Latest update.
This commit is contained in:
+135
-52
@@ -441,62 +441,14 @@ static int load_pkcs12(BIO *in, const char *desc,
|
||||
return ret;
|
||||
}
|
||||
|
||||
#if !defined(OPENSSL_NO_OCSP) && !defined(OPENSSL_NO_SOCK)
|
||||
static int load_cert_crl_http(const char *url, X509 **pcert, X509_CRL **pcrl)
|
||||
{
|
||||
char *host = NULL, *port = NULL, *path = NULL;
|
||||
BIO *bio = NULL;
|
||||
OCSP_REQ_CTX *rctx = NULL;
|
||||
int use_ssl, rv = 0;
|
||||
if (!OCSP_parse_url(url, &host, &port, &path, &use_ssl))
|
||||
goto err;
|
||||
if (use_ssl) {
|
||||
BIO_puts(bio_err, "https not supported\n");
|
||||
goto err;
|
||||
}
|
||||
bio = BIO_new_connect(host);
|
||||
if (!bio || !BIO_set_conn_port(bio, port))
|
||||
goto err;
|
||||
rctx = OCSP_REQ_CTX_new(bio, 1024);
|
||||
if (rctx == NULL)
|
||||
goto err;
|
||||
if (!OCSP_REQ_CTX_http(rctx, "GET", path))
|
||||
goto err;
|
||||
if (!OCSP_REQ_CTX_add1_header(rctx, "Host", host))
|
||||
goto err;
|
||||
if (pcert) {
|
||||
do {
|
||||
rv = X509_http_nbio(rctx, pcert);
|
||||
} while (rv == -1);
|
||||
} else {
|
||||
do {
|
||||
rv = X509_CRL_http_nbio(rctx, pcrl);
|
||||
} while (rv == -1);
|
||||
}
|
||||
|
||||
err:
|
||||
OPENSSL_free(host);
|
||||
OPENSSL_free(path);
|
||||
OPENSSL_free(port);
|
||||
BIO_free_all(bio);
|
||||
OCSP_REQ_CTX_free(rctx);
|
||||
if (rv != 1) {
|
||||
BIO_printf(bio_err, "Error loading %s from %s\n",
|
||||
pcert ? "certificate" : "CRL", url);
|
||||
ERR_print_errors(bio_err);
|
||||
}
|
||||
return rv;
|
||||
}
|
||||
#endif
|
||||
|
||||
X509 *load_cert(const char *file, int format, const char *cert_descrip)
|
||||
{
|
||||
X509 *x = NULL;
|
||||
BIO *cert;
|
||||
|
||||
if (format == FORMAT_HTTP) {
|
||||
#if !defined(OPENSSL_NO_OCSP) && !defined(OPENSSL_NO_SOCK)
|
||||
load_cert_crl_http(file, &x, NULL);
|
||||
#if !defined(OPENSSL_NO_SOCK)
|
||||
x = X509_load_http(file, NULL, NULL, 0 /* timeout */);
|
||||
#endif
|
||||
return x;
|
||||
}
|
||||
@@ -537,8 +489,8 @@ X509_CRL *load_crl(const char *infile, int format)
|
||||
BIO *in = NULL;
|
||||
|
||||
if (format == FORMAT_HTTP) {
|
||||
#if !defined(OPENSSL_NO_OCSP) && !defined(OPENSSL_NO_SOCK)
|
||||
load_cert_crl_http(infile, NULL, &x);
|
||||
#if !defined(OPENSSL_NO_SOCK)
|
||||
x = X509_CRL_load_http(infile, NULL, NULL, 0 /* timeout */);
|
||||
#endif
|
||||
return x;
|
||||
}
|
||||
@@ -1981,6 +1933,137 @@ void store_setup_crl_download(X509_STORE *st)
|
||||
X509_STORE_set_lookup_crls_cb(st, crls_http_cb);
|
||||
}
|
||||
|
||||
#ifndef OPENSSL_NO_SOCK
|
||||
static const char *tls_error_hint(void)
|
||||
{
|
||||
unsigned long err = ERR_peek_error();
|
||||
|
||||
if (ERR_GET_LIB(err) != ERR_LIB_SSL)
|
||||
err = ERR_peek_last_error();
|
||||
if (ERR_GET_LIB(err) != ERR_LIB_SSL)
|
||||
return NULL;
|
||||
|
||||
switch (ERR_GET_REASON(err)) {
|
||||
case SSL_R_WRONG_VERSION_NUMBER:
|
||||
return "The server does not support (a suitable version of) TLS";
|
||||
case SSL_R_UNKNOWN_PROTOCOL:
|
||||
return "The server does not support HTTPS";
|
||||
case SSL_R_CERTIFICATE_VERIFY_FAILED:
|
||||
return "Cannot authenticate server via its TLS certificate, likely due to mismatch with our trusted TLS certs or missing revocation status";
|
||||
