SslStreamSecurityUpgradeProvider.cs 51 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334
  1. //------------------------------------------------------------
  2. // Copyright (c) Microsoft Corporation. All rights reserved.
  3. //------------------------------------------------------------
  4. namespace System.ServiceModel.Channels
  5. {
  6. using System.Collections.ObjectModel;
  7. using System.Diagnostics;
  8. using System.IdentityModel.Policy;
  9. using System.IdentityModel.Selectors;
  10. using System.IdentityModel.Tokens;
  11. using System.IO;
  12. using System.Net.Security;
  13. using System.Runtime;
  14. using System.Runtime.Diagnostics;
  15. using System.Security.Authentication;
  16. using System.Security.Authentication.ExtendedProtection;
  17. using System.Security.Cryptography.X509Certificates;
  18. using System.ServiceModel;
  19. using System.ServiceModel.Description;
  20. using System.ServiceModel.Diagnostics;
  21. using System.ServiceModel.Diagnostics.Application;
  22. using System.ServiceModel.Security;
  23. using System.ServiceModel.Security.Tokens;
  24. class SslStreamSecurityUpgradeProvider : StreamSecurityUpgradeProvider, IStreamUpgradeChannelBindingProvider
  25. {
  26. SecurityTokenAuthenticator clientCertificateAuthenticator;
  27. SecurityTokenManager clientSecurityTokenManager;
  28. SecurityTokenProvider serverTokenProvider;
  29. EndpointIdentity identity;
  30. IdentityVerifier identityVerifier;
  31. X509Certificate2 serverCertificate;
  32. bool requireClientCertificate;
  33. string scheme;
  34. bool enableChannelBinding;
  35. SslStreamSecurityUpgradeProvider(IDefaultCommunicationTimeouts timeouts, SecurityTokenManager clientSecurityTokenManager, bool requireClientCertificate, string scheme, IdentityVerifier identityVerifier)
  36. : base(timeouts)
  37. {
  38. this.identityVerifier = identityVerifier;
  39. this.scheme = scheme;
  40. this.clientSecurityTokenManager = clientSecurityTokenManager;
  41. this.requireClientCertificate = requireClientCertificate;
  42. }
  43. SslStreamSecurityUpgradeProvider(IDefaultCommunicationTimeouts timeouts, SecurityTokenProvider serverTokenProvider, bool requireClientCertificate, SecurityTokenAuthenticator clientCertificateAuthenticator, string scheme, IdentityVerifier identityVerifier)
  44. : base(timeouts)
  45. {
  46. this.serverTokenProvider = serverTokenProvider;
  47. this.requireClientCertificate = requireClientCertificate;
  48. this.clientCertificateAuthenticator = clientCertificateAuthenticator;
  49. this.identityVerifier = identityVerifier;
  50. this.scheme = scheme;
  51. }
  52. public static SslStreamSecurityUpgradeProvider CreateClientProvider(
  53. SslStreamSecurityBindingElement bindingElement, BindingContext context)
  54. {
  55. SecurityCredentialsManager credentialProvider = context.BindingParameters.Find<SecurityCredentialsManager>();
  56. if (credentialProvider == null)
  57. {
  58. credentialProvider = ClientCredentials.CreateDefaultCredentials();
  59. }
  60. SecurityTokenManager tokenManager = credentialProvider.CreateSecurityTokenManager();
  61. return new SslStreamSecurityUpgradeProvider(context.Binding, tokenManager, bindingElement.RequireClientCertificate, context.Binding.Scheme, bindingElement.IdentityVerifier);
  62. }
  63. public static SslStreamSecurityUpgradeProvider CreateServerProvider(
  64. SslStreamSecurityBindingElement bindingElement, BindingContext context)
  65. {
  66. SecurityCredentialsManager credentialProvider =
  67. context.BindingParameters.Find<SecurityCredentialsManager>();
  68. if (credentialProvider == null)
  69. {
  70. credentialProvider = ServiceCredentials.CreateDefaultCredentials();
  71. }
  72. Uri listenUri = TransportSecurityHelpers.GetListenUri(context.ListenUriBaseAddress, context.ListenUriRelativeAddress);
  73. SecurityTokenManager tokenManager = credentialProvider.CreateSecurityTokenManager();
