libpurple/plugins/ssl/ssl-nss.c

Fri, 31 Oct 2014 18:02:39 -0400

author
Daniel Atallah <datallah@pidgin.im>
date
Fri, 31 Oct 2014 18:02:39 -0400
branch
release-2.x.y
changeset 36208
681554f27e84
parent 36207
befb6523dc5c
child 36209
9bafa7dfb2a3
permissions
-rw-r--r--

As of NSS 3.15.2, NSS_SetDomesticPolicy() doesn't do anything, so don't use it.

7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1 /**
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
2 * @file ssl-nss.c Mozilla NSS SSL plugin.
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
3 *
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
4 * purple
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
5 *
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
6 * Copyright (C) 2003 Christian Hammond <chipx86@gnupdate.org>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
7 *
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
8 * This program is free software; you can redistribute it and/or modify
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
9 * it under the terms of the GNU General Public License as published by
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
10 * the Free Software Foundation; either version 2 of the License, or
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
11 * (at your option) any later version.
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
12 *
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
13 * This program is distributed in the hope that it will be useful,
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
16 * GNU General Public License for more details.
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
17 *
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
18 * You should have received a copy of the GNU General Public License
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
19 * along with this program; if not, write to the Free Software
19859
71d37b57eff2 The FSF changed its address a while ago; our files were out of date.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 19847
diff changeset
20 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02111-1301 USA
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
21 */
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
22 #include "internal.h"
7051
8ddb8f560399 [gaim-migrate @ 7614]
Christian Hammond <chipx86@chipx86.com>
parents: 7050
diff changeset
23 #include "debug.h"
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
24 #include "certificate.h"
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
25 #include "plugin.h"
7051
8ddb8f560399 [gaim-migrate @ 7614]
Christian Hammond <chipx86@chipx86.com>
parents: 7050
diff changeset
26 #include "sslconn.h"
19983
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
27 #include "util.h"
9943
b54a762f60fa [gaim-migrate @ 10835]
Nathan Walp <nwalp@pidgin.im>
parents: 9582
diff changeset
28 #include "version.h"
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
29
7029
fe690e0607ec [gaim-migrate @ 7592]
Christian Hammond <chipx86@chipx86.com>
parents: 7028
diff changeset
30 #define SSL_NSS_PLUGIN_ID "ssl-nss"
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
31
34242
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
32 #ifdef _WIN32
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
33 # ifndef HAVE_LONG_LONG
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
34 #define HAVE_LONG_LONG
36160
d13511faaeec Update NSS to 3.17.1 for the windows build
Daniel Atallah <datallah@pidgin.im>
parents: 36157
diff changeset
35 /* WINDDK_BUILD is defined because the checks around usage of
d13511faaeec Update NSS to 3.17.1 for the windows build
Daniel Atallah <datallah@pidgin.im>
parents: 36157
diff changeset
36 * intrisic functions are wrong in nspr */
d13511faaeec Update NSS to 3.17.1 for the windows build
Daniel Atallah <datallah@pidgin.im>
parents: 36157
diff changeset
37 #define WINDDK_BUILD
34242
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
38 # endif
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
39 #else
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
40 /* TODO: Why is this done?
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
41 * This is probably being overridden by <nspr.h> (prcpucfg.h) on *nix OSes */
9582
68facdf2b52d [gaim-migrate @ 10425]
Christian Hammond <chipx86@chipx86.com>
parents: 8749
diff changeset
42 #undef HAVE_LONG_LONG /* Make Mozilla less angry. If angry, Mozilla SMASH! */
34242
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
43 #endif
9582
68facdf2b52d [gaim-migrate @ 10425]
Christian Hammond <chipx86@chipx86.com>
parents: 8749
diff changeset
44
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
45 #include <nspr.h>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
46 #include <nss.h>
19983
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
47 #include <nssb64.h>
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
48 #include <ocsp.h>
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
49 #include <pk11func.h>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
50 #include <prio.h>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
51 #include <secerr.h>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
52 #include <secmod.h>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
53 #include <ssl.h>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
54 #include <sslerr.h>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
55 #include <sslproto.h>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
56
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
57 /* There's a bug in some versions of this header that requires that some of
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
58 the headers above be included first. This is true for at least libnss
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
59 3.15.4. */
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
60 #include <certdb.h>
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
61
17673
efba6798f37e Avoid including NSPR's private header pprio.h just for the prototype of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 17623
diff changeset
62 /* This is defined in NSPR's <private/pprio.h>, but to avoid including a
efba6798f37e Avoid including NSPR's private header pprio.h just for the prototype of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 17623
diff changeset
63 * private header we duplicate the prototype here */
efba6798f37e Avoid including NSPR's private header pprio.h just for the prototype of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 17623
diff changeset
64 NSPR_API(PRFileDesc*) PR_ImportTCPSocket(PRInt32 osfd);
efba6798f37e Avoid including NSPR's private header pprio.h just for the prototype of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 17623
diff changeset
65
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
66 typedef struct
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
67 {
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
68 PRFileDesc *fd;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
69 PRFileDesc *in;
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
70 guint handshake_handler;
29942
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
71 guint handshake_timer;
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
72 } PurpleSslNssData;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
73
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
74 #define PURPLE_SSL_NSS_DATA(gsc) ((PurpleSslNssData *)gsc->private_data)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
75
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
76 static const PRIOMethods *_nss_methods = NULL;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
77 static PRDescIdentity _identity;
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
78 static PurpleCertificateScheme x509_nss;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
79
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
80 /* Thank you, Evolution */
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
81 static void
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
82 set_errno(int code)
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
83 {
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
84 /* FIXME: this should handle more. */
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
85 switch (code) {
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
86 case PR_INVALID_ARGUMENT_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
87 errno = EINVAL;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
88 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
89 case PR_PENDING_INTERRUPT_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
90 errno = EINTR;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
91 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
92 case PR_IO_PENDING_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
93 errno = EAGAIN;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
94 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
95 case PR_WOULD_BLOCK_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
96 errno = EAGAIN;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
97 /*errno = EWOULDBLOCK; */
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
98 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
99 case PR_IN_PROGRESS_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
100 errno = EINPROGRESS;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
101 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
102 case PR_ALREADY_INITIATED_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
103 errno = EALREADY;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
104 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
105 case PR_NETWORK_UNREACHABLE_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
106 errno = EHOSTUNREACH;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
107 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
108 case PR_CONNECT_REFUSED_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
109 errno = ECONNREFUSED;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
110 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
111 case PR_CONNECT_TIMEOUT_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
112 case PR_IO_TIMEOUT_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
113 errno = ETIMEDOUT;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
114 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
115 case PR_NOT_CONNECTED_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
116 errno = ENOTCONN;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
117 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
118 case PR_CONNECT_RESET_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
119 errno = ECONNRESET;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
120 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
121 case PR_IO_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
122 default:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
123 errno = EIO;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
124 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
125 }
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
126 }
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
127
22104
56970903b8e9 Probe for -Wstrict-prototypes to get some more warnings. I then cleaned up
Richard Laager <rlaager@pidgin.im>
parents: 20288
diff changeset
128 static gchar *get_error_text(void)
19847
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
129 {
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
130 PRInt32 len = PR_GetErrorTextLength();
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
131 gchar *ret = NULL;
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
132
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
133 if (len > 0) {
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
134 ret = g_malloc(len + 1);
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
135 len = PR_GetErrorText(ret);
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
136 ret[len] = '\0';
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
137 }
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
138
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
139 return ret;
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
140 }
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
141
7993
3bfea94dd0eb [gaim-migrate @ 8670]
Christian Hammond <chipx86@chipx86.com>
parents: 7862
diff changeset
142 static void
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
143 ssl_nss_init_nss(void)
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
144 {
36164
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
145 #if NSS_VMAJOR > 3 || ( NSS_VMAJOR == 3 && NSS_VMINOR >= 14 )
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
146 SSLVersionRange supported, enabled;
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
147 #endif /* NSS >= 3.14 */
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
148
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
149 PR_Init(PR_SYSTEM_THREAD, PR_PRIORITY_NORMAL, 1);
16866
2187f9250a16 Proabably fixes ticket #578, it's the recommended way of initializing NSS
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 16744
diff changeset
150 NSS_NoDB_Init(".");
36208
681554f27e84 As of NSS 3.15.2, NSS_SetDomesticPolicy() doesn't do anything, so don't use it.
