use nettle's base64 implementation

This commit is contained in:
Nikos Mavrogiannopoulos
2015-10-30 14:47:19 +01:00
parent 413407c394
commit 037225a6da
12 changed files with 158 additions and 39 deletions
+1
View File
@@ -44,6 +44,7 @@ AC_CHECK_MEMBERS([struct iphdr.ihl], [],
AC_CHECK_SIZEOF([unsigned long])
AC_C_BIGENDIAN
PKG_CHECK_MODULES([LIBNETTLE], [nettle >= 2.7])
PKG_CHECK_MODULES([LIBGNUTLS], [gnutls >= 3.1.10])
AC_CHECK_LIB(gnutls, gnutls_pkcs11_reinit, [
AC_DEFINE([HAVE_PKCS11], [], [PKCS11 detected in gnutls])
+2 -2
View File
@@ -77,7 +77,7 @@ ocserv_SOURCES = main.c main-auth.c worker-vpn.c worker-auth.c tlslib.c \
worker-bandwidth.c worker-bandwidth.h ctl.h main-ctl.h \
vasprintf.c vasprintf.h worker-proxyproto.c \
proc-search.c proc-search.h http-heads.h ip-util.c ip-util.h \
main-ban.c main-ban.h common-config.h \
main-ban.c main-ban.h common-config.h base64-helper.c base64-helper.h \
str.c str.h gettime.h $(CCAN_SOURCES) $(HTTP_PARSER_SOURCES) \
$(PROTOBUF_SOURCES) sec-mod-acct.h setproctitle.c setproctitle.h
@@ -96,7 +96,7 @@ ocserv_LDADD += $(LIBGNUTLS_LIBS) $(PAM_LIBS) $(LIBUTIL) \
$(LIBSECCOMP) $(LIBWRAP) $(LIBCRYPT) $(NEEDED_HTTP_PARSER_LIBS) \
$(LIBPROTOBUF_C_LIBS) $(LIBSYSTEMD) $(LIBTALLOC_LIBS) \
$(RADCLI_LIBS) $(LIBLZ4_LIBS) $(LIBKRB5_LIBS) \
$(LIBTASN1_LIBS) $(LIBOATH_LIBS)
$(LIBTASN1_LIBS) $(LIBOATH_LIBS) $(LIBNETTLE_LIBS)
if PCL
+9 -7
View File
@@ -35,7 +35,7 @@
#include <gssapi/gssapi.h>
#include <gssapi/gssapi_ext.h>
#include <gssapi/gssapi_krb5.h>
#include <gl/base64.h>
#include <base64-helper.h>
#include "common-config.h"
static gss_cred_id_t glob_creds;
@@ -229,7 +229,7 @@ static int gssapi_auth_init(void **ctx, void *pool, const char *spnego, const ch
if (pctx == NULL)
return ERR_AUTH_FAIL;
ret = base64_decode_alloc(spnego, strlen(spnego), &raw, &raw_len);
ret = oc_base64_decode_alloc(pctx, spnego, strlen(spnego), &raw, &raw_len);
if (ret == 0) {
syslog(LOG_ERR, "gssapi: error in base64 decoding %s", __func__);
return ERR_AUTH_FAIL;
@@ -240,7 +240,7 @@ static int gssapi_auth_init(void **ctx, void *pool, const char *spnego, const ch
ret = gss_accept_sec_context(&minor, &pctx->gssctx, glob_creds, &buf,
GSS_C_NO_CHANNEL_BINDINGS, &client, &mech_type, &pctx->msg,
&flags, &time, &pctx->delegated_creds);
free(raw);
talloc_free(raw);
if (ret == GSS_S_CONTINUE_NEEDED) {
gss_release_name(&minor, &client);
@@ -291,7 +291,7 @@ static int gssapi_auth_pass(void *ctx, const char *spnego, unsigned spnego_len)
int ret;
/* nothing to be done */
ret = base64_decode_alloc(spnego, spnego_len, &raw, &raw_len);
ret = oc_base64_decode_alloc(pctx, spnego, spnego_len, &raw, &raw_len);
if (ret == 0) {
syslog(LOG_ERR, "gssapi: error in base64 decoding %s", __func__);
return ERR_AUTH_FAIL;
@@ -302,7 +302,7 @@ static int gssapi_auth_pass(void *ctx, const char *spnego, unsigned spnego_len)
ret = gss_accept_sec_context(&minor, &pctx->gssctx, glob_creds, &buf,
GSS_C_NO_CHANNEL_BINDINGS, &client, &mech_type, &pctx->msg,
&flags, &time, &pctx->delegated_creds);
free(raw);
talloc_free(raw);
if (ret == GSS_S_CONTINUE_NEEDED) {
gss_release_name(&minor, &client);
@@ -329,10 +329,12 @@ static int gssapi_auth_msg(void *ctx, void *pool, passwd_msg_st *pst)
/* our msg is our SPNEGO reply */
if (pctx->msg.value != NULL) {
length = BASE64_LENGTH(pctx->msg.length)+1;
length = BASE64_ENCODE_RAW_LENGTH(pctx->msg.length)+1;
pst->msg_str = talloc_size(pool, length);
base64_encode((char *)pctx->msg.value, pctx->msg.length, pst->msg_str, length);
oc_base64_encode(pctx->msg.value, pctx->msg.length,
pst->msg_str, length);
gss_release_buffer(&min, &pctx->msg);
pctx->msg.value = NULL;
}
-1
View File
@@ -22,7 +22,6 @@
#define RADIUS_H
#include <sec-mod-auth.h>
#include <base64.h>
struct radius_ctx_st {
char username[MAX_USERNAME_SIZE*2];
+76
View File
@@ -0,0 +1,76 @@
/*
* Copyright (C) 2015 Red Hat
*
* This file is part of ocserv.