  74. RecipientServiceModelSecurityTokenRequirement serverCertRequirement = new RecipientServiceModelSecurityTokenRequirement();
  75. serverCertRequirement.TokenType = SecurityTokenTypes.X509Certificate;
  76. serverCertRequirement.RequireCryptographicToken = true;
  77. serverCertRequirement.KeyUsage = SecurityKeyUsage.Exchange;
  78. serverCertRequirement.TransportScheme = context.Binding.Scheme;
  79. serverCertRequirement.ListenUri = listenUri;
  80. SecurityTokenProvider tokenProvider = tokenManager.CreateSecurityTokenProvider(serverCertRequirement);
  81. if (tokenProvider == null)
  82. {
  83. throw DiagnosticUtility.ExceptionUtility.ThrowHelperError(new InvalidOperationException(SR.GetString(SR.ClientCredentialsUnableToCreateLocalTokenProvider, serverCertRequirement)));
  84. }
  85. SecurityTokenAuthenticator certificateAuthenticator =
  86. TransportSecurityHelpers.GetCertificateTokenAuthenticator(tokenManager, context.Binding.Scheme, listenUri);
  87. return new SslStreamSecurityUpgradeProvider(context.Binding, tokenProvider, bindingElement.RequireClientCertificate,
  88. certificateAuthenticator, context.Binding.Scheme, bindingElement.IdentityVerifier);
  89. }
  90. public override EndpointIdentity Identity
  91. {
  92. get
  93. {
  94. if ((this.identity == null) && (this.serverCertificate != null))
  95. {
  96. this.identity = SecurityUtils.GetServiceCertificateIdentity(this.serverCertificate);
  97. }
  98. return this.identity;
  99. }
  100. }
  101. public IdentityVerifier IdentityVerifier
  102. {
  103. get
  104. {
  105. return this.identityVerifier;
  106. }
  107. }
  108. public bool RequireClientCertificate
  109. {
  110. get
  111. {
  112. return this.requireClientCertificate;
  113. }
  114. }
  115. public X509Certificate2 ServerCertificate
  116. {
  117. get
  118. {
  119. return this.serverCertificate;
  120. }
  121. }
  122. public SecurityTokenAuthenticator ClientCertificateAuthenticator
  123. {
  124. get
  125. {
  126. if (this.clientCertificateAuthenticator == null)
  127. {
  128. this.clientCertificateAuthenticator = new X509SecurityTokenAuthenticator(X509ClientCertificateAuthentication.DefaultCertificateValidator);
  129. }
  130. return this.clientCertificateAuthenticator;
  131. }
  132. }
  133. public SecurityTokenManager ClientSecurityTokenManager
  134. {
  135. get
  136. {
  137. return this.clientSecurityTokenManager;
  138. }
  139. }
  140. public string Scheme
  141. {
  142. get { return this.scheme; }
  143. }
  144. public override T GetProperty<T>()
  145. {
  146. if (typeof(T) == typeof(IChannelBindingProvider) || typeof(T) == typeof(IStreamUpgradeChannelBindingProvider))
  147. {
  148. return (T)(object)this;
  149. }
  150. return base.GetProperty<T>();
  151. }
  152. ChannelBinding IStreamUpgradeChannelBindingProvider.GetChannelBinding(StreamUpgradeInitiator upgradeInitiator, ChannelBindingKind kind)
  153. {
  154. if (upgradeInitiator == null)
  155. {
  156. throw DiagnosticUtility.ExceptionUtility.ThrowHelperArgumentNull("upgradeInitiator");
  157. }
  158. SslStreamSecurityUpgradeInitiator sslUpgradeInitiator = upgradeInitiator as SslStreamSecurityUpgradeInitiator;
  159. if (sslUpgradeInitiator == null)
  160. {
  161. throw DiagnosticUtility.ExceptionUtility.ThrowHelperArgument("upgradeInitiator", SR.GetString(SR.UnsupportedUpgradeInitiator, upgradeInitiator.GetType()));
  162. }
  163. if (kind != ChannelBindingKind.Endpoint)
  164. {
  165. throw DiagnosticUtility.ExceptionUtility.ThrowHelperArgument("kind", SR.GetString(SR.StreamUpgradeUnsupportedChannelBindingKind, this.GetType(), kind));
  166. }
  167. return sslUpgradeInitiator.ChannelBinding;
  168. }
  169. ChannelBinding IStreamUpgradeChannelBindingProvider.GetChannelBinding(StreamUpgradeAcceptor upgradeAcceptor, ChannelBindingKind kind)
  170. {
  171. if (upgradeAcceptor == null)
  172. {
  173. throw DiagnosticUtility.ExceptionUtility.ThrowHelperArgumentNull("upgradeAcceptor");
  174. }
