2013-09-04 14:15:56 -04:00
|
|
|
#define RSTRING_NOT_MODIFIED 1
|
2015-09-18 12:43:51 -04:00
|
|
|
|
2012-08-22 19:53:25 -04:00
|
|
|
#include <ruby.h>
|
2016-02-25 16:50:38 -05:00
|
|
|
#include <ruby/version.h>
|
|
|
|
#include <ruby/io.h>
|
2015-09-18 12:43:51 -04:00
|
|
|
|
|
|
|
#ifdef HAVE_OPENSSL_BIO_H
|
|
|
|
|
2012-08-22 19:53:25 -04:00
|
|
|
#include <openssl/bio.h>
|
|
|
|
#include <openssl/ssl.h>
|
2014-05-25 17:25:11 -04:00
|
|
|
#include <openssl/dh.h>
|
2012-08-22 19:53:25 -04:00
|
|
|
#include <openssl/err.h>
|
2015-01-13 23:11:26 -05:00
|
|
|
#include <openssl/x509.h>
|
2012-08-22 19:53:25 -04:00
|
|
|
|
2015-11-06 18:27:43 -05:00
|
|
|
#ifndef SSL_OP_NO_COMPRESSION
|
|
|
|
#define SSL_OP_NO_COMPRESSION 0
|
|
|
|
#endif
|
|
|
|
|
2012-08-22 19:53:25 -04:00
|
|
|
typedef struct {
|
|
|
|
BIO* read;
|
|
|
|
BIO* write;
|
|
|
|
SSL* ssl;
|
|
|
|
SSL_CTX* ctx;
|
|
|
|
} ms_conn;
|
|
|
|
|
2015-01-13 23:11:26 -05:00
|
|
|
typedef struct {
|
|
|
|
unsigned char* buf;
|
|
|
|
int bytes;
|
|
|
|
} ms_cert_buf;
|
|
|
|
|
2021-01-26 16:18:51 -05:00
|
|
|
VALUE eError;
|
|
|
|
|
2020-10-16 09:36:08 -04:00
|
|
|
void engine_free(void *ptr) {
|
|
|
|
ms_conn *conn = ptr;
|
2015-01-13 23:11:26 -05:00
|
|
|
ms_cert_buf* cert_buf = (ms_cert_buf*)SSL_get_app_data(conn->ssl);
|
|
|
|
if(cert_buf) {
|
|
|
|
OPENSSL_free(cert_buf->buf);
|
|
|
|
free(cert_buf);
|
|
|
|
}
|
2014-09-04 23:57:06 -04:00
|
|
|
SSL_free(conn->ssl);
|
|
|
|
SSL_CTX_free(conn->ctx);
|
2012-08-22 19:53:25 -04:00
|
|
|
|
|
|
|
free(conn);
|
|
|
|
}
|
|
|
|
|
2020-10-16 09:36:08 -04:00
|
|
|
const rb_data_type_t engine_data_type = {
|
|
|
|
"MiniSSL/ENGINE",
|
|
|
|
{ 0, engine_free, 0 },
|
|
|
|
0, 0, RUBY_TYPED_FREE_IMMEDIATELY,
|
|
|
|
};
|
|
|
|
|
2014-05-25 17:25:11 -04:00
|
|
|
DH *get_dh1024() {
|
|
|
|
/* `openssl dhparam 1024 -C`
|
|
|
|
* -----BEGIN DH PARAMETERS-----
|
|
|
|
* MIGHAoGBALPwcEv0OstmQCZdfHw0N5r+07lmXMxkpQacy1blwj0LUqC+Divp6pBk
|
|
|
|
* usTJ9W2/dOYr1X7zi6yXNLp4oLzc/31PUL3D9q8CpGS7vPz5gijKSw9BwCTT5z9+
|
|
|
|
* KF9v46qw8XqT5HHV87sWFlGQcVFq+pEkA2kPikkKZ/X/CCcpCAV7AgEC
|
|
|
|
* -----END DH PARAMETERS-----
|
|
|
|
*/
|
|
|
|
static unsigned char dh1024_p[] = {
|
|
|
|
0xB3,0xF0,0x70,0x4B,0xF4,0x3A,0xCB,0x66,0x40,0x26,0x5D,0x7C,
|
|
|
|
0x7C,0x34,0x37,0x9A,0xFE,0xD3,0xB9,0x66,0x5C,0xCC,0x64,0xA5,
|
|
|
|
0x06,0x9C,0xCB,0x56,0xE5,0xC2,0x3D,0x0B,0x52,0xA0,0xBE,0x0E,
|
|
|
|
0x2B,0xE9,0xEA,0x90,0x64,0xBA,0xC4,0xC9,0xF5,0x6D,0xBF,0x74,
|
|
|
|
0xE6,0x2B,0xD5,0x7E,0xF3,0x8B,0xAC,0x97,0x34,0xBA,0x78,0xA0,
|
|
|
|
0xBC,0xDC,0xFF,0x7D,0x4F,0x50,0xBD,0xC3,0xF6,0xAF,0x02,0xA4,
|
|
|
|
