libpurple/plugins/ssl/ssl-nss.c

Wed, 26 Nov 2014 16:01:25 +0530

author
Ankit Vani <a@nevitus.org>
date
Wed, 26 Nov 2014 16:01:25 +0530
branch
soc.2013.gobjectification.plugins
changeset 37158
96b5ab42da00
parent 37157
87898632ad06
parent 36237
47cc3f47592c
child 37426
6fd4989b77e4
permissions
-rw-r--r--

Merged default branch

7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1 /**
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
2 * @file ssl-nss.c Mozilla NSS SSL plugin.
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
3 *
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
4 * purple
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
5 *
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
6 * Copyright (C) 2003 Christian Hammond <chipx86@gnupdate.org>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
7 *
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
8 * This program is free software; you can redistribute it and/or modify
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
9 * it under the terms of the GNU General Public License as published by
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
10 * the Free Software Foundation; either version 2 of the License, or
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
11 * (at your option) any later version.
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
12 *
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
13 * This program is distributed in the hope that it will be useful,
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
16 * GNU General Public License for more details.
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
17 *
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
18 * You should have received a copy of the GNU General Public License
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
19 * along with this program; if not, write to the Free Software
19859
71d37b57eff2 The FSF changed its address a while ago; our files were out of date.
John Bailey <rekkanoryo@rekkanoryo.org>
parents: 19847
diff changeset
20 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02111-1301 USA
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
21 */
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
22 #include "internal.h"
7051
8ddb8f560399 [gaim-migrate @ 7614]
Christian Hammond <chipx86@chipx86.com>
parents: 7050
diff changeset
23 #include "debug.h"
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
24 #include "certificate.h"
36367
891eea799578 Renamed plugin.[ch] to plugins.[ch], since we (will) no longer have a PurplePlugin structure.
Ankit Vani <a@nevitus.org>
parents: 34249
diff changeset
25 #include "plugins.h"
7051
8ddb8f560399 [gaim-migrate @ 7614]
Christian Hammond <chipx86@chipx86.com>
parents: 7050
diff changeset
26 #include "sslconn.h"
19983
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
27 #include "util.h"
9943
b54a762f60fa [gaim-migrate @ 10835]
Nathan Walp <nwalp@pidgin.im>
parents: 9582
diff changeset
28 #include "version.h"
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
29
7029
fe690e0607ec [gaim-migrate @ 7592]
Christian Hammond <chipx86@chipx86.com>
parents: 7028
diff changeset
30 #define SSL_NSS_PLUGIN_ID "ssl-nss"
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
31
34242
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
32 #ifdef _WIN32
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
33 # ifndef HAVE_LONG_LONG
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
34 #define HAVE_LONG_LONG
36160
d13511faaeec Update NSS to 3.17.1 for the windows build
Daniel Atallah <datallah@pidgin.im>
parents: 36157
diff changeset
35 /* WINDDK_BUILD is defined because the checks around usage of
d13511faaeec Update NSS to 3.17.1 for the windows build
Daniel Atallah <datallah@pidgin.im>
parents: 36157
diff changeset
36 * intrisic functions are wrong in nspr */
d13511faaeec Update NSS to 3.17.1 for the windows build
Daniel Atallah <datallah@pidgin.im>
parents: 36157
diff changeset
37 #define WINDDK_BUILD
34242
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
38 # endif
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
39 #else
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
40 /* TODO: Why is this done?
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
41 * This is probably being overridden by <nspr.h> (prcpucfg.h) on *nix OSes */
9582
68facdf2b52d [gaim-migrate @ 10425]
Christian Hammond <chipx86@chipx86.com>
parents: 8749
diff changeset
42 #undef HAVE_LONG_LONG /* Make Mozilla less angry. If angry, Mozilla SMASH! */
34242
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
43 #endif
9582
68facdf2b52d [gaim-migrate @ 10425]
Christian Hammond <chipx86@chipx86.com>
parents: 8749
diff changeset
44
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
45 #include <nspr.h>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
46 #include <nss.h>
19983
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
47 #include <nssb64.h>
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
48 #include <ocsp.h>
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
49 #include <pk11func.h>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
50 #include <prio.h>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
51 #include <secerr.h>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
52 #include <secmod.h>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
53 #include <ssl.h>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
54 #include <sslerr.h>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
55 #include <sslproto.h>
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
56
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
57 /* There's a bug in some versions of this header that requires that some of
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
58 the headers above be included first. This is true for at least libnss
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
59 3.15.4. */
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
60 #include <certdb.h>
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
61
17673
efba6798f37e Avoid including NSPR's private header pprio.h just for the prototype of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 17623
diff changeset
62 /* This is defined in NSPR's <private/pprio.h>, but to avoid including a
efba6798f37e Avoid including NSPR's private header pprio.h just for the prototype of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 17623
diff changeset
63 * private header we duplicate the prototype here */
efba6798f37e Avoid including NSPR's private header pprio.h just for the prototype of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 17623
diff changeset
64 NSPR_API(PRFileDesc*) PR_ImportTCPSocket(PRInt32 osfd);
efba6798f37e Avoid including NSPR's private header pprio.h just for the prototype of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 17623
diff changeset
65
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
66 typedef struct
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
67 {
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
68 PRFileDesc *fd;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
69 PRFileDesc *in;
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
70 guint handshake_handler;
29942
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
71 guint handshake_timer;
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
72 } PurpleSslNssData;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
73
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
74 #define PURPLE_SSL_NSS_DATA(gsc) ((PurpleSslNssData *)gsc->private_data)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
75
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
76 static const PRIOMethods *_nss_methods = NULL;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
77 static PRDescIdentity _identity;
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
78 static PurpleCertificateScheme x509_nss;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
79
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
80 /* Thank you, Evolution */
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
81 static void
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
82 set_errno(int code)
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
83 {
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
84 /* FIXME: this should handle more. */
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
85 switch (code) {
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
86 case PR_INVALID_ARGUMENT_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
87 errno = EINVAL;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
88 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
89 case PR_PENDING_INTERRUPT_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
90 errno = EINTR;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
91 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
92 case PR_IO_PENDING_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
93 errno = EAGAIN;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
94 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
95 case PR_WOULD_BLOCK_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
96 errno = EAGAIN;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
97 /*errno = EWOULDBLOCK; */
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
98 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
99 case PR_IN_PROGRESS_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
100 errno = EINPROGRESS;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
101 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
102 case PR_ALREADY_INITIATED_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
103 errno = EALREADY;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
104 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
105 case PR_NETWORK_UNREACHABLE_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
106 errno = EHOSTUNREACH;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
107 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
108 case PR_CONNECT_REFUSED_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
109 errno = ECONNREFUSED;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
110 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
111 case PR_CONNECT_TIMEOUT_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
112 case PR_IO_TIMEOUT_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
113 errno = ETIMEDOUT;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
114 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
115 case PR_NOT_CONNECTED_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
116 errno = ENOTCONN;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
117 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
118 case PR_CONNECT_RESET_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
119 errno = ECONNRESET;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
120 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
121 case PR_IO_ERROR:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
122 default:
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
123 errno = EIO;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
124 break;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
125 }
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
126 }
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
127
22104
56970903b8e9 Probe for -Wstrict-prototypes to get some more warnings. I then cleaned up
Richard Laager <rlaager@pidgin.im>
parents: 20288
diff changeset
128 static gchar *get_error_text(void)
19847
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
129 {
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
130 PRInt32 len = PR_GetErrorTextLength();
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
131 gchar *ret = NULL;
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
132
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
133 if (len > 0) {
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
134 ret = g_malloc(len + 1);
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
135 len = PR_GetErrorText(ret);
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
136 ret[len] = '\0';
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
137 }
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
138
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
139 return ret;
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
140 }
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
141
36220
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
142 static const PRUint16 default_ciphers[] = {
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
143 #if NSS_VMAJOR > 3 || ( NSS_VMAJOR == 3 && NSS_VMINOR > 15 ) \
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
144 || ( NSS_VMAJOR == 3 && NSS_VMINOR == 15 && NSS_VPATCH >= 1 )
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
145 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
146 TLS_DHE_RSA_WITH_AES_128_CBC_SHA256,
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
147 TLS_DHE_RSA_WITH_AES_256_CBC_SHA256,
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
148 # if NSS_VMAJOR > 3 || ( NSS_VMAJOR == 3 && NSS_VMINOR > 15 ) \
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
149 || ( NSS_VMAJOR == 3 && NSS_VMINOR == 15 && NSS_VPATCH >= 2 )
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
150 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
151 TLS_DHE_RSA_WITH_AES_128_GCM_SHA256,
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
152 TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
153 # endif
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
154 #endif
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
155 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA,
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
156 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA,
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
157
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
158 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA,
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
159 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA,
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
160
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
161 TLS_DHE_RSA_WITH_AES_128_CBC_SHA,
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
162
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
163 TLS_DHE_RSA_WITH_AES_256_CBC_SHA,
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
164
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
165 TLS_DHE_DSS_WITH_AES_128_CBC_SHA, /* deprecated (DSS) */
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
166 /* TLS_DHE_DSS_WITH_AES_256_CBC_SHA, false }, // deprecated (DSS) */
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
167
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
168 TLS_ECDHE_RSA_WITH_RC4_128_SHA, /* deprecated (RC4) */
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
169 TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, /* deprecated (RC4) */
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
170
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
171 /* RFC 6120 Mandatory */
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
172 TLS_RSA_WITH_AES_128_CBC_SHA, /* deprecated (RSA key exchange) */
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
173 TLS_RSA_WITH_AES_256_CBC_SHA, /* deprecated (RSA key exchange) */
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
174 /* TLS_RSA_WITH_3DES_EDE_CBC_SHA, deprecated (RSA key exchange, 3DES) */
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
175
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
176 0 /* end marker */
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
177 };
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
178
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
179 /* It's unfortunate we need to manage these manually,
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
180 * ideally NSS would choose good defaults.
