libpurple/plugins/ssl/ssl-gnutls.c

Sat, 04 Apr 2020 01:36:20 +0200

author
Samuel Thibault <samuel.thibault@ens-lyon.org>
date
Sat, 04 Apr 2020 01:36:20 +0200
branch
discord-ssl-crash
changeset 40322
3e026e7db681
parent 40238
6dba8046e1b1
permissions
-rw-r--r--

Make ssl_*_read robust against bogus connection, like ssl_*_write is

7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1 /**
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
2 * @file ssl-gnutls.c GNUTLS SSL plugin.
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
3 *
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
4 * purple
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
5 *
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
6 * Copyright (C) 2003 Christian Hammond <chipx86@gnupdate.org>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
7 *
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
8 * This program is free software; you can redistribute it and/or modify
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
9 * it under the terms of the GNU General Public License as published by
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
10 * the Free Software Foundation; either version 2 of the License, or
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
11 * (at your option) any later version.
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
12 *
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
13 * This program is distributed in the hope that it will be useful,
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
16 * GNU General Public License for more details.
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
17 *
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
18 * You should have received a copy of the GNU General Public License
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
19 * along with this program; if not, write to the Free Software
19859
71d37b57eff2 The FSF changed its address a while ago; our files were out of date.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 19827
diff changeset
20 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02111-1301 USA
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
21 */
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
22 #include "internal.h"
7051
8ddb8f560399 [gaim-migrate @ 7614]
Christian Hammond <chipx86@chipx86.com>
parents: 7050
diff changeset
23 #include "debug.h"
17509
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
24 #include "certificate.h"
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
25 #include "plugin.h"
7051
8ddb8f560399 [gaim-migrate @ 7614]
Christian Hammond <chipx86@chipx86.com>
parents: 7050
diff changeset
26 #include "sslconn.h"
9943
b54a762f60fa [gaim-migrate @ 10835]
Nathan Walp <nwalp@pidgin.im>
parents: 8749
diff changeset
27 #include "version.h"
17390
7fda160e7c5e - Made a big mess of stuff in the GnuTLS pluging to look at cert auth
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17345
diff changeset
28 #include "util.h"
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
29
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
30 #define SSL_GNUTLS_PLUGIN_ID "ssl-gnutls"
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
31
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
32 #include <gnutls/gnutls.h>
17390
7fda160e7c5e - Made a big mess of stuff in the GnuTLS pluging to look at cert auth
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17345
diff changeset
33 #include <gnutls/x509.h>
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
34
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
35 typedef struct
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
36 {
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
37 gnutls_session_t session;
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
38 guint handshake_handler;
29942
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
39 guint handshake_timer;
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
40 } PurpleSslGnutlsData;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
41
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
42 #define PURPLE_SSL_GNUTLS_DATA(gsc) ((PurpleSslGnutlsData *)gsc->private_data)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
43
29939
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
44 static gnutls_certificate_client_credentials xcred = NULL;
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
45
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
46 #ifdef HAVE_GNUTLS_PRIORITY_FUNCS
29940
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
47 /* Priority strings. The default one is, well, the default (and is always
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
48 * set). The hash table is of the form hostname => priority (both
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
49 * char *).
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
50 *
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
51 * We only use a gnutls_priority_t for the default on the assumption that
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
52 * that's the more common case. Improvement patches (like matching on
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
53 * subdomains) welcome.
29939
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
54 */
29940
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
55 static gnutls_priority_t default_priority = NULL;
29939
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
56 static GHashTable *host_priorities = NULL;
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
57 #endif
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
58
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7834
diff changeset
59 static void
27407
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
60 ssl_gnutls_log(int level, const char *str)
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
61 {
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
62 /* GnuTLS log messages include the '\n' */
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
63 purple_debug_misc("gnutls", "lvl %d: %s", level, str);
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
64 }
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
65
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
66 static void
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7834
diff changeset
67 ssl_gnutls_init_gnutls(void)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
68 {
27407
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
69 const char *debug_level;
29939
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
70 const char *host_priorities_str;
27407
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
71
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
72 debug_level = g_getenv("PURPLE_GNUTLS_DEBUG");
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
73 if (debug_level) {
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
74 int level = atoi(debug_level);
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
75 if (level < 0) {
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
76 purple_debug_warning("gnutls", "Assuming log level 0 instead of %d\n",
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
77 level);
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
78 level = 0;
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
79 }
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
80
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
81 /* "The level is an integer between 0 and 9. Higher values mean more verbosity." */
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
82 gnutls_global_set_log_level(level);
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
83 gnutls_global_set_log_function(ssl_gnutls_log);
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
84 }
dd036d781b36 Allow GnuTLS logging to be controlled via PURPLE_GNUTLS_DEBUG envvar.
Paul Aurich <darkrain42@pidgin.im>
parents: 27337
diff changeset
85
29939
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
86 /* Expected format: host=priority;host2=priority;*=priority
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
87 * where "*" is used to override the default priority string for
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
88 * libpurple.
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
89 */
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
90 host_priorities_str = g_getenv("PURPLE_GNUTLS_PRIORITIES");
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
91 if (host_priorities_str) {
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
92 #ifndef HAVE_GNUTLS_PRIORITY_FUNCS
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
93 purple_debug_warning("gnutls", "Warning, PURPLE_GNUTLS_PRIORITIES "
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
94 "environment variable set, but we were built "
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
95 "against an older GnuTLS that doesn't support "
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
96 "this. :-(");
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
97 #else /* HAVE_GNUTLS_PRIORITY_FUNCS */
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
98 char **entries = g_strsplit(host_priorities_str, ";", -1);
29940
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
99 char *default_priority_str = NULL;
29939
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
100 guint i;
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
101
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
102 host_priorities = g_hash_table_new_full(g_str_hash, g_str_equal,
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
103 g_free, g_free);
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
104
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
105 for (i = 0; entries[i]; ++i) {
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
106 char *host = entries[i];
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
107 char *equals = strchr(host, '=');
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
108 char *prio_str;
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
109
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
110 if (equals) {
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
111 *equals = '\0';
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
112 prio_str = equals + 1;
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
113
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
114 /* Empty? */
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
115 if (*prio_str == '\0') {
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
116 purple_debug_warning("gnutls", "Ignoring empty priority "
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
117 "string for %s\n", host);
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
118 } else {
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
119 /* TODO: Validate each of these and complain */
38256
035f00c4fd87 Replace misused g_str_equal() with purple_strequal()
qarkai <qarkai@gmail.com>
parents: 38216
diff changeset
120 if (purple_strequal(host, "*")) {
29939
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
121 /* Override the default priority */
29940
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
122 g_free(default_priority_str);
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
123 default_priority_str = g_strdup(prio_str);
29939
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
124 } else
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
125 g_hash_table_insert(host_priorities, g_strdup(host),
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
126 g_strdup(prio_str));
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
127 }
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
128 }
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
129 }
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
130
29940
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
131 if (default_priority_str) {
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
132 if (gnutls_priority_init(&default_priority, default_priority_str, NULL)) {
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
133 purple_debug_warning("gnutls", "Unable to set default priority to %s\n",
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
134 default_priority_str);
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
135 /* Versions of GnuTLS as of 2.8.6 (2010-03-31) don't free/NULL
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
136 * this on error.
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
137 */
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
138 gnutls_free(default_priority);
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
139 default_priority = NULL;
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
140 }
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
141
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
142 g_free(default_priority_str);
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
143 }
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
144
29939
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
145 g_strfreev(entries);
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
146 #endif /* HAVE_GNUTLS_PRIORITY_FUNCS */
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
147 }
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
148
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
149 #ifdef HAVE_GNUTLS_PRIORITY_FUNCS
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
150 /* Make sure we set have a default priority! */
29940
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
151 if (!default_priority) {
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
152 if (gnutls_priority_init(&default_priority, "NORMAL:%SSL3_RECORD_VERSION", NULL)) {
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
153 /* See comment above about memory leak */
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
154 gnutls_free(default_priority);
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
155 gnutls_priority_init(&default_priority, "NORMAL", NULL);
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
156 }
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
157 }
29939
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
158 #endif /* HAVE_GNUTLS_PRIORITY_FUNCS */
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
159
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
160 gnutls_global_init();
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
161
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
162 gnutls_certificate_allocate_credentials(&xcred);
17509
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
163
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
164 /* TODO: I can likely remove this */
17430
95d550efcc3d disapproval of revision '8976f9e287fef5bd2856c34ea931afa70a997895'
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17429
diff changeset
165 gnutls_certificate_set_x509_trust_file(xcred, "ca.pem",
95d550efcc3d disapproval of revision '8976f9e287fef5bd2856c34ea931afa70a997895'
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17429
diff changeset
166 GNUTLS_X509_FMT_PEM);
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7834
diff changeset
167 }
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
168
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7834
diff changeset
169 static gboolean
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7834
diff changeset
170 ssl_gnutls_init(void)
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7834
diff changeset
171 {
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
172 return TRUE;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
173 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
174
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
175 static void
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
176 ssl_gnutls_uninit(void)
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
177 {
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
178 gnutls_global_deinit();
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
179
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
180 gnutls_certificate_free_credentials(xcred);
29939
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
181 xcred = NULL;
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
182
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
183 #ifdef HAVE_GNUTLS_PRIORITY_FUNCS
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
184 if (host_priorities) {
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
185 g_hash_table_destroy(host_priorities);
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
186 host_priorities = NULL;
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
187 }
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
188
29940
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
189 gnutls_priority_deinit(default_priority);
29939
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
190 default_priority = NULL;
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
191 #endif
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
192 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
193
18475
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
194 static void
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
195 ssl_gnutls_verified_cb(PurpleCertificateVerificationStatus st,
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
196 gpointer userdata)
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
197 {
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
198 PurpleSslConnection *gsc = (PurpleSslConnection *) userdata;
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
199
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
200 if (st == PURPLE_CERTIFICATE_VALID) {
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
201 /* Certificate valid? Good! Do the connection! */
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
202 gsc->connect_cb(gsc->connect_cb_data, gsc, PURPLE_INPUT_READ);
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
203 } else {
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
204 /* Otherwise, signal an error */
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
