certificates and keys were moved to permanent configuration

This commit is contained in:
Nikos Mavrogiannopoulos
2015-06-25 13:38:59 +02:00
parent 696b64dd98
commit 9d621d2b5d
6 changed files with 91 additions and 95 deletions
+18 -26
View File
@@ -652,6 +652,20 @@ size_t urlfw_size = 0;
}
perm_config->gid = grp->gr_gid;
}
READ_MULTI_LINE("server-cert", perm_config->cert, perm_config->cert_size);
READ_MULTI_LINE("server-key", perm_config->key, perm_config->key_size);
READ_STRING("dh-params", perm_config->dh_params_file);
READ_STRING("pin-file", perm_config->pin_file);
READ_STRING("srk-pin-file", perm_config->srk_pin_file);
READ_STRING("ca-cert", perm_config->ca);
PREAD_STRING(perm_config, "socket-file", perm_config->socket_file_prefix);
PREAD_STRING(perm_config, "occtl-socket-file", perm_config->occtl_socket_file);
if (perm_config->occtl_socket_file == NULL)
perm_config->occtl_socket_file = talloc_strdup(perm_config, OCCTL_UNIX_SOCKET);
PREAD_STRING(perm_config, "chroot-dir", perm_config->chroot_dir);
}
/* When adding allocated data, remember to modify
@@ -679,16 +693,11 @@ size_t urlfw_size = 0;
READ_NUMERIC("rate-limit-ms", config->rate_limit_ms);
READ_STRING("ocsp-response", config->ocsp_response);
READ_MULTI_LINE("server-cert", config->cert, config->cert_size);
READ_MULTI_LINE("server-key", config->key, config->key_size);
READ_STRING("dh-params", config->dh_params_file);
READ_STRING("pin-file", config->pin_file);
READ_STRING("srk-pin-file", config->srk_pin_file);
#ifdef ANYCONNECT_CLIENT_COMPAT
READ_STRING("user-profile", config->xml_config_file);
#endif
READ_STRING("ca-cert", config->ca);
READ_STRING("default-domain", config->default_domain);
READ_STRING("crl", config->crl);
READ_STRING("cert-user-oid", config->cert_user_oid);
@@ -701,11 +710,6 @@ size_t urlfw_size = 0;
READ_STATIC_STRING("pid-file", pid_file);
PREAD_STRING(perm_config, "socket-file", perm_config->socket_file_prefix);
PREAD_STRING(perm_config, "occtl-socket-file", perm_config->occtl_socket_file);
if (perm_config->occtl_socket_file == NULL)
perm_config->occtl_socket_file = talloc_strdup(perm_config, OCCTL_UNIX_SOCKET);
val = get_option("session-control", NULL);
if (val != NULL) {
fprintf(stderr, "The option 'session-control' is deprecated\n");
@@ -756,7 +760,6 @@ size_t urlfw_size = 0;
READ_TF("ping-leases", config->ping_leases, 0);
READ_STRING("tls-priorities", config->priorities);
PREAD_STRING(perm_config, "chroot-dir", perm_config->chroot_dir);
READ_NUMERIC("mtu", config->default_mtu);
@@ -941,7 +944,7 @@ static void check_cfg(struct perm_cfg_st *perm_config)
exit(1);
}
if (perm_config->config->cert_size != perm_config->config->key_size) {
if (perm_config->cert_size != perm_config->key_size) {
fprintf(stderr, "The specified number of keys doesn't match the certificates\n");
exit(1);
}
@@ -972,8 +975,8 @@ static void check_cfg(struct perm_cfg_st *perm_config)
}
#ifdef ANYCONNECT_CLIENT_COMPAT
if (perm_config->config->cert) {
perm_config->config->cert_hash = calc_sha1_hash(perm_config->config, perm_config->config->cert[0], 1);
if (perm_config->cert && perm_config->cert_hash == NULL) {
perm_config->cert_hash = calc_sha1_hash(perm_config, perm_config->cert[0], 1);
}
if (perm_config->config->xml_config_file) {
@@ -1051,7 +1054,6 @@ unsigned i;
#ifdef ANYCONNECT_CLIENT_COMPAT
DEL(perm_config->config->xml_config_file);
DEL(perm_config->config->xml_config_hash);
DEL(perm_config->config->cert_hash);
#endif
DEL(perm_config->config->cgroup);
DEL(perm_config->config->route_add_cmd);
@@ -1062,10 +1064,6 @@ unsigned i;
DEL(perm_config->config->ocsp_response);
DEL(perm_config->config->banner);
DEL(perm_config->config->dh_params_file);
DEL(perm_config->config->pin_file);
DEL(perm_config->config->srk_pin_file);
DEL(perm_config->config->ca);
DEL(perm_config->config->crl);
DEL(perm_config->config->cert_user_oid);
DEL(perm_config->config->cert_group_oid);
@@ -1097,12 +1095,6 @@ unsigned i;
for (i=0;i<perm_config->config->network.nbns_size;i++)
DEL(perm_config->config->network.nbns[i]);
DEL(perm_config->config->network.nbns);
for (i=0;i<perm_config->config->key_size;i++)
DEL(perm_config->config->key[i]);
DEL(perm_config->config->key);
for (i=0;i<perm_config->config->cert_size;i++)
DEL(perm_config->config->cert[i]);
DEL(perm_config->config->cert);
for (i=0;i<perm_config->config->custom_header_size;i++)
DEL(perm_config->config->custom_header[i]);
DEL(perm_config->config->custom_header);
