mirror of
https://gitlab.com/openconnect/ocserv.git
synced 2026-10-12 01:26:48 +08:00
certificates and keys were moved to permanent configuration
This commit is contained in:
+18
-26
@@ -652,6 +652,20 @@ size_t urlfw_size = 0;
|
||||
}
|
||||
perm_config->gid = grp->gr_gid;
|
||||
}
|
||||
|
||||
READ_MULTI_LINE("server-cert", perm_config->cert, perm_config->cert_size);
|
||||
READ_MULTI_LINE("server-key", perm_config->key, perm_config->key_size);
|
||||
READ_STRING("dh-params", perm_config->dh_params_file);
|
||||
READ_STRING("pin-file", perm_config->pin_file);
|
||||
READ_STRING("srk-pin-file", perm_config->srk_pin_file);
|
||||
READ_STRING("ca-cert", perm_config->ca);
|
||||
|
||||
PREAD_STRING(perm_config, "socket-file", perm_config->socket_file_prefix);
|
||||
PREAD_STRING(perm_config, "occtl-socket-file", perm_config->occtl_socket_file);
|
||||
if (perm_config->occtl_socket_file == NULL)
|
||||
perm_config->occtl_socket_file = talloc_strdup(perm_config, OCCTL_UNIX_SOCKET);
|
||||
|
||||
PREAD_STRING(perm_config, "chroot-dir", perm_config->chroot_dir);
|
||||
}
|
||||
|
||||
/* When adding allocated data, remember to modify
|
||||
@@ -679,16 +693,11 @@ size_t urlfw_size = 0;
|
||||
READ_NUMERIC("rate-limit-ms", config->rate_limit_ms);
|
||||
|
||||
READ_STRING("ocsp-response", config->ocsp_response);
|
||||
READ_MULTI_LINE("server-cert", config->cert, config->cert_size);
|
||||
READ_MULTI_LINE("server-key", config->key, config->key_size);
|
||||
READ_STRING("dh-params", config->dh_params_file);
|
||||
READ_STRING("pin-file", config->pin_file);
|
||||
READ_STRING("srk-pin-file", config->srk_pin_file);
|
||||
|
||||
#ifdef ANYCONNECT_CLIENT_COMPAT
|
||||
READ_STRING("user-profile", config->xml_config_file);
|
||||
#endif
|
||||
|
||||
READ_STRING("ca-cert", config->ca);
|
||||
READ_STRING("default-domain", config->default_domain);
|
||||
READ_STRING("crl", config->crl);
|
||||
READ_STRING("cert-user-oid", config->cert_user_oid);
|
||||
@@ -701,11 +710,6 @@ size_t urlfw_size = 0;
|
||||
READ_STATIC_STRING("pid-file", pid_file);
|
||||
|
||||
|
||||
PREAD_STRING(perm_config, "socket-file", perm_config->socket_file_prefix);
|
||||
PREAD_STRING(perm_config, "occtl-socket-file", perm_config->occtl_socket_file);
|
||||
if (perm_config->occtl_socket_file == NULL)
|
||||
perm_config->occtl_socket_file = talloc_strdup(perm_config, OCCTL_UNIX_SOCKET);
|
||||
|
||||
val = get_option("session-control", NULL);
|
||||
if (val != NULL) {
|
||||
fprintf(stderr, "The option 'session-control' is deprecated\n");
|
||||