0x64,0xBB,0xBC,0xFC,0xF9,0x82,0x28,0xCA,0x4B,0x0F,0x41,0xC0,
|
|
|
|
0x24,0xD3,0xE7,0x3F,0x7E,0x28,0x5F,0x6F,0xE3,0xAA,0xB0,0xF1,
|
|
|
|
0x7A,0x93,0xE4,0x71,0xD5,0xF3,0xBB,0x16,0x16,0x51,0x90,0x71,
|
|
|
|
0x51,0x6A,0xFA,0x91,0x24,0x03,0x69,0x0F,0x8A,0x49,0x0A,0x67,
|
|
|
|
0xF5,0xFF,0x08,0x27,0x29,0x08,0x05,0x7B
|
|
|
|
};
|
|
|
|
static unsigned char dh1024_g[] = { 0x02 };
|
|
|
|
|
|
|
|
DH *dh;
|
2020-12-01 08:51:16 -05:00
|
|
|
#if !(OPENSSL_VERSION_NUMBER < 0x10100005L || defined(LIBRESSL_VERSION_NUMBER))
|
|
|
|
BIGNUM *p, *g;
|
|
|
|
#endif
|
|
|
|
|
2014-05-25 17:25:11 -04:00
|
|
|
dh = DH_new();
|
2016-12-16 09:01:58 -05:00
|
|
|
|
2017-05-12 15:16:23 -04:00
|
|
|
#if OPENSSL_VERSION_NUMBER < 0x10100005L || defined(LIBRESSL_VERSION_NUMBER)
|
2014-05-25 17:25:11 -04:00
|
|
|
dh->p = BN_bin2bn(dh1024_p, sizeof(dh1024_p), NULL);
|
|
|
|
dh->g = BN_bin2bn(dh1024_g, sizeof(dh1024_g), NULL);
|
|
|
|
|
|
|
|
if ((dh->p == NULL) || (dh->g == NULL)) {
|
|
|
|
DH_free(dh);
|
|
|
|
return NULL;
|
|
|
|
}
|
2016-12-16 09:01:58 -05:00
|
|
|
#else
|
|
|
|
p = BN_bin2bn(dh1024_p, sizeof(dh1024_p), NULL);
|
|
|
|
g = BN_bin2bn(dh1024_g, sizeof(dh1024_g), NULL);
|
|
|
|
|
|
|
|
if (p == NULL || g == NULL || !DH_set0_pqg(dh, p, NULL, g)) {
|
|
|
|
DH_free(dh);
|
|
|
|
BN_free(p);
|
|
|
|
BN_free(g);
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
#endif
|
2014-05-25 17:25:11 -04:00
|
|
|
|
|
|
|
return dh;
|
|
|
|
}
|
|
|
|
|
2021-01-26 16:18:51 -05:00
|
|
|
static void
|
|
|
|
sslctx_free(void *ptr) {
|
|
|
|
SSL_CTX *ctx = ptr;
|
|
|
|
SSL_CTX_free(ctx);
|
|
|
|
}
|
|
|
|
|
|
|
|
static const rb_data_type_t sslctx_type = {
|
|
|
|
"MiniSSL/SSLContext",
|
|
|
|
{
|
|
|
|
0, sslctx_free,
|
|
|
|
},
|
|
|
|
0, 0, RUBY_TYPED_FREE_IMMEDIATELY,
|
|
|
|
};
|
|
|
|
|
|
|
|
ms_conn* engine_alloc(VALUE klass, VALUE* obj) {
|
|
|
|
ms_conn* conn;
|
|
|
|
|
|
|
|
*obj = TypedData_Make_Struct(klass, ms_conn, &engine_data_type, conn);
|
|
|
|
|
|
|
|
conn->read = BIO_new(BIO_s_mem());
|
|
|
|
BIO_set_nbio(conn->read, 1);
|
|
|
|
|
|
|
|
conn->write = BIO_new(BIO_s_mem());
|
|
|
|
BIO_set_nbio(conn->write, 1);
|
|
|
|
|
|
|
|
conn->ssl = 0;
|
|
|
|
conn->ctx = 0;
|
|
|
|
|
|
|
|
return conn;
|
|
|
|
}
|
|
|
|
|
2015-01-13 23:11:26 -05:00
|
|
|
static int engine_verify_callback(int preverify_ok, X509_STORE_CTX* ctx) {
|
|
|
|
X509* err_cert;
|
|
|
|
SSL* ssl;
|
|
|
|
int bytes;
|
|
|
|
unsigned char* buf = NULL;
|
|
|
|
|
|
|
|
if(!preverify_ok) {
|
|
|
|
err_cert = X509_STORE_CTX_get_current_cert(ctx);
|
|
|
|
if(err_cert) {
|
|
|
|
/*
|
|
|
|
* Save the failed certificate for inspection/logging.
