diff options
Diffstat (limited to 'src/irmd/oap')
| -rw-r--r-- | src/irmd/oap/cli.c | 38 | ||||
| -rw-r--r-- | src/irmd/oap/tests/common.c | 19 |
2 files changed, 32 insertions, 25 deletions
diff --git a/src/irmd/oap/cli.c b/src/irmd/oap/cli.c index ebfcd71f..2203596f 100644 --- a/src/irmd/oap/cli.c +++ b/src/irmd/oap/cli.c @@ -50,6 +50,7 @@ struct oap_cli_ctx { uint8_t __id[OAP_ID_SIZE]; buffer_t id; + char peer[NAME_SIZE + 1]; /* expected server name */ uint8_t kex_buf[CRYPT_KEY_BUFSZ]; uint8_t req_hash[MAX_HASH_SIZE]; size_t req_hash_len; @@ -241,6 +242,7 @@ static int do_client_kex_prepare(const char * server_name, int oap_cli_prepare(void ** ctx, const struct name_info * info, + const char * peer, buffer_t * req_buf, buffer_t data, bool rekey) @@ -259,6 +261,11 @@ int oap_cli_prepare(void ** ctx, clrbuf(*req_buf); *ctx = NULL; + if (peer != NULL && strlen(peer) > NAME_SIZE) { + log_err("Peer name too long."); + return -EINVAL; + } + /* Allocate ctx to carry between prepare and complete */ s = malloc(sizeof(*s)); if (s == NULL) { @@ -269,13 +276,15 @@ int oap_cli_prepare(void ** ctx, memset(s, 0, sizeof(*s)); OAP_CLI_CTX_INIT(s); + strcpy(s->peer, peer != NULL ? peer : info->name); + /* Generate session ID */ if (random_buffer(s->__id, OAP_ID_SIZE) < 0) { log_err("Failed to generate OAP session ID."); goto fail_id; } - log_dbg_id(s->id.data, "Preparing OAP request for %s.", info->name); + log_dbg_id(s->id.data, "Preparing OAP request for %s.", s->peer); /* Load client credentials */ if (load_cli_credentials(info, &pkp, &crt) < 0) { @@ -315,7 +324,7 @@ int oap_cli_prepare(void ** ctx, oap_hdr_init(&s->local_hdr, s->id, s->kex_buf, data, s->scfg.c.nid); - if (do_client_kex_prepare(info->name, s) < 0) { + if (do_client_kex_prepare(s->peer, s) < 0) { log_err_id(s->id.data, "Failed to prepare client KEX."); goto fail_kex; } @@ -482,7 +491,8 @@ static int do_client_kex_complete(struct oap_cli_ctx * s, } SET_KEX_CIPHER(scfg, peer_hdr->cipher_str); - if (crypt_validate_nid(scfg->c.nid) < 0) { + + if (crypt_cipher_rank(scfg->c.nid) < 0) { log_err_id(id, "Server cipher '%s' not supported.", peer_hdr->cipher_str); return -ENOTSUP; @@ -518,13 +528,12 @@ static int do_client_kex_complete(struct oap_cli_ctx * s, return do_client_kex_complete_dhe(s, peer_hdr, sk); } -int oap_cli_complete(void * ctx, - const struct name_info * info, - buffer_t rsp_buf, - buffer_t * data, - struct crypt_sk * sk, - const buffer_t * cached_crt, - buffer_t * peer_crt) +int oap_cli_complete(void * ctx, + buffer_t rsp_buf, + buffer_t * data, + struct crypt_sk * sk, + const buffer_t * cached_crt, + buffer_t * peer_crt) { struct oap_cli_ctx * s = ctx; struct oap_hdr peer_hdr; @@ -538,7 +547,6 @@ int oap_cli_complete(void * ctx, int rc; assert(ctx != NULL); - assert(info != NULL); assert(data != NULL); assert(sk != NULL); @@ -550,7 +558,7 @@ int oap_cli_complete(void * ctx, id = s->id.data; - log_dbg_id(id, "Completing OAP for %s.", info->name); + log_dbg_id(id, "Completing OAP for %s.", s->peer); /* Decode response header