Daniel Atallah <datallah@pidgin.im>
parents: 36207
diff changeset
151 #if (NSS_VMAJOR == 3 && (NSS_VMINOR < 15 || (NSS_VMINOR == 15 && NSS_VMICRO < 2)))
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
152 NSS_SetDomesticPolicy();
36208
681554f27e84 As of NSS 3.15.2, NSS_SetDomesticPolicy() doesn't do anything, so don't use it.
Daniel Atallah <datallah@pidgin.im>
parents: 36207
diff changeset
153 #endif /* NSS < 3.15.2 */
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
154
24388
32a4cf358f9c Enable a number of default-disabled strong ciphers for NSS.
Ethan Blanton <elb@pidgin.im>
parents: 24276
diff changeset
155 SSL_CipherPrefSetDefault(TLS_DHE_RSA_WITH_AES_256_CBC_SHA, 1);
32a4cf358f9c Enable a number of default-disabled strong ciphers for NSS.
Ethan Blanton <elb@pidgin.im>
parents: 24276
diff changeset
156 SSL_CipherPrefSetDefault(TLS_DHE_DSS_WITH_AES_256_CBC_SHA, 1);
32a4cf358f9c Enable a number of default-disabled strong ciphers for NSS.
Ethan Blanton <elb@pidgin.im>
parents: 24276
diff changeset
157 SSL_CipherPrefSetDefault(TLS_RSA_WITH_AES_256_CBC_SHA, 1);
32a4cf358f9c Enable a number of default-disabled strong ciphers for NSS.
Ethan Blanton <elb@pidgin.im>
parents: 24276
diff changeset
158 SSL_CipherPrefSetDefault(TLS_DHE_DSS_WITH_RC4_128_SHA, 1);
32a4cf358f9c Enable a number of default-disabled strong ciphers for NSS.
Ethan Blanton <elb@pidgin.im>
parents: 24276
diff changeset
159 SSL_CipherPrefSetDefault(TLS_DHE_RSA_WITH_AES_128_CBC_SHA, 1);
32a4cf358f9c Enable a number of default-disabled strong ciphers for NSS.
Ethan Blanton <elb@pidgin.im>
parents: 24276
diff changeset
160 SSL_CipherPrefSetDefault(TLS_DHE_DSS_WITH_AES_128_CBC_SHA, 1);
32a4cf358f9c Enable a number of default-disabled strong ciphers for NSS.
Ethan Blanton <elb@pidgin.im>
parents: 24276
diff changeset
161 SSL_CipherPrefSetDefault(SSL_RSA_WITH_RC4_128_SHA, 1);
32a4cf358f9c Enable a number of default-disabled strong ciphers for NSS.
Ethan Blanton <elb@pidgin.im>
parents: 24276
diff changeset
162 SSL_CipherPrefSetDefault(TLS_RSA_WITH_AES_128_CBC_SHA, 1);
32a4cf358f9c Enable a number of default-disabled strong ciphers for NSS.
Ethan Blanton <elb@pidgin.im>
parents: 24276
diff changeset
163 SSL_CipherPrefSetDefault(SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA, 1);
32a4cf358f9c Enable a number of default-disabled strong ciphers for NSS.
Ethan Blanton <elb@pidgin.im>
parents: 24276
diff changeset
164 SSL_CipherPrefSetDefault(SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA, 1);
32a4cf358f9c Enable a number of default-disabled strong ciphers for NSS.
Ethan Blanton <elb@pidgin.im>
parents: 24276
diff changeset
165 SSL_CipherPrefSetDefault(SSL_DHE_RSA_WITH_DES_CBC_SHA, 1);
32a4cf358f9c Enable a number of default-disabled strong ciphers for NSS.
Ethan Blanton <elb@pidgin.im>
parents: 24276
diff changeset
166 SSL_CipherPrefSetDefault(SSL_DHE_DSS_WITH_DES_CBC_SHA, 1);
32a4cf358f9c Enable a number of default-disabled strong ciphers for NSS.
Ethan Blanton <elb@pidgin.im>
parents: 24276
diff changeset
167
36164
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
168 #if NSS_VMAJOR > 3 || ( NSS_VMAJOR == 3 && NSS_VMINOR >= 14 )
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
169 /* Get the ranges of supported and enabled SSL versions */
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
170 if ((SSL_VersionRangeGetSupported(ssl_variant_stream, &supported) == SECSuccess) &&
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
171 (SSL_VersionRangeGetDefault(ssl_variant_stream, &enabled) == SECSuccess)) {
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
172 purple_debug_info("nss", "TLS supported versions: "
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
173 "0x%04hx through 0x%04hx\n", supported.min, supported.max);
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
174 purple_debug_info("nss", "TLS versions allowed by default: "
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
175 "0x%04hx through 0x%04hx\n", enabled.min, enabled.max);
36152
f4e63e354f45 Allow and prefer TLS 1.2 and 1.1 when using libnss. Patch from Elrond,
Mark Doliner <mark@kingant.net>
parents: 35623
diff changeset
176
36164
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
177 /* Make sure all versions of TLS supported by the local library are
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
178 enabled. (For some reason NSS doesn't enable newer versions of TLS
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
179 by default -- more context in ticket #15909.) */
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
180 if (supported.max > enabled.max) {
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
181 enabled.max = supported.max;
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
182 if (SSL_VersionRangeSetDefault(ssl_variant_stream, &enabled) == SECSuccess) {
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
183 purple_debug_info("nss", "Changed allowed TLS versions to "
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
184 "0x%04hx through 0x%04hx\n", enabled.min, enabled.max);
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
185 } else {
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
186 purple_debug_error("nss", "Error setting allowed TLS versions to "
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
187 "0x%04hx through 0x%04hx\n", enabled.min, enabled.max);
36152
f4e63e354f45 Allow and prefer TLS 1.2 and 1.1 when using libnss. Patch from Elrond,
Mark Doliner <mark@kingant.net>
parents: 35623
diff changeset
188 }
f4e63e354f45 Allow and prefer TLS 1.2 and 1.1 when using libnss. Patch from Elrond,
Mark Doliner <mark@kingant.net>
parents: 35623
diff changeset
189 }
f4e63e354f45 Allow and prefer TLS 1.2 and 1.1 when using libnss. Patch from Elrond,
Mark Doliner <mark@kingant.net>
parents: 35623
diff changeset
190 }
36164
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
191 #endif /* NSS >= 3.14 */
36152
f4e63e354f45 Allow and prefer TLS 1.2 and 1.1 when using libnss. Patch from Elrond,
Mark Doliner <mark@kingant.net>
parents: 35623
diff changeset
192
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
193 /** Disable OCSP Checking until we can make that use our HTTP & Proxy stuff */
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
194 CERT_EnableOCSPChecking(PR_FALSE);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
195
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
196 _identity = PR_GetUniqueIdentity("Purple");
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
197 _nss_methods = PR_GetDefaultIOMethods();
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
198 }
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
199
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
200 static SECStatus
35135
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
201 ssl_auth_cert(void *arg, PRFileDesc *socket, PRBool checksig, PRBool is_server)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
202 {
35135
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
203 /* We just skip cert verification here, and will verify the whole chain
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
204 * in ssl_nss_handshake_cb, after the handshake is complete.
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
205 *
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
206 * The problem is, purple_certificate_verify is asynchronous and
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
207 * ssl_auth_cert should return the result synchronously (it may ask the
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
208 * user, if an unknown certificate should be trusted or not).
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
209 *
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
210 * Ideally, SSL_AuthCertificateHook/ssl_auth_cert should decide
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
211 * immediately, if the certificate chain is already trusted and possibly
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
212 * SSL_BadCertHook to deal with unknown certificates.
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
213 *
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
214 * Current implementation may not be ideal, but is no less secure in
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
215 * terms of MITM attack.