+33 -33
View File
@@ -171,6 +171,36 @@ run-as-group = nogroup
# specified relatively to the chroot directory.
socket-file = /var/run/ocserv-socket
# The key and the certificates of the server
# The key may be a file, or any URL supported by GnuTLS (e.g.,
# tpmkey:uuid=xxxxxxx-xxxx-xxxx-xxxx-xxxxxxxx;storage=user
# or pkcs11:object=my-vpn-key;object-type=private)
#
# The server-cert file may contain a single certificate, or
# a sorted certificate chain.
#
# There may be multiple server-cert and server-key directives,
# but each key should correspond to the preceding certificate.
server-cert = /path/to/cert.pem
server-key = /path/to/key.pem
# Diffie-Hellman parameters. Only needed if you require support
# for the DHE ciphersuites (by default this server supports ECDHE).
# Can be generated using:
# certtool --generate-dh-params --outfile /path/to/dh.pem
#dh-params = /path/to/dh.pem
# In case PKCS #11 or TPM keys are used the PINs should be available
# in files. The srk-pin-file is applicable to TPM keys only, and is the
# storage root key.
#pin-file = /path/to/pin.txt
#srk-pin-file = /path/to/srkpin.txt
# The Certificate Authority that will be used to verify
# client certificates (public keys) if certificate authentication
# is set.
#ca-cert = /path/to/ca.pem
### All configuration options below this line are reloaded on a SIGHUP.
### The options above, will remain unchanged.
@@ -229,24 +259,9 @@ mobile-dpd = 1800
# (DF) bit.
try-mtu-discovery = false
# The key and the certificates of the server
# The key may be a file, or any URL supported by GnuTLS (e.g.,
# tpmkey:uuid=xxxxxxx-xxxx-xxxx-xxxx-xxxxxxxx;storage=user
# or pkcs11:object=my-vpn-key;object-type=private)
#
# The server-cert file may contain a single certificate, or
# a sorted certificate chain.
#
# There may be multiple server-cert and server-key directives,
# but each key should correspond to the preceding certificate.
server-cert = /path/to/cert.pem
server-key = /path/to/key.pem
# Diffie-Hellman parameters. Only needed if you require support
# for the DHE ciphersuites (by default this server supports ECDHE).
# Can be generated using:
# certtool --generate-dh-params --outfile /path/to/dh.pem
#dh-params = /path/to/dh.pem
# The revocation list of the certificates issued by the 'ca-cert' above.
# See the manual to generate an empty CRL initially.
#crl = /path/to/crl.pem
# If you have a certificate from a CA that provides an OCSP
# service you may provide a fresh OCSP status response within
@@ -257,17 +272,6 @@ server-key = /path/to/key.pem
# Make sure that you replace the following file in an atomic way.
#ocsp-response = /path/to/ocsp.der
# In case PKCS #11 or TPM keys are used the PINs should be available
# in files. The srk-pin-file is applicable to TPM keys only, and is the
# storage root key.
#pin-file = /path/to/pin.txt
#srk-pin-file = /path/to/srkpin.txt
# The Certificate Authority that will be used to verify
# client certificates (public keys) if certificate authentication
# is set.
#ca-cert = /path/to/ca.pem
# The object identifier that will be used to read the user ID in the client
# certificate. The object identifier should be part of the certificate's DN
# Useful OIDs are:
@@ -280,10 +284,6 @@ server-key = /path/to/key.pem
