32
33
#define _LARGEFILE_SOURCE
33
34
#define _FILE_OFFSET_BITS 64
39
#include <net/if.h> /* if_nametoindex */
40
#include <sys/ioctl.h> // ioctl, ifreq, SIOCGIFFLAGS, IFF_UP, SIOCSIFFLAGS
41
#include <net/if.h> // ioctl, ifreq, SIOCGIFFLAGS, IFF_UP, SIOCSIFFLAGS
36
#define _GNU_SOURCE /* TEMP_FAILURE_RETRY(), asprintf() */
38
#include <stdio.h> /* fprintf(), stderr, fwrite(),
39
stdout, ferror(), sscanf(),
41
#include <stdint.h> /* uint16_t, uint32_t */
42
#include <stddef.h> /* NULL, size_t, ssize_t */
43
#include <stdlib.h> /* free(), EXIT_SUCCESS, EXIT_FAILURE,
45
#include <stdbool.h> /* bool, true */
46
#include <string.h> /* memset(), strcmp(), strlen(),
47
strerror(), asprintf(), strcpy() */
48
#include <sys/ioctl.h> /* ioctl */
49
#include <sys/types.h> /* socket(), inet_pton(), sockaddr,
50
sockaddr_in6, PF_INET6,
51
SOCK_STREAM, INET6_ADDRSTRLEN,
52
uid_t, gid_t, open(), opendir(),
54
#include <sys/stat.h> /* open() */
55
#include <sys/socket.h> /* socket(), struct sockaddr_in6,
56
struct in6_addr, inet_pton(),
58
#include <fcntl.h> /* open() */
59
#include <dirent.h> /* opendir(), struct dirent, readdir()
61
#include <inttypes.h> /* PRIu16, intmax_t, SCNdMAX */
62
#include <assert.h> /* assert() */
63
#include <errno.h> /* perror(), errno */
64
#include <time.h> /* nanosleep(), time() */
65
#include <net/if.h> /* ioctl, ifreq, SIOCGIFFLAGS, IFF_UP,
66
SIOCSIFFLAGS, if_indextoname(),
67
if_nametoindex(), IF_NAMESIZE */
68
#include <netinet/in.h>
69
#include <unistd.h> /* close(), SEEK_SET, off_t, write(),
70
getuid(), getgid(), setuid(),
72
#include <arpa/inet.h> /* inet_pton(), htons */
73
#include <iso646.h> /* not, and, or */
74
#include <argp.h> /* struct argp_option, error_t, struct
75
argp_state, struct argp,
76
argp_parse(), ARGP_KEY_ARG,
77
ARGP_KEY_END, ARGP_ERR_UNKNOWN */
78
#include <sys/klog.h> /* klogctl() */
81
/* All Avahi types, constants and functions
43
84
#include <avahi-core/core.h>
44
85
#include <avahi-core/lookup.h>
45
86
#include <avahi-core/log.h>
47
88
#include <avahi-common/malloc.h>
48
89
#include <avahi-common/error.h>
51
#include <sys/types.h> /* socket(), inet_pton() */
52
#include <sys/socket.h> /* socket(), struct sockaddr_in6,
53
struct in6_addr, inet_pton() */
54
#include <gnutls/gnutls.h> /* All GnuTLS stuff */
55
#include <gnutls/openpgp.h> /* GnuTLS with openpgp stuff */
57
#include <unistd.h> /* close() */
58
#include <netinet/in.h>
59
#include <stdbool.h> /* true */
60
#include <string.h> /* memset */
61
#include <arpa/inet.h> /* inet_pton() */
62
#include <iso646.h> /* not */
65
#include <errno.h> /* perror() */
92
#include <gnutls/gnutls.h> /* All GnuTLS types, constants and
95
init_gnutls_session(),
97
#include <gnutls/openpgp.h>
98
/* gnutls_certificate_set_openpgp_key_file(),
99
GNUTLS_OPENPGP_FMT_BASE64 */
102
#include <gpgme.h> /* All GPGME types, constants and
105
GPGME_PROTOCOL_OpenPGP,
71
108
#define BUFFER_SIZE 256
74
static const char *certdir = "/conf/conf.d/mandos";
75
static const char *certfile = "openpgp-client.txt";
76
static const char *certkey = "openpgp-client-key.txt";
110
#define PATHDIR "/conf/conf.d/mandos"
111
#define SECKEY "seckey.txt"
112
#define PUBKEY "pubkey.txt"
78
114
bool debug = false;
115
static const char mandos_protocol_version[] = "1";
116
const char *argp_program_version = "mandos-client " VERSION;
117
const char *argp_program_bug_address = "<mandos@fukt.bsnet.se>";
119
/* Used for passing in values through the Avahi callback functions */
81
121
AvahiSimplePoll *simple_poll;
82
122
AvahiServer *server;
83
123
gnutls_certificate_credentials_t cred;
84
124
unsigned int dh_bits;
125
gnutls_dh_params_t dh_params;
85
126
const char *priority;
88
static ssize_t pgp_packet_decrypt (char *packet, size_t packet_size,
91
gpgme_data_t dh_crypto, dh_plain;
131
* Make room in "buffer" for at least BUFFER_SIZE additional bytes.
132
* "buffer_capacity" is how much is currently allocated,
133
* "buffer_length" is how much is already used.
