#include "empathy-tls-verifier.h"
-#include <gcr/gcr-simple-certificate.h>
-#include <gcr/gcr-trust.h>
+#include <gcr/gcr.h>
#define DEBUG_FLAG EMPATHY_DEBUG_TLS
#include "empathy-debug.h"
enum {
PROP_TLS_CERTIFICATE = 1,
PROP_HOSTNAME,
+ PROP_REFERENCE_IDENTITIES,
LAST_PROPERTY,
};
typedef struct {
EmpathyTLSCertificate *certificate;
gchar *hostname;
+ gchar **reference_identities;
GSimpleAsyncResult *verify_result;
GHashTable *details;
return retval;
}
-static gboolean
-check_is_certificate_exception (EmpathyTLSVerifier *self,
- gconstpointer data, gsize n_data)
+static void
+build_certificate_list_for_gnutls (GcrCertificateChain *chain,
+ gnutls_x509_crt_t **list,
+ guint *n_list,
+ gnutls_x509_crt_t **anchors,
+ guint *n_anchors)
{
GcrCertificate *cert;
- GError *error = NULL;
- gboolean ret;
- EmpathyTLSVerifierPriv *priv = GET_PRIV (self);
+ guint idx, length;
+ gnutls_x509_crt_t *retval;
+ gnutls_x509_crt_t gcert;
+ gnutls_datum_t datum;
+ gsize n_data;
- cert = gcr_simple_certificate_new_static (data, n_data);
- ret = gcr_trust_is_certificate_exception (cert, GCR_PURPOSE_CLIENT_AUTH,
- priv->hostname, NULL, &error);
- g_object_unref (cert);
+ g_assert (list);
+ g_assert (n_list);
+ g_assert (anchors);
+ g_assert (n_anchors);
- if (!ret && error) {
- DEBUG ("Can't lookup certificate exception for %s: %s", priv->hostname,
- error->message);
- g_clear_error (&error);
- }
+ *list = *anchors = NULL;
+ *n_list = *n_anchors = 0;
- return ret;
-}
+ length = gcr_certificate_chain_get_length (chain);
+ retval = g_malloc0 (sizeof (gnutls_x509_crt_t) * length);
-static gboolean
-check_is_certificate_anchor (EmpathyTLSVerifier *self,
- gconstpointer data, gsize n_data)
-{
- GcrCertificate *cert;
- GError *error = NULL;
- gboolean ret;
+ /* Convert the main body of the chain to gnutls */
+ for (idx = 0; idx < length; ++idx)
+ {
+ cert = gcr_certificate_chain_get_certificate (chain, idx);
+ datum.data = (gpointer)gcr_certificate_get_der_data (cert, &n_data);
+ datum.size = n_data;
- cert = gcr_simple_certificate_new_static (data, n_data);
- ret = gcr_trust_is_certificate_anchor (cert, GCR_PURPOSE_CLIENT_AUTH,
- NULL, &error);
- g_object_unref (cert);
+ gnutls_x509_crt_init (&gcert);
+ if (gnutls_x509_crt_import (gcert, &datum, GNUTLS_X509_FMT_DER) < 0)
+ g_return_if_reached ();
- if (!ret && error) {
- DEBUG ("Can't lookup certificate anchor: %s", error->message);
- g_clear_error (&error);
- }
+ retval[idx] = gcert;
+ }
+
+ *list = retval;
+ *n_list = length;
- return ret;
+ /* See if we have an anchor */
+ if (gcr_certificate_chain_get_status (chain) ==
+ GCR_CERTIFICATE_CHAIN_ANCHORED)
+ {
+ cert = gcr_certificate_chain_get_anchor (chain);
+ g_return_if_fail (cert);
+
+ datum.data = (gpointer)gcr_certificate_get_der_data (cert, &n_data);
+ datum.size = n_data;
+
+ gnutls_x509_crt_init (&gcert);
+ if (gnutls_x509_crt_import (gcert, &datum, GNUTLS_X509_FMT_DER) < 0)
+ g_return_if_reached ();
+
+ retval = g_malloc0 (sizeof (gnutls_x509_crt_t) * 1);
+ retval[0] = gcert;
+ *anchors = retval;
+ *n_anchors = 1;
