mirror of
https://gitlab.com/openconnect/ocserv.git
synced 2026-10-12 01:26:48 +08:00
use nettle's base64 implementation
This commit is contained in:
@@ -44,6 +44,7 @@ AC_CHECK_MEMBERS([struct iphdr.ihl], [],
|
||||
AC_CHECK_SIZEOF([unsigned long])
|
||||
AC_C_BIGENDIAN
|
||||
|
||||
PKG_CHECK_MODULES([LIBNETTLE], [nettle >= 2.7])
|
||||
PKG_CHECK_MODULES([LIBGNUTLS], [gnutls >= 3.1.10])
|
||||
AC_CHECK_LIB(gnutls, gnutls_pkcs11_reinit, [
|
||||
AC_DEFINE([HAVE_PKCS11], [], [PKCS11 detected in gnutls])
|
||||
|
||||
+2
-2
@@ -77,7 +77,7 @@ ocserv_SOURCES = main.c main-auth.c worker-vpn.c worker-auth.c tlslib.c \
|
||||
worker-bandwidth.c worker-bandwidth.h ctl.h main-ctl.h \
|
||||
vasprintf.c vasprintf.h worker-proxyproto.c \
|
||||
proc-search.c proc-search.h http-heads.h ip-util.c ip-util.h \
|
||||
main-ban.c main-ban.h common-config.h \
|
||||
main-ban.c main-ban.h common-config.h base64-helper.c base64-helper.h \
|
||||
str.c str.h gettime.h $(CCAN_SOURCES) $(HTTP_PARSER_SOURCES) \
|
||||
$(PROTOBUF_SOURCES) sec-mod-acct.h setproctitle.c setproctitle.h
|
||||
|
||||
@@ -96,7 +96,7 @@ ocserv_LDADD += $(LIBGNUTLS_LIBS) $(PAM_LIBS) $(LIBUTIL) \
|
||||
$(LIBSECCOMP) $(LIBWRAP) $(LIBCRYPT) $(NEEDED_HTTP_PARSER_LIBS) \
|
||||
$(LIBPROTOBUF_C_LIBS) $(LIBSYSTEMD) $(LIBTALLOC_LIBS) \
|
||||
$(RADCLI_LIBS) $(LIBLZ4_LIBS) $(LIBKRB5_LIBS) \
|
||||
$(LIBTASN1_LIBS) $(LIBOATH_LIBS)
|
||||
$(LIBTASN1_LIBS) $(LIBOATH_LIBS) $(LIBNETTLE_LIBS)
|
||||
|
||||
|
||||
if PCL
|
||||
|
||||
+9
-7
@@ -35,7 +35,7 @@
|
||||
#include <gssapi/gssapi.h>
|
||||
#include <gssapi/gssapi_ext.h>
|
||||
#include <gssapi/gssapi_krb5.h>
|
||||
#include <gl/base64.h>
|
||||
#include <base64-helper.h>
|
||||
#include "common-config.h"
|
||||
|
||||
static gss_cred_id_t glob_creds;
|
||||
@@ -229,7 +229,7 @@ static int gssapi_auth_init(void **ctx, void *pool, const char *spnego, const ch
|
||||
if (pctx == NULL)
|
||||
return ERR_AUTH_FAIL;
|
||||
|
||||
ret = base64_decode_alloc(spnego, strlen(spnego), &raw, &raw_len);
|
||||
ret = oc_base64_decode_alloc(pctx, spnego, strlen(spnego), &raw, &raw_len);
|
||||
if (ret == 0) {
|
||||
syslog(LOG_ERR, "gssapi: error in base64 decoding %s", __func__);
|
||||
return ERR_AUTH_FAIL;
|
||||
@@ -240,7 +240,7 @@ static int gssapi_auth_init(void **ctx, void *pool, const char *spnego, const ch
|
||||