135
size_t adjustbuffer(char **buffer, size_t buffer_length,
136
size_t buffer_capacity){
137
if(buffer_length + BUFFER_SIZE > buffer_capacity){
138
*buffer = realloc(*buffer, buffer_capacity + BUFFER_SIZE);
142
buffer_capacity += BUFFER_SIZE;
144
return buffer_capacity;
150
static bool init_gpgme(mandos_context *mc, const char *seckey,
151
const char *pubkey, const char *tempdir){
95
ssize_t new_packet_capacity = 0;
96
ssize_t new_packet_length = 0;
97
154
gpgme_engine_info_t engine_info;
100
fprintf(stderr, "Trying to decrypt OpenPGP packet\n");
158
* Helper function to insert pub and seckey to the engine keyring.
160
bool import_key(const char *filename){
162
gpgme_data_t pgp_data;
164
fd = (int)TEMP_FAILURE_RETRY(open(filename, O_RDONLY));
170
rc = gpgme_data_new_from_fd(&pgp_data, fd);
171
if(rc != GPG_ERR_NO_ERROR){
172
fprintf(stderr, "bad gpgme_data_new_from_fd: %s: %s\n",
173
gpgme_strsource(rc), gpgme_strerror(rc));
177
rc = gpgme_op_import(mc->ctx, pgp_data);
178
if(rc != GPG_ERR_NO_ERROR){
179
fprintf(stderr, "bad gpgme_op_import: %s: %s\n",
180
gpgme_strsource(rc), gpgme_strerror(rc));
184
ret = (int)TEMP_FAILURE_RETRY(close(fd));
188
gpgme_data_release(pgp_data);
193
fprintf(stderr, "Initialize gpgme\n");
104
197
gpgme_check_version(NULL);
105
198
rc = gpgme_engine_check_version(GPGME_PROTOCOL_OpenPGP);
106
if (rc != GPG_ERR_NO_ERROR){
199
if(rc != GPG_ERR_NO_ERROR){
107
200
fprintf(stderr, "bad gpgme_engine_check_version: %s: %s\n",
108
201
gpgme_strsource(rc), gpgme_strerror(rc));
112
/* Set GPGME home directory */
113
rc = gpgme_get_engine_info (&engine_info);
114
if (rc != GPG_ERR_NO_ERROR){
205
/* Set GPGME home directory for the OpenPGP engine only */
206
rc = gpgme_get_engine_info(&engine_info);
207
if(rc != GPG_ERR_NO_ERROR){
115
208
fprintf(stderr, "bad gpgme_get_engine_info: %s: %s\n",
116
209
gpgme_strsource(rc), gpgme_strerror(rc));
119
212
while(engine_info != NULL){
120
213
if(engine_info->protocol == GPGME_PROTOCOL_OpenPGP){
121
214
gpgme_set_engine_info(GPGME_PROTOCOL_OpenPGP,
122
engine_info->file_name, homedir);
215
engine_info->file_name, tempdir);
125
218
engine_info = engine_info->next;
127
220
if(engine_info == NULL){
128
fprintf(stderr, "Could not set home dir to %s\n", homedir);
132
/* Create new GPGME data buffer from packet buffer */
133
rc = gpgme_data_new_from_mem(&dh_crypto, packet, packet_size, 0);
134
if (rc != GPG_ERR_NO_ERROR){
221
fprintf(stderr, "Could not set GPGME home dir to %s\n", tempdir);
225
/* Create new GPGME "context" */
226
rc = gpgme_new(&(mc->ctx));
227
if(rc != GPG_ERR_NO_ERROR){
228
fprintf(stderr, "bad gpgme_new: %s: %s\n",
229
gpgme_strsource(rc), gpgme_strerror(rc));
233
if(not import_key(pubkey) or not import_key(seckey)){
241
* Decrypt OpenPGP data.
242
* Returns -1 on error
244
static ssize_t pgp_packet_decrypt(const mandos_context *mc,
245
const char *cryptotext,
248
gpgme_data_t dh_crypto, dh_plain;
251
size_t plaintext_capacity = 0;
252
ssize_t plaintext_length = 0;
255
fprintf(stderr, "Trying to decrypt OpenPGP data\n");
258
/* Create new GPGME data buffer from memory cryptotext */
259
rc = gpgme_data_new_from_mem(&dh_crypto, cryptotext, crypto_size,
261
if(rc != GPG_ERR_NO_ERROR){
135
262
fprintf(stderr, "bad gpgme_data_new_from_mem: %s: %s\n",
136
263
gpgme_strsource(rc), gpgme_strerror(rc));
140
267
/* Create new empty GPGME data buffer for the plaintext */
141
268
rc = gpgme_data_new(&dh_plain);
142
if (rc != GPG_ERR_NO_ERROR){
269
if(rc != GPG_ERR_NO_ERROR){
143
270
fprintf(stderr, "bad gpgme_data_new: %s: %s\n",
144
271
gpgme_strsource(rc), gpgme_strerror(rc));
148
/* Create new GPGME "context" */
149
rc = gpgme_new(&ctx);
150
if (rc != GPG_ERR_NO_ERROR){
151
fprintf(stderr, "bad gpgme_new: %s: %s\n",
152
gpgme_strsource(rc), gpgme_strerror(rc));
156
/* Decrypt data from the FILE pointer to the plaintext data
158
rc = gpgme_op_decrypt(ctx, dh_crypto, dh_plain);
159
if (rc != GPG_ERR_NO_ERROR){
272
gpgme_data_release(dh_crypto);
276
/* Decrypt data from the cryptotext data buffer to the plaintext
278
rc = gpgme_op_decrypt(mc->ctx, dh_crypto, dh_plain);
279
if(rc != GPG_ERR_NO_ERROR){
160
280
fprintf(stderr, "bad gpgme_op_decrypt: %s: %s\n",
161
281
gpgme_strsource(rc), gpgme_strerror(rc));
282
plaintext_length = -1;
284
gpgme_decrypt_result_t result;
285
result = gpgme_op_decrypt_result(mc->ctx);
287