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
216 */
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
217 return SECSuccess;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
218 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
219
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
220 static gboolean
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
221 ssl_nss_init(void)
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
222 {
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
223 return TRUE;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
224 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
225
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
226 static void
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
227 ssl_nss_uninit(void)
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
228 {
29943
8bd0701c9bbd nss: NSS should work after reiniting libpurple. Closes #11524.
Paul Aurich <darkrain42@pidgin.im>
parents: 29942
diff changeset
229 NSS_Shutdown();
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
230 PR_Cleanup();
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
231
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
232 _nss_methods = NULL;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
233 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
234
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
235 static void
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
236 ssl_nss_verified_cb(PurpleCertificateVerificationStatus st,
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
237 gpointer userdata)
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
238 {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
239 PurpleSslConnection *gsc = (PurpleSslConnection *) userdata;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
240
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
241 if (st == PURPLE_CERTIFICATE_VALID) {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
242 /* Certificate valid? Good! Do the connection! */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
243 gsc->connect_cb(gsc->connect_cb_data, gsc, PURPLE_INPUT_READ);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
244 } else {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
245 /* Otherwise, signal an error */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
246 if(gsc->error_cb != NULL)
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
247 gsc->error_cb(gsc, PURPLE_SSL_CERTIFICATE_INVALID,
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
248 gsc->connect_cb_data);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
249 purple_ssl_close(gsc);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
250 }
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
251 }
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
252
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
253 /** Transforms an NSS containing an X.509 certificate into a Certificate instance
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
254 *
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
255 * @param cert Certificate to transform
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
256 * @return A newly allocated Certificate
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
257 */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
258 static PurpleCertificate *
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
259 x509_import_from_nss(CERTCertificate* cert)
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
260 {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
261 /* New certificate to return */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
262 PurpleCertificate * crt;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
263
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
264 /* Allocate the certificate and load it with data */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
265 crt = g_new0(PurpleCertificate, 1);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
266 crt->scheme = &x509_nss;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
267 crt->data = CERT_DupCertificate(cert);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
268
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
269 return crt;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
270 }
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
271
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
272 static GList *
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
273 ssl_nss_get_peer_certificates(PRFileDesc *socket, PurpleSslConnection * gsc)
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
274 {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
275 CERTCertificate *curcert;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
276 CERTCertificate *issuerCert;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
277 PurpleCertificate * newcrt;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
278
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
279 /* List of Certificate instances to return */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
280 GList * peer_certs = NULL;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
281 int count;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
282 int64 now = PR_Now();
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
283
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
284 curcert = SSL_PeerCertificate(socket);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
285 if (curcert == NULL) {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
286 purple_debug_error("nss", "could not DupCertificate\n");
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
287 return NULL;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
288 }
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
289
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
290 for (count = 0 ; count < CERT_MAX_CERT_CHAIN ; count++) {
24276
469eea3c328d Fix a NULL pointer deref in the NSS SSL implementation with certain self-signed
Daniel Atallah <datallah@pidgin.im>
parents: 24065
diff changeset
291 purple_debug_info("nss", "subject=%s issuer=%s\n", curcert->subjectName,
469eea3c328d Fix a NULL pointer deref in the NSS SSL implementation with certain self-signed
Daniel Atallah <datallah@pidgin.im>
parents: 24065
diff changeset
292 curcert->issuerName ? curcert->issuerName : "(null)");
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
293 newcrt = x509_import_from_nss(curcert);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
294 peer_certs = g_list_append(peer_certs, newcrt);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
295
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
296 if (curcert->isRoot) {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
297 break;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
298 }
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
299 issuerCert = CERT_FindCertIssuer(curcert, now, certUsageSSLServer);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
300 if (!issuerCert) {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
301 purple_debug_error("nss", "partial certificate chain\n");
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
302 break;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
303 }
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
304 CERT_DestroyCertificate(curcert);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
305 curcert = issuerCert;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
306 }
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
307 CERT_DestroyCertificate(curcert);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
308
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
309 return peer_certs;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
310 }
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
311
35368
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
312 /*
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
313 * Ideally this information would be exposed to the UI somehow, but for now we
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
314 * just print it to the debug log
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
315 */
35623
1bb4759f7b9b Remove stray whitespace.
Mark Doliner <mark@kingant.net>
parents: 35622
diff changeset
316 static void
35622
b29a773d89c1 Avoid camel case function name.
Mark Doliner <mark@kingant.net>
parents: 35368
diff changeset
317 print_security_info(PRFileDesc *fd)
35368
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
318 {
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
319 SECStatus result;
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
320 SSLChannelInfo channel;
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
321 SSLCipherSuiteInfo suite;
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
322
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
323 result = SSL_GetChannelInfo(fd, &channel, sizeof channel);
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
324 if (result == SECSuccess && channel.length == sizeof channel
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
325 && channel.cipherSuite) {
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
326 result = SSL_GetCipherSuiteInfo(channel.cipherSuite,
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
327 &suite, sizeof suite);
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
328
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
329 if (result == SECSuccess) {
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
330 purple_debug_info("nss", "SSL version %d.%d using "
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
331 "%d-bit %s with %d-bit %s MAC\n"
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
332 "Server Auth: %d-bit %s, "
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
333 "Key Exchange: %d-bit %s, "
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
334 "Compression: %s\n"
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
335 "Cipher Suite Name: %s\n",
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
336 channel.protocolVersion >> 8,
35623
1bb4759f7b9b Remove stray whitespace.
Mark Doliner <mark@kingant.net>
parents: 35622
diff changeset
337 channel.protocolVersion & 0xff,
35368
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
338 suite.effectiveKeyBits,
35623
1bb4759f7b9b Remove stray whitespace.
Mark Doliner <mark@kingant.net>
parents: 35622
diff changeset
339 suite.symCipherName,
35368
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
340 suite.macBits,
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
341 suite.macAlgorithmName,
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
342 channel.authKeyBits,
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
343 suite.authAlgorithmName,
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
344 channel.keaKeyBits, suite.keaTypeName,
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
345 channel.compressionMethodName,
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
346 suite.cipherSuiteName);
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
347 }
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
348 }
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
349 }
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
350
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
351
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
352 static void
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
353 ssl_nss_handshake_cb(gpointer data, int fd, PurpleInputCondition cond)
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
354 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
355 PurpleSslConnection *gsc = (PurpleSslConnection *)data;
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
356 PurpleSslNssData *nss_data = gsc->private_data;
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
357
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
358 /* I don't think this the best way to do this...
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
359 * It seems to work because it'll eventually use the cached value
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
360 */
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
361 if(SSL_ForceHandshake(nss_data->in) != SECSuccess) {
19847
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
362 gchar *error_txt;
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
363 set_errno(PR_GetError());
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
364 if (errno == EAGAIN || errno == EWOULDBLOCK)
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
365 return;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
366
19847
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
367 error_txt = get_error_text();
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
368 purple_debug_error("nss", "Handshake failed %s (%d)\n", error_txt ? error_txt : "", PR_GetError());
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
369 g_free(error_txt);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
370
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
371 if (gsc->error_cb != NULL)
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
372 gsc->error_cb(gsc, PURPLE_SSL_HANDSHAKE_FAILED, gsc->connect_cb_data);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
373
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
374 purple_ssl_close(gsc);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
375
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
376 return;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
377 }
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
378
35622
b29a773d89c1 Avoid camel case function name.
Mark Doliner <mark@kingant.net>
parents: 35368
diff changeset
379 print_security_info(nss_data->in);
35368
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
380
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
381 purple_input_remove(nss_data->handshake_handler);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
382 nss_data->handshake_handler = 0;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
383
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
384 /* If a Verifier was given, hand control over to it */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
385 if (gsc->verifier) {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
386 GList *peers;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
387 /* First, get the peer cert chain */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
388 peers = ssl_nss_get_peer_certificates(nss_data->in, gsc);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
389
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
390 /* Now kick off the verification process */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
391 purple_certificate_verify(gsc->verifier,
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
392 gsc->host,
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
393 peers,
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
394 ssl_nss_verified_cb,
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
395 gsc);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
396
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
397 purple_certificate_destroy_list(peers);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
398 } else {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
399 /* Otherwise, just call the "connection complete"
35135
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
400 * callback. The verification was already done with
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
401 * SSL_AuthCertificate, the default verifier
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
402 * (SSL_AuthCertificateHook was not called in ssl_nss_connect).