+ }
}
-static gnutls_x509_crt_t
-convert_cert_to_gnutls (GArray *cert_data)
+static void
+free_certificate_list_for_gnutls (gnutls_x509_crt_t *list,
+ guint n_list)
{
- gnutls_x509_crt_t cert;
- gnutls_datum_t datum = { (unsigned char*)cert_data->data, cert_data->len };
+ guint idx;
- gnutls_x509_crt_init (&cert);
- gnutls_x509_crt_import (cert, &datum, GNUTLS_X509_FMT_DER);
-
- return cert;
+ for (idx = 0; idx < n_list; idx++)
+ gnutls_x509_crt_deinit (list[idx]);
+ g_free (list);
}
static void
}
static void
-perform_verification (EmpathyTLSVerifier *self)
+debug_certificate (GcrCertificate *cert)
+{
+ gchar *subject = gcr_certificate_get_subject_dn (cert);
+ DEBUG ("Certificate: %s", subject);
+ g_free (subject);
+}
+
+static void
+debug_certificate_chain (GcrCertificateChain *chain)
+{
+ GEnumClass *enum_class;
+ GEnumValue *enum_value;
+ gint idx, length;
+ GcrCertificate *cert;
+
+ enum_class = G_ENUM_CLASS
+ (g_type_class_peek (GCR_TYPE_CERTIFICATE_CHAIN_STATUS));
+ enum_value = g_enum_get_value (enum_class,
+ gcr_certificate_chain_get_status (chain));
+ length = gcr_certificate_chain_get_length (chain);
+ DEBUG ("Certificate chain: length %u status %s",
+ length, enum_value ? enum_value->value_nick : "XXX");
+
+ for (idx = 0; idx < length; ++idx)
+ {
+ cert = gcr_certificate_chain_get_certificate (chain, idx);
+ debug_certificate (cert);
+ }
+}
+
+static void
+perform_verification (EmpathyTLSVerifier *self,
+ GcrCertificateChain *chain)
{
- gnutls_x509_crt_t cert, anchor;
gboolean ret = FALSE;
EmpTLSCertificateRejectReason reason =
EMP_TLS_CERTIFICATE_REJECT_REASON_UNKNOWN;
- gsize idx;
- GPtrArray *certs = NULL;
- GArray *cert_data;
- GPtrArray *cert_chain;
- gint res;
+ gnutls_x509_crt_t *list, *anchors;
+ guint n_list, n_anchors;
guint verify_output;
+ gint res;
+ gint i;
+ gboolean matched = FALSE;
EmpathyTLSVerifierPriv *priv = GET_PRIV (self);
- DEBUG ("Starting verification");
+ DEBUG ("Performing verification");
+ debug_certificate_chain (chain);
- g_object_get (priv->certificate, "cert-data", &certs, NULL);
- cert_chain = g_ptr_array_new_with_free_func
- ((GDestroyNotify)gnutls_x509_crt_deinit);
+ list = anchors = NULL;
+ n_list = n_anchors = 0;
/*
- * If the first certificate is an exception then we completely
+ * If the first certificate is an pinned certificate then we completely
* ignore the rest of the verification process.
*/
- cert_data = g_ptr_array_index (certs, 0);
- if (check_is_certificate_exception (self, cert_data->data, cert_data->len)) {
- DEBUG ("Found certificate exception for %s", priv->hostname);
+ if (gcr_certificate_chain_get_status (chain) == GCR_CERTIFICATE_CHAIN_PINNED)
+ {
+ DEBUG ("Found pinned certificate for %s", priv->hostname);
complete_verification (self);
goto out;
}
- cert = convert_cert_to_gnutls (cert_data);
- g_ptr_array_add (cert_chain, cert);
-
- /*
- * Find out which of our certificates is the anchor. Note that we
- * don't allow the leaf certificate on the tree to be an anchor.
- * Also build up the certificate chain. But only up to our anchor.
