The FreeRADIUS server $Id: f3670dba8951ca10eb4948feb3dc3db9423a334f $
Loading...
Searching...
No Matches
conf.c
Go to the documentation of this file.
1/*
2 * This program is free software; you can redistribute it and/or modify
3 * it under the terms of the GNU General Public License as published by
4 * the Free Software Foundation; either version 2 of the License, or
5 * (at your option) any later version.
6 *
7 * This program is distributed in the hope that it will be useful,
8 * but WITHOUT ANY WARRANTY; without even the implied warranty of
9 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10 * GNU General Public License for more details.
11 *
12 * You should have received a copy of the GNU General Public License
13 * along with this program; if not, write to the Free Software
14 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
15 */
16
17/**
18 * $Id: d81ad6701acbe09eab4c6bdef74484d768300fcf $
19 *
20 * @file tls/conf.c
21 * @brief Configuration parsing for TLS servers and clients.
22 *
23 * @copyright 2026 Network RADIUS SAS (legal@networkradius.com)
24 */
25RCSID("$Id: d81ad6701acbe09eab4c6bdef74484d768300fcf $")
26USES_APPLE_DEPRECATED_API /* OpenSSL API has been deprecated by Apple */
27
28#ifdef WITH_TLS
29#define LOG_PREFIX "tls"
30
31#ifdef HAVE_SYS_STAT_H
32# include <sys/stat.h>
33#endif
34#include <openssl/conf.h>
35#include <openssl/pem.h>
36
37#include <freeradius-devel/server/module.h>
38#include <freeradius-devel/server/virtual_servers.h>
39#include <freeradius-devel/util/debug.h>
40#include <freeradius-devel/util/syserror.h>
41#include <freeradius-devel/util/rand.h>
42
43#include "base.h"
44#include "log.h"
45#include "strerror.h"
46#include "utils.h"
47
48static int tls_conf_parse_cache_mode(TALLOC_CTX *ctx, void *out, void *parent, CONF_ITEM *ci, conf_parser_t const *rule);
49static int tls_virtual_server_cf_parse(TALLOC_CTX *ctx, void *out, void *parent, CONF_ITEM *ci, conf_parser_t const *rule);
50static int tls_fragment_size_parse(TALLOC_CTX *ctx, void *out, void *parent, CONF_ITEM *ci, conf_parser_t const *rule);
51static int tls_padding_parse(TALLOC_CTX *ctx, void *out, void *parent, CONF_ITEM *ci, conf_parser_t const *rule);
52static int tls_ticket_lifetime_parse(TALLOC_CTX *ctx, void *out, void *parent, CONF_ITEM *ci, conf_parser_t const *rule);
53static int tls_chain_private_key_file_parse(TALLOC_CTX *ctx, void *out, void *parent, CONF_ITEM *ci, conf_parser_t const *rule);
54
55/** Certificate formats
56 *
57 */
58static fr_table_num_sorted_t const certificate_format_table[] = {
59 { L("ASN1"), SSL_FILETYPE_ASN1 },
60 { L("DER"), SSL_FILETYPE_ASN1 }, /* Alternate name for ASN1 */
61 { L("PEM"), SSL_FILETYPE_PEM }
62};
63static size_t certificate_format_table_len = NUM_ELEMENTS(certificate_format_table);
64
65static fr_table_num_sorted_t const chain_verify_mode_table[] = {
66 { L("hard"), FR_TLS_CHAIN_VERIFY_HARD },
67 { L("none"), FR_TLS_CHAIN_VERIFY_NONE },
68 { L("soft"), FR_TLS_CHAIN_VERIFY_SOFT }
69};
70static size_t chain_verify_mode_table_len = NUM_ELEMENTS(chain_verify_mode_table);
71
72static fr_table_num_sorted_t const cache_mode_table[] = {
73 { L("auto"), FR_TLS_TICKET_AUTO },
74 { L("disabled"), FR_TLS_TICKET_DISABLED },
75 { L("stateful"), FR_TLS_TICKET_STATEFUL },
76 { L("stateless"), FR_TLS_TICKET_STATELESS }
77};
78static size_t cache_mode_table_len = NUM_ELEMENTS(cache_mode_table);
79
80static fr_table_num_sorted_t const verify_mode_table[] = {
81 { L("all"), FR_TLS_VERIFY_MODE_ALL },
82 { L("client"), FR_TLS_VERIFY_MODE_LEAF },
83 { L("client-and-issuer"), FR_TLS_VERIFY_MODE_LEAF | FR_TLS_VERIFY_MODE_ISSUER },
84 { L("disabled"), FR_TLS_VERIFY_MODE_DISABLED },
85 { L("untrusted"), FR_TLS_VERIFY_MODE_UNTRUSTED }
86};
87static size_t verify_mode_table_len = NUM_ELEMENTS(verify_mode_table);
88
89static conf_parser_t tls_ticket_config[] = {
90 { FR_CONF_OFFSET("mode", fr_tls_ticket_conf_t, mode),
91 .func = tls_conf_parse_cache_mode,
92 .uctx = &(cf_table_parse_ctx_t){
93 .table = cache_mode_table,
94 .len = &cache_mode_table_len
95 },
96 .dflt = "auto" },
97 { FR_CONF_OFFSET_HINT_TYPE("name", FR_TYPE_STRING, fr_tls_ticket_conf_t, id_name),
98 .dflt = "%{EAP-Type}%interpreter('server')", .quote = T_DOUBLE_QUOTED_STRING },
99 { FR_CONF_OFFSET("lifetime", fr_tls_ticket_conf_t, lifetime), .func = tls_ticket_lifetime_parse, .dflt = "1d" },
100 { FR_CONF_OFFSET_IS_SET("min_lifetime", FR_TYPE_TIME_DELTA, 0, fr_tls_ticket_conf_t, min_lifetime),
101 .dflt = "10s" },
102
103 { FR_CONF_OFFSET("require_extended_master_secret", fr_tls_ticket_conf_t, require_extms), .dflt = "yes" },
104 { FR_CONF_OFFSET("require_perfect_forward_secrecy", fr_tls_ticket_conf_t, require_pfs), .dflt = "no" },
105
106 { FR_CONF_OFFSET("session_ticket_key", fr_tls_ticket_conf_t, session_ticket_key) },
107
108 /*
109 * Deprecated
110 */
111 { FR_CONF_V3_DEPRECATED("enable", fr_tls_ticket_conf_t, NULL) },
112 { FR_CONF_V3_DEPRECATED("max_entries", fr_tls_ticket_conf_t, NULL) },
113 { FR_CONF_V3_DEPRECATED("persist_dir", fr_tls_ticket_conf_t, NULL) },
114
116};
117
118static conf_parser_t tls_chain_config[] = {
119 { FR_CONF_OFFSET("format", fr_tls_chain_conf_t, file_format),
121 .uctx = &(cf_table_parse_ctx_t){
122 .table = certificate_format_table,
123 .len = &certificate_format_table_len
124 },
125 .dflt = "pem" },
126 /*
127 * private_key_file must be the last file row. Its parse
128 * callback loads every file in the section.