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
181 * This is mostly based on FireFox's list:
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
182 * https://hg.mozilla.org/mozilla-central/log/default/security/manager/ssl/src/nsNSSComponent.cpp */
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
183 static void ssl_nss_init_ciphers(void) {
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
184 /* Disable any ciphers that NSS might have enabled by default */
36209
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
185 const PRUint16 *cipher;
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
186 for (cipher = SSL_GetImplementedCiphers(); *cipher != 0; ++cipher) {
36220
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
187 SSL_CipherPrefSetDefault(*cipher, PR_FALSE);
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
188 }
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
189
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
190 /* Now only set SSL/TLS ciphers we knew about at compile time */
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
191 for (cipher = default_ciphers; *cipher != 0; ++cipher) {
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
192 SSL_CipherPrefSetDefault(*cipher, PR_TRUE);
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
193 }
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
194
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
195 /* Now log the available and enabled Ciphers */
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
196 for (cipher = SSL_GetImplementedCiphers(); *cipher != 0; ++cipher) {
36209
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
197 const PRUint16 suite = *cipher;
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
198 SECStatus rv;
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
199 PRBool enabled;
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
200 SSLCipherSuiteInfo info;
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
201
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
202 rv = SSL_CipherPrefGetDefault(suite, &enabled);
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
203 if (rv != SECSuccess) {
36219
703e982d8d18 Fix building with NSS 3.10.8 (which is what squeeze has and is probably the oldest we need to worry about)
Daniel Atallah <datallah@pidgin.im>
parents: 36209
diff changeset
204 gchar *error_txt = get_error_text();
36209
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
205 purple_debug_warning("nss",
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
206 "SSL_CipherPrefGetDefault didn't like value 0x%04x: %s\n",
36219
703e982d8d18 Fix building with NSS 3.10.8 (which is what squeeze has and is probably the oldest we need to worry about)
Daniel Atallah <datallah@pidgin.im>
parents: 36209
diff changeset
207 suite, error_txt);
703e982d8d18 Fix building with NSS 3.10.8 (which is what squeeze has and is probably the oldest we need to worry about)
Daniel Atallah <datallah@pidgin.im>
parents: 36209
diff changeset
208 g_free(error_txt);
36209
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
209 continue;
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
210 }
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
211 rv = SSL_GetCipherSuiteInfo(suite, &info, (int)(sizeof info));
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
212 if (rv != SECSuccess) {
36219
703e982d8d18 Fix building with NSS 3.10.8 (which is what squeeze has and is probably the oldest we need to worry about)
Daniel Atallah <datallah@pidgin.im>
parents: 36209
diff changeset
213 gchar *error_txt = get_error_text();
36209
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
214 purple_debug_warning("nss",
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
215 "SSL_GetCipherSuiteInfo didn't like value 0x%04x: %s\n",
36219
703e982d8d18 Fix building with NSS 3.10.8 (which is what squeeze has and is probably the oldest we need to worry about)
Daniel Atallah <datallah@pidgin.im>
parents: 36209
diff changeset
216 suite, error_txt);
703e982d8d18 Fix building with NSS 3.10.8 (which is what squeeze has and is probably the oldest we need to worry about)
Daniel Atallah <datallah@pidgin.im>
parents: 36209
diff changeset
217 g_free(error_txt);
36209
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
218 continue;
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
219 }
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
220 purple_debug_info("nss", "Cipher - %s: %s\n",
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
221 info.cipherSuiteName,
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
222 enabled ? "Enabled" : "Disabled");
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
223 }
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
224 }
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
225
7993
3bfea94dd0eb [gaim-migrate @ 8670]
Christian Hammond <chipx86@chipx86.com>
parents: 7862
diff changeset
226 static void
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
227 ssl_nss_init_nss(void)
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
228 {
36164
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
229 #if NSS_VMAJOR > 3 || ( NSS_VMAJOR == 3 && NSS_VMINOR >= 14 )
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
230 SSLVersionRange supported, enabled;
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
231 #endif /* NSS >= 3.14 */
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
232
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
233 PR_Init(PR_SYSTEM_THREAD, PR_PRIORITY_NORMAL, 1);
16866
2187f9250a16 Proabably fixes ticket #578, it's the recommended way of initializing NSS
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 16744
diff changeset
234 NSS_NoDB_Init(".");
36219
703e982d8d18 Fix building with NSS 3.10.8 (which is what squeeze has and is probably the oldest we need to worry about)
Daniel Atallah <datallah@pidgin.im>
parents: 36209
diff changeset
235 #if (NSS_VMAJOR == 3 && (NSS_VMINOR < 15 || (NSS_VMINOR == 15 && NSS_VPATCH < 2)))
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
236 NSS_SetDomesticPolicy();
36208
681554f27e84 As of NSS 3.15.2, NSS_SetDomesticPolicy() doesn't do anything, so don't use it.
Daniel Atallah <datallah@pidgin.im>
parents: 36207
diff changeset
237 #endif /* NSS < 3.15.2 */
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
238
36220
f26d96f03176 Update NSS Default Cipher suites
Daniel Atallah <datallah@pidgin.im>
parents: 36219
diff changeset
239 ssl_nss_init_ciphers();
24388
32a4cf358f9c Enable a number of default-disabled strong ciphers for NSS.
Ethan Blanton <elb@pidgin.im>
parents: 24276
diff changeset
240
36164
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
241 #if NSS_VMAJOR > 3 || ( NSS_VMAJOR == 3 && NSS_VMINOR >= 14 )
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
242 /* Get the ranges of supported and enabled SSL versions */
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
243 if ((SSL_VersionRangeGetSupported(ssl_variant_stream, &supported) == SECSuccess) &&
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
244 (SSL_VersionRangeGetDefault(ssl_variant_stream, &enabled) == SECSuccess)) {
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
245 purple_debug_info("nss", "TLS supported versions: "
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
246 "0x%04hx through 0x%04hx\n", supported.min, supported.max);
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
247 purple_debug_info("nss", "TLS versions allowed by default: "
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
248 "0x%04hx through 0x%04hx\n", enabled.min, enabled.max);
36152
f4e63e354f45 Allow and prefer TLS 1.2 and 1.1 when using libnss. Patch from Elrond,
Mark Doliner <mark@kingant.net>
parents: 35623
diff changeset
249
36166
304d073d134e Manual merge release-2.x.y branch into master.
Mark Doliner <mark@kingant.net>
parents: 36163 36165
diff changeset
250 /* Make sure SSL 3.0 is disabled (it's old and everyone should be
304d073d134e Manual merge release-2.x.y branch into master.
Mark Doliner <mark@kingant.net>
parents: 36163 36165
diff changeset
251 using at least TLS 1.0 by now), and make sure all versions of TLS
304d073d134e Manual merge release-2.x.y branch into master.
Mark Doliner <mark@kingant.net>
parents: 36163 36165
diff changeset
252 supported by the local library are enabled (for some reason NSS
304d073d134e Manual merge release-2.x.y branch into master.
Mark Doliner <mark@kingant.net>
parents: 36163 36165
diff changeset
253 doesn't enable newer versions of TLS by default -- more context in
304d073d134e Manual merge release-2.x.y branch into master.
Mark Doliner <mark@kingant.net>
parents: 36163 36165
diff changeset
254 ticket #15909). */
304d073d134e Manual merge release-2.x.y branch into master.
Mark Doliner <mark@kingant.net>
parents: 36163 36165
diff changeset
255 if (enabled.min != SSL_LIBRARY_VERSION_TLS_1_0 || supported.max > enabled.max) {
36164
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
256 enabled.max = supported.max;
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
257 if (SSL_VersionRangeSetDefault(ssl_variant_stream, &enabled) == SECSuccess) {
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
258 purple_debug_info("nss", "Changed allowed TLS versions to "
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
259 "0x%04hx through 0x%04hx\n", enabled.min, enabled.max);
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
260 } else {
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
261 purple_debug_error("nss", "Error setting allowed TLS versions to "
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
262 "0x%04hx through 0x%04hx\n", enabled.min, enabled.max);
36152
f4e63e354f45 Allow and prefer TLS 1.2 and 1.1 when using libnss. Patch from Elrond,
Mark Doliner <mark@kingant.net>
parents: 35623
diff changeset
263 }
f4e63e354f45 Allow and prefer TLS 1.2 and 1.1 when using libnss. Patch from Elrond,
Mark Doliner <mark@kingant.net>
parents: 35623
diff changeset
264 }
f4e63e354f45 Allow and prefer TLS 1.2 and 1.1 when using libnss. Patch from Elrond,
Mark Doliner <mark@kingant.net>
parents: 35623
diff changeset
265 }
36164
6d2325070ec8 Change this to a preprocessor check.
