32
32
#define _LARGEFILE_SOURCE
33
33
#define _FILE_OFFSET_BITS 64
39
#include <net/if.h> /* if_nametoindex */
35
#define _GNU_SOURCE /* TEMP_FAILURE_RETRY() */
37
#include <stdio.h> /* fprintf(), stderr, fwrite(), stdout,
39
#include <stdint.h> /* uint16_t, uint32_t */
40
#include <stddef.h> /* NULL, size_t, ssize_t */
41
#include <stdlib.h> /* free(), EXIT_SUCCESS, EXIT_FAILURE,
43
#include <stdbool.h> /* bool, true */
44
#include <string.h> /* memset(), strcmp(), strlen(),
45
strerror(), memcpy(), strcpy() */
46
#include <sys/ioctl.h> /* ioctl */
47
#include <sys/types.h> /* socket(), inet_pton(), sockaddr,
48
sockaddr_in6, PF_INET6,
49
SOCK_STREAM, INET6_ADDRSTRLEN,
51
#include <inttypes.h> /* PRIu16 */
52
#include <sys/socket.h> /* socket(), struct sockaddr_in6,
53
struct in6_addr, inet_pton(),
55
#include <assert.h> /* assert() */
56
#include <errno.h> /* perror(), errno */
57
#include <time.h> /* time() */
58
#include <net/if.h> /* ioctl, ifreq, SIOCGIFFLAGS, IFF_UP,
59
SIOCSIFFLAGS, if_indextoname(),
60
if_nametoindex(), IF_NAMESIZE */
61
#include <unistd.h> /* close(), SEEK_SET, off_t, write(),
62
getuid(), getgid(), setuid(),
64
#include <netinet/in.h>
65
#include <arpa/inet.h> /* inet_pton(), htons */
66
#include <iso646.h> /* not, and */
67
#include <argp.h> /* struct argp_option, error_t, struct
68
argp_state, struct argp,
69
argp_parse(), ARGP_KEY_ARG,
70
ARGP_KEY_END, ARGP_ERR_UNKNOWN */
73
/* All Avahi types, constants and functions
41
76
#include <avahi-core/core.h>
42
77
#include <avahi-core/lookup.h>
43
78
#include <avahi-core/log.h>
45
80
#include <avahi-common/malloc.h>
46
81
#include <avahi-common/error.h>
49
#include <sys/types.h> /* socket(), inet_pton() */
50
#include <sys/socket.h> /* socket(), struct sockaddr_in6,
51
struct in6_addr, inet_pton() */
52
#include <gnutls/gnutls.h> /* All GnuTLS stuff */
53
#include <gnutls/openpgp.h> /* GnuTLS with openpgp stuff */
55
#include <unistd.h> /* close() */
56
#include <netinet/in.h>
57
#include <stdbool.h> /* true */
58
#include <string.h> /* memset */
59
#include <arpa/inet.h> /* inet_pton() */
60
#include <iso646.h> /* not */
63
#include <errno.h> /* perror() */
84
#include <gnutls/gnutls.h> /* All GnuTLS types, constants and functions
86
init_gnutls_session(),
88
#include <gnutls/openpgp.h> /* gnutls_certificate_set_openpgp_key_file(),
89
GNUTLS_OPENPGP_FMT_BASE64 */
92
#include <gpgme.h> /* All GPGME types, constants and functions
94
GPGME_PROTOCOL_OpenPGP,
69
97
#define BUFFER_SIZE 256
71
static int dh_bits = 1024;
73
100
static const char *keydir = "/conf/conf.d/mandos";
74
static const char *pubkeyfile = "pubkey.txt";
75
static const char *seckeyfile = "seckey.txt";
101
static const char mandos_protocol_version[] = "1";
102
const char *argp_program_version = "password-request 1.0";
103
const char *argp_program_bug_address = "<mandos@fukt.bsnet.se>";
105
/* Used for passing in values through the Avahi callback functions */
81
gnutls_session_t session;
107
AvahiSimplePoll *simple_poll;
82
109
gnutls_certificate_credentials_t cred;
110
unsigned int dh_bits;
83
111
gnutls_dh_params_t dh_params;
87
static ssize_t pgp_packet_decrypt (char *packet, size_t packet_size,
112
const char *priority;
116
* Make room in "buffer" for at least BUFFER_SIZE additional bytes.