*
* ocserv is free software: you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 2 of the License, or
* (at your option) any later version.
*
* ocserv is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
* General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
#include <config.h>
#include <nettle/base64.h>
#include <talloc.h>
#include "base64-helper.h"
void oc_base64_encode (const char *restrict in, size_t inlen,
char *restrict out, size_t outlen)
{
unsigned raw = BASE64_ENCODE_RAW_LENGTH(inlen);
if (outlen < raw+1) {
snprintf(out, outlen, "(too long data)");
return;
}
base64_encode_raw((uint8_t*)out, inlen, (uint8_t*)in);
out[raw] = 0;
return;
}
int
oc_base64_decode(const uint8_t *src, unsigned src_length,
uint8_t *dst, size_t *dst_length)
{
struct base64_decode_ctx ctx;
int ret;
base64_decode_init(&ctx);
ret = base64_decode_update(&ctx, dst_length, dst, src_length, src);
if (ret == 0)
return 0;
return base64_decode_final(&ctx);
}
int oc_base64_decode_alloc(void *pool, const char *in, size_t inlen,
char **out, size_t *outlen)
{
int len, ret;
void *tmp;
len = BASE64_DECODE_LENGTH(inlen);
tmp = talloc_size(pool, len);
if (tmp == NULL)
return 0;
*outlen = len;
ret = oc_base64_decode((void*)in, inlen, tmp, outlen);
if (ret == 0) {
talloc_free(tmp);
return 0;
}
*out = tmp;
return 1;
}
+38
View File
@@ -0,0 +1,38 @@
/*
* Copyright (C) 2015 Red Hat
*
* Author: Nikos Mavrogiannopoulos
*
* This file is part of ocserv.
*
* The GnuTLS is free software; you can redistribute it and/or
* modify it under the terms of the GNU Lesser General Public License
* as published by the Free Software Foundation; either version 2.1 of
* the License, or (at your option) any later version.
*
* This library is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
* Lesser General Public License for more details.
*
* You should have received a copy of the GNU Lesser General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>
*/
#ifndef BASE64_HELPER_H
# define BASE64_HELPER_H
#include <nettle/base64.h>
/* Prototypes compatible with the gnulib's */
int
oc_base64_decode(const uint8_t *src, unsigned src_length,
uint8_t *dst, size_t *dst_length);
int oc_base64_decode_alloc(void *pool, const char *in, size_t inlen,
char **out, size_t *outlen);
void oc_base64_encode (const char *restrict in, size_t inlen,
char *restrict out, size_t outlen);
#endif
+4 -4
View File
@@ -23,7 +23,7 @@
#include <string.h>
#include <stdio.h>
#include <stdarg.h>
#include <base64.h>
#include <base64-helper.h>
#include <vpn.h>
#include <worker.h>
@@ -190,7 +190,7 @@ void mslog_hex(const main_server_st * s, const struct proc_st* proc,
return;
if (b64) {
base64_encode((char*)bin, bin_size, (char*)buf, sizeof(buf));
oc_base64_encode((char*)bin, bin_size, (char*)buf, sizeof(buf));
} else {
buf_size = sizeof(buf);
ret = gnutls_hex_encode(&data, buf, &buf_size);
@@ -215,7 +215,7 @@ void oclog_hex(const worker_st* ws, int priority,
return;
if (b64) {
base64_encode((char*)bin, bin_size, (char*)buf, sizeof(buf));
oc_base64_encode((char*)bin, bin_size, (char*)buf, sizeof(buf));
} else {
buf_size = sizeof(buf);
ret = gnutls_hex_encode(&data, buf, &buf_size);