Mark Doliner <mark@kingant.net>
parents: 36162
diff changeset
266 #endif /* NSS >= 3.14 */
36152
f4e63e354f45 Allow and prefer TLS 1.2 and 1.1 when using libnss. Patch from Elrond,
Mark Doliner <mark@kingant.net>
parents: 35623
diff changeset
267
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
268 /** Disable OCSP Checking until we can make that use our HTTP & Proxy stuff */
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
269 CERT_EnableOCSPChecking(PR_FALSE);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
270
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
271 _identity = PR_GetUniqueIdentity("Purple");
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
272 _nss_methods = PR_GetDefaultIOMethods();
36209
9bafa7dfb2a3 Add logging of supported and enabled cipher suites to the NSS plugin.
Daniel Atallah <datallah@pidgin.im>
parents: 36208
diff changeset
273
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
274 }
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
275
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
276 static SECStatus
35135
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
277 ssl_auth_cert(void *arg, PRFileDesc *socket, PRBool checksig, PRBool is_server)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
278 {
35135
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
279 /* We just skip cert verification here, and will verify the whole chain
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
280 * in ssl_nss_handshake_cb, after the handshake is complete.
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
281 *
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
282 * The problem is, purple_certificate_verify is asynchronous and
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
283 * ssl_auth_cert should return the result synchronously (it may ask the
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
284 * user, if an unknown certificate should be trusted or not).
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
285 *
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
286 * Ideally, SSL_AuthCertificateHook/ssl_auth_cert should decide
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
287 * immediately, if the certificate chain is already trusted and possibly
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
288 * SSL_BadCertHook to deal with unknown certificates.
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
289 *
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
290 * Current implementation may not be ideal, but is no less secure in
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
291 * terms of MITM attack.
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
292 */
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
293 return SECSuccess;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
294 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
295
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
296 static gboolean
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
297 ssl_nss_init(void)
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
298 {
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
299 return TRUE;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
300 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
301
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
302 static void
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
303 ssl_nss_uninit(void)
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
304 {
29943
8bd0701c9bbd nss: NSS should work after reiniting libpurple. Closes #11524.
Paul Aurich <darkrain42@pidgin.im>
parents: 29942
diff changeset
305 NSS_Shutdown();
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
306 PR_Cleanup();
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
307
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
308 _nss_methods = NULL;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
309 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
310
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
311 static void
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
312 ssl_nss_verified_cb(PurpleCertificateVerificationStatus st,
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
313 gpointer userdata)
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
314 {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
315 PurpleSslConnection *gsc = (PurpleSslConnection *) userdata;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
316
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
317 if (st == PURPLE_CERTIFICATE_VALID) {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
318 /* Certificate valid? Good! Do the connection! */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
319 gsc->connect_cb(gsc->connect_cb_data, gsc, PURPLE_INPUT_READ);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
320 } else {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
321 /* Otherwise, signal an error */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
322 if(gsc->error_cb != NULL)
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
323 gsc->error_cb(gsc, PURPLE_SSL_CERTIFICATE_INVALID,
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
324 gsc->connect_cb_data);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
325 purple_ssl_close(gsc);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
326 }
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
327 }
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
328
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
329 /** Transforms an NSS containing an X.509 certificate into a Certificate instance
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
330 *
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
331 * @param cert Certificate to transform
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
332 * @return A newly allocated Certificate
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
333 */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
334 static PurpleCertificate *
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
335 x509_import_from_nss(CERTCertificate* cert)
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
336 {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
337 /* New certificate to return */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
338 PurpleCertificate * crt;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
339
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
340 /* Allocate the certificate and load it with data */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
341 crt = g_new0(PurpleCertificate, 1);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
342 crt->scheme = &x509_nss;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
343 crt->data = CERT_DupCertificate(cert);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
344
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
345 return crt;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
346 }
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
347
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
348 static GList *
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
349 ssl_nss_get_peer_certificates(PRFileDesc *socket, PurpleSslConnection * gsc)
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
350 {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
351 CERTCertificate *curcert;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
352 CERTCertificate *issuerCert;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
353 PurpleCertificate * newcrt;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
354
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
355 /* List of Certificate instances to return */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
356 GList * peer_certs = NULL;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
357 int count;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
358 int64 now = PR_Now();
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
359
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
360 curcert = SSL_PeerCertificate(socket);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
361 if (curcert == NULL) {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
362 purple_debug_error("nss", "could not DupCertificate\n");
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
363 return NULL;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
364 }
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
365
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
366 for (count = 0 ; count < CERT_MAX_CERT_CHAIN ; count++) {
24276
469eea3c328d Fix a NULL pointer deref in the NSS SSL implementation with certain self-signed
Daniel Atallah <datallah@pidgin.im>
parents: 24065
diff changeset
367 purple_debug_info("nss", "subject=%s issuer=%s\n", curcert->subjectName,
469eea3c328d Fix a NULL pointer deref in the NSS SSL implementation with certain self-signed
Daniel Atallah <datallah@pidgin.im>
parents: 24065
diff changeset
368 curcert->issuerName ? curcert->issuerName : "(null)");
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
369 newcrt = x509_import_from_nss(curcert);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
370 peer_certs = g_list_append(peer_certs, newcrt);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
371
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
372 if (curcert->isRoot) {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
373 break;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
374 }
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
375 issuerCert = CERT_FindCertIssuer(curcert, now, certUsageSSLServer);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
376 if (!issuerCert) {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
377 purple_debug_error("nss", "partial certificate chain\n");
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
378 break;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
379 }
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
380 CERT_DestroyCertificate(curcert);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
381 curcert = issuerCert;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
382 }
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
383 CERT_DestroyCertificate(curcert);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
384
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
385 return peer_certs;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
386 }
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
387
35368
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
388 /*
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
389 * Ideally this information would be exposed to the UI somehow, but for now we
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
390 * just print it to the debug log
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
391 */
35623
1bb4759f7b9b Remove stray whitespace.
Mark Doliner <mark@kingant.net>
parents: 35622
diff changeset
392 static void
35622
b29a773d89c1 Avoid camel case function name.
Mark Doliner <mark@kingant.net>
parents: 35368
diff changeset
393 print_security_info(PRFileDesc *fd)
35368
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
394 {
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
395 SECStatus result;
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
396 SSLChannelInfo channel;
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
397 SSLCipherSuiteInfo suite;
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
398
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
399 result = SSL_GetChannelInfo(fd, &channel, sizeof channel);
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
400 if (result == SECSuccess && channel.length == sizeof channel
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
401 && channel.cipherSuite) {
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
402 result = SSL_GetCipherSuiteInfo(channel.cipherSuite,
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
403 &suite, sizeof suite);
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
404
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
405 if (result == SECSuccess) {
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
406 purple_debug_info("nss", "SSL version %d.%d using "
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
407 "%d-bit %s with %d-bit %s MAC\n"
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
408 "Server Auth: %d-bit %s, "
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
409 "Key Exchange: %d-bit %s, "
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
410 "Compression: %s\n"
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
411 "Cipher Suite Name: %s\n",
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
412 channel.protocolVersion >> 8,
35623
1bb4759f7b9b Remove stray whitespace.
Mark Doliner <mark@kingant.net>
parents: 35622
diff changeset
413 channel.protocolVersion & 0xff,
35368
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
414 suite.effectiveKeyBits,
35623
1bb4759f7b9b Remove stray whitespace.
Mark Doliner <mark@kingant.net>
parents: 35622
diff changeset
415 suite.symCipherName,
35368
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
416 suite.macBits,
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
417 suite.macAlgorithmName,
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
418 channel.authKeyBits,
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
419 suite.authAlgorithmName,
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
420 channel.keaKeyBits, suite.keaTypeName,
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
421 channel.compressionMethodName,
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
422 suite.cipherSuiteName);
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
423 }
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
424 }
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
425 }
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
426
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
427
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
428 static void
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
429 ssl_nss_handshake_cb(gpointer data, int fd, PurpleInputCondition cond)
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
430 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
431 PurpleSslConnection *gsc = (PurpleSslConnection *)data;
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
432 PurpleSslNssData *nss_data = gsc->private_data;
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
433
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
434 /* I don't think this the best way to do this...
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
435 * It seems to work because it'll eventually use the cached value
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
436 */
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
437 if(SSL_ForceHandshake(nss_data->in) != SECSuccess) {
19847
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
438 gchar *error_txt;
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
439 set_errno(PR_GetError());
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
440 if (errno == EAGAIN || errno == EWOULDBLOCK)
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
441 return;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
442
19847
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
443 error_txt = get_error_text();
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
444 purple_debug_error("nss", "Handshake failed %s (%d)\n", error_txt ? error_txt : "", PR_GetError());
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
445 g_free(error_txt);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
446
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
447 if (gsc->error_cb != NULL)
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
448 gsc->error_cb(gsc, PURPLE_SSL_HANDSHAKE_FAILED, gsc->connect_cb_data);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
449
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
450 purple_ssl_close(gsc);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
451
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
452 return;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
453 }
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
454
35622
b29a773d89c1 Avoid camel case function name.
