mirror of
https://gitlab.torproject.org/tpo/core/tor.git
synced 2024-12-06 19:41:15 +01:00
[flagday] handle nicknames and connection init properly; go to cert chains. something still odd w/tls
svn:r1658
This commit is contained in:
@@ -44,8 +44,9 @@ struct tor_tls_st {
|
||||
};
|
||||
|
||||
static X509* tor_tls_create_certificate(crypto_pk_env_t *rsa,
|
||||
crypto_pk_env_t *identity,
|
||||
const char *nickname);
|
||||
crypto_pk_env_t *rsa_sign,
|
||||
const char *cname,
|
||||
const char *cname_sign);
|
||||
|
||||
/* global tls context, keep it here because nobody else needs to touch it */
|
||||
static tor_tls_context *global_tls_context = NULL;
|
||||
@@ -132,24 +133,26 @@ static int always_accept_verify_cb(int preverify_ok,
|
||||
/* Generate a self-signed certificate with the private key 'rsa' and
|
||||
* identity key 'identity and commonName 'nickname'. Return a certificate
|
||||
* on success, NULL on failure.
|
||||
* DOCDOC
|
||||
*/
|
||||
X509 *
|
||||
tor_tls_create_certificate(crypto_pk_env_t *rsa,
|
||||
crypto_pk_env_t *identity,
|
||||
const char *nickname)
|
||||
crypto_pk_env_t *rsa_sign,
|
||||
const char *cname,
|
||||
const char *cname_sign)
|
||||
{
|
||||
time_t start_time, end_time;
|
||||
EVP_PKEY *id_pkey = NULL, *pkey=NULL;
|
||||
EVP_PKEY *sign_pkey = NULL, *pkey=NULL;
|
||||
X509 *x509 = NULL;
|
||||
X509_NAME *name = NULL;
|
||||
X509_NAME *name = NULL, *name_issuer=NULL;
|
||||
int nid;
|
||||
|
||||
tor_tls_init();
|
||||
|
||||
start_time = time(NULL);
|
||||
|
||||
assert(rsa && nickname);
|
||||
if (!(id_pkey = _crypto_pk_env_get_evp_pkey(identity,1)))
|
||||
assert(rsa && cname && rsa_sign && cname_sign);
|
||||
if (!(sign_pkey = _crypto_pk_env_get_evp_pkey(rsa_sign,1)))
|
||||
goto error;
|
||||
if (!(pkey = _crypto_pk_env_get_evp_pkey(rsa,0)))
|
||||
goto error;
|
||||
@@ -167,12 +170,21 @@ tor_tls_create_certificate(crypto_pk_env_t *rsa,
|
||||
"TOR", -1, -1, 0))) goto error;
|
||||
if ((nid = OBJ_txt2nid("commonName")) == NID_undef) goto error;
|
||||
if (!(X509_NAME_add_entry_by_NID(name, nid, MBSTRING_ASC,
|
||||
(char*)nickname, -1, -1, 0))) goto error;
|
||||
|
||||
if (!(X509_set_issuer_name(x509, name)))
|
||||
goto error;
|
||||
(char*)cname, -1, -1, 0))) goto error;
|
||||
if (!(X509_set_subject_name(x509, name)))
|
||||
goto error;
|
||||
|
||||
if (!(name_issuer = X509_NAME_new()))
|
||||
goto error;
|
||||
if ((nid = OBJ_txt2nid("organizationName")) == NID_undef) goto error;
|
||||
if (!(X509_NAME_add_entry_by_NID(name_issuer, nid, MBSTRING_ASC,
|
||||
"TOR", -1, -1, 0))) goto error;
|
||||
if ((nid = OBJ_txt2nid("commonName")) == NID_undef) goto error;
|
||||
if (!(X509_NAME_add_entry_by_NID(name_issuer, nid, MBSTRING_ASC,
|
||||
(char*)cname_sign, -1, -1, 0))) goto error;
|
||||
if (!(X509_set_issuer_name(x509, name_issuer)))
|
||||
goto error;
|
||||
|
||||
if (!X509_time_adj(X509_get_notBefore(x509),0,&start_time))
|
||||
goto error;
|
||||
end_time = start_time + CERT_LIFETIME;
|
||||
@@ -180,7 +192,7 @@ tor_tls_create_certificate(crypto_pk_env_t *rsa,
|
||||
goto error;
|
||||
if (!X509_set_pubkey(x509, pkey))
|
||||
goto error;
|
||||
if (!X509_sign(x509, id_pkey, EVP_sha1()))
|
||||
if (!X509_sign(x509, sign_pkey, EVP_sha1()))
|
||||
goto error;
|
||||
|
||||
goto done;
|
||||
@@ -190,12 +202,14 @@ tor_tls_create_certificate(crypto_pk_env_t *rsa,
|
||||
x509 = NULL;
|
||||
}
|
||||
done:
|
||||