|
|
|
|
*/
|
|
|
|
bytes = i2d_X509(err_cert, &buf);
|
|
|
|
if(bytes > 0) {
|
|
|
|
ms_cert_buf* cert_buf = (ms_cert_buf*)malloc(sizeof(ms_cert_buf));
|
|
|
|
cert_buf->buf = buf;
|
|
|
|
cert_buf->bytes = bytes;
|
|
|
|
ssl = X509_STORE_CTX_get_ex_data(ctx, SSL_get_ex_data_X509_STORE_CTX_idx());
|
|
|
|
SSL_set_app_data(ssl, cert_buf);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return preverify_ok;
|
|
|
|
}
|
|
|
|
|
2021-01-26 16:18:51 -05:00
|
|
|
static VALUE
|
|
|
|
sslctx_alloc(VALUE klass) {
|
|
|
|
SSL_CTX *ctx;
|
|
|
|
long mode = 0 |
|
|
|
|
SSL_MODE_ENABLE_PARTIAL_WRITE |
|
|
|
|
SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER |
|
|
|
|
SSL_MODE_RELEASE_BUFFERS;
|
|
|
|
|
|
|
|
#ifdef HAVE_TLS_SERVER_METHOD
|
|
|
|
ctx = SSL_CTX_new(TLS_method());
|
|
|
|
// printf("\nctx using TLS_method security_level %d\n", SSL_CTX_get_security_level(ctx));
|
|
|
|
#else
|
|
|
|
ctx = SSL_CTX_new(SSLv23_method());
|
|
|
|
#endif
|
|
|
|
if (!ctx) {
|
|
|
|
rb_raise(eError, "SSL_CTX_new");
|
|
|
|
}
|
|
|
|
SSL_CTX_set_mode(ctx, mode);
|
|
|
|
|
|
|
|
return TypedData_Wrap_Struct(klass, &sslctx_type, ctx);
|
|
|
|
}
|
|
|
|
|
|
|
|
VALUE
|
|
|
|
sslctx_initialize(VALUE self, VALUE mini_ssl_ctx) {
|
2012-11-29 14:34:46 -05:00
|
|
|
SSL_CTX* ctx;
|
2021-01-26 16:18:51 -05:00
|
|
|
|
2020-12-01 08:51:16 -05:00
|
|
|
#ifdef HAVE_SSL_CTX_SET_MIN_PROTO_VERSION
|
|
|
|
int min;
|
|
|
|
#endif
|
|
|
|
int ssl_options;
|
2021-01-26 16:18:51 -05:00
|
|
|
VALUE key, cert, ca, verify_mode, ssl_cipher_filter, no_tlsv1, no_tlsv1_1,
|
|
|
|
verification_flags;
|
2020-12-01 08:51:16 -05:00
|
|
|
DH *dh;
|
|
|
|
|
|
|
|
#if OPENSSL_VERSION_NUMBER < 0x10002000L
|
|
|
|
EC_KEY *ecdh;
|
|
|
|
#endif
|
2012-11-29 14:34:46 -05:00
|
|
|
|
2021-01-26 16:18:51 -05:00
|
|
|
TypedData_Get_Struct(self, SSL_CTX, &sslctx_type, ctx);
|
2014-05-05 17:30:15 -04:00
|
|
|
|
2021-01-26 16:18:51 -05:00
|
|
|
key = rb_funcall(mini_ssl_ctx, rb_intern_const("key"), 0);
|
2016-07-24 17:29:23 -04:00
|
|
|
StringValue(key);
|
|
|
|
|
2021-01-26 16:18:51 -05:00
|
|
|
cert = rb_funcall(mini_ssl_ctx, rb_intern_const("cert"), 0);
|
2016-07-24 17:29:23 -04:00
|
|
|
StringValue(cert);
|
|
|
|
|
2021-01-26 16:18:51 -05:00
|
|
|
ca = rb_funcall(mini_ssl_ctx, rb_intern_const("ca"), 0);
|
2015-01-13 23:11:26 -05:00
|
|
|
|
2021-01-26 16:18:51 -05:00
|
|
|
verify_mode = rb_funcall(mini_ssl_ctx, rb_intern_const("verify_mode"), 0);
|
2015-01-13 23:11:26 -05:00
|
|
|
|
2021-01-26 16:18:51 -05:00
|
|
|
ssl_cipher_filter = rb_funcall(mini_ssl_ctx, rb_intern_const("ssl_cipher_filter"), 0);
|
2017-11-24 10:14:23 -05:00
|
|
|
|
2021-01-26 16:18:51 -05:00
|
|
|
no_tlsv1 = rb_funcall(mini_ssl_ctx, rb_intern_const("no_tlsv1"), 0);
|
2018-04-17 09:25:22 -04:00
|
|
|
|
2021-01-26 16:18:51 -05:00
|
|
|
no_tlsv1_1 = rb_funcall(mini_ssl_ctx, rb_intern_const("no_tlsv1_1"), 0);
|
2012-08-22 19:53:25 -04:00
|
|
|
|
2015-10-20 03:22:59 -04:00
|
|
|
SSL_CTX_use_certificate_chain_file(ctx, RSTRING_PTR(cert));
|
2012-08-23 00:43:40 -04:00
|
|
|
SSL_CTX_use_PrivateKey_file(ctx, RSTRING_PTR(key), SSL_FILETYPE_PEM);
|
2015-01-13 23:11:26 -05:00
|
|
|
|
2021-01-26 16:18:51 -05:00
|
|
|
verification_flags = rb_funcall(mini_ssl_ctx, rb_intern_const("verification_flags"), 0);
|
2020-12-07 18:21:23 -05:00
|
|
|
|