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
403 */
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
404 gsc->connect_cb(gsc->connect_cb_data, gsc, cond);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
405 }
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
406 }
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
407
29942
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
408 static gboolean
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
409 start_handshake_cb(gpointer data)
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
410 {
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
411 PurpleSslConnection *gsc = data;
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
412 PurpleSslNssData *nss_data = PURPLE_SSL_NSS_DATA(gsc);
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
413
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
414 nss_data->handshake_timer = 0;
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
415
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
416 ssl_nss_handshake_cb(gsc, gsc->fd, PURPLE_INPUT_READ);
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
417 return FALSE;
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
418 }
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
419
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
420 static void
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
421 ssl_nss_connect(PurpleSslConnection *gsc)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
422 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
423 PurpleSslNssData *nss_data = g_new0(PurpleSslNssData, 1);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
424 PRSocketOptionData socket_opt;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
425
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
426 gsc->private_data = nss_data;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
427
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
428 nss_data->fd = PR_ImportTCPSocket(gsc->fd);
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
429
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
430 if (nss_data->fd == NULL)
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
431 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
432 purple_debug_error("nss", "nss_data->fd == NULL!\n");
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
433
8362
1dc105ff1804 [gaim-migrate @ 9087]
Nathan Walp <nwalp@pidgin.im>
parents: 8360
diff changeset
434 if (gsc->error_cb != NULL)
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
435 gsc->error_cb(gsc, PURPLE_SSL_CONNECT_FAILED, gsc->connect_cb_data);
8362
1dc105ff1804 [gaim-migrate @ 9087]
Nathan Walp <nwalp@pidgin.im>
parents: 8360
diff changeset
436
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
437 purple_ssl_close((PurpleSslConnection *)gsc);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
438
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
439 return;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
440 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
441
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
442 socket_opt.option = PR_SockOpt_Nonblocking;
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
443 socket_opt.value.non_blocking = PR_TRUE;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
444
19847
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
445 if (PR_SetSocketOption(nss_data->fd, &socket_opt) != PR_SUCCESS) {
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
446 gchar *error_txt = get_error_text();
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
447 purple_debug_warning("nss", "unable to set socket into non-blocking mode: %s (%d)\n", error_txt ? error_txt : "", PR_GetError());
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
448 g_free(error_txt);
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
449 }
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
450
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
451 nss_data->in = SSL_ImportFD(NULL, nss_data->fd);
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
452
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
453 if (nss_data->in == NULL)
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
454 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
455 purple_debug_error("nss", "nss_data->in == NUL!\n");
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
456
8362
1dc105ff1804 [gaim-migrate @ 9087]
Nathan Walp <nwalp@pidgin.im>
parents: 8360
diff changeset
457 if (gsc->error_cb != NULL)
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
458 gsc->error_cb(gsc, PURPLE_SSL_CONNECT_FAILED, gsc->connect_cb_data);
8362
1dc105ff1804 [gaim-migrate @ 9087]
Nathan Walp <nwalp@pidgin.im>
parents: 8360
diff changeset
459
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
460 purple_ssl_close((PurpleSslConnection *)gsc);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
461
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
462 return;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
463 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
464
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
465 SSL_OptionSet(nss_data->in, SSL_SECURITY, PR_TRUE);
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
466 SSL_OptionSet(nss_data->in, SSL_HANDSHAKE_AS_CLIENT, PR_TRUE);
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
467
35135
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
468 /* If we have our internal verifier set up, use it. Otherwise,
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
469 * use default. */
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
470 if (gsc->verifier != NULL)
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
471 SSL_AuthCertificateHook(nss_data->in, ssl_auth_cert, NULL);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
472
7157
aad2cacc9238 [gaim-migrate @ 7724]
Nathan Walp <nwalp@pidgin.im>
parents: 7053
diff changeset
473 if(gsc->host)
aad2cacc9238 [gaim-migrate @ 7724]
Nathan Walp <nwalp@pidgin.im>
parents: 7053
diff changeset
474 SSL_SetURL(nss_data->in, gsc->host);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
475
13264
f5db933aa42a [gaim-migrate @ 15629]
Björn Voigt <bjoern@cs.tu-berlin.de>
parents: 13201
diff changeset
476 #if 0
f5db933aa42a [gaim-migrate @ 15629]
Björn Voigt <bjoern@cs.tu-berlin.de>
parents: 13201
diff changeset
477 /* This seems like it'd the be the correct way to implement the
f5db933aa42a [gaim-migrate @ 15629]
Björn Voigt <bjoern@cs.tu-berlin.de>
parents: 13201
diff changeset
478 nonblocking stuff, but it doesn't seem to work */
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
479 SSL_HandshakeCallback(nss_data->in,
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
480 (SSLHandshakeCallback) ssl_nss_handshake_cb, gsc);
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
481 #endif
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
482 SSL_ResetHandshake(nss_data->in, PR_FALSE);
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
483
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
484 nss_data->handshake_handler = purple_input_add(gsc->fd,
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
485 PURPLE_INPUT_READ, ssl_nss_handshake_cb, gsc);
7274
42ec5f56e32a [gaim-migrate @ 7851]
Christian Hammond <chipx86@chipx86.com>
parents: 7157
diff changeset
486
29942
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
487 nss_data->handshake_timer = purple_timeout_add(0, start_handshake_cb, gsc);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
488 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
489
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
490 static void
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
491 ssl_nss_close(PurpleSslConnection *gsc)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
492 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
493 PurpleSslNssData *nss_data = PURPLE_SSL_NSS_DATA(gsc);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
494
7467
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7274
diff changeset
495 if(!nss_data)
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7274
diff changeset
496 return;
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7274
diff changeset
497
17623
4f45361d7e3b A while ago, "Paranoid" emailed devel@p.i, having noticed that purple_ssl_close() closes the ssl fd twice. I meant to commit this fix sooner, but here it is.
Daniel Atallah <datallah@pidgin.im>
parents: 16866
diff changeset
498 if (nss_data->in) {
4f45361d7e3b A while ago, "Paranoid" emailed devel@p.i, having noticed that purple_ssl_close() closes the ssl fd twice. I meant to commit this fix sooner, but here it is.
Daniel Atallah <datallah@pidgin.im>
parents: 16866
diff changeset
499 PR_Close(nss_data->in);
4f45361d7e3b A while ago, "Paranoid" emailed devel@p.i, having noticed that purple_ssl_close() closes the ssl fd twice. I meant to commit this fix sooner, but here it is.
Daniel Atallah <datallah@pidgin.im>
parents: 16866
diff changeset
500 gsc->fd = -1;
4f45361d7e3b A while ago, "Paranoid" emailed devel@p.i, having noticed that purple_ssl_close() closes the ssl fd twice. I meant to commit this fix sooner, but here it is.
Daniel Atallah <datallah@pidgin.im>
parents: 16866
diff changeset
501 } else if (nss_data->fd) {
4f45361d7e3b A while ago, "Paranoid" emailed devel@p.i, having noticed that purple_ssl_close() closes the ssl fd twice. I meant to commit this fix sooner, but here it is.
Daniel Atallah <datallah@pidgin.im>
parents: 16866
diff changeset
502 PR_Close(nss_data->fd);
4f45361d7e3b A while ago, "Paranoid" emailed devel@p.i, having noticed that purple_ssl_close() closes the ssl fd twice. I meant to commit this fix sooner, but here it is.
Daniel Atallah <datallah@pidgin.im>
parents: 16866
diff changeset
503 gsc->fd = -1;
4f45361d7e3b A while ago, "Paranoid" emailed devel@p.i, having noticed that purple_ssl_close() closes the ssl fd twice. I meant to commit this fix sooner, but here it is.
