From eb50fd9d15fa48392fbe416c0f9068d614273d83 Mon Sep 17 00:00:00 2001 From: Tobias Brunner Date: Fri, 24 Jul 2026 14:41:43 +0200 Subject: [PATCH] keychain: Remove unused macOS KeyChain plugin The macOS frontend was the only user of this plugin. --- configure.ac | 4 - scripts/test.sh | 2 +- src/libstrongswan/Makefile.am | 7 - .../plugins/keychain/Makefile.am | 17 -- .../plugins/keychain/keychain_creds.c | 207 ------------------ .../plugins/keychain/keychain_creds.h | 45 ---- .../plugins/keychain/keychain_plugin.c | 99 --------- .../plugins/keychain/keychain_plugin.h | 43 ---- 8 files changed, 1 insertion(+), 423 deletions(-) delete mode 100644 src/libstrongswan/plugins/keychain/Makefile.am delete mode 100644 src/libstrongswan/plugins/keychain/keychain_creds.c delete mode 100644 src/libstrongswan/plugins/keychain/keychain_creds.h delete mode 100644 src/libstrongswan/plugins/keychain/keychain_plugin.c delete mode 100644 src/libstrongswan/plugins/keychain/keychain_plugin.h diff --git a/configure.ac b/configure.ac index 5a9c1611d..2a733bda5 100644 --- a/configure.ac +++ b/configure.ac @@ -211,7 +211,6 @@ ARG_ENABL_SET([eap-dynamic], [enable dynamic EAP proxy module.]) ARG_ENABL_SET([eap-radius], [enable RADIUS proxy authentication module.]) ARG_ENABL_SET([ext-auth], [enable plugin calling an external authorization script.]) ARG_ENABL_SET([ipseckey], [enable IPSECKEY authentication plugin.]) -ARG_ENABL_SET([keychain], [enables OS X Keychain Services credential set.]) ARG_ENABL_SET([pkcs11], [enables the PKCS11 token support plugin.]) ARG_ENABL_SET([tpm], [enables the TPM plugin to access private keys and certificates bound to a TPM 2.0.]) ARG_DISBL_SET([revocation], [disable X509 CRL/OCSP revocation check plugin.]) @@ -1544,7 +1543,6 @@ ADD_PLUGIN([fips-prf], [s charon nm cmd]) ADD_PLUGIN([gmp], [s charon swanctl pki scripts attest nm cmd aikgen fc]) ADD_PLUGIN([curve25519], [s charon swanctl pki scripts nm cmd]) ADD_PLUGIN([agent], [s charon nm cmd]) -ADD_PLUGIN([keychain], [s charon cmd]) ADD_PLUGIN([chapoly], [s charon scripts nm cmd]) ADD_PLUGIN([xcbc], [s charon nm cmd]) ADD_PLUGIN([cmac], [s charon nm cmd]) @@ -1709,7 +1707,6 @@ AM_CONDITIONAL(USE_WOLFSSL, test x$wolfssl = xtrue) AM_CONDITIONAL(USE_GCRYPT, test x$gcrypt = xtrue) AM_CONDITIONAL(USE_BOTAN, test x$botan = xtrue) AM_CONDITIONAL(USE_AGENT, test x$agent = xtrue) -AM_CONDITIONAL(USE_KEYCHAIN, test x$keychain = xtrue) AM_CONDITIONAL(USE_PKCS11, test x$pkcs11 = xtrue) AM_CONDITIONAL(USE_TPM, test x$tpm = xtrue) AM_CONDITIONAL(USE_CHAPOLY, test x$chapoly = xtrue) @@ -1998,7 +1995,6 @@ AC_CONFIG_FILES([ src/libstrongswan/plugins/gcrypt/Makefile src/libstrongswan/plugins/botan/Makefile src/libstrongswan/plugins/agent/Makefile - src/libstrongswan/plugins/keychain/Makefile src/libstrongswan/plugins/pkcs11/Makefile src/libstrongswan/plugins/chapoly/Makefile src/libstrongswan/plugins/ctr/Makefile diff --git a/scripts/test.sh b/scripts/test.sh index 1ac96338c..7b7df3cd9 100755 --- a/scripts/test.sh +++ b/scripts/test.sh @@ -262,7 +262,7 @@ all|alpine|codeql|coverage|sonarcloud|no-dbg|no-testable-ke) CFLAGS="$CFLAGS -DDEBUG_LEVEL=-1" fi CONFIG="--enable-all --disable-android-dns --disable-android-log - --disable-kernel-pfroute --disable-keychain + --disable-kernel-pfroute --disable-lock-profiler --disable-padlock --disable-fuzzing --disable-osx-attr --disable-tkm --disable-unwind-backtraces diff --git a/src/libstrongswan/Makefile.am b/src/libstrongswan/Makefile.am index 5a3e50301..b865a1a25 100644 --- a/src/libstrongswan/Makefile.am +++ b/src/libstrongswan/Makefile.am @@ -628,13 +628,6 @@ if MONOLITHIC endif endif -if USE_KEYCHAIN - SUBDIRS += plugins/keychain -if MONOLITHIC - libstrongswan_la_LIBADD += plugins/keychain/libstrongswan-keychain.la -endif -endif - if USE_PKCS11 SUBDIRS += plugins/pkcs11 if MONOLITHIC diff --git a/src/libstrongswan/plugins/keychain/Makefile.am b/src/libstrongswan/plugins/keychain/Makefile.am deleted file mode 100644 index 07d2bcdbb..000000000 --- a/src/libstrongswan/plugins/keychain/Makefile.am +++ /dev/null @@ -1,17 +0,0 @@ - -AM_CPPFLAGS = -I$(top_srcdir)/src/libstrongswan - -AM_CFLAGS = $(PLUGIN_CFLAGS) - -if MONOLITHIC -noinst_LTLIBRARIES = libstrongswan-keychain.la -else -plugin_LTLIBRARIES = libstrongswan-keychain.la -endif - -libstrongswan_keychain_la_SOURCES = \ - keychain_plugin.h keychain_plugin.c \ - keychain_creds.h keychain_creds.c - -libstrongswan_keychain_la_LDFLAGS = -module -avoid-version \ - -framework Security -framework CoreFoundation diff --git a/src/libstrongswan/plugins/keychain/keychain_creds.c b/src/libstrongswan/plugins/keychain/keychain_creds.c deleted file mode 100644 index 23d457d53..000000000 --- a/src/libstrongswan/plugins/keychain/keychain_creds.c +++ /dev/null @@ -1,207 +0,0 @@ -/* - * Copyright (C) 2013 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "keychain_creds.h" - -#include -#include -#include - -#include - -/** - * System Roots keychain - */ -#define SYSTEM_ROOTS "/System/Library/Keychains/SystemRootCertificates.keychain" - -/** - * System keychain - */ -#define SYSTEM "/Library/Keychains/System.keychain" - -typedef struct private_keychain_creds_t private_keychain_creds_t; - -/** - * Private data of an keychain_creds_t object. - */ -struct private_keychain_creds_t { - - /** - * Public keychain_creds_t interface. - */ - keychain_creds_t public; - - /** - * Active in-memory credential set - */ - mem_cred_t *set; - - /** - * System roots credential set - */ - mem_cred_t *roots; - - /** - * Run loop of event monitoring thread - */ - CFRunLoopRef loop; -}; - -/** - * Load a credential sets with certificates from a keychain path - */ -static mem_cred_t* load_certs(private_keychain_creds_t *this, char *path) -{ - SecKeychainRef keychain; - SecKeychainSearchRef search; - SecKeychainItemRef item; - mem_cred_t *set; - OSStatus status; - int loaded = 0; - - set = mem_cred_create(); - - DBG2(DBG_CFG, "loading certificates from %s:", path); - status = SecKeychainOpen(path, &keychain); - if (status == errSecSuccess) - { - status = SecKeychainSearchCreateFromAttributes(keychain, - kSecCertificateItemClass, NULL, &search); - if (status == errSecSuccess) - { - while (SecKeychainSearchCopyNext(search, &item) == errSecSuccess) - { - certificate_t *cert; - UInt32 len; - void *data; - - if (SecKeychainItemCopyAttributesAndData(item, NULL, NULL, NULL, - &len, &data) == errSecSuccess) - { - cert = lib->creds->create(lib->creds, - CRED_CERTIFICATE, CERT_X509, - BUILD_BLOB_ASN1_DER, chunk_create(data, len), - BUILD_END); - if (cert) - { - DBG2(DBG_CFG, " loaded '%Y'", cert->get_subject(cert)); - set->add_cert(set, TRUE, cert); - loaded++; - } - SecKeychainItemFreeAttributesAndData(NULL, data); - } - CFRelease(item); - } - CFRelease(search); - } - CFRelease(keychain); - } - DBG1(DBG_CFG, "loaded %d certificates from %s", loaded, path); - return set; -} - -/** - * Callback function reloading keychain on changes - */ -static OSStatus keychain_cb(SecKeychainEvent keychainEvent, - SecKeychainCallbackInfo *info, - private_keychain_creds_t *this) -{ - mem_cred_t *new; - - DBG1(DBG_CFG, "received keychain event, reloading credentials"); - - /* register new before removing old */ - new = load_certs(this, SYSTEM); - lib->credmgr->add_set(lib->credmgr, &new->set); - lib->credmgr->remove_set(lib->credmgr, &this->set->set); - - lib->credmgr->flush_cache(lib->credmgr, CERT_X509); - - this->set->destroy(this->set); - this->set = new; - - return errSecSuccess; -} - -/** - * Wait for changes in the keychain and handle them - */ -static job_requeue_t monitor_changes(private_keychain_creds_t *this) -{ - if (SecKeychainAddCallback((SecKeychainCallback)keychain_cb, - kSecAddEventMask | kSecDeleteEventMask | - kSecUpdateEventMask | kSecTrustSettingsChangedEventMask, - this) == errSecSuccess) - { - this->loop = CFRunLoopGetCurrent(); - - /* does not return until canceled */ - CFRunLoopRun(); - - this->loop = NULL; - SecKeychainRemoveCallback((SecKeychainCallback)keychain_cb); - } - return JOB_REQUEUE_NONE; -} - -/** - * Cancel the monitoring thread in its RunLoop - */ -static bool cancel_monitor(private_keychain_creds_t *this) -{ - if (this->loop) - { - CFRunLoopStop(this->loop); - } - return TRUE; -} - -METHOD(keychain_creds_t, destroy, void, - private_keychain_creds_t *this) -{ - lib->credmgr->remove_set(lib->credmgr, &this->set->set); - lib->credmgr->remove_set(lib->credmgr, &this->roots->set); - this->set->destroy(this->set); - this->roots->destroy(this->roots); - free(this); -} - -/** - * See header - */ -keychain_creds_t *keychain_creds_create() -{ - private_keychain_creds_t *this; - - INIT(this, - .public = { - .destroy = _destroy, - }, - ); - - this->roots = load_certs(this, SYSTEM_ROOTS); - this->set = load_certs(this, SYSTEM); - - lib->credmgr->add_set(lib->credmgr, &this->roots->set); - lib->credmgr->add_set(lib->credmgr, &this->set->set); - - lib->processor->queue_job(lib->processor, - (job_t*)callback_job_create_with_prio((void*)monitor_changes, - this, NULL, (void*)cancel_monitor, JOB_PRIO_CRITICAL)); - - return &this->public; -} diff --git a/src/libstrongswan/plugins/keychain/keychain_creds.h b/src/libstrongswan/plugins/keychain/keychain_creds.h deleted file mode 100644 index c9f014fc1..000000000 --- a/src/libstrongswan/plugins/keychain/keychain_creds.h +++ /dev/null @@ -1,45 +0,0 @@ -/* - * Copyright (C) 2013 