117
* "buffer_capacity" is how much is currently allocated,
118
* "buffer_length" is how much is already used.
120
size_t adjustbuffer(char **buffer, size_t buffer_length,
121
size_t buffer_capacity){
122
if (buffer_length + BUFFER_SIZE > buffer_capacity){
123
*buffer = realloc(*buffer, buffer_capacity + BUFFER_SIZE);
127
buffer_capacity += BUFFER_SIZE;
129
return buffer_capacity;
133
* Decrypt OpenPGP data using keyrings in HOMEDIR.
134
* Returns -1 on error
136
static ssize_t pgp_packet_decrypt (const char *cryptotext,
89
139
const char *homedir){
90
140
gpgme_data_t dh_crypto, dh_plain;
94
ssize_t new_packet_capacity = 0;
95
ssize_t new_packet_length = 0;
144
size_t plaintext_capacity = 0;
145
ssize_t plaintext_length = 0;
96
146
gpgme_engine_info_t engine_info;
99
fprintf(stderr, "Trying to decrypt OpenPGP packet\n");
149
fprintf(stderr, "Trying to decrypt OpenPGP data\n");
197
/* Delete the GPGME FILE pointer cryptotext data buffer */
198
gpgme_data_release(dh_crypto);
200
251
/* Seek back to the beginning of the GPGME plaintext data buffer */
201
252
if (gpgme_data_seek(dh_plain, (off_t) 0, SEEK_SET) == -1){
202
253
perror("pgpme_data_seek");
254
plaintext_length = -1;
207
if (new_packet_length + BUFFER_SIZE > new_packet_capacity){
208
*new_packet = realloc(*new_packet,
209
(unsigned int)new_packet_capacity
211
if (*new_packet == NULL){
215
new_packet_capacity += BUFFER_SIZE;
260
plaintext_capacity = adjustbuffer(plaintext,
261
(size_t)plaintext_length,
263
if (plaintext_capacity == 0){
264
perror("adjustbuffer");
265
plaintext_length = -1;
218
ret = gpgme_data_read(dh_plain, *new_packet + new_packet_length,
269
ret = gpgme_data_read(dh_plain, *plaintext + plaintext_length,
220
271
/* Print the data, if any */
225
277
perror("gpgme_data_read");
278
plaintext_length = -1;
228
new_packet_length += ret;
281
plaintext_length += ret;
231
/* FIXME: check characters before printing to screen so to not print
232
terminal control characters */
234
/* fprintf(stderr, "decrypted password is: "); */
235
/* fwrite(*new_packet, 1, new_packet_length, stderr); */
236
/* fprintf(stderr, "\n"); */
285
fprintf(stderr, "Decrypted password is: ");
286
for(ssize_t i = 0; i < plaintext_length; i++){
287
fprintf(stderr, "%02hhX ", (*plaintext)[i]);
289
fprintf(stderr, "\n");
294
/* Delete the GPGME cryptotext data buffer */
295
gpgme_data_release(dh_crypto);
239
297
/* Delete the GPGME plaintext data buffer */
240
298
gpgme_data_release(dh_plain);
241
return new_packet_length;
299
return plaintext_length;
244
302
static const char * safer_gnutls_strerror (int value) {
309
/* GnuTLS log function callback */
251
310
static void debuggnutls(__attribute__((unused)) int level,
252
311
const char* string){
253
fprintf(stderr, "%s", string);
312
fprintf(stderr, "GnuTLS: %s", string);
256
static int initgnutls(encrypted_session *es){
315
static int init_gnutls_global(mandos_context *mc,
316
const char *pubkeyfile,
317
const char *seckeyfile){
261
321
fprintf(stderr, "Initializing GnuTLS\n");
264
if ((ret = gnutls_global_init ())
265
!= GNUTLS_E_SUCCESS) {
266
fprintf (stderr, "global_init: %s\n", safer_gnutls_strerror(ret));
324
ret = gnutls_global_init();
325
if (ret != GNUTLS_E_SUCCESS) {
326
fprintf (stderr, "GnuTLS global_init: %s\n",
327
safer_gnutls_strerror(ret));
332
/* "Use a log level over 10 to enable all debugging options."
