From 482a9e8a22f8831c128bb94f748179b6695e2bd2 Mon Sep 17 00:00:00 2001 From: pfelt Date: Sat, 3 Feb 2007 23:39:03 +0000 Subject: [PATCH] the bulk of the conversion to native gnutls (no openssl shim) --- configure.ac | 12 ++ include/connio.h | 49 +++-- include/xplhash.h | 1 + .../admin/bongo/admintool/SetupCommands.py | 54 ++++-- src/apps/manager/manager.c | 3 + src/apps/setup/bongo-setup.py | 13 +- src/libs/connio/connio.c | 171 +++++++++++------- src/libs/connio/conniop.h | 2 + src/libs/connio/unix-ip.c | 2 +- src/libs/python/bongo/Xpl.py.in | 3 + src/libs/python/bongo/admin/Util.py | 65 ------- src/libs/xpl/hash.c | 12 ++ 12 files changed, 214 insertions(+), 173 deletions(-) diff --git a/configure.ac b/configure.ac index b9ab6e7..30968ac 100644 --- a/configure.ac +++ b/configure.ac @@ -278,6 +278,18 @@ XPL_DEFAULT_CERT_PATH=${XPL_DEFAULT_STATE_DIR}/dbf/osslcert.pem AC_SUBST(XPL_DEFAULT_CERT_PATH) AC_DEFINE_UNQUOTED(XPL_DEFAULT_CERT_PATH, "$XPL_DEFAULT_CERT_PATH", [Default cert path]) +XPL_DEFAULT_RSAPARAMS_PATH=${XPL_DEFAULT_STATE_DIR}/dbf/rsaparams.pem +AC_SUBST(XPL_DEFAULT_RSAPARAMS_PATH) +AC_DEFINE_UNQUOTED(XPL_DEFAULT_RSAPARAMS_PATH, "$XPL_DEFAULT_RSAPARAMS_PATH", [Default path for RSA parameters]) + +XPL_DEFAULT_DHPARAMS_PATH=${XPL_DEFAULT_STATE_DIR}/dbf/dhparams.pem +AC_SUBST(XPL_DEFAULT_DHPARAMS_PATH) +AC_DEFINE_UNQUOTED(XPL_DEFAULT_DHPARAMS_PATH, "$XPL_DEFAULT_DHPARAMS_PATH", [Default path for DH parameters]) + +XPL_DEFAULT_RANDSEED_PATH=${XPL_DEFAULT_STATE_DIR}/dbf/randomseed +AC_SUBST(XPL_DEFAULT_RANDSEED_PATH) +AC_DEFINE_UNQUOTED(XPL_DEFAULT_RANDSEED_PATH, "$XPL_DEFAULT_RANDSEED_PATH", [Default path for seed to RNG]) + XPL_DEFAULT_KEY_PATH=${XPL_DEFAULT_STATE_DIR}/dbf/osslpriv.pem AC_SUBST(XPL_DEFAULT_KEY_PATH) AC_DEFINE_UNQUOTED(XPL_DEFAULT_KEY_PATH, "$XPL_DEFAULT_KEY_PATH", [Default key path]) diff --git a/include/connio.h b/include/connio.h index 76fed75..0d1c318 100644 --- a/include/connio.h +++ b/include/connio.h @@ -26,12 +26,15 @@ #include #include - -typedef SSL_CTX bongo_ssl_context; +#include +#include // from openssl -#define SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS 0x00000800L +#define SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS 0x00000800L +typedef struct { + gnutls_certificate_credentials_t cert_cred; +} bongo_ssl_context; #define CONN_BUFSIZE 1023 #define CONN_TCP_MTU (1536 * 3) @@ -298,8 +301,8 @@ typedef unsigned int in_addr_t; } \ (c)->send.read = (c)->send.write = (c)->send.buffer; \ if ((c)->ssl.enable) { \ - SSL_shutdown((c)->ssl.context); \ - SSL_free((c)->ssl.context); \ + gnutls_bye((c)->ssl.context, GNUTLS_SHUT_RDWR); \ + gnutls_deinit((c)->ssl.context); \ (c)->ssl.context = NULL; \ (c)->ssl.enable = FALSE; \ } \ @@ -312,15 +315,11 @@ typedef unsigned int in_addr_t; #define CONN_SSL_NEW(c, s) \ { \ - (c)->ssl.context = SSL_new(s); \ - if ((c)->ssl.context \ - && (SSL_set_bsdfd((c)->ssl.context, (c)->socket) == 1)) \ + (c)->ssl.context = __gnutls_new(s); \ + if ((c)->ssl.context) \ (c)->ssl.enable = TRUE; \ } else { \ - if ((c)->ssl.context) { \ - SSL_free((c)->ssl.context); \ - (c)->ssl.context = NULL; \ - } \ + (c)->ssl.context = NULL; \ (c)->ssl.enable = FALSE; \ } \ } @@ -328,7 +327,7 @@ typedef unsigned int