205 if(gsc->error_cb != NULL)
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
206 gsc->error_cb(gsc, PURPLE_SSL_CERTIFICATE_INVALID,
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
207 gsc->connect_cb_data);
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
208 purple_ssl_close(gsc);
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
209 }
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
210 }
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
211
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
212
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
213
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
214 static void ssl_gnutls_handshake_cb(gpointer data, gint source,
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
215 PurpleInputCondition cond)
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
216 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
217 PurpleSslConnection *gsc = data;
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
218 PurpleSslGnutlsData *gnutls_data = PURPLE_SSL_GNUTLS_DATA(gsc);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
219 ssize_t ret;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
220
20151
0b5ba1105191 applied changes from 5252885d793a4d288d92856d511d721bf5bb87ef
Richard Laager <rlaager@pidgin.im>
parents: 19859
diff changeset
221 /*purple_debug_info("gnutls", "Handshaking with %s\n", gsc->host);*/
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
222 ret = gnutls_handshake(gnutls_data->session);
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
223
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
224 if(ret == GNUTLS_E_AGAIN || ret == GNUTLS_E_INTERRUPTED)
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
225 return;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
226
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
227 purple_input_remove(gnutls_data->handshake_handler);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
228 gnutls_data->handshake_handler = 0;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
229
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
230 if(ret != 0) {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
231 purple_debug_error("gnutls", "Handshake failed. Error %s\n",
15846
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
232 gnutls_strerror(ret));
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
233
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
234 if(gsc->error_cb != NULL)
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
235 gsc->error_cb(gsc, PURPLE_SSL_HANDSHAKE_FAILED,
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
236 gsc->connect_cb_data);
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
237
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
238 purple_ssl_close(gsc);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
239 } else {
18458
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
240 /* Now we are cooking with gas! */
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
241 PurpleSslOps *ops = purple_ssl_get_ops();
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
242 GList * peers = ops->get_peer_certificates(gsc);
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
243
18458
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
244 PurpleCertificateScheme *x509 =
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
245 purple_certificate_find_scheme("x509");
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
246
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
247 GList * l;
19711
19b0780efe0e Fix compiler warnings about having a variable declaration after some
Mark Doliner <markdoliner@pidgin.im>
parents: 19501
diff changeset
248
19b0780efe0e Fix compiler warnings about having a variable declaration after some
Mark Doliner <markdoliner@pidgin.im>
parents: 19501
diff changeset
249 /* TODO: Remove all this debugging babble */
19b0780efe0e Fix compiler warnings about having a variable declaration after some
Mark Doliner <markdoliner@pidgin.im>
parents: 19501
diff changeset
250 purple_debug_info("gnutls", "Handshake complete\n");
19b0780efe0e Fix compiler warnings about having a variable declaration after some
Mark Doliner <markdoliner@pidgin.im>
parents: 19501
diff changeset
251
18458
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
252 for (l=peers; l; l = l->next) {
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
253 PurpleCertificate *crt = l->data;
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
254 GByteArray *z =
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
255 x509->get_fingerprint_sha1(crt);
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
256 gchar * fpr =
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
257 purple_base16_encode_chunked(z->data,
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
258 z->len);
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
259
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
260 purple_debug_info("gnutls/x509",
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
261 "Key print: %s\n",
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
262 fpr);
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
263
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
264 /* Kill the cert! */
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
265 x509->destroy_certificate(crt);
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
266
18458
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
267 g_free(fpr);
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
268 g_byte_array_free(z, TRUE);
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
269 }
e2f60e9d44aa - Add debugging babble
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18455
diff changeset
270 g_list_free(peers);
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
271
17390
7fda160e7c5e - Made a big mess of stuff in the GnuTLS pluging to look at cert auth
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17345
diff changeset
272 {
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
273 const gnutls_datum_t *cert_list;
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
274 unsigned int cert_list_size = 0;
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
275 gnutls_session_t session=gnutls_data->session;
36256
a437550a9308 Remove -Wno-sign-compare and backport fixes from default.
Elliott Sales de Andrade <qulogic@pidgin.im>
parents: 36191
diff changeset
276 guint i;
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
277
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
278 cert_list =
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
279 gnutls_certificate_get_peers(session, &cert_list_size);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
280
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
281 purple_debug_info("gnutls",
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
282 "Peer provided %d certs\n",
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
283 cert_list_size);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
284 for (i=0; i<cert_list_size; i++)
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
285 {
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
286 gchar fpr_bin[256];
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
287 gsize fpr_bin_sz = sizeof(fpr_bin);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
288 gchar * fpr_asc = NULL;
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
289 gchar tbuf[256];
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
290 gsize tsz=sizeof(tbuf);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
291 gchar * tasc = NULL;
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
292 gnutls_x509_crt_t cert;
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
293
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
294 gnutls_x509_crt_init(&cert);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
295 gnutls_x509_crt_import (cert, &cert_list[i],
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
296 GNUTLS_X509_FMT_DER);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
297
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
298 gnutls_x509_crt_get_fingerprint(cert, GNUTLS_DIG_SHA,
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
299 fpr_bin, &fpr_bin_sz);
17390
7fda160e7c5e - Made a big mess of stuff in the GnuTLS pluging to look at cert auth
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17345
diff changeset
300
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
301 fpr_asc =
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
302 purple_base16_encode_chunked((const guchar *)fpr_bin, fpr_bin_sz);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
303
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
304 purple_debug_info("gnutls",
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
305 "Lvl %d SHA1 fingerprint: %s\n",
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
306 i, fpr_asc);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
307
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
308 tsz=sizeof(tbuf);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
309 gnutls_x509_crt_get_serial(cert,tbuf,&tsz);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
310 tasc=purple_base16_encode_chunked((const guchar *)tbuf, tsz);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
311 purple_debug_info("gnutls",
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
312 "Serial: %s\n",
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
313 tasc);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
314 g_free(tasc);
17390
7fda160e7c5e - Made a big mess of stuff in the GnuTLS pluging to look at cert auth
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17345
diff changeset
315
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
316 tsz=sizeof(tbuf);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
317 gnutls_x509_crt_get_dn (cert, tbuf, &tsz);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
318 purple_debug_info("gnutls",
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
319 "Cert DN: %s\n",
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
320 tbuf);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
321 tsz=sizeof(tbuf);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
322 gnutls_x509_crt_get_issuer_dn (cert, tbuf, &tsz);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
323 purple_debug_info("gnutls",
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
324 "Cert Issuer DN: %s\n",
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
325 tbuf);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
326
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
327 g_free(fpr_asc);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
328 fpr_asc = NULL;
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
329 gnutls_x509_crt_deinit(cert);
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
330 }
17430
95d550efcc3d disapproval of revision '8976f9e287fef5bd2856c34ea931afa70a997895'
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17429
diff changeset
331 }
18475
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
332
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
333 /* TODO: The following logic should really be in libpurple */
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
334 /* If a Verifier was given, hand control over to it */
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
335 if (gsc->verifier) {
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
336 GList *peers;
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
337 /* First, get the peer cert chain */
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
338 peers = purple_ssl_get_peer_certificates(gsc);
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
339
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
340 /* Now kick off the verification process */
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
341 purple_certificate_verify(gsc->verifier,
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
342 gsc->host,
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
343 peers,
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
344 ssl_gnutls_verified_cb,
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
345 gsc);
18656
02c822b398d2 - purple_certificate_verify no longer takes possession of the
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18654
diff changeset
346
02c822b398d2 - purple_certificate_verify no longer takes possession of the
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18654
diff changeset
347 purple_certificate_destroy_list(peers);
18475
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
348 } else {
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
349 /* Otherwise, just call the "connection complete"
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
350 callback */
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
351 gsc->connect_cb(gsc->connect_cb_data, gsc, cond);
e3893e58c4c2 - ssl-gnutls plugin uses Verifiers now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18458
diff changeset
352 }
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
353 }
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
354
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
355 }
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
356
29942
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
357 static gboolean
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
358 start_handshake_cb(gpointer data)
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
359 {
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
360 PurpleSslConnection *gsc = data;
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
361 PurpleSslGnutlsData *gnutls_data = PURPLE_SSL_GNUTLS_DATA(gsc);
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
362
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
363 purple_debug_info("gnutls", "Starting handshake with %s\n", gsc->host);
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
364
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
365 gnutls_data->handshake_timer = 0;
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
366
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
367 ssl_gnutls_handshake_cb(gsc, gsc->fd, PURPLE_INPUT_READ);
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
368 return FALSE;
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
369 }
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
370
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
371 static void
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
372 ssl_gnutls_connect(PurpleSslConnection *gsc)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
373 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
374 PurpleSslGnutlsData *gnutls_data;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
375
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
376 gnutls_data = g_new0(PurpleSslGnutlsData, 1);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
377 gsc->private_data = gnutls_data;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
378
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
379 gnutls_init(&gnutls_data->session, GNUTLS_CLIENT);
25643
04831cc56f5a Use _set_default_priority on gnutls versions lacking _priority_set_direct.
Ethan Blanton <elb@pidgin.im>
parents: 25642
diff changeset
380 #ifdef HAVE_GNUTLS_PRIORITY_FUNCS
29939
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
381 {
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
382 const char *prio_str = NULL;
29940
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
383 gboolean set = FALSE;
29939
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
384
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
385 /* Let's see if someone has specified a specific priority */
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
386 if (gsc->host && host_priorities)
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
387 prio_str = g_hash_table_lookup(host_priorities, gsc->host);
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
388
29940
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
389 if (prio_str)
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
390 set = (GNUTLS_E_SUCCESS ==
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
391 gnutls_priority_set_direct(gnutls_data->session, prio_str,
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
392 NULL));
29939
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
393
29940
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
394 if (!set)
7dd000cb5073 gnutls: Use gnutls_priority_init for the default priority.
Paul Aurich <darkrain42@pidgin.im>
parents: 29939
diff changeset
395 gnutls_priority_set(gnutls_data->session, default_priority);
29939
4b6203acfa26 gnutls: Allow overriding (per-host) of GnuTLS priorities via env. Fixes #11616
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
396 }
25643
04831cc56f5a Use _set_default_priority on gnutls versions lacking _priority_set_direct.
Ethan Blanton <elb@pidgin.im>
parents: 25642
diff changeset
397 #else
04831cc56f5a Use _set_default_priority on gnutls versions lacking _priority_set_direct.
Ethan Blanton <elb@pidgin.im>
parents: 25642
diff changeset
398 gnutls_set_default_priority(gnutls_data->session);
04831cc56f5a Use _set_default_priority on gnutls versions lacking _priority_set_direct.
Ethan Blanton <elb@pidgin.im>
parents: 25642
diff changeset
399 #endif
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
400
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
401 gnutls_credentials_set(gnutls_data->session, GNUTLS_CRD_CERTIFICATE,
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
402 xcred);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
403
14223
c6ba4f3482de [gaim-migrate @ 16809]
Mark Doliner <markdoliner@pidgin.im>
parents: 13985
diff changeset
404 gnutls_transport_set_ptr(gnutls_data->session, GINT_TO_POINTER(gsc->fd));
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
405
40238
6dba8046e1b1 Implement SNI support for the gnutls SSL plugin.
Mihai Moldovan <ionic@ionic.de>
parents: 39634
diff changeset
406 /* SNI support. */
6dba8046e1b1 Implement SNI support for the gnutls SSL plugin.