# OU (organizational unit) = 2.5.4.11
#cert-group-oid = 2.5.4.11
# The revocation list of the certificates issued by the 'ca-cert' above.
# See the manual to generate an empty CRL initially.
#crl = /path/to/crl.pem
# Uncomment this to enable compression negotiation (LZS, LZ4).
#compression = true
+8 -8
View File
@@ -116,7 +116,7 @@ int pin_callback(void *user, int attempt, const char *token_url,
}
static
int load_pins(struct cfg_st *config, struct pin_st *s)
int load_pins(struct perm_cfg_st *config, struct pin_st *s)
{
int fd, ret;
@@ -649,15 +649,15 @@ void sec_mod_server(void *main_pool, struct perm_cfg_st *perm_config, const char
exit(1);
}
ret = load_pins(sec->config, &pins);
ret = load_pins(sec->perm_config, &pins);
if (ret < 0) {
seclog(sec, LOG_ERR, "error loading PIN files");
exit(1);
}
/* FIXME: the private key isn't reloaded on reload */
sec->key_size = sec->config->key_size;
sec->key = talloc_size(sec, sizeof(*sec->key) * sec->config->key_size);
sec->key_size = sec->perm_config->key_size;
sec->key = talloc_size(sec, sizeof(*sec->key) * sec->perm_config->key_size);
if (sec->key == NULL) {
seclog(sec, LOG_ERR, "error in memory allocation");
exit(1);
@@ -669,19 +669,19 @@ void sec_mod_server(void *main_pool, struct perm_cfg_st *perm_config, const char
GNUTLS_FATAL_ERR(ret);
/* load the private key */
if (gnutls_url_is_supported(sec->config->key[i]) != 0) {
if (gnutls_url_is_supported(sec->perm_config->key[i]) != 0) {
gnutls_privkey_set_pin_function(sec->key[i],
pin_callback, &pins);
ret =
gnutls_privkey_import_url(sec->key[i],
sec->config->key[i], 0);
sec->perm_config->key[i], 0);
GNUTLS_FATAL_ERR(ret);
} else {
gnutls_datum_t data;
ret = gnutls_load_file(sec->config->key[i], &data);
ret = gnutls_load_file(sec->perm_config->key[i], &data);
if (ret < 0) {
seclog(sec, LOG_ERR, "error loading file '%s'",
sec->config->key[i]);
sec->perm_config->key[i]);
GNUTLS_FATAL_ERR(ret);
}
+15 -15
View File
@@ -445,12 +445,12 @@ gnutls_x509_crt_t crt = NULL;
int ret;
unsigned usage;
if (s->config->cert_size > 1)
if (s->perm_config->cert_size > 1)
return;
if (gnutls_url_is_supported(s->config->cert[0]) == 0) {
if (gnutls_url_is_supported(s->perm_config->cert[0]) == 0) {
/* no URL */
ret = gnutls_load_file(s->config->cert[0], &data);
ret = gnutls_load_file(s->perm_config->cert[0], &data);
if (ret < 0)
return;
@@ -469,7 +469,7 @@ unsigned usage;
if (!(usage & GNUTLS_KEY_KEY_ENCIPHERMENT)) {
mslog(s, NULL, LOG_WARNING, "server certificate key usage prevents key encipherment; unable to support the RSA ciphersuites; "
"if that is not intentional, regenerate the server certificate with the key usage flag 'key encipherment' set.");
if (s->config->dh_params_file != NULL)
if (s->perm_config->dh_params_file != NULL)
mslog(s, NULL, LOG_WARNING, "no DH-params file specified; server will be limited to ECDHE ciphersuites\n");
}
}
@@ -487,11 +487,11 @@ static void set_dh_params(main_server_st* s, tls_st *creds)
gnutls_datum_t data;
int ret;
if (s->config->dh_params_file != NULL) {
if (s->perm_config->dh_params_file != NULL) {
ret = gnutls_dh_params_init (&creds->dh_params);
GNUTLS_FATAL_ERR(ret);
ret = gnutls_load_file(s->config->dh_params_file, &data);
ret = gnutls_load_file(s->perm_config->dh_params_file, &data);
