Christian Grothoff | 90e9f83 | 2012-02-07 11:16:47 +0100 | [diff] [blame] | 1 | /* Copyright (c) 2012, Jacob Appelbaum. |
Jacob Appelbaum | 63e548e | 2012-07-29 16:25:30 -0700 | [diff] [blame] | 2 | * Copyright (c) 2012, The Tor Project, Inc. |
| 3 | * Copyright (c) 2012, Christian Grothoff. */ |
Christian Grothoff | 90e9f83 | 2012-02-07 11:16:47 +0100 | [diff] [blame] | 4 | /* See LICENSE for licensing information */ |
| 5 | /* |
| 6 | This file contains the license for tlsdate, |
| 7 | a free software project to set your system clock securely. |
| 8 | |
| 9 | It also lists the licenses for other components used by tlsdate. |
| 10 | |
| 11 | For more information about tlsdate, see https://github.com/ioerror/tlsdate |
| 12 | |
| 13 | If you got this file as a part of a larger bundle, |
| 14 | there may be other license terms that you should be aware of. |
| 15 | |
| 16 | =============================================================================== |
| 17 | tlsdate is distributed under this license: |
| 18 | |
| 19 | Copyright (c) 2011-2012, Jacob Appelbaum <jacob@appelbaum.net> |
| 20 | Copyright (c) 2011-2012, The Tor Project, Inc. |
| 21 | |
| 22 | Redistribution and use in source and binary forms, with or without |
| 23 | modification, are permitted provided that the following conditions are |
| 24 | met: |
| 25 | |
| 26 | * Redistributions of source code must retain the above copyright |
| 27 | notice, this list of conditions and the following disclaimer. |
| 28 | |
| 29 | * Redistributions in binary form must reproduce the above |
| 30 | copyright notice, this list of conditions and the following disclaimer |
| 31 | in the documentation and/or other materials provided with the |
| 32 | distribution. |
| 33 | |
| 34 | * Neither the names of the copyright owners nor the names of its |
| 35 | contributors may be used to endorse or promote products derived from |
| 36 | this software without specific prior written permission. |
| 37 | |
| 38 | THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
| 39 | "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
| 40 | LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR |
| 41 | A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT |
| 42 | OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
| 43 | SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT |
| 44 | LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
| 45 | DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
| 46 | THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
| 47 | (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
| 48 | OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
| 49 | =============================================================================== |
| 50 | If you got tlsdate as a static binary with OpenSSL included, then you should |
| 51 | know: |
| 52 | |
| 53 | "This product includes software developed by the OpenSSL Project for use in |
| 54 | the OpenSSL Toolkit (http://www.openssl.org/)" |
| 55 | |
| 56 | =============================================================================== |
| 57 | */ |
| 58 | |
| 59 | /** |
Christian Grothoff | e267c35 | 2012-02-14 01:10:54 +0100 | [diff] [blame] | 60 | * \file tlsdate-helper.c |
| 61 | * \brief Helper program that does the actual work of setting the system clock. |
Christian Grothoff | 90e9f83 | 2012-02-07 11:16:47 +0100 | [diff] [blame] | 62 | **/ |
| 63 | |
| 64 | /* |
| 65 | * tlsdate is a tool for setting the system clock by hand or by communication |
| 66 | * with the network. It does not set the RTC. It is designed to be as secure as |
| 67 | * TLS (RFC 2246) but of course the security of TLS is often reduced to |
| 68 | * whichever CA racket you believe is trustworthy. By default, tlsdate trusts |
| 69 | * your local CA root store - so any of these companies could assist in a MITM |
| 70 | * attack against you and you'd be screwed. |
| 71 | |
| 72 | * This tool is designed to be run by hand or as a system daemon. It must be |
| 73 | * run as root or otherwise have the proper caps; it will not be able to set |
| 74 | * the system time without running as root or another privileged user. |
| 75 | */ |
| 76 | |
Brian Aker | b12abad | 2012-10-16 01:25:00 -0400 | [diff] [blame] | 77 | #include "config.h" |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 78 | |
Daniel Kurtz | a2d82d5 | 2019-06-07 15:26:54 -0600 | [diff] [blame] | 79 | #include "src/openssl_compat.h" |
Brian Aker | b12abad | 2012-10-16 01:25:00 -0400 | [diff] [blame] | 80 | #include "src/tlsdate-helper.h" |
Christian Grothoff | 90e9f83 | 2012-02-07 11:16:47 +0100 | [diff] [blame] | 81 | |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 82 | #include <errno.h> |
| 83 | #include <netdb.h> |
| 84 | #include <stdlib.h> |
| 85 | #include <sys/types.h> |
| 86 | #include <sys/socket.h> |
| 87 | |
Jacob Appelbaum | fa76530 | 2013-01-18 15:47:47 +0100 | [diff] [blame] | 88 | #include "src/proxy-bio.h" |
Ben Chan | cc6af4b | 2019-04-11 14:13:08 -0700 | [diff] [blame] | 89 | #include "src/util.h" |
Brian Aker | b12abad | 2012-10-16 01:25:00 -0400 | [diff] [blame] | 90 | #include "src/compat/clock.h" |
Elly Jones | 9ae3aa6 | 2012-06-20 15:32:46 -0400 | [diff] [blame] | 91 | |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 92 | static int g_ca_racket; |
| 93 | |
| 94 | static const char *g_ca_cert_container; |
| 95 | |
| 96 | // Target host to connect to. |
| 97 | static const char *g_host; |
| 98 | |
| 99 | // Port to connect to on the target host. |
| 100 | static const char *g_port; |
| 101 | |
| 102 | // The SSL/TLS protocol used |
| 103 | static const char *g_protocol; |
| 104 | |
| 105 | // Proxy with format scheme://proxy_host:proxy_port. |
| 106 | static char *g_proxy; |
| 107 | |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 108 | static void |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 109 | validate_proxy_scheme (const char *scheme) |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 110 | { |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 111 | if (!strcmp (scheme, "http")) |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 112 | return; |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 113 | if (!strcmp (scheme, "socks4")) |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 114 | return; |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 115 | if (!strcmp (scheme, "socks5")) |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 116 | return; |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 117 | die ("invalid proxy scheme\n"); |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 118 | } |
| 119 | |
| 120 | static void |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 121 | validate_proxy_host (const char *host) |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 122 | { |
| 123 | const char *kValid = "ABCDEFGHIJKLMNOPQRSTUVWXYZ" |
| 124 | "abcdefghijklmnopqrstuvwxyz" |
| 125 | "0123456789" |
| 126 | ".-"; |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 127 | if (strspn (host, kValid) != strlen (host)) |
| 128 | die ("invalid char in host\n"); |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 129 | } |
| 130 | |