ret = gss_accept_sec_context(&minor, &pctx->gssctx, glob_creds, &buf,
|
||||
GSS_C_NO_CHANNEL_BINDINGS, &client, &mech_type, &pctx->msg,
|
||||
&flags, &time, &pctx->delegated_creds);
|
||||
free(raw);
|
||||
talloc_free(raw);
|
||||
|
||||
if (ret == GSS_S_CONTINUE_NEEDED) {
|
||||
gss_release_name(&minor, &client);
|
||||
@@ -291,7 +291,7 @@ static int gssapi_auth_pass(void *ctx, const char *spnego, unsigned spnego_len)
|
||||
int ret;
|
||||
|
||||
/* nothing to be done */
|
||||
ret = base64_decode_alloc(spnego, spnego_len, &raw, &raw_len);
|
||||
ret = oc_base64_decode_alloc(pctx, spnego, spnego_len, &raw, &raw_len);
|
||||
if (ret == 0) {
|
||||
syslog(LOG_ERR, "gssapi: error in base64 decoding %s", __func__);
|
||||
return ERR_AUTH_FAIL;
|
||||
@@ -302,7 +302,7 @@ static int gssapi_auth_pass(void *ctx, const char *spnego, unsigned spnego_len)
|
||||
ret = gss_accept_sec_context(&minor, &pctx->gssctx, glob_creds, &buf,
|
||||
GSS_C_NO_CHANNEL_BINDINGS, &client, &mech_type, &pctx->msg,
|
||||
&flags, &time, &pctx->delegated_creds);
|
||||
free(raw);
|
||||
talloc_free(raw);
|
||||
|
||||
if (ret == GSS_S_CONTINUE_NEEDED) {
|
||||
gss_release_name(&minor, &client);
|
||||
@@ -329,10 +329,12 @@ static int gssapi_auth_msg(void *ctx, void *pool, passwd_msg_st *pst)
|
||||
|
||||
/* our msg is our SPNEGO reply */
|
||||
if (pctx->msg.value != NULL) {
|
||||
length = BASE64_LENGTH(pctx->msg.length)+1;
|
||||
length = BASE64_ENCODE_RAW_LENGTH(pctx->msg.length)+1;
|
||||
pst->msg_str = talloc_size(pool, length);
|
||||
|
||||
base64_encode((char *)pctx->msg.value, pctx->msg.length, pst->msg_str, length);
|
||||
oc_base64_encode(pctx->msg.value, pctx->msg.length,
|
||||
pst->msg_str, length);
|
||||
|
||||
gss_release_buffer(&min, &pctx->msg);
|
||||
pctx->msg.value = NULL;
|
||||
}
|
||||
|
||||
@@ -22,7 +22,6 @@
|
||||
#define RADIUS_H
|
||||
|
||||
#include <sec-mod-auth.h>
|
||||
#include <base64.h>
|
||||
|
||||
struct radius_ctx_st {
|
||||
char username[MAX_USERNAME_SIZE*2];
|
||||
|
||||
@@ -0,0 +1,76 @@
|
||||
/*
|
||||
* Copyright (C) 2015 Red Hat
|
||||
*
|
||||
* This file is part of ocserv.
|
||||
*
|
||||
* ocserv is free software: you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by
|
||||
* the Free Software Foundation, either version 2 of the License, or
|
||||
* (at your option) any later version.
