Stu Tomlinson
3d01915407
Accept PKCS#12 file in either key or cert
2022-06-23 17:24:38 +01:00
Stu Tomlinson
3891b73c44
Open PKCS12 files as binary
...
Opening as text on Windows causes read failures:
tls DEBUG error:0680008E:asn1 encoding routines::not enough data
2022-06-23 09:44:00 +01:00
Steffen Jaeckel
d8c9ca49e1
Be user-friendly when opening a pfx/p12 file
...
Before this change the user had to provide a password callback, even if the
PKCS#12 encoded file has no or an empty password.
This changes the behavior, so we first try to open the file without a
password and only then ask the user to provide one.
This fixes #204 .
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-05-05 16:34:44 +02:00
Steffen Jaeckel
5ac415986e
finish implementing XEP-0198
...
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-04-06 13:51:05 +02:00
Steffen Jaeckel
e1ee758b61
fix warning when compiling against OpenSSL 3.0.x
...
`ERR_func_error_string()` has been deprecated.
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-03-23 17:04:13 +01:00
Steffen Jaeckel
4b5e103d9c
move password cache into libstrophe
...
The cache is stored per connection object and is cleared on
* entry of wrong password
* release of connection object
* successful connection
It can be configured that libstrophe retries the password entry in case
the user entered a wrong password.
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-03-23 17:04:13 +01:00
Steffen Jaeckel
bddb80a192
add support for a password callback
...
In order to be able to load password-protected key files a password
callback was added.
This also adds support for PKCS#12 containers instead of certificate+key.
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-03-21 00:24:22 +01:00
Steffen Jaeckel
fc6ba89c61
properly rename internal [v]snprintf() functions
...
Otherwise it clashes when we want to re-introduce the `xmpp_` prefix'ed
versions.
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-03-16 14:39:20 +01:00
Steffen Jaeckel
528c16e6c8
fix build with OpenSSL 1.1.0l
...
Debian 9.13 (stretch) brings this version and building failed there.
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-03-09 16:48:07 +01:00
Steffen Jaeckel
93e04b8d03
make logging functions private
...
Fixes #189
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-02-06 12:36:38 +01:00
Steffen Jaeckel
a97714da18
make alloc-class of functions private
...
Fixes #189
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-02-06 12:36:38 +01:00
Steffen Jaeckel
2850fd7792
fix build with libressl
...
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-02-04 13:36:17 +01:00
Steffen Jaeckel
d8d0e75466
improve OpenSSL error logging
...
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-02-04 13:36:17 +01:00
Steffen Jaeckel
b0631e322f
use lower-case labels
...
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2021-12-03 12:04:29 +01:00
Steffen Jaeckel
12009a009d
implement certificate verification API for OpenSSL
...
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2021-10-28 17:23:32 +02:00
Dmitry Podgorny
ee5f9fb77b
tls/openssl: fix openssl-3.0.0 support
...
3.0.0 includes the "id-on-xmppAddr" object and OBJ_create() returns
NID_undef if we try to create a new one.
2021-03-23 02:08:22 +02:00
Dmitry Podgorny
4790a61437
tls/openssl: fix openssl-0.9.8 support
...
0.9.8 doesn't implement GENERAL_NAME_get0_otherName().
2021-03-23 02:07:00 +02:00
Steffen Jaeckel
18c95fa7bd
add support for client authentication via certificates
...
The SASL EXTERNAL method is implemented to make this possible.
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2021-03-23 02:04:59 +02:00
Dmitry Podgorny
db8a511f68
style: remove extra const keyword from interfaces
...
Const variables in prototypes don't add much value, but make the code
larger and redundant. Remove these const keywords.
Note, this doesn't apply to pointers to const memory.
2021-03-19 22:12:15 +02:00
Dmitry Podgorny
acced31192
tls/openssl: Fix undefined error codes for LibreSSL
...
LibreSSL doesn't define all error codes which OpenSSL defines. Wrap them
with #ifndef.
Reference: https://bugs.gentoo.org/744127
2020-09-24 13:34:49 +03:00
Dmitry Podgorny
4dd78be10d
tls/openssl: fix compilation with older openssl
...
Not all error codes are present in older versions of openssl.
2020-09-15 03:07:02 +03:00
Dmitry Podgorny
197896ba1b
tls/openssl: improve logging
...
Log error names and codes to increase verbosity in debug mode.
2020-06-18 22:18:59 +03:00
Oleg Synelnykov
198bdd77d0
Remove -Wno-unused-parameter
...
Introduced UNUSED macro with cast to void in commoh.h for internal
use. Used cast to void directly in those files which do not
include common.h. Although this change doesn't fix semantic issues
with unused function parameters, it does explicitly mark all those
places, which might require attention in future.
2020-03-31 17:37:12 +03:00
Dmitry Podgorny
562a06425b
Unify coding style
...
@sjaeckel integrated clang-format with formal coding style. Run his
script and commit changes.
There are pros and cons of this commit.
Mixed coding style is a "broken window". A good single style simplifies
reading and writing code.
On the other hand, this is a big change which will lead to conflicts.