| 131 | static void |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 132 | validate_port (const char *port) |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 133 | { |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 134 | if (!port) |
| 135 | return; |
| 136 | char *end; |
| 137 | const int kBase = 10; |
| 138 | unsigned long value = strtoul(port, &end, kBase); |
| 139 | if (errno != 0 || value > SHRT_MAX || value == 0 || *end != '\0') |
| 140 | die("invalid port %s\n", port); |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 141 | } |
| 142 | |
| 143 | static void |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 144 | parse_proxy_uri (char *proxy, char **scheme, char **host, char **port) |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 145 | { |
| 146 | /* Expecting a URI, so: <scheme> '://' <host> ':' <port> */ |
| 147 | *scheme = proxy; |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 148 | proxy = strstr (proxy, "://"); |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 149 | if (!proxy) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 150 | die ("malformed proxy URI\n"); |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 151 | *proxy = '\0'; /* terminate scheme string */ |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 152 | proxy += strlen ("://"); |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 153 | *host = proxy; |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 154 | proxy = strchr (proxy, ':'); |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 155 | if (!proxy) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 156 | die ("malformed proxy URI\n"); |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 157 | *proxy++ = '\0'; |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 158 | *port = proxy; |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 159 | validate_proxy_scheme (*scheme); |
| 160 | validate_proxy_host (*host); |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 161 | validate_port (*port); |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 162 | } |
| 163 | |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 164 | /* Returns a BIO that talks through a HTTP proxy using the CONNECT command. |
| 165 | * The created BIO will ask the proxy to CONNECT to |target_host|:|target_port| |
| 166 | * using |scheme|. |
| 167 | */ |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 168 | static BIO * |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 169 | BIO_create_proxy (const char *scheme, const char *target_host, |
| 170 | const char *target_port) |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 171 | { |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 172 | BIO *bio_proxy = BIO_new_proxy (); |
| 173 | BIO_proxy_set_type (bio_proxy, scheme); |
| 174 | BIO_proxy_set_target_host (bio_proxy, target_host); |
| 175 | BIO_proxy_set_target_port (bio_proxy, atoi (target_port)); |
| 176 | return bio_proxy; |
| 177 | } |
| 178 | |
Pavol Marko | d9dd19d | 2020-01-17 23:32:57 +0100 | [diff] [blame^] | 179 | static void |
| 180 | addr_to_str (const struct sockaddr *addr, char* dest, |
| 181 | socklen_t size) |
| 182 | { |
| 183 | struct sockaddr_in* addr_ipv4 = NULL; |
| 184 | struct sockaddr_in6* addr_ipv6 = NULL; |
| 185 | memset (dest, '\0', size); |
| 186 | if (addr->sa_family == AF_INET) { |
| 187 | addr_ipv4 = (struct sockaddr_in*)addr; |
| 188 | inet_ntop (AF_INET, &addr_ipv4->sin_addr, dest, size); |
| 189 | return; |
| 190 | } |
| 191 | if (addr->sa_family == AF_INET6) { |
| 192 | addr_ipv6 = (struct sockaddr_in6*)addr; |
| 193 | inet_ntop (AF_INET6, &addr_ipv6->sin6_addr, dest, size); |
| 194 | return; |
| 195 | } |
| 196 | verb ("V: unknown sa_family %hu\n", addr->sa_family); |
| 197 | } |
| 198 | |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 199 | /* Connects to |host| on port |port|. |
| 200 | * Returns the socket file descriptor if successful, otherwise exits with |
| 201 | * failure. |
| 202 | */ |
| 203 | static int create_connection (const char *host, const char *port) |
| 204 | { |
| 205 | int err, sock = -1; |
| 206 | struct addrinfo *ai = NULL, *cai = NULL; |
| 207 | struct addrinfo hints = { |
| 208 | .ai_flags = AI_ADDRCONFIG, |
| 209 | .ai_family = AF_UNSPEC, |
| 210 | .ai_socktype = SOCK_STREAM, |
| 211 | }; |
Pavol Marko | d9dd19d | 2020-01-17 23:32:57 +0100 | [diff] [blame^] | 212 | // Use INET6_ADDRSTRLEN for the buffer holding IP addresses as it will always |
| 213 | // be longer than INET_ADDRSTRLEN. |
| 214 | char addr_str_buf[INET6_ADDRSTRLEN]; |
| 215 | memset (addr_str_buf, '\0', INET6_ADDRSTRLEN); |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 216 | |
| 217 | err = getaddrinfo (host, port, &hints, &ai); |
| 218 | |
| 219 | if (err != 0 || !ai) |
| 220 | die ("getaddrinfo (%s): %s\n", host, gai_strerror (err)); |
| 221 | |
| 222 | for (cai = ai; cai; cai = cai->ai_next) |
| 223 | { |
Pavol Marko | d9dd19d | 2020-01-17 23:32:57 +0100 | [diff] [blame^] | 224 | addr_to_str (cai->ai_addr, addr_str_buf, INET6_ADDRSTRLEN); |
| 225 | verb ("V: attempting to connect to %s\n", addr_str_buf); |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 226 | sock = socket (cai->ai_family, SOCK_STREAM, 0); |
| 227 | if (sock < 0) |
| 228 | { |
| 229 | perror ("socket"); |
| 230 | continue; |
| 231 | } |
| 232 | |
| 233 | if (connect (sock, cai->ai_addr, cai->ai_addrlen) != 0) |
| 234 | { |
| 235 | perror ("connect"); |
| 236 | close (sock); |
| 237 | sock = -1; |
| 238 | continue; |
| 239 | } |
| 240 | break; |
| 241 | } |
| 242 | freeaddrinfo (ai); |
| 243 | |
| 244 | if (sock < 0) |
| 245 | die ("failed to find any remote addresses for %s:%s\n", host, port); |
| 246 | |
| 247 | return sock; |
| 248 | } |
| 249 | |
| 250 | /* Creates a BIO wrapper over the socket connection to |host|:|port|. |
| 251 | * This workaround is needed because BIO_s_connect() doesn't support IPv6. |
| 252 | */ |
| 253 | static BIO *BIO_create_socket (const char *host, const char *port) |
| 254 | { |
| 255 | BIO *bio_socket = NULL; |
| 256 | int sockfd = create_connection (host, port); |
| 257 | if ( !(bio_socket = BIO_new_fd (sockfd, 1 /* close_flag */))) |
| 258 | die ("BIO_new_fd failed\n"); |
| 259 | |
| 260 | return bio_socket; |
| 261 | } |
| 262 | |
| 263 | /* Creates an OpenSSL BIO-chain which talks to |target_host|:|target_port| |
| 264 | * using the SSL protocol. If |proxy| is set it will be used as a HTTP proxy. |
| 265 | */ |
| 266 | static BIO * |
| 267 | make_ssl_bio (SSL_CTX *ctx, const char *target_host, const char *target_port, |
| 268 | char *proxy) |
| 269 | { |
| 270 | BIO *bio_socket = NULL; |
| 271 | BIO *bio_ssl = NULL; |
| 272 | BIO *bio_proxy = NULL; |
| 273 | char *scheme = NULL; |
| 274 | char *proxy_host = NULL; |
| 275 | char *proxy_port = NULL; |
| 276 | |
| 277 | if ( !(bio_ssl = BIO_new_ssl (ctx, 1))) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 278 | die ("BIO_new_ssl failed\n"); |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 279 | |
| 280 | if (proxy) |
| 281 | { |
| 282 | verb ("V: using proxy %s\n", proxy); |
| 283 | parse_proxy_uri (proxy, &scheme, &proxy_host, &proxy_port); |
| 284 | |
| 285 | if ( !(bio_proxy = BIO_create_proxy (scheme, target_host, target_port))) |