Mihai Moldovan <ionic@ionic.de>
parents: 39634
diff changeset
407 if (gsc->host && !g_hostname_is_ip_address(gsc->host))
6dba8046e1b1 Implement SNI support for the gnutls SSL plugin.
Mihai Moldovan <ionic@ionic.de>
parents: 39634
diff changeset
408 gnutls_server_name_set(gnutls_data->session, GNUTLS_NAME_DNS, gsc->host, strlen(gsc->host));
6dba8046e1b1 Implement SNI support for the gnutls SSL plugin.
Mihai Moldovan <ionic@ionic.de>
parents: 39634
diff changeset
409
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
410 gnutls_data->handshake_handler = purple_input_add(gsc->fd,
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
411 PURPLE_INPUT_READ, ssl_gnutls_handshake_cb, gsc);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
412
17345
cbe9758e542e - Document some weird-looking logic in the GnuTLS plugin.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 16744
diff changeset
413 /* Orborde asks: Why are we configuring a callback, then
29942
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
414 (almost) immediately calling it?
17345
cbe9758e542e - Document some weird-looking logic in the GnuTLS plugin.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 16744
diff changeset
415
cbe9758e542e - Document some weird-looking logic in the GnuTLS plugin.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 16744
diff changeset
416 Answer: gnutls_handshake (up in handshake_cb) needs to be called
cbe9758e542e - Document some weird-looking logic in the GnuTLS plugin.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 16744
diff changeset
417 once in order to get the ball rolling on the SSL connection.
cbe9758e542e - Document some weird-looking logic in the GnuTLS plugin.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 16744
diff changeset
418 Once it has done so, only then will the server reply, triggering
cbe9758e542e - Document some weird-looking logic in the GnuTLS plugin.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 16744
diff changeset
419 the callback.
cbe9758e542e - Document some weird-looking logic in the GnuTLS plugin.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 16744
diff changeset
420
cbe9758e542e - Document some weird-looking logic in the GnuTLS plugin.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 16744
diff changeset
421 Since the logic driving gnutls_handshake is the same with the first
cbe9758e542e - Document some weird-looking logic in the GnuTLS plugin.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 16744
diff changeset
422 and subsequent calls, we'll just fire the callback immediately to
cbe9758e542e - Document some weird-looking logic in the GnuTLS plugin.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 16744
diff changeset
423 accomplish this.
cbe9758e542e - Document some weird-looking logic in the GnuTLS plugin.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 16744
diff changeset
424 */
29942
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
425 gnutls_data->handshake_timer = purple_timeout_add(0, start_handshake_cb,
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
426 gsc);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
427 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
428
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
429 static void
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
430 ssl_gnutls_close(PurpleSslConnection *gsc)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
431 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
432 PurpleSslGnutlsData *gnutls_data = PURPLE_SSL_GNUTLS_DATA(gsc);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
433
7467
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7325
diff changeset
434 if(!gnutls_data)
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7325
diff changeset
435 return;
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7325
diff changeset
436
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
437 if(gnutls_data->handshake_handler)
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
438 purple_input_remove(gnutls_data->handshake_handler);
29942
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
439 if (gnutls_data->handshake_timer)
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29940
diff changeset
440 purple_timeout_remove(gnutls_data->handshake_timer);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
441
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
442 gnutls_bye(gnutls_data->session, GNUTLS_SHUT_RDWR);
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
443
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
444 gnutls_deinit(gnutls_data->session);
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
445
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
446 g_free(gnutls_data);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
447 gsc->private_data = NULL;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
448 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
449
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
450 static size_t
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
451 ssl_gnutls_read(PurpleSslConnection *gsc, void *data, size_t len)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
452 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
453 PurpleSslGnutlsData *gnutls_data = PURPLE_SSL_GNUTLS_DATA(gsc);
40322
3e026e7db681 Make ssl_*_read robust against bogus connection, like ssl_*_write is
Samuel Thibault <samuel.thibault@ens-lyon.org>
parents: 40238
diff changeset
454 ssize_t s = 0;
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
455
40322
3e026e7db681 Make ssl_*_read robust against bogus connection, like ssl_*_write is
Samuel Thibault <samuel.thibault@ens-lyon.org>
parents: 40238
diff changeset
456 if(gnutls_data)
3e026e7db681 Make ssl_*_read robust against bogus connection, like ssl_*_write is
Samuel Thibault <samuel.thibault@ens-lyon.org>
parents: 40238
diff changeset
457 s = gnutls_record_recv(gnutls_data->session, data, len);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
458
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
459 if(s == GNUTLS_E_AGAIN || s == GNUTLS_E_INTERRUPTED) {
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
460 s = -1;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
461 errno = EAGAIN;
36146
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
462
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
463 #ifdef GNUTLS_E_PREMATURE_TERMINATION
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
464 } else if (s == GNUTLS_E_PREMATURE_TERMINATION) {
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
465 purple_debug_warning("gnutls", "Received a FIN on the TCP socket "
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
466 "for %s. This either means that the remote server closed "
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
467 "the socket without sending us a Close Notify alert or a "
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
468 "man-in-the-middle injected a FIN into the TCP stream. "
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
469 "Assuming it's the former.\n", gsc->host);
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
470 #else
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
471 } else if (s == GNUTLS_E_UNEXPECTED_PACKET_LENGTH) {
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
472 purple_debug_warning("gnutls", "Received packet of unexpected "
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
473 "length on the TCP socket for %s. Among other "
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
474 "possibilities this might mean that the remote server "
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
475 "closed the socket without sending us a Close Notify alert. "
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
476 "Assuming that's the case for compatibility, however, note "
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
477 "that it's quite possible that we're incorrectly ignoing "
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
478 "a real error.\n", gsc->host);
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
479 #endif
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
480 /*
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
481 * Summary:
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
482 * Always treat a closed TCP connection as if the remote server cleanly
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
483 * terminated the SSL session.
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
484 *
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
485 * Background:
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
486 * Most TLS servers send a Close Notify alert before sending TCP FIN
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
487 * when closing a session. This informs us at the TLS layer that the
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
488 * connection is being cleanly closed. Without this it's more
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
489 * difficult for us to determine whether the session was closed
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
490 * cleanly (we would need to resort to having the application layer
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
491 * perform this check, e.g. by looking at the Content-Length HTTP
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
492 * header for HTTP connections).
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
493 *
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
494 * There ARE servers that don't send Close Notify and we want to be
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
495 * compatible with them. And so we don't require Close Notify. This
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
496 * seems to match the behavior of libnss. This is a slightly
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
497 * unfortunate situation. It means a malicious MITM can inject a FIN
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
498 * into our TCP stream and cause our encrypted session to termiate
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
499 * and we won't indicate any problem to the user.
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
500 *
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
501 * GnuTLS < 3.0.0 returned the UNEXPECTED_PACKET_LENGTH error on EOF.
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
502 * GnuTLS >= 3.0.0 added the PREMATURE_TERMINATION error to allow us
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
503 * to detect the problem more specifically.
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
504 *
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
505 * For historical discussion see:
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
506 * https://developer.pidgin.im/ticket/16172
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
507 * http://trac.adiumx.com/intertrac/ticket%3A16678
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
508 * https://bugzilla.mozilla.org/show_bug.cgi?id=508698#c4
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
509 * http://lists.gnu.org/archive/html/gnutls-devel/2008-03/msg00058.html
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
510 * Or search for GNUTLS_E_UNEXPECTED_PACKET_LENGTH or
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
511 * GNUTLS_E_PREMATURE_TERMINATION
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
512 */
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
513 s = 0;
42ba908c25c7 Fix Yahoo login when using the GnuTLS library for TLS connections.
Mark Doliner <mark@kingant.net>
parents: 35978
diff changeset
514
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
515 } else if(s < 0) {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
516 purple_debug_error("gnutls", "receive failed: %s\n",
15846
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
517 gnutls_strerror(s));
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
518 s = -1;
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
519 /*
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
520 * TODO: Set errno to something more appropriate. Or even
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
521 * better: allow ssl plugins to keep track of their
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
522 * own error message, then add a new ssl_ops function
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
523 * that returns the error message.
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
524 */
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
525 errno = EIO;
7834
6a092463d774 [gaim-migrate @ 8487]
Mike Hearn <mike@theoretic.com>
parents: 7631
diff changeset
526 }
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
527
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
528 return s;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
529 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
530
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
531 static size_t
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
532 ssl_gnutls_write(PurpleSslConnection *gsc, const void *data, size_t len)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
533 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
534 PurpleSslGnutlsData *gnutls_data = PURPLE_SSL_GNUTLS_DATA(gsc);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
535 ssize_t s = 0;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
536
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
537 /* XXX: when will gnutls_data be NULL? */
7467
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7325
diff changeset
538 if(gnutls_data)
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7325
diff changeset
539 s = gnutls_record_send(gnutls_data->session, data, len);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
540
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
541 if(s == GNUTLS_E_AGAIN || s == GNUTLS_E_INTERRUPTED) {
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
542 s = -1;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
543 errno = EAGAIN;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
544 } else if(s < 0) {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
545 purple_debug_error("gnutls", "send failed: %s\n",
15846
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
546 gnutls_strerror(s));
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
547 s = -1;
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
548 /*
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
549 * TODO: Set errno to something more appropriate. Or even
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
550 * better: allow ssl plugins to keep track of their
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
551 * own error message, then add a new ssl_ops function
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
552 * that returns the error message.
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
553 */
7a956b382f6c There were a few problems here
Mark Doliner <markdoliner@pidgin.im>
parents: 15435
diff changeset
554 errno = EIO;
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
555 }
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 11513
diff changeset
556
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
557 return s;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
558 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
559
19494
c9ee38003eb6 - TODO-whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19359
diff changeset
560 /* Forward declarations are fun! */
18248
8f462eaffecd - Style issues
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18247
diff changeset
561 static PurpleCertificate *
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
562 x509_import_from_datum(const gnutls_datum_t dt, gnutls_x509_crt_fmt_t mode);
31155
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
563 /* indeed! */
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
564 static gboolean
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
565 x509_certificate_signed_by(PurpleCertificate * crt,
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
566 PurpleCertificate * issuer);
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
567 static void
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
568 x509_destroy_certificate(PurpleCertificate * crt);
17510
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
569
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
570 static GList *
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
571 ssl_gnutls_get_peer_certificates(PurpleSslConnection * gsc)
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
572 {
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
573 PurpleSslGnutlsData *gnutls_data = PURPLE_SSL_GNUTLS_DATA(gsc);
31155
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
574 PurpleCertificate *prvcrt = NULL;
17510
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
575
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
576 /* List of Certificate instances to return */
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
577 GList * peer_certs = NULL;
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
578
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
579 /* List of raw certificates as given by GnuTLS */
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
580 const gnutls_datum_t *cert_list;
17510
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
581 unsigned int cert_list_size = 0;
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
582
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
583 unsigned int i;
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
584
17510
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
585 /* This should never, ever happen. */
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
586 g_return_val_if_fail( gnutls_certificate_type_get (gnutls_data->session) == GNUTLS_CRT_X509, NULL);
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
587
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
588 /* Get the certificate list from GnuTLS */
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
589 /* TODO: I am _pretty sure_ this doesn't block or do other exciting things */
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
590 cert_list = gnutls_certificate_get_peers(gnutls_data->session,
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
591 &cert_list_size);
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
592
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
593 /* Convert each certificate to a Certificate and append it to the list */
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
594 for (i = 0; i < cert_list_size; i++) {
18248
8f462eaffecd - Style issues
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18247
diff changeset
595 PurpleCertificate * newcrt = x509_import_from_datum(cert_list[i],
18245
2ddae03c3c9e - Add a mode switch to allow DER or PEM imports (necessary because SSL certs
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17510
diff changeset
596 GNUTLS_X509_FMT_DER);
17510
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
597 /* Append is somewhat inefficient on linked lists, but is easy
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
598 to read. If someone complains, I'll change it.
