Implemented a callback based credential set, currently for shared keys only

This commit is contained in:
Martin Willi
2010-08-04 09:26:21 +02:00
parent 0749e91bec
commit 62be923683
6 changed files with 267 additions and 97 deletions
+1
View File
@@ -44,6 +44,7 @@ credentials/sets/auth_cfg_wrapper.c credentials/sets/auth_cfg_wrapper.h \
credentials/sets/ocsp_response_wrapper.c credentials/sets/ocsp_response_wrapper.h \
credentials/sets/cert_cache.c credentials/sets/cert_cache.h \
credentials/sets/mem_cred.c credentials/sets/mem_cred.h \
credentials/sets/callback_cred.c credentials/sets/callback_cred.h \
credentials/auth_cfg.c credentials/auth_cfg.h credentials/credential_set.h \
credentials/cert_validator.h \
database/database.h database/database_factory.h database/database_factory.c \
+1
View File
@@ -42,6 +42,7 @@ credentials/sets/auth_cfg_wrapper.c credentials/sets/auth_cfg_wrapper.h \
credentials/sets/ocsp_response_wrapper.c credentials/sets/ocsp_response_wrapper.h \
credentials/sets/cert_cache.c credentials/sets/cert_cache.h \
credentials/sets/mem_cred.c credentials/sets/mem_cred.h \
credentials/sets/callback_cred.c credentials/sets/callback_cred.h \
credentials/auth_cfg.c credentials/auth_cfg.h credentials/credential_set.h \
credentials/cert_validator.h \
database/database.h database/database_factory.h database/database_factory.c \
@@ -0,0 +1,141 @@
/*
* Copyright (C) 2010 Martin Willi
* Copyright (C) 2010 revosec AG
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#include "callback_cred.h"
typedef struct private_callback_cred_t private_callback_cred_t;
/**
* Private data of an callback_cred_t object.
*/
struct private_callback_cred_t {
/**
* Public callback_cred_t interface.
*/
callback_cred_t public;
/**
* Callback of this set, for all types, and generic
*/
union {
void *generic;
callback_cred_shared_cb_t shared;
} cb;
/**
* Data to pass to callback
*/
void *data;
};
/**
* Shared key enumerator on callbacks
*/
typedef struct {
/* implements enumerator_t */
enumerator_t public;
/* backref to this */
private_callback_cred_t *this;
/* own identity to match */
identification_t *me;
/* other identity to match */
identification_t *other;
/* current shared key */
shared_key_t *current;
} shared_enumerator_t;
METHOD(enumerator_t, shared_enumerate, bool,
shared_enumerator_t *this, shared_key_t **out,
id_match_t *match_me, id_match_t *match_other)
{
DESTROY_IF(this->current);
this->current = this->this->cb.shared(this->this->data,
this->me, this->other, match_me, match_other);
if (this->current)
{
*out = this->current;
return TRUE;
}
return FALSE;
}
METHOD(enumerator_t, shared_destroy, void,
shared_enumerator_t *this)
{
DESTROY_IF(this->current);
free(this);
}
METHOD(credential_set_t, create_shared_enumerator, enumerator_t*,
private_callback_cred_t *this, shared_key_type_t type,
identification_t *me, identification_t *other)
{
shared_enumerator_t *enumerator;
INIT(enumerator,
.public = {
.enumerate = (void*)_shared_enumerate,
.destroy = _shared_destroy,
},
.this = this,
.me = me,
.other = other,
);
return &enumerator->public;
}
METHOD(callback_cred_t, destroy, void,
private_callback_cred_t *this)
{
free(this);
}
/**
* Create a generic callback credential set
*/
static private_callback_cred_t* create_generic(void *cb, void *data)
{
private_callback_cred_t *this;
INIT(this,
.public = {
.set = {
.create_shared_enumerator = (void*)return_null,
.create_private_enumerator = (void*)return_null,
.create_cert_enumerator = (void*)return_null,
.create_cdp_enumerator = (void*)return_null,
.cache_cert = (void*)nop,
},
.destroy = _destroy,
},
.cb.generic = cb,
.data = data,
);
return this;
}
/**
* See header
*/
callback_cred_t *callback_cred_create_shared(callback_cred_shared_cb_t cb,
void *data)
{
private_callback_cred_t *this = create_generic(cb, data);
this->public.set.create_shared_enumerator = _create_shared_enumerator;
return &this->public;
}
@@ -0,0 +1,65 @@
/*
* Copyright (C) 2010 Martin Willi
* Copyright (C) 2010 revosec AG
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup callback_cred callback_cred
* @{ @ingroup sets
*/
#ifndef CALLBACK_CRED_H_
#define CALLBACK_CRED_H_
typedef struct callback_cred_t callback_cred_t;
#include <credentials/credential_set.h>
/**
* Callback function to get shared keys.