| 286 | die ("BIO_create_proxy failed\n"); |
| 287 | |
| 288 | bio_socket = BIO_create_socket (proxy_host, proxy_port); |
| 289 | |
| 290 | BIO_push (bio_ssl, bio_proxy); |
| 291 | BIO_push (bio_ssl, bio_socket); |
| 292 | } |
| 293 | else |
| 294 | { |
| 295 | bio_socket = BIO_create_socket (target_host, target_port); |
| 296 | BIO_push (bio_ssl, bio_socket); |
| 297 | } |
| 298 | return bio_ssl; |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 299 | } |
Christian Grothoff | 90e9f83 | 2012-02-07 11:16:47 +0100 | [diff] [blame] | 300 | |
Daniel Borkmann | 23c2b80 | 2012-07-30 14:06:12 +0200 | [diff] [blame] | 301 | /** helper function for 'malloc' */ |
| 302 | static void * |
| 303 | xmalloc (size_t size) |
| 304 | { |
| 305 | void *ptr; |
Daniel Borkmann | 23c2b80 | 2012-07-30 14:06:12 +0200 | [diff] [blame] | 306 | if (0 == size) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 307 | die ("xmalloc: zero size\n"); |
| 308 | ptr = malloc (size); |
Daniel Borkmann | 23c2b80 | 2012-07-30 14:06:12 +0200 | [diff] [blame] | 309 | if (NULL == ptr) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 310 | die ("xmalloc: out of memory (allocating %zu bytes)\n", size); |
Daniel Borkmann | 23c2b80 | 2012-07-30 14:06:12 +0200 | [diff] [blame] | 311 | return ptr; |
| 312 | } |
| 313 | |
| 314 | |
| 315 | /** helper function for 'free' */ |
| 316 | static void |
| 317 | xfree (void *ptr) |
| 318 | { |
Daniel Borkmann | 592acc5 | 2012-07-30 14:08:02 +0200 | [diff] [blame] | 319 | if (NULL == ptr) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 320 | die ("xfree: NULL pointer given as argument\n"); |
| 321 | free (ptr); |
Daniel Borkmann | 23c2b80 | 2012-07-30 14:06:12 +0200 | [diff] [blame] | 322 | } |
| 323 | |
| 324 | |
Jacob Appelbaum | 123bb3e | 2012-07-16 17:25:34 -0700 | [diff] [blame] | 325 | void |
Jacob Appelbaum | 42ccf9d | 2012-07-29 16:30:15 -0700 | [diff] [blame] | 326 | openssl_time_callback (const SSL* ssl, int where, int ret) |
Jacob Appelbaum | 9f80729 | 2012-07-16 18:24:37 -0700 | [diff] [blame] | 327 | { |
A soldier | 31056a6 | 2012-08-16 01:10:57 -0700 | [diff] [blame] | 328 | if (where == SSL_CB_CONNECT_LOOP && |
Daniel Kurtz | a2d82d5 | 2019-06-07 15:26:54 -0600 | [diff] [blame] | 329 | #if OPENSSL_VERSION_NUMBER < 0x10100000L |
Elly Fong-Jones | 9b811a4 | 2012-12-13 16:17:21 -0500 | [diff] [blame] | 330 | (ssl->state == SSL3_ST_CR_SRVR_HELLO_A || ssl->state == SSL3_ST_CR_SRVR_HELLO_B)) |
Daniel Kurtz | a2d82d5 | 2019-06-07 15:26:54 -0600 | [diff] [blame] | 331 | #else |
| 332 | (SSL_get_state(ssl) == TLS_ST_CR_SRVR_HELLO)) |
| 333 | #endif |
Jacob Appelbaum | 9f80729 | 2012-07-16 18:24:37 -0700 | [diff] [blame] | 334 | { |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 335 | // XXX TODO: If we want to trust the remote system for time, |
| 336 | // can we just read that time out of the remote system and if the |
| 337 | // cert verifies, decide that the time is reasonable? |
| 338 | // Such a process seems to indicate that a once valid cert would be |
| 339 | // forever valid - we stopgap that by ensuring it isn't less than |
| 340 | // the latest compiled_time and isn't above max_reasonable_time... |
| 341 | // XXX TODO: Solve eternal question about the Chicken and the Egg... |
| 342 | uint32_t compiled_time = RECENT_COMPILE_DATE; |
| 343 | uint32_t max_reasonable_time = MAX_REASONABLE_TIME; |
| 344 | uint32_t server_time; |
| 345 | verb ("V: freezing time for x509 verification\n"); |
Daniel Kurtz | a2d82d5 | 2019-06-07 15:26:54 -0600 | [diff] [blame] | 346 | SSL_get_server_random(ssl, (unsigned char *)&server_time, |
| 347 | sizeof (uint32_t)); |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 348 | if (compiled_time < ntohl (server_time) |
| 349 | && |
| 350 | ntohl (server_time) < max_reasonable_time) |
| 351 | { |
| 352 | verb ("V: remote peer provided: %d, preferred over compile time: %d\n", |
| 353 | ntohl (server_time), compiled_time); |
| 354 | verb ("V: freezing time with X509_VERIFY_PARAM_set_time\n"); |
Daniel Kurtz | a2d82d5 | 2019-06-07 15:26:54 -0600 | [diff] [blame] | 355 | X509_VERIFY_PARAM_set_time (SSL_get0_param((SSL *)ssl), |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 356 | (time_t) ntohl (server_time) + 86400); |
| 357 | } |
| 358 | else |
| 359 | { |
| 360 | die ("V: the remote server is a false ticker! server: %d compile: %d\n", |
| 361 | ntohl (server_time), compiled_time); |
| 362 | } |
Jacob Appelbaum | 9f80729 | 2012-07-16 18:24:37 -0700 | [diff] [blame] | 363 | } |
Jacob Appelbaum | 123bb3e | 2012-07-16 17:25:34 -0700 | [diff] [blame] | 364 | } |
| 365 | |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 366 | uint32_t |
Jacob Appelbaum | 42ccf9d | 2012-07-29 16:30:15 -0700 | [diff] [blame] | 367 | get_certificate_keybits (EVP_PKEY *public_key) |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 368 | { |
| 369 | /* |
| 370 | In theory, we could use check_bitlen_dsa() and check_bitlen_rsa() |
| 371 | */ |
| 372 | uint32_t key_bits; |
Daniel Kurtz | a2d82d5 | 2019-06-07 15:26:54 -0600 | [diff] [blame] | 373 | switch (EVP_PKEY_id (public_key)) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 374 | { |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 375 | case EVP_PKEY_RSA: |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 376 | verb ("V: key type: EVP_PKEY_RSA\n"); |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 377 | break; |
| 378 | case EVP_PKEY_RSA2: |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 379 | verb ("V: key type: EVP_PKEY_RSA2\n"); |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 380 | break; |
| 381 | case EVP_PKEY_DSA: |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 382 | verb ("V: key type: EVP_PKEY_DSA\n"); |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 383 | break; |
| 384 | case EVP_PKEY_DSA1: |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 385 | verb ("V: key type: EVP_PKEY_DSA1\n"); |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 386 | break; |
| 387 | case EVP_PKEY_DSA2: |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 388 | verb ("V: key type: EVP_PKEY_DSA2\n"); |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 389 | break; |
| 390 | case EVP_PKEY_DSA3: |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 391 | verb ("V: key type: EVP_PKEY_DSA3\n"); |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 392 | break; |
| 393 | case EVP_PKEY_DSA4: |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 394 | verb ("V: key type: EVP_PKEY_DSA4\n"); |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 395 | break; |
| 396 | case EVP_PKEY_DH: |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 397 | verb ("V: key type: EVP_PKEY_DH\n"); |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 398 | break; |
| 399 | case EVP_PKEY_EC: |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 400 | verb ("V: key type: EVP_PKEY_EC\n"); |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 401 | break; |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 402 | // Should we also care about EVP_PKEY_HMAC and EVP_PKEY_CMAC? |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 403 | default: |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 404 | die ("unknown public key type\n"); |
