Benjamin Wright | 9201d1a | 2018-04-05 12:12:26 -0700 | [diff] [blame] | 1 | /* |
| 2 | * Copyright 2018 The WebRTC Project Authors. All rights reserved. |
| 3 | * |
| 4 | * Use of this source code is governed by a BSD-style license |
| 5 | * that can be found in the LICENSE file in the root of the source |
| 6 | * tree. An additional intellectual property rights grant can be found |
| 7 | * in the file PATENTS. All contributing project authors may |
| 8 | * be found in the AUTHORS file in the root of the source tree. |
| 9 | */ |
| 10 | |
| 11 | #include <string> |
| 12 | #include <vector> |
| 13 | |
| 14 | #if defined(WEBRTC_POSIX) |
| 15 | #include <unistd.h> |
| 16 | #endif |
| 17 | |
| 18 | #if defined(WEBRTC_WIN) |
| 19 | // Must be included first before openssl headers. |
| 20 | #include "rtc_base/win32.h" // NOLINT |
| 21 | #endif // WEBRTC_WIN |
| 22 | |
| 23 | #include <openssl/bio.h> |
| 24 | #include <openssl/crypto.h> |
| 25 | #include <openssl/x509.h> |
| 26 | #include <openssl/x509v3.h> |
| 27 | |
| 28 | #include "rtc_base/arraysize.h" |
| 29 | #include "rtc_base/gunit.h" |
| 30 | #include "rtc_base/numerics/safe_conversions.h" |
| 31 | #include "rtc_base/openssl.h" |
| 32 | #include "rtc_base/opensslcommon.h" |
| 33 | #include "rtc_base/sslroots.h" |
| 34 | #include "test/gmock.h" |
| 35 | |
| 36 | namespace rtc { |
| 37 | namespace { |
| 38 | // Fake Self-Signed SSL Certifiacte with CN: *.webrtc.org. |
| 39 | // This is only to be used for testing (it isn't signed by a CA anyway). |
| 40 | const unsigned char kFakeSSLCertificate[] = { |
| 41 | 0x30, 0x82, 0x02, 0x68, 0x30, 0x82, 0x02, 0x12, 0xA0, 0x03, 0x02, 0x01, |
| 42 | 0x02, 0x02, 0x09, 0x00, 0xC8, 0x83, 0x59, 0x4D, 0x90, 0xC3, 0x5F, 0xC8, |
| 43 | 0x30, 0x0D, 0x06, 0x09, 0x2A, 0x86, 0x48, 0x86, 0xF7, 0x0D, 0x01, 0x01, |
| 44 | 0x0B, 0x05, 0x00, 0x30, 0x81, 0x8D, 0x31, 0x0B, 0x30, 0x09, 0x06, 0x03, |
| 45 | 0x55, 0x04, 0x06, 0x13, 0x02, 0x55, 0x53, 0x31, 0x0B, 0x30, 0x09, 0x06, |
| 46 | 0x03, 0x55, 0x04, 0x08, 0x0C, 0x02, 0x57, 0x41, 0x31, 0x2C, 0x30, 0x2A, |
| 47 | 0x06, 0x03, 0x55, 0x04, 0x0A, 0x0C, 0x23, 0x46, 0x61, 0x6B, 0x65, 0x20, |
| 48 | 0x57, 0x65, 0x62, 0x52, 0x54, 0x43, 0x20, 0x43, 0x65, 0x72, 0x74, 0x69, |
| 49 | 0x66, 0x69, 0x63, 0x61, 0x74, 0x65, 0x20, 0x46, 0x6F, 0x72, 0x20, 0x54, |
| 50 | 0x65, 0x73, 0x74, 0x69, 0x6E, 0x67, 0x31, 0x2C, 0x30, 0x2A, 0x06, 0x03, |
| 51 | 0x55, 0x04, 0x0B, 0x0C, 0x23, 0x46, 0x61, 0x6B, 0x65, 0x20, 0x57, 0x65, |
| 52 | 0x62, 0x52, 0x54, 0x43, 0x20, 0x43, 0x65, 0x72, 0x74, 0x69, 0x66, 0x69, |
| 53 | 0x63, 0x61, 0x74, 0x65, 0x20, 0x46, 0x6F, 0x72, 0x20, 0x54, 0x65, 0x73, |
| 54 | 0x74, 0x69, 0x6E, 0x67, 0x31, 0x15, 0x30, 0x13, 0x06, 0x03, 0x55, 0x04, |
| 55 | 0x03, 0x0C, 0x0C, 0x2A, 0x2E, 0x77, 0x65, 0x62, 0x72, 0x74, 0x63, 0x2E, |