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
599 TODO: Is anyone complaining? (Maybe elb?) */
31155
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
600 /* only append if previous cert was actually signed by this one.
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
601 * Thanks Microsoft. */
37837
d6fc1ce76ffe ssl-gnutls: Fix error handling of x509_import_from_datum
dx <dx@dxzone.com.ar>
parents: 36256
diff changeset
602 if ((newcrt != NULL) && ((prvcrt == NULL) || x509_certificate_signed_by(prvcrt, newcrt))) {
31155
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
603 peer_certs = g_list_append(peer_certs, newcrt);
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
604 prvcrt = newcrt;
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
605 } else {
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
606 x509_destroy_certificate(newcrt);
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
607 purple_debug_error("gnutls", "Dropping further peer certificates "
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
608 "because the chain is broken!\n");
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
609 break;
757baa7d408f Apply Stu's specific certificate changes listed below to the 2.7.7 branch.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 29942
diff changeset
610 }
17510
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
611 }
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
612
19494
c9ee38003eb6 - TODO-whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19359
diff changeset
613 /* cert_list doesn't need free()-ing */
17510
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
614
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
615 return peer_certs;
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
616 }
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
617
17509
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
618 /************************************************************************/
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
619 /* X.509 functionality */
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
620 /************************************************************************/
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
621 const gchar * SCHEME_NAME = "x509";
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
622
18248
8f462eaffecd - Style issues
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18247
diff changeset
623 static PurpleCertificateScheme x509_gnutls;
17509
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
624
18652
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
625 /** Refcounted GnuTLS certificate data instance */
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
626 typedef struct {
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
627 gint refcount;
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
628 gnutls_x509_crt_t crt;
18652
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
629 } x509_crtdata_t;
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
630
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
631 /** Helper functions for reference counting */
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
632 static x509_crtdata_t *
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
633 x509_crtdata_addref(x509_crtdata_t *cd)
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
634 {
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
635 (cd->refcount)++;
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
636 return cd;
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
637 }
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
638
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
639 static void
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
640 x509_crtdata_delref(x509_crtdata_t *cd)
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
641 {
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
642 (cd->refcount)--;
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
643
19714
b424012723a8 refcount of 0 is normal
Mark Doliner <markdoliner@pidgin.im>
parents: 19713
diff changeset
644 if (cd->refcount < 0)
19713
d0456ce4f4e9 Replace a call to g_assert() with a logging statement
Mark Doliner <markdoliner@pidgin.im>
parents: 19712
diff changeset
645 g_critical("Refcount of x509_crtdata_t is %d, which is less "
d0456ce4f4e9 Replace a call to g_assert() with a logging statement
Mark Doliner <markdoliner@pidgin.im>
parents: 19712
diff changeset
646 "than zero!\n", cd->refcount);
d0456ce4f4e9 Replace a call to g_assert() with a logging statement
Mark Doliner <markdoliner@pidgin.im>
parents: 19712
diff changeset
647
18652
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
648 /* If the refcount reaches zero, kill the structure */
19713
d0456ce4f4e9 Replace a call to g_assert() with a logging statement
Mark Doliner <markdoliner@pidgin.im>
parents: 19712
diff changeset
649 if (cd->refcount <= 0) {
18652
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
650 /* Kill the internal data */
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
651 gnutls_x509_crt_deinit( cd->crt );
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
652 /* And kill the struct */
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
653 g_free( cd );
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
654 }
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
655 }
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
656
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
657 /** Helper macro to retrieve the GnuTLS crt_t from a PurpleCertificate */
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
658 #define X509_GET_GNUTLS_DATA(pcrt) ( ((x509_crtdata_t *) (pcrt->data))->crt)
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
659
20174
dc85e2b0d3da applied changes from 8b8bc5b1ef1263e1c0f00a9ed208accff09d988e
Richard Laager <rlaager@pidgin.im>
parents: 20151
diff changeset
660 /** Transforms a gnutls_datum containing an X.509 certificate into a Certificate instance under the x509_gnutls scheme
17510
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
661 *
18245
2ddae03c3c9e - Add a mode switch to allow DER or PEM imports (necessary because SSL certs
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17510
diff changeset
662 * @param dt Datum to transform
2ddae03c3c9e - Add a mode switch to allow DER or PEM imports (necessary because SSL certs
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17510
diff changeset
663 * @param mode GnuTLS certificate format specifier (GNUTLS_X509_FMT_PEM for
2ddae03c3c9e - Add a mode switch to allow DER or PEM imports (necessary because SSL certs
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17510
diff changeset
664 * reading from files, and GNUTLS_X509_FMT_DER for converting
2ddae03c3c9e - Add a mode switch to allow DER or PEM imports (necessary because SSL certs
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17510
diff changeset
665 * "over the wire" certs for SSL)
17510
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
666 *
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
667 * @return A newly allocated Certificate structure of the x509_gnutls scheme
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
668 */
18248
8f462eaffecd - Style issues
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18247
diff changeset
669 static PurpleCertificate *
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
670 x509_import_from_datum(const gnutls_datum_t dt, gnutls_x509_crt_fmt_t mode)
17510
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
671 {
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
672 /* Internal certificate data structure */
18652
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
673 x509_crtdata_t *certdat;
17510
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
674 /* New certificate to return */
18248
8f462eaffecd - Style issues
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18247
diff changeset
675 PurpleCertificate * crt;
17510
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
676
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
677 /* Allocate and prepare the internal certificate data */
18652
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
678 certdat = g_new0(x509_crtdata_t, 1);
37837
d6fc1ce76ffe ssl-gnutls: Fix error handling of x509_import_from_datum
dx <dx@dxzone.com.ar>
parents: 36256
diff changeset
679 if (gnutls_x509_crt_init(&(certdat->crt)) != 0) {
d6fc1ce76ffe ssl-gnutls: Fix error handling of x509_import_from_datum
dx <dx@dxzone.com.ar>
parents: 36256
diff changeset
680 g_free(certdat);
d6fc1ce76ffe ssl-gnutls: Fix error handling of x509_import_from_datum
dx <dx@dxzone.com.ar>
parents: 36256
diff changeset
681 return NULL;
d6fc1ce76ffe ssl-gnutls: Fix error handling of x509_import_from_datum
dx <dx@dxzone.com.ar>
parents: 36256
diff changeset
682 }
18652
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
683 certdat->refcount = 0;
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
684
17510
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
685 /* Perform the actual certificate parse */
18652
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
686 /* Yes, certdat->crt should be passed as-is */
37837
d6fc1ce76ffe ssl-gnutls: Fix error handling of x509_import_from_datum
dx <dx@dxzone.com.ar>
parents: 36256
diff changeset
687 if (gnutls_x509_crt_import(certdat->crt, &dt, mode) != 0) {
d6fc1ce76ffe ssl-gnutls: Fix error handling of x509_import_from_datum
dx <dx@dxzone.com.ar>
parents: 36256
diff changeset
688 g_free(certdat);
d6fc1ce76ffe ssl-gnutls: Fix error handling of x509_import_from_datum
dx <dx@dxzone.com.ar>
parents: 36256
diff changeset
689 return NULL;
d6fc1ce76ffe ssl-gnutls: Fix error handling of x509_import_from_datum
dx <dx@dxzone.com.ar>
parents: 36256
diff changeset
690 }
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
691
17510
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
692 /* Allocate the certificate and load it with data */
18480
42936c867fee - More g_new0 instead of g_new
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18475
diff changeset
693 crt = g_new0(PurpleCertificate, 1);
17510
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
694 crt->scheme = &x509_gnutls;
18652
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
695 crt->data = x509_crtdata_addref(certdat);
17510
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
696
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
697 return crt;
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
698 }
b9314561d25a - Wrote GnuTLS get_peer_certificates function
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17509
diff changeset
699
17509
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
700 /** Imports a PEM-formatted X.509 certificate from the specified file.
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
701 * @param filename Filename to import from. Format is PEM
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
702 *
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
703 * @return A newly allocated Certificate structure of the x509_gnutls scheme
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
704 */
18248
8f462eaffecd - Style issues
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18247
diff changeset
705 static PurpleCertificate *
17509
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
706 x509_import_from_file(const gchar * filename)
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
707 {
18248
8f462eaffecd - Style issues
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18247
diff changeset
708 PurpleCertificate *crt; /* Certificate being constructed */
17509
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
709 gchar *buf; /* Used to load the raw file data */
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
710 gsize buf_sz; /* Size of the above */
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
711 gnutls_datum_t dt; /* Struct to pass down to GnuTLS */
17509
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
712
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
713 purple_debug_info("gnutls",
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
714 "Attempting to load X.509 certificate from %s\n",
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
715 filename);
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
716
17509
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
717 /* Next, we'll simply yank the entire contents of the file
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
718 into memory */
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
719 /* TODO: Should I worry about very large files here? */
39634
8324458e98f8 fix coding style in previous assert macros commit
Fabrice Bellet <fabrice@bellet.info>
parents: 39632
diff changeset
720 if (!g_file_get_contents(filename,
39632
06b9049c1914 gnutls: assert macros must only contain assertions
Fabrice Bellet <fabrice@bellet.info>
parents: 38256
diff changeset
721 &buf,
06b9049c1914 gnutls: assert macros must only contain assertions
Fabrice Bellet <fabrice@bellet.info>
parents: 38256
diff changeset
722 &buf_sz,
06b9049c1914 gnutls: assert macros must only contain assertions
Fabrice Bellet <fabrice@bellet.info>
parents: 38256
diff changeset
723 NULL /* No error checking for now */
39634
8324458e98f8 fix coding style in previous assert macros commit
Fabrice Bellet <fabrice@bellet.info>
parents: 39632
diff changeset
724 )) {
39632
06b9049c1914 gnutls: assert macros must only contain assertions
Fabrice Bellet <fabrice@bellet.info>
parents: 38256
diff changeset
725 return NULL;
39634
8324458e98f8 fix coding style in previous assert macros commit
Fabrice Bellet <fabrice@bellet.info>
parents: 39632
diff changeset
726 }
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
727
17509
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
728 /* Load the datum struct */
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
729 dt.data = (unsigned char *) buf;
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
730 dt.size = buf_sz;
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
731
21720
235394d5c7f4 Pull a bunch of bugfix only changes to im.pidgin.pidgin.2.3.1,
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 20288
diff changeset
732 /* Perform the conversion; files should be in PEM format */
235394d5c7f4 Pull a bunch of bugfix only changes to im.pidgin.pidgin.2.3.1,
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 20288
diff changeset
733 crt = x509_import_from_datum(dt, GNUTLS_X509_FMT_PEM);
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
734
17509
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
735 /* Cleanup */
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
736 g_free(buf);
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
737
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
738 return crt;
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
739 }
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
740
29930
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
741 /** Imports a number of PEM-formatted X.509 certificates from the specified file.