| 405 | break; |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 406 | } |
Daniel Kurtz | a2d82d5 | 2019-06-07 15:26:54 -0600 | [diff] [blame] | 407 | key_bits = EVP_PKEY_bits (public_key); |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 408 | verb ("V: keybits: %d\n", key_bits); |
| 409 | return key_bits; |
| 410 | } |
| 411 | |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 412 | uint32_t |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 413 | dns_label_count (char *label, char *delim) |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 414 | { |
| 415 | char *label_tmp; |
| 416 | char *saveptr; |
| 417 | char *saveptr_tmp; |
| 418 | uint32_t label_count; |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 419 | label_tmp = strdup (label); |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 420 | label_count = 0; |
| 421 | saveptr = NULL; |
| 422 | saveptr_tmp = NULL; |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 423 | saveptr = strtok_r (label_tmp, delim, &saveptr); |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 424 | if (NULL != saveptr) |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 425 | { |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 426 | // Did we find our first label? |
| 427 | if (saveptr[0] != delim[0]) |
| 428 | { |
| 429 | label_count++; |
| 430 | verb ("V: label found; total label count: %d\n", label_count); |
| 431 | } |
| 432 | do |
| 433 | { |
| 434 | // Find all subsequent labels |
| 435 | label_count++; |
| 436 | saveptr_tmp = strtok_r (NULL, delim, &saveptr); |
| 437 | verb ("V: label found; total label count: %d\n", label_count); |
| 438 | } |
| 439 | while (NULL != saveptr_tmp); |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 440 | } |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 441 | free (label_tmp); |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 442 | return label_count; |
| 443 | } |
| 444 | |
| 445 | // first we split strings on '.' |
| 446 | // then we call each split string a 'label' |
| 447 | // Do not allow '*' for the top level domain label; eg never allow *.*.com |
| 448 | // Do not allow '*' for subsequent subdomains; eg never allow *.foo.example.com |
| 449 | // Do allow *.example.com |
| 450 | uint32_t |
| 451 | check_wildcard_match_rfc2595 (const char *orig_hostname, |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 452 | const char *orig_cert_wild_card) |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 453 | { |
| 454 | char *hostname; |
| 455 | char *hostname_to_free; |
| 456 | char *cert_wild_card; |
| 457 | char *cert_wild_card_to_free; |
| 458 | char *expected_label; |
| 459 | char *wildcard_label; |
| 460 | char *delim; |
| 461 | char *wildchar; |
| 462 | uint32_t ok; |
| 463 | uint32_t wildcard_encountered; |
| 464 | uint32_t label_count; |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 465 | // First we copy the original strings |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 466 | hostname = strndup (orig_hostname, strlen (orig_hostname)); |
| 467 | cert_wild_card = strndup (orig_cert_wild_card, strlen (orig_cert_wild_card)); |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 468 | hostname_to_free = hostname; |
| 469 | cert_wild_card_to_free = cert_wild_card; |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 470 | delim = strdup ("."); |
| 471 | wildchar = strdup ("*"); |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 472 | verb ("V: Inspecting '%s' for possible wildcard match against '%s'\n", |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 473 | hostname, cert_wild_card); |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 474 | // By default we have not processed any labels |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 475 | label_count = dns_label_count (cert_wild_card, delim); |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 476 | // By default we have no match |
| 477 | ok = 0; |
| 478 | wildcard_encountered = 0; |
| 479 | // First - do we have labels? If not, we refuse to even try to match |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 480 | if ( (NULL != strpbrk (cert_wild_card, delim)) && |
| 481 | (NULL != strpbrk (hostname, delim)) && |
| 482 | (label_count <= ( (uint32_t) RFC2595_MIN_LABEL_COUNT))) |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 483 | { |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 484 | if (wildchar[0] == cert_wild_card[0]) |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 485 | { |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 486 | verb ("V: Found wildcard in at start of provided certificate name\n"); |
| 487 | do |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 488 | { |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 489 | // Skip over the bytes between the first char and until the next label |
| 490 | wildcard_label = strsep (&cert_wild_card, delim); |
| 491 | expected_label = strsep (&hostname, delim); |
| 492 | if (NULL != wildcard_label && |
| 493 | NULL != expected_label && |
| 494 | NULL != hostname && |
| 495 | NULL != cert_wild_card) |
| 496 | { |
| 497 | // Now we only consider this wildcard valid if the rest of the |
| 498 | // hostnames match verbatim |
| 499 | verb ("V: Attempting match of '%s' against '%s'\n", |
| 500 | expected_label, wildcard_label); |
| 501 | // This is the case where we have a label that begins with wildcard |
| 502 | // Furthermore, we only allow this for the first label |
| 503 | if (wildcard_label[0] == wildchar[0] && |
| 504 | 0 == wildcard_encountered && 0 == ok) |
| 505 | { |
| 506 | verb ("V: Forced match of '%s' against '%s'\n", expected_label, wildcard_label); |
| 507 | wildcard_encountered = 1; |
| 508 | } |
| 509 | else |
| 510 | { |
| 511 | verb ("V: Attempting match of '%s' against '%s'\n", |
| 512 | hostname, cert_wild_card); |
| 513 | if (0 == strcasecmp (expected_label, wildcard_label) && |
| 514 | label_count >= ( (uint32_t) RFC2595_MIN_LABEL_COUNT)) |
| 515 | { |
| 516 | ok = 1; |
| 517 | verb ("V: remaining labels match!\n"); |
| 518 | break; |
| 519 | } |
| 520 | else |
| 521 | { |
| 522 | ok = 0; |
| 523 | verb ("V: remaining labels do not match!\n"); |
| 524 | break; |
| 525 | } |
| 526 | } |
| 527 | } |
| 528 | else |
| 529 | { |
| 530 | // We hit this case when we have a mismatched number of labels |
| 531 | verb ("V: NULL label; no wildcard here\n"); |
| 532 | break; |
| 533 | } |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 534 | } |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 535 | while (0 != wildcard_encountered && label_count <= RFC2595_MIN_LABEL_COUNT); |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 536 | } |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 537 | else |
| 538 | { |
| 539 | verb ("V: Not a RFC 2595 wildcard\n"); |
| 540 | } |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 541 | } |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 542 | else |
| 543 | { |
| 544 | verb ("V: Not a valid wildcard certificate\n"); |
| 545 | ok = 0; |
| 546 | } |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 547 | // Free our copies |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 548 | free (wildchar); |