|
|
|
if (!NIL_P(verification_flags)) {
|
|
|
|
X509_VERIFY_PARAM *param = SSL_CTX_get0_param(ctx);
|
|
|
|
X509_VERIFY_PARAM_set_flags(param, NUM2INT(verification_flags));
|
|
|
|
SSL_CTX_set1_param(ctx, param);
|
|
|
|
}
|
|
|
|
|
2015-01-13 23:11:26 -05:00
|
|
|
if (!NIL_P(ca)) {
|
2016-07-24 17:29:23 -04:00
|
|
|
StringValue(ca);
|
2015-01-13 23:11:26 -05:00
|
|
|
SSL_CTX_load_verify_locations(ctx, RSTRING_PTR(ca), NULL);
|
|
|
|
}
|
2016-11-22 09:54:30 -05:00
|
|
|
|
2019-07-09 17:28:07 -04:00
|
|
|
ssl_options = SSL_OP_CIPHER_SERVER_PREFERENCE | SSL_OP_SINGLE_ECDH_USE | SSL_OP_NO_COMPRESSION;
|
2018-04-17 09:25:22 -04:00
|
|
|
|
2019-07-09 17:28:07 -04:00
|
|
|
#ifdef HAVE_SSL_CTX_SET_MIN_PROTO_VERSION
|
|
|
|
if (RTEST(no_tlsv1_1)) {
|
|
|
|
min = TLS1_2_VERSION;
|
|
|
|
}
|
|
|
|
else if (RTEST(no_tlsv1)) {
|
|
|
|
min = TLS1_1_VERSION;
|
|
|
|
}
|
|
|
|
else {
|
|
|
|
min = TLS1_VERSION;
|
|
|
|
}
|
2020-10-16 09:36:08 -04:00
|
|
|
|
2019-07-09 17:28:07 -04:00
|
|
|
SSL_CTX_set_min_proto_version(ctx, min);
|
|
|
|
|
|
|
|
SSL_CTX_set_options(ctx, ssl_options);
|
|
|
|
|
|
|
|
#else
|
|
|
|
/* As of 1.0.2f, SSL_OP_SINGLE_DH_USE key use is always on */
|
|
|
|
ssl_options |= SSL_OP_NO_SSLv2 | SSL_OP_NO_SSLv3 | SSL_OP_SINGLE_DH_USE;
|
|
|
|
|
|
|
|
if (RTEST(no_tlsv1)) {
|
2018-04-17 09:25:22 -04:00
|
|
|
ssl_options |= SSL_OP_NO_TLSv1;
|
|
|
|
}
|
2019-07-09 17:28:07 -04:00
|
|
|
if(RTEST(no_tlsv1_1)) {
|
|
|
|
ssl_options |= SSL_OP_NO_TLSv1 | SSL_OP_NO_TLSv1_1;
|
|
|
|
}
|
2018-04-17 09:25:22 -04:00
|
|
|
SSL_CTX_set_options(ctx, ssl_options);
|
2019-07-09 17:28:07 -04:00
|
|
|
#endif
|
|
|
|
|
2014-05-25 17:25:11 -04:00
|
|
|
SSL_CTX_set_session_cache_mode(ctx, SSL_SESS_CACHE_OFF);
|
|
|
|
|
2017-11-24 10:14:23 -05:00
|
|
|
if (!NIL_P(ssl_cipher_filter)) {
|
|
|
|
StringValue(ssl_cipher_filter);
|
|
|
|
SSL_CTX_set_cipher_list(ctx, RSTRING_PTR(ssl_cipher_filter));
|
|
|
|
}
|
|
|
|
else {
|
|
|
|
SSL_CTX_set_cipher_list(ctx, "HIGH:!aNULL@STRENGTH");
|
|
|
|
}
|
2014-05-25 17:25:11 -04:00
|
|
|
|
2020-12-01 08:51:16 -05:00
|
|
|
dh = get_dh1024();
|
2014-05-25 17:25:11 -04:00
|
|
|
SSL_CTX_set_tmp_dh(ctx, dh);
|
|
|
|
|
2018-11-01 21:36:22 -04:00
|
|
|
#if OPENSSL_VERSION_NUMBER < 0x10002000L
|
|
|
|
// Remove this case if OpenSSL 1.0.1 (now EOL) support is no
|
|
|
|
// longer needed.
|
2020-12-01 08:51:16 -05:00
|
|
|
ecdh = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
|
2014-05-25 17:25:11 -04:00
|
|
|
if (ecdh) {
|
|
|
|
SSL_CTX_set_tmp_ecdh(ctx, ecdh);
|
|
|
|
EC_KEY_free(ecdh);
|
|
|
|
}
|
2018-11-01 21:36:22 -04:00
|
|
|
#elif OPENSSL_VERSION_NUMBER < 0x10100000L || defined(LIBRESSL_VERSION_NUMBER)
|
|
|
|
SSL_CTX_set_ecdh_auto(ctx, 1);
|
2015-08-12 10:28:01 -04:00
|
|
|
#endif
|
2012-08-22 19:53:25 -04:00
|
|
|
|
2015-01-13 23:11:26 -05:00
|
|
|
if (NIL_P(verify_mode)) {
|
2021-01-26 16:18:51 -05:00
|
|
|
/* SSL_CTX_set_verify(ctx, SSL_VERIFY_NONE, NULL); */
|
2015-01-13 23:11:26 -05:00
|
|
|
} else {
|
2021-01-26 16:18:51 -05:00
|
|
|
SSL_CTX_set_verify(ctx, NUM2INT(verify_mode), engine_verify_callback);
|
2015-01-13 23:11:26 -05:00
|
|
|
}
|
2021-01-26 16:18:51 -05:00
|
|
|
// printf("\ninitialize end security_level %d\n", SSL_CTX_get_security_level(ctx));
|
|
|
|
rb_obj_freeze(self);
|
|
|
|
return self;
|
|
|
|
}
|
