2 * empathy-tls-verifier.c - Source for EmpathyTLSVerifier
3 * Copyright (C) 2010 Collabora Ltd.
4 * @author Cosimo Cecchi <cosimo.cecchi@collabora.co.uk>
5 * @author Stef Walter <stefw@collabora.co.uk>
7 * This library is free software; you can redistribute it and/or
8 * modify it under the terms of the GNU Lesser General Public
9 * License as published by the Free Software Foundation; either
10 * version 2.1 of the License, or (at your option) any later version.
12 * This library is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15 * Lesser General Public License for more details.
17 * You should have received a copy of the GNU Lesser General Public
18 * License along with this library; if not, write to the Free Software
19 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
24 #include <gnutls/gnutls.h>
25 #include <gnutls/x509.h>
27 #include <telepathy-glib/util.h>
29 #include "empathy-tls-verifier.h"
33 #define DEBUG_FLAG EMPATHY_DEBUG_TLS
34 #include "empathy-debug.h"
35 #include "empathy-utils.h"
37 G_DEFINE_TYPE (EmpathyTLSVerifier, empathy_tls_verifier,
40 #define GET_PRIV(obj) EMPATHY_GET_PRIV (obj, EmpathyTLSVerifier);
43 PROP_TLS_CERTIFICATE = 1,
50 EmpathyTLSCertificate *certificate;
53 GSimpleAsyncResult *verify_result;
57 } EmpathyTLSVerifierPriv;
60 verification_output_to_reason (gint res,
62 EmpTLSCertificateRejectReason *reason)
64 gboolean retval = TRUE;
66 g_assert (reason != NULL);
68 if (res != GNUTLS_E_SUCCESS)
72 /* the certificate is not structurally valid */
75 case GNUTLS_E_INSUFFICIENT_CREDENTIALS:
76 *reason = EMP_TLS_CERTIFICATE_REJECT_REASON_UNTRUSTED;
78 case GNUTLS_E_CONSTRAINT_ERROR:
79 *reason = EMP_TLS_CERTIFICATE_REJECT_REASON_LIMIT_EXCEEDED;
82 *reason = EMP_TLS_CERTIFICATE_REJECT_REASON_UNKNOWN;
89 /* the certificate is structurally valid, check for other errors. */
90 if (verify_output & GNUTLS_CERT_INVALID)
94 if (verify_output & GNUTLS_CERT_SIGNER_NOT_FOUND)
95 *reason = EMP_TLS_CERTIFICATE_REJECT_REASON_SELF_SIGNED;
96 else if (verify_output & GNUTLS_CERT_SIGNER_NOT_CA)
97 *reason = EMP_TLS_CERTIFICATE_REJECT_REASON_UNTRUSTED;
98 else if (verify_output & GNUTLS_CERT_INSECURE_ALGORITHM)
99 *reason = EMP_TLS_CERTIFICATE_REJECT_REASON_INSECURE;
100 else if (verify_output & GNUTLS_CERT_NOT_ACTIVATED)
101 *reason = EMP_TLS_CERTIFICATE_REJECT_REASON_NOT_ACTIVATED;
102 else if (verify_output & GNUTLS_CERT_EXPIRED)
103 *reason = EMP_TLS_CERTIFICATE_REJECT_REASON_EXPIRED;
105 *reason = EMP_TLS_CERTIFICATE_REJECT_REASON_UNKNOWN;
115 build_certificate_list_for_gnutls (GcrCertificateChain *chain,
116 gnutls_x509_crt_t **list, guint *n_list,
117 gnutls_x509_crt_t **anchors, guint *n_anchors)
119 GcrCertificate *cert;
121 gnutls_x509_crt_t *retval;
122 gnutls_x509_crt_t gcert;
123 gnutls_datum_t datum;
129 g_assert (n_anchors);
131 *list = *anchors = NULL;
132 *n_list = *n_anchors = 0;
134 length = gcr_certificate_chain_get_length (chain);