| 549 | free (delim); |
| 550 | free (hostname_to_free); |
| 551 | free (cert_wild_card_to_free); |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 552 | if (wildcard_encountered & ok && label_count >= RFC2595_MIN_LABEL_COUNT) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 553 | { |
| 554 | verb ("V: wildcard match of %s against %s\n", |
| 555 | orig_hostname, orig_cert_wild_card); |
| 556 | return (wildcard_encountered & ok); |
| 557 | } |
| 558 | else |
| 559 | { |
| 560 | verb ("V: wildcard match failure of %s against %s\n", |
| 561 | orig_hostname, orig_cert_wild_card); |
| 562 | return 0; |
| 563 | } |
Jacob Appelbaum | ad12a3a | 2012-08-05 17:47:17 -0700 | [diff] [blame] | 564 | } |
| 565 | |
Jacob Appelbaum | 42ccf9d | 2012-07-29 16:30:15 -0700 | [diff] [blame] | 566 | /** |
| 567 | This extracts the first commonName and checks it against hostname. |
| 568 | */ |
| 569 | uint32_t |
| 570 | check_cn (SSL *ssl, const char *hostname) |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 571 | { |
Daniel Borkmann | 23c2b80 | 2012-07-30 14:06:12 +0200 | [diff] [blame] | 572 | int ok = 0; |
Jacob Appelbaum | 42ccf9d | 2012-07-29 16:30:15 -0700 | [diff] [blame] | 573 | uint32_t ret; |
| 574 | char *cn_buf; |
| 575 | X509 *certificate; |
Jacob Appelbaum | 8f7682d | 2012-07-31 03:28:26 -0700 | [diff] [blame] | 576 | X509_NAME *xname; |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 577 | cn_buf = xmalloc (TLSDATE_HOST_NAME_MAX + 1); |
| 578 | certificate = SSL_get_peer_certificate (ssl); |
Jacob Appelbaum | 8f7682d | 2012-07-31 03:28:26 -0700 | [diff] [blame] | 579 | if (NULL == certificate) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 580 | { |
| 581 | die ("Unable to extract certificate\n"); |
| 582 | } |
| 583 | memset (cn_buf, '\0', (TLSDATE_HOST_NAME_MAX + 1)); |
| 584 | xname = X509_get_subject_name (certificate); |
| 585 | ret = X509_NAME_get_text_by_NID (xname, NID_commonName, |
| 586 | cn_buf, TLSDATE_HOST_NAME_MAX); |
| 587 | if (-1 == ret && ret != strlen (hostname)) |
| 588 | { |
| 589 | die ("Unable to extract commonName\n"); |
| 590 | } |
| 591 | if (strcasecmp (cn_buf, hostname)) |
| 592 | { |
| 593 | verb ("V: commonName mismatch! Expected: %s - received: %s\n", |
| 594 | hostname, cn_buf); |
| 595 | } |
| 596 | else |
| 597 | { |
| 598 | verb ("V: commonName matched: %s\n", cn_buf); |
| 599 | ok = 1; |
| 600 | } |
| 601 | X509_NAME_free (xname); |
| 602 | X509_free (certificate); |
| 603 | xfree (cn_buf); |
Daniel Borkmann | 23c2b80 | 2012-07-30 14:06:12 +0200 | [diff] [blame] | 604 | return ok; |
Jacob Appelbaum | 42ccf9d | 2012-07-29 16:30:15 -0700 | [diff] [blame] | 605 | } |
| 606 | |
| 607 | /** |
| 608 | Search for a hostname match in the SubjectAlternativeNames. |
| 609 | */ |
| 610 | uint32_t |
| 611 | check_san (SSL *ssl, const char *hostname) |
| 612 | { |
Jacob Appelbaum | fc9761e | 2012-07-30 01:29:49 -0700 | [diff] [blame] | 613 | X509 *cert; |
Jacob Appelbaum | fc9761e | 2012-07-30 01:29:49 -0700 | [diff] [blame] | 614 | int extcount, ok = 0; |
| 615 | /* What an OpenSSL mess ... */ |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 616 | if (NULL == (cert = SSL_get_peer_certificate (ssl))) |
Jacob Appelbaum | fc9761e | 2012-07-30 01:29:49 -0700 | [diff] [blame] | 617 | { |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 618 | die ("Getting certificate failed\n"); |
| 619 | } |
| 620 | if ( (extcount = X509_get_ext_count (cert)) > 0) |
| 621 | { |
| 622 | int i; |
| 623 | for (i = 0; i < extcount; ++i) |
Jacob Appelbaum | 145886f | 2012-07-30 01:56:53 -0700 | [diff] [blame] | 624 | { |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 625 | const char *extstr; |
| 626 | X509_EXTENSION *ext; |
| 627 | ext = X509_get_ext (cert, i); |
| 628 | extstr = OBJ_nid2sn (OBJ_obj2nid (X509_EXTENSION_get_object (ext))); |
| 629 | if (!strcmp (extstr, "subjectAltName")) |
Jacob Appelbaum | fc9761e | 2012-07-30 01:29:49 -0700 | [diff] [blame] | 630 | { |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 631 | int j; |
| 632 | void *extvalstr; |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 633 | STACK_OF (CONF_VALUE) *val; |
| 634 | CONF_VALUE *nval; |
| 635 | #if OPENSSL_VERSION_NUMBER >= 0x10000000L |
| 636 | const |
| 637 | #endif |
| 638 | X509V3_EXT_METHOD *method; |
| 639 | if (! (method = X509V3_EXT_get (ext))) |
| 640 | { |
| 641 | break; |
| 642 | } |
Daniel Kurtz | a2d82d5 | 2019-06-07 15:26:54 -0600 | [diff] [blame] | 643 | extvalstr = X509V3_EXT_d2i(ext); |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 644 | if (!extvalstr) |
| 645 | { |
| 646 | break; |
| 647 | } |
| 648 | if (method->i2v) |
| 649 | { |
| 650 | val = method->i2v (method, extvalstr, NULL); |
| 651 | for (j = 0; j < sk_CONF_VALUE_num (val); ++j) |
| 652 | { |
| 653 | nval = sk_CONF_VALUE_value (val, j); |
| 654 | if ( (!strcasecmp (nval->name, "DNS") && |
| 655 | !strcasecmp (nval->value, hostname)) || |
| 656 | (!strcasecmp (nval->name, "iPAddress") && |
| 657 | !strcasecmp (nval->value, hostname))) |
| 658 | { |
| 659 | verb ("V: subjectAltName matched: %s, type: %s\n", nval->value, nval->name); // We matched this; so it's safe to print |
| 660 | ok = 1; |
| 661 | break; |
| 662 | } |
| 663 | // Attempt to match subjectAltName DNS names |
| 664 | if (!strcasecmp (nval->name, "DNS")) |
| 665 | { |
| 666 | ok = check_wildcard_match_rfc2595 (hostname, nval->value); |
| 667 | if (ok) |
| 668 | { |
| 669 | break; |
| 670 | } |
| 671 | } |
| 672 | verb ("V: subjectAltName found but not matched: %s, type: %s\n", nval->value, nval->name); // XXX: Clean this string! |
| 673 | } |
| 674 | } |
| 675 | } |
| 676 | else |
| 677 | { |
| 678 | verb ("V: found non subjectAltName extension\n"); |
| 679 | } |
| 680 | if (ok) |
| 681 | { |
Jacob Appelbaum | fc9761e | 2012-07-30 01:29:49 -0700 | [diff] [blame] | 682 | break; |
| 683 | } |
Jacob Appelbaum | fc9761e | 2012-07-30 01:29:49 -0700 | [diff] [blame] | 684 | } |
Jacob Appelbaum | fc9761e | 2012-07-30 01:29:49 -0700 | [diff] [blame] | 685 | } |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 686 | else |
| 687 | { |
| 688 | verb ("V: no X509_EXTENSION field(s) found\n"); |
| 689 | } |
| 690 | X509_free (cert); |
Jacob Appelbaum | 145886f | 2012-07-30 01:56:53 -0700 | [diff] [blame] | 691 | return ok; |
Jacob Appelbaum | 42ccf9d | 2012-07-29 16:30:15 -0700 | [diff] [blame] | 692 | } |
| 693 | |
| 694 | uint32_t |
| 695 | check_name (SSL *ssl, const char *hostname) |
| 696 | { |
| 697 | uint32_t ret; |
Jacob Appelbaum | 193e561 | 2012-07-30 03:01:35 -0700 | [diff] [blame] | 698 | ret = 0; |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 699 | ret = check_cn (ssl, hostname); |
| 700 | ret += check_san (ssl, hostname); |
Jacob Appelbaum | 193e561 | 2012-07-30 03:01:35 -0700 | [diff] [blame] | 701 | if (0 != ret && 0 < ret) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 702 | { |
| 703 | verb ("V: hostname verification passed\n"); |
| 704 | } |
| 705 | else |
| 706 | { |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 707 | die ("hostname verification failed for host %s!\n", g_host); |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 708 | } |