| 56 | 0x6F, 0x72, 0x67, 0x30, 0x1E, 0x17, 0x0D, 0x31, 0x38, 0x30, 0x34, 0x30, |
| 57 | 0x33, 0x32, 0x31, 0x35, 0x34, 0x30, 0x38, 0x5A, 0x17, 0x0D, 0x31, 0x39, |
| 58 | 0x30, 0x34, 0x30, 0x33, 0x32, 0x31, 0x35, 0x34, 0x30, 0x38, 0x5A, 0x30, |
| 59 | 0x81, 0x8D, 0x31, 0x0B, 0x30, 0x09, 0x06, 0x03, 0x55, 0x04, 0x06, 0x13, |
| 60 | 0x02, 0x55, 0x53, 0x31, 0x0B, 0x30, 0x09, 0x06, 0x03, 0x55, 0x04, 0x08, |
| 61 | 0x0C, 0x02, 0x57, 0x41, 0x31, 0x2C, 0x30, 0x2A, 0x06, 0x03, 0x55, 0x04, |
| 62 | 0x0A, 0x0C, 0x23, 0x46, 0x61, 0x6B, 0x65, 0x20, 0x57, 0x65, 0x62, 0x52, |
| 63 | 0x54, 0x43, 0x20, 0x43, 0x65, 0x72, 0x74, 0x69, 0x66, 0x69, 0x63, 0x61, |
| 64 | 0x74, 0x65, 0x20, 0x46, 0x6F, 0x72, 0x20, 0x54, 0x65, 0x73, 0x74, 0x69, |
| 65 | 0x6E, 0x67, 0x31, 0x2C, 0x30, 0x2A, 0x06, 0x03, 0x55, 0x04, 0x0B, 0x0C, |
| 66 | 0x23, 0x46, 0x61, 0x6B, 0x65, 0x20, 0x57, 0x65, 0x62, 0x52, 0x54, 0x43, |
| 67 | 0x20, 0x43, 0x65, 0x72, 0x74, 0x69, 0x66, 0x69, 0x63, 0x61, 0x74, 0x65, |
| 68 | 0x20, 0x46, 0x6F, 0x72, 0x20, 0x54, 0x65, 0x73, 0x74, 0x69, 0x6E, 0x67, |
| 69 | 0x31, 0x15, 0x30, 0x13, 0x06, 0x03, 0x55, 0x04, 0x03, 0x0C, 0x0C, 0x2A, |
| 70 | 0x2E, 0x77, 0x65, 0x62, 0x72, 0x74, 0x63, 0x2E, 0x6F, 0x72, 0x67, 0x30, |
| 71 | 0x5C, 0x30, 0x0D, 0x06, 0x09, 0x2A, 0x86, 0x48, 0x86, 0xF7, 0x0D, 0x01, |
| 72 | 0x01, 0x01, 0x05, 0x00, 0x03, 0x4B, 0x00, 0x30, 0x48, 0x02, 0x41, 0x00, |
| 73 | 0xAE, 0xAE, 0x85, 0x2A, 0x40, 0xD6, 0x99, 0x35, 0x09, 0x34, 0x1B, 0xC5, |
| 74 | 0xAC, 0x6C, 0x79, 0xC7, 0xC3, 0xDE, 0x1B, 0xCF, 0x17, 0x8D, 0x6B, 0x84, |
| 75 | 0xEC, 0x8B, 0x4E, 0x2B, 0xC1, 0x83, 0x43, 0xDF, 0x76, 0x0F, 0x5F, 0x5A, |
| 76 | 0xA9, 0x7D, 0x94, 0xC0, 0x54, 0x5C, 0xFF, 0xBC, 0x7C, 0x86, 0xDC, 0x9A, |
| 77 | 0xCE, 0xB9, 0xDF, 0xE6, 0x0B, 0xC4, 0x5B, 0x6E, 0x56, 0x9F, 0xBC, 0x40, |
| 78 | 0xF5, 0xA0, 0x52, 0xA7, 0x02, 0x03, 0x01, 0x00, 0x01, 0xA3, 0x53, 0x30, |
| 79 | 0x51, 0x30, 0x1D, 0x06, 0x03, 0x55, 0x1D, 0x0E, 0x04, 0x16, 0x04, 0x14, |
| 80 | 0xB7, 0xC0, 0x9A, 0xA7, 0x22, 0xAF, 0xF8, 0x7D, 0xFF, 0x68, 0xDB, 0x80, |
| 81 | 0xAC, 0x0A, 0xB6, 0xDC, 0x64, 0x89, 0xDB, 0xD4, 0x30, 0x1F, 0x06, 0x03, |
| 82 | 0x55, 0x1D, 0x23, 0x04, 0x18, 0x30, 0x16, 0x80, 0x14, 0xB7, 0xC0, 0x9A, |
| 83 | 0xA7, 0x22, 0xAF, 0xF8, 0x7D, 0xFF, 0x68, 0xDB, 0x80, 0xAC, 0x0A, 0xB6, |
| 84 | 0xDC, 0x64, 0x89, 0xDB, 0xD4, 0x30, 0x0F, 0x06, 0x03, 0x55, 0x1D, 0x13, |
| 85 | 0x01, 0x01, 0xFF, 0x04, 0x05, 0x30, 0x03, 0x01, 0x01, 0xFF, 0x30, 0x0D, |
| 86 | 0x06, 0x09, 0x2A, 0x86, 0x48, 0x86, 0xF7, 0x0D, 0x01, 0x01, 0x0B, 0x05, |
| 87 | 0x00, 0x03, 0x41, 0x00, 0x50, 0x6D, 0xCC, 0x62, 0xAE, 0xD1, 0x7C, 0x4D, |
| 88 | 0xEF, 0x90, 0x1E, 0x9B, 0x72, 0x73, 0xE0, 0x56, 0x66, 0x32, 0x6A, 0x78, |
| 89 | 0xE8, 0x0F, 0xAD, 0x21, 0x32, 0x54, 0xA5, 0xB3, 0xB8, 0x14, 0x54, 0xBC, |
| 90 | 0x50, 0xF7, 0x7F, 0x73, 0xD6, 0x44, 0x1E, 0x82, 0xD9, 0x4B, 0x49, 0x48, |
