/* $OpenLDAP$ */
/*
- * Copyright 1998-2000 The OpenLDAP Foundation, All Rights Reserved.
+ * Copyright 1998-2002 The OpenLDAP Foundation, All Rights Reserved.
* COPYING RESTRICTIONS APPLY, see COPYRIGHT file
*
* tls.c - Handle tls/ssl using SSLeay or OpenSSL.
#include <openssl/x509v3.h>
#include <openssl/err.h>
#include <openssl/rand.h>
+#include <openssl/safestack.h>
#elif defined( HAVE_SSL_H )
#include <ssl.h>
#endif
static char *tls_opt_randfile = NULL;
#define HAS_TLS( sb ) ber_sockbuf_ctrl( sb, LBER_SB_OPT_HAS_IO, \
- (void *)&ldap_pvt_sockbuf_io_tls )
+ (void *)&sb_tls_sbio )
static void tls_report_error( void );
}
#endif /* LDAP_R_COMPILE */
+/*
+ * Tear down the TLS subsystem. Should only be called once.
+ */
+void
+ldap_pvt_tls_destroy( void )
+{
+ SSL_CTX_free(tls_def_ctx);
+ tls_def_ctx = NULL;
+
+ EVP_cleanup();
+ ERR_free_strings();
+
+ if ( tls_opt_certfile ) {
+ LDAP_FREE( tls_opt_certfile );
+ tls_opt_certfile = NULL;
+ }
+ if ( tls_opt_keyfile ) {
+ LDAP_FREE( tls_opt_keyfile );
+ tls_opt_keyfile = NULL;
+ }
+ if ( tls_opt_cacertfile ) {
+ LDAP_FREE( tls_opt_cacertfile );
+ tls_opt_cacertfile = NULL;
+ }
+ if ( tls_opt_cacertdir ) {
+ LDAP_FREE( tls_opt_cacertdir );
+ tls_opt_cacertdir = NULL;
+ }
+ if ( tls_opt_ciphersuite ) {
+ LDAP_FREE( tls_opt_ciphersuite );
+ tls_opt_ciphersuite = NULL;
+ }
+ if ( tls_opt_randfile ) {
+ LDAP_FREE( tls_opt_randfile );
+ tls_opt_randfile = NULL;
+ }
+}
+
/*
* Initialize TLS subsystem. Should be called only once.
*/
}
if ( tls_opt_ciphersuite &&
!SSL_CTX_set_cipher_list( tls_def_ctx,
- tls_opt_ciphersuite ) ) {
+ tls_opt_ciphersuite ) )
+ {
Debug( LDAP_DEBUG_ANY,
"TLS: could not set cipher list %s.\n",
tls_opt_ciphersuite, 0, 0 );
tls_opt_cacertdir )
|| !SSL_CTX_set_default_verify_paths( tls_def_ctx ) )
{
- Debug( LDAP_DEBUG_ANY,
- "TLS: could not load verify locations (file:`%s',dir:`%s').\n",
- tls_opt_cacertfile,tls_opt_cacertdir,0);
+ Debug( LDAP_DEBUG_ANY, "TLS: "
+ "could not load verify locations (file:`%s',dir:`%s').\n",
+ tls_opt_cacertfile ? tls_opt_cacertfile : "",
+ tls_opt_cacertdir ? tls_opt_cacertdir : "",
+ 0 );
tls_report_error();
goto error_exit;
}
calist = get_ca_list( tls_opt_cacertfile, tls_opt_cacertdir );
if ( !calist ) {
- Debug( LDAP_DEBUG_ANY,
- "TLS: could not load client CA list (file:`%s',dir:`%s').\n",
- tls_opt_cacertfile,tls_opt_cacertdir,0);
+ Debug( LDAP_DEBUG_ANY, "TLS: "
+ "could not load client CA list (file:`%s',dir:`%s').\n",
+ tls_opt_cacertfile ? tls_opt_cacertfile : "",
+ tls_opt_cacertdir ? tls_opt_cacertdir : "",
+ 0 );
tls_report_error();