Mark Doliner <mark@kingant.net>
parents: 35368
diff changeset
455 print_security_info(nss_data->in);
35368
9728bb0f6dcc Print information about the SSL connection to the debug log
Daniel Atallah <datallah@pidgin.im>
parents: 35135
diff changeset
456
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
457 purple_input_remove(nss_data->handshake_handler);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
458 nss_data->handshake_handler = 0;
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
459
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
460 /* If a Verifier was given, hand control over to it */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
461 if (gsc->verifier) {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
462 GList *peers;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
463 /* First, get the peer cert chain */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
464 peers = ssl_nss_get_peer_certificates(nss_data->in, gsc);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
465
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
466 /* Now kick off the verification process */
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
467 purple_certificate_verify(gsc->verifier,
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
468 gsc->host,
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
469 peers,
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
470 ssl_nss_verified_cb,
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
471 gsc);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
472
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
473 purple_certificate_destroy_list(peers);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
474 } else {
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
475 /* Otherwise, just call the "connection complete"
35135
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
476 * callback. The verification was already done with
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
477 * SSL_AuthCertificate, the default verifier
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
478 * (SSL_AuthCertificateHook was not called in ssl_nss_connect).
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
479 */
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
480 gsc->connect_cb(gsc->connect_cb_data, gsc, cond);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
481 }
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
482 }
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
483
29942
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
484 static gboolean
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
485 start_handshake_cb(gpointer data)
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
486 {
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
487 PurpleSslConnection *gsc = data;
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
488 PurpleSslNssData *nss_data = PURPLE_SSL_NSS_DATA(gsc);
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
489
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
490 nss_data->handshake_timer = 0;
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
491
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
492 ssl_nss_handshake_cb(gsc, gsc->fd, PURPLE_INPUT_READ);
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
493 return FALSE;
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
494 }
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
495
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
496 static void
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
497 ssl_nss_connect(PurpleSslConnection *gsc)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
498 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
499 PurpleSslNssData *nss_data = g_new0(PurpleSslNssData, 1);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
500 PRSocketOptionData socket_opt;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
501
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
502 gsc->private_data = nss_data;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
503
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
504 nss_data->fd = PR_ImportTCPSocket(gsc->fd);
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
505
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
506 if (nss_data->fd == NULL)
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
507 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
508 purple_debug_error("nss", "nss_data->fd == NULL!\n");
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
509
8362
1dc105ff1804 [gaim-migrate @ 9087]
Nathan Walp <nwalp@pidgin.im>
parents: 8360
diff changeset
510 if (gsc->error_cb != NULL)
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
511 gsc->error_cb(gsc, PURPLE_SSL_CONNECT_FAILED, gsc->connect_cb_data);
8362
1dc105ff1804 [gaim-migrate @ 9087]
Nathan Walp <nwalp@pidgin.im>
parents: 8360
diff changeset
512
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
513 purple_ssl_close((PurpleSslConnection *)gsc);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
514
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
515 return;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
516 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
517
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
518 socket_opt.option = PR_SockOpt_Nonblocking;
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
519 socket_opt.value.non_blocking = PR_TRUE;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
520
19847
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
521 if (PR_SetSocketOption(nss_data->fd, &socket_opt) != PR_SUCCESS) {
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
522 gchar *error_txt = get_error_text();
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
523 purple_debug_warning("nss", "unable to set socket into non-blocking mode: %s (%d)\n", error_txt ? error_txt : "", PR_GetError());
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
524 g_free(error_txt);
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
525 }
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
526
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
527 nss_data->in = SSL_ImportFD(NULL, nss_data->fd);
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
528
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
529 if (nss_data->in == NULL)
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
530 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
531 purple_debug_error("nss", "nss_data->in == NUL!\n");
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
532
8362
1dc105ff1804 [gaim-migrate @ 9087]
Nathan Walp <nwalp@pidgin.im>
parents: 8360
diff changeset
533 if (gsc->error_cb != NULL)
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
534 gsc->error_cb(gsc, PURPLE_SSL_CONNECT_FAILED, gsc->connect_cb_data);
8362
1dc105ff1804 [gaim-migrate @ 9087]
Nathan Walp <nwalp@pidgin.im>
parents: 8360
diff changeset
535
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
536 purple_ssl_close((PurpleSslConnection *)gsc);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
537
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
538 return;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
539 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
540
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
541 SSL_OptionSet(nss_data->in, SSL_SECURITY, PR_TRUE);
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
542 SSL_OptionSet(nss_data->in, SSL_HANDSHAKE_AS_CLIENT, PR_TRUE);
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
543
35135
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
544 /* If we have our internal verifier set up, use it. Otherwise,
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
545 * use default. */
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
546 if (gsc->verifier != NULL)
72bdcc0f7267 Clean up unused ssl/NSS code and write up some comments to resolve any doubts. Refs #15308
Tomasz Wasilczyk <twasilczyk@pidgin.im>
parents: 34242
diff changeset
547 SSL_AuthCertificateHook(nss_data->in, ssl_auth_cert, NULL);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
548
7157
aad2cacc9238 [gaim-migrate @ 7724]
Nathan Walp <nwalp@pidgin.im>
parents: 7053
diff changeset
549 if(gsc->host)
aad2cacc9238 [gaim-migrate @ 7724]
Nathan Walp <nwalp@pidgin.im>
parents: 7053
diff changeset
550 SSL_SetURL(nss_data->in, gsc->host);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
551
13264
f5db933aa42a [gaim-migrate @ 15629]
Björn Voigt <bjoern@cs.tu-berlin.de>
parents: 13201
diff changeset
552 #if 0
f5db933aa42a [gaim-migrate @ 15629]
Björn Voigt <bjoern@cs.tu-berlin.de>
parents: 13201
diff changeset
553 /* This seems like it'd the be the correct way to implement the
f5db933aa42a [gaim-migrate @ 15629]
Björn Voigt <bjoern@cs.tu-berlin.de>
parents: 13201
diff changeset
554 nonblocking stuff, but it doesn't seem to work */
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
555 SSL_HandshakeCallback(nss_data->in,
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
556 (SSLHandshakeCallback) ssl_nss_handshake_cb, gsc);
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
557 #endif
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
558 SSL_ResetHandshake(nss_data->in, PR_FALSE);
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
559
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
560 nss_data->handshake_handler = purple_input_add(gsc->fd,
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
561 PURPLE_INPUT_READ, ssl_nss_handshake_cb, gsc);
7274
42ec5f56e32a [gaim-migrate @ 7851]
Christian Hammond <chipx86@chipx86.com>
parents: 7157
diff changeset
562
29942
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
563 nss_data->handshake_timer = purple_timeout_add(0, start_handshake_cb, gsc);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
564 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
565
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
566 static void
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
567 ssl_nss_close(PurpleSslConnection *gsc)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
568 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
569 PurpleSslNssData *nss_data = PURPLE_SSL_NSS_DATA(gsc);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
570
7467
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7274
diff changeset
571 if(!nss_data)
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7274
diff changeset
572 return;
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7274
diff changeset
573
17623
4f45361d7e3b A while ago, "Paranoid" emailed devel@p.i, having noticed that purple_ssl_close() closes the ssl fd twice. I meant to commit this fix sooner, but here it is.
Daniel Atallah <datallah@pidgin.im>
parents: 16866
diff changeset
574 if (nss_data->in) {
4f45361d7e3b A while ago, "Paranoid" emailed devel@p.i, having noticed that purple_ssl_close() closes the ssl fd twice. I meant to commit this fix sooner, but here it is.
Daniel Atallah <datallah@pidgin.im>
parents: 16866
diff changeset
575 PR_Close(nss_data->in);
4f45361d7e3b A while ago, "Paranoid" emailed devel@p.i, having noticed that purple_ssl_close() closes the ssl fd twice. I meant to commit this fix sooner, but here it is.
Daniel Atallah <datallah@pidgin.im>
parents: 16866
diff changeset
576 gsc->fd = -1;
4f45361d7e3b A while ago, "Paranoid" emailed devel@p.i, having noticed that purple_ssl_close() closes the ssl fd twice. I meant to commit this fix sooner, but here it is.
Daniel Atallah <datallah@pidgin.im>
parents: 16866
diff changeset
577 } else if (nss_data->fd) {
4f45361d7e3b A while ago, "Paranoid" emailed devel@p.i, having noticed that purple_ssl_close() closes the ssl fd twice. I meant to commit this fix sooner, but here it is.
Daniel Atallah <datallah@pidgin.im>
parents: 16866
diff changeset
578 PR_Close(nss_data->fd);
4f45361d7e3b A while ago, "Paranoid" emailed devel@p.i, having noticed that purple_ssl_close() closes the ssl fd twice. I meant to commit this fix sooner, but here it is.
Daniel Atallah <datallah@pidgin.im>
parents: 16866
diff changeset
579 gsc->fd = -1;
4f45361d7e3b A while ago, "Paranoid" emailed devel@p.i, having noticed that purple_ssl_close() closes the ssl fd twice. I meant to commit this fix sooner, but here it is.
Daniel Atallah <datallah@pidgin.im>
parents: 16866
diff changeset
580 }
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
581
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
582 if (nss_data->handshake_handler)
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
583 purple_input_remove(nss_data->handshake_handler);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
584
29942
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
585 if (nss_data->handshake_timer)
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
586 purple_timeout_remove(nss_data->handshake_timer);
4c74f05635c5 gnutls/nss: Don't call the handshake functions synchronously. Fixes #11525
Paul Aurich <darkrain42@pidgin.im>
parents: 29930
diff changeset
587
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
588 g_free(nss_data);
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
589 gsc->private_data = NULL;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
590 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
591
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
592 static size_t
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
593 ssl_nss_read(PurpleSslConnection *gsc, void *data, size_t len)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
594 {
33841
d91084abb15c Fix return types for PR_Read/PR_Write.