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
742 * @param filename Filename to import from. Format is PEM
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
743 *
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
744 * @return A newly allocated GSList of Certificate structures of the x509_gnutls scheme
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
745 */
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
746 static GSList *
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
747 x509_importcerts_from_file(const gchar * filename)
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
748 {
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
749 PurpleCertificate *crt; /* Certificate being constructed */
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
750 gchar *buf; /* Used to load the raw file data */
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
751 gchar *begin, *end;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
752 GSList *crts = NULL;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
753 gsize buf_sz; /* Size of the above */
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
754 gnutls_datum_t dt; /* Struct to pass down to GnuTLS */
29930
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
755
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
756 purple_debug_info("gnutls",
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
757 "Attempting to load X.509 certificates from %s\n",
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
758 filename);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
759
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
760 /* Next, we'll simply yank the entire contents of the file
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
761 into memory */
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
762 /* TODO: Should I worry about very large files here? */
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
763 g_return_val_if_fail(
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
764 g_file_get_contents(filename,
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
765 &buf,
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
766 &buf_sz,
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
767 NULL /* No error checking for now */
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
768 ),
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
769 NULL);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
770
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
771 begin = buf;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
772 while((end = strstr(begin, "-----END CERTIFICATE-----")) != NULL) {
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
773 end += sizeof("-----END CERTIFICATE-----")-1;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
774 /* Load the datum struct */
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
775 dt.data = (unsigned char *) begin;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
776 dt.size = (end-begin);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
777
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
778 /* Perform the conversion; files should be in PEM format */
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
779 crt = x509_import_from_datum(dt, GNUTLS_X509_FMT_PEM);
37837
d6fc1ce76ffe ssl-gnutls: Fix error handling of x509_import_from_datum
dx <dx@dxzone.com.ar>
parents: 36256
diff changeset
780 if (crt != NULL) {
d6fc1ce76ffe ssl-gnutls: Fix error handling of x509_import_from_datum
dx <dx@dxzone.com.ar>
parents: 36256
diff changeset
781 crts = g_slist_prepend(crts, crt);
d6fc1ce76ffe ssl-gnutls: Fix error handling of x509_import_from_datum
dx <dx@dxzone.com.ar>
parents: 36256
diff changeset
782 }
29930
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
783 begin = end;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
784 }
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
785
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
786 /* Cleanup */
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
787 g_free(buf);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
788
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
789 return crts;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
790 }
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
791
18496
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
792 /**
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
793 * Exports a PEM-formatted X.509 certificate to the specified file.
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
794 * @param filename Filename to export to. Format will be PEM
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
795 * @param crt Certificate to export
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
796 *
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
797 * @return TRUE if success, otherwise FALSE
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
798 */
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
799 static gboolean
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
800 x509_export_certificate(const gchar *filename, PurpleCertificate *crt)
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
801 {
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
802 gnutls_x509_crt_t crt_dat; /* GnuTLS cert struct */
18496
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
803 int ret;
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
804 gchar * out_buf; /* Data to output */
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
805 size_t out_size; /* Output size */
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
806 gboolean success = FALSE;
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
807
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
808 /* Paranoia paranoia paranoia! */
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
809 g_return_val_if_fail(filename, FALSE);
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
810 g_return_val_if_fail(crt, FALSE);
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
811 g_return_val_if_fail(crt->scheme == &x509_gnutls, FALSE);
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
812 g_return_val_if_fail(crt->data, FALSE);
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
813
18652
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
814 crt_dat = X509_GET_GNUTLS_DATA(crt);
18496
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
815
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
816 /* Obtain the output size required */
18593
9d2bd532bf74 - Fix intermittent crash due to uninitialized variable
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18592
diff changeset
817 out_size = 0;
18496
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
818 ret = gnutls_x509_crt_export(crt_dat, GNUTLS_X509_FMT_PEM,
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
819 NULL, /* Provide no buffer yet */
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
820 &out_size /* Put size here */
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
821 );
18591
9d7c99e312b9 - Fix an incorrect assertion in GnuTLS plugin
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18496
diff changeset
822 g_return_val_if_fail(ret == GNUTLS_E_SHORT_MEMORY_BUFFER, FALSE);
18496
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
823
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
824 /* Now allocate a buffer and *really* export it */
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
825 out_buf = g_new0(gchar, out_size);
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
826 ret = gnutls_x509_crt_export(crt_dat, GNUTLS_X509_FMT_PEM,
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
827 out_buf, /* Export to our new buffer */
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
828 &out_size /* Put size here */
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
829 );
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
830 if (ret != 0) {
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
831 purple_debug_error("gnutls/x509",
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
832 "Failed to export cert to buffer with code %d\n",
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
833 ret);
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
834 g_free(out_buf);
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
835 return FALSE;
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
836 }
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
837
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
838 /* Write it out to an actual file */
19501
4c14c89dcf02 - Add purple_util_write_data_to_file_absolute; glib's
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19497
diff changeset
839 success = purple_util_write_data_to_file_absolute(filename,
4c14c89dcf02 - Add purple_util_write_data_to_file_absolute; glib's
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19497
diff changeset
840 out_buf, out_size);
18496
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
841
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
842 g_free(out_buf);
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
843 return success;
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
844 }
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
845
18654
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
846 static PurpleCertificate *
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
847 x509_copy_certificate(PurpleCertificate *crt)
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
848 {
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
849 x509_crtdata_t *crtdat;
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
850 PurpleCertificate *newcrt;
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
851
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
852 g_return_val_if_fail(crt, NULL);
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
853 g_return_val_if_fail(crt->scheme == &x509_gnutls, NULL);
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
854
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
855 crtdat = (x509_crtdata_t *) crt->data;
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
856
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
857 newcrt = g_new0(PurpleCertificate, 1);
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
858 newcrt->scheme = &x509_gnutls;
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
859 newcrt->data = x509_crtdata_addref(crtdat);
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
860
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
861 return newcrt;
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
862 }
17509
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
863 /** Frees a Certificate
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
864 *
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
865 * Destroys a Certificate's internal data structures and frees the pointer
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
866 * given.
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
867 * @param crt Certificate instance to be destroyed. It WILL NOT be destroyed
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
868 * if it is not of the correct CertificateScheme. Can be NULL
17509
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
869 *
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
870 */
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
871 static void
18248
8f462eaffecd - Style issues
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18247
diff changeset
872 x509_destroy_certificate(PurpleCertificate * crt)
17509
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
873 {
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
874 if (NULL == crt) return;
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
875
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
876 /* Check that the scheme is x509_gnutls */
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
877 if ( crt->scheme != &x509_gnutls ) {
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
878 purple_debug_error("gnutls",
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
879 "destroy_certificate attempted on certificate of wrong scheme (scheme was %s, expected %s)\n",
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
880 crt->scheme->name,
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
881 SCHEME_NAME);
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
882 return;
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
883 }
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
884
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
885 g_return_if_fail(crt->data != NULL);
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
886 g_return_if_fail(crt->scheme != NULL);
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
887
18652
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
888 /* Use the reference counting system to free (or not) the
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
889 underlying data */
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
890 x509_crtdata_delref((x509_crtdata_t *)crt->data);
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
891
17509
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
892 /* Kill the structure itself */
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
893 g_free(crt);
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
894 }
fa009823dbfd - Exposed the _Certificate struct definition in certificate.h
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17507
diff changeset
895
18250
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
896 /** Determines whether one certificate has been issued and signed by another
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
897 *
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
898 * @param crt Certificate to check the signature of
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
899 * @param issuer Issuer's certificate
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
900 *
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
901 * @return TRUE if crt was signed and issued by issuer, otherwise FALSE
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
902 * @TODO Modify this function to return a reason for invalidity?
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
903 */
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
904 static gboolean
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
905 x509_certificate_signed_by(PurpleCertificate * crt,
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
906 PurpleCertificate * issuer)
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
907 {
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
908 gnutls_x509_crt_t crt_dat;
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
909 gnutls_x509_crt_t issuer_dat;
19353
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
910 unsigned int verify; /* used to store result from GnuTLS verifier */
18250
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
911 int ret;
27917
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
912 gchar *crt_id = NULL;
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
913 gchar *issuer_id = NULL;
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
914
18250
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
915 g_return_val_if_fail(crt, FALSE);
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
916 g_return_val_if_fail(issuer, FALSE);
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
917
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
918 /* Verify that both certs are the correct scheme */
18482
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
919 g_return_val_if_fail(crt->scheme == &x509_gnutls, FALSE);
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
920 g_return_val_if_fail(issuer->scheme == &x509_gnutls, FALSE);
18250
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
921
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
922 /* TODO: check for more nullness? */
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
923
18652
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
924 crt_dat = X509_GET_GNUTLS_DATA(crt);
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
925 issuer_dat = X509_GET_GNUTLS_DATA(issuer);
18250
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
926
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
927 /* Ensure crt issuer matches the name on the issuer cert. */
18250
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
928 ret = gnutls_x509_crt_check_issuer(crt_dat, issuer_dat);
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
929 if (ret <= 0) {
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
930
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
931 if (ret < 0) {
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
932 purple_debug_error("gnutls/x509",
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
933 "GnuTLS error %d while checking certificate issuer match.",
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
934 ret);
19353
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
935 } else {
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
936 gchar *crt_id, *issuer_id, *crt_issuer_id;
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
937 crt_id = purple_certificate_get_unique_id(crt);
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
938 issuer_id = purple_certificate_get_unique_id(issuer);
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
939 crt_issuer_id =
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
940 purple_certificate_get_issuer_unique_id(crt);
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
941 purple_debug_info("gnutls/x509",
28655
69e23620d813 ssl-gnutls: I think this error message makes a little more sense.