129 */
130 { FR_CONF_OFFSET_FLAGS("ca_file", CONF_FLAG_FILE_READABLE | CONF_FLAG_MULTI, fr_tls_chain_conf_t, ca_files) },
131 { FR_CONF_OFFSET_FLAGS("certificate_file", CONF_FLAG_FILE_READABLE | CONF_FLAG_FILE_EXISTS | CONF_FLAG_REQUIRED, fr_tls_chain_conf_t, certificate_file) },
132 { FR_CONF_OFFSET_FLAGS("private_key_password", CONF_FLAG_SECRET, fr_tls_chain_conf_t, password) },
133 { FR_CONF_OFFSET_FLAGS("private_key_file", CONF_FLAG_FILE_READABLE | CONF_FLAG_FILE_EXISTS | CONF_FLAG_REQUIRED, fr_tls_chain_conf_t, private_key_file),
134 .func = tls_chain_private_key_file_parse },
135
136 { FR_CONF_OFFSET("verify_mode", fr_tls_chain_conf_t, verify_mode),
137 .func = cf_table_parse_int,
138 .uctx = &(cf_table_parse_ctx_t){
139 .table = chain_verify_mode_table,
140 .len = &chain_verify_mode_table_len
141 },
142 .dflt = "hard" },
143 { FR_CONF_OFFSET("include_root_ca", fr_tls_chain_conf_t, include_root_ca), .dflt = "no" },
145};
146
147static conf_parser_t tls_verify_config[] = {
148 { FR_CONF_OFFSET("mode", fr_tls_verify_conf_t, mode),
150 .uctx = &(cf_table_parse_ctx_t){
151 .table = verify_mode_table,
152 .len = &verify_mode_table_len
153 },
154 .dflt = "all" },
155 { FR_CONF_OFFSET("attribute_mode", fr_tls_verify_conf_t, attribute_mode),
156 .func = cf_table_parse_int,
157 .uctx = &(cf_table_parse_ctx_t){
158 .table = verify_mode_table,
159 .len = &verify_mode_table_len
160 },
161 .dflt = "client-and-issuer" },
162 { FR_CONF_OFFSET("der_decode", fr_tls_verify_conf_t, der_decode) },
164};
165
166#ifdef PSK_MAX_IDENTITY_LEN
167static conf_parser_t tls_psk_config[] = {
168 { FR_CONF_OFFSET("identity", fr_tls_psk_conf_t, identity) },
169 { FR_CONF_OFFSET_FLAGS("key", CONF_FLAG_SECRET, fr_tls_psk_conf_t, key) },
171};
172#endif
173
174conf_parser_t fr_tls_server_config[] = {
175 { FR_CONF_OFFSET_TYPE_FLAGS("virtual_server", FR_TYPE_VOID, 0, fr_tls_conf_t, virtual_server), .func = tls_virtual_server_cf_parse },
176
177 { FR_CONF_SUBSECTION_ALLOC_MULTI("chain", 0, fr_tls_conf_t, chains, tls_chain_config),
178 .subcs_type = "fr_tls_chain_conf_t", .name2 = CF_IDENT_ANY },
179
180 { FR_CONF_V3_DEPRECATED("pem_file_type", fr_tls_conf_t, NULL) },
181 { FR_CONF_V3_DEPRECATED("certificate_file", fr_tls_conf_t, NULL) },
182 { FR_CONF_V3_DEPRECATED("private_key_password", fr_tls_conf_t, NULL) },
183 { FR_CONF_V3_DEPRECATED("private_key_file", fr_tls_conf_t, NULL) },
184
185 { FR_CONF_OFFSET("verify_depth", fr_tls_conf_t, verify_depth), .dflt = "0" },
186 { FR_CONF_OFFSET_FLAGS("ca_path", CONF_FLAG_FILE_READABLE, fr_tls_conf_t, ca_path) },
187 { FR_CONF_OFFSET_FLAGS("ca_file", CONF_FLAG_FILE_READABLE, fr_tls_conf_t, ca_file) },
188
189#ifdef PSK_MAX_IDENTITY_LEN
190 { FR_CONF_OFFSET_SUBSECTION("psk", 0, fr_tls_conf_t, psk, tls_psk_config) },
191 { FR_CONF_V3_DEPRECATED("psk_identity", fr_tls_conf_t, NULL) },
192 { FR_CONF_V3_DEPRECATED("psk_hexphrase", fr_tls_conf_t, NULL) },
193 { FR_CONF_V3_DEPRECATED("psk_query", fr_tls_conf_t, NULL) },
194#endif
195 { FR_CONF_OFFSET("keylog_file", fr_tls_conf_t, keylog_file) },
196
197 { FR_CONF_OFFSET_FLAGS("dh_file", CONF_FLAG_FILE_READABLE, fr_tls_conf_t, dh_file) },
198 { FR_CONF_OFFSET("fragment_size", fr_tls_conf_t, fragment_size), .func = tls_fragment_size_parse, .dflt = "1024" },
199 { FR_CONF_OFFSET("padding", fr_tls_conf_t, padding_block_size), .func = tls_padding_parse },
200
201 { FR_CONF_OFFSET("disable_single_dh_use", fr_tls_conf_t, disable_single_dh_use) },
202
203 { FR_CONF_OFFSET("cipher_list", fr_tls_conf_t, cipher_list) },
204 { FR_CONF_OFFSET("cipher_suites", fr_tls_conf_t, cipher_suites) },
205 { FR_CONF_OFFSET("cipher_server_preference", fr_tls_conf_t, cipher_server_preference), .dflt = "yes" },
206#ifdef SSL3_FLAGS_NO_RENEGOTIATE_CIPHERS
207 { FR_CONF_OFFSET("allow_renegotiation", fr_tls_conf_t, allow_renegotiation), .dflt = "no" },
208#endif
209
210#ifndef OPENSSL_NO_ECDH
211 { FR_CONF_OFFSET("ecdh_curve", fr_tls_conf_t, ecdh_curve), .dflt = "prime256v1" },
212#endif
