/mandos/release

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/release

« back to all changes in this revision

Viewing changes to network-hooks.d/wireless

  • Committer: Teddy Hogeborn
  • Date: 2015-03-10 18:03:38 UTC
  • mto: (237.7.304 trunk)
  • mto: This revision was merged to the branch mainline in revision 325.
  • Revision ID: teddy@recompile.se-20150310180338-pcxw6r2qmw9k6br9
Add ":!RSA" to GnuTLS priority string, to disallow non-DHE kx.

If Mandos was somehow made to use a non-ephemeral Diffie-Hellman key
exchange algorithm in the TLS handshake, any saved network traffic
could then be decrypted later if the Mandos client key was obtained.
By default, Mandos uses ephemeral DH key exchanges which does not have
this problem, but a non-ephemeral key exchange algorithm was still
enabled by default.  The simplest solution is to simply turn that off,
which ensures that Mandos will always use ephemeral DH key exchanges.

There is a "PFS" priority string specifier, but we can't use it because:

1. Security-wise, it is a mix between "NORMAL" and "SECURE128" - it
   enables a lot more algorithms than "SECURE256".

2. It is only available since GnuTLS 3.2.4.

Thanks to Andreas Fischer <af@bantuX.org> for reporting this issue.

Show diffs side-by-side

added added

removed removed

Lines of Context:
6
6
# configuration file(s) should be copied into the
7
7
# /etc/mandos/network-hooks.d directory.
8
8
 
9
# Copyright © 2012 Teddy Hogeborn
 
10
# Copyright © 2012 Björn Påhlsson
 
11
9
12
# Copying and distribution of this file, with or without modification,
10
13
# are permitted in any medium without royalty provided the copyright
11
14
# notice and this notice are preserved.  This file is offered as-is,
32
35
    exit
33
36
fi
34
37
 
35
 
ifkeys=`env | sed -n -e 's/^ADDRESS_\([^=]*\)=.*/\1/p' "$CONFIG" \
36
 
    | sort -u`
 
38
ifkeys=`sed -n -e 's/^ADDRESS_\([^=]*\)=.*/\1/p' "$CONFIG" | sort -u`
37
39
 
38
40
# Exit if DEVICE is set and is not any of the wireless interfaces
39
41
if [ -n "$DEVICE" ]; then
41
43
        for KEY in $ifkeys; do
42
44
            ADDRESS=`eval 'echo "$ADDRESS_'"$KEY"\"`
43
45
            INTERFACE=`addrtoif "$ADDRESS"`
44
 
            if [ "$INTERFACE" = "$DEVICE" ]; then
45
 
                break 2
46
 
            fi
 
46
            
 
47
            case "$DEVICE" in
 
48
                *,"$INTERFACE"|*,"$INTERFACE",*|"$INTERFACE",*|"$INTERFACE")
 
49
                    break 2;;
 
50
            esac
47
51
        done
48
52
        exit
49
53
    done
70
74
    WPAS_OPTIONS="-P$PIDFILE $WPAS_OPTIONS"
71
75
fi
72
76
 
