_fetch -i signing.example.net.pem \
77 -c www.example.com.pem \
78 -u http://ocsp.example.net/ \
80 -o www.example.com.ocsp.der