@@ -756,7 +760,6 @@ size_t urlfw_size = 0;
|
||||
READ_TF("ping-leases", config->ping_leases, 0);
|
||||
|
||||
READ_STRING("tls-priorities", config->priorities);
|
||||
PREAD_STRING(perm_config, "chroot-dir", perm_config->chroot_dir);
|
||||
|
||||
READ_NUMERIC("mtu", config->default_mtu);
|
||||
|
||||
@@ -941,7 +944,7 @@ static void check_cfg(struct perm_cfg_st *perm_config)
|
||||
exit(1);
|
||||
}
|
||||
|
||||
if (perm_config->config->cert_size != perm_config->config->key_size) {
|
||||
if (perm_config->cert_size != perm_config->key_size) {
|
||||
fprintf(stderr, "The specified number of keys doesn't match the certificates\n");
|
||||
exit(1);
|
||||
}
|
||||
@@ -972,8 +975,8 @@ static void check_cfg(struct perm_cfg_st *perm_config)
|
||||
}
|
||||
|
||||
#ifdef ANYCONNECT_CLIENT_COMPAT
|
||||
if (perm_config->config->cert) {
|
||||
perm_config->config->cert_hash = calc_sha1_hash(perm_config->config, perm_config->config->cert[0], 1);
|
||||
if (perm_config->cert && perm_config->cert_hash == NULL) {
|
||||
perm_config->cert_hash = calc_sha1_hash(perm_config, perm_config->cert[0], 1);
|
||||
}
|
||||
|
||||
if (perm_config->config->xml_config_file) {
|
||||
@@ -1051,7 +1054,6 @@ unsigned i;
|
||||
#ifdef ANYCONNECT_CLIENT_COMPAT
|
||||
DEL(perm_config->config->xml_config_file);
|
||||
DEL(perm_config->config->xml_config_hash);
|
||||
DEL(perm_config->config->cert_hash);
|
||||
#endif
|
||||
DEL(perm_config->config->cgroup);
|
||||
DEL(perm_config->config->route_add_cmd);
|
||||
@@ -1062,10 +1064,6 @@ unsigned i;
|
||||
|
||||
DEL(perm_config->config->ocsp_response);
|
||||
DEL(perm_config->config->banner);
|
||||
DEL(perm_config->config->dh_params_file);
|
||||
DEL(perm_config->config->pin_file);
|
||||
DEL(perm_config->config->srk_pin_file);
|
||||
DEL(perm_config->config->ca);
|
||||
DEL(perm_config->config->crl);
|
||||
DEL(perm_config->config->cert_user_oid);
|
||||
DEL(perm_config->config->cert_group_oid);
|
||||
@@ -1097,12 +1095,6 @@ unsigned i;
|
||||
for (i=0;i<perm_config->config->network.nbns_size;i++)
|
||||
DEL(perm_config->config->network.nbns[i]);
|
||||
DEL(perm_config->config->network.nbns);
|
||||
for (i=0;i<perm_config->config->key_size;i++)
|
||||
DEL(perm_config->config->key[i]);
|
||||
DEL(perm_config->config->key);
|
||||
for (i=0;i<perm_config->config->cert_size;i++)
|
||||
DEL(perm_config->config->cert[i]);
|
||||
DEL(perm_config->config->cert);
|
||||
for (i=0;i<perm_config->config->custom_header_size;i++)
|
||||
DEL(perm_config->config->custom_header[i]);
|
||||
DEL(perm_config->config->custom_header);