Elliott Sales de Andrade <qulogic@pidgin.im>
parents: 33810
diff changeset
595 PRInt32 ret;
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
596 PurpleSslNssData *nss_data = PURPLE_SSL_NSS_DATA(gsc);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
597
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
598 ret = PR_Read(nss_data->in, data, len);
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
599
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
600 if (ret == -1)
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
601 set_errno(PR_GetError());
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
602
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
603 return ret;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
604 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
605
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
606 static size_t
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
607 ssl_nss_write(PurpleSslConnection *gsc, const void *data, size_t len)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
608 {
33841
d91084abb15c Fix return types for PR_Read/PR_Write.
Elliott Sales de Andrade <qulogic@pidgin.im>
parents: 33810
diff changeset
609 PRInt32 ret;
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
610 PurpleSslNssData *nss_data = PURPLE_SSL_NSS_DATA(gsc);
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
611
7467
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7274
diff changeset
612 if(!nss_data)
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7274
diff changeset
613 return 0;
a459b5408f83 [gaim-migrate @ 8080]
Nathan Walp <nwalp@pidgin.im>
parents: 7274
diff changeset
614
13201
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
615 ret = PR_Write(nss_data->in, data, len);
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
616
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
617 if (ret == -1)
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
618 set_errno(PR_GetError());
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
619
8c224ef70efa [gaim-migrate @ 15563]
Daniel Atallah <datallah@pidgin.im>
parents: 12209
diff changeset
620 return ret;
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
621 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
622
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
623 static GList *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
624 ssl_nss_peer_certs(PurpleSslConnection *gsc)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
625 {
20221
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
626 #if 0
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
627 PurpleSslNssData *nss_data = PURPLE_SSL_NSS_DATA(gsc);
19847
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
628 CERTCertificate *cert;
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
629 /*
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
630 GList *chain = NULL;
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
631 void *pinArg;
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
632 SECStatus status;
19847
c53701927784 Attempt to display user readable error messages for NSS.
Daniel Atallah <datallah@pidgin.im>
parents: 19827
diff changeset
633 */
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
634
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
635 /* TODO: this is a blind guess */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
636 cert = SSL_PeerCertificate(nss_data->fd);
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
637
20221
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
638 if (cert)
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
639 CERT_DestroyCertificate(cert);
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
640 #endif
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
641
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
642
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
643
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
644 return NULL;
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
645 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
646
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
647 /************************************************************************/
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
648 /* X.509 functionality */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
649 /************************************************************************/
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
650 static PurpleCertificateScheme x509_nss;
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
651
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
652 /** Helpr macro to retrieve the NSS certdata from a PurpleCertificate */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
653 #define X509_NSS_DATA(pcrt) ( (CERTCertificate * ) (pcrt->data) )
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
654
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
655 /** Imports a PEM-formatted X.509 certificate from the specified file.
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
656 * @param filename Filename to import from. Format is PEM
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
657 *
29930
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
658 * @return A newly allocated Certificate structure of the x509_nss scheme
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
659 */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
660 static PurpleCertificate *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
661 x509_import_from_file(const gchar *filename)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
662 {
19486
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
663 gchar *rawcert;
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
664 gsize len = 0;
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
665 CERTCertificate *crt_dat;
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
666 PurpleCertificate *crt;
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
667
27823
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
668 g_return_val_if_fail(filename != NULL, NULL);
19486
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
669
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
670 purple_debug_info("nss/x509",
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
671 "Loading certificate from %s\n",
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
672 filename);
27823
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
673
19486
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
674 /* Load the raw data up */
20221
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
675 if (!g_file_get_contents(filename,
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
676 &rawcert, &len,
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
677 NULL)) {
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
678 purple_debug_error("nss/x509", "Unable to read certificate file.\n");
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
679 return NULL;
28e31ee832cd applied changes from e56db1b8a7bb8729e30fb3bf99a94ff7887fe4ec
Luke Schierer <lschiere@pidgin.im>
parents: 19984
diff changeset
680 }
19486
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
681
27823
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
682 if (len == 0) {
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
683 purple_debug_error("nss/x509",
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
684 "Certificate file has no contents!\n");
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
685 if (rawcert)
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
686 g_free(rawcert);
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
687 return NULL;
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
688 }
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
689
19486
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
690 /* Decode the certificate */
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
691 crt_dat = CERT_DecodeCertFromPackage(rawcert, len);
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
692 g_free(rawcert);
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
693
27823
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
694 g_return_val_if_fail(crt_dat != NULL, NULL);
8eb52a9d3a6d Continue verification when we can't find a *cached* peer. Fixes #9664.
Paul Aurich <darkrain42@pidgin.im>
parents: 27692
diff changeset
695
19486
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
696 crt = g_new0(PurpleCertificate, 1);
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
697 crt->scheme = &x509_nss;
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
698 crt->data = crt_dat;
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
699
19486
83d0375f1784 - Add x509_import_from_file
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19485
diff changeset
700 return crt;
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
701 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
702
29930
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
703 /** Imports a number of PEM-formatted X.509 certificates from the specified file.
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
704 * @param filename Filename to import from. Format is PEM
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
705 *
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
706 * @return A GSList of newly allocated Certificate structures of the x509_nss scheme
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
707 */
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
708 static GSList *
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
709 x509_importcerts_from_file(const gchar *filename)
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
710 {
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
711 gchar *rawcert, *begin, *end;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
712 gsize len = 0;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
713 GSList *crts = NULL;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
714 CERTCertificate *crt_dat;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
715 PurpleCertificate *crt;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
716
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
717 g_return_val_if_fail(filename != NULL, NULL);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
718
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
719 purple_debug_info("nss/x509",
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
720 "Loading certificate from %s\n",
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
721 filename);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
722
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
723 /* Load the raw data up */
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
724 if (!g_file_get_contents(filename,
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
725 &rawcert, &len,
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
726 NULL)) {
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
727 purple_debug_error("nss/x509", "Unable to read certificate file.\n");
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
728 return NULL;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
729 }
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
730
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
731 if (len == 0) {
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
732 purple_debug_error("nss/x509",
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
733 "Certificate file has no contents!\n");
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
734 if (rawcert)
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
735 g_free(rawcert);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
736 return NULL;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
737 }
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
738
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
739 begin = rawcert;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
740 while((end = strstr(begin, "-----END CERTIFICATE-----")) != NULL) {
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
741 end += sizeof("-----END CERTIFICATE-----")-1;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
742 /* Decode the certificate */
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
743 crt_dat = CERT_DecodeCertFromPackage(begin, (end-begin));
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
744
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
745 g_return_val_if_fail(crt_dat != NULL, NULL);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
746
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
747 crt = g_new0(PurpleCertificate, 1);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
748 crt->scheme = &x509_nss;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
749 crt->data = crt_dat;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
750 crts = g_slist_prepend(crts, crt);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
751 begin = end;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
752 }
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
753 g_free(rawcert);
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
754
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
755 return crts;
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
756 }
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
757 /**
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
758 * Exports a PEM-formatted X.509 certificate to the specified file.
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
759 * @param filename Filename to export to. Format will be PEM
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
760 * @param crt Certificate to export
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
761 *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
762 * @return TRUE if success, otherwise FALSE
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
763 */
19983
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
764 /* This function should not be so complicated, but NSS doesn't seem to have a
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
765 "convert yon certificate to PEM format" function. */
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
766 static gboolean
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
767 x509_export_certificate(const gchar *filename, PurpleCertificate *crt)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
768 {
19983
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
769 CERTCertificate *crt_dat;
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
770 SECItem *dercrt;
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
771 gchar *b64crt;
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
772 gchar *pemcrt;
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
773 gboolean ret = FALSE;
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
774
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
775 g_return_val_if_fail(filename, FALSE);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
776 g_return_val_if_fail(crt, FALSE);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
777 g_return_val_if_fail(crt->scheme == &x509_nss, FALSE);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
778
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
779 crt_dat = X509_NSS_DATA(crt);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
780 g_return_val_if_fail(crt_dat, FALSE);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
781
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
782 purple_debug_info("nss/x509",
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
783 "Exporting certificate to %s\n", filename);
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
784
19983
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
785 /* First, use NSS voodoo to create a DER-formatted certificate */
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
786 dercrt = SEC_ASN1EncodeItem(NULL, NULL, crt_dat,
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
787 SEC_ASN1_GET(SEC_SignedCertificateTemplate));
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
788 g_return_val_if_fail(dercrt != NULL, FALSE);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
789
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
790 /* Now encode it to b64 */
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
791 b64crt = NSSBase64_EncodeItem(NULL, NULL, 0, dercrt);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
792 SECITEM_FreeItem(dercrt, PR_TRUE);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
793 g_return_val_if_fail(b64crt, FALSE);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
794
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
795 /* Wrap it in nice PEM header things */
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
796 pemcrt = g_strdup_printf("-----BEGIN CERTIFICATE-----\n%s\n-----END CERTIFICATE-----\n", b64crt);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
797 PORT_Free(b64crt); /* Notice that b64crt was allocated by an NSS
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
798 function; hence, we'll let NSPR free it. */
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
799
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
800 /* Finally, dump the silly thing to a file. */
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
801 ret = purple_util_write_data_to_file_absolute(filename, pemcrt, -1);
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
802
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
803 g_free(pemcrt);
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
804
19983
2d79626570ae - Make ssl-nss x509_export_certificate work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19982
diff changeset
805 return ret;
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
806 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
807
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
808 static PurpleCertificate *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
809 x509_copy_certificate(PurpleCertificate *crt)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
810 {
19009
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
811 CERTCertificate *crt_dat;
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
812 PurpleCertificate *newcrt;
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
813
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
814 g_return_val_if_fail(crt, NULL);
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
815 g_return_val_if_fail(crt->scheme == &x509_nss, NULL);
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
816
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
817 crt_dat = X509_NSS_DATA(crt);
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
818 g_return_val_if_fail(crt_dat, NULL);
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
819
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
820 /* Create the certificate copy */
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
821 newcrt = g_new0(PurpleCertificate, 1);
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
822 newcrt->scheme = &x509_nss;
19023
547e94194c7a - Comment on NSS's refcounting prowess
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19014
diff changeset
823 /* NSS does refcounting automatically */
19009
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
824 newcrt->data = CERT_DupCertificate(crt_dat);
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
825
19009
01fe9523e6d6 - x509_nss copy op
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19008
diff changeset
826 return newcrt;
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
827 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
828
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
829 /** Frees a Certificate
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
830 *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
831 * Destroys a Certificate's internal data structures and frees the pointer
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
832 * given.