271
335
gnutls_global_set_log_level(11);
272
336
gnutls_global_set_log_function(debuggnutls);
275
/* openpgp credentials */
276
if ((ret = gnutls_certificate_allocate_credentials (&es->cred))
277
!= GNUTLS_E_SUCCESS) {
278
fprintf (stderr, "memory error: %s\n",
339
/* OpenPGP credentials */
340
gnutls_certificate_allocate_credentials(&mc->cred);
341
if (ret != GNUTLS_E_SUCCESS){
342
fprintf (stderr, "GnuTLS memory error: %s\n",
279
343
safer_gnutls_strerror(ret));
344
gnutls_global_deinit ();
289
354
ret = gnutls_certificate_set_openpgp_key_file
290
(es->cred, pubkeyfile, seckeyfile, GNUTLS_OPENPGP_FMT_BASE64);
355
(mc->cred, pubkeyfile, seckeyfile, GNUTLS_OPENPGP_FMT_BASE64);
291
356
if (ret != GNUTLS_E_SUCCESS) {
293
(stderr, "Error[%d] while reading the OpenPGP key pair ('%s',"
295
ret, pubkeyfile, seckeyfile);
296
fprintf(stdout, "The Error is: %s\n",
358
"Error[%d] while reading the OpenPGP key pair ('%s',"
359
" '%s')\n", ret, pubkeyfile, seckeyfile);
360
fprintf(stdout, "The GnuTLS error is: %s\n",
297
361
safer_gnutls_strerror(ret));
301
//GnuTLS server initialization
302
if ((ret = gnutls_dh_params_init (&es->dh_params))
303
!= GNUTLS_E_SUCCESS) {
304
fprintf (stderr, "Error in dh parameter initialization: %s\n",
305
safer_gnutls_strerror(ret));
309
if ((ret = gnutls_dh_params_generate2 (es->dh_params, dh_bits))
310
!= GNUTLS_E_SUCCESS) {
311
fprintf (stderr, "Error in prime generation: %s\n",
312
safer_gnutls_strerror(ret));
316
gnutls_certificate_set_dh_params (es->cred, es->dh_params);
318
// GnuTLS session creation
319
if ((ret = gnutls_init (&es->session, GNUTLS_SERVER))
320
!= GNUTLS_E_SUCCESS){
365
/* GnuTLS server initialization */
366
ret = gnutls_dh_params_init(&mc->dh_params);
367
if (ret != GNUTLS_E_SUCCESS) {
368
fprintf (stderr, "Error in GnuTLS DH parameter initialization:"
369
" %s\n", safer_gnutls_strerror(ret));
372
ret = gnutls_dh_params_generate2(mc->dh_params, mc->dh_bits);
373
if (ret != GNUTLS_E_SUCCESS) {
374
fprintf (stderr, "Error in GnuTLS prime generation: %s\n",
375
safer_gnutls_strerror(ret));
379
gnutls_certificate_set_dh_params(mc->cred, mc->dh_params);
385
gnutls_certificate_free_credentials(mc->cred);
386
gnutls_global_deinit();
391
static int init_gnutls_session(mandos_context *mc,
392
gnutls_session_t *session){
394
/* GnuTLS session creation */
395
ret = gnutls_init(session, GNUTLS_SERVER);
396
if (ret != GNUTLS_E_SUCCESS){
321
397
fprintf(stderr, "Error in GnuTLS session initialization: %s\n",
322
398
safer_gnutls_strerror(ret));
325
if ((ret = gnutls_priority_set_direct (es->session, "NORMAL", &err))
326
!= GNUTLS_E_SUCCESS) {
327
fprintf(stderr, "Syntax error at: %s\n", err);
328
fprintf(stderr, "GnuTLS error: %s\n",
329
safer_gnutls_strerror(ret));
403
ret = gnutls_priority_set_direct(*session, mc->priority, &err);
404
if (ret != GNUTLS_E_SUCCESS) {
405
fprintf(stderr, "Syntax error at: %s\n", err);
406
fprintf(stderr, "GnuTLS error: %s\n",
407
safer_gnutls_strerror(ret));
408
gnutls_deinit (*session);
333
if ((ret = gnutls_credentials_set
334
(es->session, GNUTLS_CRD_CERTIFICATE, es->cred))
335
!= GNUTLS_E_SUCCESS) {
336
fprintf(stderr, "Error setting a credentials set: %s\n",
413
ret = gnutls_credentials_set(*session, GNUTLS_CRD_CERTIFICATE,
415
if (ret != GNUTLS_E_SUCCESS) {
416
fprintf(stderr, "Error setting GnuTLS credentials: %s\n",
337
417