- */
- anchor = NULL;
- for (idx = 1; idx < certs->len; idx++)
- {
- cert_data = g_ptr_array_index (certs, idx);
-
- /* Add this to the chain */
- cert = convert_cert_to_gnutls (cert_data);
- g_ptr_array_add (cert_chain, cert);
-
- /* Stop the chain at the first anchor */
- if (check_is_certificate_anchor (self, cert_data->data,
- cert_data->len)) {
- anchor = cert;
- break;
- }
- }
+ build_certificate_list_for_gnutls (chain, &list, &n_list,
+ &anchors, &n_anchors);
+ if (list == NULL || n_list == 0) {
+ g_warn_if_reached ();
+ abort_verification (self, EMP_TLS_CERTIFICATE_REJECT_REASON_UNKNOWN);
+ goto out;
+ }
verify_output = 0;
- res = gnutls_x509_crt_list_verify
- ((const gnutls_x509_crt_t*)cert_chain->pdata,
- cert_chain->len, anchor ? &anchor : NULL, anchor ? 1 : 1,
+ res = gnutls_x509_crt_list_verify (list, n_list, anchors, n_anchors,
NULL, 0, 0, &verify_output);
ret = verification_output_to_reason (res, verify_output, &reason);
reason);
if (!ret) {
- g_ptr_array_free (cert_chain, TRUE);
abort_verification (self, reason);
goto out;
}
- /* now check if the certificate matches the hostname first. */
- cert = g_ptr_array_index (cert_chain, 0);
- if (gnutls_x509_crt_check_hostname (cert, priv->hostname) == 0)
+ /* now check if the certificate matches one of the reference identities. */
+ if (priv->reference_identities != NULL)
+ {
+ for (i = 0, matched = FALSE; priv->reference_identities[i] != NULL; ++i)
+ {
+ if (gnutls_x509_crt_check_hostname (list[0],
+ priv->reference_identities[i]) == 1)
+ {
+ matched = TRUE;
+ break;
+ }
+ }
+ }
+
+ if (!matched)
{
gchar *certified_hostname;
- certified_hostname = empathy_get_x509_certificate_hostname (cert);
+ certified_hostname = empathy_get_x509_certificate_hostname (list[0]);
tp_asv_set_string (priv->details,
"expected-hostname", priv->hostname);
tp_asv_set_string (priv->details,
}
DEBUG ("Hostname matched");
-
- /* TODO: And here is where we check negative trust (ie: revocation) */
+ complete_verification (self);
out:
- g_ptr_array_free (cert_chain, TRUE);
+ free_certificate_list_for_gnutls (list, n_list);
+ free_certificate_list_for_gnutls (anchors, n_anchors);
}
-static gboolean
-perform_verification_cb (gpointer user_data)
+static void
+perform_verification_cb (GObject *object,
+ GAsyncResult *res,
+ gpointer user_data)
{
- EmpathyTLSVerifier *self = user_data;
+ GError *error = NULL;
- perform_verification (self);
+ GcrCertificateChain *chain = GCR_CERTIFICATE_CHAIN (object);
+ EmpathyTLSVerifier *self = EMPATHY_TLS_VERIFIER (user_data);
- return FALSE;
-}
-
-static gboolean
-start_verification (GIOSchedulerJob *job,
- GCancellable *cancellable,
- gpointer user_data)
-{
- EmpathyTLSVerifier *self = user_data;
+ /* Even if building the chain fails, try verifying what we have */
+ if (!gcr_certificate_chain_build_finish (chain, res, &error))
+ {
+ DEBUG ("Building of certificate chain failed: %s", error->message);
+ g_clear_error (&error);
+ }
- g_io_scheduler_job_send_to_mainloop_async (job,
- perform_verification_cb, self, NULL);
+ perform_verification (self, chain);
- return FALSE;
+ /* Matches ref when staring chain build */
+ g_object_unref (self);
}
static void
case PROP_HOSTNAME:
g_value_set_string (value, priv->hostname);
break;
+ case PROP_REFERENCE_IDENTITIES:
+ g_value_set_boxed (value, priv->reference_identities);
+ break;
default:
G_OBJECT_WARN_INVALID_PROPERTY_ID (object, property_id, pspec);
break;
case PROP_HOSTNAME:
priv->hostname = g_value_dup_string (value);
break;
+ case PROP_REFERENCE_IDENTITIES:
+ priv->reference_identities = g_value_dup_boxed (value);
+ break;
default:
G_OBJECT_WARN_INVALID_PROPERTY_ID (object, property_id, pspec);
break;
tp_clear_boxed (G_TYPE_HASH_TABLE, &priv->details);
g_free (priv->hostname);
+ g_strfreev (priv->reference_identities);
G_OBJECT_CLASS (empathy_tls_verifier_parent_class)->finalize (object);
}
g_object_class_install_property (oclass, PROP_TLS_CERTIFICATE, pspec);
pspec = g_param_spec_string ("hostname", "The hostname",
- "The hostname which should be certified by the certificate.",
+ "The hostname which is certified by the certificate.",
NULL,
G_PARAM_CONSTRUCT_ONLY | G_PARAM_READWRITE | G_PARAM_STATIC_STRINGS);
g_object_class_install_property (oclass, PROP_HOSTNAME, pspec);
+
+ pspec = g_param_spec_boxed ("reference-identities",
+ "The reference identities",
+ "The certificate should certify one of these identities.",
+ G_TYPE_STRV,
+ G_PARAM_CONSTRUCT_ONLY | G_PARAM_READWRITE | G_PARAM_STATIC_STRINGS);
+ g_object_class_install_property (oclass, PROP_REFERENCE_IDENTITIES, pspec);
}
EmpathyTLSVerifier *
empathy_tls_verifier_new (EmpathyTLSCertificate *certificate,
- const gchar *hostname)
+ const gchar *hostname, const gchar **reference_identities)
{
g_assert (EMPATHY_IS_TLS_CERTIFICATE (certificate));
g_assert (hostname != NULL);
+ g_assert (reference_identities != NULL);
return g_object_new (EMPATHY_TYPE_TLS_VERIFIER,
"certificate", certificate,
"hostname", hostname,
+ "reference-identities", reference_identities,
NULL);
}
GAsyncReadyCallback callback,
gpointer user_data)
{
+ GcrCertificateChain *chain;
+ GcrCertificate *cert;
+ GPtrArray *cert_data = NULL;
+ GArray *data;
+ guint idx;
EmpathyTLSVerifierPriv *priv = GET_PRIV (self);
+ DEBUG ("Starting verification");
+
g_return_if_fail (priv->verify_result == NULL);
+ g_object_get (priv->certificate, "cert-data", &cert_data, NULL);
+ g_return_if_fail (cert_data);
+
priv->verify_result = g_simple_async_result_new (G_OBJECT (self),
callback, user_data, NULL);
- g_io_scheduler_push_job (start_verification,
- self, NULL, G_PRIORITY_DEFAULT, NULL);
+ /* Create a certificate chain */
+ chain = gcr_certificate_chain_new ();
+ for (idx = 0; idx < cert_data->len; ++idx) {
+ data = g_ptr_array_index (cert_data, idx);
+ cert = gcr_simple_certificate_new ((guchar *) data->data, data->len);
+ gcr_certificate_chain_add (chain, cert);
+ g_object_unref (cert);
+ }
+
+ gcr_certificate_chain_build_async (chain, GCR_PURPOSE_CLIENT_AUTH, priv->hostname, 0,
+ NULL, perform_verification_cb, g_object_ref (self));
+
+ g_object_unref (chain);
+ g_boxed_free (TP_ARRAY_TYPE_UCHAR_ARRAY_LIST, cert_data);
}
gboolean
return TRUE;
}
+
+void
+empathy_tls_verifier_store_exception (EmpathyTLSVerifier *self)
+{
+ GArray *data;
+ GcrCertificate *cert;
+ GPtrArray *cert_data = NULL;
+ GError *error = NULL;
+ EmpathyTLSVerifierPriv *priv = GET_PRIV (self);
+
+ g_object_get (priv->certificate, "cert-data", &cert_data, NULL);
+ g_return_if_fail (cert_data);
+
+ if (!cert_data->len)
+ {
+ DEBUG ("No certificate to pin.");
+ return;
+ }
+
+ /* The first certificate in the chain is for the host */
+ data = g_ptr_array_index (cert_data, 0);
+ cert = gcr_simple_certificate_new ((gpointer)data->data, data->len);
+
+ DEBUG ("Storing pinned certificate:");
+ debug_certificate (cert);
+
+ if (!gcr_trust_add_pinned_certificate (cert, GCR_PURPOSE_CLIENT_AUTH,
+ priv->hostname, NULL, &error))
+ DEBUG ("Can't store the pinned certificate: %s", error->message);
+
+ g_object_unref (cert);
+ g_boxed_free (TP_ARRAY_TYPE_UCHAR_ARRAY_LIST, cert_data);
+}