fprintf(stderr, "gpgme_op_decrypt_result failed\n");
289
fprintf(stderr, "Unsupported algorithm: %s\n",
290
result->unsupported_algorithm);
291
fprintf(stderr, "Wrong key usage: %u\n",
292
result->wrong_key_usage);
293
if(result->file_name != NULL){
294
fprintf(stderr, "File name: %s\n", result->file_name);
296
gpgme_recipient_t recipient;
297
recipient = result->recipients;
299
while(recipient != NULL){
300
fprintf(stderr, "Public key algorithm: %s\n",
301
gpgme_pubkey_algo_name(recipient->pubkey_algo));
302
fprintf(stderr, "Key ID: %s\n", recipient->keyid);
303
fprintf(stderr, "Secret key available: %s\n",
304
recipient->status == GPG_ERR_NO_SECKEY
306
recipient = recipient->next;
166
fprintf(stderr, "Decryption of OpenPGP packet succeeded\n");
170
gpgme_decrypt_result_t result;
171
result = gpgme_op_decrypt_result(ctx);
173
fprintf(stderr, "gpgme_op_decrypt_result failed\n");
175
fprintf(stderr, "Unsupported algorithm: %s\n",
176
result->unsupported_algorithm);
177
fprintf(stderr, "Wrong key usage: %d\n",
178
result->wrong_key_usage);
179
if(result->file_name != NULL){
180
fprintf(stderr, "File name: %s\n", result->file_name);
182
gpgme_recipient_t recipient;
183
recipient = result->recipients;
185
while(recipient != NULL){
186
fprintf(stderr, "Public key algorithm: %s\n",
187
gpgme_pubkey_algo_name(recipient->pubkey_algo));
188
fprintf(stderr, "Key ID: %s\n", recipient->keyid);
189
fprintf(stderr, "Secret key available: %s\n",
190
recipient->status == GPG_ERR_NO_SECKEY
192
recipient = recipient->next;
198
/* Delete the GPGME FILE pointer cryptotext data buffer */
199
gpgme_data_release(dh_crypto);
315
fprintf(stderr, "Decryption of OpenPGP data succeeded\n");
201
318
/* Seek back to the beginning of the GPGME plaintext data buffer */
202
if (gpgme_data_seek(dh_plain, (off_t) 0, SEEK_SET) == -1){
203
perror("pgpme_data_seek");
319
if(gpgme_data_seek(dh_plain, (off_t)0, SEEK_SET) == -1){
320
perror("gpgme_data_seek");
321
plaintext_length = -1;
208
if (new_packet_length + BUFFER_SIZE > new_packet_capacity){
209
*new_packet = realloc(*new_packet,
210
(unsigned int)new_packet_capacity
212
if (*new_packet == NULL){
216
new_packet_capacity += BUFFER_SIZE;
327
plaintext_capacity = adjustbuffer(plaintext,
328
(size_t)plaintext_length,
330
if(plaintext_capacity == 0){
331
perror("adjustbuffer");
332
plaintext_length = -1;
219
ret = gpgme_data_read(dh_plain, *new_packet + new_packet_length,
336
ret = gpgme_data_read(dh_plain, *plaintext + plaintext_length,
221
338
/* Print the data, if any */
226
344
perror("gpgme_data_read");
229
new_packet_length += ret;
232
/* FIXME: check characters before printing to screen so to not print
233
terminal control characters */
235
/* fprintf(stderr, "decrypted password is: "); */
236
/* fwrite(*new_packet, 1, new_packet_length, stderr); */
237
/* fprintf(stderr, "\n"); */
345
plaintext_length = -1;
348
plaintext_length += ret;
352
fprintf(stderr, "Decrypted password is: ");
353
for(ssize_t i = 0; i < plaintext_length; i++){
354
fprintf(stderr, "%02hhX ", (*plaintext)[i]);
356
fprintf(stderr, "\n");
361
/* Delete the GPGME cryptotext data buffer */
362
gpgme_data_release(dh_crypto);
240
364
/* Delete the GPGME plaintext data buffer */
241
365
gpgme_data_release(dh_plain);
242
return new_packet_length;
366
return plaintext_length;
245
static const char * safer_gnutls_strerror (int value) {
246
const char *ret = gnutls_strerror (value);
369
static const char * safer_gnutls_strerror(int value) {
370
const char *ret = gnutls_strerror(value); /* Spurious warning from
371
-Wunreachable-code */
248
373
ret = "(unknown)";
377
/* GnuTLS log function callback */
252
378
static void debuggnutls(__attribute__((unused)) int level,
253
379
const char* string){
254
fprintf(stderr, "%s", string);
380
fprintf(stderr, "GnuTLS: %s", string);
257
static int initgnutls(mandos_context *mc){
383
static int init_gnutls_global(mandos_context *mc,
384
const char *pubkeyfilename,
385
const char *seckeyfilename){
262
389
fprintf(stderr, "Initializing GnuTLS\n");
265
if ((ret = gnutls_global_init ())
266
!= GNUTLS_E_SUCCESS) {
267
fprintf (stderr, "global_init: %s\n", safer_gnutls_strerror(ret));
392
ret = gnutls_global_init();
393
if(ret != GNUTLS_E_SUCCESS) {
394
fprintf(stderr, "GnuTLS global_init: %s\n",
395
safer_gnutls_strerror(ret));
400
/* "Use a log level over 10 to enable all debugging options."