safer_gnutls_strerror(ret));
418
gnutls_deinit (*session);
341
422
/* ignore client certificate if any. */
342
gnutls_certificate_server_set_request (es->session,
423
gnutls_certificate_server_set_request (*session,
343
424
GNUTLS_CERT_IGNORE);
345
gnutls_dh_set_prime_bits (es->session, dh_bits);
426
gnutls_dh_set_prime_bits (*session, mc->dh_bits);
431
/* Avahi log function callback */
350
432
static void empty_log(__attribute__((unused)) AvahiLogLevel level,
351
433
__attribute__((unused)) const char *txt){}
435
/* Called when a Mandos server is found */
353
436
static int start_mandos_communication(const char *ip, uint16_t port,
354
AvahiIfIndex if_index){
437
AvahiIfIndex if_index,
356
struct sockaddr_in6 to;
357
encrypted_session es;
440
union { struct sockaddr in; struct sockaddr_in6 in6; } to;
358
441
char *buffer = NULL;
359
442
char *decrypted_buffer;
360
443
size_t buffer_length = 0;
361
444
size_t buffer_capacity = 0;
362
445
ssize_t decrypted_buffer_size;
365
448
char interface[IF_NAMESIZE];
449
gnutls_session_t session;
451
ret = init_gnutls_session (mc, &session);
368
fprintf(stderr, "Setting up a tcp connection to %s, port %d\n",
457
fprintf(stderr, "Setting up a tcp connection to %s, port %" PRIu16
372
461
tcp_sd = socket(PF_INET6, SOCK_STREAM, 0);
374
463
perror("socket");
378
if(if_indextoname((unsigned int)if_index, interface) == NULL){
468
if(if_indextoname((unsigned int)if_index, interface) == NULL){
380
469
perror("if_indextoname");
386
472
fprintf(stderr, "Binding to interface %s\n", interface);
389
475
memset(&to,0,sizeof(to)); /* Spurious warning */
390
to.sin6_family = AF_INET6;
391
ret = inet_pton(AF_INET6, ip, &to.sin6_addr);
476
to.in6.sin6_family = AF_INET6;
477
/* It would be nice to have a way to detect if we were passed an
478
IPv4 address here. Now we assume an IPv6 address. */
479
ret = inet_pton(AF_INET6, ip, &to.in6.sin6_addr);
393
481
perror("inet_pton");
397
485
fprintf(stderr, "Bad address: %s\n", ip);
400
to.sin6_port = htons(port); /* Spurious warning */
488
to.in6.sin6_port = htons(port); /* Spurious warning */
402
to.sin6_scope_id = (uint32_t)if_index;
490
to.in6.sin6_scope_id = (uint32_t)if_index;
405
fprintf(stderr, "Connection to: %s, port %d\n", ip, port);
493
fprintf(stderr, "Connection to: %s, port %" PRIu16 "\n", ip,
406
495
char addrstr[INET6_ADDRSTRLEN] = "";
407
if(inet_ntop(to.sin6_family, &(to.sin6_addr), addrstr,
496
if(inet_ntop(to.in6.sin6_family, &(to.in6.sin6_addr), addrstr,
408
497
sizeof(addrstr)) == NULL){
409
498
perror("inet_ntop");
411
500
if(strcmp(addrstr, ip) != 0){
412
fprintf(stderr, "Canonical address form: %s\n",
413
addrstr, ntohs(to.sin6_port));
501
fprintf(stderr, "Canonical address form: %s\n", addrstr);
418
ret = connect(tcp_sd, (struct sockaddr *) &to, sizeof(to));
506
ret = connect(tcp_sd, &to.in, sizeof(to));
420
508
perror("connect");
424
ret = initgnutls (&es);
512
const char *out = mandos_protocol_version;
515
size_t out_size = strlen(out);
516
ret = TEMP_FAILURE_RETRY(write(tcp_sd, out + written,
517
out_size - written));
523
written += (size_t)ret;
524
if(written < out_size){
527
if (out == mandos_protocol_version){
430
gnutls_transport_set_ptr (es.session,
431
(gnutls_transport_ptr_t) tcp_sd);
434
537
fprintf(stderr, "Establishing TLS session with %s\n", ip);
437
ret = gnutls_handshake (es.session);
540