in_addr_t; #define CONN_SSL_FREE(c) \ { \ if ((c)->ssl.enable) { \ - SSL_free((c)->ssl.context); \ + gnutls_deinit((c)->ssl.context); \ (c)->ssl.context = NULL; \ (c)->ssl.enable = FALSE; \ } \ @@ -336,14 +335,13 @@ typedef unsigned int in_addr_t; #define CONN_SSL_ACCEPT(c, s) \ { \ - (c)->ssl.context = SSL_new(s); \ + (c)->ssl.context = __gnutls_new(s); \ if ((c)->ssl.context \ - && (SSL_set_bsdfd((c)->ssl.context, (c)->socket) == 1) \ - && (SSL_accept((c)->ssl.context) == 1)) { \ + && (gnutls_handshake((c)->ssl.context) == 0)) { \ (c)->ssl.enable = TRUE; \ } else { \ if ((c)->ssl.context) { \ - SSL_free((c)->ssl.context); \ + gnutls_deinit((c)->ssl.context); \ (c)->ssl.context = NULL; \ } \ (c)->ssl.enable = FALSE; \ @@ -352,14 +350,13 @@ typedef unsigned int in_addr_t; #define CONN_SSL_CONNECT(c, s, r) \ { \ - (c)->ssl.context = SSL_new(s); \ + (c)->ssl.context = __gnutls_new(s); \ if ((c)->ssl.context \ - && (SSL_set_bsdfd((c)->ssl.context, (c)->socket) == 1) \ - && (SSL_connect((c)->ssl.context) == 1)) { \ + && (gnutls_handshake((c)->ssl.context) == 0)) { \ (c)->ssl.enable = TRUE; \ } else { \ if ((c)->ssl.context) { \ - SSL_free((c)->ssl.context); \ + gnutls_deinit((c)->ssl.context); \ (c)->ssl.context = NULL; \ } \ (c)->ssl.enable = FALSE; \ @@ -402,10 +399,10 @@ typedef unsigned int in_addr_t; #endif -#define CONN_SSL_READ(c, b, l, r) (r) = SSL_read((c)->ssl.context, (void *)(b), (l)); \ +#define CONN_SSL_READ(c, b, l, r) (r) = gnutls_record_recv((c)->ssl.context, (void *)(b), (l)); \ CONN_TRACE_DATA_AND_ERROR((c), CONN_TRACE_EVENT_READ, (b), (r), "SSL_READ"); -#define CONN_SSL_WRITE(c, b, l, r) (r) = SSL_write((c)->ssl.context, (void *)(b), (l)); \ +#define CONN_SSL_WRITE(c, b, l, r) (r) = gnutls_record_send((c)->ssl.context, (void *)(b), (l)); \ CONN_TRACE_DATA_AND_ERROR((c), CONN_TRACE_EVENT_WRITE, (b), (r), "SSL_WRITE"); typedef struct _ConnectionBuffer { @@ -419,12 +416,10 @@ typedef struct _ConnectionBuffer { int timeOut; } ConnectionBuffer; -typedef SSL_METHOD *(* SSLMethod)(void); - typedef struct _ConnSSLConfiguration { unsigned long options; - SSLMethod method; + void *method; long mode; @@ -455,7 +450,7 @@ typedef struct _Connection { struct { BOOL enable; - SSL *context; + gnutls_session_t context; } ssl; struct sockaddr_in socketAddress; diff --git a/include/xplhash.h b/include/xplhash.h index f382394..9ba3aab 100644 --- a/include/xplhash.h +++ b/include/xplhash.h @@ -48,5 +48,6 @@ void XplHashFinalBytes(xpl_hash_context *context, unsigned char *buffer, size_t void XplHashFinal(xpl_hash_context *context, xpl_hash_stringcase strcase, unsigned char *buffer, size_t length); void XplRandomData(void *buffer, size_t length); +void XplSaveRandomSeed(void); #endif // XPLHASH_H diff --git a/src/apps/admin/bongo/admintool/SetupCommands.py b/src/apps/admin/bongo/admintool/SetupCommands.py index 7370914..4f88f51 100644 --- a/src/apps/admin/bongo/admintool/SetupCommands.py +++ b/src/apps/admin/bongo/admintool/SetupCommands.py @@ -2,6 +2,9 @@ import os import logging import shutil import socket +import tempfile + +from string import Template from bongo.cmdparse import Command @@ -138,10 +141,23 @@ class