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
833 * @param crt Certificate instance to be destroyed. It WILL NOT be destroyed
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
834 * if it is not of the correct CertificateScheme. Can be NULL
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
835 *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
836 */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
837 static void
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
838 x509_destroy_certificate(PurpleCertificate * crt)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
839 {
19010
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
840 CERTCertificate *crt_dat;
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
841
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
842 g_return_if_fail(crt);
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
843 g_return_if_fail(crt->scheme == &x509_nss);
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
844
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
845 crt_dat = X509_NSS_DATA(crt);
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
846 g_return_if_fail(crt_dat);
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
847
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
848 /* Finally we have the certificate. So let's kill it */
19023
547e94194c7a - Comment on NSS's refcounting prowess
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19014
diff changeset
849 /* NSS does refcounting automatically */
19010
ad839d846fae - x509_nss destroy_certificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19009
diff changeset
850 CERT_DestroyCertificate(crt_dat);
19027
921b7e331382 - x509_destroy_certificate is supposed to free the PurpleCertificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19023
diff changeset
851
921b7e331382 - x509_destroy_certificate is supposed to free the PurpleCertificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19023
diff changeset
852 /* Delete the PurpleCertificate as well */
921b7e331382 - x509_destroy_certificate is supposed to free the PurpleCertificate
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19023
diff changeset
853 g_free(crt);
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
854 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
855
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
856 /** Determines whether one certificate has been issued and signed by another
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
857 *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
858 * @param crt Certificate to check the signature of
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
859 * @param issuer Issuer's certificate
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
860 *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
861 * @return TRUE if crt was signed and issued by issuer, otherwise FALSE
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
862 * @TODO Modify this function to return a reason for invalidity?
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
863 */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
864 static gboolean
19980
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
865 x509_signed_by(PurpleCertificate * crt,
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
866 PurpleCertificate * issuer)
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
867 {
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
868 CERTCertificate *subjectCert;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
869 CERTCertificate *issuerCert;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
870 SECStatus st;
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
871
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
872 issuerCert = X509_NSS_DATA(issuer);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
873 g_return_val_if_fail(issuerCert, FALSE);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
874
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
875 subjectCert = X509_NSS_DATA(crt);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
876 g_return_val_if_fail(subjectCert, FALSE);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
877
33810
8b2f9fad7227 ssl-nss: Fix handling of certificates without a Subject.
Daniel Atallah <datallah@pidgin.im>
parents: 33669
diff changeset
878 if (subjectCert->issuerName == NULL || issuerCert->subjectName == NULL
24276
469eea3c328d Fix a NULL pointer deref in the NSS SSL implementation with certain self-signed
Daniel Atallah <datallah@pidgin.im>
parents: 24065
diff changeset
879 || PORT_Strcmp(subjectCert->issuerName, issuerCert->subjectName) != 0)
24065
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
880 return FALSE;
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
881 st = CERT_VerifySignedData(&subjectCert->signatureWrap, issuerCert, PR_Now(), NULL);
bfc4c0035d91 Patch to fully enable NSS SSL Certificates from #6500.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 22104
diff changeset
882 return st == SECSuccess;
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
883 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
884
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
885 static GByteArray *
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
886 x509_sha1sum(PurpleCertificate *crt)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
887 {
19014
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
888 CERTCertificate *crt_dat;
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
889 size_t hashlen = 20; /* Size of an sha1sum */
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
890 GByteArray *sha1sum;
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
891 SECItem *derCert; /* DER representation of the cert */
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
892 SECStatus st;
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
893
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
894 g_return_val_if_fail(crt, NULL);
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
895 g_return_val_if_fail(crt->scheme == &x509_nss, NULL);
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
896
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
897 crt_dat = X509_NSS_DATA(crt);
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
898 g_return_val_if_fail(crt_dat, NULL);
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
899
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
900 /* Get the certificate DER representation */
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
901 derCert = &(crt_dat->derCert);
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
902
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
903 /* Make a hash! */
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
904 sha1sum = g_byte_array_sized_new(hashlen);
19797
92736e34b16a - ssl-nss now reports a certificate's sha1sum correctly
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19671
diff changeset
905 /* glib leaves the size as 0 by default */
92736e34b16a - ssl-nss now reports a certificate's sha1sum correctly
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19671
diff changeset
906 sha1sum->len = hashlen;
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
907
19014
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
908 st = PK11_HashBuf(SEC_OID_SHA1, sha1sum->data,
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
909 derCert->data, derCert->len);
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
910
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
911 /* Check for errors */
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
912 if (st != SECSuccess) {
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
913 g_byte_array_free(sha1sum, TRUE);
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
914 purple_debug_error("nss/x509",
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
915 "Error: hashing failed!\n");
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
916 return NULL;
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
917 }
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
918
1a67cc27fb12 - x509_nss sha1sum
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19013
diff changeset
919 return sha1sum;
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
920 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
921
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
922 static gchar *
19980
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
923 x509_dn (PurpleCertificate *crt)
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
924 {
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
925 CERTCertificate *crt_dat;
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
926
19980
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
927 g_return_val_if_fail(crt, NULL);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
928 g_return_val_if_fail(crt->scheme == &x509_nss, NULL);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
929
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
930 crt_dat = X509_NSS_DATA(crt);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
931 g_return_val_if_fail(crt_dat, NULL);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
932
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
933 return g_strdup(crt_dat->subjectName);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
934 }
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
935
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
936 static gchar *
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
937 x509_issuer_dn (PurpleCertificate *crt)
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
938 {
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
939 CERTCertificate *crt_dat;
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
940
19980
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
941 g_return_val_if_fail(crt, NULL);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
942 g_return_val_if_fail(crt->scheme == &x509_nss, NULL);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
943
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
944 crt_dat = X509_NSS_DATA(crt);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
945 g_return_val_if_fail(crt_dat, NULL);
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
946
24577
fdb8b167200e x509_issuer_dn() should return the certificate's issuer name, not the cert
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 24513
diff changeset
947 return g_strdup(crt_dat->issuerName);
19980
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
948 }
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
949
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
950 static gchar *
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
951 x509_common_name (PurpleCertificate *crt)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
952 {
19011
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
953 CERTCertificate *crt_dat;
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
954 char *nss_cn;
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
955 gchar *ret_cn;
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
956
19011
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
957 g_return_val_if_fail(crt, NULL);
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
958 g_return_val_if_fail(crt->scheme == &x509_nss, NULL);
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
959
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
960 crt_dat = X509_NSS_DATA(crt);
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
961 g_return_val_if_fail(crt_dat, NULL);
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
962
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
963 /* Q:
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
964 Why get a newly allocated string out of NSS, strdup it, and then
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
965 return the new copy?
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
966
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
967 A:
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
968 The NSS LXR docs state that I should use the NSPR free functions on
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
969 the strings that the NSS cert functions return. Since the libpurple
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
970 API expects a g_free()-able string, we make our own copy and return
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
971 that.