Jacob Appelbaum | 42ccf9d | 2012-07-29 16:30:15 -0700 | [diff] [blame] | 709 | return ret; |
| 710 | } |
| 711 | |
| 712 | uint32_t |
| 713 | verify_signature (SSL *ssl, const char *hostname) |
| 714 | { |
| 715 | long ssl_verify_result; |
| 716 | X509 *certificate; |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 717 | certificate = SSL_get_peer_certificate (ssl); |
Jacob Appelbaum | 42ccf9d | 2012-07-29 16:30:15 -0700 | [diff] [blame] | 718 | if (NULL == certificate) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 719 | { |
| 720 | die ("Getting certificate failed\n"); |
| 721 | } |
Jacob Appelbaum | 42ccf9d | 2012-07-29 16:30:15 -0700 | [diff] [blame] | 722 | // In theory, we verify that the cert is valid |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 723 | ssl_verify_result = SSL_get_verify_result (ssl); |
Jacob Appelbaum | 42ccf9d | 2012-07-29 16:30:15 -0700 | [diff] [blame] | 724 | switch (ssl_verify_result) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 725 | { |
| 726 | case X509_V_ERR_DEPTH_ZERO_SELF_SIGNED_CERT: |
| 727 | case X509_V_ERR_SELF_SIGNED_CERT_IN_CHAIN: |
| 728 | die ("certificate is self signed\n"); |
| 729 | case X509_V_OK: |
| 730 | verb ("V: certificate verification passed\n"); |
| 731 | break; |
| 732 | default: |
| 733 | die ("certification verification error: %ld\n", |
| 734 | ssl_verify_result); |
| 735 | } |
| 736 | return 0; |
Jacob Appelbaum | 42ccf9d | 2012-07-29 16:30:15 -0700 | [diff] [blame] | 737 | } |
| 738 | |
| 739 | void |
| 740 | check_key_length (SSL *ssl) |
| 741 | { |
| 742 | uint32_t key_bits; |
| 743 | X509 *certificate; |
| 744 | EVP_PKEY *public_key; |
| 745 | certificate = SSL_get_peer_certificate (ssl); |
A soldier | 31056a6 | 2012-08-16 01:10:57 -0700 | [diff] [blame] | 746 | if (NULL == certificate) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 747 | { |
| 748 | die ("Getting certificate failed\n"); |
| 749 | } |
Jacob Appelbaum | 42ccf9d | 2012-07-29 16:30:15 -0700 | [diff] [blame] | 750 | public_key = X509_get_pubkey (certificate); |
| 751 | if (NULL == public_key) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 752 | { |
| 753 | die ("public key extraction failure\n"); |
| 754 | } |
| 755 | else |
| 756 | { |
| 757 | verb ("V: public key is ready for inspection\n"); |
| 758 | } |
Jacob Appelbaum | 42ccf9d | 2012-07-29 16:30:15 -0700 | [diff] [blame] | 759 | key_bits = get_certificate_keybits (public_key); |
Daniel Kurtz | a2d82d5 | 2019-06-07 15:26:54 -0600 | [diff] [blame] | 760 | if (MIN_PUB_KEY_LEN >= key_bits && EVP_PKEY_id(public_key) != EVP_PKEY_EC) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 761 | { |
| 762 | die ("Unsafe public key size: %d bits\n", key_bits); |
| 763 | } |
| 764 | else |
| 765 | { |
Daniel Kurtz | a2d82d5 | 2019-06-07 15:26:54 -0600 | [diff] [blame] | 766 | if (EVP_PKEY_id(public_key) == EVP_PKEY_EC) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 767 | if (key_bits >= MIN_ECC_PUB_KEY_LEN |
| 768 | && key_bits <= MAX_ECC_PUB_KEY_LEN) |
| 769 | { |
| 770 | verb ("V: ECC key length appears safe\n"); |
| 771 | } |
| 772 | else |
| 773 | { |
| 774 | die ("Unsafe ECC key size: %d bits\n", key_bits); |
| 775 | } |
| 776 | else |
| 777 | { |
| 778 | verb ("V: key length appears safe\n"); |
| 779 | } |
| 780 | } |
Jacob Appelbaum | 42ccf9d | 2012-07-29 16:30:15 -0700 | [diff] [blame] | 781 | EVP_PKEY_free (public_key); |
| 782 | } |
| 783 | |
| 784 | void |
| 785 | inspect_key (SSL *ssl, const char *hostname) |
| 786 | { |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 787 | verify_signature (ssl, hostname); |
| 788 | check_name (ssl, hostname); |
Jacob Appelbaum | c4d3f9f | 2012-07-17 18:20:56 -0700 | [diff] [blame] | 789 | } |
| 790 | |
Christian Grothoff | 88b422b | 2012-02-14 00:35:09 +0100 | [diff] [blame] | 791 | /** |
| 792 | * Run SSL handshake and store the resulting time value in the |
| 793 | * 'time_map'. |
| 794 | * |
| 795 | * @param time_map where to store the current time |
| 796 | */ |
| 797 | static void |
Jacob Appelbaum | c732f4e | 2012-07-15 22:38:46 -0400 | [diff] [blame] | 798 | run_ssl (uint32_t *time_map, int time_is_an_illusion) |
Christian Grothoff | 90e9f83 | 2012-02-07 11:16:47 +0100 | [diff] [blame] | 799 | { |
Christian Grothoff | 90e9f83 | 2012-02-07 11:16:47 +0100 | [diff] [blame] | 800 | BIO *s_bio; |
Christian Grothoff | 90e9f83 | 2012-02-07 11:16:47 +0100 | [diff] [blame] | 801 | SSL_CTX *ctx; |
| 802 | SSL *ssl; |
Jacob Appelbaum | 12e15c9 | 2013-01-07 11:17:32 -0800 | [diff] [blame] | 803 | struct stat statbuf; |
Christian Grothoff | 90e9f83 | 2012-02-07 11:16:47 +0100 | [diff] [blame] | 804 | SSL_load_error_strings(); |
| 805 | SSL_library_init(); |
Christian Grothoff | 90e9f83 | 2012-02-07 11:16:47 +0100 | [diff] [blame] | 806 | ctx = NULL; |
Daniel Kurtz | a2d82d5 | 2019-06-07 15:26:54 -0600 | [diff] [blame] | 807 | |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 808 | if (0 == strcmp ("sslv23", g_protocol)) |
Jacob Appelbaum | 12e15c9 | 2013-01-07 11:17:32 -0800 | [diff] [blame] | 809 | { |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 810 | verb ("V: using SSLv23_client_method()\n"); |
| 811 | ctx = SSL_CTX_new (SSLv23_client_method()); |
Jacob Appelbaum | 12e15c9 | 2013-01-07 11:17:32 -0800 | [diff] [blame] | 812 | } |
Mattias Nissler | 2ca1457 | 2020-01-13 15:01:43 +0100 | [diff] [blame] | 813 | #ifndef OPENSSL_NO_SSL3_METHOD |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 814 | else if (0 == strcmp ("sslv3", g_protocol)) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 815 | { |
| 816 | verb ("V: using SSLv3_client_method()\n"); |
| 817 | ctx = SSL_CTX_new (SSLv3_client_method()); |
| 818 | } |
Mattias Nissler | 2ca1457 | 2020-01-13 15:01:43 +0100 | [diff] [blame] | 819 | #endif |
| 820 | #ifndef OPENSSL_NO_TLS1_METHOD |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 821 | else if (0 == strcmp ("tlsv1", g_protocol)) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 822 | { |
| 823 | verb ("V: using TLSv1_client_method()\n"); |
| 824 | ctx = SSL_CTX_new (TLSv1_client_method()); |
| 825 | } |
Mattias Nissler | 2ca1457 | 2020-01-13 15:01:43 +0100 | [diff] [blame] | 826 | #endif |
| 827 | #ifndef OPENSSL_NO_TLS1_1_METHOD |
| 828 | else if (0 == strcmp ("tlsv11", g_protocol)) |
| 829 | { |
| 830 | verb ("V: using TLSv1_1_client_method()\n"); |
| 831 | ctx = SSL_CTX_new (TLSv1_1_client_method()); |
| 832 | } |
| 833 | #endif |
| 834 | #ifndef OPENSSL_NO_TLS1_2_METHOD |
| 835 | else if (0 == strcmp ("tlsv12", g_protocol)) |
| 836 | { |
| 837 | verb ("V: using TLSv1_2_client_method()\n"); |
| 838 | ctx = SSL_CTX_new (TLSv1_2_client_method()); |
| 839 | } |
| 840 | #endif |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 841 | else |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 842 | die ("Unsupported protocol `%s'\n", g_protocol); |
Daniel Kurtz | a2d82d5 | 2019-06-07 15:26:54 -0600 | [diff] [blame] | 843 | |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 844 | if (ctx == NULL) |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 845 | die ("OpenSSL failed to support protocol `%s'\n", g_protocol); |