Paul Aurich <darkrain42@pidgin.im>
parents: 28652
diff changeset
942 "Certificate %s is issued by "
69e23620d813 ssl-gnutls: I think this error message makes a little more sense.
Paul Aurich <darkrain42@pidgin.im>
parents: 28652
diff changeset
943 "%s, which does not match %s.\n",
20177
92af9f603b75 applied changes from f143c30a12f30c53e017f1bfc22ccddee96036fc
Richard Laager <rlaager@pidgin.im>
parents: 20176
diff changeset
944 crt_id ? crt_id : "(null)",
92af9f603b75 applied changes from f143c30a12f30c53e017f1bfc22ccddee96036fc
Richard Laager <rlaager@pidgin.im>
parents: 20176
diff changeset
945 crt_issuer_id ? crt_issuer_id : "(null)",
92af9f603b75 applied changes from f143c30a12f30c53e017f1bfc22ccddee96036fc
Richard Laager <rlaager@pidgin.im>
parents: 20176
diff changeset
946 issuer_id ? issuer_id : "(null)");
19353
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
947 g_free(crt_id);
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
948 g_free(issuer_id);
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
949 g_free(crt_issuer_id);
18250
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
950 }
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
951
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
952 /* The issuer is not correct, or there were errors */
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
953 return FALSE;
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
954 }
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
955
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
956 /* Check basic constraints extension (if it exists then the CA flag must
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
957 be set to true, and it must exist for certs with version 3 or higher. */
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
958 ret = gnutls_x509_crt_get_basic_constraints(issuer_dat, NULL, NULL, NULL);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
959 if (ret == GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
960 if (gnutls_x509_crt_get_version(issuer_dat) >= 3) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
961 /* Reject cert (no basic constraints and cert version is >= 3). */
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
962 gchar *issuer_id = purple_certificate_get_unique_id(issuer);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
963 purple_debug_info("gnutls/x509", "Rejecting cert because the "
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
964 "basic constraints extension is missing from issuer cert "
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
965 "for %s. The basic constraints extension is required on "
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
966 "all version 3 or higher certs (this cert is version %d).",
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
967 issuer_id ? issuer_id : "(null)",
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
968 gnutls_x509_crt_get_version(issuer_dat));
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
969 g_free(issuer_id);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
970 return FALSE;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
971 } else {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
972 /* Allow cert (no basic constraints and cert version is < 3). */
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
973 purple_debug_info("gnutls/x509", "Basic constraint extension is "
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
974 "missing from issuer cert for %s. Allowing this because "
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
975 "the cert is version %d and the basic constraints "
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
976 "extension is only required for version 3 or higher "
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
977 "certs.", issuer_id ? issuer_id : "(null)",
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
978 gnutls_x509_crt_get_version(issuer_dat));
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
979 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
980 } else if (ret <= 0) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
981 /* Reject cert (CA flag is false in basic constraints). */
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
982 gchar *issuer_id = purple_certificate_get_unique_id(issuer);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
983 purple_debug_info("gnutls/x509", "Rejecting cert because the CA flag "
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
984 "is set to false in the basic constraints extension for "
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
985 "issuer cert %s. ret=%d\n",
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
986 issuer_id ? issuer_id : "(null)", ret);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
987 g_free(issuer_id);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
988 return FALSE;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
989 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36146
diff changeset
990
18250
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
991 /* Now, check the signature */
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
992 /* The second argument is a ptr to an array of "trusted" issuer certs,
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
993 but we're only using one trusted one */
19359
8961d49b1b87 - x509_signed_by now accepts a signature by an X.509 version 1
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19356
diff changeset
994 ret = gnutls_x509_crt_verify(crt_dat, &issuer_dat, 1,
8961d49b1b87 - x509_signed_by now accepts a signature by an X.509 version 1
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19356
diff changeset
995 /* Permit signings by X.509v1 certs
8961d49b1b87 - x509_signed_by now accepts a signature by an X.509 version 1
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19356
diff changeset
996 (Verisign and possibly others have
8961d49b1b87 - x509_signed_by now accepts a signature by an X.509 version 1
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19356
diff changeset
997 root certificates that predate the
8961d49b1b87 - x509_signed_by now accepts a signature by an X.509 version 1
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19356
diff changeset
998 current standard) */
8961d49b1b87 - x509_signed_by now accepts a signature by an X.509 version 1
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19356
diff changeset
999 GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT,
8961d49b1b87 - x509_signed_by now accepts a signature by an X.509 version 1
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19356
diff changeset
1000 &verify);
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
1001
19353
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
1002 if (ret != 0) {
18250
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
1003 purple_debug_error("gnutls/x509",
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
1004 "Attempted certificate verification caused a GnuTLS error code %d. I will just say the signature is bad, but you should look into this.\n", ret);
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
1005 return FALSE;
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
1006 }
19353
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
1007
28652
46da88b82471 Check the GnuTLS version before using a recent-ish flag. Fixes #10412.
Paul Aurich <darkrain42@pidgin.im>
parents: 27917
diff changeset
1008 #ifdef HAVE_GNUTLS_CERT_INSECURE_ALGORITHM
27917
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1009 if (verify & GNUTLS_CERT_INSECURE_ALGORITHM) {
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1010 /*
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1011 * A certificate in the chain is signed with an insecure
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1012 * algorithm. Put a warning into the log to make this error
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1013 * perfectly clear as soon as someone looks at the debug log is
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1014 * generated.
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1015 */
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1016 crt_id = purple_certificate_get_unique_id(crt);
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1017 issuer_id = purple_certificate_get_issuer_unique_id(crt);
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1018 purple_debug_warning("gnutls/x509",
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1019 "Insecure hash algorithm used by %s to sign %s\n",
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1020 issuer_id, crt_id);
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1021 }
28652
46da88b82471 Check the GnuTLS version before using a recent-ish flag. Fixes #10412.
Paul Aurich <darkrain42@pidgin.im>
parents: 27917
diff changeset
1022 #endif
27917
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1023
19353
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
1024 if (verify & GNUTLS_CERT_INVALID) {
18250
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
1025 /* Signature didn't check out, but at least
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
1026 there were no errors*/
27917
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1027 if (!crt_id)
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1028 crt_id = purple_certificate_get_unique_id(crt);
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1029 if (!issuer_id)
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1030 issuer_id = purple_certificate_get_issuer_unique_id(crt);
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1031 purple_debug_error("gnutls/x509",
e52e7ddb0cb2 Add a debug log message when MD5 is used in a verification chain. Refs #4458.
Paul Aurich <darkrain42@pidgin.im>
parents: 27407
diff changeset
1032 "Bad signature from %s on %s\n",
19353
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
1033 issuer_id, crt_id);
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
1034 g_free(crt_id);
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
1035 g_free(issuer_id);
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
1036
18250
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
1037 return FALSE;
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
1038 } /* if (ret, etc.) */
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
1039
19353
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
1040 /* If we got here, the signature is good */
bf6a0230d8e7 - Fix x509_signed_by. Apparently I can't read documentation.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19019
diff changeset
1041 return TRUE;
18250
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
1042 }
d7663374e33d - Add x509_certificate_signed_by, which checks a signature on a certificate made by an issuer
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18248
diff changeset
1043
18455
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1044 static GByteArray *
38214
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1045 x509_shasum(PurpleCertificate *crt, gnutls_digest_algorithm_t algo)
18455
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1046 {
38214
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1047 size_t hashlen = (algo == GNUTLS_DIG_SHA1) ? 20 : 32;
18455
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1048 size_t tmpsz = hashlen; /* Throw-away variable for GnuTLS to stomp on*/
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
1049 gnutls_x509_crt_t crt_dat;
18455
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1050 GByteArray *hash; /**< Final hash container */
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1051 guchar hashbuf[hashlen]; /**< Temporary buffer to contain hash */
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1052
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1053 g_return_val_if_fail(crt, NULL);
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1054
18652
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
1055 crt_dat = X509_GET_GNUTLS_DATA(crt);
18455
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1056
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1057 /* Extract the fingerprint */
19495
af7b321844ab - More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19494
diff changeset
1058 g_return_val_if_fail(
38214
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1059 0 == gnutls_x509_crt_get_fingerprint(crt_dat, algo,
19495
af7b321844ab - More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19494
diff changeset
1060 hashbuf, &tmpsz),
af7b321844ab - More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19494
diff changeset
1061 NULL);
18455
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1062
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1063 /* This shouldn't happen */
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1064 g_return_val_if_fail(tmpsz == hashlen, NULL);
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
1065
18455
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1066 /* Okay, now create and fill hash array */
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1067 hash = g_byte_array_new();
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1068 g_byte_array_append(hash, hashbuf, hashlen);
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1069
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1070 return hash;
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1071 }
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1072
38214
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1073 static GByteArray *
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1074 x509_sha1sum(PurpleCertificate *crt)
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1075 {
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1076 return x509_shasum(crt, GNUTLS_DIG_SHA1);
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1077 }
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1078
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1079 static GByteArray *
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1080 x509_sha256sum(PurpleCertificate *crt)
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1081 {
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1082 return x509_shasum(crt, GNUTLS_DIG_SHA256);
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1083 }
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1084
18482
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1085 static gchar *
19019
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1086 x509_cert_dn (PurpleCertificate *crt)
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1087 {
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
1088 gnutls_x509_crt_t cert_dat;
19019
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1089 gchar *dn = NULL;
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1090 size_t dn_size;
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1091
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1092 g_return_val_if_fail(crt, NULL);
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1093 g_return_val_if_fail(crt->scheme == &x509_gnutls, NULL);
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1094
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1095 cert_dat = X509_GET_GNUTLS_DATA(crt);
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1096
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1097 /* Figure out the length of the Distinguished Name */
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1098 /* Claim that the buffer is size 0 so GnuTLS just tells us how much