272
403
gnutls_global_set_log_level(11);
273
404
gnutls_global_set_log_function(debuggnutls);
276
/* openpgp credentials */
277
if ((ret = gnutls_certificate_allocate_credentials (&es->cred))
278
!= GNUTLS_E_SUCCESS) {
279
fprintf (stderr, "memory error: %s\n",
280
safer_gnutls_strerror(ret));
407
/* OpenPGP credentials */
408
gnutls_certificate_allocate_credentials(&mc->cred);
409
if(ret != GNUTLS_E_SUCCESS){
410
fprintf(stderr, "GnuTLS memory error: %s\n", /* Spurious warning
414
safer_gnutls_strerror(ret));
415
gnutls_global_deinit();
285
fprintf(stderr, "Attempting to use OpenPGP certificate %s"
286
" and keyfile %s as GnuTLS credentials\n", certfile,
420
fprintf(stderr, "Attempting to use OpenPGP public key %s and"
421
" secret key %s as GnuTLS credentials\n", pubkeyfilename,
290
425
ret = gnutls_certificate_set_openpgp_key_file
291
(es->cred, certfile, certkey, GNUTLS_OPENPGP_FMT_BASE64);
292
if (ret != GNUTLS_E_SUCCESS) {
294
(stderr, "Error[%d] while reading the OpenPGP key pair ('%s',"
296
ret, certfile, certkey);
297
fprintf(stdout, "The Error is: %s\n",
298
safer_gnutls_strerror(ret));
302
//GnuTLS server initialization
303
if ((ret = gnutls_dh_params_init (&es->dh_params))
304
!= GNUTLS_E_SUCCESS) {
305
fprintf (stderr, "Error in dh parameter initialization: %s\n",
306
safer_gnutls_strerror(ret));
310
if ((ret = gnutls_dh_params_generate2 (es->dh_params, DH_BITS))
311
!= GNUTLS_E_SUCCESS) {
312
fprintf (stderr, "Error in prime generation: %s\n",
313
safer_gnutls_strerror(ret));
317
gnutls_certificate_set_dh_params (es->cred, es->dh_params);
319
// GnuTLS session creation
320
if ((ret = gnutls_init (&es->session, GNUTLS_SERVER))
321
!= GNUTLS_E_SUCCESS){
426
(mc->cred, pubkeyfilename, seckeyfilename,
427
GNUTLS_OPENPGP_FMT_BASE64);
428
if(ret != GNUTLS_E_SUCCESS) {
430
"Error[%d] while reading the OpenPGP key pair ('%s',"
431
" '%s')\n", ret, pubkeyfilename, seckeyfilename);
432
fprintf(stderr, "The GnuTLS error is: %s\n",
433
safer_gnutls_strerror(ret));
437
/* GnuTLS server initialization */
438
ret = gnutls_dh_params_init(&mc->dh_params);
439
if(ret != GNUTLS_E_SUCCESS) {
440
fprintf(stderr, "Error in GnuTLS DH parameter initialization:"
441
" %s\n", safer_gnutls_strerror(ret));
444
ret = gnutls_dh_params_generate2(mc->dh_params, mc->dh_bits);
445
if(ret != GNUTLS_E_SUCCESS) {
446
fprintf(stderr, "Error in GnuTLS prime generation: %s\n",
447
safer_gnutls_strerror(ret));
451
gnutls_certificate_set_dh_params(mc->cred, mc->dh_params);
457
gnutls_certificate_free_credentials(mc->cred);
458
gnutls_global_deinit();
459
gnutls_dh_params_deinit(mc->dh_params);
463
static int init_gnutls_session(mandos_context *mc,
464
gnutls_session_t *session){
466
/* GnuTLS session creation */
467
ret = gnutls_init(session, GNUTLS_SERVER);
468
if(ret != GNUTLS_E_SUCCESS){
322
469
fprintf(stderr, "Error in GnuTLS session initialization: %s\n",
323
470
safer_gnutls_strerror(ret));
326
if ((ret = gnutls_priority_set_direct (es->session, mc->priority, &err))
327
!= GNUTLS_E_SUCCESS) {
328
fprintf(stderr, "Syntax error at: %s\n", err);
329
fprintf(stderr, "GnuTLS error: %s\n",
330
safer_gnutls_strerror(ret));
475
ret = gnutls_priority_set_direct(*session, mc->priority, &err);
476
if(ret != GNUTLS_E_SUCCESS) {
477
fprintf(stderr, "Syntax error at: %s\n", err);
478
fprintf(stderr, "GnuTLS error: %s\n",
479
safer_gnutls_strerror(ret));
480
gnutls_deinit(*session);
334
if ((ret = gnutls_credentials_set
335
(es->session, GNUTLS_CRD_CERTIFICATE, es->cred))
336
!= GNUTLS_E_SUCCESS) {
337
fprintf(stderr, "Error setting a credentials set: %s\n",
485
ret = gnutls_credentials_set(*session, GNUTLS_CRD_CERTIFICATE,
487
if(ret != GNUTLS_E_SUCCESS) {
488
fprintf(stderr, "Error setting GnuTLS credentials: %s\n",
338
489
safer_gnutls_strerror(ret));
490
gnutls_deinit(*session);
342
494
/* ignore client certificate if any. */
343
gnutls_certificate_server_set_request (es->session,
495
gnutls_certificate_server_set_request(*session,
346
gnutls_dh_set_prime_bits (es->session, DH_BITS);
498
gnutls_dh_set_prime_bits(*session, mc->dh_bits);
503
/* Avahi log function callback */
351
504
static void empty_log(__attribute__((unused)) AvahiLogLevel level,
352
505
__attribute__((unused)) const char *txt){}
507
/* Called when a Mandos server is found */
354
508
static int start_mandos_communication(const char *ip, uint16_t port,