| 846 | if (g_ca_racket) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 847 | { |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 848 | if (-1 == stat (g_ca_cert_container, &statbuf)) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 849 | { |
| 850 | die ("Unable to stat CA certficate container\n"); |
| 851 | } |
| 852 | else |
| 853 | { |
| 854 | switch (statbuf.st_mode & S_IFMT) |
| 855 | { |
| 856 | case S_IFREG: |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 857 | if (1 != SSL_CTX_load_verify_locations( |
| 858 | ctx, g_ca_cert_container, NULL)) |
| 859 | fprintf(stderr, "SSL_CTX_load_verify_locations failed\n"); |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 860 | break; |
| 861 | case S_IFDIR: |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 862 | if (1 != SSL_CTX_load_verify_locations( |
| 863 | ctx, NULL, g_ca_cert_container)) |
| 864 | fprintf(stderr, "SSL_CTX_load_verify_locations failed\n"); |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 865 | break; |
| 866 | default: |
| 867 | die ("Unable to load CA certficate container\n"); |
| 868 | } |
| 869 | } |
| 870 | } |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 871 | verb ("V: setting up connection to %s:%s\n", g_host, g_port); |
| 872 | if (NULL == (s_bio = make_ssl_bio(ctx, g_host, g_port, g_proxy))) |
Christian Grothoff | 90e9f83 | 2012-02-07 11:16:47 +0100 | [diff] [blame] | 873 | die ("SSL BIO setup failed\n"); |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 874 | BIO_get_ssl (s_bio, &ssl); |
Christian Grothoff | 90e9f83 | 2012-02-07 11:16:47 +0100 | [diff] [blame] | 875 | if (NULL == ssl) |
| 876 | die ("SSL setup failed\n"); |
Jacob Appelbaum | 9f80729 | 2012-07-16 18:24:37 -0700 | [diff] [blame] | 877 | if (time_is_an_illusion) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 878 | { |
| 879 | SSL_set_info_callback (ssl, openssl_time_callback); |
| 880 | } |
| 881 | SSL_set_mode (ssl, SSL_MODE_AUTO_RETRY); |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 882 | SSL_set_tlsext_host_name (ssl, g_host); |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 883 | if (NULL == BIO_new_fp (stdout, BIO_NOCLOSE)) |
| 884 | die ("BIO_new_fp returned error, possibly: %s", strerror (errno)); |
Jacob Appelbaum | 405a793 | 2012-02-15 15:22:02 -0800 | [diff] [blame] | 885 | // This should run in seccomp |
| 886 | // eg: prctl(PR_SET_SECCOMP, 1); |
Pavol Marko | d9dd19d | 2020-01-17 23:32:57 +0100 | [diff] [blame^] | 887 | verb ("V: BIO_do_connect\n"); |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 888 | if (1 != BIO_do_connect (s_bio)) // XXX TODO: BIO_should_retry() later? |
Jacob Appelbaum | 9a15957 | 2012-02-20 12:39:44 -0800 | [diff] [blame] | 889 | die ("SSL connection failed\n"); |
Pavol Marko | d9dd19d | 2020-01-17 23:32:57 +0100 | [diff] [blame^] | 890 | verb ("V: BIO_do_handshake\n"); |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 891 | if (1 != BIO_do_handshake (s_bio)) |
Philipp Winter | d96af62 | 2012-02-15 22:15:50 +0100 | [diff] [blame] | 892 | die ("SSL handshake failed\n"); |
Christian Grothoff | 90e9f83 | 2012-02-07 11:16:47 +0100 | [diff] [blame] | 893 | // Verify the peer certificate against the CA certs on the local system |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 894 | if (g_ca_racket) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 895 | { |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 896 | inspect_key (ssl, g_host); |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 897 | } |
| 898 | else |
| 899 | { |
| 900 | verb ("V: Certificate verification skipped!\n"); |
| 901 | } |
| 902 | check_key_length (ssl); |
Christian Grothoff | 90e9f83 | 2012-02-07 11:16:47 +0100 | [diff] [blame] | 903 | // from /usr/include/openssl/ssl3.h |
Jacob Appelbaum | ca64b50 | 2012-06-28 21:54:14 -0700 | [diff] [blame] | 904 | // ssl->s3->server_random is an unsigned char of 32 bits |
Daniel Kurtz | a2d82d5 | 2019-06-07 15:26:54 -0600 | [diff] [blame] | 905 | SSL_get_server_random(ssl, (unsigned char *)time_map, sizeof(uint32_t)); |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 906 | SSL_free (ssl); |
| 907 | SSL_CTX_free (ctx); |
Christian Grothoff | 88b422b | 2012-02-14 00:35:09 +0100 | [diff] [blame] | 908 | } |
Christian Grothoff | 90e9f83 | 2012-02-07 11:16:47 +0100 | [diff] [blame] | 909 | |
Christian Grothoff | 191cd98 | 2012-02-14 00:48:45 +0100 | [diff] [blame] | 910 | /** drop root rights and become 'nobody' */ |
Christian Grothoff | bd15a22 | 2012-02-14 00:40:57 +0100 | [diff] [blame] | 911 | |
Christian Grothoff | 88b422b | 2012-02-14 00:35:09 +0100 | [diff] [blame] | 912 | int |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 913 | main (int argc, char **argv) |
Christian Grothoff | 88b422b | 2012-02-14 00:35:09 +0100 | [diff] [blame] | 914 | { |
| 915 | uint32_t *time_map; |
David Goulet | 0809df1 | 2012-07-31 23:27:34 -0400 | [diff] [blame] | 916 | struct tlsdate_time start_time, end_time, warp_time; |
Christian Grothoff | 88b422b | 2012-02-14 00:35:09 +0100 | [diff] [blame] | 917 | int status; |
| 918 | pid_t ssl_child; |
Christian Grothoff | e267c35 | 2012-02-14 01:10:54 +0100 | [diff] [blame] | 919 | long long rt_time_ms; |
| 920 | uint32_t server_time_s; |
Jeroen Massar | c27a92a | 2012-07-13 11:49:05 +0200 | [diff] [blame] | 921 | int setclock; |
| 922 | int showtime; |
Will Drewry | 7270675 | 2013-09-13 15:57:10 -0500 | [diff] [blame] | 923 | int showtime_raw; |
Jacob Appelbaum | 894d527 | 2012-07-15 14:32:39 -0400 | [diff] [blame] | 924 | int timewarp; |
Jacob Appelbaum | c732f4e | 2012-07-15 22:38:46 -0400 | [diff] [blame] | 925 | int leap; |
Elly Fong-Jones | 4687c5d | 2012-10-03 17:34:48 -0400 | [diff] [blame] | 926 | if (argc != 12) |
Christian Grothoff | 88b422b | 2012-02-14 00:35:09 +0100 | [diff] [blame] | 927 | return 1; |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 928 | g_host = argv[1]; |
| 929 | g_port = argv[2]; |
| 930 | validate_port(g_port); |
| 931 | g_protocol = argv[3]; |
| 932 | g_ca_cert_container = argv[6]; |
| 933 | g_ca_racket = (0 != strcmp ("unchecked", argv[4])); |
Christian Grothoff | 88b422b | 2012-02-14 00:35:09 +0100 | [diff] [blame] | 934 | verbose = (0 != strcmp ("quiet", argv[5])); |
Jeroen Massar | c27a92a | 2012-07-13 11:49:05 +0200 | [diff] [blame] | 935 | setclock = (0 == strcmp ("setclock", argv[7])); |
| 936 | showtime = (0 == strcmp ("showtime", argv[8])); |
Will Drewry | 7270675 | 2013-09-13 15:57:10 -0500 | [diff] [blame] | 937 | showtime_raw = (0 == strcmp ("showtime=raw", argv[8])); |
Jacob Appelbaum | 894d527 | 2012-07-15 14:32:39 -0400 | [diff] [blame] | 938 | timewarp = (0 == strcmp ("timewarp", argv[9])); |
Jacob Appelbaum | c732f4e | 2012-07-15 22:38:46 -0400 | [diff] [blame] | 939 | leap = (0 == strcmp ("leapaway", argv[10])); |
Andreea Costinas | 6d6944a | 2019-03-27 15:29:09 +0100 | [diff] [blame] | 940 | g_proxy = (0 == strcmp ("none", argv[11]) ? NULL : argv[11]); |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 941 | clock_init_time (&warp_time, RECENT_COMPILE_DATE, 0); |
Jacob Appelbaum | 894d527 | 2012-07-15 14:32:39 -0400 | [diff] [blame] | 942 | if (timewarp) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 943 | { |
| 944 | verb ("V: RECENT_COMPILE_DATE is %lu.%06lu\n", |
| 945 | (unsigned long) CLOCK_SEC (&warp_time), |
| 946 | (unsigned long) CLOCK_USEC (&warp_time)); |