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
972
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
973 NSPR is something of a prima donna. */
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
974
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
975 nss_cn = CERT_GetCommonName( &(crt_dat->subject) );
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
976 ret_cn = g_strdup(nss_cn);
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
977 PORT_Free(nss_cn);
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
978
21cdaee203e8 - x509_nss get_subject_name (x509_common_name)
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19010
diff changeset
979 return ret_cn;
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
980 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
981
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
982 static gboolean
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
983 x509_check_name (PurpleCertificate *crt, const gchar *name)
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
984 {
19012
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
985 CERTCertificate *crt_dat;
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
986 SECStatus st;
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
987
19012
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
988 g_return_val_if_fail(crt, FALSE);
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
989 g_return_val_if_fail(crt->scheme == &x509_nss, FALSE);
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
990
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
991 crt_dat = X509_NSS_DATA(crt);
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
992 g_return_val_if_fail(crt_dat, FALSE);
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
993
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
994 st = CERT_VerifyCertName(crt_dat, name);
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
995
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
996 if (st == SECSuccess) {
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
997 return TRUE;
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
998 }
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
999 else if (st == SECFailure) {
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
1000 return FALSE;
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
1001 }
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
1002
19012
7813c38f34e9 - ssl-nss x509_nss check_name
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19011
diff changeset
1003 /* If we get here...bad things! */
19671
3848f6f679fd - Change g_assert to purple_debug_error
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19486
diff changeset
1004 purple_debug_error("nss/x509",
3848f6f679fd - Change g_assert to purple_debug_error
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19486
diff changeset
1005 "x509_check_name fell through where it shouldn't "
3848f6f679fd - Change g_assert to purple_debug_error
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19486
diff changeset
1006 "have.\n");
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1007 return FALSE;
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1008 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1009
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1010 static gboolean
36167
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1011 x509_times (PurpleCertificate *crt, gint64 *activation, gint64 *expiration)
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1012 {
19013
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1013 CERTCertificate *crt_dat;
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1014 PRTime nss_activ, nss_expir;
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
1015
19013
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1016 g_return_val_if_fail(crt, FALSE);
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1017 g_return_val_if_fail(crt->scheme == &x509_nss, FALSE);
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1018
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1019 crt_dat = X509_NSS_DATA(crt);
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1020 g_return_val_if_fail(crt_dat, FALSE);
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1021
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1022 /* Extract the times into ugly PRTime thingies */
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1023 /* TODO: Maybe this shouldn't throw an error? */
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1024 g_return_val_if_fail(
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1025 SECSuccess == CERT_GetCertTimes(crt_dat,
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1026 &nss_activ, &nss_expir),
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1027 FALSE);
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1028
19982
1b453261f6ec - Fix ssl-nss x509 to properly convert NSPR PRTime to time_t (in
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19980
diff changeset
1029 /* NSS's native PRTime type *almost* corresponds to time_t; however,
1b453261f6ec - Fix ssl-nss x509 to properly convert NSPR PRTime to time_t (in
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19980
diff changeset
1030 it measures *microseconds* since the epoch, not seconds. Hence
1b453261f6ec - Fix ssl-nss x509 to properly convert NSPR PRTime to time_t (in
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19980
diff changeset
1031 the funny conversion. */
34242
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
1032 nss_activ = nss_activ / 1000000;
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
1033 nss_expir = nss_expir / 1000000;
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
1034
19013
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1035 if (activation) {
34242
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
1036 *activation = nss_activ;
19013
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1037 }
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1038 if (expiration) {
34242
2aa4d5ab8916 Add workaround so that certificates with times that can't be represented using
Daniel Atallah <datallah@pidgin.im>
parents: 33841
diff changeset
1039 *expiration = nss_expir;
19013
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1040 }
31294
73607ab89c6f Remove trailing whitespace
Richard Laager <rlaager@pidgin.im>
parents: 29943
diff changeset
1041
19013
60c74d9597f3 - x509_nss get_times
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19012
diff changeset
1042 return TRUE;
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1043 }
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1044
36167
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1045 static GByteArray *
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1046 x509_get_der_data(PurpleCertificate *crt)
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1047 {
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1048 CERTCertificate *crt_dat;
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1049 SECItem *dercrt;
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1050 GByteArray *data;
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1051
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1052 crt_dat = X509_NSS_DATA(crt);
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1053 g_return_val_if_fail(crt_dat, NULL);
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1054
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1055 dercrt = SEC_ASN1EncodeItem(NULL, NULL, crt_dat,
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1056 SEC_ASN1_GET(SEC_SignedCertificateTemplate));
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1057 g_return_val_if_fail(dercrt != NULL, FALSE);
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1058
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1059 data = g_byte_array_sized_new(dercrt->len);
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1060 memcpy(data->data, dercrt->data, dercrt->len);
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1061 data->len = dercrt->len;
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1062
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1063 SECITEM_FreeItem(dercrt, PR_TRUE);
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1064
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1065 return data;
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1066 }
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1067
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1068 static gboolean
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1069 x509_register_trusted_tls_cert(PurpleCertificate *crt, gboolean ca)
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1070 {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1071 CERTCertDBHandle *certdb = CERT_GetDefaultCertDB();
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1072 CERTCertificate *crt_dat;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1073 CERTCertTrust trust;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1074
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1075 g_return_val_if_fail(crt, FALSE);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1076 g_return_val_if_fail(crt->scheme == &x509_nss, FALSE);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1077
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1078 crt_dat = X509_NSS_DATA(crt);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1079 g_return_val_if_fail(crt_dat, FALSE);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1080
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1081 purple_debug_info("nss", "Trusting %s\n", crt_dat->subjectName);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1082
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1083 if (ca && !CERT_IsCACert(crt_dat, NULL)) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1084 purple_debug_error("nss",
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1085 "Refusing to set non-CA cert as trusted CA\n");
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1086 return FALSE;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1087 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1088
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1089 if (crt_dat->isperm) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1090 purple_debug_info("nss",
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1091 "Skipping setting trust for cert in permanent DB\n");
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1092 return TRUE;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1093 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1094
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1095 if (ca) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1096 trust.sslFlags = CERTDB_TRUSTED_CA | CERTDB_TRUSTED_CLIENT_CA;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1097 } else {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1098 trust.sslFlags = CERTDB_TRUSTED;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1099 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1100 trust.emailFlags = 0;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1101 trust.objectSigningFlags = 0;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1102
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1103 CERT_ChangeCertTrust(certdb, crt_dat, &trust);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1104
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1105 return TRUE;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1106 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1107
36201
bf10d2bb6919 Fix problems from the merge from release-2.x.y.
Mark Doliner <mark@kingant.net>
parents: 36200
diff changeset
1108 static void x509_verify_cert(PurpleCertificateVerificationRequest *vrq, PurpleCertificateVerificationStatus *flags)
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1109 {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1110 CERTCertDBHandle *certdb = CERT_GetDefaultCertDB();
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1111 CERTCertificate *crt_dat;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1112 PRTime now = PR_Now();
36207
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1113 SECStatus rv;
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1114 PurpleCertificate *first_cert = vrq->cert_chain->data;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1115 CERTVerifyLog log;
36207
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1116 gboolean self_signed = FALSE;
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1117
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1118 crt_dat = X509_NSS_DATA(first_cert);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1119
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1120 log.arena = PORT_NewArena(512);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1121 log.head = log.tail = NULL;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1122 log.count = 0;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1123 rv = CERT_VerifyCert(certdb, crt_dat, PR_TRUE, certUsageSSLServer, now, NULL, &log);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1124
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1125 if (rv != SECSuccess || log.count > 0) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1126 CERTVerifyLogNode *node = NULL;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1127 unsigned int depth = (unsigned int)-1;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1128
36207
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1129 if (crt_dat->isRoot) {
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1130 self_signed = TRUE;
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1131 *flags |= PURPLE_CERTIFICATE_SELF_SIGNED;
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1132 }
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1133
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1134 /* Handling of untrusted, etc. modeled after
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1135 * source/security/manager/ssl/src/TransportSecurityInfo.cpp in Firefox
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1136 */
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1137 for (node = log.head; node; node = node->next) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1138 if (depth != node->depth) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1139 depth = node->depth;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1140 purple_debug_error("nss", "CERT %d. %s %s:\n", depth,
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1141 node->cert->subjectName,
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1142 depth ? "[Certificate Authority]": "");
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1143 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1144 purple_debug_error("nss", " ERROR %ld: %s\n", node->error,
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1145 PR_ErrorToName(node->error));
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1146 switch (node->error) {
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1147 case SEC_ERROR_EXPIRED_CERTIFICATE:
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1148 *flags |= PURPLE_CERTIFICATE_EXPIRED;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1149 break;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1150 case SEC_ERROR_REVOKED_CERTIFICATE:
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1151 *flags |= PURPLE_CERTIFICATE_REVOKED;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1152 break;
36204
9086eaeacd2c Improve NSS handling for unknown CAs
Daniel Atallah <datallah@pidgin.im>
parents: 36191
diff changeset
1153 case SEC_ERROR_UNKNOWN_ISSUER:
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1154 case SEC_ERROR_UNTRUSTED_ISSUER:
36207
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1155 if (!self_signed) {
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1156 *flags |= PURPLE_CERTIFICATE_CA_UNKNOWN;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1157 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1158 break;
36207
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1159 case SEC_ERROR_CA_CERT_INVALID:
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1160 case SEC_ERROR_EXPIRED_ISSUER_CERTIFICATE:
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1161 case SEC_ERROR_UNTRUSTED_CERT:
36219
703e982d8d18 Fix building with NSS 3.10.8 (which is what squeeze has and is probably the oldest we need to worry about)
Daniel Atallah <datallah@pidgin.im>
parents: 36209
diff changeset
1162 #ifdef SEC_ERROR_CERT_SIGNATURE_ALGORITHM_DISABLED
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1163 case SEC_ERROR_CERT_SIGNATURE_ALGORITHM_DISABLED:
36219
703e982d8d18 Fix building with NSS 3.10.8 (which is what squeeze has and is probably the oldest we need to worry about)
Daniel Atallah <datallah@pidgin.im>
parents: 36209
diff changeset
1164 #endif
36207
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1165 if (!self_signed) {
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1166 *flags |= PURPLE_CERTIFICATE_INVALID_CHAIN;
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1167 }
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1168 break;
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1169 case SEC_ERROR_BAD_SIGNATURE:
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1170 default:
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1171 *flags |= PURPLE_CERTIFICATE_INVALID_CHAIN;
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1172 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1173 if (node->cert)
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1174 CERT_DestroyCertificate(node->cert);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1175 }
36207
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1176 }
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1177
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1178 rv = CERT_VerifyCertName(crt_dat, vrq->subject_name);
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1179 if (rv != SECSuccess) {
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1180 purple_debug_error("nss", "subject name not verified\n");
befb6523dc5c Fix NSS handling of self-signed certificates. Fixes #16412.