213 { FR_CONF_OFFSET("tls_max_version", fr_tls_conf_t, tls_max_version) },
214
215 { FR_CONF_OFFSET("tls_min_version", fr_tls_conf_t, tls_min_version), .dflt = "1.2" },
216
217 { FR_CONF_OFFSET("client_hello_parse", fr_tls_conf_t, client_hello_parse )},
218
219 { FR_CONF_OFFSET_SUBSECTION("session", 0, fr_tls_conf_t, cache, tls_ticket_config) },
220
221 { FR_CONF_OFFSET_SUBSECTION("verify", 0, fr_tls_conf_t, verify, tls_verify_config) },
222
223 { FR_CONF_OFFSET_SUBSECTION("cache", CONF_FLAG_V3_DEPRECATED, fr_tls_conf_t, cache, tls_ticket_config) },
224 { FR_CONF_V3_DEPRECATED("check_cert_issuer", fr_tls_conf_t, check_cert_issuer) },
225 { FR_CONF_V3_DEPRECATED("check_cert_cn", fr_tls_conf_t, check_cert_cn) },
227};
228
229conf_parser_t fr_tls_client_config[] = {
230 /*
231 * Optional. Without it a client validates the server certificate
232 * with OpenSSL alone, which is what a caller that owns its own
233 * transport wants. With it, fr_tls_session_alloc_client() runs
234 * the `verify certificate` section of the named virtual server.
235 */
236 { FR_CONF_OFFSET_TYPE_FLAGS("virtual_server", FR_TYPE_VOID, CONF_FLAG_OK_MISSING, fr_tls_conf_t, virtual_server),
237 .func = tls_virtual_server_cf_parse },
238
239 { FR_CONF_SUBSECTION_ALLOC_MULTI("chain", CONF_FLAG_OK_MISSING, fr_tls_conf_t, chains, tls_chain_config),
240 .subcs_type = "fr_tls_chain_conf_t" },
241
242 { FR_CONF_OFFSET_SUBSECTION("verify", 0, fr_tls_conf_t, verify, tls_verify_config) },
243
244 { FR_CONF_OFFSET_SUBSECTION("session", 0, fr_tls_conf_t, cache, tls_ticket_config) },
245
246 { FR_CONF_V3_DEPRECATED("pem_file_type", fr_tls_conf_t, NULL) },
247 { FR_CONF_V3_DEPRECATED("certificate_file", fr_tls_conf_t, NULL) },
248 { FR_CONF_V3_DEPRECATED("private_key_password", fr_tls_conf_t, NULL) },
249 { FR_CONF_V3_DEPRECATED("private_key_file", fr_tls_conf_t, NULL) },
250
251#ifdef PSK_MAX_IDENTITY_LEN
252 { FR_CONF_OFFSET_SUBSECTION("psk", 0, fr_tls_conf_t, psk, tls_psk_config) },
253 { FR_CONF_V3_DEPRECATED("psk_identity", fr_tls_conf_t, NULL) },
254 { FR_CONF_V3_DEPRECATED("psk_hexphrase", fr_tls_conf_t, NULL) },
255#endif
256
257 { FR_CONF_OFFSET("keylog_file", fr_tls_conf_t, keylog_file) },
258
259 { FR_CONF_OFFSET("verify_depth", fr_tls_conf_t, verify_depth), .dflt = "0" },
260 { FR_CONF_OFFSET_FLAGS("ca_path", CONF_FLAG_FILE_READABLE, fr_tls_conf_t, ca_path) },
261
262 { FR_CONF_OFFSET_FLAGS("ca_file", CONF_FLAG_FILE_READABLE, fr_tls_conf_t, ca_file) },
263 { FR_CONF_OFFSET("dh_file", fr_tls_conf_t, dh_file) },
264 { FR_CONF_OFFSET("random_file", fr_tls_conf_t, random_file) },
265 { FR_CONF_OFFSET("fragment_size", fr_tls_conf_t, fragment_size), .func = tls_fragment_size_parse, .dflt = "1024" },
266
267 { FR_CONF_OFFSET("cipher_list", fr_tls_conf_t, cipher_list) },
268 { FR_CONF_OFFSET("cipher_suites", fr_tls_conf_t, cipher_suites) },
269
270#ifndef OPENSSL_NO_ECDH
271 { FR_CONF_OFFSET("ecdh_curve", fr_tls_conf_t, ecdh_curve), .dflt = "prime256v1" },
272#endif
273
274 { FR_CONF_OFFSET("tls_max_version", fr_tls_conf_t, tls_max_version) },
275
276 { FR_CONF_OFFSET("tls_min_version", fr_tls_conf_t, tls_min_version), .dflt = "1.2" },
277
278 { FR_CONF_OFFSET_SUBSECTION("cache", CONF_FLAG_V3_DEPRECATED, fr_tls_conf_t, cache, tls_ticket_config) },
279 { FR_CONF_V3_DEPRECATED("check_cert_issuer", fr_tls_conf_t, check_cert_issuer) },
280 { FR_CONF_V3_DEPRECATED("check_cert_cn", fr_tls_conf_t, check_cert_cn) },
282};
283
284static int tls_virtual_server_cf_parse(TALLOC_CTX *ctx, void *out, void *parent, CONF_ITEM *ci, conf_parser_t const *rule)
285{
286 fr_tls_conf_t *conf = talloc_get_type_abort(parent, fr_tls_conf_t);
287 virtual_server_t const *vs = NULL;
288
289 if (virtual_server_cf_parse(ctx, &vs, parent, ci, rule) < 0) return -1;
290
291 if (!vs) return 0;
292
293 /*
294 * `out` points to conf->virtual_server
295 */
296 *((CONF_SECTION const **)out) = virtual_server_cs(vs);
297 conf->verify_certificate = cf_section_find(conf->virtual_server, "verify", "certificate") ? true : false;