  175. SslStreamSecurityUpgradeAcceptor sslupgradeAcceptor = upgradeAcceptor as SslStreamSecurityUpgradeAcceptor;
  176. if (sslupgradeAcceptor == null)
  177. {
  178. throw DiagnosticUtility.ExceptionUtility.ThrowHelperArgument("upgradeAcceptor", SR.GetString(SR.UnsupportedUpgradeAcceptor, upgradeAcceptor.GetType()));
  179. }
  180. if (kind != ChannelBindingKind.Endpoint)
  181. {
  182. throw DiagnosticUtility.ExceptionUtility.ThrowHelperArgument("kind", SR.GetString(SR.StreamUpgradeUnsupportedChannelBindingKind, this.GetType(), kind));
  183. }
  184. return sslupgradeAcceptor.ChannelBinding;
  185. }
  186. void IChannelBindingProvider.EnableChannelBindingSupport()
  187. {
  188. this.enableChannelBinding = true;
  189. }
  190. bool IChannelBindingProvider.IsChannelBindingSupportEnabled
  191. {
  192. get
  193. {
  194. return this.enableChannelBinding;
  195. }
  196. }
  197. public override StreamUpgradeAcceptor CreateUpgradeAcceptor()
  198. {
  199. ThrowIfDisposedOrNotOpen();
  200. return new SslStreamSecurityUpgradeAcceptor(this);
  201. }
  202. public override StreamUpgradeInitiator CreateUpgradeInitiator(EndpointAddress remoteAddress, Uri via)
  203. {
  204. ThrowIfDisposedOrNotOpen();
  205. return new SslStreamSecurityUpgradeInitiator(this, remoteAddress, via);
  206. }
  207. protected override void OnAbort()
  208. {
  209. if (this.clientCertificateAuthenticator != null)
  210. {
  211. SecurityUtils.AbortTokenAuthenticatorIfRequired(this.clientCertificateAuthenticator);
  212. }
  213. CleanupServerCertificate();
  214. }
  215. protected override void OnClose(TimeSpan timeout)
  216. {
  217. if (this.clientCertificateAuthenticator != null)
  218. {
  219. SecurityUtils.CloseTokenAuthenticatorIfRequired(this.clientCertificateAuthenticator, timeout);
  220. }
  221. CleanupServerCertificate();
  222. }
  223. protected override IAsyncResult OnBeginClose(TimeSpan timeout, AsyncCallback callback, object state)
  224. {
  225. return SecurityUtils.BeginCloseTokenAuthenticatorIfRequired(this.clientCertificateAuthenticator, timeout, callback, state);
  226. }
  227. protected override void OnEndClose(IAsyncResult result)
  228. {
  229. SecurityUtils.EndCloseTokenAuthenticatorIfRequired(result);
  230. CleanupServerCertificate();
  231. }
  232. void SetupServerCertificate(SecurityToken token)
  233. {
  234. X509SecurityToken x509Token = token as X509SecurityToken;
  235. if (x509Token == null)
  236. {
  237. SecurityUtils.AbortTokenProviderIfRequired(this.serverTokenProvider);
  238. throw DiagnosticUtility.ExceptionUtility.ThrowHelperError(new InvalidOperationException(SR.GetString(
  239. SR.InvalidTokenProvided, this.serverTokenProvider.GetType(), typeof(X509SecurityToken))));
  240. }
  241. this.serverCertificate = new X509Certificate2(x509Token.Certificate);
  242. }
  243. void CleanupServerCertificate()
  244. {
  245. if (this.serverCertificate != null)
  246. {
  247. SecurityUtils.ResetCertificate(this.serverCertificate);
  248. this.serverCertificate = null;
  249. }
  250. }
  251. protected override void OnOpen(TimeSpan timeout)
  252. {
  253. TimeoutHelper timeoutHelper = new TimeoutHelper(timeout);
  254. SecurityUtils.OpenTokenAuthenticatorIfRequired(this.ClientCertificateAuthenticator, timeoutHelper.RemainingTime());
  255. if (this.serverTokenProvider != null)
  256. {
  257. SecurityUtils.OpenTokenProviderIfRequired(this.serverTokenProvider, timeoutHelper.RemainingTime());
  258. SecurityToken token = this.serverTokenProvider.GetToken(timeout);
  259. SetupServerCertificate(token);
  260. SecurityUtils.CloseTokenProviderIfRequired(this.serverTokenProvider, timeoutHelper.RemainingTime());
  261. this.serverTokenProvider = null;
  262. }
  263. }
  264. protected override IAsyncResult OnBeginOpen(TimeSpan timeout, AsyncCallback callback, object state)
  265. {
  266. return new OpenAsyncResult(this, timeout, callback, state);
  267. }