Daniel Atallah <datallah@pidgin.im>
parents: 16866
diff changeset
504 }
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
505
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
506 if (nss_data->handshake_handler)
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
507 purple_input_remove(nss_data->handshake_handler);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
508
29942
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
509 if (nss_data->handshake_timer)
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
510 purple_timeout_remove(nss_data->handshake_timer);
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
511
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
512 g_free(nss_data);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
513 gsc->private_data = NULL;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
514 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
515
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
516 static size_t
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
517 ssl_nss_read(PurpleSslConnection *gsc, void *data, size_t len)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
518 {
33841
d91084abb15c Fix return types for PR_Read/PR_Write.
Elliott Sales de Andrade <qulogic@pidgin.im>
parents: 33810
diff changeset
519 PRInt32 ret;
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
520 PurpleSslNssData *nss_data = PURPLE_SSL_NSS_DATA(gsc);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
521
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
522 ret = PR_Read(nss_data->in, data, len);
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
523
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
524 if (ret == -1)
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
525 set_errno(PR_GetError());
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
526
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
527 return ret;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
528 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
529
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
530 static size_t
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
531 ssl_nss_write(PurpleSslConnection *gsc, const void *data, size_t len)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
532 {
33841
d91084abb15c Fix return types for PR_Read/PR_Write.
Elliott Sales de Andrade <qulogic@pidgin.im>
parents: 33810
diff changeset
533 PRInt32 ret;
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
534 PurpleSslNssData *nss_data = PURPLE_SSL_NSS_DATA(gsc);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
535
7467
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7274
diff changeset
536 if(!nss_data)
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7274
diff changeset
537 return 0;
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7274
diff changeset
538
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
539 ret = PR_Write(nss_data->in, data, len);
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
540
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
541 if (ret == -1)
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
542 set_errno(PR_GetError());
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
543
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
544 return ret;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
545 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
546
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
547 static GList *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
548 ssl_nss_peer_certs(PurpleSslConnection *gsc)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
549 {
20221
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
550 #if 0
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
551 PurpleSslNssData *nss_data = PURPLE_SSL_NSS_DATA(gsc);
19847
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
552 CERTCertificate *cert;
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
553 /*
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
554 GList *chain = NULL;
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
555 void *pinArg;
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
556 SECStatus status;
19847
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
557 */
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
558
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
559 /* TODO: this is a blind guess */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
560 cert = SSL_PeerCertificate(nss_data->fd);
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
561
20221
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
562 if (cert)
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
563 CERT_DestroyCertificate(cert);
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
564 #endif
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
565
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
566
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
567
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
568 return NULL;
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
569 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
570
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
571 /************************************************************************/
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
572 /* X.509 functionality */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
573 /************************************************************************/
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
574 static PurpleCertificateScheme x509_nss;
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
575
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
576 /** Helpr macro to retrieve the NSS certdata from a PurpleCertificate */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
577 #define X509_NSS_DATA(pcrt) ( (CERTCertificate * ) (pcrt->data) )
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
578
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
579 /** Imports a PEM-formatted X.509 certificate from the specified file.
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
580 * @param filename Filename to import from. Format is PEM
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
581 *
29930
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
582 * @return A newly allocated Certificate structure of the x509_nss scheme
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
583 */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
584 static PurpleCertificate *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
585 x509_import_from_file(const gchar *filename)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
586 {
19486
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
587 gchar *rawcert;
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
588 gsize len = 0;
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
589 CERTCertificate *crt_dat;
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
590 PurpleCertificate *crt;
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
591
27823
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
592 g_return_val_if_fail(filename != NULL, NULL);
19486
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
593
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
594 purple_debug_info("nss/x509",
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
595 "Loading certificate from %s\n",
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
596 filename);
27823
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
597
19486
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
598 /* Load the raw data up */
20221
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
599 if (!g_file_get_contents(filename,
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
600 &rawcert, &len,
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
601 NULL)) {
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
602 purple_debug_error("nss/x509", "Unable to read certificate file.\n");
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
603 return NULL;
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
604 }
19486
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
605
27823
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
606 if (len == 0) {
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
607 purple_debug_error("nss/x509",
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
608 "Certificate file has no contents!\n");
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
609 if (rawcert)
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
610 g_free(rawcert);
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
611 return NULL;
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
612 }
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
613
19486
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
614 /* Decode the certificate */
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
615 crt_dat = CERT_DecodeCertFromPackage(rawcert, len);
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
616 g_free(rawcert);
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
617
27823
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
618 g_return_val_if_fail(crt_dat != NULL, NULL);
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
619
19486
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
620 crt = g_new0(PurpleCertificate, 1);
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
621 crt->scheme = &x509_nss;
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
622 crt->data = crt_dat;
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
623
19486
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
624 return crt;
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
625 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
626
29930
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
627 /** Imports a number of PEM-formatted X.509 certificates from the specified file.
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
628 * @param filename Filename to import from. Format is PEM
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
629 *
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
630 * @return A GSList of newly allocated Certificate structures of the x509_nss scheme
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
631 */
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
632 static GSList *
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
633 x509_importcerts_from_file(const gchar *filename)
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
634 {
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
635 gchar *rawcert, *begin, *end;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
636 gsize len = 0;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
637 GSList *crts = NULL;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
638 CERTCertificate *crt_dat;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
639 PurpleCertificate *crt;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
640
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
641 g_return_val_if_fail(filename != NULL, NULL);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
642
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
643 purple_debug_info("nss/x509",
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
644 "Loading certificate from %s\n",
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
645 filename);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
646
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
647 /* Load the raw data up */
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
648 if (!g_file_get_contents(filename,
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
649 &rawcert, &len,
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
650 NULL)) {
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
651 purple_debug_error("nss/x509", "Unable to read certificate file.\n");
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
652 return NULL;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
653 }
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
654
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
655 if (len == 0) {
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
656 purple_debug_error("nss/x509",
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
657 "Certificate file has no contents!\n");
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
658 if (rawcert)
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
659 g_free(rawcert);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
660 return NULL;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
661 }
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
662
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
663 begin = rawcert;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
664 while((end = strstr(begin, "-----END CERTIFICATE-----")) != NULL) {
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
665 end += sizeof("-----END CERTIFICATE-----")-1;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
666 /* Decode the certificate */
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
667 crt_dat = CERT_DecodeCertFromPackage(begin, (end-begin));
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
668
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
669 g_return_val_if_fail(crt_dat != NULL, NULL);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
670
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
671 crt = g_new0(PurpleCertificate, 1);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
672 crt->scheme = &x509_nss;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
673 crt->data = crt_dat;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
674 crts = g_slist_prepend(crts, crt);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
675 begin = end;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
676 }
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
677 g_free(rawcert);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
678
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
679 return crts;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
680 }
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
681 /**
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
682 * Exports a PEM-formatted X.509 certificate to the specified file.