298 conf->new_session = cf_section_find(conf->virtual_server, "new", "session") ? true : false;
299 conf->establish_session = cf_section_find(conf->virtual_server, "establish", "session") ? true : false;
300 conf->fail_session = cf_section_find(conf->virtual_server, "fail", "session") ? true : false;
301 conf->encode_session = cf_section_find(conf->virtual_server, "encode", "session") ? true : false;
302 conf->decode_session = cf_section_find(conf->virtual_server, "decode", "session") ? true : false;
303#ifdef PSK_MAX_IDENTITY_LEN
304 conf->load_psk = cf_section_find(conf->virtual_server, "load", "psk") ? true : false;
305#else
306 if (cf_section_find(conf->virtual_server, "load", "psk")) {
307 cf_log_err(ci, "Specified virtual_server has a \"load psk { ... }\" section, "
308 "but OpenSSL was built without PSK support");
309 return -1;
310 }
311#endif
312 return 0;
313}
314
315static int tls_conf_parse_cache_mode(TALLOC_CTX *ctx, void *out, void *parent, CONF_ITEM *ci, conf_parser_t const *rule)
316{
317 fr_tls_conf_t *conf = talloc_get_type_abort((uint8_t *)parent - offsetof(fr_tls_conf_t, cache), fr_tls_conf_t);
318 int cache_mode;
319
320 if (cf_table_parse_int(ctx, &cache_mode, parent, ci, rule) < 0) return -1;
321
322 /*
323 * Ensure our virtual server contains the
324 * correct sections for the specified
325 * cache mode.
326 */
327 switch (cache_mode) {
328 case FR_TLS_TICKET_DISABLED:
329 case FR_TLS_TICKET_STATELESS:
330 break;
331
332 case FR_TLS_TICKET_STATEFUL:
333 if (!conf->virtual_server) {
334 cf_log_err(ci, "A virtual_server must be set when session.mode = \"stateful\"");
335 error:
336 return -1;
337 }
338
339 if (!cf_section_find(conf->virtual_server, "load", "session")) {
340 cf_log_err(ci, "Specified virtual_server must contain a \"load session { ... }\" section "
341 "when session.mode = \"stateful\"");
342 goto error;
343 }
344
345 if (!cf_section_find(conf->virtual_server, "store", "session")) {
346 cf_log_err(ci, "Specified virtual_server must contain a \"store session { ... }\" section "
347 "when session.mode = \"stateful\"");
348 goto error;
349 }
350
351 if (!cf_section_find(conf->virtual_server, "clear", "session")) {
352 cf_log_err(ci, "Specified virtual_server must contain a \"clear session { ... }\" section "
353 "when session.mode = \"stateful\"");
354 goto error;
355 }
356
357 if (conf->tls_min_version >= (float)1.3) {
358 cf_log_err(ci, "session.mode = \"stateful\" is not supported with tls_min_version >= 1.3");
359 goto error;
360 }
361 break;
362
363 case FR_TLS_TICKET_AUTO:
364 if (!conf->virtual_server) {
365 WARN("A virtual_server must be provided for stateful caching. "
366 "session.mode = \"auto\" rewritten to session.mode = \"stateless\"");
367 cache_stateless:
368 cache_mode = FR_TLS_TICKET_STATELESS;
369 break;
370 }
371
372 if (!cf_section_find(conf->virtual_server, "load", "session")) {
373 cf_log_warn(ci, "Specified virtual_server missing \"load session { ... }\" section. "
374 "session.mode = \"auto\" rewritten to session.mode = \"stateless\"");
375 goto cache_stateless;
376 }
377
378 if (!cf_section_find(conf->virtual_server, "store", "session")) {
379 cf_log_warn(ci, "Specified virtual_server missing \"store session { ... }\" section. "
380 "session.mode = \"auto\" rewritten to session.mode = \"stateless\"");
381 goto cache_stateless;
382 }
383
384 if (!cf_section_find(conf->virtual_server, "clear", "session")) {
385 cf_log_warn(ci, "Specified virtual_server missing \"clear cache { ... }\" section. "
386 "session.mode = \"auto\" rewritten to session.mode = \"stateless\"");
387 goto cache_stateless;
388 }
389
390 if (conf->tls_min_version >= (float)1.3) {
391 cf_log_err(ci, "stateful session-resumption is not supported with tls_min_version >= 1.3. "
392 "session.mode = \"auto\" rewritten to session.mode = \"stateless\"");
393 goto cache_stateless;
394 }
395 break;
396 }
397
398 /*
399 * Generate random, ephemeral, session-ticket keys.