135 retval = g_malloc0 (sizeof (gnutls_x509_crt_t) * length);
137 /* Convert the main body of the chain to gnutls */
138 for (idx = 0; idx < length; ++idx)
140 cert = gcr_certificate_chain_get_certificate (chain, idx);
141 datum.data = (gpointer)gcr_certificate_get_der_data (cert, &n_data);
144 gnutls_x509_crt_init (&gcert);
145 if (gnutls_x509_crt_import (gcert, &datum, GNUTLS_X509_FMT_DER) < 0)
146 g_return_if_reached ();
154 /* See if we have an anchor */
155 if (gcr_certificate_chain_get_status (chain) ==
156 GCR_CERTIFICATE_CHAIN_ANCHORED)
158 cert = gcr_certificate_chain_get_anchor (chain);
159 g_return_if_fail (cert);
161 datum.data = (gpointer)gcr_certificate_get_der_data (cert, &n_data);
164 gnutls_x509_crt_init (&gcert);
165 if (gnutls_x509_crt_import (gcert, &datum, GNUTLS_X509_FMT_DER) < 0)
166 g_return_if_reached ();
168 retval = g_malloc0 (sizeof (gnutls_x509_crt_t) * 1);
176 free_certificate_list_for_gnutls (gnutls_x509_crt_t *list, guint n_list)
180 for (idx = 0; idx < n_list; idx++)
181 gnutls_x509_crt_deinit (list[idx]);
186 complete_verification (EmpathyTLSVerifier *self)
188 EmpathyTLSVerifierPriv *priv = GET_PRIV (self);
190 DEBUG ("Verification successful, completing...");
192 g_simple_async_result_complete_in_idle (priv->verify_result);
194 tp_clear_object (&priv->verify_result);
198 abort_verification (EmpathyTLSVerifier *self,
199 EmpTLSCertificateRejectReason reason)
201 EmpathyTLSVerifierPriv *priv = GET_PRIV (self);
203 DEBUG ("Verification error %u, aborting...", reason);
205 g_simple_async_result_set_error (priv->verify_result,
206 G_IO_ERROR, reason, "TLS verification failed with reason %u",
208 g_simple_async_result_complete_in_idle (priv->verify_result);
210 tp_clear_object (&priv->verify_result);
214 debug_certificate_chain (GcrCertificateChain *chain)
216 GEnumClass *enum_class;
217 GEnumValue *enum_value;
219 GcrCertificate *cert;
222 enum_class = G_ENUM_CLASS
223 (g_type_class_peek (GCR_TYPE_CERTIFICATE_CHAIN_STATUS));
224 enum_value = g_enum_get_value (enum_class,
225 gcr_certificate_chain_get_status (chain));
226 length = gcr_certificate_chain_get_length (chain);
227 DEBUG ("Certificate chain: length %u status %s",
228 length, enum_value ? enum_value->value_nick : "XXX");
230 for (idx = 0; idx < length; ++idx)
232 cert = gcr_certificate_chain_get_certificate (chain, idx);
233 subject = gcr_certificate_get_subject_dn (cert);
234 DEBUG (" Certificate: %s", subject);
240 perform_verification (EmpathyTLSVerifier *self, GcrCertificateChain *chain)
242 gboolean ret = FALSE;
243 EmpTLSCertificateRejectReason reason =
244 EMP_TLS_CERTIFICATE_REJECT_REASON_UNKNOWN;
245 gnutls_x509_crt_t *list, *anchors;
246 guint n_list, n_anchors;
249 EmpathyTLSVerifierPriv *priv = GET_PRIV (self);
251 DEBUG ("Performing verification");
252 debug_certificate_chain (chain);
255 * If the first certificate is an pinned certificate then we completely
256 * ignore the rest of the verification process.