2012-08-22 19:53:25 -04:00
|
|
|
|
2021-01-26 16:18:51 -05:00
|
|
|
VALUE engine_init_server(VALUE self, VALUE sslctx) {
|
|
|
|
ms_conn* conn;
|
|
|
|
VALUE obj;
|
|
|
|
SSL_CTX* ctx;
|
|
|
|
SSL* ssl;
|
2012-08-22 19:53:25 -04:00
|
|
|
|
2021-01-26 16:18:51 -05:00
|
|
|
conn = engine_alloc(self, &obj);
|
|
|
|
|
|
|
|
TypedData_Get_Struct(sslctx, SSL_CTX, &sslctx_type, ctx);
|
|
|
|
|
|
|
|
ssl = SSL_new(ctx);
|
|
|
|
conn->ssl = ssl;
|
|
|
|
SSL_set_app_data(ssl, NULL);
|
|
|
|
SSL_set_bio(ssl, conn->read, conn->write);
|
2012-08-22 19:53:25 -04:00
|
|
|
SSL_set_accept_state(ssl);
|
|
|
|
return obj;
|
|
|
|
}
|
|
|
|
|
|
|
|
VALUE engine_init_client(VALUE klass) {
|
|
|
|
VALUE obj;
|
|
|
|
ms_conn* conn = engine_alloc(klass, &obj);
|
2019-07-08 15:49:45 -04:00
|
|
|
#ifdef HAVE_DTLS_METHOD
|
2018-12-02 15:02:26 -05:00
|
|
|
conn->ctx = SSL_CTX_new(DTLS_method());
|
2019-07-08 15:49:45 -04:00
|
|
|
#else
|
|
|
|
conn->ctx = SSL_CTX_new(DTLSv1_method());
|
|
|
|
#endif
|
2012-08-22 19:53:25 -04:00
|
|
|
conn->ssl = SSL_new(conn->ctx);
|
2015-01-13 23:11:26 -05:00
|
|
|
SSL_set_app_data(conn->ssl, NULL);
|
2012-08-22 19:53:25 -04:00
|
|
|
SSL_set_verify(conn->ssl, SSL_VERIFY_NONE, NULL);
|
|
|
|
|
|
|
|
SSL_set_bio(conn->ssl, conn->read, conn->write);
|
|
|
|
|
|
|
|
SSL_set_connect_state(conn->ssl);
|
|
|
|
return obj;
|
|
|
|
}
|
|
|
|
|
2012-08-23 00:43:40 -04:00
|
|
|
VALUE engine_inject(VALUE self, VALUE str) {
|
2012-08-22 19:53:25 -04:00
|
|
|
ms_conn* conn;
|
|
|
|
long used;
|
|
|
|
|
2020-10-16 09:36:08 -04:00
|
|
|
TypedData_Get_Struct(self, ms_conn, &engine_data_type, conn);
|
2012-08-22 19:53:25 -04:00
|
|
|
|
|
|
|
StringValue(str);
|
|
|
|
|
2012-11-29 14:34:46 -05:00
|
|
|
used = BIO_write(conn->read, RSTRING_PTR(str), (int)RSTRING_LEN(str));
|
2012-08-22 19:53:25 -04:00
|
|
|
|
|
|
|
if(used == 0 || used == -1) {
|
|
|
|
return Qfalse;
|
|
|
|
}
|
|
|
|
|
|
|
|
return INT2FIX(used);
|
|
|
|
}
|
|
|
|
|
2020-12-01 08:51:16 -05:00
|
|
|
NORETURN(void raise_error(SSL* ssl, int result));
|
|
|
|
|
2012-08-22 19:53:25 -04:00
|
|
|
void raise_error(SSL* ssl, int result) {
|
2015-01-13 23:11:26 -05:00
|
|
|
char buf[512];
|
|
|
|
char msg[512];
|
|
|
|
const char* err_str;
|
|
|
|
int err = errno;
|
2020-05-13 11:48:34 -04:00
|
|
|
int mask = 4095;
|
2015-01-13 23:11:26 -05:00
|
|
|
int ssl_err = SSL_get_error(ssl, result);
|
2017-08-08 19:01:16 -04:00
|
|
|
int verify_err = (int) SSL_get_verify_result(ssl);
|
2015-01-13 23:11:26 -05:00
|
|
|
|
|
|
|
if(SSL_ERROR_SYSCALL == ssl_err) {
|
2015-07-15 01:07:37 -04:00
|
|
|
snprintf(msg, sizeof(msg), "System error: %s - %d", strerror(err), err);
|
2015-01-13 23:11:26 -05:00
|
|
|
|
|
|
|
} else if(SSL_ERROR_SSL == ssl_err) {
|
|
|
|
if(X509_V_OK != verify_err) {
|
|
|
|
err_str = X509_verify_cert_error_string(verify_err);
|
|
|
|
snprintf(msg, sizeof(msg),
|
|
|
|
"OpenSSL certificate verification error: %s - %d",
|
|
|
|
err_str, verify_err);
|
|
|
|
|
|
|
|
} else {
|
2017-08-08 19:01:16 -04:00
|
|
|
err = (int) ERR_get_error();
|
2015-01-13 23:11:26 -05:00
|
|
|
ERR_error_string_n(err, buf, sizeof(buf));
|
2020-12-01 08:51:16 -05:00
|
|
|
snprintf(msg, sizeof(msg), "OpenSSL error: %s - %d", buf, err & mask);
|
2015-01-13 23:11:26 -05:00
|
|
|
}
|
|
|
|
} else {
|
|
|
|