400 */
401 if (cache_mode & FR_TLS_TICKET_STATELESS) {
402 /*
403 * Fill the key with randomness if one
404 * wasn't specified by the user.
405 */
406 if (!conf->cache.session_ticket_key) {
407 MEM(conf->cache.session_ticket_key = talloc_array(conf, uint8_t, 256));
408 fr_rand_buffer(UNCONST(uint8_t *, conf->cache.session_ticket_key),
409 talloc_array_length(conf->cache.session_ticket_key));
410 }
411 }
412
413 *((int *)out) = cache_mode;
414
415 return 0;
416}
417
418/** Keep `fragment_size` between 100 and the TLS record limit
419 *
420 * A TLS record holds at most SSL3_RT_MAX_PLAIN_LENGTH bytes, so a larger
421 * fragment size gains nothing. The EAP RFCs ask for fragments of at least
422 * 1020 bytes, but the server accepts down to 100.
423 */
424static int tls_fragment_size_parse(TALLOC_CTX *ctx, void *out, void *parent, CONF_ITEM *ci, conf_parser_t const *rule)
425{
426 uint32_t *fragment_size = out;
427
428 if (cf_pair_parse_value(ctx, out, parent, ci, rule) < 0) return -1;
429
430 if (*fragment_size < 100) {
431 cf_log_warn(ci, "Ignoring \"fragment_size = %u\", forcing to \"fragment_size = 100\"", *fragment_size);
432 *fragment_size = 100;
433 }
434 if (*fragment_size > SSL3_RT_MAX_PLAIN_LENGTH) {
435 cf_log_warn(ci, "Ignoring \"fragment_size = %u\", forcing to \"fragment_size = %u\"",
436 *fragment_size, (unsigned int)SSL3_RT_MAX_PLAIN_LENGTH);
437 *fragment_size = SSL3_RT_MAX_PLAIN_LENGTH;
438 }
439
440 return 0;
441}
442
443/** Keep `padding` at or below the TLS record limit
444 *
445 */
446static int tls_padding_parse(TALLOC_CTX *ctx, void *out, void *parent, CONF_ITEM *ci, conf_parser_t const *rule)
447{
448 uint32_t *padding = out;
449
450 if (cf_pair_parse_value(ctx, out, parent, ci, rule) < 0) return -1;
451
452 if (*padding > SSL3_RT_MAX_PLAIN_LENGTH) {
453 cf_log_warn(ci, "Ignoring \"padding = %u\", forcing to \"padding = %u\"",
454 *padding, (unsigned int)SSL3_RT_MAX_PLAIN_LENGTH);
455 *padding = SSL3_RT_MAX_PLAIN_LENGTH;
456 }
457
458 return 0;
459}
460
461/** Keep `session.lifetime` at or below #FR_TLS_MAX_SESSION_LIFETIME
462 *
463 */
464static int tls_ticket_lifetime_parse(TALLOC_CTX *ctx, void *out, void *parent, CONF_ITEM *ci, conf_parser_t const *rule)
465{
466 fr_time_delta_t *lifetime = out;
467 fr_time_delta_t const max = fr_time_delta_from_sec(FR_TLS_MAX_SESSION_LIFETIME);
468
469 if (cf_pair_parse_value(ctx, out, parent, ci, rule) < 0) return -1;
470
471 if (fr_time_delta_gt(*lifetime, max)) {
472 cf_log_warn(ci, "Ignoring \"lifetime = %pV\", forcing to \"lifetime = %pV\"",
474 *lifetime = max;
475 }
476
477 return 0;
478}
479
480#ifdef __APPLE__
481/*
482 * Setting private_key_password to this marker reads the
483 * password from certadmin instead.
484 */
485static char const *special_string = "Apple:UsecertAdmin";
486
487/** Read the private key password from certadmin
488 *
489 * @param[in,out] chain whose password is replaced when set to the marker.
490 * @param[in] ci for error messages.
491 * @return
492 * - 0 on success, or if the password is not the marker.
493 * - -1 if certadmin failed.