355
509
AvahiIfIndex if_index,
356
510
mandos_context *mc){
358
struct sockaddr_in6 to;
359
encrypted_session es;
513
union { struct sockaddr in; struct sockaddr_in6 in6; } to;
360
514
char *buffer = NULL;
361
515
char *decrypted_buffer;
362
516
size_t buffer_length = 0;
363
517
size_t buffer_capacity = 0;
364
518
ssize_t decrypted_buffer_size;
367
521
char interface[IF_NAMESIZE];
522
gnutls_session_t session;
524
ret = init_gnutls_session(mc, &session);
370
fprintf(stderr, "Setting up a tcp connection to %s, port %d\n",
530
fprintf(stderr, "Setting up a tcp connection to %s, port %" PRIu16
374
534
tcp_sd = socket(PF_INET6, SOCK_STREAM, 0);
376
536
perror("socket");
381
541
if(if_indextoname((unsigned int)if_index, interface) == NULL){
383
perror("if_indextoname");
542
perror("if_indextoname");
388
545
fprintf(stderr, "Binding to interface %s\n", interface);
391
memset(&to,0,sizeof(to)); /* Spurious warning */
392
to.sin6_family = AF_INET6;
393
ret = inet_pton(AF_INET6, ip, &to.sin6_addr);
548
memset(&to, 0, sizeof(to));
549
to.in6.sin6_family = AF_INET6;
550
/* It would be nice to have a way to detect if we were passed an
551
IPv4 address here. Now we assume an IPv6 address. */
552
ret = inet_pton(AF_INET6, ip, &to.in6.sin6_addr);
395
554
perror("inet_pton");
399
558
fprintf(stderr, "Bad address: %s\n", ip);
402
to.sin6_port = htons(port); /* Spurious warning */
561
to.in6.sin6_port = htons(port); /* Spurious warnings from
563
-Wunreachable-code */
404
to.sin6_scope_id = (uint32_t)if_index;
565
to.in6.sin6_scope_id = (uint32_t)if_index;
407
fprintf(stderr, "Connection to: %s, port %d\n", ip, port);
408
/* char addrstr[INET6_ADDRSTRLEN]; */
409
/* if(inet_ntop(to.sin6_family, &(to.sin6_addr), addrstr, */
410
/* sizeof(addrstr)) == NULL){ */
411
/* perror("inet_ntop"); */
413
/* fprintf(stderr, "Really connecting to: %s, port %d\n", */
414
/* addrstr, ntohs(to.sin6_port)); */
568
fprintf(stderr, "Connection to: %s, port %" PRIu16 "\n", ip,
570
char addrstr[INET6_ADDRSTRLEN] = "";
571
if(inet_ntop(to.in6.sin6_family, &(to.in6.sin6_addr), addrstr,
572
sizeof(addrstr)) == NULL){
575
if(strcmp(addrstr, ip) != 0){
576
fprintf(stderr, "Canonical address form: %s\n", addrstr);
418
ret = connect(tcp_sd, (struct sockaddr *) &to, sizeof(to));
581
ret = connect(tcp_sd, &to.in, sizeof(to));
420
583
perror("connect");
424
ret = initgnutls (&es);
587
const char *out = mandos_protocol_version;
590
size_t out_size = strlen(out);
591
ret = (int)TEMP_FAILURE_RETRY(write(tcp_sd, out + written,
592
out_size - written));
598
written += (size_t)ret;
599
if(written < out_size){
602
if(out == mandos_protocol_version){
430
gnutls_transport_set_ptr (es.session,
431
(gnutls_transport_ptr_t) tcp_sd);
434
612
fprintf(stderr, "Establishing TLS session with %s\n", ip);
437
ret = gnutls_handshake (es.session);
439
if (ret != GNUTLS_E_SUCCESS){
615
gnutls_transport_set_ptr(session, (gnutls_transport_ptr_t) tcp_sd);
618
ret = gnutls_handshake(session);
619
} while(ret == GNUTLS_E_AGAIN or ret == GNUTLS_E_INTERRUPTED);
621
if(ret != GNUTLS_E_SUCCESS){
441
fprintf(stderr, "\n*** Handshake failed ***\n");
623
fprintf(stderr, "*** GnuTLS Handshake failed ***\n");
448
//Retrieve OpenPGP packet that contains the wanted password
630
/* Read OpenPGP packet that contains the wanted password */
451
633
fprintf(stderr, "Retrieving pgp encrypted password from %s\n",
456
if (buffer_length + BUFFER_SIZE > buffer_capacity){
457
buffer = realloc(buffer, buffer_capacity + BUFFER_SIZE);
462
buffer_capacity += BUFFER_SIZE;
638
buffer_capacity = adjustbuffer(&buffer, buffer_length,
640
if(buffer_capacity == 0){
641
perror("adjustbuffer");
465
ret = gnutls_record_recv
466
(es.session, buffer+buffer_length, BUFFER_SIZE);
646
sret = gnutls_record_recv(session, buffer+buffer_length,
472
653
case GNUTLS_E_INTERRUPTED:
473
654
case GNUTLS_E_AGAIN:
475
656
case GNUTLS_E_REHANDSHAKE:
476
ret = gnutls_handshake (es.session);
478
fprintf(stderr, "\n*** Handshake failed ***\n");
658
ret = gnutls_handshake(session);
659
} while(ret == GNUTLS_E_AGAIN or ret == GNUTLS_E_INTERRUPTED);
661
fprintf(stderr, "*** GnuTLS Re-handshake failed ***\n");
485
668
fprintf(stderr, "Unknown error while reading data from"
486
" encrypted session with mandos server\n");
669
" encrypted session with Mandos server\n");