snprintf(msg, sizeof(msg), "Unknown OpenSSL error: %d", ssl_err);
|
|
|
|
}
|
2012-08-22 19:53:25 -04:00
|
|
|
|
2012-08-23 01:34:10 -04:00
|
|
|
ERR_clear_error();
|
2015-07-16 12:57:08 -04:00
|
|
|
rb_raise(eError, "%s", msg);
|
2012-08-22 19:53:25 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
VALUE engine_read(VALUE self) {
|
|
|
|
ms_conn* conn;
|
|
|
|
char buf[512];
|
2016-01-14 21:44:59 -05:00
|
|
|
int bytes, error;
|
2012-08-22 19:53:25 -04:00
|
|
|
|
2020-10-16 09:36:08 -04:00
|
|
|
TypedData_Get_Struct(self, ms_conn, &engine_data_type, conn);
|
2012-08-22 19:53:25 -04:00
|
|
|
|
2015-01-13 23:11:26 -05:00
|
|
|
ERR_clear_error();
|
|
|
|
|
2012-08-22 19:53:25 -04:00
|
|
|
bytes = SSL_read(conn->ssl, (void*)buf, sizeof(buf));
|
|
|
|
|
|
|
|
if(bytes > 0) {
|
|
|
|
return rb_str_new(buf, bytes);
|
|
|
|
}
|
|
|
|
|
|
|
|
if(SSL_want_read(conn->ssl)) return Qnil;
|
|
|
|
|
2015-05-01 19:39:22 -04:00
|
|
|
error = SSL_get_error(conn->ssl, bytes);
|
2015-01-13 23:11:26 -05:00
|
|
|
|
|
|
|
if(error == SSL_ERROR_ZERO_RETURN) {
|
2012-08-23 01:34:10 -04:00
|
|
|
rb_eof_error();
|
2015-01-13 23:11:26 -05:00
|
|
|
} else {
|
|
|
|
raise_error(conn->ssl, bytes);
|
2012-08-23 01:34:10 -04:00
|
|
|
}
|
|
|
|
|
2012-08-23 01:38:41 -04:00
|
|
|
return Qnil;
|
2012-08-22 19:53:25 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
VALUE engine_write(VALUE self, VALUE str) {
|
|
|
|
ms_conn* conn;
|
|
|
|
int bytes;
|
|
|
|
|
2020-10-16 09:36:08 -04:00
|
|
|
TypedData_Get_Struct(self, ms_conn, &engine_data_type, conn);
|
2012-08-22 19:53:25 -04:00
|
|
|
|
|
|
|
StringValue(str);
|
|
|
|
|
2015-01-13 23:11:26 -05:00
|
|
|
ERR_clear_error();
|
|
|
|
|
2012-11-29 14:34:46 -05:00
|
|
|
bytes = SSL_write(conn->ssl, (void*)RSTRING_PTR(str), (int)RSTRING_LEN(str));
|
2012-08-22 19:53:25 -04:00
|
|
|
if(bytes > 0) {
|
|
|
|
return INT2FIX(bytes);
|
|
|
|
}
|
|
|
|
|
|
|
|
if(SSL_want_write(conn->ssl)) return Qnil;
|
|
|
|
|
|
|
|
raise_error(conn->ssl, bytes);
|
2012-08-23 01:38:41 -04:00
|
|
|
|
|
|
|
return Qnil;
|
2012-08-22 19:53:25 -04:00
|
|
|
}
|
|
|
|
|
2012-08-23 00:43:40 -04:00
|
|
|
VALUE engine_extract(VALUE self) {
|
2012-08-22 19:53:25 -04:00
|
|
|
ms_conn* conn;
|
|
|
|
int bytes;
|
|
|
|
size_t pending;
|
2021-01-26 16:18:51 -05:00
|
|
|
// https://www.openssl.org/docs/manmaster/man3/BIO_f_buffer.html
|
|
|
|
// crypto/bio/bf_buff.c DEFAULT_BUFFER_SIZE
|
|
|
|
char buf[4096];
|
2012-08-22 19:53:25 -04:00
|
|
|
|
2020-10-16 09:36:08 -04:00
|
|
|
TypedData_Get_Struct(self, ms_conn, &engine_data_type, conn);
|
2012-08-22 19:53:25 -04:00
|
|
|
|
|
|
|
pending = BIO_pending(conn->write);
|
|
|
|
if(pending > 0) {
|
|
|
|
bytes = BIO_read(conn->write, buf, sizeof(buf));
|
|
|
|
if(bytes > 0) {
|
|
|
|
return rb_str_new(buf, bytes);
|
|
|
|
} else if(!BIO_should_retry(conn->write)) {
|
|
|
|
raise_error(conn->ssl, bytes);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return Qnil;
|
|
|
|
}
|
|
|
|
|
2016-07-25 20:20:17 -04:00
|
|
|
VALUE engine_shutdown(VALUE self) {
|
|
|
|
ms_conn* conn;
|
2016-11-22 09:54:30 -05:00
|
|
|
int ok;
|
2016-07-25 20:20:17 -04:00
|
|
|
|
2020-10-16 09:36:08 -04:00
|
|
|
TypedData_Get_Struct(self, ms_conn, &engine_data_type, conn);
|
2016-07-25 20:20:17 -04:00
|
|
|
|
|
|
|
ERR_clear_error();
|
|
|
|
|
|
|
|