gnutls_transport_set_ptr (session, (gnutls_transport_ptr_t) tcp_sd);
543
ret = gnutls_handshake (session);
544
} while(ret == GNUTLS_E_AGAIN or ret == GNUTLS_E_INTERRUPTED);
439
546
if (ret != GNUTLS_E_SUCCESS){
441
fprintf(stderr, "\n*** Handshake failed ***\n");
548
fprintf(stderr, "*** GnuTLS Handshake failed ***\n");
442
549
gnutls_perror (ret);
448
//Retrieve OpenPGP packet that contains the wanted password
555
/* Read OpenPGP packet that contains the wanted password */
451
558
fprintf(stderr, "Retrieving pgp encrypted password from %s\n",
473
579
case GNUTLS_E_AGAIN:
475
581
case GNUTLS_E_REHANDSHAKE:
476
ret = gnutls_handshake (es.session);
583
ret = gnutls_handshake (session);
584
} while(ret == GNUTLS_E_AGAIN or ret == GNUTLS_E_INTERRUPTED);
478
fprintf(stderr, "\n*** Handshake failed ***\n");
586
fprintf(stderr, "*** GnuTLS Re-handshake failed ***\n");
479
587
gnutls_perror (ret);
485
593
fprintf(stderr, "Unknown error while reading data from"
486
" encrypted session with mandos server\n");
594
" encrypted session with Mandos server\n");
488
gnutls_bye (es.session, GNUTLS_SHUT_RDWR);
596
gnutls_bye (session, GNUTLS_SHUT_RDWR);
492
600
buffer_length += (size_t) ret;
605
fprintf(stderr, "Closing TLS session\n");
608
gnutls_bye (session, GNUTLS_SHUT_RDWR);
496
610
if (buffer_length > 0){
497
611
decrypted_buffer_size = pgp_packet_decrypt(buffer,
499
613
&decrypted_buffer,
501
615
if (decrypted_buffer_size >= 0){
502
617
while(written < (size_t) decrypted_buffer_size){
503
618
ret = (int)fwrite (decrypted_buffer + written, 1,
504
619
(size_t)decrypted_buffer_size - written,
525
fprintf(stderr, "Closing TLS session\n");
637
/* Shutdown procedure */
529
gnutls_bye (es.session, GNUTLS_SHUT_RDWR);
532
gnutls_deinit (es.session);
533
gnutls_certificate_free_credentials (es.cred);
534
gnutls_global_deinit ();
642
gnutls_deinit (session);
538
static AvahiSimplePoll *simple_poll = NULL;
539
static AvahiServer *server = NULL;
541
static void resolve_callback(
542
AvahiSServiceResolver *r,
543
AvahiIfIndex interface,
544
AVAHI_GCC_UNUSED AvahiProtocol protocol,
545
AvahiResolverEvent event,
549
const char *host_name,
550
const AvahiAddress *address,
552
AVAHI_GCC_UNUSED AvahiStringList *txt,
553
AVAHI_GCC_UNUSED AvahiLookupResultFlags flags,
554
AVAHI_GCC_UNUSED void* userdata) {
646
static void resolve_callback(AvahiSServiceResolver *r,
647
AvahiIfIndex interface,
648
AVAHI_GCC_UNUSED AvahiProtocol protocol,
649
AvahiResolverEvent event,
653
const char *host_name,
654
const AvahiAddress *address,
656
AVAHI_GCC_UNUSED AvahiStringList *txt,
657
AVAHI_GCC_UNUSED AvahiLookupResultFlags
660
mandos_context *mc = userdata;
556
661
assert(r); /* Spurious warning */
558
663
/* Called whenever a service has been resolved successfully or
571
676
char ip[AVAHI_ADDRESS_STR_MAX];
572
677
avahi_address_snprint(ip, sizeof(ip), address);
574
fprintf(stderr, "Mandos server \"%s\" found on %s (%s) on"
575
" port %d\n", name, host_name, ip, port);
679
fprintf(stderr, "Mandos server \"%s\" found on %s (%s, %"
680
PRIu16 ") on port %d\n", name, host_name, ip,
577
int ret = start_mandos_communication(ip, port, interface);
683
int ret = start_mandos_communication(ip, port, interface, mc);
685
avahi_simple_poll_quit(mc->simple_poll);
583
689
avahi_s_service_resolver_free(r);
586
static void browse_callback(
587
AvahiSServiceBrowser *b,