Daniel Atallah <datallah@pidgin.im>
parents: 36204
diff changeset
1181 *flags |= PURPLE_CERTIFICATE_NAME_MISMATCH;
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1182 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1183
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1184 PORT_FreeArena(log.arena, PR_FALSE);
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1185 }
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1186
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1187 static PurpleCertificateScheme x509_nss = {
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1188 "x509", /* Scheme name */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1189 N_("X.509 Certificates"), /* User-visible scheme name */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1190 x509_import_from_file, /* Certificate import function */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1191 x509_export_certificate, /* Certificate export function */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1192 x509_copy_certificate, /* Copy */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1193 x509_destroy_certificate, /* Destroy cert */
19980
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
1194 x509_signed_by, /* Signed-by */
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1195 x509_sha1sum, /* SHA1 fingerprint */
19980
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
1196 x509_dn, /* Unique ID */
35d5d780ba42 - Make ssl-nss unique_id and issuer_unique_id work
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19859
diff changeset
1197 x509_issuer_dn, /* Issuer Unique ID */
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1198 x509_common_name, /* Subject name */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1199 x509_check_name, /* Check subject name */
19827
62c3805f723e - Add purple_reserved fields to various structures.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19797
diff changeset
1200 x509_times, /* Activation/Expiration time */
29930
80f4616de5ce Implement reading multiple certificates from a single "bundle" of
Stu Tomlinson <nosnilmot@pidgin.im>
parents: 27935
diff changeset
1201 x509_importcerts_from_file, /* Multiple certificate import function */
36167
21ef99aa6390 Fix merge issues from c3e87cb60c02
Daniel Atallah <datallah@pidgin.im>
parents: 36166
diff changeset
1202 x509_get_der_data, /* Binary DER data */
36191
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1203 x509_register_trusted_tls_cert, /* Register a certificate as trusted for TLS */
2e4475087f04 Fix basic constraints checking for both our SSL plugins.
Mark Doliner <mark@kingant.net>
parents: 36165
diff changeset
1204 x509_verify_cert, /* Verify that the specified cert chain is trusted */
19827
62c3805f723e - Add purple_reserved fields to various structures.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19797
diff changeset
1205
36200
4721e2194afa Merge changes from the release-2.x.y branch into master.
Mark Doliner <mark@kingant.net>
parents: 36167 36191
diff changeset
1206 NULL,
4721e2194afa Merge changes from the release-2.x.y branch into master.
Mark Doliner <mark@kingant.net>
parents: 36167 36191
diff changeset
1207 NULL,
19827
62c3805f723e - Add purple_reserved fields to various structures.
William Ehlhardt <williamehlhardt@gmail.com>
parents: 19797
diff changeset
1208 NULL
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1209 };
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1210
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1211 static PurpleSslOps ssl_ops =
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1212 {
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1213 ssl_nss_init,
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1214 ssl_nss_uninit,
14222
71d8761db708 [gaim-migrate @ 16808]
Mark Doliner <markdoliner@pidgin.im>
parents: 13530
diff changeset
1215 ssl_nss_connect,
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1216 ssl_nss_close,
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1217 ssl_nss_read,
16744
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1218 ssl_nss_write,
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1219 ssl_nss_peer_certs,
16744
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1220
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1221 /* padding */
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1222 NULL,
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1223 NULL,
36237
47cc3f47592c Fix merged NSS stuff for 3.0.0 (hopefully)
Daniel Atallah <datallah@pidgin.im>
parents: 36229
diff changeset
1224 NULL,
16744
fcdab37ba1c2 Added NULL pads to ssl stuff
Gary Kramlich <grim@reaperworld.com>
parents: 16158
diff changeset
1225 NULL
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1226 };
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1227
36501
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1228 static PurplePluginInfo *
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1229 plugin_query(GError **error)
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1230 {
36642
b8ba53daa445 Updated libpurple to use current GPlugin
Ankit Vani <a@nevitus.org>
parents: 36505
diff changeset
1231 const gchar * const authors[] = {
b8ba53daa445 Updated libpurple to use current GPlugin
Ankit Vani <a@nevitus.org>
parents: 36505
diff changeset
1232 "Christian Hammond <chipx86@gnupdate.org>",
b8ba53daa445 Updated libpurple to use current GPlugin
Ankit Vani <a@nevitus.org>
parents: 36505
diff changeset
1233 NULL
b8ba53daa445 Updated libpurple to use current GPlugin
Ankit Vani <a@nevitus.org>
parents: 36505
diff changeset
1234 };
b8ba53daa445 Updated libpurple to use current GPlugin
Ankit Vani <a@nevitus.org>
parents: 36505
diff changeset
1235
36501
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1236 return purple_plugin_info_new(
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1237 "id", SSL_NSS_PLUGIN_ID,
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1238 "name", N_("NSS"),
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1239 "version", DISPLAY_VERSION,
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1240 "category", N_("SSL"),
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1241 "summary", N_("Provides SSL support through Mozilla NSS."),
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1242 "description", N_("Provides SSL support through Mozilla NSS."),
36642
b8ba53daa445 Updated libpurple to use current GPlugin
Ankit Vani <a@nevitus.org>
parents: 36505
diff changeset
1243 "authors", authors,
36501
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1244 "website", PURPLE_WEBSITE,
36505
60c161851325 Integrated purple ABI requirement into GPlugin's "abi-version" property
Ankit Vani <a@nevitus.org>
parents: 36501
diff changeset
1245 "abi-version", PURPLE_ABI_VERSION,
36653
4084c34c051d Override gplugin info's "flags" property. Added PURPLE_PLUGIN_INFO_FLAGS_INTERNAL and PURPLE_PLUGIN_INFO_FLAGS_AUTO_LOAD.
Ankit Vani <a@nevitus.org>
parents: 36642
diff changeset
1246 "flags", PURPLE_PLUGIN_INFO_FLAGS_INTERNAL,
36501
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1247 NULL
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1248 );
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1249 }
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1250
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1251 static gboolean
36501
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1252 plugin_load(PurplePlugin *plugin, GError **error)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1253 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1254 if (!purple_ssl_get_ops()) {
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1255 purple_ssl_set_ops(&ssl_ops);
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
1256 }
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1257
11033
dc68e074f10d [gaim-migrate @ 12919]
Etan Reisner <deryni@pidgin.im>
parents: 10519
diff changeset
1258 /* Init NSS now, so others can use it even if sslconn never does */
dc68e074f10d [gaim-migrate @ 12919]
Etan Reisner <deryni@pidgin.im>
parents: 10519
diff changeset
1259 ssl_nss_init_nss();
dc68e074f10d [gaim-migrate @ 12919]
Etan Reisner <deryni@pidgin.im>
parents: 10519
diff changeset
1260
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1261 /* Register the X.509 functions we provide */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1262 purple_certificate_register_scheme(&x509_nss);
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1263
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1264 return TRUE;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1265 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1266
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1267 static gboolean
36501
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1268 plugin_unload(PurplePlugin *plugin, GError **error)
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1269 {
15884
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1270 if (purple_ssl_get_ops() == &ssl_ops) {
4de1981757fc sed -ie 's/gaim/purple/g'
Sean Egan <seanegan@pidgin.im>
parents: 15435
diff changeset
1271 purple_ssl_set_ops(NULL);
7862
9b96706e44e7 [gaim-migrate @ 8516]
Bill Tompkins <obobo@users.sourceforge.net>
parents: 7467
diff changeset
1272 }
19008
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1273
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1274 /* Unregister our X.509 functions */
222e4861b5a2 - Skeleton for ssl-nss x509 provider
William Ehlhardt <williamehlhardt@gmail.com>
parents: 17673
diff changeset
1275 purple_certificate_unregister_scheme(&x509_nss);
7050
12730863b0f9 [gaim-migrate @ 7613]
Christian Hammond <chipx86@chipx86.com>
parents: 7029
diff changeset
1276
7016
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1277 return TRUE;
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1278 }
895a5ff9ebd4 [gaim-migrate @ 7579]
Christian Hammond <chipx86@chipx86.com>
parents:
diff changeset
1279
36501
a7a71bf77f83 Refactored ssl plugins to use the new API
Ankit Vani <a@nevitus.org>
parents: 36367
diff changeset
1280 PURPLE_PLUGIN_INIT(ssl_nss, plugin_query, plugin_load, plugin_unload);

mercurial