ok = SSL_shutdown(conn->ssl);
|
|
|
|
if (ok == 0) {
|
|
|
|
return Qfalse;
|
|
|
|
}
|
|
|
|
|
|
|
|
return Qtrue;
|
|
|
|
}
|
|
|
|
|
|
|
|
VALUE engine_init(VALUE self) {
|
|
|
|
ms_conn* conn;
|
|
|
|
|
2020-10-16 09:36:08 -04:00
|
|
|
TypedData_Get_Struct(self, ms_conn, &engine_data_type, conn);
|
2016-07-25 20:20:17 -04:00
|
|
|
|
|
|
|
return SSL_in_init(conn->ssl) ? Qtrue : Qfalse;
|
|
|
|
}
|
|
|
|
|
2015-01-13 23:11:26 -05:00
|
|
|
VALUE engine_peercert(VALUE self) {
|
|
|
|
ms_conn* conn;
|
|
|
|
X509* cert;
|
|
|
|
int bytes;
|
|
|
|
unsigned char* buf = NULL;
|
|
|
|
ms_cert_buf* cert_buf = NULL;
|
|
|
|
VALUE rb_cert_buf;
|
|
|
|
|
2020-10-16 09:36:08 -04:00
|
|
|
TypedData_Get_Struct(self, ms_conn, &engine_data_type, conn);
|
2015-01-13 23:11:26 -05:00
|
|
|
|
|
|
|
cert = SSL_get_peer_certificate(conn->ssl);
|
|
|
|
if(!cert) {
|
|
|
|
/*
|
|
|
|
* See if there was a failed certificate associated with this client.
|
|
|
|
*/
|
|
|
|
cert_buf = (ms_cert_buf*)SSL_get_app_data(conn->ssl);
|
|
|
|
if(!cert_buf) {
|
|
|
|
return Qnil;
|
|
|
|
}
|
|
|
|
buf = cert_buf->buf;
|
|
|
|
bytes = cert_buf->bytes;
|
|
|
|
|
|
|
|
} else {
|
|
|
|
bytes = i2d_X509(cert, &buf);
|
|
|
|
X509_free(cert);
|
|
|
|
|
|
|
|
if(bytes < 0) {
|
|
|
|
return Qnil;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2016-02-25 16:50:38 -05:00
|
|
|
rb_cert_buf = rb_str_new((const char*)(buf), bytes);
|
2015-01-13 23:11:26 -05:00
|
|
|
if(!cert_buf) {
|
|
|
|
OPENSSL_free(buf);
|
|
|
|
}
|
|
|
|
|
|
|
|
return rb_cert_buf;
|
|
|
|
}
|
|
|
|
|
2020-09-17 11:15:19 -04:00
|
|
|
/* @see Puma::MiniSSL::Socket#ssl_version_state
|
|
|
|
* @version 5.0.0
|
|
|
|
*/
|
2020-05-13 11:48:34 -04:00
|
|
|
static VALUE
|
|
|
|
engine_ssl_vers_st(VALUE self) {
|
|
|
|
ms_conn* conn;
|
2020-10-16 09:36:08 -04:00
|
|
|
TypedData_Get_Struct(self, ms_conn, &engine_data_type, conn);
|
2020-05-13 11:48:34 -04:00
|
|
|
return rb_ary_new3(2, rb_str_new2(SSL_get_version(conn->ssl)), rb_str_new2(SSL_state_string(conn->ssl)));
|
|
|
|
}
|
|
|
|
|
2015-09-18 12:43:51 -04:00
|
|
|
VALUE noop(VALUE self) {
|
|
|
|
return Qnil;
|
|
|
|
}
|
|
|
|
|
2012-08-23 01:12:12 -04:00
|
|
|
void Init_mini_ssl(VALUE puma) {
|
2021-01-26 16:18:51 -05:00
|
|
|
VALUE mod, eng, sslctx;
|
2012-11-29 14:34:46 -05:00
|
|
|
|
2017-10-16 09:42:16 -04:00
|
|
|
/* Fake operation for documentation (RDoc, YARD) */
|
|
|
|
#if 0 == 1
|
|
|
|
puma = rb_define_module("Puma");
|
|
|
|
#endif
|
|
|
|
|
2012-08-23 00:43:40 -04:00
|
|
|
SSL_library_init();
|
|
|
|
OpenSSL_add_ssl_algorithms();
|
|
|
|
SSL_load_error_strings();
|
|
|
|
ERR_load_crypto_strings();
|
2016-11-22 09:54:30 -05:00
|
|
|
|
2012-11-29 14:34:46 -05:00
|
|
|
mod = rb_define_module_under(puma, "MiniSSL");
|
|
|
|
eng = rb_define_class_under(mod, "Engine", rb_cObject);
|
2021-01-26 16:18:51 -05:00
|
|
|
sslctx = rb_define_class_under(mod, "SSLContext", rb_cObject);
|
|
|
|
rb_define_alloc_func(sslctx, sslctx_alloc);
|
|
|
|
rb_define_method(sslctx, "initialize", sslctx_initialize, 1);
|
|
|
|
rb_undef_method(sslctx, "initialize_copy");
|
|
|
|
|
2012-08-22 19:53:25 -04:00
|
|
|
|
2018-08-21 21:10:02 -04:00
|
|
|
// OpenSSL Build / Runtime/Load versions
|
|
|
|
|
|
|
|
/* Version of OpenSSL that Puma was compiled with */
|
2019-07-09 17:28:07 -04:00
|
|
|