  268. protected override void OnEndOpen(IAsyncResult result)
  269. {
  270. OpenAsyncResult.End(result);
  271. }
  272. class OpenAsyncResult : AsyncResult
  273. {
  274. SslStreamSecurityUpgradeProvider parent;
  275. TimeoutHelper timeoutHelper;
  276. AsyncCallback onOpenTokenAuthenticator;
  277. AsyncCallback onOpenTokenProvider;
  278. AsyncCallback onGetToken;
  279. AsyncCallback onCloseTokenProvider;
  280. public OpenAsyncResult(SslStreamSecurityUpgradeProvider parent, TimeSpan timeout,
  281. AsyncCallback callback, object state)
  282. : base(callback, state)
  283. {
  284. this.parent = parent;
  285. this.timeoutHelper = new TimeoutHelper(timeout);
  286. // since we're at channel.Open and not per-message, minimize our statics overhead and leverage GC for our callbacks
  287. this.onOpenTokenAuthenticator = Fx.ThunkCallback(new AsyncCallback(OnOpenTokenAuthenticator));
  288. IAsyncResult result = SecurityUtils.BeginOpenTokenAuthenticatorIfRequired(parent.ClientCertificateAuthenticator,
  289. timeoutHelper.RemainingTime(), onOpenTokenAuthenticator, this);
  290. if (!result.CompletedSynchronously)
  291. {
  292. return;
  293. }
  294. if (HandleOpenAuthenticatorComplete(result))
  295. {
  296. base.Complete(true);
  297. }
  298. }
  299. public static void End(IAsyncResult result)
  300. {
  301. AsyncResult.End<OpenAsyncResult>(result);
  302. }
  303. bool HandleOpenAuthenticatorComplete(IAsyncResult result)
  304. {
  305. SecurityUtils.EndOpenTokenAuthenticatorIfRequired(result);
  306. if (parent.serverTokenProvider == null)
  307. {
  308. return true;
  309. }
  310. this.onOpenTokenProvider = Fx.ThunkCallback(new AsyncCallback(OnOpenTokenProvider));
  311. IAsyncResult openTokenProviderResult = SecurityUtils.BeginOpenTokenProviderIfRequired(
  312. parent.serverTokenProvider, timeoutHelper.RemainingTime(), onOpenTokenProvider, this);
  313. if (!openTokenProviderResult.CompletedSynchronously)
  314. {
  315. return false;
  316. }
  317. return HandleOpenTokenProviderComplete(openTokenProviderResult);
  318. }
  319. bool HandleOpenTokenProviderComplete(IAsyncResult result)
  320. {
  321. SecurityUtils.EndOpenTokenProviderIfRequired(result);
  322. this.onGetToken = Fx.ThunkCallback(new AsyncCallback(OnGetToken));
  323. IAsyncResult getTokenResult = parent.serverTokenProvider.BeginGetToken(timeoutHelper.RemainingTime(),
  324. onGetToken, this);
  325. if (!getTokenResult.CompletedSynchronously)
  326. {
  327. return false;
  328. }
  329. return HandleGetTokenComplete(getTokenResult);
  330. }
  331. bool HandleGetTokenComplete(IAsyncResult result)
  332. {
  333. SecurityToken token = parent.serverTokenProvider.EndGetToken(result);
  334. parent.SetupServerCertificate(token);
  335. this.onCloseTokenProvider = Fx.ThunkCallback(new AsyncCallback(OnCloseTokenProvider));
  336. IAsyncResult closeTokenProviderResult =
  337. SecurityUtils.BeginCloseTokenProviderIfRequired(parent.serverTokenProvider, timeoutHelper.RemainingTime(),
  338. onCloseTokenProvider, this);
  339. if (!closeTokenProviderResult.CompletedSynchronously)
  340. {
  341. return false;
  342. }
  343. return HandleCloseTokenProviderComplete(closeTokenProviderResult);
  344. }
  345. bool HandleCloseTokenProviderComplete(IAsyncResult result)
  346. {
  347. SecurityUtils.EndCloseTokenProviderIfRequired(result);
  348. parent.serverTokenProvider = null;
  349. return true;
  350. }
  351. void OnOpenTokenAuthenticator(IAsyncResult result)
  352. {
  353. if (result.CompletedSynchronously)
  354. {
  355. return;
  356. }
  357. Exception completionException = null;
  358. bool completeSelf = false;
  359. try
  360. {
  361. completeSelf = this.HandleOpenAuthenticatorComplete(result);
  362. }
  363. #pragma warning suppress 56500 // [....], transferring exception to another thread
  364. catch (Exception e)
  365. {
  366. if (Fx.IsFatal(e))
  367. {
  368. throw;
  369. }
  370. completeSelf = true;
  371. completionException = e;
