1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99
|
/*
* Copyright (c) 2023 Ricardo Filipe <ricardo.l.filipe@tecnico.ulisboa.pt>
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 as published
* by the Free Software Foundation, or (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program; if not, write to the Free Software
* Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
*
* As an additional exemption you are allowed to compile & link against the
* OpenSSL libraries as published by the OpenSSL project. See the file
* COPYING for details.
*
*/
#include "tls-test-validation.h"
#include "modules/afsocket/afsocket-signals.h"
#include "transport/tls-context.h"
#include "compat/openssl_support.h"
#define TLS_TEST_VALIDATION_PLUGIN "tls-test-validation"
struct _TlsTestValidationPlugin
{
LogDriverPlugin super;
gchar *identity;
};
void
tls_test_validation_plugin_set_identity(TlsTestValidationPlugin *self, const gchar *identity)
{
g_free(self->identity);
self->identity = g_strdup(identity);
}
static void
_slot_append_test_identity(TlsTestValidationPlugin *self, AFSocketTLSCertificateValidationSignalData *data)
{
X509 *cert = X509_STORE_CTX_get0_cert(data->ctx);
data->failure = !tls_context_verify_peer(data->tls_context, cert, self->identity);
msg_debug("TlsTestValidationPlugin validated");
}
static gboolean
_attach(LogDriverPlugin *s, LogDriver *driver)
{
g_assert(s->signal_connector == NULL);
s->signal_connector = signal_slot_connector_ref(driver->super.signal_slot_connector);
msg_debug("TlsTestValidationPlugin::attach()",
evt_tag_printf("SignalSlotConnector", "%p", s->signal_connector));
CONNECT(s->signal_connector, signal_afsocket_tls_certificate_validation, _slot_append_test_identity, s);
return TRUE;
}
static void
_detach(LogDriverPlugin *s, LogDriver *driver)
{
msg_debug("TlsTestValidationPlugin::detach()",
evt_tag_printf("SignalSlotConnector", "%p", s->signal_connector));
DISCONNECT(s->signal_connector, signal_afsocket_tls_certificate_validation, _slot_append_test_identity, s);
signal_slot_connector_unref(s->signal_connector);
s->signal_connector = NULL;
}
static void
_free(LogDriverPlugin *s)
{
msg_debug("TlsTestValidationPlugin::free");
TlsTestValidationPlugin *self = (TlsTestValidationPlugin *)s;
g_free(self->identity);
log_driver_plugin_free_method(s);
}
TlsTestValidationPlugin *
tls_test_validation_plugin_new(void)
{
TlsTestValidationPlugin *self = g_new0(TlsTestValidationPlugin, 1);
log_driver_plugin_init_instance(&self->super, TLS_TEST_VALIDATION_PLUGIN);
self->super.attach = _attach;
self->super.detach = _detach;
self->super.free_fn = _free;
return self;
}
|