GNUTLS_FATAL_ERR(ret);
ret = gnutls_dh_params_import_pkcs3(creds->dh_params, &data, GNUTLS_X509_FMT_PEM);
@@ -610,15 +610,15 @@ gnutls_privkey_t key;
gnutls_datum_t data;
struct key_cb_data * cdata;
for (i=0;i<s->config->key_size;i++) {
for (i=0;i<s->perm_config->key_size;i++) {
/* load the certificate */
if (gnutls_url_is_supported(s->config->cert[i]) != 0) {
mslog(s, NULL, LOG_ERR, "Loading a certificate from '%s' is unsupported", s->config->cert[i]);
if (gnutls_url_is_supported(s->perm_config->cert[i]) != 0) {
mslog(s, NULL, LOG_ERR, "Loading a certificate from '%s' is unsupported", s->perm_config->cert[i]);
return -1;
} else {
ret = gnutls_load_file(s->config->cert[i], &data);
ret = gnutls_load_file(s->perm_config->cert[i], &data);
if (ret < 0) {
mslog(s, NULL, LOG_ERR, "error loading file '%s'", s->config->cert[i]);
mslog(s, NULL, LOG_ERR, "error loading file '%s'", s->perm_config->cert[i]);
return -1;
}
@@ -688,7 +688,7 @@ const char* perr;
set_dh_params(s, creds);
if (s->config->key_size == 0 || s->config->cert_size == 0) {
if (s->perm_config->key_size == 0 || s->perm_config->cert_size == 0) {
mslog(s, NULL, LOG_ERR, "no certificate or key files were specified");
exit(1);
}
@@ -702,14 +702,14 @@ const char* perr;
}
if (s->config->cert_req != GNUTLS_CERT_IGNORE) {
if (s->config->ca != NULL) {
if (s->perm_config->ca != NULL) {
ret =
gnutls_certificate_set_x509_trust_file(creds->xcred,
s->config->ca,
s->perm_config->ca,
GNUTLS_X509_FMT_PEM);
if (ret < 0) {
mslog(s, NULL, LOG_ERR, "error setting the CA (%s) file",
s->config->ca);
s->perm_config->ca);
exit(1);
}
+15 -11
View File
@@ -291,16 +291,6 @@ struct cfg_st {
kkdcp_st *kkdcp;
unsigned int kkdcp_size;
char *pin_file;
char *srk_pin_file;
char **cert;
size_t cert_size;
char **key;
size_t key_size;
char *ca;
char *crl;
char *dh_params_file;
char *cert_user_oid; /* The OID that will be used to extract the username */
char *cert_group_oid; /* The OID that will be used to extract the groupname */
@@ -371,6 +361,8 @@ struct cfg_st {
size_t tx_per_sec;
unsigned net_priority;
char *crl;
unsigned output_buffer;
unsigned default_mtu;
unsigned predictable_ips; /* boolean */
@@ -387,7 +379,6 @@ struct cfg_st {
#ifdef ANYCONNECT_CLIENT_COMPAT
char *xml_config_file;
char *xml_config_hash;
char *cert_hash;
#endif
/* additional configuration files */
@@ -419,6 +410,19 @@ struct perm_cfg_st {
uid_t uid;
gid_t gid;
char *pin_file;
char *srk_pin_file;
char **cert;
size_t cert_size;
char **key;
size_t key_size;
#ifdef ANYCONNECT_CLIENT_COMPAT
char *cert_hash;
#endif
char *ca;
char *dh_params_file;
char *listen_host;
char* unix_conn_file;
unsigned int port;
+2 -2
View File
@@ -1006,14 +1006,14 @@ int post_common_handler(worker_st * ws, unsigned http_ver, const char *imsg)
ret =
cstp_printf(ws,
"Set-Cookie: webvpnc=bu:/&p:t&iu:1/&sh:%s&lu:/+CSCOT+/translation-table?textdomain%%3DAnyConnect%%26type%%3Dmanifest&fu:profiles%%2F%s&fh:%s; path=/; Secure\r\n",
ws->config->cert_hash,
ws->perm_config->cert_hash,
ws->config->xml_config_file,
ws->config->xml_config_hash);
} else {
ret =
cstp_printf(ws,
"Set-Cookie: webvpnc=bu:/&p:t&iu:1/&sh:%s; path=/; Secure\r\n",
ws->config->cert_hash);
ws->perm_config->cert_hash);
}
if (ret < 0)