@@ -240,7 +240,7 @@ void seclog_hex(const struct sec_mod_st* sec, int priority,
return;
if (b64) {
base64_encode((char*)bin, bin_size, (char*)buf, sizeof(buf));
oc_base64_encode((char*)bin, bin_size, (char*)buf, sizeof(buf));
} else {
buf_size = sizeof(buf);
ret = gnutls_hex_encode(&data, buf, &buf_size);
+7 -6
View File
@@ -49,6 +49,7 @@
#include <auth/pam.h>
#include <sec-mod.h>
#include <vpn.h>
#include <base64-helper.h>
#include <sec-mod-sup-config.h>
#include <sec-mod-acct.h>
@@ -416,8 +417,8 @@ int handle_sec_auth_session_open(sec_mod_st *sec, int fd, const SecAuthSessionMs
e = find_client_entry(sec, req->sid.data);
if (e == NULL) {
char tmp[BASE64_LENGTH(SID_SIZE) + 1];
base64_encode((char *)req->sid.data, req->sid.len, (char *)tmp, sizeof(tmp));
char tmp[BASE64_ENCODE_RAW_LENGTH(SID_SIZE) + 1];
oc_base64_encode((char *)req->sid.data, req->sid.len, (char *)tmp, sizeof(tmp));
seclog(sec, LOG_INFO, "session open but with non-existing SID: %s!", tmp);
return send_failed_session_open_reply(sec, fd);
}
@@ -503,8 +504,8 @@ int handle_sec_auth_session_close(sec_mod_st *sec, int fd, const SecAuthSessionM
e = find_client_entry(sec, req->sid.data);
if (e == NULL) {
char tmp[BASE64_LENGTH(SID_SIZE) + 1];
base64_encode((char *)req->sid.data, req->sid.len, (char *)tmp, sizeof(tmp));
char tmp[BASE64_ENCODE_RAW_LENGTH(SID_SIZE) + 1];
oc_base64_encode((char *)req->sid.data, req->sid.len, (char *)tmp, sizeof(tmp));
seclog(sec, LOG_INFO, "session close but with non-existing SID: %s", tmp);
return send_msg(e, fd, SM_CMD_AUTH_CLI_STATS, &rep,
(pack_size_func) cli_stats_msg__get_packed_size,
@@ -596,8 +597,8 @@ int handle_sec_auth_stats_cmd(sec_mod_st * sec, const CliStatsMsg * req)
e = find_client_entry(sec, req->sid.data);
if (e == NULL) {
char tmp[BASE64_LENGTH(SID_SIZE) + 1];
base64_encode((char *)req->sid.data, req->sid.len, (char *)tmp, sizeof(tmp));
char tmp[BASE64_ENCODE_RAW_LENGTH(SID_SIZE) + 1];
oc_base64_encode((char *)req->sid.data, req->sid.len, (char *)tmp, sizeof(tmp));
seclog(sec, LOG_INFO, "session stats but with non-existing SID: %s", tmp);
return -1;
}
+2 -1
View File
@@ -37,6 +37,7 @@
#include <common.h>
#include <syslog.h>
#include <vpn.h>
#include <base64-helper.h>
#include <tlslib.h>
#include <sec-mod.h>
#include <ccan/hash/hash.h>
@@ -115,7 +116,7 @@ client_entry_st *new_client_entry(sec_mod_st *sec, const char *ip, unsigned pid)
goto fail;
}
base64_encode((char *)e->sid, SID_SIZE, (char *)e->auth_info.psid, sizeof(e->auth_info.psid));
oc_base64_encode((char *)e->sid, SID_SIZE, (char *)e->auth_info.psid, sizeof(e->auth_info.psid));
e->time = time(0);
if (htable_add(db, rehash(e, NULL), e) == 0) {
+2 -2
View File
@@ -24,7 +24,7 @@
#include <cookies.h>
#include <gnutls/abstract.h>
#include <ccan/htable/htable.h>
#include <base64.h>
#include <nettle/base64.h>
#define SESSION_STR "(session: %.5s)"
@@ -52,7 +52,7 @@ typedef struct stats_st {
typedef struct common_auth_info_st {
char username[MAX_USERNAME_SIZE*2];
char groupname[MAX_GROUPNAME_SIZE]; /* the owner's group */
char psid[BASE64_LENGTH(SID_SIZE) + 1]; /* printable */
char psid[BASE64_ENCODE_RAW_LENGTH(SID_SIZE) + 1]; /* printable */
char remote_ip[MAX_IP_STR];
char our_ip[MAX_IP_STR];
char ipv4[MAX_IP_STR];