494 */
495static int tls_chain_password_certadmin(fr_tls_chain_conf_t *chain, CONF_ITEM *ci)
496{
497 char cmd[256];
498 char *password, *buf;
499 long const max_password_len = 128;
500 FILE *cmd_pipe;
501
502 if (!chain->password) return 0;
503 if (strncmp(chain->password, special_string, strlen(special_string)) != 0) return 0;
504
505 snprintf(cmd, sizeof(cmd) - 1, "/usr/sbin/certadmin --get-private-key-passphrase \"%s\"",
506 chain->private_key_file);
507
508 DEBUG2("Getting private key passphrase using command \"%s\"", cmd);
509
510 cmd_pipe = popen(cmd, "r");
511 if (!cmd_pipe) {
512 cf_log_err(ci, "%s command failed: Unable to get private_key_password", cmd);
513 cf_log_err(ci, "Error reading private_key_file %s", chain->private_key_file);
514 return -1;
515 }
516
517 MEM(password = talloc_array(chain, char, max_password_len));
518
519 buf = fgets(password, max_password_len, cmd_pipe);
520 if (!buf || ferror(cmd_pipe)) {
521 pclose(cmd_pipe);
522 talloc_free(password);
523 cf_log_err(ci, "%s command failed: Unable to get private_key_password", cmd);
524 cf_log_err(ci, "Error reading private_key_file %s", chain->private_key_file);
525 return -1;
526 }
527 pclose(cmd_pipe);
528
529 /* Get rid of newline at end of password. */
530 for (buf = password; buf < (password + max_password_len); buf++) {
531 if ((unsigned char)*buf < ' ') {
532 *buf = '\0';
533 goto found;
534 }
535 }
536
537 talloc_free(password);
538 cf_log_err(ci, "%s command failed: Unable to get private_key_password", cmd);
539 cf_log_err(ci, "Error reading private_key_file %s - password is too long", chain->private_key_file);
540 return -1;
541
542found:
543 DEBUG3("Password from command = \"%s\"", password);
544 talloc_const_free(chain->password);
545 chain->password = password;
546
547 return 0;
548}
549#endif
550
551/** Free the OpenSSL objects that a chain section holds
552 */
553static int _tls_chain_conf_free(fr_tls_chain_conf_t *chain)
554{
555 if (chain->leaf) X509_free(chain->leaf);
556 if (chain->extra) sk_X509_pop_free(chain->extra, X509_free);
557 if (chain->private_key) EVP_PKEY_free(chain->private_key);
558
559 return 0;
560}
561
562/** Read one certificate from a file
563 *
564 * @param[in] ci for error messages.
565 * @param[in] fp positioned at the next certificate.
566 * @param[in] format SSL_FILETYPE_PEM or SSL_FILETYPE_ASN1.
567 * @param[in] aux read the PEM auxiliary trust data, as OpenSSL does for the leaf.
568 * @return
569 * - The certificate.
570 * - NULL at the end of a PEM file, with the error queue empty.
571 * - NULL on error, with the error left on the queue.
572 */
573static X509 *tls_chain_cert_read(CONF_ITEM *ci, FILE *fp, int format, bool aux)
574{
575 X509 *cert;
576
577 switch (format) {
578 case SSL_FILETYPE_PEM:
579 cert = aux ? PEM_read_X509_AUX(fp, NULL, NULL, NULL) : PEM_read_X509(fp, NULL, NULL, NULL);
580 if (!cert) {
581 unsigned long err = ERR_peek_last_error();
582
583 /*
584 * OpenSSL reports the end of a file by writing
585 * PEM_R_NO_START_LINE to the thread local buffer.
586 */
587 if ((ERR_GET_LIB(err) == ERR_LIB_PEM) && (ERR_GET_REASON(err) == PEM_R_NO_START_LINE)) {
588 ERR_clear_error();
589 }
590 }
591 return cert;
592
593 case SSL_FILETYPE_ASN1:
594 return d2i_X509_fp(fp, NULL);
595
596 default:
597 cf_log_err(ci, "Unknown certificate format %d", format);
598 return NULL;
599 }
600}
601
602/** Load the certificates and the private key of a `chain { ... }` section
603 *
604 * Reads certificate files in this order:
605 *
606 * 1. The leaf, then the remaining certificates, from certificate_file.
607 * 2. One certificate from each ca_file.
608 * 3. The private key from private_key_file.
609 *
610 * This callback stores the loaded objects in leaf, extra, and private_key,
611 * and records the earliest notAfter in valid_until.
612 */
613static int tls_chain_private_key_file_parse(TALLOC_CTX *ctx, void *out, void *parent, CONF_ITEM *ci, conf_parser_t const *rule)
614{
615 fr_tls_chain_conf_t *chain = talloc_get_type_abort(parent, fr_tls_chain_conf_t);
616 FILE *fp;
617 X509 *cert;
618 size_t i, ca_cnt;
619 int n;
620
621 if (cf_pair_parse_value(ctx, out, parent, ci, rule) < 0) return -1;
622
623#ifdef __APPLE__
624 if (tls_chain_password_certadmin(chain, ci) < 0) return -1;
625#endif
626
627 talloc_set_destructor(chain, _tls_chain_conf_free);
628
629 /*
630 * The leaf comes first, then the rest of the chain.