| 947 | } |
Jeroen Massar | c27a92a | 2012-07-13 11:49:05 +0200 | [diff] [blame] | 948 | /* We are not going to set the clock, thus no need to stay root */ |
Jacob Appelbaum | 894d527 | 2012-07-15 14:32:39 -0400 | [diff] [blame] | 949 | if (0 == setclock && 0 == timewarp) |
Jacob Appelbaum | 894d527 | 2012-07-15 14:32:39 -0400 | [diff] [blame] | 950 | { |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 951 | drop_privs_to (UNPRIV_USER, UNPRIV_GROUP); |
Jacob Appelbaum | 894d527 | 2012-07-15 14:32:39 -0400 | [diff] [blame] | 952 | } |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 953 | time_map = mmap (NULL, sizeof (uint32_t), |
| 954 | PROT_READ | PROT_WRITE, |
| 955 | MAP_SHARED | MAP_ANONYMOUS, -1, 0); |
| 956 | if (MAP_FAILED == time_map) |
| 957 | { |
| 958 | fprintf (stderr, "mmap failed: %s\n", |
| 959 | strerror (errno)); |
| 960 | return 1; |
| 961 | } |
| 962 | /* Get the current time from the system clock. */ |
| 963 | if (0 != clock_get_real_time (&start_time)) |
| 964 | { |
| 965 | die ("Failed to read current time of day: %s\n", strerror (errno)); |
| 966 | } |
| 967 | verb ("V: time is currently %lu.%06lu\n", |
| 968 | (unsigned long) CLOCK_SEC (&start_time), |
| 969 | (unsigned long) CLOCK_NSEC (&start_time)); |
| 970 | if ( ( (unsigned long) CLOCK_SEC (&start_time)) < ( (unsigned long) CLOCK_SEC (&warp_time))) |
| 971 | { |
| 972 | verb ("V: local clock time is less than RECENT_COMPILE_DATE\n"); |
| 973 | if (timewarp) |
| 974 | { |
| 975 | verb ("V: Attempting to warp local clock into the future\n"); |
| 976 | if (0 != clock_set_real_time (&warp_time)) |
| 977 | { |
| 978 | die ("setting time failed: %s (Attempted to set clock to %lu.%06lu)\n", |
| 979 | strerror (errno), |
| 980 | (unsigned long) CLOCK_SEC (&warp_time), |
| 981 | (unsigned long) CLOCK_SEC (&warp_time)); |
| 982 | } |
| 983 | if (0 != clock_get_real_time (&start_time)) |
| 984 | { |
| 985 | die ("Failed to read current time of day: %s\n", strerror (errno)); |
| 986 | } |
| 987 | verb ("V: time is currently %lu.%06lu\n", |
| 988 | (unsigned long) CLOCK_SEC (&start_time), |
| 989 | (unsigned long) CLOCK_NSEC (&start_time)); |
| 990 | verb ("V: It's just a step to the left...\n"); |
| 991 | } |
| 992 | } |
| 993 | else |
| 994 | { |
| 995 | verb ("V: time is greater than RECENT_COMPILE_DATE\n"); |
| 996 | } |
Christian Grothoff | 191cd98 | 2012-02-14 00:48:45 +0100 | [diff] [blame] | 997 | /* initialize to bogus value, just to be on the safe side */ |
Christian Grothoff | 88b422b | 2012-02-14 00:35:09 +0100 | [diff] [blame] | 998 | *time_map = 0; |
Christian Grothoff | e267c35 | 2012-02-14 01:10:54 +0100 | [diff] [blame] | 999 | /* Run SSL interaction in separate process (and not as 'root') */ |
Christian Grothoff | 88b422b | 2012-02-14 00:35:09 +0100 | [diff] [blame] | 1000 | ssl_child = fork (); |
| 1001 | if (-1 == ssl_child) |
| 1002 | die ("fork failed: %s\n", strerror (errno)); |
| 1003 | if (0 == ssl_child) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 1004 | { |
| 1005 | drop_privs_to (UNPRIV_USER, UNPRIV_GROUP); |
| 1006 | run_ssl (time_map, leap); |
| 1007 | (void) munmap (time_map, sizeof (uint32_t)); |
| 1008 | _exit (0); |
| 1009 | } |
Christian Grothoff | 88b422b | 2012-02-14 00:35:09 +0100 | [diff] [blame] | 1010 | if (ssl_child != waitpid (ssl_child, &status, 0)) |
| 1011 | die ("waitpid failed: %s\n", strerror (errno)); |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 1012 | if (! (WIFEXITED (status) && (0 == WEXITSTATUS (status)))) |
Christian Grothoff | 191cd98 | 2012-02-14 00:48:45 +0100 | [diff] [blame] | 1013 | die ("child process failed in SSL handshake\n"); |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 1014 | if (0 != clock_get_real_time (&end_time)) |
Christian Grothoff | 88b422b | 2012-02-14 00:35:09 +0100 | [diff] [blame] | 1015 | die ("Failed to read current time of day: %s\n", strerror (errno)); |
Christian Grothoff | e267c35 | 2012-02-14 01:10:54 +0100 | [diff] [blame] | 1016 | /* calculate RTT */ |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 1017 | rt_time_ms = (CLOCK_SEC (&end_time) - CLOCK_SEC (&start_time)) * 1000 + (CLOCK_USEC (&end_time) - CLOCK_USEC (&start_time)) / 1000; |
Christian Grothoff | e267c35 | 2012-02-14 01:10:54 +0100 | [diff] [blame] | 1018 | if (rt_time_ms < 0) |
| 1019 | rt_time_ms = 0; /* non-linear time... */ |
| 1020 | server_time_s = ntohl (*time_map); |
| 1021 | munmap (time_map, sizeof (uint32_t)); |
Jacob Appelbaum | 9a15957 | 2012-02-20 12:39:44 -0800 | [diff] [blame] | 1022 | verb ("V: server time %u (difference is about %d s) was fetched in %lld ms\n", |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 1023 | (unsigned int) server_time_s, |
| 1024 | CLOCK_SEC (&start_time) - server_time_s, |
| 1025 | rt_time_ms); |
Philipp Winter | b3ca577 | 2012-02-16 11:56:11 +0100 | [diff] [blame] | 1026 | /* warning if the handshake took too long */ |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 1027 | if (rt_time_ms > TLS_RTT_THRESHOLD) |
| 1028 | { |
| 1029 | verb ("V: the TLS handshake took more than %d msecs - consider using a different " \ |
| 1030 | "server or run it again\n", TLS_RTT_THRESHOLD); |
| 1031 | } |
Will Drewry | 7270675 | 2013-09-13 15:57:10 -0500 | [diff] [blame] | 1032 | if (showtime_raw) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 1033 | { |
| 1034 | fwrite (&server_time_s, sizeof (server_time_s), 1, stdout); |
| 1035 | } |
Jeroen Massar | c27a92a | 2012-07-13 11:49:05 +0200 | [diff] [blame] | 1036 | if (showtime) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 1037 | { |
| 1038 | struct tm ltm; |
| 1039 | time_t tim = server_time_s; |
| 1040 | char buf[256]; |
| 1041 | localtime_r (&tim, <m); |
| 1042 | if (0 == strftime (buf, sizeof buf, "%a %b %e %H:%M:%S %Z %Y", <m)) |
| 1043 | { |
| 1044 | die ("strftime returned 0\n"); |
| 1045 | } |
| 1046 | fprintf (stdout, "%s\n", buf); |
| 1047 | } |
Christian Grothoff | 191cd98 | 2012-02-14 00:48:45 +0100 | [diff] [blame] | 1048 | /* finally, actually set the time */ |
Jeroen Massar | c27a92a | 2012-07-13 11:49:05 +0200 | [diff] [blame] | 1049 | if (setclock) |
Will Drewry | c45952f | 2013-09-03 13:51:24 -0500 | [diff] [blame] | 1050 | { |
| 1051 | struct tlsdate_time server_time; |
| 1052 | clock_init_time (&server_time, server_time_s + (rt_time_ms / 2 / 1000), |
| 1053 | (rt_time_ms / 2) % 1000); |
| 1054 | // We should never receive a time that is before the time we were last |
| 1055 | // compiled; we subscribe to the linear theory of time for this program |
| 1056 | // and this program alone! |
| 1057 | if (CLOCK_SEC (&server_time) >= MAX_REASONABLE_TIME) |
| 1058 | die ("remote server is a false ticker from the future!\n"); |
| 1059 | if (CLOCK_SEC (&server_time) <= RECENT_COMPILE_DATE) |
| 1060 | die ("remote server is a false ticker!\n"); |
| 1061 | if (0 != clock_set_real_time (&server_time)) |
| 1062 | die ("setting time failed: %s (Difference from server is about %d)\n", |
| 1063 | strerror (errno), |
| 1064 | CLOCK_SEC (&start_time) - server_time_s); |
| 1065 | verb ("V: setting time succeeded\n"); |
| 1066 | } |
Christian Grothoff | 90e9f83 | 2012-02-07 11:16:47 +0100 | [diff] [blame] | 1067 | return 0; |
| 1068 | } |