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
683 * @param filename Filename to export to. Format will be PEM
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
684 * @param crt Certificate to export
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
685 *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
686 * @return TRUE if success, otherwise FALSE
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
687 */
19983
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
688 /* This function should not be so complicated, but NSS doesn't seem to have a
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
689 "convert yon certificate to PEM format" function. */
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
690 static gboolean
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
691 x509_export_certificate(const gchar *filename, PurpleCertificate *crt)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
692 {
19983
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
693 CERTCertificate *crt_dat;
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
694 SECItem *dercrt;
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
695 gchar *b64crt;
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
696 gchar *pemcrt;
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
697 gboolean ret = FALSE;
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
698
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
699 g_return_val_if_fail(filename, FALSE);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
700 g_return_val_if_fail(crt, FALSE);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
701 g_return_val_if_fail(crt->scheme == &x509_nss, FALSE);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
702
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
703 crt_dat = X509_NSS_DATA(crt);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
704 g_return_val_if_fail(crt_dat, FALSE);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
705
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
706 purple_debug_info("nss/x509",
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
707 "Exporting certificate to %s\n", filename);
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
708
19983
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
709 /* First, use NSS voodoo to create a DER-formatted certificate */
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
710 dercrt = SEC_ASN1EncodeItem(NULL, NULL, crt_dat,
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
711 SEC_ASN1_GET(SEC_SignedCertificateTemplate));
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
712 g_return_val_if_fail(dercrt != NULL, FALSE);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
713
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
714 /* Now encode it to b64 */
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
715 b64crt = NSSBase64_EncodeItem(NULL, NULL, 0, dercrt);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
716 SECITEM_FreeItem(dercrt, PR_TRUE);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
717 g_return_val_if_fail(b64crt, FALSE);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
718
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
719 /* Wrap it in nice PEM header things */
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
720 pemcrt = g_strdup_printf("-----BEGIN CERTIFICATE-----\n%s\n-----END CERTIFICATE-----\n", b64crt);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
721 PORT_Free(b64crt); /* Notice that b64crt was allocated by an NSS
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
722 function; hence, we'll let NSPR free it. */
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
723
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
724 /* Finally, dump the silly thing to a file. */
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
725 ret = purple_util_write_data_to_file_absolute(filename, pemcrt, -1);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
726
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
727 g_free(pemcrt);
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
728
19983
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
729 return ret;
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
730 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
731
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
732 static PurpleCertificate *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
733 x509_copy_certificate(PurpleCertificate *crt)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
734 {
19009
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
735 CERTCertificate *crt_dat;
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
736 PurpleCertificate *newcrt;
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
737
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
738 g_return_val_if_fail(crt, NULL);
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
739 g_return_val_if_fail(crt->scheme == &x509_nss, NULL);
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
740
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
741 crt_dat = X509_NSS_DATA(crt);
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
742 g_return_val_if_fail(crt_dat, NULL);
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
743
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
744 /* Create the certificate copy */
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
745 newcrt = g_new0(PurpleCertificate, 1);
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
746 newcrt->scheme = &x509_nss;
19023
547e94194c7a - Comment on NSS's refcounting prowess
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19014
diff changeset
747 /* NSS does refcounting automatically */
19009
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
748 newcrt->data = CERT_DupCertificate(crt_dat);
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
749
19009
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
750 return newcrt;
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
751 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
752
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
753 /** Frees a Certificate
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
754 *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
755 * Destroys a Certificate's internal data structures and frees the pointer
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
756 * given.
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
757 * @param crt Certificate instance to be destroyed. It WILL NOT be destroyed
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
758 * if it is not of the correct CertificateScheme. Can be NULL
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
759 *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
760 */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
761 static void
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
762 x509_destroy_certificate(PurpleCertificate * crt)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
763 {
19010
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
764 CERTCertificate *crt_dat;
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
765
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
766 g_return_if_fail(crt);
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
767 g_return_if_fail(crt->scheme == &x509_nss);
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
768
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
769 crt_dat = X509_NSS_DATA(crt);
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
770 g_return_if_fail(crt_dat);
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
771
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
772 /* Finally we have the certificate. So let's kill it */
19023
547e94194c7a - Comment on NSS's refcounting prowess
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19014
diff changeset
773 /* NSS does refcounting automatically */
19010
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
774 CERT_DestroyCertificate(crt_dat);
19027
921b7e331382 - x509_destroy_certificate is supposed to free the PurpleCertificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19023
diff changeset
775
921b7e331382 - x509_destroy_certificate is supposed to free the PurpleCertificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19023
diff changeset
776 /* Delete the PurpleCertificate as well */
921b7e331382 - x509_destroy_certificate is supposed to free the PurpleCertificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19023
diff changeset
777 g_free(crt);
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
778 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
779
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
780 /** Determines whether one certificate has been issued and signed by another
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
781 *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
782 * @param crt Certificate to check the signature of
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
783 * @param issuer Issuer's certificate
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
784 *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
785 * @return TRUE if crt was signed and issued by issuer, otherwise FALSE
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
786 * @TODO Modify this function to return a reason for invalidity?
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
787 */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
788 static gboolean
19980
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
789 x509_signed_by(PurpleCertificate * crt,
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
790 PurpleCertificate * issuer)
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
791 {
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
792 CERTCertificate *subjectCert;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
793 CERTCertificate *issuerCert;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
794 SECStatus st;
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
795
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
796 issuerCert = X509_NSS_DATA(issuer);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
797 g_return_val_if_fail(issuerCert, FALSE);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
798
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
799 subjectCert = X509_NSS_DATA(crt);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
800 g_return_val_if_fail(subjectCert, FALSE);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
801
33810
8b2f9fad7227 ssl-nss: Fix handling of certificates without a Subject.
Daniel Atallah <datallah@pidgin.im>
parents: 33669
diff changeset
802 if (subjectCert->issuerName == NULL || issuerCert->subjectName == NULL
24276
469eea3c328d Fix a NULL pointer deref in the NSS SSL implementation with certain self-signed
Daniel Atallah <datallah@pidgin.im>
parents: 24065
diff changeset
803 || PORT_Strcmp(subjectCert->issuerName, issuerCert->subjectName) != 0)
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
804 return FALSE;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
805 st = CERT_VerifySignedData(&subjectCert->signatureWrap, issuerCert, PR_Now(), NULL);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
806 return st == SECSuccess;
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
807 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
808
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
809 static GByteArray *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
810 x509_sha1sum(PurpleCertificate *crt)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
811 {
19014
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
812 CERTCertificate *crt_dat;
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
813 size_t hashlen = 20; /* Size of an sha1sum */
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
814 GByteArray *sha1sum;
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
815 SECItem *derCert; /* DER representation of the cert */
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
816 SECStatus st;
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
817
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
818 g_return_val_if_fail(crt, NULL);
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
819 g_return_val_if_fail(crt->scheme == &x509_nss, NULL);
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
820
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
821 crt_dat = X509_NSS_DATA(crt);
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
822 g_return_val_if_fail(crt_dat, NULL);
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
823
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
824 /* Get the certificate DER representation */
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
825 derCert = &(crt_dat->derCert);
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
826
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
827 /* Make a hash! */
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
828 sha1sum = g_byte_array_sized_new(hashlen);
19797
92736e34b16a - ssl-nss now reports a certificate's sha1sum correctly
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19671
diff changeset
829 /* glib leaves the size as 0 by default */
92736e34b16a - ssl-nss now reports a certificate's sha1sum correctly
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19671
diff changeset
830 sha1sum->len = hashlen;
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
831
19014
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
832 st = PK11_HashBuf(SEC_OID_SHA1, sha1sum->data,
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
833 derCert->data, derCert->len);
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
834
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
835 /* Check for errors */
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
836 if (st != SECSuccess) {
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
837 g_byte_array_free(sha1sum, TRUE);
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
838 purple_debug_error("nss/x509",
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
839 "Error: hashing failed!\n");
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
840 return NULL;
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
841 }
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
842
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
843 return sha1sum;
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
844 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
845
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
846 static gchar *
19980
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
847 x509_dn (PurpleCertificate *crt)
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
848 {
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
849 CERTCertificate *crt_dat;
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
850
19980
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
851 g_return_val_if_fail(crt, NULL);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
852 g_return_val_if_fail(crt->scheme == &x509_nss, NULL);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
853
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
854 crt_dat = X509_NSS_DATA(crt);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
855 g_return_val_if_fail(crt_dat, NULL);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
856
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
857 return g_strdup(crt_dat->subjectName);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
858 }
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
859
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
860 static gchar *
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
861 x509_issuer_dn (PurpleCertificate *crt)
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
862 {
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
863 CERTCertificate *crt_dat;
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
864
19980
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
865 g_return_val_if_fail(crt, NULL);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
866 g_return_val_if_fail(crt->scheme == &x509_nss, NULL);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
867
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
868 crt_dat = X509_NSS_DATA(crt);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
869 g_return_val_if_fail(crt_dat, NULL);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
870
24577
fdb8b167200e x509_issuer_dn() should return the certificate's issuer name, not the cert
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 24513
diff changeset
871 return g_strdup(crt_dat->issuerName);
19980
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
872 }
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
873
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
874 static gchar *
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
875 x509_common_name (PurpleCertificate *crt)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
876 {
19011
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
877 CERTCertificate *crt_dat;
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
878 char *nss_cn;
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
879 gchar *ret_cn;
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
880
19011
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
881 g_return_val_if_fail(crt, NULL);
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
882 g_return_val_if_fail(crt->scheme == &x509_nss, NULL);
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
883
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
884 crt_dat = X509_NSS_DATA(crt);
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
885 g_return_val_if_fail(crt_dat, NULL);
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
886
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
887 /* Q:
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
888 Why get a newly allocated string out of NSS, strdup it, and then
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
889 return the new copy?