case SSL_AD_REASON_OFFSET + TLS1_AD_UNKNOWN_CA:
|
||||
return "Server did not accept our TLS certificate, likely due to mismatch with server's trust anchor or missing revocation status";
|
||||
case SSL_AD_REASON_OFFSET + SSL3_AD_HANDSHAKE_FAILURE:
|
||||
return "TLS handshake failure. Possibly the server requires our TLS certificate but did not receive it";
|
||||
default: /* no error or no hint available for error */
|
||||
return NULL;
|
||||
}
|
||||
}
|
||||
|
||||
/* HTTP callback function that supports TLS connection also via HTTPS proxy */
|
||||
BIO *app_http_tls_cb(BIO *hbio, void *arg, int connect, int detail)
|
||||
{
|
||||
APP_HTTP_TLS_INFO *info = (APP_HTTP_TLS_INFO *)arg;
|
||||
SSL_CTX *ssl_ctx = info->ssl_ctx;
|
||||
SSL *ssl;
|
||||
BIO *sbio = NULL;
|
||||
|
||||
if (connect && detail) { /* connecting with TLS */
|
||||
if ((info->use_proxy
|
||||
&& !OSSL_HTTP_proxy_connect(hbio, info->server, info->port,
|
||||
NULL, NULL, /* no proxy credentials */
|
||||
info->timeout, bio_err, opt_getprog()))
|
||||
|| (sbio = BIO_new(BIO_f_ssl())) == NULL) {
|
||||
return NULL;
|
||||
}
|
||||
if (ssl_ctx == NULL || (ssl = SSL_new(ssl_ctx)) == NULL) {
|
||||
BIO_free(sbio);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
SSL_set_tlsext_host_name(ssl, info->server);
|
||||
|
||||
SSL_set_connect_state(ssl);
|
||||
BIO_set_ssl(sbio, ssl, BIO_CLOSE);
|
||||
|
||||
hbio = BIO_push(sbio, hbio);
|
||||
} else if (!connect && !detail) { /* disconnecting after error */
|
||||
const char *hint = tls_error_hint();
|
||||
if (hint != NULL)
|
||||
ERR_add_error_data(1, hint);
|
||||
/*
|
||||
* If we pop sbio and BIO_free() it this may lead to libssl double free.
|
||||
* Rely on BIO_free_all() done by OSSL_HTTP_transfer() in http_client.c
|
||||
*/
|
||||
}
|
||||
return hbio;
|
||||
}
|
||||
|
||||
ASN1_VALUE *app_http_get_asn1(const char *url, const char *proxy,
|
||||
const char *proxy_port, SSL_CTX *ssl_ctx,
|
||||
const STACK_OF(CONF_VALUE) *headers,
|
||||
long timeout, const char *expected_content_type,
|
||||
const ASN1_ITEM *it)
|
||||
{
|
||||
APP_HTTP_TLS_INFO info;
|
||||
char *server;
|
||||
char *port;
|
||||
int use_ssl;
|
||||
ASN1_VALUE *resp = NULL;
|
||||
|
||||
if (url == NULL || it == NULL) {
|
||||
HTTPerr(0, ERR_R_PASSED_NULL_PARAMETER);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
if (!OSSL_HTTP_parse_url(url, &server, &port, NULL /* ppath */, &use_ssl))
|
||||
return NULL;
|
||||
if (use_ssl && ssl_ctx == NULL) {
|
||||
HTTPerr(0, ERR_R_PASSED_NULL_PARAMETER);
|
||||
ERR_add_error_data(1, "missing SSL_CTX");
|
||||
goto end;
|
||||
}
|
||||
|
||||
info.server = server;
|
||||
info.port = port;
|
||||
info.use_proxy = proxy != NULL;
|
||||
info.timeout = timeout;
|
||||
info.ssl_ctx = ssl_ctx;
|
||||
resp = OSSL_HTTP_get_asn1(url, proxy, proxy_port,
|
||||
NULL, NULL, app_http_tls_cb, &info,
|
||||
headers, 0 /* maxline */, 0 /* max_resp_len */,
|
||||
timeout, expected_content_type, it);
|
||||
end:
|
||||
OPENSSL_free(server);
|
||||
OPENSSL_free(port);
|
||||
return resp;
|
||||
|
||||
}
|
||||
|
||||
ASN1_VALUE *app_http_post_asn1(const char *host, const char *port,
|
||||
const char *path, const char *proxy,
|
||||
const char *proxy_port, SSL_CTX *ssl_ctx,
|
||||
const STACK_OF(CONF_VALUE) *headers,