631 */
632 fp = fopen(chain->certificate_file, "r");
633 if (!fp) {
634 cf_log_err(ci, "Failed opening certificate_file \"%s\": %s", chain->certificate_file, fr_syserror(errno));
635 return -1;
636 }
637
638 chain->leaf = tls_chain_cert_read(ci, fp, chain->file_format, true);
639 if (!chain->leaf) {
640 fr_tls_strerror_printf("No certificate found");
641 cf_log_perr(ci, "Failed reading certificate_file \"%s\"", chain->certificate_file);
642 fclose(fp);
643 return -1;
644 }
645
646 MEM(chain->extra = sk_X509_new_null());
647 while ((cert = tls_chain_cert_read(ci, fp, chain->file_format, false))) {
648 if (chain->file_format != SSL_FILETYPE_PEM) {
649 X509_free(cert);
650 break; /* A DER file holds exactly one certificate */
651 }
652 MEM(sk_X509_push(chain->extra, cert) > 0);
653 }
654 fclose(fp);
655 if (ERR_peek_error()) {
656 fr_tls_strerror_printf(NULL);
657 cf_log_perr(ci, "Failed reading certificate_file \"%s\"", chain->certificate_file);
658 return -1;
659 }
660
661 /*
662 * One certificate per ca_file.
663 */
664 ca_cnt = chain->ca_files ? talloc_array_length(chain->ca_files) : 0;
665 for (i = 0; i < ca_cnt; i++) {
666 fp = fopen(chain->ca_files[i], "r");
667 if (!fp) {
668 cf_log_err(ci, "Failed opening ca_file \"%s\": %s", chain->ca_files[i], fr_syserror(errno));
669 return -1;
670 }
671 cert = tls_chain_cert_read(ci, fp, chain->file_format, false);
672 fclose(fp);
673 if (!cert) {
674 fr_tls_strerror_printf("No certificate found");
675 cf_log_perr(ci, "Failed reading ca_file \"%s\"", chain->ca_files[i]);
676 return -1;
677 }
678 MEM(sk_X509_push(chain->extra, cert) > 0);
679 }
680
681 /*
682 * The password callback stops OpenSSL prompting on stdin
683 * when the key is encrypted and no password is set.
684 */
685 fp = fopen(chain->private_key_file, "r");
686 if (!fp) {
687 cf_log_err(ci, "Failed opening private_key_file \"%s\": %s", chain->private_key_file, fr_syserror(errno));
688 return -1;
689 }
690 switch (chain->file_format) {
691 case SSL_FILETYPE_PEM:
692 chain->private_key = PEM_read_PrivateKey(fp, NULL, fr_tls_session_password_cb,
693 UNCONST(char *, chain->password));
694 break;
695
696 case SSL_FILETYPE_ASN1:
697 chain->private_key = d2i_PrivateKey_fp(fp, NULL);
698 break;
699
700 default:
701 fr_assert(0);
702 break;
703 }
704 fclose(fp);
705 if (!chain->private_key) {
706 fr_tls_strerror_printf(NULL);
707 cf_log_perr(ci, "Failed reading private_key_file \"%s\"", chain->private_key_file);
708 return -1;
709 }
710
711 if (X509_check_private_key(chain->leaf, chain->private_key) != 1) {
712 fr_tls_strerror_printf(NULL);
713 cf_log_perr(ci, "Private key does not match the certificate public key");
714 return -1;
715 }
716
717 /*
718 * Record the earliest notAfter.
719 */
720 chain->valid_until = fr_unix_time_wrap(0);
722DIAG_OFF(used-but-marked-unused) /* fix spurious warnings for sk macros */
723 for (n = -1; n < sk_X509_num(chain->extra); n++) {
724 time_t not_after;
725
726 cert = (n < 0) ? chain->leaf : sk_X509_value(chain->extra, n);
727 if (fr_tls_utils_asn1time_to_epoch(&not_after, X509_get0_notAfter(cert)) < 0) {
728 cf_log_perr(ci, "Failed parsing notAfter time of certificate %d in the chain", n + 2);
729 return -1;
730 }
731 if (!fr_unix_time_ispos(chain->valid_until) ||
732 fr_unix_time_gt(chain->valid_until, fr_unix_time_from_time(not_after))) {
733 chain->valid_until = fr_unix_time_from_time(not_after);
734 }
735 }
736DIAG_ON(used-but-marked-unused)
738
739 cf_log_debug(ci, "Certificate chain valid until %pV", fr_box_date(chain->valid_until));
740
741 return 0;
742}
743#endif /* WITH_TLS */
int n
Definition acutest.h:636
#define UNCONST(_type, _ptr)
Remove const qualification from a pointer.
Definition build.h:186
#define USES_APPLE_DEPRECATED_API
Definition build.h:547
#define RCSID(id)
Definition build.h:560
#define DIAG_UNKNOWN_PRAGMAS
Definition build.h:533
#define L(_str)
Helper for initialising arrays of string literals.
Definition build.h:228
#define DIAG_ON(_x)
Definition build.h:535
#define NUM_ELEMENTS(_t)
Definition build.h:406
#define DIAG_OFF(_x)
Definition build.h:534
int cf_table_parse_int(UNUSED TALLOC_CTX *ctx, void *out, UNUSED void *parent, CONF_ITEM *ci, conf_parser_t const *rule)
Generic function for parsing conf pair values as int.
Definition cf_parse.c:1802
int cf_pair_parse_value(TALLOC_CTX *ctx, void *out, UNUSED void *base, CONF_ITEM *ci, conf_parser_t const *rule)
Parses a CONF_PAIR into a C data type.
Definition cf_parse.c:252
#define CONF_PARSER_TERMINATOR
Definition cf_parse.h:696
cf_parse_t func
Override default parsing behaviour for the specified type with a custom parsing function.
Definition cf_parse.h:650
#define FR_CONF_V3_DEPRECATED(_name, _struct, _field)
conf_parser_t entry which raises an error if a deprecated v3 item is found
Definition cf_parse.h:430
#define FR_CONF_OFFSET(_name, _struct, _field)
conf_parser_t which parses a single CONF_PAIR, writing the result to a field in a struct
Definition cf_parse.h:280
#define FR_CONF_SUBSECTION_ALLOC_MULTI(_name, _flags, _struct, _field, _subcs)
conf_parser_t which allocates one struct for each instance of a subsection
Definition cf_parse.h:387
#define FR_CONF_OFFSET_IS_SET(_name, _type, _flags, _struct, _field)
conf_parser_t which parses a single CONF_PAIR, writing the result to a field in a struct,...