258 if (gcr_certificate_chain_get_status (chain) == GCR_CERTIFICATE_CHAIN_PINNED)
260 DEBUG ("Found pinned certificate for %s", priv->hostname);
261 complete_verification (self);
265 build_certificate_list_for_gnutls (chain, &list, &n_list,
266 &anchors, &n_anchors);
267 if (list == NULL || n_list == 0) {
268 g_warn_if_reached ();
269 abort_verification (self, EMP_TLS_CERTIFICATE_REJECT_REASON_UNKNOWN);
274 res = gnutls_x509_crt_list_verify (list, n_list, anchors, n_anchors,
275 NULL, 0, 0, &verify_output);
276 ret = verification_output_to_reason (res, verify_output, &reason);
278 DEBUG ("Certificate verification gave result %d with reason %u", ret,
282 abort_verification (self, reason);
286 /* now check if the certificate matches the hostname. */
287 if (gnutls_x509_crt_check_hostname (list[0], priv->hostname) == 0)
289 gchar *certified_hostname;
291 certified_hostname = empathy_get_x509_certificate_hostname (list[0]);
292 tp_asv_set_string (priv->details,
293 "expected-hostname", priv->hostname);
294 tp_asv_set_string (priv->details,
295 "certificate-hostname", certified_hostname);
297 DEBUG ("Hostname mismatch: got %s but expected %s",
298 certified_hostname, priv->hostname);
300 g_free (certified_hostname);
301 abort_verification (self,
302 EMP_TLS_CERTIFICATE_REJECT_REASON_HOSTNAME_MISMATCH);
306 DEBUG ("Hostname matched");
307 complete_verification (self);
310 free_certificate_list_for_gnutls (list, n_list);
311 free_certificate_list_for_gnutls (anchors, n_anchors);
315 perform_verification_cb (GObject *object, GAsyncResult *res, gpointer user_data)
317 GError *error = NULL;
319 GcrCertificateChain *chain = GCR_CERTIFICATE_CHAIN (object);
320 EmpathyTLSVerifier *self = EMPATHY_TLS_VERIFIER (user_data);
322 /* Even if building the chain fails, try verifying what we have */
323 if (!gcr_certificate_chain_build_finish (chain, res, &error))
325 DEBUG ("Building of certificate chain failed: %s", error->message);
326 g_clear_error (&error);
329 perform_verification (self, chain);
331 /* Matches ref when staring chain build */
332 g_object_unref (self);
336 empathy_tls_verifier_get_property (GObject *object,
341 EmpathyTLSVerifierPriv *priv = GET_PRIV (object);
345 case PROP_TLS_CERTIFICATE:
346 g_value_set_object (value, priv->certificate);
349 g_value_set_string (value, priv->hostname);
352 G_OBJECT_WARN_INVALID_PROPERTY_ID (object, property_id, pspec);
358 empathy_tls_verifier_set_property (GObject *object,
363 EmpathyTLSVerifierPriv *priv = GET_PRIV (object);
367 case PROP_TLS_CERTIFICATE:
368 priv->certificate = g_value_dup_object (value);
371 priv->hostname = g_value_dup_string (value);
374 G_OBJECT_WARN_INVALID_PROPERTY_ID (object, property_id, pspec);
380 empathy_tls_verifier_dispose (GObject *object)
382 EmpathyTLSVerifierPriv *priv = GET_PRIV (object);
384 if (priv->dispose_run)
387 priv->dispose_run = TRUE;
389 tp_clear_object (&priv->certificate);
391 G_OBJECT_CLASS (empathy_tls_verifier_parent_class)->dispose (object);
395 empathy_tls_verifier_finalize (GObject *object)
397 EmpathyTLSVerifierPriv *priv = GET_PRIV (object);
399 DEBUG ("%p", object);
401 tp_clear_boxed (G_TYPE_HASH_TABLE, &priv->details);
402 g_free (priv->hostname);
404 G_OBJECT_CLASS (empathy_tls_verifier_parent_class)->finalize (object);
408 empathy_tls_verifier_init (EmpathyTLSVerifier *self)
410 EmpathyTLSVerifierPriv *priv;
412 priv = self->priv = G_TYPE_INSTANCE_GET_PRIVATE (self,
413 EMPATHY_TYPE_TLS_VERIFIER, EmpathyTLSVerifierPriv);