588
AvahiIfIndex interface,
589
AvahiProtocol protocol,
590
AvahiBrowserEvent event,
594
AVAHI_GCC_UNUSED AvahiLookupResultFlags flags,
597
AvahiServer *s = userdata;
598
assert(b); /* Spurious warning */
600
/* Called whenever a new services becomes available on the LAN or
601
is removed from the LAN */
605
case AVAHI_BROWSER_FAILURE:
607
fprintf(stderr, "(Browser) %s\n",
608
avahi_strerror(avahi_server_errno(server)));
609
avahi_simple_poll_quit(simple_poll);
612
case AVAHI_BROWSER_NEW:
613
/* We ignore the returned resolver object. In the callback
614
function we free it. If the server is terminated before
615
the callback function is called the server will free
616
the resolver for us. */
618
if (!(avahi_s_service_resolver_new(s, interface, protocol, name,
620
AVAHI_PROTO_INET6, 0,
621
resolve_callback, s)))
622
fprintf(stderr, "Failed to resolve service '%s': %s\n", name,
623
avahi_strerror(avahi_server_errno(s)));
626
case AVAHI_BROWSER_REMOVE:
629
case AVAHI_BROWSER_ALL_FOR_NOW:
630
case AVAHI_BROWSER_CACHE_EXHAUSTED:
692
static void browse_callback( AvahiSServiceBrowser *b,
693
AvahiIfIndex interface,
694
AvahiProtocol protocol,
695
AvahiBrowserEvent event,
699
AVAHI_GCC_UNUSED AvahiLookupResultFlags
702
mandos_context *mc = userdata;
703
assert(b); /* Spurious warning */
705
/* Called whenever a new services becomes available on the LAN or
706
is removed from the LAN */
710
case AVAHI_BROWSER_FAILURE:
712
fprintf(stderr, "(Avahi browser) %s\n",
713
avahi_strerror(avahi_server_errno(mc->server)));
714
avahi_simple_poll_quit(mc->simple_poll);
717
case AVAHI_BROWSER_NEW:
718
/* We ignore the returned Avahi resolver object. In the callback
719
function we free it. If the Avahi server is terminated before
720
the callback function is called the Avahi server will free the
723
if (!(avahi_s_service_resolver_new(mc->server, interface,
724
protocol, name, type, domain,
725
AVAHI_PROTO_INET6, 0,
726
resolve_callback, mc)))
727
fprintf(stderr, "Avahi: Failed to resolve service '%s': %s\n",
728
name, avahi_strerror(avahi_server_errno(mc->server)));
731
case AVAHI_BROWSER_REMOVE:
734
case AVAHI_BROWSER_ALL_FOR_NOW:
735
case AVAHI_BROWSER_CACHE_EXHAUSTED:
737
fprintf(stderr, "No Mandos server found, still searching...\n");
635
743
/* Combines file name and path and returns the malloced new
645
memcpy(tmp, first, f_len);
753
memcpy(tmp, first, f_len); /* Spurious warning */
647
755
tmp[f_len] = '/';
649
memcpy(tmp + f_len + 1, second, s_len);
757
memcpy(tmp + f_len + 1, second, s_len); /* Spurious warning */
651
759
tmp[f_len + 1 + s_len] = '\0';
656
int main(AVAHI_GCC_UNUSED int argc, AVAHI_GCC_UNUSED char*argv[]) {
657
AvahiServerConfig config;
764
int main(int argc, char *argv[]){
658
765
AvahiSServiceBrowser *sb = NULL;
662
int returncode = EXIT_SUCCESS;
663
const char *interface = NULL;
768
int exitcode = EXIT_SUCCESS;
769
const char *interface = "eth0";
770
struct ifreq network;
774
char *connect_to = NULL;
664
775
AvahiIfIndex if_index = AVAHI_IF_UNSPEC;
665
char *connect_to = NULL;
776
const char *pubkeyfile = "pubkey.txt";
777
const char *seckeyfile = "seckey.txt";
778
mandos_context mc = { .simple_poll = NULL, .server = NULL,
779
.dh_bits = 1024, .priority = "SECURE256"};
780
bool gnutls_initalized = false;
667
debug_int = debug ? 1 : 0;
669
static struct option long_options[] = {