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
890
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
891 A:
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
892 The NSS LXR docs state that I should use the NSPR free functions on
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
893 the strings that the NSS cert functions return. Since the libpurple
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
894 API expects a g_free()-able string, we make our own copy and return
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
895 that.
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
896
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
897 NSPR is something of a prima donna. */
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
898
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
899 nss_cn = CERT_GetCommonName( &(crt_dat->subject) );
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
900 ret_cn = g_strdup(nss_cn);
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
901 PORT_Free(nss_cn);
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
902
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
903 return ret_cn;
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
904 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
905
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
906 static gboolean
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
907 x509_check_name (PurpleCertificate *crt, const gchar *name)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
908 {
19012
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
909 CERTCertificate *crt_dat;
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
910 SECStatus st;
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
911
19012
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
912 g_return_val_if_fail(crt, FALSE);
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
913 g_return_val_if_fail(crt->scheme == &x509_nss, FALSE);
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
914
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
915 crt_dat = X509_NSS_DATA(crt);
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
916 g_return_val_if_fail(crt_dat, FALSE);
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
917
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
918 st = CERT_VerifyCertName(crt_dat, name);
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
919
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
920 if (st == SECSuccess) {
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
921 return TRUE;
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
922 }
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
923 else if (st == SECFailure) {
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
924 return FALSE;
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
925 }
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
926
19012
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
927 /* If we get here...bad things! */
19671
3848f6f679fd - Change g_assert to purple_debug_error
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19486
diff changeset
928 purple_debug_error("nss/x509",
3848f6f679fd - Change g_assert to purple_debug_error
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19486
diff changeset
929 "x509_check_name fell through where it shouldn't "
3848f6f679fd - Change g_assert to purple_debug_error
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19486
diff changeset
930 "have.\n");
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
931 return FALSE;
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
932 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
933
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
934 static gboolean
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
935 x509_times (PurpleCertificate *crt, time_t *activation, time_t *expiration)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
936 {
19013
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
937 CERTCertificate *crt_dat;
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
938 PRTime nss_activ, nss_expir;
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
939
19013
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
940 g_return_val_if_fail(crt, FALSE);
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
941 g_return_val_if_fail(crt->scheme == &x509_nss, FALSE);
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
942
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
943 crt_dat = X509_NSS_DATA(crt);
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
944 g_return_val_if_fail(crt_dat, FALSE);
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
945
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
946 /* Extract the times into ugly PRTime thingies */
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
947 /* TODO: Maybe this shouldn't throw an error? */
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
948 g_return_val_if_fail(
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
949 SECSuccess == CERT_GetCertTimes(crt_dat,
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
950 &nss_activ, &nss_expir),
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
951 FALSE);
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
952
19982
1b453261f6ec - Fix ssl-nss x509 to properly convert NSPR PRTime to time_t (in
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19980
diff changeset
953 /* NSS's native PRTime type *almost* corresponds to time_t; however,
1b453261f6ec - Fix ssl-nss x509 to properly convert NSPR PRTime to time_t (in
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19980
diff changeset
954 it measures *microseconds* since the epoch, not seconds. Hence
1b453261f6ec - Fix ssl-nss x509 to properly convert NSPR PRTime to time_t (in
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19980
diff changeset
955 the funny conversion. */
34242
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
956 nss_activ = nss_activ / 1000000;
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
957 nss_expir = nss_expir / 1000000;
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
958
19013
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
959 if (activation) {
34242
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
960 *activation = nss_activ;
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
961 #if SIZEOF_TIME_T == 4
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
962 /** Hack to deal with dates past the 32-bit barrier.
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
963 Handling is different for signed vs unsigned 32-bit types.
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
964 */
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
965 if (*activation != nss_activ) {
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
966 if (nss_activ < 0) {
34242
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
967 purple_debug_warning("nss",
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
968 "Setting Activation Date to epoch to handle pre-epoch value\n");
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
969 *activation = 0;
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
970 } else {
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
971 purple_debug_error("nss",
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
972 "Activation date past 32-bit barrier, forcing invalidity\n");
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
973 return FALSE;
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
974 }
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
975 }
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
976 #endif
19013
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
977 }
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
978 if (expiration) {
34242
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
979 *expiration = nss_expir;
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
980 #if SIZEOF_TIME_T == 4
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
981 if (*expiration != nss_expir) {
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
982 if (*expiration < nss_expir) {
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
983 if (*expiration < 0) {
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
984 purple_debug_warning("nss",
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
985 "Setting Expiration Date to 32-bit signed max\n");
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
986 *expiration = PR_INT32_MAX;
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
987 } else {
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
988 purple_debug_warning("nss",
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
989 "Setting Expiration Date to 32-bit unsigned max\n");
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
990 *expiration = PR_UINT32_MAX;
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
991 }
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
992 } else {
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
993 purple_debug_error("nss",
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
994 "Expiration date prior to unix epoch, forcing invalidity\n");
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
995 return FALSE;
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
996 }
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
997 }
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
998 #endif
19013
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
999 }
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
1000
19013
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1001 return TRUE;
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1002 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1003
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1004 static gboolean
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1005 x509_register_trusted_tls_cert(PurpleCertificate *crt, gboolean ca)
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1006 {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1007 CERTCertDBHandle *certdb = CERT_GetDefaultCertDB();
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1008 CERTCertificate *crt_dat;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1009 CERTCertTrust trust;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1010
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1011 g_return_val_if_fail(crt, FALSE);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1012 g_return_val_if_fail(crt->scheme == &x509_nss, FALSE);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1013
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1014 crt_dat = X509_NSS_DATA(crt);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1015 g_return_val_if_fail(crt_dat, FALSE);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1016
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1017 purple_debug_info("nss", "Trusting %s\n", crt_dat->subjectName);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1018
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1019 if (ca && !CERT_IsCACert(crt_dat, NULL)) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1020 purple_debug_error("nss",
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1021 "Refusing to set non-CA cert as trusted CA\n");
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1022 return FALSE;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1023 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1024
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1025 if (crt_dat->isperm) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1026 purple_debug_info("nss",
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1027 "Skipping setting trust for cert in permanent DB\n");
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1028 return TRUE;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1029 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1030
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1031 if (ca) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1032 trust.sslFlags = CERTDB_TRUSTED_CA | CERTDB_TRUSTED_CLIENT_CA;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1033 } else {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1034 trust.sslFlags = CERTDB_TRUSTED;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1035 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1036 trust.emailFlags = 0;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1037 trust.objectSigningFlags = 0;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1038
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1039 CERT_ChangeCertTrust(certdb, crt_dat, &trust);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1040
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1041 return TRUE;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1042 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1043
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1044 static void x509_verify_cert(PurpleCertificateVerificationRequest *vrq, PurpleCertificateInvalidityFlags *flags)
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1045 {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1046 CERTCertDBHandle *certdb = CERT_GetDefaultCertDB();
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1047 CERTCertificate *crt_dat;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1048 PRTime now = PR_Now();
36207
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1049 SECStatus rv;
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1050 PurpleCertificate *first_cert = vrq->cert_chain->data;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1051 CERTVerifyLog log;
36207
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1052 gboolean self_signed = FALSE;
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1053
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1054 crt_dat = X509_NSS_DATA(first_cert);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1055
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1056 log.arena = PORT_NewArena(512);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1057 log.head = log.tail = NULL;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1058 log.count = 0;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1059 rv = CERT_VerifyCert(certdb, crt_dat, PR_TRUE, certUsageSSLServer, now, NULL, &log);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1060
