From 0393db76e01112d47ed989e3d704aca2fafcc1b6 Mon Sep 17 00:00:00 2001 From: Nick Mathewson Date: Sat, 17 Apr 2004 18:15:00 +0000 Subject: [PATCH] [flagday] handle nicknames and connection init properly; go to cert chains. something still odd w/tls svn:r1658 --- .../tor-0_0_6incompat/src/common/tortls.c | 60 ++++++++++++------- .../tor-0_0_6incompat/src/or/connection_or.c | 7 ++- branches/tor-0_0_6incompat/src/or/main.c | 1 + 3 files changed, 43 insertions(+), 25 deletions(-) diff --git a/branches/tor-0_0_6incompat/src/common/tortls.c b/branches/tor-0_0_6incompat/src/common/tortls.c index c50329167c..8a8fb67b43 100644 --- a/branches/tor-0_0_6incompat/src/common/tortls.c +++ b/branches/tor-0_0_6incompat/src/common/tortls.c @@ -44,8 +44,9 @@ struct tor_tls_st { }; static X509* tor_tls_create_certificate(crypto_pk_env_t *rsa, - crypto_pk_env_t *identity, - const char *nickname); + crypto_pk_env_t *rsa_sign, + const char *cname, + const char *cname_sign); /* global tls context, keep it here because nobody else needs to touch it */ static tor_tls_context *global_tls_context = NULL; @@ -132,24 +133,26 @@ static int always_accept_verify_cb(int preverify_ok, /* Generate a self-signed certificate with the private key 'rsa' and * identity key 'identity and commonName 'nickname'. Return a certificate * on success, NULL on failure. + * DOCDOC */ X509 * tor_tls_create_certificate(crypto_pk_env_t *rsa, - crypto_pk_env_t *identity, - const char *nickname) + crypto_pk_env_t *rsa_sign, + const char *cname, + const char *cname_sign) { time_t start_time, end_time; - EVP_PKEY *id_pkey = NULL, *pkey=NULL; + EVP_PKEY *sign_pkey = NULL, *pkey=NULL; X509 *x509 = NULL; - X509_NAME *name = NULL; + X509_NAME *name = NULL, *name_issuer=NULL; int nid; tor_tls_init(); start_time = time(NULL); - assert(rsa && nickname); - if (!(id_pkey = _crypto_pk_env_get_evp_pkey(identity,1))) + assert(rsa && cname && rsa_sign && cname_sign); + if (!(sign_pkey = _crypto_pk_env_get_evp_pkey(rsa_sign,1))) goto error; if (!(pkey = _crypto_pk_env_get_evp_pkey(rsa,0))) goto error; @@ -167,12 +170,21 @@ tor_tls_create_certificate(crypto_pk_env_t *rsa, "TOR", -1, -1, 0))) goto error; if ((nid = OBJ_txt2nid("commonName")) == NID_undef) goto error; if (!(X509_NAME_add_entry_by_NID(name, nid, MBSTRING_ASC, - (char*)nickname, -1, -1, 0))) goto error; - - if (!(X509_set_issuer_name(x509, name))) - goto error; + (char*)cname, -1, -1, 0))) goto error; if (!(X509_set_subject_name(x509, name))) goto error; + + if (!(name_issuer = X509_NAME_new())) + goto error; + if ((nid = OBJ_txt2nid("organizationName")) == NID_undef) goto error; + if (!(X509_NAME_add_entry_by_NID(name_issuer, nid, MBSTRING_ASC, + "TOR", -1, -1, 0))) goto error; + if ((nid = OBJ_txt2nid("commonName")) == NID_undef) goto error; + if (!(X509_NAME_add_entry_by_NID(name_issuer, nid, MBSTRING_ASC, + (char*)cname_sign, -1, -1, 0))) goto error; + if (!