goto error_exit;
}
if ( tls_opt_keyfile &&
!SSL_CTX_use_PrivateKey_file( tls_def_ctx,
tls_opt_keyfile,
- SSL_FILETYPE_PEM ) ) {
+ SSL_FILETYPE_PEM ) )
+ {
Debug( LDAP_DEBUG_ANY,
"TLS: could not use key file `%s'.\n",
tls_opt_keyfile,0,0);
if ( tls_opt_certfile &&
!SSL_CTX_use_certificate_file( tls_def_ctx,
tls_opt_certfile,
- SSL_FILETYPE_PEM ) ) {
+ SSL_FILETYPE_PEM ) )
+ {
Debug( LDAP_DEBUG_ANY,
"TLS: could not use certificate `%s'.\n",
tls_opt_certfile,0,0);
goto error_exit;
}
if ( ( tls_opt_certfile || tls_opt_keyfile ) &&
- !SSL_CTX_check_private_key( tls_def_ctx ) ) {
+ !SSL_CTX_check_private_key( tls_def_ctx ) )
+ {
Debug( LDAP_DEBUG_ANY,
"TLS: private key mismatch.\n",
0,0,0);
Sockbuf_IO_Desc *sbiod;
};
-extern BIO_METHOD ldap_pvt_sb_bio_method;
+static BIO_METHOD sb_tls_bio_method;
static int
sb_tls_setup( Sockbuf_IO_Desc *sbiod, void *arg )
p->ssl = (SSL *)arg;
p->sbiod = sbiod;
- bio = BIO_new( &ldap_pvt_sb_bio_method );
+ bio = BIO_new( &sb_tls_bio_method );
bio->ptr = (void *)p;
SSL_set_bio( p->ssl, bio, bio );
sbiod->sbiod_pvt = p;
return ret;
}
-Sockbuf_IO ldap_pvt_sockbuf_io_tls =
+static Sockbuf_IO sb_tls_sbio =
{
sb_tls_setup, /* sbi_setup */
sb_tls_remove, /* sbi_remove */
}
static int
-sb_tls_bio_write( BIO *b, char *buf, int len )
+sb_tls_bio_write( BIO *b, const char *buf, int len )
{
struct tls_data *p;
int ret;
if ( p == NULL || p->sbiod == NULL )
return 0;
- ret = LBER_SBIOD_WRITE_NEXT( p->sbiod, buf, len );
+ ret = LBER_SBIOD_WRITE_NEXT( p->sbiod, (char *)buf, len );
BIO_clear_retry_flags( b );
if ( ret < 0 && errno == EWOULDBLOCK )
}
static long
-sb_tls_bio_ctrl( BIO *b, int cmd, long num, char *ptr )
+sb_tls_bio_ctrl( BIO *b, int cmd, long num, void *ptr )
{
if ( cmd == BIO_CTRL_FLUSH ) {
/* The OpenSSL library needs this */
}
static int
-sb_tls_bio_puts( BIO *b, char *str )
+sb_tls_bio_puts( BIO *b, const char *str )
{
return sb_tls_bio_write( b, str, strlen( str ) );
}
-BIO_METHOD ldap_pvt_sb_bio_method =
+static BIO_METHOD sb_tls_bio_method =
{
( 100 | 0x400 ), /* it's a source/sink BIO */
"sockbuf glue",
ber_sockbuf_add_io( sb, &ber_sockbuf_io_debug,
LBER_SBIOD_LEVEL_TRANSPORT, (void *)"tls_" );
#endif
- ber_sockbuf_add_io( sb, &ldap_pvt_sockbuf_io_tls,
+ ber_sockbuf_add_io( sb, &sb_tls_sbio,
LBER_SBIOD_LEVEL_TRANSPORT, (void *)ssl );
if( ctx == NULL ) {
ld->ld_error = LDAP_STRDUP(ERR_error_string(err, buf));
}
Debug( LDAP_DEBUG_ANY,"TLS: can't connect.\n",0,0,0);
- ber_sockbuf_remove_io( sb, &ldap_pvt_sockbuf_io_tls,
+ ber_sockbuf_remove_io( sb, &sb_tls_sbio,
LBER_SBIOD_LEVEL_TRANSPORT );