SetupSslCommand(Command): self.add_option("-c", "--cert") self.add_option("-k", "--key") + self.add_option("-i", "--ip") + self.add_option("-d", "--domain") def run(self, options, args): + ct = os.popen('which certtool').read().strip() + if ct is '': + self.error("Cannot find GNUTLS certtool") + return + certpath = Xpl.DEFAULT_CERT_PATH keypath = Xpl.DEFAULT_KEY_PATH + rsapath = Xpl.DEFAULT_RSAPARAMS_PATH + dhpath = Xpl.DEFAULT_DHPARAMS_PATH + rngpath = Xpl.DEFAULT_RANDSEED_PATH + + cmds = [] + t, template = tempfile.mkstemp() if options.cert and options.key: self.log.info("Copying the requested certificate and key into place") @@ -153,20 +169,30 @@ class SetupSslCommand(Command): shutil.copyfile(options.cert, certpath) shutil.copyfile(options.key, keypath) + else: + self.log.info("Generating a new cert/key pair") + cmds.append([keypath, '--generate-privkey --bits 1024']) + cmds.append([certpath, ' -s --load-privkey ' + keypath + ' --template ' + template]) + format = Template("organization = \"Bongo Project\"" \ + "unit = \"Fake Certs Dept.\"\nstate = \"None\"\ncountry = US \n" \ + "cn = ${cn} \nserial = 0001 \nexpiration_days = 700 \n" \ + "dns_name = ${dns} \nip_address = ${ip} \nsigning_key") + os.write(t, format.substitute(cn = options.domain, dns = options.domain, ip = options.ip)) - return + os.close(t) + cmds.append([dhpath, '--generate-dh-params --bits 1024']) + cmds.append([rsapath, '--generate-privkey --bits 512']) - self.log.info("Generating a new cert/key pair") + self.log.info("Creating encryption data. *This may take some time!*") + for cmdpair in cmds: + path, cmdopts = cmdpair + command = ct + ' ' + cmdopts + ' --outfile ' + path + ' > /dev/null' + if not os.path.exists(os.path.dirname(path)): + os.makedirs(path) + self.log.info("Creating %s...", path) + self.log.debug("running: %s", command) + ret = os.system(command) / 256 + if ret: + self.error("Error!") - # ensure that the directories exist for the cert and key files - for p in certpath, keypath: - if not os.path.exists(os.path.dirname(p)): - os.makedirs(p) - - cmd = "openssl req -x509 -nodes -subj /C=US/ST=foo/L=bar/CN=%s -newkey rsa:1024 -keyout %s -out %s" % (socket.gethostname(), keypath, certpath) - - self.log.debug("running %s", cmd) - cmdret = os.system(cmd) / 256 - - if cmdret: - self.error("error running openssl") + os.remove(template) diff --git a/src/apps/manager/manager.c b/src/apps/manager/manager.c index b0f7610..b15dfd5 100644 --- a/src/apps/manager/manager.c +++ b/src/apps/manager/manager.c @@ -832,6 +832,9 @@ main(int argc, char **argv) BOOL unlockFile = FALSE; BOOL startLdap = FALSE; + XplInit(); + XplSaveRandomSeed(); /// is this appropriate? + if (getuid() == 0) { if (XplSetEffectiveUser(MsgGetUnprivilegedUser()) < 0) { fprintf(stderr, "bongomanager: could not drop to unprivileged user '%s'\n", MsgGetUnprivilegedUser()); diff --git a/src/apps/setup/bongo-setup.py b/src/apps/setup/bongo-setup.py index 7bda166..d416499 100755 --- a/src/apps/setup/bongo-setup.py +++ b/src/apps/setup/bongo-setup.py @@ -162,7 +162,6 @@ See \"%(bongo_setup)s --help\" for command-line options to further automate the print 'Imported objects from \"%s\".' % options.file SetupACL(mdbconf, options) GeneratePasswords(options) - SetupCerts(options) print 'Configuring final