414 priv->details = tp_asv_new (NULL, NULL);
418 empathy_tls_verifier_class_init (EmpathyTLSVerifierClass *klass)
421 GObjectClass *oclass = G_OBJECT_CLASS (klass);
423 g_type_class_add_private (klass, sizeof (EmpathyTLSVerifierPriv));
425 oclass->set_property = empathy_tls_verifier_set_property;
426 oclass->get_property = empathy_tls_verifier_get_property;
427 oclass->finalize = empathy_tls_verifier_finalize;
428 oclass->dispose = empathy_tls_verifier_dispose;
430 pspec = g_param_spec_object ("certificate", "The EmpathyTLSCertificate",
431 "The EmpathyTLSCertificate to be verified.",
432 EMPATHY_TYPE_TLS_CERTIFICATE,
433 G_PARAM_CONSTRUCT_ONLY | G_PARAM_READWRITE | G_PARAM_STATIC_STRINGS);
434 g_object_class_install_property (oclass, PROP_TLS_CERTIFICATE, pspec);
436 pspec = g_param_spec_string ("hostname", "The hostname",
437 "The hostname which should be certified by the certificate.",
439 G_PARAM_CONSTRUCT_ONLY | G_PARAM_READWRITE | G_PARAM_STATIC_STRINGS);
440 g_object_class_install_property (oclass, PROP_HOSTNAME, pspec);
444 empathy_tls_verifier_new (EmpathyTLSCertificate *certificate,
445 const gchar *hostname)
447 g_assert (EMPATHY_IS_TLS_CERTIFICATE (certificate));
448 g_assert (hostname != NULL);
450 return g_object_new (EMPATHY_TYPE_TLS_VERIFIER,
451 "certificate", certificate,
452 "hostname", hostname,
457 empathy_tls_verifier_verify_async (EmpathyTLSVerifier *self,
458 GAsyncReadyCallback callback,
461 GcrCertificateChain *chain;
462 GcrCertificate *cert;
463 GPtrArray *certs = NULL;
466 EmpathyTLSVerifierPriv *priv = GET_PRIV (self);
468 DEBUG ("Starting verification");
470 g_return_if_fail (priv->verify_result == NULL);
472 g_object_get (priv->certificate, "cert-data", &certs, NULL);
473 g_return_if_fail (certs);
475 priv->verify_result = g_simple_async_result_new (G_OBJECT (self),
476 callback, user_data, NULL);
478 /* Create a certificate chain */
479 chain = gcr_certificate_chain_new ();
480 for (idx = 0; idx < certs->len; ++idx) {
481 cert_data = g_ptr_array_index (certs, idx);
482 cert = gcr_simple_certificate_new_static (cert_data->data, cert_data->len);
483 gcr_certificate_chain_add (chain, cert);
484 g_object_unref (cert);
487 gcr_certificate_chain_build_async (chain, GCR_PURPOSE_CLIENT_AUTH, priv->hostname, 0,
488 NULL, perform_verification_cb, g_object_ref (self));
490 g_object_unref (chain);
491 g_ptr_array_unref (certs);
495 empathy_tls_verifier_verify_finish (EmpathyTLSVerifier *self,
497 EmpTLSCertificateRejectReason *reason,
498 GHashTable **details,
501 EmpathyTLSVerifierPriv *priv = GET_PRIV (self);
503 if (g_simple_async_result_propagate_error (G_SIMPLE_ASYNC_RESULT (res),
507 *reason = (*error)->code;
511 *details = tp_asv_new (NULL, NULL);
512 tp_g_hash_table_update (*details, priv->details,
513 (GBoxedCopyFunc) g_strdup,
514 (GBoxedCopyFunc) tp_g_value_slice_dup);
521 *reason = EMP_TLS_CERTIFICATE_REJECT_REASON_UNKNOWN;
527 empathy_tls_verifier_store_exception (EmpathyTLSVerifier *self)
530 GcrCertificate *cert;
532 GError *error = NULL;
533 EmpathyTLSVerifierPriv *priv = GET_PRIV (self);
535 g_object_get (priv->certificate, "cert-data", &certs, NULL);
536 last_cert = g_ptr_array_index (certs, certs->len - 1);
537 cert = gcr_simple_certificate_new_static ((gpointer)last_cert->data,
540 if (!gcr_trust_add_pinned_certificate (cert, GCR_PURPOSE_CLIENT_AUTH,
541 priv->hostname, NULL, &error))
542 DEBUG ("Can't store the certificate exeption: %s", error->message);
544 g_object_unref (cert);