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1061 if (rv != SECSuccess || log.count > 0) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1062 CERTVerifyLogNode *node = NULL;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1063 unsigned int depth = (unsigned int)-1;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1064
36207
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1065 if (crt_dat->isRoot) {
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1066 self_signed = TRUE;
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1067 *flags |= PURPLE_CERTIFICATE_SELF_SIGNED;
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1068 }
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1069
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1070 /* Handling of untrusted, etc. modeled after
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1071 * source/security/manager/ssl/src/TransportSecurityInfo.cpp in Firefox
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1072 */
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1073 for (node = log.head; node; node = node->next) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1074 if (depth != node->depth) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1075 depth = node->depth;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1076 purple_debug_error("nss", "CERT %d. %s %s:\n", depth,
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1077 node->cert->subjectName,
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1078 depth ? "[Certificate Authority]": "");
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1079 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1080 purple_debug_error("nss", " ERROR %ld: %s\n", node->error,
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1081 PR_ErrorToName(node->error));
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1082 switch (node->error) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1083 case SEC_ERROR_EXPIRED_CERTIFICATE:
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1084 *flags |= PURPLE_CERTIFICATE_EXPIRED;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1085 break;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1086 case SEC_ERROR_REVOKED_CERTIFICATE:
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1087 *flags |= PURPLE_CERTIFICATE_REVOKED;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1088 break;
36204
9086eaeacd2c Improve NSS handling for unknown CAs
Daniel Atallah <datallah@pidgin.im>
parents: 36191
diff changeset
1089 case SEC_ERROR_UNKNOWN_ISSUER:
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1090 case SEC_ERROR_UNTRUSTED_ISSUER:
36207
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1091 if (!self_signed) {
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1092 *flags |= PURPLE_CERTIFICATE_CA_UNKNOWN;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1093 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1094 break;
36207
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1095 case SEC_ERROR_CA_CERT_INVALID:
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1096 case SEC_ERROR_EXPIRED_ISSUER_CERTIFICATE:
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1097 case SEC_ERROR_UNTRUSTED_CERT:
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1098 case SEC_ERROR_CERT_SIGNATURE_ALGORITHM_DISABLED:
36207
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1099 if (!self_signed) {
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1100 *flags |= PURPLE_CERTIFICATE_INVALID_CHAIN;
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1101 }
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1102 break;
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1103 case SEC_ERROR_BAD_SIGNATURE:
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1104 default:
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1105 *flags |= PURPLE_CERTIFICATE_INVALID_CHAIN;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1106 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1107 if (node->cert)
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1108 CERT_DestroyCertificate(node->cert);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1109 }
36207
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1110 }
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1111
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1112 rv = CERT_VerifyCertName(crt_dat, vrq->subject_name);
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1113 if (rv != SECSuccess) {
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1114 purple_debug_error("nss", "subject name not verified\n");
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1115 *flags |= PURPLE_CERTIFICATE_NAME_MISMATCH;
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1116 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1117
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1118 PORT_FreeArena(log.arena, PR_FALSE);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1119 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1120
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1121 static PurpleCertificateScheme x509_nss = {
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1122 "x509", /* Scheme name */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1123 N_("X.509 Certificates"), /* User-visible scheme name */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1124 x509_import_from_file, /* Certificate import function */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1125 x509_export_certificate, /* Certificate export function */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1126 x509_copy_certificate, /* Copy */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1127 x509_destroy_certificate, /* Destroy cert */
19980
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
1128 x509_signed_by, /* Signed-by */
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1129 x509_sha1sum, /* SHA1 fingerprint */
19980
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
1130 x509_dn, /* Unique ID */
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
1131 x509_issuer_dn, /* Issuer Unique ID */
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1132 x509_common_name, /* Subject name */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1133 x509_check_name, /* Check subject name */
19827
62c3805f723e - Add purple_reserved fields to various structures.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19797
diff changeset
1134 x509_times, /* Activation/Expiration time */
29930
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
1135 x509_importcerts_from_file, /* Multiple certificate import function */
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1136 x509_register_trusted_tls_cert, /* Register a certificate as trusted for TLS */
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1137 x509_verify_cert, /* Verify that the specified cert chain is trusted */
19827
62c3805f723e - Add purple_reserved fields to various structures.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19797
diff changeset
1138 NULL
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1139 };
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1140
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1141 static PurpleSslOps ssl_ops =
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1142 {
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1143 ssl_nss_init,
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1144 ssl_nss_uninit,
14222
71d8761db708 [gaim-migrate @ 16808]
Mark Doliner <markdoliner@pidgin.im>
parents: 13530
diff changeset
1145 ssl_nss_connect,
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1146 ssl_nss_close,
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1147 ssl_nss_read,
16744
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1148 ssl_nss_write,
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1149 ssl_nss_peer_certs,
16744
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1150
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1151 /* padding */
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1152 NULL,
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1153 NULL,
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1154 NULL
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1155 };
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1156
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1157
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1158 static gboolean
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1159 plugin_load(PurplePlugin *plugin)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1160 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1161 if (!purple_ssl_get_ops()) {
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1162 purple_ssl_set_ops(&ssl_ops);
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
1163 }
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1164
11033
dc68e074f10d [gaim-migrate @ 12919]
Etan Reisner <deryni@pidgin.im>
parents: 10519
diff changeset
1165 /* Init NSS now, so others can use it even if sslconn never does */
dc68e074f10d [gaim-migrate @ 12919]
Etan Reisner <deryni@pidgin.im>
parents: 10519
diff changeset
1166 ssl_nss_init_nss();
dc68e074f10d [gaim-migrate @ 12919]
Etan Reisner <deryni@pidgin.im>
parents: 10519
diff changeset
1167
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1168 /* Register the X.509 functions we provide */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1169 purple_certificate_register_scheme(&x509_nss);
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1170
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1171 return TRUE;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1172 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1173
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1174 static gboolean
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1175 plugin_unload(PurplePlugin *plugin)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1176 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1177 if (purple_ssl_get_ops() == &ssl_ops) {
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1178 purple_ssl_set_ops(NULL);
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
1179 }
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1180
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1181 /* Unregister our X.509 functions */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1182 purple_certificate_unregister_scheme(&x509_nss);
7050
12730863b0f9 [gaim-migrate @ 7613]
Christian Hammond <chipx86@chipx86.com>
parents: 7029
diff changeset
1183
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1184 return TRUE;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1185 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1186
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1187 static PurplePluginInfo info =
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1188 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1189 PURPLE_PLUGIN_MAGIC,
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1190 PURPLE_MAJOR_VERSION,
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1191 PURPLE_MINOR_VERSION,
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1192 PURPLE_PLUGIN_STANDARD, /**< type */
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1193 NULL, /**< ui_requirement */
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1194 PURPLE_PLUGIN_FLAG_INVISIBLE, /**< flags */
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1195 NULL, /**< dependencies */
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1196 PURPLE_PRIORITY_DEFAULT, /**< priority */
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1197
7029
fe690e0607ec [gaim-migrate @ 7592]
Christian Hammond <chipx86@chipx86.com>
parents: 7028
diff changeset
1198 SSL_NSS_PLUGIN_ID, /**< id */
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1199 N_("NSS"), /**< name */
20288
5ca925a094e2 applied changes from 03b709ec2a153e7e82719df0ba4635108bb1d3c6
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 20221
diff changeset
1200 DISPLAY_VERSION, /**< version */
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1201 /** summary */
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1202 N_("Provides SSL support through Mozilla NSS."),
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1203 /** description */
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1204 N_("Provides SSL support through Mozilla NSS."),
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1205 "Christian Hammond <chipx86@gnupdate.org>",
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1206 PURPLE_WEBSITE, /**< homepage */
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1207
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1208 plugin_load, /**< load */
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1209 plugin_unload, /**< unload */
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1210 NULL, /**< destroy */
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1211
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1212 NULL, /**< ui_info */
11513
89bf8d856291 [gaim-migrate @ 13758]
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 11256
diff changeset
1213 NULL, /**< extra_info */
89bf8d856291 [gaim-migrate @ 13758]
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 11256
diff changeset
1214 NULL, /**< prefs_info */
16744
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1215 NULL, /**< actions */
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1216
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1217 /* padding */
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1218 NULL,
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1219 NULL,
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1220 NULL,
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1221 NULL
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1222 };
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1223
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1224 static void
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1225 init_plugin(PurplePlugin *plugin)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1226 {
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1227 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1228
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1229 PURPLE_INIT_PLUGIN(ssl_nss, init_plugin, info)

mercurial