(X509_set_issuer_name(x509, name_issuer))) + goto error; + if (!X509_time_adj(X509_get_notBefore(x509),0,&start_time)) goto error; end_time = start_time + CERT_LIFETIME; @@ -180,7 +192,7 @@ tor_tls_create_certificate(crypto_pk_env_t *rsa, goto error; if (!X509_set_pubkey(x509, pkey)) goto error; - if (!X509_sign(x509, id_pkey, EVP_sha1())) + if (!X509_sign(x509, sign_pkey, EVP_sha1())) goto error; goto done; @@ -190,12 +202,14 @@ tor_tls_create_certificate(crypto_pk_env_t *rsa, x509 = NULL; } done: - if (id_pkey) - EVP_PKEY_free(id_pkey); + if (sign_pkey) + EVP_PKEY_free(sign_pkey); if (pkey) EVP_PKEY_free(pkey); if (name) X509_NAME_free(name); + if (name_issuer) + X509_NAME_free(name_issuer); return x509; } @@ -228,7 +242,9 @@ tor_tls_context_new(crypto_pk_env_t *identity, crypto_dh_env_t *dh = NULL; EVP_PKEY *pkey = NULL; tor_tls_context *result = NULL; - X509 *cert = NULL; + X509 *cert = NULL, *idcert = NULL; + char nn2[1024]; + sprintf(nn2, "%s ", nickname); tor_tls_init(); @@ -237,8 +253,9 @@ tor_tls_context_new(crypto_pk_env_t *identity, goto error; if (crypto_pk_generate_key(rsa)<0) goto error; - cert = tor_tls_create_certificate(rsa, identity, nickname); - if (!cert) { + cert = tor_tls_create_certificate(rsa, identity, nickname, nn2); + idcert = tor_tls_create_certificate(rsa, identity, nn2, nn2); + if (!cert || !idcert) { log(LOG_WARN, "Error creating certificate"); goto error; } @@ -260,6 +277,8 @@ tor_tls_context_new(crypto_pk_env_t *identity, goto error; if (cert && !SSL_CTX_use_certificate(result->ctx,cert)) goto error; + if (idcert && !SSL_CTX_add_extra_chain_cert(result->ctx,idcert)) + goto error; SSL_CTX_set_session_cache_mode(result->ctx, SSL_SESS_CACHE_OFF); if (isServer) { assert(rsa); @@ -303,7 +322,7 @@ tor_tls_context_new(crypto_pk_env_t *identity, SSL_CTX_free(result->ctx); if (result) free(result); - + /* leak certs XXXX ? */ return -1; } @@ -531,7 +550,6 @@ tor_tls_verify(tor_tls *tls, crypto_pk_env_t *identity_key) { X509 *cert = NULL; EVP_PKEY *id_pkey = NULL; - RSA *rsa = NULL; time_t now, t; int r = -1; if (!(cert = SSL_get_peer_certificate(tls->ssl))) @@ -563,8 +581,6 @@ tor_tls_verify(tor_tls *tls, crypto_pk_env_t *identity_key) X509_free(cert); if (id_pkey) EVP_PKEY_free(id_pkey); - if (rsa) - RSA_free(rsa); return r; } diff --git a/branches/tor-0_0_6incompat/src/or/connection_or.c b/branches/tor-0_0_6incompat/src/or/connection_or.c index f8863af8a1..e91aabca1d 100644 --- a/branches/tor-0_0_6incompat/src/or/connection_or.c +++ b/branches/tor-0_0_6incompat/src/or/connection_or.c @@ -217,13 +217,14 @@ static int connection_tls_finish_handshake(connection_t *conn) { log_fn(LOG_INFO,"Router %s is already connected on fd %d. Dropping fd %d.", router->nickname, c->s, conn->s); return -1; } - - if (strcmp(conn->nickname, nickname)) { + if (conn->nickname && strcmp(conn->nickname, nickname)) { log_fn(options.DirPort ? LOG_WARN : LOG_INFO, - "Other side claims to be '%s', but we expected '%s'", + "Other side is '%s', but we tried to connect to '%s'", nickname, conn->nickname); return -1; } + connection_or_init_conn_from_router(conn,router); + if (!options.ORPort) { /* If I'm an OP... */ conn->receiver_bucket = conn->bandwidth = DEFAULT_BANDWIDTH_OP; } diff --git a/branches/tor-0_0_6incompat/src/or/main.c b/branches/tor-0_0_6incompat/src/or/main.c index 6e8064399a..6c508cd611 100644 --- a/branches/tor-0_0_6incompat/src/or/main.c +++ b/branches/tor-0_0_6incompat/src/or/main.c @@ -53,6 +53,7 @@ int has_completed_circuit=0; ****************************************************************************/ int connection_add(connection_t *conn) { + assert(conn); if(nfds >= options.MaxConn-1) { log_fn(LOG_WARN,"failing because nfds is too high.");