|
||||
*
|
||||
* ocserv is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||
* General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License
|
||||
* along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
*/
|
||||
|
||||
#include <config.h>
|
||||
#include <nettle/base64.h>
|
||||
#include <talloc.h>
|
||||
#include "base64-helper.h"
|
||||
|
||||
void oc_base64_encode (const char *restrict in, size_t inlen,
|
||||
char *restrict out, size_t outlen)
|
||||
{
|
||||
unsigned raw = BASE64_ENCODE_RAW_LENGTH(inlen);
|
||||
if (outlen < raw+1) {
|
||||
snprintf(out, outlen, "(too long data)");
|
||||
return;
|
||||
}
|
||||
base64_encode_raw((uint8_t*)out, inlen, (uint8_t*)in);
|
||||
out[raw] = 0;
|
||||
return;
|
||||
}
|
||||
|
||||
int
|
||||
oc_base64_decode(const uint8_t *src, unsigned src_length,
|
||||
uint8_t *dst, size_t *dst_length)
|
||||
{
|
||||
struct base64_decode_ctx ctx;
|
||||
int ret;
|
||||
|
||||
base64_decode_init(&ctx);
|
||||
|
||||
ret = base64_decode_update(&ctx, dst_length, dst, src_length, src);
|
||||
if (ret == 0)
|
||||
return 0;
|
||||
|
||||
return base64_decode_final(&ctx);
|
||||
}
|
||||
|
||||
int oc_base64_decode_alloc(void *pool, const char *in, size_t inlen,
|
||||
char **out, size_t *outlen)
|
||||
{
|
||||
int len, ret;
|
||||
void *tmp;
|
||||
|
||||
len = BASE64_DECODE_LENGTH(inlen);
|
||||
|
||||
tmp = talloc_size(pool, len);
|
||||
if (tmp == NULL)
|
||||
return 0;
|
||||
|
||||
*outlen = len;
|
||||
ret = oc_base64_decode((void*)in, inlen, tmp, outlen);
|
||||
if (ret == 0) {
|
||||
talloc_free(tmp);
|
||||
return 0;
|
||||
}
|
||||
|
||||
*out = tmp;
|
||||
|
||||
return 1;
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
/*
|
||||
* Copyright (C) 2015 Red Hat
|
||||
*
|
||||
* Author: Nikos Mavrogiannopoulos
|
||||
*
|
||||
* This file is part of ocserv.
|
||||
*
|
||||
* The GnuTLS is free software; you can redistribute it and/or
|
||||
* modify it under the terms of the GNU Lesser General Public License
|
||||
* as published by the Free Software Foundation; either version 2.1 of
|
||||
* the License, or (at your option) any later version.
|
||||
*
|
||||
* This library is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||
* Lesser General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU Lesser General Public License
|
||||
* along with this program. If not, see <http://www.gnu.org/licenses/>
|
||||
*/
|
||||
#ifndef BASE64_HELPER_H
|
||||
# define BASE64_HELPER_H
|
||||
|
||||
#include <nettle/base64.h>
|
||||
|
||||
/* Prototypes compatible with the gnulib's */
|
||||
|
||||
int
|
||||
oc_base64_decode(const uint8_t *src, unsigned src_length,
|
||||
uint8_t *dst, size_t *dst_length);
|
||||
|
||||
int oc_base64_decode_alloc(void *pool, const char *in, size_t inlen,
|
||||
char **out, size_t *outlen);
|
||||
|
||||
void oc_base64_encode (const char *restrict in, size_t inlen,
|
||||
char *restrict out, size_t outlen);