670
{"debug", no_argument, &debug_int, 1},
671
{"connect", required_argument, NULL, 'C'},
672
{"interface", required_argument, NULL, 'i'},
673
{"keydir", required_argument, NULL, 'd'},
674
{"seckey", required_argument, NULL, 'c'},
675
{"pubkey", required_argument, NULL, 'k'},
676
{"dh-bits", required_argument, NULL, 'D'},
679
int option_index = 0;
680
ret = getopt_long (argc, argv, "i:", long_options,
783
struct argp_option options[] = {
784
{ .name = "debug", .key = 128,
785
.doc = "Debug mode", .group = 3 },
786
{ .name = "connect", .key = 'c',
788
.doc = "Connect directly to a sepcified mandos server",
790
{ .name = "interface", .key = 'i',
792
.doc = "Interface that Avahi will conntect through",
794
{ .name = "keydir", .key = 'd',
796
.doc = "Directory where the openpgp keyring is",
798
{ .name = "seckey", .key = 's',
800
.doc = "Secret openpgp key for gnutls authentication",
802
{ .name = "pubkey", .key = 'p',
804
.doc = "Public openpgp key for gnutls authentication",
806
{ .name = "dh-bits", .key = 129,
808
.doc = "dh-bits to use in gnutls communication",
810
{ .name = "priority", .key = 130,
812
.doc = "GNUTLS priority", .group = 1 },
817
error_t parse_opt (int key, char *arg,
818
struct argp_state *state) {
819
/* Get the INPUT argument from `argp_parse', which we know is
820
a pointer to our plugin list pointer. */
842
mc.dh_bits = (unsigned int) strtol(arg, NULL, 10);
856
return ARGP_ERR_UNKNOWN;
706
dh_bits = atoi(optarg);
861
struct argp argp = { .options = options, .parser = parse_opt,
863
.doc = "Mandos client -- Get and decrypt"
864
" passwords from mandos server" };
865
ret = argp_parse (&argp, argc, argv, 0, 0, NULL);
866
if (ret == ARGP_ERR_UNKNOWN){
867
fprintf(stderr, "Unknown error while parsing arguments\n");
868
exitcode = EXIT_FAILURE;
714
debug = debug_int ? true : false;
716
873
pubkeyfile = combinepath(keydir, pubkeyfile);
717
874
if (pubkeyfile == NULL){
718
875
perror("combinepath");
722
if(interface != NULL){
723
if_index = (AvahiIfIndex) if_nametoindex(interface);
725
fprintf(stderr, "No such interface: \"%s\"\n", interface);
876
exitcode = EXIT_FAILURE;
880
seckeyfile = combinepath(keydir, seckeyfile);
881
if (seckeyfile == NULL){
882
perror("combinepath");
883
exitcode = EXIT_FAILURE;
887
ret = init_gnutls_global(&mc, pubkeyfile, seckeyfile);
889
fprintf(stderr, "init_gnutls_global failed\n");
890
exitcode = EXIT_FAILURE;
893
gnutls_initalized = true;
896
/* If the interface is down, bring it up */
898
sd = socket(PF_INET6, SOCK_DGRAM, IPPROTO_IP);
901
exitcode = EXIT_FAILURE;
904
strcpy(network.ifr_name, interface); /* Spurious warning */
905
ret = ioctl(sd, SIOCGIFFLAGS, &network);
907
perror("ioctl SIOCGIFFLAGS");
908
exitcode = EXIT_FAILURE;
911
if((network.ifr_flags & IFF_UP) == 0){
912
network.ifr_flags |= IFF_UP;
913
ret = ioctl(sd, SIOCSIFFLAGS, &network);
915
perror("ioctl SIOCSIFFLAGS");
916
exitcode = EXIT_FAILURE;
936
if_index = (AvahiIfIndex) if_nametoindex(interface);
938
fprintf(stderr, "No such interface: \"%s\"\n", interface);
730
942
if(connect_to != NULL){
733
945
char *address = strrchr(connect_to, ':');
734
946
if(address == NULL){
735
947
fprintf(stderr, "No colon in address\n");
948
exitcode = EXIT_FAILURE;
739
952
uint16_t port = (uint16_t) strtol(address+1, NULL, 10);
741
954
perror("Bad port number");
955
exitcode = EXIT_FAILURE;
745