|
||||
|
||||
+33
-33
@@ -171,6 +171,36 @@ run-as-group = nogroup
|
||||
# specified relatively to the chroot directory.
|
||||
socket-file = /var/run/ocserv-socket
|
||||
|
||||
# The key and the certificates of the server
|
||||
# The key may be a file, or any URL supported by GnuTLS (e.g.,
|
||||
# tpmkey:uuid=xxxxxxx-xxxx-xxxx-xxxx-xxxxxxxx;storage=user
|
||||
# or pkcs11:object=my-vpn-key;object-type=private)
|
||||
#
|
||||
# The server-cert file may contain a single certificate, or
|
||||
# a sorted certificate chain.
|
||||
#
|
||||
# There may be multiple server-cert and server-key directives,
|
||||
# but each key should correspond to the preceding certificate.
|
||||
server-cert = /path/to/cert.pem
|
||||
server-key = /path/to/key.pem
|
||||
|
||||
# Diffie-Hellman parameters. Only needed if you require support
|
||||
# for the DHE ciphersuites (by default this server supports ECDHE).
|
||||
# Can be generated using:
|
||||
# certtool --generate-dh-params --outfile /path/to/dh.pem
|
||||
#dh-params = /path/to/dh.pem
|
||||
|
||||
# In case PKCS #11 or TPM keys are used the PINs should be available
|
||||
# in files. The srk-pin-file is applicable to TPM keys only, and is the
|
||||
# storage root key.
|
||||
#pin-file = /path/to/pin.txt
|
||||
#srk-pin-file = /path/to/srkpin.txt
|
||||
|
||||
# The Certificate Authority that will be used to verify
|
||||
# client certificates (public keys) if certificate authentication
|
||||
# is set.
|
||||
#ca-cert = /path/to/ca.pem
|
||||
|
||||
|
||||
### All configuration options below this line are reloaded on a SIGHUP.
|
||||
### The options above, will remain unchanged.
|
||||
@@ -229,24 +259,9 @@ mobile-dpd = 1800
|
||||
# (DF) bit.
|
||||
try-mtu-discovery = false
|
||||
|
||||
# The key and the certificates of the server
|
||||
# The key may be a file, or any URL supported by GnuTLS (e.g.,
|
||||
# tpmkey:uuid=xxxxxxx-xxxx-xxxx-xxxx-xxxxxxxx;storage=user
|
||||
# or pkcs11:object=my-vpn-key;object-type=private)
|
||||
#
|
||||
# The server-cert file may contain a single certificate, or
|
||||
# a sorted certificate chain.
|
||||
#
|
||||
# There may be multiple server-cert and server-key directives,
|
||||
# but each key should correspond to the preceding certificate.
|
||||
server-cert = /path/to/cert.pem
|
||||
server-key = /path/to/key.pem
|
||||
|
||||
# Diffie-Hellman parameters. Only needed if you require support
|
||||
# for the DHE ciphersuites (by default this server supports ECDHE).
|
||||
# Can be generated using:
|
||||
# certtool --generate-dh-params --outfile /path/to/dh.pem
|
||||
#dh-params = /path/to/dh.pem
|
||||
# The revocation list of the certificates issued by the 'ca-cert' above.
|
||||
# See the manual to generate an empty CRL initially.
|
||||
#crl = /path/to/crl.pem
|
||||
|
||||
# If you have a certificate from a CA that provides an OCSP
|
||||
# service you may provide a fresh OCSP status response within
|
||||
@@ -257,17 +272,6 @@ server-key = /path/to/key.pem
|
||||
# Make sure that you replace the following file in an atomic way.
|
||||
#ocsp-response = /path/to/ocsp.der
|
||||
|
||||
# In case PKCS #11 or TPM keys are used the PINs should be available
|
||||
# in files. The srk-pin-file is applicable to TPM keys only, and is the
|
||||
# storage root key.
|
||||
#pin-file = /path/to/pin.txt
|
||||
#srk-pin-file = /path/to/srkpin.txt
|
||||
|
||||
# The Certificate Authority that will be used to verify
|
||||
# client certificates (public keys) if certificate authentication
|
||||
# is set.
|
||||
#ca-cert = /path/to/ca.pem
|
||||
|
||||
# The object identifier that will be used to read the user ID in the client
|
||||
# certificate. The object identifier should be part of the certificate's DN
|
||||
# Useful OIDs are:
|
||||
@@ -280,10 +284,6 @@ server-key = /path/to/key.pem
|
||||
# OU (organizational unit) = 2.5.4.11
|
||||
#cert-group-oid = 2.5.4.11
|
||||
|
||||
# The revocation list of the certificates issued by the 'ca-cert' above.
|