|
||||
|
||||
#endif
|
||||
@@ -23,7 +23,7 @@
|
||||
#include <string.h>
|
||||
#include <stdio.h>
|
||||
#include <stdarg.h>
|
||||
#include <base64.h>
|
||||
#include <base64-helper.h>
|
||||
|
||||
#include <vpn.h>
|
||||
#include <worker.h>
|
||||
@@ -190,7 +190,7 @@ void mslog_hex(const main_server_st * s, const struct proc_st* proc,
|
||||
return;
|
||||
|
||||
if (b64) {
|
||||
base64_encode((char*)bin, bin_size, (char*)buf, sizeof(buf));
|
||||
oc_base64_encode((char*)bin, bin_size, (char*)buf, sizeof(buf));
|
||||
} else {
|
||||
buf_size = sizeof(buf);
|
||||
ret = gnutls_hex_encode(&data, buf, &buf_size);
|
||||
@@ -215,7 +215,7 @@ void oclog_hex(const worker_st* ws, int priority,
|
||||
return;
|
||||
|
||||
if (b64) {
|
||||
base64_encode((char*)bin, bin_size, (char*)buf, sizeof(buf));
|
||||
oc_base64_encode((char*)bin, bin_size, (char*)buf, sizeof(buf));
|
||||
} else {
|
||||
buf_size = sizeof(buf);
|
||||
ret = gnutls_hex_encode(&data, buf, &buf_size);
|
||||
@@ -240,7 +240,7 @@ void seclog_hex(const struct sec_mod_st* sec, int priority,
|
||||
return;
|
||||
|
||||
if (b64) {
|
||||
base64_encode((char*)bin, bin_size, (char*)buf, sizeof(buf));
|
||||
oc_base64_encode((char*)bin, bin_size, (char*)buf, sizeof(buf));
|
||||
} else {
|
||||
buf_size = sizeof(buf);
|
||||
ret = gnutls_hex_encode(&data, buf, &buf_size);
|
||||
|
||||
+7
-6
@@ -49,6 +49,7 @@
|
||||
#include <auth/pam.h>
|
||||
#include <sec-mod.h>
|
||||
#include <vpn.h>
|
||||
#include <base64-helper.h>
|
||||
#include <sec-mod-sup-config.h>
|
||||
#include <sec-mod-acct.h>
|
||||
|
||||
@@ -416,8 +417,8 @@ int handle_sec_auth_session_open(sec_mod_st *sec, int fd, const SecAuthSessionMs
|
||||
|
||||
e = find_client_entry(sec, req->sid.data);
|
||||
if (e == NULL) {
|
||||
char tmp[BASE64_LENGTH(SID_SIZE) + 1];
|
||||
base64_encode((char *)req->sid.data, req->sid.len, (char *)tmp, sizeof(tmp));
|
||||
char tmp[BASE64_ENCODE_RAW_LENGTH(SID_SIZE) + 1];
|
||||
oc_base64_encode((char *)req->sid.data, req->sid.len, (char *)tmp, sizeof(tmp));
|
||||
seclog(sec, LOG_INFO, "session open but with non-existing SID: %s!", tmp);
|
||||
return send_failed_session_open_reply(sec, fd);
|
||||
}
|
||||
@@ -503,8 +504,8 @@ int handle_sec_auth_session_close(sec_mod_st *sec, int fd, const SecAuthSessionM
|
||||
|
||||
e = find_client_entry(sec, req->sid.data);
|
||||
if (e == NULL) {
|
||||
char tmp[BASE64_LENGTH(SID_SIZE) + 1];
|
||||
base64_encode((char *)req->sid.data, req->sid.len, (char *)tmp, sizeof(tmp));
|
||||
char tmp[BASE64_ENCODE_RAW_LENGTH(SID_SIZE) + 1];
|
||||
oc_base64_encode((char *)req->sid.data, req->sid.len, (char *)tmp, sizeof(tmp));
|
||||
seclog(sec, LOG_INFO, "session close but with non-existing SID: %s", tmp);
|
||||
return send_msg(e, fd, SM_CMD_AUTH_CLI_STATS, &rep,
|
||||
(pack_size_func) cli_stats_msg__get_packed_size,
|
||||
@@ -596,8 +597,8 @@ int handle_sec_auth_stats_cmd(sec_mod_st * sec, const CliStatsMsg * req)