2020-01-31 01:16:50 +02:00
Steffen Jaeckel
abd1b08a97
trim trailing spaces
2020-01-31 01:14:32 +02:00
Manuel Kasper
f0436490b0
Enable SNI with OpenSSL 0.9.8f as well
2019-12-24 09:07:51 +01:00
Manuel Kasper
243664926f
Enable TLS SNI
2019-12-23 14:34:19 +01:00
Dmitry Podgorny
284e8f4421
tls/openssl: check return code
...
Check return code of SSL_CTX_set_default_verify_paths() and fail TLS on
an error. However, ignore the error when XMPP_CONN_FLAG_TRUST_TLS is
set.
2019-11-10 15:57:23 +02:00
Dmitry Podgorny
296df2fca9
tls/openssl: don't use deprecated function in 1.1.0+
...
SSLv23_client_method() was deprecated in OpenSSL 1.1.0. It is left as
macro to TLS_client_method.
2019-11-25 13:45:51 +00:00
François Revol
234bef4025
Haiku: C89
2019-11-17 14:28:26 +01:00
Dmitry Podgorny
18b67d6eaf
tls/openssl: add LibreSSL support
...
OpenSSL and LibreSSL versions are incompatible. Moreover, LibreSSL
always define OPENSSL_VERSION_NUMBER as 0x20000000L. Instead of checking
for LibreSSL everywhere explicitly, redefine OPENSSL_VERSION_NUMBER.
See similar issues with nginx project: https://trac.nginx.org/nginx/ticket/1605
2019-10-11 01:59:34 +03:00
Hoenig Mark (TT/EIS3-Lol)
5ee06776ee
tls/openssl: don't call SSL_shutdown() after a fatal error
...
According to SSL_shutdown(3), the function must not be called
if previous fatal error occurred.
2019-07-03 15:14:01 +02:00
Dmitry Podgorny
9cc9ea86bb
tls/openssl: log some info about certificate
...
Log subject name and issuer name from certificate after TLS connection
is established or fails to connect.
2018-11-06 10:53:46 +02:00
Dmitry Podgorny
7ede9c6d03
tls/openssl: suppress error in special case in tls_stop()
...
When peer closes connection instead of proper shutdown SSL_shutdown()
fails in bidirectional mode. Handle this case and suppress the error.
2018-02-18 12:03:11 +02:00
Dmitry Podgorny
d0644c5e95
tls/openssl: print errno on unrecoverable error
2017-08-23 09:23:51 +03:00
Dmitry Podgorny
8d2d59e914
tls/openssl: add OpenSSL-1.1.0 support ( #109 )
...
OpenSSL-1.1.0 marks cleanup functions as deprecated and changes
initialization function. It implements implicit de-initialization.
Reported by @zygmund2000.
2017-07-12 02:07:14 +03:00
Dmitry Podgorny
9269d6b0d5
conn: add flag XMPP_CONN_FLAG_TRUST_TLS
...
TLS modules accept invalid server's certificates when the flag is set.
2017-07-04 17:20:33 +03:00
Dmitry Podgorny
cc53012cfa
tls/openssl: enable cert verification for openssl older then 1.0.2
...
TODO: add flag to trust certificate even if verification fails.
2017-07-01 15:51:49 +03:00
Steffen Jaeckel
f226891520
fix openssl memory leaks
2017-06-29 16:54:41 +02:00
Alexander Krotov
92d006a41b
Disable hostname verification for pre-1.0.2 OpenSSL
2017-06-23 13:45:24 +03:00
Alexander Krotov
0741820711
Verify certificate hostname when using OpenSSL ( fixes #100 )
2017-06-23 03:00:26 +03:00
Alexander Krotov
c9ddc2b7ef
Make tls_new accept xmpp_conn_t
2017-06-23 02:59:05 +03:00
Alexander Krotov
f776b34d8c
Fix tls_openssl.c indentation
2017-06-22 19:44:41 +03:00
Alexander Krotov
f47609c1f0
Disable insecure SSL/TLS versions
2017-06-20 22:44:39 +03:00
Dmitry Podgorny
0c60e8d384
tls_openssl: coding style
2016-09-02 00:49:32 +03:00
Dmitry Podgorny
ab80d72518
tls/openssl: handle SSL_shutdown() properly
...
Handle SSL_ERROR_WANT_READ/WRITE and return value 0.
2016-04-19 19:57:52 +00:00
Dmitry Podgorny
ba7422c893
tls/openssl: be more verbose
...
Log non-recoverable errors. The openssl error queue can contain useful
information.
2016-04-19 18:21:27 +00:00
Dmitry Podgorny
4b444ea699
tls/openssl: fixed indentation
2016-04-19 16:33:47 +00:00
Dmitry Podgorny
b04c40d3ea
tls: don't hang with openssl implementation
...
* Exit from tls_start() on fatal errors. If SSL_connect() fails and
returns -1 this leads to endless loop in case of fatal error.
* Don't set writefds on SSL_ERROR_WANT_READ. Otherwise, this makes
select(2) exit immediately what leads to CPU usage.
2015-10-13 02:43:23 +03:00
Dariusz Dwornikowski
71f75b2e2e
Closes #31
2014-10-23 08:44:52 +02:00