||||
# See the manual to generate an empty CRL initially.
|
||||
#crl = /path/to/crl.pem
|
||||
|
||||
# Uncomment this to enable compression negotiation (LZS, LZ4).
|
||||
#compression = true
|
||||
|
||||
|
||||
+8
-8
@@ -116,7 +116,7 @@ int pin_callback(void *user, int attempt, const char *token_url,
|
||||
}
|
||||
|
||||
static
|
||||
int load_pins(struct cfg_st *config, struct pin_st *s)
|
||||
int load_pins(struct perm_cfg_st *config, struct pin_st *s)
|
||||
{
|
||||
int fd, ret;
|
||||
|
||||
@@ -649,15 +649,15 @@ void sec_mod_server(void *main_pool, struct perm_cfg_st *perm_config, const char
|
||||
exit(1);
|
||||
}
|
||||
|
||||
ret = load_pins(sec->config, &pins);
|
||||
ret = load_pins(sec->perm_config, &pins);
|
||||
if (ret < 0) {
|
||||
seclog(sec, LOG_ERR, "error loading PIN files");
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/* FIXME: the private key isn't reloaded on reload */
|
||||
sec->key_size = sec->config->key_size;
|
||||
sec->key = talloc_size(sec, sizeof(*sec->key) * sec->config->key_size);
|
||||
sec->key_size = sec->perm_config->key_size;
|
||||
sec->key = talloc_size(sec, sizeof(*sec->key) * sec->perm_config->key_size);
|
||||
if (sec->key == NULL) {
|
||||
seclog(sec, LOG_ERR, "error in memory allocation");
|
||||
exit(1);
|
||||
@@ -669,19 +669,19 @@ void sec_mod_server(void *main_pool, struct perm_cfg_st *perm_config, const char
|
||||
GNUTLS_FATAL_ERR(ret);
|
||||
|
||||
/* load the private key */
|
||||
if (gnutls_url_is_supported(sec->config->key[i]) != 0) {
|
||||
if (gnutls_url_is_supported(sec->perm_config->key[i]) != 0) {
|
||||
gnutls_privkey_set_pin_function(sec->key[i],
|
||||
pin_callback, &pins);
|
||||
ret =
|
||||
gnutls_privkey_import_url(sec->key[i],
|
||||
sec->config->key[i], 0);
|
||||
sec->perm_config->key[i], 0);
|
||||
GNUTLS_FATAL_ERR(ret);
|
||||
} else {
|
||||
gnutls_datum_t data;
|
||||
ret = gnutls_load_file(sec->config->key[i], &data);
|
||||
ret = gnutls_load_file(sec->perm_config->key[i], &data);
|
||||
if (ret < 0) {
|
||||
seclog(sec, LOG_ERR, "error loading file '%s'",
|
||||
sec->config->key[i]);
|
||||
sec->perm_config->key[i]);
|
||||
GNUTLS_FATAL_ERR(ret);
|
||||
}
|
||||
|
||||
|
||||
+15
-15
@@ -445,12 +445,12 @@ gnutls_x509_crt_t crt = NULL;
|
||||
int ret;
|
||||
unsigned usage;
|
||||
|
||||
if (s->config->cert_size > 1)
|
||||
if (s->perm_config->cert_size > 1)
|
||||
return;
|
||||
|
||||
if (gnutls_url_is_supported(s->config->cert[0]) == 0) {
|
||||
if (gnutls_url_is_supported(s->perm_config->cert[0]) == 0) {
|
||||
/* no URL */
|
||||
ret = gnutls_load_file(s->config->cert[0], &data);
|
||||
ret = gnutls_load_file(s->perm_config->cert[0], &data);
|
||||
if (ret < 0)
|
||||
return;
|
||||
|
||||
@@ -469,7 +469,7 @@ unsigned usage;
|
||||
if (!(usage & GNUTLS_KEY_KEY_ENCIPHERMENT)) {
|
||||
mslog(s, NULL, LOG_WARNING, "server certificate key usage prevents key encipherment; unable to support the RSA ciphersuites; "
|
||||
"if that is not intentional, regenerate the server certificate with the key usage flag 'key encipherment' set.");
|
||||
if (s->config->dh_params_file != NULL)
|
||||
if (s->perm_config->dh_params_file != NULL)
|
||||
mslog(s, NULL, LOG_WARNING, "no DH-params file specified; server will be limited to ECDHE ciphersuites\n");
|
||||
}
|
||||
}
|
||||
@@ -487,11 +487,11 @@ static void set_dh_params(main_server_st* s, tls_st *creds)
|
||||
gnutls_datum_t data;
|
||||
int ret;
|
||||
|
||||
if (s->config->dh_params_file != NULL) {
|
||||
if (s->perm_config->dh_params_file != NULL) {
|
||||
ret = gnutls_dh_params_init (&creds->dh_params);
|
||||
GNUTLS_FATAL_ERR(ret);
|
||||
|
||||
ret = gnutls_load_file(s->config->dh_params_file, &data);
|
||||
ret = gnutls_load_file(s->perm_config->dh_params_file, &data);
|
||||
GNUTLS_FATAL_ERR(ret);
|
||||
|
||||
ret = gnutls_dh_params_import_pkcs3(creds->dh_params, &data, GNUTLS_X509_FMT_PEM);
|
||||