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup keychain_creds keychain_creds - * @{ @ingroup keychain - */ - -#ifndef KEYCHAIN_CREDS_H_ -#define KEYCHAIN_CREDS_H_ - -typedef struct keychain_creds_t keychain_creds_t; - -#include - -/** - * Credential set using OS X Keychain Services. - */ -struct keychain_creds_t { - - /** - * Destroy a keychain_creds_t. - */ - void (*destroy)(keychain_creds_t *this); -}; - -/** - * Create a keychain_creds instance. - */ -keychain_creds_t *keychain_creds_create(); - -#endif /** KEYCHAIN_CREDS_H_ @}*/ diff --git a/src/libstrongswan/plugins/keychain/keychain_plugin.c b/src/libstrongswan/plugins/keychain/keychain_plugin.c deleted file mode 100644 index 6a58eb583..000000000 --- a/src/libstrongswan/plugins/keychain/keychain_plugin.c +++ /dev/null @@ -1,99 +0,0 @@ -/* - * Copyright (C) 2013 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "keychain_plugin.h" -#include "keychain_creds.h" - -#include - -typedef struct private_keychain_plugin_t private_keychain_plugin_t; - -/** - * private data of keychain_plugin - */ -struct private_keychain_plugin_t { - - /** - * public functions - */ - keychain_plugin_t public; - - /** - * System level Keychain Services credential set - */ - keychain_creds_t *creds; -}; - -METHOD(plugin_t, get_name, char*, - private_keychain_plugin_t *this) -{ - return "keychain"; -} - -/** - * Load/unload certificates from Keychain. - */ -static bool load_creds(private_keychain_plugin_t *this, - plugin_feature_t *feature, bool reg, void *data) -{ - if (reg) - { - this->creds = keychain_creds_create(); - } - else - { - this->creds->destroy(this->creds); - } - return TRUE; -} - -METHOD(plugin_t, get_features, int, - private_keychain_plugin_t *this, plugin_feature_t *features[]) -{ - static plugin_feature_t f[] = { - PLUGIN_CALLBACK((plugin_feature_callback_t)load_creds, NULL), - PLUGIN_PROVIDE(CUSTOM, "keychain"), - PLUGIN_DEPENDS(CERT_DECODE, CERT_X509), - }; - *features = f; - return countof(f); -} - -METHOD(plugin_t, destroy, void, - private_keychain_plugin_t *this) -{ - free(this); -} - -/* - * see header file - */ -PLUGIN_DEFINE(keychain) -{ - private_keychain_plugin_t *this; - - INIT(this, - .public = { - .plugin = { - .get_name = _get_name, - .get_features = _get_features, - .destroy = _destroy, - }, - }, - ); - - return &this->public.plugin; -} diff --git a/src/libstrongswan/plugins/keychain/keychain_plugin.h b/src/libstrongswan/plugins/keychain/keychain_plugin.h deleted file mode 100644 index fbcadeeb4..000000000 --- a/src/libstrongswan/plugins/keychain/keychain_plugin.h +++ /dev/null @@ -1,43 +0,0 @@ -/* - * Copyright (C) 2013 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup keychain keychain - * @ingroup plugins - * - * @defgroup keychain_plugin keychain_plugin - * @{ @ingroup keychain - */ - -#ifndef KEYCHAIN_PLUGIN_H_ -#define KEYCHAIN_PLUGIN_H_ - -#include - -typedef struct keychain_plugin_t keychain_plugin_t; - -/** - * Plugin providing OS X Keychain Services support. - */ -struct keychain_plugin_t { - - /** - * Implements plugin interface, - */ - plugin_t plugin; -}; - -#endif /** KEYCHAIN_PLUGIN_H_ @}*/