73
 
case "${MODE:-$1}" in
74
 
    start)
75
 
        mkdir -m u=rwx,go= -p "$CTRLDIR"
76
 
        "$wpa_supplicant" -B -g "$CTRL" -p "$CTRLDIR" $WPAS_OPTIONS
77
 
        for KEY in $ifkeys; do
78
 
            ADDRESS=`eval 'echo "$ADDRESS_'"$KEY"\"`
79
 
            INTERFACE=`addrtoif "$ADDRESS"`
80
 
            DRIVER=`eval 'echo "$WPA_DRIVER_'"$KEY"\"`
81
 
            IFDELAY=`eval 'echo "$DELAY_'"$KEY"\"`
82
 
            "$wpa_cli" -g "$CTRL" interface_add "$INTERFACE" "" \
83
 
                "${DRIVER:-wext}" "$CTRLDIR" > /dev/null \
84
 
                | sed -e '/^OK$/d'
85
 
            NETWORK=`"$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" \
86
 
                add_network`
87
 
            eval wpa_interface_"$KEY"
88
 
            "$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" enable_network \
89
 
                "$NETWORK" | sed -e '/^OK$/d'
90
 
            sleep "${IFDELAY:-$DELAY}" &
91
 
            sleep=$!
92
 
            while :; do
93
 
                kill -0 $sleep 2>/dev/null || break
94
 
                STATE=`"$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" \
95
 
                    status | sed -n -e 's/^wpa_state=//p'`
96
 
                if [ "$STATE" = COMPLETED ]; then
97
 
                    while :; do
98
 
                        kill -0 $sleep 2>/dev/null || break 2
99
 
                        UP=`cat /sys/class/net/"$INTERFACE"/operstate`
100
 
                        if [ "$UP" = up ]; then
101
 
                            kill $sleep 2>/dev/null
102
 
                            break 2
103
 
                        fi
104
 
                        sleep 1
105
 
                    done
106
 
                fi
107
 
                sleep 1
108
 
            done &
109
 
            wait $sleep || :
110
 
            IPADDRS=`eval 'echo "$IPADDRS_'"$KEY"\"`
111
 
            if [ -n "$IPADDRS" ]; then
112
 
                if [ "$IPADDRS" = dhcp ]; then
113
 
                    ipconfig -c dhcp -d "$INTERFACE" || :
114
 
                    #dhclient "$INTERFACE"
115
 
                else
116
 
                    for ipaddr in $IPADDRS; do
117
 
                        "$ip" addr add "$ipaddr" dev "$INTERFACE"
118
 
                    done
119
 
                fi
120
 
            fi
121
 
            ROUTES=`eval 'echo "$ROUTES_'"$KEY"\"`
122
 
            if [ -n "$ROUTES" ]; then
123
 
                for route in $ROUTES; do
124
 
                    "$ip" route add "$route" dev "$BRIDGE"
125
 
                done
126
 
            fi
127
 
        done
128
 
        ;;
129
 
    stop)
130
 
        "$wpa_cli" -g "$CTRL" terminate 2>&1 | sed -e '/^OK$/d'
131
 
        for KEY in $ifkeys; do
132
 
            ADDRESS=`eval 'echo "$ADDRESS_'"$KEY"\"`
133
 
            INTERFACE=`addrtoif "$ADDRESS"`
134
 
            "$ip" addr show scope global permanent dev "$INTERFACE" \
135
 
                | while read type addr rest; do
 
77
do_start(){
 
78
    mkdir -m u=rwx,go= -p "$CTRLDIR"
 
79
    "$wpa_supplicant" -B -g "$CTRL" -p "$CTRLDIR" $WPAS_OPTIONS
 
80
    for KEY in $ifkeys; do
 
81
        ADDRESS=`eval 'echo "$ADDRESS_'"$KEY"\"`
 
82
        INTERFACE=`addrtoif "$ADDRESS"`
 
83
        DRIVER=`eval 'echo "$WPA_DRIVER_'"$KEY"\"`
 
84
        IFDELAY=`eval 'echo "$DELAY_'"$KEY"\"`
 
85
        "$wpa_cli" -g "$CTRL" interface_add "$INTERFACE" "" \
 
86
            "${DRIVER:-wext}" "$CTRLDIR" > /dev/null \
 
87
            | sed -e '/^OK$/d'
 
88
        NETWORK=`"$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" add_network`
 
89
        eval wpa_interface_"$KEY"
 
90
        "$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" enable_network \
 
91
            "$NETWORK" | sed -e '/^OK$/d'
 
92
        sleep "${IFDELAY:-$DELAY}" &
 
93
        sleep=$!
 
94
        while :; do
 
95
            kill -0 $sleep 2>/dev/null || break
 
96
            STATE=`"$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" status \
 
97
                | sed -n -e 's/^wpa_state=//p'`
 
98
            if [ "$STATE" = COMPLETED ]; then
 
99
                while :; do
 
100
                    kill -0 $sleep 2>/dev/null || break 2
 
101
                    UP=`cat /sys/class/net/"$INTERFACE"/operstate`
 
102
                    if [ "$UP" = up ]; then
 
103
                        kill $sleep 2>/dev/null
 
104
                        break 2
 
105
                    fi
 
106
                    sleep 1
 
107
                done
 
108
            fi
 
109
            sleep 1
 
110
        done &
 
111
        wait $sleep || :
 
112
        IPADDRS=`eval 'echo "$IPADDRS_'"$KEY"\"`
 
113
        if [ -n "$IPADDRS" ]; then
 
114
            if [ "$IPADDRS" = dhcp ]; then
 
115
                ipconfig -c dhcp -d "$INTERFACE" || :
 
116
                #dhclient "$INTERFACE"
 
117
            else
 
118
                for ipaddr in $IPADDRS; do
 
119
                    "$ip" addr add "$ipaddr" dev "$INTERFACE"
 
120
                done
 
121
            fi
 
122
        fi
 
123
        ROUTES=`eval 'echo "$ROUTES_'"$KEY"\"`
 
124
        if [ -n "$ROUTES" ]; then
 
125
            for route in $ROUTES; do
 
126
                "$ip" route add "$route" dev "$INTERFACE"
 
127
            done
 
128
        fi
 
129
    done
 
130
}
 
131
 
 
132
do_stop(){
 
133
    "$wpa_cli" -g "$CTRL" terminate 2>&1 | sed -e '/^OK$/d'
 
134
    for KEY in $ifkeys; do
 
135
        ADDRESS=`eval 'echo "$ADDRESS_'"$KEY"\"`
 
136
        INTERFACE=`addrtoif "$ADDRESS"`
 
137
        "$ip" addr show scope global permanent dev "$INTERFACE" \
 
138
            | while read type addr rest; do
136
139
                case "$type" in
137
140
                    inet|inet6)
138
141
                        "$ip" addr del "$addr" dev "$INTERFACE"
139
142
                        ;;
140
143
                esac
141
144
            done
142
 
            "$ip" link set dev "$INTERFACE" down
143
 
        done
 
145
        "$ip" link set dev "$INTERFACE" down
 
146
    done
 
147
}
 
148
 
 
149
case "${MODE:-$1}" in
 
150
    start|stop)
 
151
        do_"${MODE:-$1}"
144
152
        ;;
145
153
    files)
146
154
        echo "$wpa_supplicant"