if (id_pkey)
|
||||
EVP_PKEY_free(id_pkey);
|
||||
if (sign_pkey)
|
||||
EVP_PKEY_free(sign_pkey);
|
||||
if (pkey)
|
||||
EVP_PKEY_free(pkey);
|
||||
if (name)
|
||||
X509_NAME_free(name);
|
||||
if (name_issuer)
|
||||
X509_NAME_free(name_issuer);
|
||||
return x509;
|
||||
}
|
||||
|
||||
@@ -228,7 +242,9 @@ tor_tls_context_new(crypto_pk_env_t *identity,
|
||||
crypto_dh_env_t *dh = NULL;
|
||||
EVP_PKEY *pkey = NULL;
|
||||
tor_tls_context *result = NULL;
|
||||
X509 *cert = NULL;
|
||||
X509 *cert = NULL, *idcert = NULL;
|
||||
char nn2[1024];
|
||||
sprintf(nn2, "%s <identity>", nickname);
|
||||
|
||||
tor_tls_init();
|
||||
|
||||
@@ -237,8 +253,9 @@ tor_tls_context_new(crypto_pk_env_t *identity,
|
||||
goto error;
|
||||
if (crypto_pk_generate_key(rsa)<0)
|
||||
goto error;
|
||||
cert = tor_tls_create_certificate(rsa, identity, nickname);
|
||||
if (!cert) {
|
||||
cert = tor_tls_create_certificate(rsa, identity, nickname, nn2);
|
||||
idcert = tor_tls_create_certificate(rsa, identity, nn2, nn2);
|
||||
if (!cert || !idcert) {
|
||||
log(LOG_WARN, "Error creating certificate");
|
||||
goto error;
|
||||
}
|
||||
@@ -260,6 +277,8 @@ tor_tls_context_new(crypto_pk_env_t *identity,
|
||||
goto error;
|
||||
if (cert && !SSL_CTX_use_certificate(result->ctx,cert))
|
||||
goto error;
|
||||
if (idcert && !SSL_CTX_add_extra_chain_cert(result->ctx,idcert))
|
||||
goto error;
|
||||
SSL_CTX_set_session_cache_mode(result->ctx, SSL_SESS_CACHE_OFF);
|
||||
if (isServer) {
|
||||
assert(rsa);
|
||||
@@ -303,7 +322,7 @@ tor_tls_context_new(crypto_pk_env_t *identity,
|
||||
SSL_CTX_free(result->ctx);
|
||||
if (result)
|
||||
free(result);
|
||||
|
||||
/* leak certs XXXX ? */
|
||||
return -1;
|
||||
}
|
||||
|
||||
@@ -531,7 +550,6 @@ tor_tls_verify(tor_tls *tls, crypto_pk_env_t *identity_key)
|
||||
{
|
||||
X509 *cert = NULL;
|
||||
EVP_PKEY *id_pkey = NULL;
|
||||
RSA *rsa = NULL;
|
||||
time_t now, t;
|
||||
int r = -1;
|
||||
if (!(cert = SSL_get_peer_certificate(tls->ssl)))
|
||||
@@ -563,8 +581,6 @@ tor_tls_verify(tor_tls *tls, crypto_pk_env_t *identity_key)
|
||||
X509_free(cert);
|
||||
if (id_pkey)
|
||||
EVP_PKEY_free(id_pkey);
|
||||
if (rsa)
|
||||
RSA_free(rsa);
|
||||
return r;
|
||||
}
|
||||
|
||||
|
||||
@@ -217,13 +217,14 @@ static int connection_tls_finish_handshake(connection_t *conn) {
|
||||
log_fn(LOG_INFO,"Router %s is already connected on fd %d. Dropping fd %d.", router->nickname, c->s, conn->s);
|
||||
return -1;
|
||||
}
|
||||
|
||||
if (strcmp(conn->nickname, nickname)) {
|
||||
if (conn->nickname && strcmp(conn->nickname, nickname)) {
|
||||
log_fn(options.DirPort ? LOG_WARN : LOG_INFO,
|
||||
"Other side claims to be '%s', but we expected '%s'",
|
||||
"Other side is '%s', but we tried to connect to '%s'",
|
||||
nickname, conn->nickname);
|
||||
return -1;
|
||||
}
|
||||
connection_or_init_conn_from_router(conn,router);
|
||||
|
||||
if (!options.ORPort) { /* If I'm an OP... */
|
||||
conn->receiver_bucket = conn->bandwidth = DEFAULT_BANDWIDTH_OP;
|
||||
}
|
||||
|
||||
@@ -53,6 +53,7 @@ int has_completed_circuit=0;
|
||||
****************************************************************************/
|
||||
|
||||
int connection_add(connection_t *conn) {
|
||||
assert(conn);
|
||||
|
||||
if(nfds >= options.MaxConn-1) {
|
||||
log_fn(LOG_WARN,"failing because nfds is too high.");
|
||||
|
||||
Reference in New Issue
Block a user