#ifdef LDAP_DEBUG
ber_sockbuf_remove_io( sb, &ber_sockbuf_io_debug,
ber_sockbuf_add_io( sb, &ber_sockbuf_io_debug,
LBER_SBIOD_LEVEL_TRANSPORT, (void *)"tls_" );
#endif
- ber_sockbuf_add_io( sb, &ldap_pvt_sockbuf_io_tls,
+ ber_sockbuf_add_io( sb, &sb_tls_sbio,
LBER_SBIOD_LEVEL_TRANSPORT, (void *)ssl );
}
return 1;
Debug( LDAP_DEBUG_ANY,"TLS: can't accept.\n",0,0,0 );
tls_report_error();
- ber_sockbuf_remove_io( sb, &ldap_pvt_sockbuf_io_tls,
+ ber_sockbuf_remove_io( sb, &sb_tls_sbio,
LBER_SBIOD_LEVEL_TRANSPORT );
#ifdef LDAP_DEBUG
ber_sockbuf_remove_io( sb, &ber_sockbuf_io_debug,
return p;
}
+int
+ldap_pvt_tls_check_hostname( void *s, const char *name_in )
+{
+ int i, ret = LDAP_LOCAL_ERROR;
+ X509 *x;
+ const char *name;
+
+ if( ldap_int_hostname &&
+ ( !name_in || !strcasecmp( name_in, "localhost" ) ) )
+ {
+ name = ldap_int_hostname;
+ } else {
+ name = name_in;
+ }
+
+ x = SSL_get_peer_certificate((SSL *)s);
+ if (!x)
+ {
+ Debug( LDAP_DEBUG_ANY,
+ "TLS: unable to get peer certificate.\n",
+ 0, 0, 0 );
+ return ret;
+ }
+
+ i = X509_get_ext_by_NID(x, NID_subject_alt_name, -1);
+ if (i >= 0)
+ {
+ X509_EXTENSION *ex;
+ STACK_OF(GENERAL_NAME) *alt;
+
+ ex = X509_get_ext(x, i);
+ alt = X509V3_EXT_d2i(ex);
+ if (alt)
+ {
+ int n, len1, len2;
+ char *domain;
+ GENERAL_NAME *gn;
+ X509V3_EXT_METHOD *method;
+
+ len1 = strlen(name);
+ n = sk_GENERAL_NAME_num(alt);
+ domain = strchr(name, '.');
+ if (domain)
+ len2 = len1 - (domain-name);
+ for (i=0; i<n; i++)
+ {
+ gn = sk_GENERAL_NAME_value(alt, i);
+ if (gn->type == GEN_DNS)
+ {
+ char *sn = ASN1_STRING_data(gn->d.ia5);
+ int sl = ASN1_STRING_length(gn->d.ia5);
+
+ /* Is this an exact match? */
+ if ((len1 == sl) && !strncasecmp(name, sn, len1))
+ break;
+
+ /* Is this a wildcard match? */
+ if ((*sn == '*') && domain && (len2 == sl-1) &&
+ !strncasecmp(domain, sn+1, len2))
+ break;
+ }
+ }
+ method = X509V3_EXT_get(ex);
+ method->ext_free(alt);
+ if (i < n) /* Found a match */
+ ret = LDAP_SUCCESS;
+ }
+ }
+
+ if (ret != LDAP_SUCCESS)
+ {
+ X509_NAME *xn;
+ char buf[2048];
+
+ xn = X509_get_subject_name(x);
+
+ if (X509_NAME_get_text_by_NID(xn, NID_commonName, buf, sizeof(buf))
+ == -1)
+ {
+ Debug( LDAP_DEBUG_ANY,
+ "TLS: unable to get common name from peer certificate.\n",
+ 0, 0, 0 );
+ } else if (strcasecmp(name, buf))
+ {
+ Debug( LDAP_DEBUG_ANY, "TLS: hostname (%s) does not match "
+ "common name in certificate (%s).\n",
+ name, buf, 0 );
+ ret = LDAP_CONNECT_ERROR;
+ } else
+ {
+ ret = LDAP_SUCCESS;
+ }
+ }
+ X509_free(x);
+ return ret;
+}
+
const char *
ldap_pvt_tls_get_peer_issuer( void *s )