488
gnutls_bye (es.session, GNUTLS_SHUT_RDWR);
671
gnutls_bye(session, GNUTLS_SHUT_RDWR);
492
buffer_length += (size_t) ret;
675
buffer_length += (size_t) sret;
496
if (buffer_length > 0){
497
decrypted_buffer_size = pgp_packet_decrypt(buffer,
680
fprintf(stderr, "Closing TLS session\n");
683
gnutls_bye(session, GNUTLS_SHUT_RDWR);
685
if(buffer_length > 0){
686
decrypted_buffer_size = pgp_packet_decrypt(mc, buffer,
501
if (decrypted_buffer_size >= 0){
689
if(decrypted_buffer_size >= 0){
502
691
while(written < (size_t) decrypted_buffer_size){
503
ret = (int)fwrite (decrypted_buffer + written, 1,
504
(size_t)decrypted_buffer_size - written,
692
ret = (int)fwrite(decrypted_buffer + written, 1,
693
(size_t)decrypted_buffer_size - written,
506
695
if(ret == 0 and ferror(stdout)){
508
697
fprintf(stderr, "Error writing encrypted data: %s\n",
586
775
const char *name,
587
776
const char *type,
588
777
const char *domain,
589
AVAHI_GCC_UNUSED AvahiLookupResultFlags flags,
778
AVAHI_GCC_UNUSED AvahiLookupResultFlags
590
780
void* userdata) {
591
781
mandos_context *mc = userdata;
592
assert(b); /* Spurious warning */
594
784
/* Called whenever a new services becomes available on the LAN or
595
785
is removed from the LAN */
599
789
case AVAHI_BROWSER_FAILURE:
601
fprintf(stderr, "(Browser) %s\n",
791
fprintf(stderr, "(Avahi browser) %s\n",
602
792
avahi_strerror(avahi_server_errno(mc->server)));
603
793
avahi_simple_poll_quit(mc->simple_poll);
606
796
case AVAHI_BROWSER_NEW:
607
/* We ignore the returned resolver object. In the callback
608
function we free it. If the server is terminated before
609
the callback function is called the server will free
610
the resolver for us. */
612
if (!(avahi_s_service_resolver_new(mc->server, interface, protocol, name,
797
/* We ignore the returned Avahi resolver object. In the callback
798
function we free it. If the Avahi server is terminated before
799
the callback function is called the Avahi server will free the
802
if(!(avahi_s_service_resolver_new(mc->server, interface,
803
protocol, name, type, domain,
614
804
AVAHI_PROTO_INET6, 0,
615
805
resolve_callback, mc)))
616
fprintf(stderr, "Failed to resolve service '%s': %s\n", name,
617
avahi_strerror(avahi_server_errno(s)));
806
fprintf(stderr, "Avahi: Failed to resolve service '%s': %s\n",
807
name, avahi_strerror(avahi_server_errno(mc->server)));
620
810
case AVAHI_BROWSER_REMOVE:
623
813
case AVAHI_BROWSER_ALL_FOR_NOW:
624
814
case AVAHI_BROWSER_CACHE_EXHAUSTED:
816
fprintf(stderr, "No Mandos server found, still searching...\n");
629
/* Combines file name and path and returns the malloced new
630
string. some sane checks could/should be added */
631
static const char *combinepath(const char *first, const char *second){
632
size_t f_len = strlen(first);
633
size_t s_len = strlen(second);
634
char *tmp = malloc(f_len + s_len + 2);
639
memcpy(tmp, first, f_len);
643
memcpy(tmp + f_len + 1, second, s_len);
645
tmp[f_len + 1 + s_len] = '\0';
650
int main(AVAHI_GCC_UNUSED int argc, AVAHI_GCC_UNUSED char*argv[]) {
651
AvahiServerConfig config;
822
int main(int argc, char *argv[]){
652
823
AvahiSServiceBrowser *sb = NULL;
655
int returncode = EXIT_SUCCESS;
828
int exitcode = EXIT_SUCCESS;
656
829
const char *interface = "eth0";
657
830
struct ifreq network;
659
834
char *connect_to = NULL;
835
char tempdir[] = "/tmp/mandosXXXXXX";
836
bool tempdir_created = false;
660
837
AvahiIfIndex if_index = AVAHI_IF_UNSPEC;
838
const char *seckey = PATHDIR "/" SECKEY;
839
const char *pubkey = PATHDIR "/" PUBKEY;
661
841
mandos_context mc = { .simple_poll = NULL, .server = NULL,
662
.dh_bits = 2048, .priority = "SECURE256"};
665
static struct option long_options[] = {
666
{"debug", no_argument, (int *)&debug, 1},
667
{"connect", required_argument, 0, 'C'},
668
{"interface", required_argument, 0, 'i'},
669
{"certdir", required_argument, 0, 'd'},
670
{"certkey", required_argument, 0, 'c'},
671
{"certfile", required_argument, 0, 'k'},
672
{"dh_bits", required_argument, 0, 'D'},
673
{"priority", required_argument, 0, 'p'},
676
int option_index = 0;
677
ret = getopt_long (argc, argv, "i:", long_options,
706
tmp = strtol(optarg, NULL, 10);
707
if (errno == ERANGE){
715
mc.priority = optarg;
722
certfile = combinepath(certdir, certfile);
723
if (certfile == NULL){
724
perror("combinepath");
725