|
||||
|
||||
e = find_client_entry(sec, req->sid.data);
|
||||
if (e == NULL) {
|
||||
char tmp[BASE64_LENGTH(SID_SIZE) + 1];
|
||||
base64_encode((char *)req->sid.data, req->sid.len, (char *)tmp, sizeof(tmp));
|
||||
char tmp[BASE64_ENCODE_RAW_LENGTH(SID_SIZE) + 1];
|
||||
oc_base64_encode((char *)req->sid.data, req->sid.len, (char *)tmp, sizeof(tmp));
|
||||
seclog(sec, LOG_INFO, "session stats but with non-existing SID: %s", tmp);
|
||||
return -1;
|
||||
}
|
||||
|
||||
+2
-1
@@ -37,6 +37,7 @@
|
||||
#include <common.h>
|
||||
#include <syslog.h>
|
||||
#include <vpn.h>
|
||||
#include <base64-helper.h>
|
||||
#include <tlslib.h>
|
||||
#include <sec-mod.h>
|
||||
#include <ccan/hash/hash.h>
|
||||
@@ -115,7 +116,7 @@ client_entry_st *new_client_entry(sec_mod_st *sec, const char *ip, unsigned pid)
|
||||
goto fail;
|
||||
}
|
||||
|
||||
base64_encode((char *)e->sid, SID_SIZE, (char *)e->auth_info.psid, sizeof(e->auth_info.psid));
|
||||
oc_base64_encode((char *)e->sid, SID_SIZE, (char *)e->auth_info.psid, sizeof(e->auth_info.psid));
|
||||
e->time = time(0);
|
||||
|
||||
if (htable_add(db, rehash(e, NULL), e) == 0) {
|
||||
|
||||
+2
-2
@@ -24,7 +24,7 @@
|
||||
#include <cookies.h>
|
||||
#include <gnutls/abstract.h>
|
||||
#include <ccan/htable/htable.h>
|
||||
#include <base64.h>
|
||||
#include <nettle/base64.h>
|
||||
|
||||
#define SESSION_STR "(session: %.5s)"
|
||||
|
||||
@@ -52,7 +52,7 @@ typedef struct stats_st {
|
||||
typedef struct common_auth_info_st {
|
||||
char username[MAX_USERNAME_SIZE*2];
|
||||
char groupname[MAX_GROUPNAME_SIZE]; /* the owner's group */
|
||||
char psid[BASE64_LENGTH(SID_SIZE) + 1]; /* printable */
|
||||
char psid[BASE64_ENCODE_RAW_LENGTH(SID_SIZE) + 1]; /* printable */
|
||||
char remote_ip[MAX_IP_STR];
|
||||
char our_ip[MAX_IP_STR];
|
||||
char ipv4[MAX_IP_STR];
|
||||
|
||||
+8
-8
@@ -34,7 +34,7 @@
|
||||
#include <unistd.h>
|
||||
#include <limits.h>
|
||||
#include <ipc.pb-c.h>
|
||||
#include <base64.h>
|
||||
#include <base64-helper.h>
|
||||
|
||||
#include <vpn.h>
|
||||
#include "html.h"
|
||||
@@ -169,7 +169,7 @@ static int append_group_str(worker_st * ws, str_st *str, const char *group)
|
||||
int get_auth_handler2(worker_st * ws, unsigned http_ver, const char *pmsg, unsigned pcounter)
|
||||
{
|
||||
int ret;
|
||||
char context[BASE64_LENGTH(SID_SIZE) + 1];
|
||||
char context[BASE64_ENCODE_RAW_LENGTH(SID_SIZE) + 1];
|
||||
unsigned int i, j;
|
||||
str_st str;
|
||||
const char *login_msg_start;
|
||||
@@ -200,7 +200,7 @@ int get_auth_handler2(worker_st * ws, unsigned http_ver, const char *pmsg, unsig
|
||||
|
||||
|
||||
if (ws->sid_set != 0) {
|
||||
base64_encode((char *)ws->sid, sizeof(ws->sid), (char *)context,
|
||||
oc_base64_encode((char *)ws->sid, sizeof(ws->sid), (char *)context,
|
||||
sizeof(context));
|
||||
|
||||
ret =
|
||||
@@ -916,7 +916,7 @@ int auth_cookie(worker_st * ws, void *cookie, size_t cookie_size)