{
case LDAP_OPT_X_TLS_CERTFILE:
case LDAP_OPT_X_TLS_KEYFILE:
case LDAP_OPT_X_TLS_RANDOM_FILE:
- return ldap_pvt_tls_set_option( NULL, option, (void *) arg );
+ return ldap_pvt_tls_set_option( ld, option, (void *) arg );
case LDAP_OPT_X_TLS_REQUIRE_CERT:
i = ( ( strcasecmp( arg, "on" ) == 0 ) ||
( strcasecmp( arg, "yes" ) == 0) ||
( strcasecmp( arg, "true" ) == 0 ) );
- return ldap_pvt_tls_set_option( NULL, option, (void *) &i );
+ return ldap_pvt_tls_set_option( ld, option, (void *) &i );
case LDAP_OPT_X_TLS:
i = -1;
*(int *)arg = tls_opt_require_cert;
break;
case LDAP_OPT_X_TLS_RANDOM_FILE:
- *(char **)arg = tls_opt_randfile;
+ *(char **)arg = tls_opt_randfile ?
+ LDAP_STRDUP( tls_opt_randfile ) : NULL;
break;
default:
return -1;
ldap_int_tls_start ( LDAP *ld, LDAPConn *conn, LDAPURLDesc *srv )
{
Sockbuf *sb = conn->lconn_sb;
- void *ctx = ld->ld_defconn->lconn_tls_ctx;
char *host;
- char *peer_cert_cn;
void *ssl;
if( srv ) {
host = conn->lconn_server->lud_host;
}
+ /* avoid NULL host */
+ if( host == NULL ) {
+ host = "localhost";
+ }
+
(void) ldap_pvt_tls_init();
/*
* Fortunately, the lib uses blocking io...
*/
if ( ldap_int_tls_connect( ld, conn ) < 0 ) {
- return LDAP_CONNECT_ERROR;
+ ld->ld_errno = LDAP_CONNECT_ERROR;
+ return (ld->ld_errno);
}
ssl = (void *) ldap_pvt_tls_sb_ctx( sb );
assert( ssl != NULL );
/*
- * compare host with name in certificate
+ * compare host with name(s) in certificate
*/
-
- peer_cert_cn = ldap_pvt_tls_get_peer_hostname( ssl );
- if ( !peer_cert_cn ) {
- /* could not get hostname from peer certificate */
- Debug( LDAP_DEBUG_ANY,
- "TLS: unable to get common name from peer certificate.\n",
- 0, 0, 0 );
- return LDAP_LOCAL_ERROR;
+ ld->ld_errno = ldap_pvt_tls_check_hostname( ssl, host );
+ if (ld->ld_errno != LDAP_SUCCESS) {
+ return ld->ld_errno;
}
- if ( strcasecmp( host, peer_cert_cn ) != 0 ) {
- Debug( LDAP_DEBUG_ANY, "TLS: hostname (%s) does not match "
- "common name in certificate (%s).\n",
- host, peer_cert_cn, 0 );
- LDAP_FREE( peer_cert_cn );
- return LDAP_CONNECT_ERROR;
- }
-
- LDAP_FREE( peer_cert_cn );
-
/*
* set SASL properties to TLS ssf and authid
*/
ssf = ldap_pvt_tls_get_strength( ssl );
authid = ldap_pvt_tls_get_peer( ssl );
- (void) ldap_int_sasl_external( ld, authid, ssf );
+ (void) ldap_int_sasl_external( ld, conn, authid, ssf );
}
return LDAP_SUCCESS;
/* XXYYZ: this initiates operation only on default connection! */
- if ( ldap_pvt_tls_inplace( ld->ld_sb ) != 0 ) {
+ if ( ld->ld_sb != NULL && ldap_pvt_tls_inplace( ld->ld_sb ) != 0 ) {
return LDAP_LOCAL_ERROR;
}