settings...' from bongo import MDB @@ -196,11 +195,11 @@ See \"%(bongo_setup)s --help\" for command-line options to further automate the except BongoError: if not domain in ['localhost', 'localhost.localdomain']: raise - + smtpserver = msgserver + '\\' + msgapi.AGENT_SMTP if(mdb.IsObject(smtpserver)): mdb.AddAttribute(smtpserver, msgapi.A_DOMAIN, domain) - + try: default = socket.gethostbyname(domain) except: @@ -209,6 +208,12 @@ See \"%(bongo_setup)s --help\" for command-line options to further automate the ip = Input('Enter IP address on which to run Bongo', {}, default, options) mdb.SetAttribute(msgserver, msgapi.A_IP_ADDRESS, [ip]) + + options.domain = domain + options.ip = ip + + # now we have the hostname and ip, we can setup a sensible cert. + SetupCerts(options) # shut down the temporary slapd if mdbconf.has_key("slapdConfig"): @@ -580,6 +585,8 @@ def SetupCerts(options): if not certops: print 'Generating certificate + key...' + certops.append('--ip=\"%s\"' % options.ip) + certops.append('--domain=\"%s\"' % options.domain) if AdminCmd(options, authops + ['setup-ssl'] + certops) != 0: raise BongoError('Certificate + key installation failed.') diff --git a/src/libs/connio/connio.c b/src/libs/connio/connio.c index baac33e..10c75c9 100644 --- a/src/libs/connio/connio.c +++ b/src/libs/connio/connio.c @@ -39,6 +39,29 @@ #include "conniop.h" ConnIOGlobals ConnIO; +gnutls_dh_params_t dh_params; +gnutls_rsa_params_t rsa_params; + +gnutls_session_t +__gnutls_new(bongo_ssl_context *context) { + gnutls_session_t session; + int ccode; + + ccode = gnutls_init(&session, GNUTLS_SERVER); + if (ccode) { + return(NULL); + } + + ccode = gnutls_set_default_export_priority(session); + + /* store in the credetials loaded earler */ + ccode = gnutls_credentials_set(session, GNUTLS_CRD_CERTIFICATE, context->cert_cred); + + /* initialize the dh bits */ + gnutls_dh_set_prime_bits(session, 1024); + + return session; +} BOOL ConnStartup(unsigned long TimeOut, BOOL EnableSSL) @@ -49,6 +72,56 @@ ConnStartup(unsigned long TimeOut, BOOL EnableSSL) int i; unsigned char c; unsigned char seed[129]; + FILE *genparams; + + /* initialize the gnutls library */ + gnutls_global_init(); + + /* try to load dh data out of a file */ + gnutls_dh_params_init(&dh_params); + genparams = fopen(XPL_DEFAULT_DHPARAMS_PATH, "r"); + if (genparams) { + char tmpdata[2048]; + gnutls_datum dh_parameters; + + dh_parameters.size = fread(tmpdata, 1, sizeof(tmpdata)-1, genparams); + /* null the last byte */ + tmpdata[dh_parameters.size] = 0x00; + + fclose(genparams); + + /* store the data in the datum so that we can initialize it */ + dh_parameters.data = tmpdata; + + /* import the key */ + i = gnutls_dh_params_import_pkcs3(dh_params, &dh_parameters, GNUTLS_X509_FMT_PEM); + } else { + /* generate dh stuff */ + gnutls_dh_params_generate2(dh_params, 1024); + } + + /* try to load the rsa data out of a file */ + gnutls_rsa_params_init(&rsa_params); + genparams = fopen(XPL_DEFAULT_RSAPARAMS_PATH, "r"); + if (genparams) { + char tmpdata[2048]; + gnutls_datum rsa_parameters; + + rsa_parameters.size = fread(tmpdata, 1, sizeof(tmpdata)-1, genparams); + /* null the last byte */ + tmpdata[rsa_parameters.size] = 0x00; + + fclose(genparams); + + /* store