959
address = connect_to;
746
ret = start_mandos_communication(address, port, if_index);
960
ret = start_mandos_communication(address, port, if_index, &mc);
962
exitcode = EXIT_FAILURE;
964
exitcode = EXIT_SUCCESS;
754
seckeyfile = combinepath(keydir, seckeyfile);
755
if (seckeyfile == NULL){
756
perror("combinepath");
761
970
avahi_set_log_function(empty_log);
764
/* Initialize the psuedo-RNG */
973
/* Initialize the pseudo-RNG for Avahi */
765
974
srand((unsigned int) time(NULL));
767
/* Allocate main loop object */
768
if (!(simple_poll = avahi_simple_poll_new())) {
769
fprintf(stderr, "Failed to create simple poll object.\n");
774
/* Do not publish any local records */
775
avahi_server_config_init(&config);
776
config.publish_hinfo = 0;
777
config.publish_addresses = 0;
778
config.publish_workstation = 0;
779
config.publish_domain = 0;
781
/* Allocate a new server */
782
server = avahi_server_new(avahi_simple_poll_get(simple_poll),
783
&config, NULL, NULL, &error);
785
/* Free the configuration data */
786
avahi_server_config_free(&config);
788
/* Check if creating the server object succeeded */
790
fprintf(stderr, "Failed to create server: %s\n",
976
/* Allocate main Avahi loop object */
977
mc.simple_poll = avahi_simple_poll_new();
978
if (mc.simple_poll == NULL) {
979
fprintf(stderr, "Avahi: Failed to create simple poll"
981
exitcode = EXIT_FAILURE;
986
AvahiServerConfig config;
987
/* Do not publish any local Zeroconf records */
988
avahi_server_config_init(&config);
989
config.publish_hinfo = 0;
990
config.publish_addresses = 0;
991
config.publish_workstation = 0;
992
config.publish_domain = 0;
994
/* Allocate a new server */
995
mc.server = avahi_server_new(avahi_simple_poll_get
996
(mc.simple_poll), &config, NULL,
999
/* Free the Avahi configuration data */
1000
avahi_server_config_free(&config);
1003
/* Check if creating the Avahi server object succeeded */
1004
if (mc.server == NULL) {
1005
fprintf(stderr, "Failed to create Avahi server: %s\n",
791
1006
avahi_strerror(error));
792
returncode = EXIT_FAILURE;
1007
exitcode = EXIT_FAILURE;
796
/* Create the service browser */
797
sb = avahi_s_service_browser_new(server, if_index,
1011
/* Create the Avahi service browser */
1012
sb = avahi_s_service_browser_new(mc.server, if_index,
798
1013
AVAHI_PROTO_INET6,
799
1014
"_mandos._tcp", NULL, 0,
800
browse_callback, server);
1015
browse_callback, &mc);
802
1017
fprintf(stderr, "Failed to create service browser: %s\n",
803
avahi_strerror(avahi_server_errno(server)));
804
returncode = EXIT_FAILURE;
1018
avahi_strerror(avahi_server_errno(mc.server)));
1019
exitcode = EXIT_FAILURE;
808
1023
/* Run the main loop */
811
fprintf(stderr, "Starting avahi loop search\n");
1026
fprintf(stderr, "Starting Avahi loop search\n");
814
avahi_simple_poll_loop(simple_poll);
1029
avahi_simple_poll_loop(mc.simple_poll);
819
1034
fprintf(stderr, "%s exiting\n", argv[0]);
822
1037
/* Cleanup things */
824
1039
avahi_s_service_browser_free(sb);
827
avahi_server_free(server);
1041
if (mc.server != NULL)
1042
avahi_server_free(mc.server);
830
avahi_simple_poll_free(simple_poll);
1044
if (mc.simple_poll != NULL)
1045
avahi_simple_poll_free(mc.simple_poll);
831
1046
free(pubkeyfile);
832
1047
free(seckeyfile);
1049
if (gnutls_initalized){
1050
gnutls_certificate_free_credentials(mc.cred);
1051
gnutls_global_deinit ();