Definition cf_parse.h:294
#define FR_CONF_OFFSET_HINT_TYPE(_name, _type, _struct, _field)
conf_parser_t which parses a single CONF_PAIR, writing the result to a field in a struct
Definition cf_parse.h:253
#define FR_CONF_OFFSET_FLAGS(_name, _flags, _struct, _field)
conf_parser_t which parses a single CONF_PAIR, writing the result to a field in a struct
Definition cf_parse.h:268
#define FR_CONF_OFFSET_SUBSECTION(_name, _flags, _struct, _field, _subcs)
conf_parser_t which populates a sub-struct using a CONF_SECTION
Definition cf_parse.h:309
@ CONF_FLAG_REQUIRED
Error out if no matching CONF_PAIR is found, and no dflt value is set.
Definition cf_parse.h:450
@ CONF_FLAG_MULTI
CONF_PAIR can have multiple copies.
Definition cf_parse.h:467
@ CONF_FLAG_V3_DEPRECATED
If a matching CONF_PAIR is found, error out with a deprecated message.
Definition cf_parse.h:448
@ CONF_FLAG_SECRET
Only print value if debug level >= 3.
Definition cf_parse.h:454
@ CONF_FLAG_FILE_READABLE
File matching value must exist, and must be readable.
Definition cf_parse.h:456
@ CONF_FLAG_OK_MISSING
OK if it's missing.
Definition cf_parse.h:475
@ CONF_FLAG_FILE_EXISTS
File matching value must exist.
Definition cf_parse.h:462
#define FR_CONF_OFFSET_TYPE_FLAGS(_name, _type, _flags, _struct, _field)
conf_parser_t which parses a single CONF_PAIR, writing the result to a field in a struct
Definition cf_parse.h:238
Defines a CONF_PAIR to C data type mapping.
Definition cf_parse.h:633
Common header for all CONF_* types.
Definition cf_priv.h:54
A section grouping multiple CONF_PAIR.
Definition cf_priv.h:106
CONF_SECTION * cf_section_find(CONF_SECTION const *cs, char const *name1, char const *name2)
Find a CONF_SECTION with name1 and optionally name2.
Definition cf_util.c:1235
#define cf_log_err(_cf, _fmt,...)
Definition cf_util.h:340
#define cf_log_perr(_cf, _fmt,...)
Definition cf_util.h:347
#define cf_log_warn(_cf, _fmt,...)
Definition cf_util.h:341
#define cf_log_debug(_cf, _fmt,...)
Definition cf_util.h:343
#define CF_IDENT_ANY
Definition cf_util.h:80
#define MEM(x)
Definition debug.h:38
talloc_free(hp)
#define DEBUG3(_fmt,...)
Definition log.h:271
@ FR_TYPE_TIME_DELTA
A period of time measured in nanoseconds.
@ FR_TYPE_STRING
String of printable characters.
@ FR_TYPE_VOID
User data.
unsigned int uint32_t
unsigned char uint8_t
static size_t used
#define fr_assert(_expr)
Definition rad_assert.h:37
#define DEBUG2(fmt,...)
#define WARN(fmt,...)
static rs_t * conf
Definition radsniff.c:52
void fr_rand_buffer(void *start, size_t length)
Definition rand.c:124
PUBLIC int snprintf(char *string, size_t length, char *format, va_alist)
Definition snprintf.c:689
char const * fr_syserror(int num)
Guaranteed to be thread-safe version of strerror.
Definition syserror.c:243
An element in a lexicographically sorted array of name to num mappings.
Definition table.h:49
static int talloc_const_free(void const *ptr)
Free const'd memory.
Definition talloc.h:289
#define fr_unix_time_ispos(_a)
Definition time.h:372
static fr_time_delta_t fr_time_delta_from_sec(int64_t sec)
Definition time.h:590
#define fr_unix_time_gt(_a, _b)
Definition time.h:365
#define fr_unix_time_wrap(_time)
Definition time.h:160
static fr_unix_time_t fr_unix_time_from_time(time_t time)
Convert a time_t into out internal fr_unix_time_t.
Definition time.h:536
#define fr_time_delta_gt(_a, _b)
Definition time.h:283
A time delta, a difference in time measured in nanoseconds.
Definition time.h:80
@ T_DOUBLE_QUOTED_STRING
Definition token.h:119
static fr_slen_t parent
Definition pair.h:864
int fr_tls_utils_asn1time_to_epoch(time_t *out, ASN1_TIME const *asn1)
Convert OpenSSL's ASN1_TIME to an epoch time.
Definition utils.c:115
static fr_sbuff_err_t char size_t fr_sbuff_t size_t max
Definition value.h:1061
static fr_sbuff_err_t char ** out
Definition value.h:1061
#define fr_box_time_delta(_val)
Definition value.h:397
#define fr_box_date(_val)
Definition value.h:378
int virtual_server_cf_parse(UNUSED TALLOC_CTX *ctx, void *out, UNUSED void *parent, CONF_ITEM *ci, UNUSED conf_parser_t const *rule)
Wrapper for the config parser to allow pass1 resolution of virtual servers.
CONF_SECTION * virtual_server_cs(virtual_server_t const *vs)
Return the configuration section for a virtual server.