returncode = EXIT_FAILURE;
729
certkey = combinepath(certdir, certkey);
730
if (certkey == NULL){
731
perror("combinepath");
732
returncode = EXIT_FAILURE;
842
.dh_bits = 1024, .priority = "SECURE256"
843
":!CTYPE-X.509:+CTYPE-OPENPGP" };
844
bool gnutls_initialized = false;
845
bool gpgme_initialized = false;
849
struct argp_option options[] = {
850
{ .name = "debug", .key = 128,
851
.doc = "Debug mode", .group = 3 },
852
{ .name = "connect", .key = 'c',
853
.arg = "ADDRESS:PORT",
854
.doc = "Connect directly to a specific Mandos server",
856
{ .name = "interface", .key = 'i',
858
.doc = "Interface that will be used to search for Mandos"
861
{ .name = "seckey", .key = 's',
863
.doc = "OpenPGP secret key file base name",
865
{ .name = "pubkey", .key = 'p',
867
.doc = "OpenPGP public key file base name",
869
{ .name = "dh-bits", .key = 129,
871
.doc = "Bit length of the prime number used in the"
872
" Diffie-Hellman key exchange",
874
{ .name = "priority", .key = 130,
876
.doc = "GnuTLS priority string for the TLS handshake",
878
{ .name = "delay", .key = 131,
880
.doc = "Maximum delay to wait for interface startup",
885
error_t parse_opt(int key, char *arg,
886
struct argp_state *state) {
888
case 128: /* --debug */
891
case 'c': /* --connect */
894
case 'i': /* --interface */
897
case 's': /* --seckey */
900
case 'p': /* --pubkey */
903
case 129: /* --dh-bits */
904
ret = sscanf(arg, "%" SCNdMAX "%n", &tmpmax, &numchars);
905
if(ret < 1 or tmpmax != (typeof(mc.dh_bits))tmpmax
906
or arg[numchars] != '\0'){
907
fprintf(stderr, "Bad number of DH bits\n");
910
mc.dh_bits = (typeof(mc.dh_bits))tmpmax;
912
case 130: /* --priority */
915
case 131: /* --delay */
916
ret = sscanf(arg, "%lf%n", &delay, &numchars);
917
if(ret < 1 or arg[numchars] != '\0'){
918
fprintf(stderr, "Bad delay\n");
927
return ARGP_ERR_UNKNOWN;
932
struct argp argp = { .options = options, .parser = parse_opt,
934
.doc = "Mandos client -- Get and decrypt"
935
" passwords from a Mandos server" };
936
ret = argp_parse(&argp, argc, argv, 0, 0, NULL);
937
if(ret == ARGP_ERR_UNKNOWN){
938
fprintf(stderr, "Unknown error while parsing arguments\n");
939
exitcode = EXIT_FAILURE;
944
/* If the interface is down, bring it up */
946
/* Lower kernel loglevel to KERN_NOTICE to avoid KERN_INFO
947
messages to mess up the prompt */
948
ret = klogctl(8, NULL, 5);
953
sd = socket(PF_INET6, SOCK_DGRAM, IPPROTO_IP);
956
exitcode = EXIT_FAILURE;
957
ret = klogctl(7, NULL, 0);
963
strcpy(network.ifr_name, interface);
964
ret = ioctl(sd, SIOCGIFFLAGS, &network);
966
perror("ioctl SIOCGIFFLAGS");
967
ret = klogctl(7, NULL, 0);
971
exitcode = EXIT_FAILURE;
974
if((network.ifr_flags & IFF_UP) == 0){
975
network.ifr_flags |= IFF_UP;
976
ret = ioctl(sd, SIOCSIFFLAGS, &network);
978
perror("ioctl SIOCSIFFLAGS");
979
exitcode = EXIT_FAILURE;
980
ret = klogctl(7, NULL, 0);
987
/* sleep checking until interface is running */
988
for(int i=0; i < delay * 4; i++){
989
ret = ioctl(sd, SIOCGIFFLAGS, &network);
991
perror("ioctl SIOCGIFFLAGS");
992
} else if(network.ifr_flags & IFF_RUNNING){
995
struct timespec sleeptime = { .tv_nsec = 250000000 };
996
nanosleep(&sleeptime, NULL);
998
ret = (int)TEMP_FAILURE_RETRY(close(sd));
1002
/* Restores kernel loglevel to default */
1003
ret = klogctl(7, NULL, 0);
1022
ret = init_gnutls_global(&mc, pubkey, seckey);
1024
fprintf(stderr, "init_gnutls_global failed\n");
1025
exitcode = EXIT_FAILURE;
1028
gnutls_initialized = true;
1031
if(mkdtemp(tempdir) == NULL){
1035
tempdir_created = true;
1037
if(not init_gpgme(&mc, pubkey, seckey, tempdir)){
1038
fprintf(stderr, "init_gpgme failed\n");
1039
exitcode = EXIT_FAILURE;
1042
gpgme_initialized = true;
736
1045
if_index = (AvahiIfIndex) if_nametoindex(interface);
737
1046
if(if_index == 0){
738
1047
fprintf(stderr, "No such interface: \"%s\"\n", interface);
1048
exitcode = EXIT_FAILURE;
742
1052
if(connect_to != NULL){
745
1055
char *address = strrchr(connect_to, ':');
746
1056
if(address == NULL){
747
1057
fprintf(stderr, "No colon in address\n");
751
uint16_t port = (uint16_t) strtol(address+1, NULL, 10);
753
perror("Bad port number");
1058
exitcode = EXIT_FAILURE;
1062
ret = sscanf(address+1, "%" SCNdMAX "%n", &tmpmax, &numchars);
1063
if(ret < 1 or tmpmax != (uint16_t)tmpmax
1064
or address[numchars+1] != '\0'){
1065
fprintf(stderr, "Bad port number\n");