rb_define_const(mod, "OPENSSL_VERSION", rb_str_new2(OPENSSL_VERSION_TEXT));
|
2018-08-21 21:10:02 -04:00
|
|
|
|
|
|
|
#if !defined(LIBRESSL_VERSION_NUMBER) && OPENSSL_VERSION_NUMBER >= 0x10100000
|
2019-07-09 17:28:07 -04:00
|
|
|
/* Version of OpenSSL that Puma loaded with */
|
|
|
|
rb_define_const(mod, "OPENSSL_LIBRARY_VERSION", rb_str_new2(OpenSSL_version(OPENSSL_VERSION)));
|
2018-08-21 21:10:02 -04:00
|
|
|
#else
|
2019-07-09 17:28:07 -04:00
|
|
|
rb_define_const(mod, "OPENSSL_LIBRARY_VERSION", rb_str_new2(SSLeay_version(SSLEAY_VERSION)));
|
2018-08-21 21:10:02 -04:00
|
|
|
#endif
|
2020-10-16 09:36:08 -04:00
|
|
|
|
|
|
|
#if defined(OPENSSL_NO_SSL3) || defined(OPENSSL_NO_SSL3_METHOD)
|
|
|
|
/* True if SSL3 is not available */
|
|
|
|
rb_define_const(mod, "OPENSSL_NO_SSL3", Qtrue);
|
|
|
|
#else
|
|
|
|
rb_define_const(mod, "OPENSSL_NO_SSL3", Qfalse);
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#if defined(OPENSSL_NO_TLS1) || defined(OPENSSL_NO_TLS1_METHOD)
|
|
|
|
/* True if TLS1 is not available */
|
|
|
|
rb_define_const(mod, "OPENSSL_NO_TLS1", Qtrue);
|
|
|
|
#else
|
|
|
|
rb_define_const(mod, "OPENSSL_NO_TLS1", Qfalse);
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#if defined(OPENSSL_NO_TLS1_1) || defined(OPENSSL_NO_TLS1_1_METHOD)
|
|
|
|
/* True if TLS1_1 is not available */
|
|
|
|
rb_define_const(mod, "OPENSSL_NO_TLS1_1", Qtrue);
|
|
|
|
#else
|
|
|
|
rb_define_const(mod, "OPENSSL_NO_TLS1_1", Qfalse);
|
|
|
|
#endif
|
2018-08-21 21:10:02 -04:00
|
|
|
|
2015-09-18 12:43:51 -04:00
|
|
|
rb_define_singleton_method(mod, "check", noop, 0);
|
|
|
|
|
2012-08-22 19:53:25 -04:00
|
|
|
eError = rb_define_class_under(mod, "SSLError", rb_eStandardError);
|
|
|
|
|
2014-05-05 17:30:15 -04:00
|
|
|
rb_define_singleton_method(eng, "server", engine_init_server, 1);
|
2012-08-22 19:53:25 -04:00
|
|
|
rb_define_singleton_method(eng, "client", engine_init_client, 0);
|
|
|
|
|
2012-08-23 00:43:40 -04:00
|
|
|
rb_define_method(eng, "inject", engine_inject, 1);
|
2012-08-22 19:53:25 -04:00
|
|
|
rb_define_method(eng, "read", engine_read, 0);
|
|
|
|
|
|
|
|
rb_define_method(eng, "write", engine_write, 1);
|
2012-08-23 00:43:40 -04:00
|
|
|
rb_define_method(eng, "extract", engine_extract, 0);
|
2015-01-13 23:11:26 -05:00
|
|
|
|
2016-07-25 20:20:17 -04:00
|
|
|
rb_define_method(eng, "shutdown", engine_shutdown, 0);
|
|
|
|
|
|
|
|
rb_define_method(eng, "init?", engine_init, 0);
|
|
|
|
|
2015-01-13 23:11:26 -05:00
|
|
|
rb_define_method(eng, "peercert", engine_peercert, 0);
|
2020-05-13 11:48:34 -04:00
|
|
|
|
|
|
|
rb_define_method(eng, "ssl_vers_st", engine_ssl_vers_st, 0);
|
2012-08-22 19:53:25 -04:00
|
|
|
}
|
2015-09-18 12:43:51 -04:00
|
|
|
|
|
|
|
#else
|
|
|
|
|
2020-12-01 08:51:16 -05:00
|
|
|
NORETURN(VALUE raise_error(VALUE self));
|
|
|
|
|
2015-09-18 12:43:51 -04:00
|
|
|
VALUE raise_error(VALUE self) {
|
|
|
|
rb_raise(rb_eStandardError, "SSL not available in this build");
|
|
|
|
}
|
|
|
|
|
|
|
|
void Init_mini_ssl(VALUE puma) {
|
2017-09-13 00:13:03 -04:00
|
|
|
VALUE mod;
|
2015-09-18 12:43:51 -04:00
|
|
|
|
|
|
|
mod = rb_define_module_under(puma, "MiniSSL");
|
|
|
|
rb_define_class_under(mod, "SSLError", rb_eStandardError);
|
|
|
|
|
|
|
|
rb_define_singleton_method(mod, "check", raise_error, 0);
|
|
|
|
}
|
|
|
|
#endif
|