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1099 space it needs */
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1100 dn_size = 0;
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1101 gnutls_x509_crt_get_dn(cert_dat, dn, &dn_size);
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1102
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1103 /* Now allocate and get the Distinguished Name */
20175
0785c8f62a58 applied changes from 38a516984dfbc8fb0def05acb69fc1180ec0b971
Richard Laager <rlaager@pidgin.im>
parents: 20174
diff changeset
1104 /* Old versions of GnuTLS have an off-by-one error in reporting
0785c8f62a58 applied changes from 38a516984dfbc8fb0def05acb69fc1180ec0b971
Richard Laager <rlaager@pidgin.im>
parents: 20174
diff changeset
1105 the size of the needed buffer in some functions, so allocate
0785c8f62a58 applied changes from 38a516984dfbc8fb0def05acb69fc1180ec0b971
Richard Laager <rlaager@pidgin.im>
parents: 20174
diff changeset
1106 an extra byte */
0785c8f62a58 applied changes from 38a516984dfbc8fb0def05acb69fc1180ec0b971
Richard Laager <rlaager@pidgin.im>
parents: 20174
diff changeset
1107 dn = g_new0(gchar, ++dn_size);
19496
648d59dc3bfa - Errorchecking in x509_cert_dn
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19495
diff changeset
1108 if (0 != gnutls_x509_crt_get_dn(cert_dat, dn, &dn_size)) {
648d59dc3bfa - Errorchecking in x509_cert_dn
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19495
diff changeset
1109 purple_debug_error("gnutls/x509",
648d59dc3bfa - Errorchecking in x509_cert_dn
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19495
diff changeset
1110 "Failed to get Distinguished Name\n");
648d59dc3bfa - Errorchecking in x509_cert_dn
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19495
diff changeset
1111 g_free(dn);
648d59dc3bfa - Errorchecking in x509_cert_dn
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19495
diff changeset
1112 return NULL;
648d59dc3bfa - Errorchecking in x509_cert_dn
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19495
diff changeset
1113 }
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
1114
19019
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1115 return dn;
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1116 }
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1117
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1118 static gchar *
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1119 x509_issuer_dn (PurpleCertificate *crt)
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1120 {
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
1121 gnutls_x509_crt_t cert_dat;
19019
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1122 gchar *dn = NULL;
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1123 size_t dn_size;
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1124
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1125 g_return_val_if_fail(crt, NULL);
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1126 g_return_val_if_fail(crt->scheme == &x509_gnutls, NULL);
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1127
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1128 cert_dat = X509_GET_GNUTLS_DATA(crt);
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1129
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1130 /* Figure out the length of the Distinguished Name */
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1131 /* Claim that the buffer is size 0 so GnuTLS just tells us how much
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1132 space it needs */
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1133 dn_size = 0;
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1134 gnutls_x509_crt_get_issuer_dn(cert_dat, dn, &dn_size);
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1135
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1136 /* Now allocate and get the Distinguished Name */
20175
0785c8f62a58 applied changes from 38a516984dfbc8fb0def05acb69fc1180ec0b971
Richard Laager <rlaager@pidgin.im>
parents: 20174
diff changeset
1137 /* Old versions of GnuTLS have an off-by-one error in reporting
0785c8f62a58 applied changes from 38a516984dfbc8fb0def05acb69fc1180ec0b971
Richard Laager <rlaager@pidgin.im>
parents: 20174
diff changeset
1138 the size of the needed buffer in some functions, so allocate
0785c8f62a58 applied changes from 38a516984dfbc8fb0def05acb69fc1180ec0b971
Richard Laager <rlaager@pidgin.im>
parents: 20174
diff changeset
1139 an extra byte */
0785c8f62a58 applied changes from 38a516984dfbc8fb0def05acb69fc1180ec0b971
Richard Laager <rlaager@pidgin.im>
parents: 20174
diff changeset
1140 dn = g_new0(gchar, ++dn_size);
19497
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1141 if (0 != gnutls_x509_crt_get_issuer_dn(cert_dat, dn, &dn_size)) {
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1142 purple_debug_error("gnutls/x509",
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1143 "Failed to get issuer's Distinguished "
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1144 "Name\n");
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1145 g_free(dn);
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1146 return NULL;
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1147 }
19712
658159391efc Get rid of some stray whitespace and consistently use tab indentation
Mark Doliner <markdoliner@pidgin.im>
parents: 19711
diff changeset
1148
19019
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1149 return dn;
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1150 }
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1151
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1152 static gchar *
18482
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1153 x509_common_name (PurpleCertificate *crt)
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1154 {
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
1155 gnutls_x509_crt_t cert_dat;
18482
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1156 gchar *cn = NULL;
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1157 size_t cn_size;
19497
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1158 int ret;
18482
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1159
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1160 g_return_val_if_fail(crt, NULL);
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1161 g_return_val_if_fail(crt->scheme == &x509_gnutls, NULL);
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1162
18652
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
1163 cert_dat = X509_GET_GNUTLS_DATA(crt);
18482
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1164
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1165 /* Figure out the length of the Common Name */
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1166 /* Claim that the buffer is size 0 so GnuTLS just tells us how much
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1167 space it needs */
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1168 cn_size = 0;
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1169 gnutls_x509_crt_get_dn_by_oid(cert_dat,
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1170 GNUTLS_OID_X520_COMMON_NAME,
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1171 0, /* First CN found, please */
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1172 0, /* Not in raw mode */
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1173 cn, &cn_size);
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1174
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1175 /* Now allocate and get the Common Name */
20175
0785c8f62a58 applied changes from 38a516984dfbc8fb0def05acb69fc1180ec0b971
Richard Laager <rlaager@pidgin.im>
parents: 20174
diff changeset
1176 /* Old versions of GnuTLS have an off-by-one error in reporting
0785c8f62a58 applied changes from 38a516984dfbc8fb0def05acb69fc1180ec0b971
Richard Laager <rlaager@pidgin.im>
parents: 20174
diff changeset
1177 the size of the needed buffer in some functions, so allocate
0785c8f62a58 applied changes from 38a516984dfbc8fb0def05acb69fc1180ec0b971
Richard Laager <rlaager@pidgin.im>
parents: 20174
diff changeset
1178 an extra byte */
0785c8f62a58 applied changes from 38a516984dfbc8fb0def05acb69fc1180ec0b971
Richard Laager <rlaager@pidgin.im>
parents: 20174
diff changeset
1179 cn = g_new0(gchar, ++cn_size);
19497
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1180 ret = gnutls_x509_crt_get_dn_by_oid(cert_dat,
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1181 GNUTLS_OID_X520_COMMON_NAME,
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1182 0, /* First CN found, please */
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1183 0, /* Not in raw mode */
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1184 cn, &cn_size);
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1185 if (ret != 0) {
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1186 purple_debug_error("gnutls/x509",
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1187 "Failed to get Common Name\n");
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1188 g_free(cn);
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1189 return NULL;
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1190 }
9766bb35cc02 - Yet More TODO whacking
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19496
diff changeset
1191
18482
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1192 return cn;
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1193 }
be73de06d821 - Add subject_name (AKA Common Name) functions to GnuTLS x509 scheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18480
diff changeset
1194
18643
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1195 static gboolean
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1196 x509_check_name (PurpleCertificate *crt, const gchar *name)
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1197 {
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
1198 gnutls_x509_crt_t crt_dat;
18643
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1199
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1200 g_return_val_if_fail(crt, FALSE);
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1201 g_return_val_if_fail(crt->scheme == &x509_gnutls, FALSE);
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1202 g_return_val_if_fail(name, FALSE);
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1203
18652
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
1204 crt_dat = X509_GET_GNUTLS_DATA(crt);
18643
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1205
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1206 if (gnutls_x509_crt_check_hostname(crt_dat, name)) {
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1207 return TRUE;
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1208 } else {
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1209 return FALSE;
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1210 }
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1211 }
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1212
19007
f3c3ddf37812 - Change the internal structure of activation/expiration times to match
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18656
diff changeset
1213 static gboolean
f3c3ddf37812 - Change the internal structure of activation/expiration times to match
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18656
diff changeset
1214 x509_times (PurpleCertificate *crt, time_t *activation, time_t *expiration)
18648
a677b7c8fd97 - Add activation/expiration time retrievers to GnuTLS plugin
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18643
diff changeset
1215 {
35978
c0b60f37a7db Backport warning fixes for libpurple from default
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 31155
diff changeset
1216 gnutls_x509_crt_t crt_dat;
19007
f3c3ddf37812 - Change the internal structure of activation/expiration times to match
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18656
diff changeset
1217 /* GnuTLS time functions return this on error */
f3c3ddf37812 - Change the internal structure of activation/expiration times to match
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18656
diff changeset
1218 const time_t errval = (time_t) (-1);
20224
d4b827c606db applied changes from 4d50bf3b08569aa2108a9f5da47fb1548d0c7dd9
Luke Schierer <lschiere@pidgin.im>
parents: 20177
diff changeset
1219 gboolean success = TRUE;
19007
f3c3ddf37812 - Change the internal structure of activation/expiration times to match
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18656
diff changeset
1220
f3c3ddf37812 - Change the internal structure of activation/expiration times to match
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18656
diff changeset
1221 g_return_val_if_fail(crt, FALSE);
f3c3ddf37812 - Change the internal structure of activation/expiration times to match
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18656
diff changeset
1222 g_return_val_if_fail(crt->scheme == &x509_gnutls, FALSE);
18648
a677b7c8fd97 - Add activation/expiration time retrievers to GnuTLS plugin
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18643
diff changeset
1223
18652
0998769e4fea - GnuTLS plugin now uses reference counting to manage its underlying
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18648
diff changeset
1224 crt_dat = X509_GET_GNUTLS_DATA(crt);
18648
a677b7c8fd97 - Add activation/expiration time retrievers to GnuTLS plugin
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18643
diff changeset
1225
19007
f3c3ddf37812 - Change the internal structure of activation/expiration times to match
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18656
diff changeset
1226 if (activation) {
f3c3ddf37812 - Change the internal structure of activation/expiration times to match
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18656
diff changeset
1227 *activation = gnutls_x509_crt_get_activation_time(crt_dat);
20224
d4b827c606db applied changes from 4d50bf3b08569aa2108a9f5da47fb1548d0c7dd9
Luke Schierer <lschiere@pidgin.im>
parents: 20177
diff changeset
1228 if (*activation == errval)
d4b827c606db applied changes from 4d50bf3b08569aa2108a9f5da47fb1548d0c7dd9
Luke Schierer <lschiere@pidgin.im>
parents: 20177
diff changeset
1229 success = FALSE;
19007
f3c3ddf37812 - Change the internal structure of activation/expiration times to match
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18656
diff changeset
1230 }
f3c3ddf37812 - Change the internal structure of activation/expiration times to match
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18656
diff changeset
1231 if (expiration) {
f3c3ddf37812 - Change the internal structure of activation/expiration times to match
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18656
diff changeset
1232 *expiration = gnutls_x509_crt_get_expiration_time(crt_dat);
20224
d4b827c606db applied changes from 4d50bf3b08569aa2108a9f5da47fb1548d0c7dd9
Luke Schierer <lschiere@pidgin.im>
parents: 20177
diff changeset
1233 if (*expiration == errval)
d4b827c606db applied changes from 4d50bf3b08569aa2108a9f5da47fb1548d0c7dd9
Luke Schierer <lschiere@pidgin.im>
parents: 20177
diff changeset
1234 success = FALSE;
19007
f3c3ddf37812 - Change the internal structure of activation/expiration times to match
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18656
diff changeset
1235 }
18648
a677b7c8fd97 - Add activation/expiration time retrievers to GnuTLS plugin
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18643
diff changeset
1236
20224
d4b827c606db applied changes from 4d50bf3b08569aa2108a9f5da47fb1548d0c7dd9
Luke Schierer <lschiere@pidgin.im>
parents: 20177