using client's md_nid for hash length */ if (oap_hdr_decode(&peer_hdr, rsp_buf, s->req_md_nid, false) < 0) { @@ -616,9 +624,9 @@ int oap_cli_complete(void * ctx, } /* Verify peer certificate name matches expected destination */ - if (peer_hdr.crt.len > 0 && strcmp(peer, info->name) != 0) { + if (peer_hdr.crt.len > 0 && strcmp(peer, s->peer) != 0) { log_err_id(id, "Peer crt for '%s' does not match '%s'.", - peer, info->name); + peer, s->peer); goto fail_oap; } @@ -667,7 +675,7 @@ int oap_cli_complete(void * ctx, goto fail_oap; } - log_info_id(id, "OAP completed for %s.", info->name); + log_info_id(id, "OAP completed for %s.", s->peer); freebuf(peer_hdr.sealed_pt); diff --git a/src/irmd/oap/tests/common.c b/src/irmd/oap/tests/common.c index 16d52c63..b65f3997 100644 --- a/src/irmd/oap/tests/common.c +++ b/src/irmd/oap/tests/common.c @@ -159,7 +159,7 @@ void oap_test_teardown(struct oap_test_ctx * ctx) if (ctx->cli.state != NULL) { res.key = ctx->cli.key; - oap_cli_complete(ctx->cli.state, &ctx->cli.info, dummy, + oap_cli_complete(ctx->cli.state, dummy, &ctx->data, &res, NULL, NULL); ctx->cli.state = NULL; } @@ -179,8 +179,8 @@ void oap_test_teardown(struct oap_test_ctx * ctx) int oap_cli_prepare_ctx(struct oap_test_ctx * ctx) { - return oap_cli_prepare(&ctx->cli.state, &ctx->cli.info, &ctx->req_hdr, - ctx->data, ctx->rekey); + return oap_cli_prepare(&ctx->cli.state, &ctx->cli.info, NULL, + &ctx->req_hdr, ctx->data, ctx->rekey); } int oap_srv_process_ctx(struct oap_test_ctx * ctx) @@ -203,8 +203,7 @@ int oap_cli_complete_ctx(struct oap_test_ctx * ctx) struct crypt_sk res = { .nid = NID_undef, .key = ctx->cli.key }; int ret; - ret = oap_cli_complete(ctx->cli.state, &ctx->cli.info, ctx->resp_hdr, - &ctx->data, &res, + ret = oap_cli_complete(ctx->cli.state, ctx->resp_hdr, &ctx->data, &res, ctx->rekey ? &ctx->cli_crt : NULL, ctx->rekey ? NULL : &ctx->cli_crt); ctx->cli.state = NULL; @@ -527,7 +526,7 @@ int roundtrip_kex_only(void) goto fail; } - if (oap_cli_prepare(&cli_state, &cli_info, &req_hdr, + if (oap_cli_prepare(&cli_state, &cli_info, NULL, &req_hdr, data, false) < 0) { printf("Client prepare failed.\n"); goto fail_cleanup; @@ -545,7 +544,7 @@ int roundtrip_kex_only(void) res.key = cli_key; - if (oap_cli_complete(cli_state, &cli_info, resp_hdr, &data, &res, + if (oap_cli_complete(cli_state, resp_hdr, &data, &res, NULL, NULL) < 0) { printf("Client complete failed.\n"); cli_state = NULL; @@ -575,8 +574,8 @@ int roundtrip_kex_only(void) fail_cleanup: if (cli_state != NULL) { res.key = cli_key; - oap_cli_complete(cli_state, &cli_info, resp_hdr, &data, - &res, NULL, NULL); + + oap_cli_complete(cli_state, resp_hdr, &data, &res, NULL, NULL); } freebuf(resp_hdr); freebuf(req_hdr); @@ -655,7 +654,7 @@ int corrupted_response(const char * root_ca, res.key = ctx.cli.key; - if (oap_cli_complete(ctx.cli.state, &ctx.cli.info, ctx.resp_hdr, + if (oap_cli_complete(ctx.cli.state, ctx.resp_hdr, &ctx.data, &res, NULL, NULL) == 0) { printf("Client should reject corrupted response.\n"); ctx.cli.state = NULL; |