|
||||
int post_common_handler(worker_st * ws, unsigned http_ver, const char *imsg)
|
||||
{
|
||||
int ret, size;
|
||||
char str_cookie[BASE64_LENGTH(ws->cookie_size)+1];
|
||||
char str_cookie[BASE64_ENCODE_RAW_LENGTH(ws->cookie_size)+1];
|
||||
size_t str_cookie_size = sizeof(str_cookie);
|
||||
char msg[MAX_BANNER_SIZE + 32];
|
||||
const char *success_msg_head;
|
||||
@@ -936,7 +936,7 @@ int post_common_handler(worker_st * ws, unsigned http_ver, const char *imsg)
|
||||
success_msg_foot_size = sizeof(oc_success_msg_foot)-1;
|
||||
}
|
||||
|
||||
base64_encode((char *)ws->cookie, ws->cookie_size,
|
||||
oc_base64_encode((char *)ws->cookie, ws->cookie_size,
|
||||
(char *)str_cookie, str_cookie_size);
|
||||
|
||||
/* reply */
|
||||
@@ -985,10 +985,10 @@ int post_common_handler(worker_st * ws, unsigned http_ver, const char *imsg)
|
||||
return -1;
|
||||
|
||||
if (ws->sid_set != 0) {
|
||||
char context[BASE64_LENGTH(SID_SIZE) + 1];
|
||||
char context[BASE64_ENCODE_RAW_LENGTH(SID_SIZE) + 1];
|
||||
|
||||
base64_encode((char *)ws->sid, sizeof(ws->sid), (char *)context,
|
||||
sizeof(context));
|
||||
oc_base64_encode((char *)ws->sid, sizeof(ws->sid), (char *)context,
|
||||
sizeof(context));
|
||||
|
||||
ret =
|
||||
cstp_printf(ws,
|
||||
|
||||
+9
-8
@@ -18,7 +18,6 @@
|
||||
*/
|
||||
|
||||
#include <config.h>
|
||||
|
||||
#include <stdlib.h>
|
||||
#include <stdarg.h>
|
||||
#include <stdio.h>
|
||||
@@ -31,7 +30,8 @@
|
||||
# include "lzs.h"
|
||||
#endif
|
||||
|
||||
#include <base64.h>
|
||||
#include <nettle/base64.h>
|
||||
#include <base64-helper.h>
|
||||
#include <c-strcase.h>
|
||||
#include <c-ctype.h>
|
||||
|
||||
@@ -166,6 +166,7 @@ struct compression_method_st comp_methods[] = {
|
||||
};
|
||||
#endif
|
||||
|
||||
|
||||
static
|
||||
void header_value_check(struct worker_st *ws, struct http_req_st *req)
|
||||
{
|
||||
@@ -356,14 +357,14 @@ void header_value_check(struct worker_st *ws, struct http_req_st *req)
|
||||
tmplen--;
|
||||
}
|
||||
|
||||
nlen = tmplen;
|
||||
nlen = BASE64_DECODE_LENGTH(tmplen);
|
||||
ws->cookie = talloc_size(ws, nlen);
|
||||
if (ws->cookie == NULL)
|
||||
return;
|
||||
|
||||
ret =
|
||||
base64_decode((char *)p, tmplen,
|
||||
(char *)ws->cookie, &nlen);
|
||||
oc_base64_decode((uint8_t*)p, tmplen,
|
||||
ws->cookie, &nlen);
|
||||
if (ret == 0) {
|
||||
oclog(ws, LOG_DEBUG,
|
||||
"could not decode cookie: %.*s",
|
||||
@@ -382,10 +383,10 @@ void header_value_check(struct worker_st *ws, struct http_req_st *req)
|
||||
tmplen--;
|
||||
}
|
||||
|
||||
nlen = sizeof(ws->sid);
|
||||
nlen = BASE64_DECODE_LENGTH(tmplen);
|
||||
ret =
|
||||
base64_decode((char *)p, tmplen,
|
||||
(char *)ws->sid, &nlen);
|
||||
oc_base64_decode((uint8_t*)p, tmplen,
|
||||
ws->sid, &nlen);
|
||||
if (ret == 0 || nlen != sizeof(ws->sid)) {
|
||||
oclog(ws, LOG_DEBUG,
|
||||
"could not decode sid: %.*s",
|
||||
|
||||
Reference in New Issue
Block a user