diff changeset
1237 return success;
18648
a677b7c8fd97 - Add activation/expiration time retrievers to GnuTLS plugin
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18643
diff changeset
1238 }
a677b7c8fd97 - Add activation/expiration time retrievers to GnuTLS plugin
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18643
diff changeset
1239
38216
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1240 /* GNUTLS_KEYID_USE_BEST_KNOWN was added in gnutls 3.4.1, but can't ifdef it
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1241 * because it's an enum member. Older versions will ignore it, which means
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1242 * using SHA1 instead of SHA256 to compare pubkeys. But hey, not my fault. */
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1243 #if GNUTLS_VERSION_NUMBER < 0x030401
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1244 #define KEYID_FLAG (1<<30)
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1245 #else
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1246 #define KEYID_FLAG GNUTLS_KEYID_USE_BEST_KNOWN
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1247 #endif
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1248
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1249 static gboolean
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1250 x509_compare_pubkeys (PurpleCertificate *crt1, PurpleCertificate *crt2)
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1251 {
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1252 gnutls_x509_crt_t crt_dat1, crt_dat2;
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1253 unsigned char buffer1[64], buffer2[64];
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1254 size_t size1, size2;
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1255 size1 = size2 = sizeof(buffer1);
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1256
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1257 g_return_val_if_fail(crt1 && crt2, FALSE);
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1258 g_return_val_if_fail(crt1->scheme == &x509_gnutls, FALSE);
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1259 g_return_val_if_fail(crt2->scheme == &x509_gnutls, FALSE);
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1260
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1261 crt_dat1 = X509_GET_GNUTLS_DATA(crt1);
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1262
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1263 if (gnutls_x509_crt_get_key_id(crt_dat1, KEYID_FLAG, buffer1, &size1) != 0) {
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1264 return FALSE;
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1265 }
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1266
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1267 crt_dat2 = X509_GET_GNUTLS_DATA(crt2);
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1268
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1269 if (gnutls_x509_crt_get_key_id(crt_dat2, KEYID_FLAG, buffer2, &size2) != 0) {
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1270 return FALSE;
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1271 }
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1272
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1273 if (size1 != size2) {
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1274 return FALSE;
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1275 }
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1276
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1277 return memcmp(buffer1, buffer2, size1) == 0;
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1278 }
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1279
18248
8f462eaffecd - Style issues
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18247
diff changeset
1280 /* X.509 certificate operations provided by this plugin */
8f462eaffecd - Style issues
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18247
diff changeset
1281 static PurpleCertificateScheme x509_gnutls = {
8f462eaffecd - Style issues
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18247
diff changeset
1282 "x509", /* Scheme name */
8f462eaffecd - Style issues
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18247
diff changeset
1283 N_("X.509 Certificates"), /* User-visible scheme name */
8f462eaffecd - Style issues
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18247
diff changeset
1284 x509_import_from_file, /* Certificate import function */
18496
3bb8e716482e - Add purple_certificate_export and associated libpurple stuff
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18482
diff changeset
1285 x509_export_certificate, /* Certificate export function */
18654
45790c3e780d - Add GnuTLS X.509 cert copy operator
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18653
diff changeset
1286 x509_copy_certificate, /* Copy */
18454
9a56a88152b9 - Add more to the Certificate struct
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18450
diff changeset
1287 x509_destroy_certificate, /* Destroy cert */
19016
3cf632c31eb3 - Add purple_certificate_signed_by
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19007
diff changeset
1288 x509_certificate_signed_by, /* Signature checker */
18455
4fe7da78f38d - Add GnuTLS SHA1 key fingerprinter
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18454
diff changeset
1289 x509_sha1sum, /* SHA1 fingerprint */
19019
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1290 x509_cert_dn, /* Unique ID */
d2415aad4cfb - Add unique_id and issuer_unique_id constructions (defined as Distinguished
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19016
diff changeset
1291 x509_issuer_dn, /* Issuer Unique ID */
18641
4b3c12392054 - Add get_activation_time and get_expiration_time to CertificateScheme
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18593
diff changeset
1292 x509_common_name, /* Subject name */
18643
a6a86ac3c219 - Add certificate_check_subject_name and associated machinery
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18642
diff changeset
1293 x509_check_name, /* Check subject name */
19827
62c3805f723e - Add purple_reserved fields to various structures.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19714
diff changeset
1294 x509_times, /* Activation/Expiration time */
29930
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 28655
diff changeset
1295 x509_importcerts_from_file, /* Multiple certificates import function */
19827
62c3805f723e - Add purple_reserved fields to various structures.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19714
diff changeset
1296
62c3805f723e - Add purple_reserved fields to various structures.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19714
diff changeset
1297 NULL,
62c3805f723e - Add purple_reserved fields to various structures.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19714
diff changeset
1298 NULL,
38214
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1299 sizeof(PurpleCertificateScheme), /* struct_size */
b3d0ba7c75f6 certificate: Use SHA256 fingerprints instead of SHA1
dx <dx@dxzone.com.ar>
parents: 38128
diff changeset
1300 x509_sha256sum, /* SHA256 fingerprint */
38216
887efbd652d8 certificate: Use public key fingerprint to compare certificates
dx <dx@dxzone.com.ar>
parents: 38214
diff changeset
1301 x509_compare_pubkeys, /* Compare public keys */
18248
8f462eaffecd - Style issues
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18247
diff changeset
1302 };
8f462eaffecd - Style issues
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18247
diff changeset
1303
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1304 static PurpleSslOps ssl_ops =
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1305 {
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1306 ssl_gnutls_init,
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1307 ssl_gnutls_uninit,
14223
c6ba4f3482de [gaim-migrate @ 16809]
Mark Doliner <markdoliner@pidgin.im>
parents: 13985
diff changeset
1308 ssl_gnutls_connect,
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1309 ssl_gnutls_close,
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1310 ssl_gnutls_read,
16744
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 15884
diff changeset
1311 ssl_gnutls_write,
18246
212bfb9c9cc7 - Expose get_peer_certificates in the SslOps struct, and modify gnutls
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18245
diff changeset
1312 ssl_gnutls_get_peer_certificates,
16744
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 15884
diff changeset
1313
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 15884
diff changeset
1314 /* padding */
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 15884
diff changeset
1315 NULL,
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 15884
diff changeset
1316 NULL,
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 15884
diff changeset
1317 NULL
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1318 };
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1319
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1320 static gboolean
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1321 plugin_load(PurplePlugin *plugin)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1322 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1323 if(!purple_ssl_get_ops()) {
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1324 purple_ssl_set_ops(&ssl_ops);
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7834
diff changeset
1325 }
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1326
11033
dc68e074f10d [gaim-migrate @ 12919]
Etan Reisner <deryni@pidgin.im>
parents: 9943
diff changeset
1327 /* Init GNUTLS now so others can use it even if sslconn never does */
dc68e074f10d [gaim-migrate @ 12919]
Etan Reisner <deryni@pidgin.im>
parents: 9943
diff changeset
1328 ssl_gnutls_init_gnutls();
dc68e074f10d [gaim-migrate @ 12919]
Etan Reisner <deryni@pidgin.im>
parents: 9943
diff changeset
1329
19356
65dacaaad968 - Move ssl-gnutls x509 registration until after GnuTLS itself is inited
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19353
diff changeset
1330 /* Register that we're providing an X.509 CertScheme */
65dacaaad968 - Move ssl-gnutls x509 registration until after GnuTLS itself is inited
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19353
diff changeset
1331 purple_certificate_register_scheme( &x509_gnutls );
65dacaaad968 - Move ssl-gnutls x509 registration until after GnuTLS itself is inited
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19353
diff changeset
1332
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1333 return TRUE;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1334 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1335
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1336 static gboolean
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1337 plugin_unload(PurplePlugin *plugin)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1338 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1339 if(purple_ssl_get_ops() == &ssl_ops) {
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1340 purple_ssl_set_ops(NULL);
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7834
diff changeset
1341 }
18447
27554a183269 - GnuTLS plugin registers an x509 certscheme now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18250
diff changeset
1342
27554a183269 - GnuTLS plugin registers an x509 certscheme now
William Ehlhardt <williamehlhardt@gmail.com>
parents: 18250
diff changeset
1343 purple_certificate_unregister_scheme( &x509_gnutls );
7050
12730863b0f9 [gaim-migrate @ 7613]
Christian Hammond <chipx86@chipx86.com>
parents: 7016
diff changeset
1344
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1345 return TRUE;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1346 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1347
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1348 static PurplePluginInfo info =
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1349 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1350 PURPLE_PLUGIN_MAGIC,
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1351 PURPLE_MAJOR_VERSION,
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1352 PURPLE_MINOR_VERSION,
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1353 PURPLE_PLUGIN_STANDARD, /**< type */
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1354 NULL, /**< ui_requirement */
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1355 PURPLE_PLUGIN_FLAG_INVISIBLE, /**< flags */
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1356 NULL, /**< dependencies */
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1357 PURPLE_PRIORITY_DEFAULT, /**< priority */
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1358
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1359 SSL_GNUTLS_PLUGIN_ID, /**< id */
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1360 N_("GNUTLS"), /**< name */
20288
5ca925a094e2 applied changes from 03b709ec2a153e7e82719df0ba4635108bb1d3c6
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 20224
diff changeset
1361 DISPLAY_VERSION, /**< version */
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1362 /** summary */
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1363 N_("Provides SSL support through GNUTLS."),
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1364 /** description */
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1365 N_("Provides SSL support through GNUTLS."),
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1366 "Christian Hammond <chipx86@gnupdate.org>",
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1367 PURPLE_WEBSITE, /**< homepage */
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1368
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1369 plugin_load, /**< load */
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1370 plugin_unload, /**< unload */
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1371 NULL, /**< destroy */
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1372
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1373 NULL, /**< ui_info */
11513
89bf8d856291 [gaim-migrate @ 13758]
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 11256
diff changeset
1374 NULL, /**< extra_info */
89bf8d856291 [gaim-migrate @ 13758]
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 11256
diff changeset
1375 NULL, /**< prefs_info */
16744
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 15884
diff changeset
1376 NULL, /**< actions */
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 15884
diff changeset
1377
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 15884
diff changeset
1378 /* padding */
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 15884
diff changeset
1379 NULL,
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 15884
diff changeset
1380 NULL,
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 15884
diff changeset
1381 NULL,
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 15884
diff changeset
1382 NULL
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1383 };
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1384
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1385 static void
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1386 init_plugin(PurplePlugin *plugin)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1387 {
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1388 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1389
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15846
diff changeset
1390 PURPLE_INIT_PLUGIN(ssl_gnutls, init_plugin, info)

mercurial