| 91 | 0x9E, 0x02, 0x8B, 0xFE, 0xC3, 0xFD, 0x5D, 0x15, 0x02, 0xE1, 0x78, 0xAC, |
| 92 | 0x9A, 0xAE, 0xFC, 0xC7, 0x48, 0xC6, 0x48, 0x6B}; |
| 93 | |
| 94 | // Simple testing helper method to create a fake SSL_SESSION with a testing |
| 95 | // peer connection set. |
| 96 | SSL_SESSION* CreateSSLSessionWithFakePeerCertificate(SSL_CTX* ssl_ctx) { |
| 97 | SSL_SESSION* ssl_session = SSL_SESSION_new(ssl_ctx); |
| 98 | const unsigned char* cert_buffer = kFakeSSLCertificate; |
| 99 | size_t cert_buffer_len = arraysize(kFakeSSLCertificate); |
| 100 | X509* ssl_peer_certificate = d2i_X509( |
| 101 | nullptr, &cert_buffer, checked_cast<long>(cert_buffer_len)); // NOLINT |
| 102 | EXPECT_NE(ssl_peer_certificate, nullptr); |
| 103 | #ifdef OPENSSL_IS_BORINGSSL |
| 104 | ssl_session->x509_peer = ssl_peer_certificate; |
| 105 | #else |
| 106 | ssl_session->peer = ssl_peer_certificate; |
| 107 | #endif |
| 108 | return ssl_session; |
| 109 | } |
| 110 | } // namespace |
| 111 | |
| 112 | TEST(OpenSSLCommonTest, VerifyPeerCertMatchesHostFailsOnNoPeerCertificate) { |
| 113 | SSL_CTX* ssl_ctx = SSL_CTX_new(DTLSv1_2_client_method()); |
| 114 | SSL* ssl = SSL_new(ssl_ctx); |
| 115 | |
| 116 | EXPECT_FALSE(openssl::VerifyPeerCertMatchesHost(ssl, "webrtc.org")); |
| 117 | |
| 118 | SSL_free(ssl); |
| 119 | SSL_CTX_free(ssl_ctx); |
| 120 | } |
| 121 | |
| 122 | TEST(OpenSSLCommonTest, VerifyPeerCertMatchesHostSucceedsOnCorrectHostname) { |
| 123 | SSL_CTX* ssl_ctx = SSL_CTX_new(DTLSv1_2_client_method()); |
| 124 | SSL* ssl = SSL_new(ssl_ctx); |
| 125 | SSL_SESSION* ssl_session = CreateSSLSessionWithFakePeerCertificate(ssl_ctx); |
| 126 | SSL_set_session(ssl, ssl_session); |
| 127 | |
| 128 | EXPECT_TRUE(openssl::VerifyPeerCertMatchesHost(ssl, "www.webrtc.org")); |
| 129 | EXPECT_TRUE(openssl::VerifyPeerCertMatchesHost(ssl, "alice.webrtc.org")); |
| 130 | EXPECT_TRUE(openssl::VerifyPeerCertMatchesHost(ssl, "bob.webrtc.org")); |
| 131 | |
| 132 | SSL_SESSION_free(ssl_session); |
| 133 | SSL_free(ssl); |
| 134 | SSL_CTX_free(ssl_ctx); |
| 135 | } |
| 136 | |
| 137 | TEST(OpenSSLCommonTest, VerifyPeerCertMatchesHostFailsOnInvalidHostname) { |
| 138 | SSL_CTX* ssl_ctx = SSL_CTX_new(DTLSv1_2_client_method()); |
| 139 | SSL* ssl = SSL_new(ssl_ctx); |
| 140 | SSL_SESSION* ssl_session = CreateSSLSessionWithFakePeerCertificate(ssl_ctx); |
| 141 | SSL_set_session(ssl, ssl_session); |
| 142 | |
| 143 | EXPECT_FALSE(openssl::VerifyPeerCertMatchesHost(ssl, "a.b.webrtc.org")); |
| 144 | EXPECT_FALSE(openssl::VerifyPeerCertMatchesHost(ssl, "notwebrtc.org")); |
| 145 | EXPECT_FALSE(openssl::VerifyPeerCertMatchesHost(ssl, "webrtc.org")); |
| 146 | |
| 147 | SSL_SESSION_free(ssl_session); |
| 148 | SSL_free(ssl); |
| 149 | SSL_CTX_free(ssl_ctx); |
| 150 | } |
| 151 | |
| 152 | } // namespace rtc |