+8 -8
View File
@@ -34,7 +34,7 @@
#include <unistd.h>
#include <limits.h>
#include <ipc.pb-c.h>
#include <base64.h>
#include <base64-helper.h>
#include <vpn.h>
#include "html.h"
@@ -169,7 +169,7 @@ static int append_group_str(worker_st * ws, str_st *str, const char *group)
int get_auth_handler2(worker_st * ws, unsigned http_ver, const char *pmsg, unsigned pcounter)
{
int ret;
char context[BASE64_LENGTH(SID_SIZE) + 1];
char context[BASE64_ENCODE_RAW_LENGTH(SID_SIZE) + 1];
unsigned int i, j;
str_st str;
const char *login_msg_start;
@@ -200,7 +200,7 @@ int get_auth_handler2(worker_st * ws, unsigned http_ver, const char *pmsg, unsig
if (ws->sid_set != 0) {
base64_encode((char *)ws->sid, sizeof(ws->sid), (char *)context,
oc_base64_encode((char *)ws->sid, sizeof(ws->sid), (char *)context,
sizeof(context));
ret =
@@ -916,7 +916,7 @@ int auth_cookie(worker_st * ws, void *cookie, size_t cookie_size)
int post_common_handler(worker_st * ws, unsigned http_ver, const char *imsg)
{
int ret, size;
char str_cookie[BASE64_LENGTH(ws->cookie_size)+1];
char str_cookie[BASE64_ENCODE_RAW_LENGTH(ws->cookie_size)+1];
size_t str_cookie_size = sizeof(str_cookie);
char msg[MAX_BANNER_SIZE + 32];
const char *success_msg_head;
@@ -936,7 +936,7 @@ int post_common_handler(worker_st * ws, unsigned http_ver, const char *imsg)
success_msg_foot_size = sizeof(oc_success_msg_foot)-1;
}
base64_encode((char *)ws->cookie, ws->cookie_size,
oc_base64_encode((char *)ws->cookie, ws->cookie_size,
(char *)str_cookie, str_cookie_size);
/* reply */
@@ -985,10 +985,10 @@ int post_common_handler(worker_st * ws, unsigned http_ver, const char *imsg)
return -1;
if (ws->sid_set != 0) {
char context[BASE64_LENGTH(SID_SIZE) + 1];
char context[BASE64_ENCODE_RAW_LENGTH(SID_SIZE) + 1];
base64_encode((char *)ws->sid, sizeof(ws->sid), (char *)context,
sizeof(context));
oc_base64_encode((char *)ws->sid, sizeof(ws->sid), (char *)context,
sizeof(context));
ret =
cstp_printf(ws,
+9 -8
View File
@@ -18,7 +18,6 @@
*/
#include <config.h>
#include <stdlib.h>
#include <stdarg.h>
#include <stdio.h>
@@ -31,7 +30,8 @@
# include "lzs.h"
#endif
#include <base64.h>
#include <nettle/base64.h>
#include <base64-helper.h>
#include <c-strcase.h>
#include <c-ctype.h>
@@ -166,6 +166,7 @@ struct compression_method_st comp_methods[] = {
};
#endif
static
void header_value_check(struct worker_st *ws, struct http_req_st *req)
{
@@ -356,14 +357,14 @@ void header_value_check(struct worker_st *ws, struct http_req_st *req)
tmplen--;
}
nlen = tmplen;
nlen = BASE64_DECODE_LENGTH(tmplen);
ws->cookie = talloc_size(ws, nlen);
if (ws->cookie == NULL)
return;
ret =
base64_decode((char *)p, tmplen,
(char *)ws->cookie, &nlen);
oc_base64_decode((uint8_t*)p, tmplen,
ws->cookie, &nlen);
if (ret == 0) {
oclog(ws, LOG_DEBUG,
"could not decode cookie: %.*s",
@@ -382,10 +383,10 @@ void header_value_check(struct worker_st *ws, struct http_req_st *req)
tmplen--;
}
nlen = sizeof(ws->sid);
nlen = BASE64_DECODE_LENGTH(tmplen);
ret =
base64_decode((char *)p, tmplen,
(char *)ws->sid, &nlen);
oc_base64_decode((uint8_t*)p, tmplen,
ws->sid, &nlen);
if (ret == 0 || nlen != sizeof(ws->sid)) {
oclog(ws, LOG_DEBUG,
"could not decode sid: %.*s",