*
* @param me own identity
* @param other other identity
* @param match_me match result of own identity
* @param match_other match result of other identity
*/
typedef shared_key_t* (*callback_cred_shared_cb_t)(void *data,
identification_t *me, identification_t *other,
id_match_t *match_me, id_match_t *match_other);
/**
* Generic callbcack using user specified callback functions.
*/
struct callback_cred_t {
/**
* Implements credential_set_t.
*/
credential_set_t set;
/**
* Destroy a callback_cred_t.
*/
void (*destroy)(callback_cred_t *this);
};
/**
* Create a callback_cred instance, for a shared key.
*
* @param cb callback function
* @param data data to pass to callback
*/
callback_cred_t *callback_cred_create_shared(callback_cred_shared_cb_t cb,
void *data);
#endif /** CALLBACK_CRED_H_ @}*/
@@ -331,13 +331,26 @@ static bool find_key(private_pkcs11_private_key_t *this, chunk_t keyid)
}
/**
* Try a login to the session
* Find a PIN and try to log in
*/
static bool login(private_pkcs11_private_key_t *this, chunk_t pin, int slot)
static bool login(private_pkcs11_private_key_t *this, chunk_t keyid, int slot)
{
identification_t *id;
shared_key_t *shared;
chunk_t pin;
CK_RV rv;
id = identification_create_from_encoding(ID_KEY_ID, keyid);
shared = lib->credmgr->get_shared(lib->credmgr, SHARED_PIN, id, NULL);
id->destroy(id);
if (!shared)
{
DBG1(DBG_CFG, "no PIN found for PKCS#11 key %#B", keyid);
return FALSE;
}
pin = shared->get_key(shared);
rv = this->lib->f->C_Login(this->session, CKU_USER, pin.ptr, pin.len);
shared->destroy(shared);
if (rv != CKR_OK)
{
DBG1(DBG_CFG, "login to '%s':%d failed: %N",
@@ -353,14 +366,11 @@ static bool login(private_pkcs11_private_key_t *this, chunk_t pin, int slot)
pkcs11_private_key_t *pkcs11_private_key_connect(key_type_t type, va_list args)
{
private_pkcs11_private_key_t *this;
chunk_t (*cb)(void *data, int try) = NULL;
void *cb_data = NULL;
char *module = NULL;
chunk_t keyid, pin;
int slot = -1, try = 0;
chunk_t keyid = chunk_empty;
int slot = -1;
CK_RV rv;
keyid = pin = chunk_empty;
while (TRUE)
{
switch (va_arg(args, builder_part_t))
@@ -368,13 +378,6 @@ pkcs11_private_key_t *pkcs11_private_key_connect(key_type_t type, va_list args)
case BUILD_PKCS11_KEYID:
keyid = va_arg(args, chunk_t);
continue;
case BUILD_PASSPHRASE:
pin = va_arg(args, chunk_t);
continue;
case BUILD_PASSPHRASE_CALLBACK:
cb = va_arg(args, void*);
cb_data = va_arg(args, void*);
continue;
case BUILD_PKCS11_SLOT:
slot = va_arg(args, int);
continue;
@@ -388,7 +391,7 @@ pkcs11_private_key_t *pkcs11_private_key_connect(key_type_t type, va_list args)
}
break;
}
if (!keyid.len || (!pin.len && !cb))
if (!keyid.len)
{
return NULL;
}
@@ -444,29 +447,10 @@ pkcs11_private_key_t *pkcs11_private_key_connect(key_type_t type, va_list args)
this->mutex = mutex_create(MUTEX_TYPE_DEFAULT);
if (pin.ptr)
if (!login(this, keyid, slot))
{
if (!login(this, pin, slot))
{
destroy(this);
return NULL;
}
}
else
{
while (TRUE)
{
pin = cb(cb_data, ++try);
if (!pin.len)
{
destroy(this);
return NULL;
}
if (login(this, pin, slot))
{
break;
}
}
destroy(this);
return NULL;
}
if (!find_key(this, keyid))