1066
exitcode = EXIT_FAILURE;
1069
port = (uint16_t)tmpmax;
756
1070
*address = '\0';
757
1071
address = connect_to;
758
ret = start_mandos_communication(address, port, if_index);
1072
ret = start_mandos_communication(address, port, if_index, &mc);
1074
exitcode = EXIT_FAILURE;
766
sd = socket(PF_INET6, SOCK_DGRAM, IPPROTO_IP);
769
returncode = EXIT_FAILURE;
772
strcpy(network.ifr_name, interface);
773
ret = ioctl(sd, SIOCGIFFLAGS, &network);
776
perror("ioctl SIOCGIFFLAGS");
777
returncode = EXIT_FAILURE;
780
if((network.ifr_flags & IFF_UP) == 0){
781
network.ifr_flags |= IFF_UP;
782
ret = ioctl(sd, SIOCSIFFLAGS, &network);
784
perror("ioctl SIOCSIFFLAGS");
785
returncode = EXIT_FAILURE;
1076
exitcode = EXIT_SUCCESS;
792
1082
avahi_set_log_function(empty_log);
795
/* Initialize the psuedo-RNG */
1085
/* Initialize the pseudo-RNG for Avahi */
796
1086
srand((unsigned int) time(NULL));
798
/* Allocate main loop object */
799
if (!(mc.simple_poll = avahi_simple_poll_new())) {
800
fprintf(stderr, "Failed to create simple poll object.\n");
801
returncode = EXIT_FAILURE;
805
/* Do not publish any local records */
806
avahi_server_config_init(&config);
807
config.publish_hinfo = 0;
808
config.publish_addresses = 0;
809
config.publish_workstation = 0;
810
config.publish_domain = 0;
812
/* Allocate a new server */
813
mc.server = avahi_server_new(avahi_simple_poll_get(simple_poll),
814
&config, NULL, NULL, &error);
816
/* Free the configuration data */
817
avahi_server_config_free(&config);
819
/* Check if creating the server object succeeded */
821
fprintf(stderr, "Failed to create server: %s\n",
1088
/* Allocate main Avahi loop object */
1089
mc.simple_poll = avahi_simple_poll_new();
1090
if(mc.simple_poll == NULL) {
1091
fprintf(stderr, "Avahi: Failed to create simple poll"
1093
exitcode = EXIT_FAILURE;
1098
AvahiServerConfig config;
1099
/* Do not publish any local Zeroconf records */
1100
avahi_server_config_init(&config);
1101
config.publish_hinfo = 0;
1102
config.publish_addresses = 0;
1103
config.publish_workstation = 0;
1104
config.publish_domain = 0;
1106
/* Allocate a new server */
1107
mc.server = avahi_server_new(avahi_simple_poll_get
1108
(mc.simple_poll), &config, NULL,
1111
/* Free the Avahi configuration data */
1112
avahi_server_config_free(&config);
1115
/* Check if creating the Avahi server object succeeded */
1116
if(mc.server == NULL) {
1117
fprintf(stderr, "Failed to create Avahi server: %s\n",
822
1118
avahi_strerror(error));
823
returncode = EXIT_FAILURE;
1119
exitcode = EXIT_FAILURE;
827
/* Create the service browser */
1123
/* Create the Avahi service browser */
828
1124
sb = avahi_s_service_browser_new(mc.server, if_index,
829
1125
AVAHI_PROTO_INET6,
830
1126
"_mandos._tcp", NULL, 0,
831
1127
browse_callback, &mc);
833
1129
fprintf(stderr, "Failed to create service browser: %s\n",
834
1130
avahi_strerror(avahi_server_errno(mc.server)));
835
returncode = EXIT_FAILURE;
1131
exitcode = EXIT_FAILURE;
839
1135
/* Run the main loop */
842
fprintf(stderr, "Starting avahi loop search\n");
1138
fprintf(stderr, "Starting Avahi loop search\n");
845
avahi_simple_poll_loop(simple_poll);
1141
avahi_simple_poll_loop(mc.simple_poll);
850
1146
fprintf(stderr, "%s exiting\n", argv[0]);
853
1149
/* Cleanup things */
855
1151
avahi_s_service_browser_free(sb);
1153
if(mc.server != NULL)
858
1154
avahi_server_free(mc.server);
861
avahi_simple_poll_free(simple_poll);
1156
if(mc.simple_poll != NULL)
1157
avahi_simple_poll_free(mc.simple_poll);
1159
if(gnutls_initialized){
1160
gnutls_certificate_free_credentials(mc.cred);
1161
gnutls_global_deinit();
1162
gnutls_dh_params_deinit(mc.dh_params);
1165
if(gpgme_initialized){
1166
gpgme_release(mc.ctx);
1169
/* Removes the temp directory used by GPGME */
1170
if(tempdir_created){
1172
struct dirent *direntry;
1173
d = opendir(tempdir);
1175
if(errno != ENOENT){
1180
direntry = readdir(d);
1181
if(direntry == NULL){
1184
/* Skip "." and ".." */
1185
if(direntry->d_name[0] == '.'
1186
and (direntry->d_name[1] == '\0'
1187
or (direntry->d_name[1] == '.'
1188
and direntry->d_name[2] == '\0'))){
1191
char *fullname = NULL;
1192
ret = asprintf(&fullname, "%s/%s", tempdir,
1198
ret = remove(fullname);
1200
fprintf(stderr, "remove(\"%s\"): %s\n", fullname,
1207
ret = rmdir(tempdir);
1208
if(ret == -1 and errno != ENOENT){