@@ -610,15 +610,15 @@ gnutls_privkey_t key;
|
||||
gnutls_datum_t data;
|
||||
struct key_cb_data * cdata;
|
||||
|
||||
for (i=0;i<s->config->key_size;i++) {
|
||||
for (i=0;i<s->perm_config->key_size;i++) {
|
||||
/* load the certificate */
|
||||
if (gnutls_url_is_supported(s->config->cert[i]) != 0) {
|
||||
mslog(s, NULL, LOG_ERR, "Loading a certificate from '%s' is unsupported", s->config->cert[i]);
|
||||
if (gnutls_url_is_supported(s->perm_config->cert[i]) != 0) {
|
||||
mslog(s, NULL, LOG_ERR, "Loading a certificate from '%s' is unsupported", s->perm_config->cert[i]);
|
||||
return -1;
|
||||
} else {
|
||||
ret = gnutls_load_file(s->config->cert[i], &data);
|
||||
ret = gnutls_load_file(s->perm_config->cert[i], &data);
|
||||
if (ret < 0) {
|
||||
mslog(s, NULL, LOG_ERR, "error loading file '%s'", s->config->cert[i]);
|
||||
mslog(s, NULL, LOG_ERR, "error loading file '%s'", s->perm_config->cert[i]);
|
||||
return -1;
|
||||
}
|
||||
|
||||
@@ -688,7 +688,7 @@ const char* perr;
|
||||
|
||||
set_dh_params(s, creds);
|
||||
|
||||
if (s->config->key_size == 0 || s->config->cert_size == 0) {
|
||||
if (s->perm_config->key_size == 0 || s->perm_config->cert_size == 0) {
|
||||
mslog(s, NULL, LOG_ERR, "no certificate or key files were specified");
|
||||
exit(1);
|
||||
}
|
||||
@@ -702,14 +702,14 @@ const char* perr;
|
||||
}
|
||||
|
||||
if (s->config->cert_req != GNUTLS_CERT_IGNORE) {
|
||||
if (s->config->ca != NULL) {
|
||||
if (s->perm_config->ca != NULL) {
|
||||
ret =
|
||||
gnutls_certificate_set_x509_trust_file(creds->xcred,
|
||||
s->config->ca,
|
||||
s->perm_config->ca,
|
||||
GNUTLS_X509_FMT_PEM);
|
||||
if (ret < 0) {
|
||||
mslog(s, NULL, LOG_ERR, "error setting the CA (%s) file",
|
||||
s->config->ca);
|
||||
s->perm_config->ca);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
|
||||
@@ -291,16 +291,6 @@ struct cfg_st {
|
||||
kkdcp_st *kkdcp;
|
||||
unsigned int kkdcp_size;
|
||||
|
||||
char *pin_file;
|
||||
char *srk_pin_file;
|
||||
char **cert;
|
||||
size_t cert_size;
|
||||
char **key;
|
||||
size_t key_size;
|
||||
|
||||
char *ca;
|
||||
char *crl;
|
||||
char *dh_params_file;
|
||||
char *cert_user_oid; /* The OID that will be used to extract the username */
|
||||
char *cert_group_oid; /* The OID that will be used to extract the groupname */
|
||||
|
||||
@@ -371,6 +361,8 @@ struct cfg_st {
|
||||
size_t tx_per_sec;
|
||||
unsigned net_priority;
|
||||
|
||||
char *crl;
|
||||
|
||||
unsigned output_buffer;
|
||||
unsigned default_mtu;
|
||||
unsigned predictable_ips; /* boolean */
|
||||
@@ -387,7 +379,6 @@ struct cfg_st {
|
||||
#ifdef ANYCONNECT_CLIENT_COMPAT
|
||||
char *xml_config_file;
|
||||
char *xml_config_hash;
|
||||
char *cert_hash;
|
||||
#endif
|
||||
|
||||
/* additional configuration files */
|
||||
@@ -419,6 +410,19 @@ struct perm_cfg_st {
|
||||
uid_t uid;
|
||||
gid_t gid;
|
||||
|
||||
char *pin_file;
|
||||
char *srk_pin_file;
|
||||
char **cert;
|
||||
size_t cert_size;
|
||||
char **key;
|
||||
size_t key_size;
|
||||
#ifdef ANYCONNECT_CLIENT_COMPAT
|
||||
char *cert_hash;
|
||||
#endif
|
||||
|
||||
char *ca;
|
||||
char *dh_params_file;
|
||||
|
||||
char *listen_host;
|
||||
char* unix_conn_file;
|
||||
unsigned int port;
|
||||
|
||||
+2
-2
@@ -1006,14 +1006,14 @@ int post_common_handler(worker_st * ws, unsigned http_ver, const char *imsg)
|
||||
ret =
|
||||
cstp_printf(ws,
|
||||
"Set-Cookie: webvpnc=bu:/&p:t&iu:1/&sh:%s&lu:/+CSCOT+/translation-table?textdomain%%3DAnyConnect%%26type%%3Dmanifest&fu:profiles%%2F%s&fh:%s; path=/; Secure\r\n",
|
||||
ws->config->cert_hash,
|
||||
ws->perm_config->cert_hash,
|
||||
ws->config->xml_config_file,
|
||||
ws->config->xml_config_hash);
|
||||
} else {
|
||||
ret =
|
||||
cstp_printf(ws,
|
||||
"Set-Cookie: webvpnc=bu:/&p:t&iu:1/&sh:%s; path=/; Secure\r\n",
|
||||
ws->config->cert_hash);
|
||||
ws->perm_config->cert_hash);
|
||||
}
|
||||
|
||||
if (ret < 0)
|
||||
|
||||
Reference in New Issue
Block a user