the data in the datum so that we can initialize it */ + rsa_parameters.data = tmpdata; + + /* import the key */ + i = gnutls_rsa_params_import_pkcs1(rsa_params, &rsa_parameters, GNUTLS_X509_FMT_PEM); + } else { + /* generate rsa stuff */ + gnutls_rsa_params_generate2(rsa_params, 512); + } XplOpenLocalSemaphore(ConnIO.allocated.sem, 0); @@ -64,9 +137,6 @@ ConnStartup(unsigned long TimeOut, BOOL EnableSSL) srand((unsigned int)time(NULL)); - SSL_load_error_strings(); - SSL_library_init(); - XPLCryptoLockInit(); memset(seed, 0, sizeof(seed)); @@ -76,8 +146,6 @@ ConnStartup(unsigned long TimeOut, BOOL EnableSSL) } seed[sizeof(seed) - 1] = '\0'; - - RAND_seed(seed, sizeof(seed) - 1); } XplSignalLocalSemaphore(ConnIO.allocated.sem); @@ -89,7 +157,8 @@ void ConnSSLContextFree(bongo_ssl_context *context) { if (context) { - SSL_CTX_free((SSL_CTX *)context); + gnutls_certificate_free_credentials(context->cert_cred); + MemFree(context); } return; @@ -98,47 +167,26 @@ ConnSSLContextFree(bongo_ssl_context *context) bongo_ssl_context * ConnSSLContextAlloc(ConnSSLConfiguration *ConfigSSL) { + bongo_ssl_context *result; int ccode; - SSL_CTX *context; - context = SSL_CTX_new(ConfigSSL->method()); - if (context) { - SSL_CTX_set_mode(context, ConfigSSL->mode); + /* get me the context */ + result = MemMalloc(sizeof(bongo_ssl_context)); - if (ConfigSSL->cipherList) { - SSL_CTX_set_cipher_list(context, ConfigSSL->cipherList); - } - - if (ConfigSSL->options & SSL_DONT_INSERT_EMPTY_FRAGMENTS) { - SSL_CTX_set_options(context, SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS); - } - - if (ConfigSSL->options & SSL_ALLOW_CHAIN) { - //FIXME: OPENSSL - // ccode = SSL_CTX_use_certificate_chain_file(context, ConfigSSL->certificate.file); - ccode = SSL_CTX_use_certificate_file(context, ConfigSSL->certificate.file, ConfigSSL->certificate.type); - } else { - ccode = SSL_CTX_use_certificate_file(context, ConfigSSL->certificate.file, ConfigSSL->certificate.type); - } - - if (ccode == 1) { - ccode = SSL_CTX_use_PrivateKey_file(context, ConfigSSL->key.file, ConfigSSL->key.type); - } - - // FIXME: OPENSSL - // if (ccode == 1) { - // ccode = SSL_CTX_check_private_key(context); - // } - - if (ccode == 1) { - return((bongo_ssl_context *)context); - } - - SSL_CTX_free(context); - context = NULL; + /* allocate the credential holder */ + ccode = gnutls_certificate_allocate_credentials(&(result->cert_cred)); + if (ccode) { + MemFree(result); + return(NULL); } - return(NULL); + ccode = gnutls_certificate_set_x509_key_file(result->cert_cred, ConfigSSL->certificate.file, ConfigSSL->key.file, ConfigSSL->key.type); + + /* store both the rsa and dh data in the creds */ + gnutls_certificate_set_dh_params(result->cert_cred, dh_params); + gnutls_certificate_set_rsa_export_params(result->cert_cred, rsa_params); + + return result; } Connection * @@ -295,12 +343,12 @@ ConnConnectInternal(Connection *conn, struct sockaddr *saddr, socklen_t slen, bo conn->ssl.enable = FALSE; return(conn->socket); - } else if ((conn->ssl.context = SSL_new((SSL_CTX *)context)) != NULL) { + } else if ((conn->ssl.context = __gnutls_new(context)) != NULL) { setsockopt(conn->socket, IPPROTO_TCP, 1, (unsigned char *)&ccode, sizeof(ccode)); - - ccode = SSL_set_bsdfd(conn->ssl.context, conn->socket); - if ((ccode == 1) - && ((ccode = SSL_connect(conn->ssl.context)) == 1)) { + + gnutls_transport_set_ptr (conn->ssl.context, (gnutls_transport_ptr_t) conn->socket); + ccode = gnutls_handshake (conn->ssl.context); + if (!ccode) { CONN_TRACE_EVENT(conn, CONN_TRACE_EVENT_SSL_CONNECT); conn->ssl.enable = TRUE; @@ -346,18 +394,18 @@ ConnEncrypt(Connection *conn, bongo_ssl_context *context) register Connection *c = conn; c->ssl.enable = FALSE; - if ((c->ssl.context = SSL_new((SSL_CTX *)context)) != NULL) { + if ((c->ssl.context = __gnutls_new(context)) != NULL) { setsockopt(c->socket, IPPROTO_TCP, 1, (unsigned char *)&ccode, sizeof(ccode)); - ccode = SSL_set_bsdfd(c->ssl.context, c->socket); - if ((ccode == 1) - && ((ccode = SSL_connect(c->ssl.context)) == 1)) { + gnutls_transport_set_ptr(c->ssl.context, (gnutls_transport_ptr_t) c->socket); + ccode = gnutls_handshake (c->ssl.context); + if (!ccode) { CONN_TRACE_EVENT(c, CONN_TRACE_EVENT_SSL_CONNECT); c->ssl.enable = TRUE; return(0); } - SSL_free(c->ssl.context); + gnutls_deinit(c->ssl.context); c->ssl.context = NULL; } @@ -377,23 +425,20 @@ ConnNegotiate(Connection *conn, bongo_ssl_context *context) return(TRUE); } - if ((c->ssl.context = SSL_new((SSL_CTX *)context)) != NULL) { + if ((c->ssl.context = __gnutls_new(context)) != NULL) { setsockopt(c->socket, IPPROTO_TCP, 1, (unsigned char *)&ccode, sizeof(ccode)); - ccode = SSL_set_bsdfd(c->ssl.context, c->socket); - if (ccode == 1) - ccode = SSL_accept(c->ssl.context); - if (ccode == 1) { + gnutls_transport_set_ptr(c->ssl.context, (gnutls_transport_ptr_t) c->socket); + ccode = gnutls_handshake(c->ssl.context); + if (!ccode) { CONN_TRACE_EVENT(c, CONN_TRACE_EVENT_SSL_CONNECT); return(TRUE); - } else { - const char *error = gnutls_strerror(-1 * ERR_get_error()); - ccode = 0; } - + printf("%s\n", gnutls_strerror(ccode)); + gnutls_deinit(c->ssl.context); c->ssl.enable = FALSE; - SSL_free(c->ssl.context); c->ssl.context = NULL; + } return(FALSE); @@ -450,7 +495,7 @@ ConnFree(Connection *Conn) } if (c->ssl.context) { - SSL_free(c->ssl.context); + gnutls_deinit(c->ssl.context); } XplWaitOnLocalSemaphore(ConnIO.allocated.sem); diff --git a/src/libs/connio/conniop.h b/src/libs/connio/conniop.h index 03e99d2..b06c3b8 100644 --- a/src/libs/connio/conniop.h +++ b/src/libs/connio/conniop.h @@ -48,4 +48,6 @@ typedef struct _ConnIO { extern ConnIOGlobals ConnIO; +gnutls_session_t __gnutls_new(bongo_ssl_context *context); + #endif diff --git a/src/libs/connio/unix-ip.c b/src/libs/connio/unix-ip.c index 64fbc12..ee7fd8d 100644 --- a/src/libs/connio/unix-ip.c +++ b/src/libs/connio/unix-ip.c @@ -63,7 +63,7 @@ static BIO_METHOD methods_bsdsockp = sock_write, sock_read, sock_puts, - NULL, /* sock_gets, + NULL, // sock_gets, sock_ctrl, sock_new, sock_free, diff --git a/src/libs/python/bongo/Xpl.py.in b/src/libs/python/bongo/Xpl.py.in index 865c31b..30bfb28 100644 --- a/src/libs/python/bongo/Xpl.py.in +++ b/src/libs/python/bongo/Xpl.py.in @@ -14,6 +14,9 @@ DEFAULT_WORK_DIR = '@XPL_DEFAULT_WORK_DIR@' DEFAULT_CERT_PATH = '@XPL_DEFAULT_CERT_PATH@' DEFAULT_KEY_PATH = '@XPL_DEFAULT_KEY_PATH@' +DEFAULT_DHPARAMS_PATH = '@XPL_DEFAULT_DHPARAMS_PATH@' +DEFAULT_RSAPARAMS_PATH = '@XPL_DEFAULT_RSAPARAMS_PATH@' +DEFAULT_RANDSEED_PATH = '@XPL_DEFAULT_RANDSEED_PATH@' DEFAULT_SLAPD_PATH = '@DEFAULT_SLAPD_PATH@' DEFAULT_SLAPD_SCHEMA_DIR = '@DEFAULT_SLAPD_SCHEMA_DIR@' diff --git a/src/libs/python/bongo/admin/Util.py b/src/libs/python/bongo/admin/Util.py index e18dbf9..c41759f 100644 --- a/src/libs/python/bongo/admin/Util.py +++ b/src/libs/python/bongo/admin/Util.py @@ -629,71 +629,6 @@ def ModifyConfProperties(props): fileProps.update(props) WriteConfProperties(fileProps) -def GenerateCertificate(keyPath, certPath): - """Generate a temporary, self-signed certificate and private key""" - openssl_path = os.popen('which openssl').read().strip() - - if openssl_path and openssl_path is not '': - # make key path - path = keyPath.split('/') - path = '/' + '/'.join(path[0:-1]) - - if not os.path.exists(path): - os.makedirs(path) - - # make cert path - path = certPath.split('/') - path = '/' + '/'.join(path[0:-1]) - - if not os.path.exists(path): - os.makedirs(path) - - cmd = openssl_path + ' req -x509 -nodes' - cmd += ' -subj \'/C=US/ST=foo/L=bar/CN=' + socket.gethostname() + '\'' - cmd += ' -newkey rsa:1024 -keyout ' + keyPath + ' -out ' + certPath - - x = os.popen4(cmd)[1].read() - - if x.find('error') >= 0: - raise BongoError(x) - else: - raise BongoError('openssl not found') - -#def GenerateCertificate(keyPath, certPath): -# from OpenSSL import crypto -# import socket -# -# pkey = crypto.PKey() -# cert = crypto.X509() -# issuer = cert.get_issuer() -# -# # This has to be the host name -# issuer.commonName = socket.gethostname() -# -# pkey.generate_key(crypto.TYPE_RSA, 1024) -# #cert.set_issuer(issuer) -# cert.sign(pkey, 'md5') -# -# pkey_dump = crypto.dump_privatekey(crypto.FILETYPE_PEM, pkey) -# cert_dump = crypto.dump_certificate(crypto.FILETYPE_PEM, cert) -# -# path = keyPath.split('/') -# path = '/' + '/'.join(path[0:-1]) -# if not os.path.exists(path): -# os.makedirs(path) -# pkey_file = open(keyPath, 'w+') -# pkey_file.write(pkey_dump) -# pkey_file.close() -# -# path = certPath.split('/') -# path = '/' + '/'.join(path[0:-1]) -# if not os.path.exists(path): -# os.makedirs(path) -# cert_file = open(certPath, 'w+') -# cert_file.write(cert_dump) -# cert_file.close() - - SCHEMA_XML = '%s/bongo-schema.xml' % Xpl.DEFAULT_CONF_DIR BASE_XML = '%s/base-schema.xml' % Xpl.DEFAULT_CONF_DIR diff --git a/src/libs/xpl/hash.c b/src/libs/xpl/hash.c index 5bba566..8ad5b86 100644 --- a/src/libs/xpl/hash.c +++ b/src/libs/xpl/hash.c @@ -6,6 +6,7 @@ * Implementation of XPL hash API: access to gcrypt's MD5 and SHA1 algorithms */ +#include #include #include #include @@ -31,6 +32,7 @@ XplHashInit(void) const char *gcry_version; gcry_control (GCRYCTL_SET_THREAD_CBS, &gcry_threads_pthread); gcry_version = gcry_check_version(NULL); + gcry_control (GCRYCTL_SET_RANDOM_SEED_FILE, XPL_DEFAULT_RANDSEED_PATH); } /** @@ -124,3 +126,13 @@ XplRandomData(void *buffer, size_t length) { gcry_randomize(buffer, length, GCRY_STRONG_RANDOM); } + +/** + * Save the current random seed to disk. This should only be done by 'management' processes, and + * should not usually be called by agents. + */ +void +XplSaveRandomSeed(void) +{ + gcry_control (GCRYCTL_UPDATE_RANDOM_SEED_FILE); +}