|
||||
const char *content_type,
|
||||
ASN1_VALUE *req, const ASN1_ITEM *req_it,
|
||||
long timeout, const ASN1_ITEM *rsp_it)
|
||||
{
|
||||
APP_HTTP_TLS_INFO info;
|
||||
|
||||
info.server = host;
|
||||
info.port = port;
|
||||
info.use_proxy = proxy != NULL;
|
||||
info.timeout = timeout;
|
||||
info.ssl_ctx = ssl_ctx;
|
||||
return OSSL_HTTP_post_asn1(host, port, path, ssl_ctx != NULL,
|
||||
proxy, proxy_port,
|
||||
NULL, NULL, app_http_tls_cb, &info,
|
||||
headers, content_type, req, req_it,
|
||||
0 /* maxline */,
|
||||
0 /* max_resp_len */, timeout, NULL, rsp_it);
|
||||
}
|
||||
|
||||
#endif
|
||||
|
||||
/*
|
||||
* Platform-specific sections
|
||||
*/
|
||||
|
||||
+40
-5
@@ -12,6 +12,8 @@
|
||||
#include <stdlib.h>
|
||||
#include <string.h> /* for memcpy() and strcmp() */
|
||||
#include "apps.h"
|
||||
#include <openssl/core_names.h>
|
||||
#include <openssl/params.h>
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/rand.h>
|
||||
#include <openssl/x509.h>
|
||||
@@ -729,10 +731,14 @@ void tlsext_cb(SSL *s, int client_server, int type,
|
||||
int generate_cookie_callback(SSL *ssl, unsigned char *cookie,
|
||||
unsigned int *cookie_len)
|
||||
{
|
||||
unsigned char *buffer;
|
||||
unsigned char *buffer = NULL;
|
||||
size_t length = 0;
|
||||
unsigned short port;
|
||||
BIO_ADDR *lpeer = NULL, *peer = NULL;
|
||||
int res = 0;
|
||||
EVP_MAC *hmac = NULL;
|
||||
EVP_MAC_CTX *ctx = NULL;
|
||||
OSSL_PARAM params[3], *p = params;
|
||||
|
||||
/* Initialize a random secret */
|
||||
if (!cookie_initialized) {
|
||||
@@ -770,13 +776,42 @@ int generate_cookie_callback(SSL *ssl, unsigned char *cookie,
|
||||
BIO_ADDR_rawaddress(peer, buffer + sizeof(port), NULL);
|
||||
|
||||
/* Calculate HMAC of buffer using the secret */
|
||||
HMAC(EVP_sha1(), cookie_secret, COOKIE_SECRET_LENGTH,
|
||||
buffer, length, cookie, cookie_len);
|
||||
|
||||
hmac = EVP_MAC_fetch(NULL, "HMAC", NULL);
|
||||
if (hmac == NULL) {
|
||||
BIO_printf(bio_err, "HMAC not found\n");
|
||||
goto end;
|
||||
}
|
||||
ctx = EVP_MAC_CTX_new(hmac);
|
||||
if (ctx == NULL) {
|
||||
BIO_printf(bio_err, "HMAC context allocation failed\n");
|
||||
goto end;
|
||||
}
|
||||
*p++ = OSSL_PARAM_construct_utf8_string(OSSL_MAC_PARAM_DIGEST, "SHA1", 0);
|
||||
*p++ = OSSL_PARAM_construct_octet_string(OSSL_MAC_PARAM_KEY, cookie_secret,
|
||||
COOKIE_SECRET_LENGTH);
|
||||
*p = OSSL_PARAM_construct_end();
|
||||
if (!EVP_MAC_CTX_set_params(ctx, params)) {
|
||||
BIO_printf(bio_err, "HMAC context parameter setting failed\n");
|
||||
goto end;
|
||||
}
|
||||
if (!EVP_MAC_init(ctx)) {
|
||||
BIO_printf(bio_err, "HMAC context initialisation failed\n");
|
||||
goto end;
|
||||
}
|
||||
if (!EVP_MAC_update(ctx, buffer, length)) {
|
||||
BIO_printf(bio_err, "HMAC context update failed\n");
|
||||
goto end;
|
||||
}
|
||||
if (!EVP_MAC_final(ctx, cookie, NULL, (size_t)cookie_len)) {
|
||||
BIO_printf(bio_err, "HMAC context final failed\n");
|
||||
goto end;
|
||||
}
|
||||
res = 1;
|
||||
end:
|
||||
OPENSSL_free(buffer);
|
||||
BIO_ADDR_free(lpeer);
|
||||
|
||||
return 1;
|
||||
return res;
|
||||
}
|
||||
|
||||
int verify_cookie_callback(SSL *ssl, const unsigned char *cookie,
|
||||
|
||||
Reference in New Issue
Block a user