  372. }
  373. if (completeSelf)
  374. {
  375. base.Complete(false, completionException);
  376. }
  377. }
  378. void OnOpenTokenProvider(IAsyncResult result)
  379. {
  380. if (result.CompletedSynchronously)
  381. {
  382. return;
  383. }
  384. Exception completionException = null;
  385. bool completeSelf = false;
  386. try
  387. {
  388. completeSelf = this.HandleOpenTokenProviderComplete(result);
  389. }
  390. #pragma warning suppress 56500 // [....], transferring exception to another thread
  391. catch (Exception e)
  392. {
  393. if (Fx.IsFatal(e))
  394. {
  395. throw;
  396. }
  397. completeSelf = true;
  398. completionException = e;
  399. }
  400. if (completeSelf)
  401. {
  402. base.Complete(false, completionException);
  403. }
  404. }
  405. void OnGetToken(IAsyncResult result)
  406. {
  407. if (result.CompletedSynchronously)
  408. {
  409. return;
  410. }
  411. Exception completionException = null;
  412. bool completeSelf = false;
  413. try
  414. {
  415. completeSelf = this.HandleGetTokenComplete(result);
  416. }
  417. #pragma warning suppress 56500 // [....], transferring exception to another thread
  418. catch (Exception e)
  419. {
  420. if (Fx.IsFatal(e))
  421. {
  422. throw;
  423. }
  424. completeSelf = true;
  425. completionException = e;
  426. }
  427. if (completeSelf)
  428. {
  429. base.Complete(false, completionException);
  430. }
  431. }
  432. void OnCloseTokenProvider(IAsyncResult result)
  433. {
  434. if (result.CompletedSynchronously)
  435. {
  436. return;
  437. }
  438. Exception completionException = null;
  439. bool completeSelf = false;
  440. try
  441. {
  442. completeSelf = this.HandleCloseTokenProviderComplete(result);
  443. }
  444. #pragma warning suppress 56500 // [....], transferring exception to another thread
  445. catch (Exception e)
  446. {
  447. if (Fx.IsFatal(e))
  448. {
  449. throw;
  450. }
  451. completeSelf = true;
  452. completionException = e;
  453. }
  454. if (completeSelf)
  455. {
  456. base.Complete(false, completionException);
  457. }
  458. }
  459. }
  460. }
  461. class SslStreamSecurityUpgradeAcceptor : StreamSecurityUpgradeAcceptorBase
  462. {
  463. SslStreamSecurityUpgradeProvider parent;
  464. SecurityMessageProperty clientSecurity;
  465. // for audit
  466. X509Certificate2 clientCertificate = null;
  467. ChannelBinding channelBindingToken;
  468. public SslStreamSecurityUpgradeAcceptor(SslStreamSecurityUpgradeProvider parent)
  469. : base(FramingUpgradeString.SslOrTls)
  470. {
  471. this.parent = parent;
  472. this.clientSecurity = new SecurityMessageProperty();
  473. }
  474. internal ChannelBinding ChannelBinding
  475. {
  476. get
  477. {
  478. Fx.Assert(this.IsChannelBindingSupportEnabled, "A request for the ChannelBinding is not permitted without enabling ChannelBinding first (through the IChannelBindingProvider interface)");
  479. return this.channelBindingToken;
  480. }
  481. }
  482. internal bool IsChannelBindingSupportEnabled
  483. {
  484. get
  485. {
  486. return ((IChannelBindingProvider)parent).IsChannelBindingSupportEnabled;
  487. }
  488. }
  489. protected override Stream OnAcceptUpgrade(Stream stream, out SecurityMessageProperty remoteSecurity)
  490. {
  491. if (TD.SslOnAcceptUpgradeIsEnabled())
  492. {
  493. TD.SslOnAcceptUpgrade(this.EventTraceActivity);
  494. }
  495. SslStream sslStream = new SslStream(stream, false, this.ValidateRemoteCertificate);
  496. try
  497. {
  498. sslStream.AuthenticateAsServer(this.parent.ServerCertificate, this.parent.RequireClientCertificate,
  499. SslProtocols.Default, false);
  500. }
  501. catch (AuthenticationException exception)
  502. {
  503. throw DiagnosticUtility.ExceptionUtility.ThrowHelperError(new SecurityNegotiationException(exception.Message,
  504. exception));
  505. }
  506. catch (IOException ioException)
  507. {
  508. throw DiagnosticUtility.ExceptionUtility.ThrowHelperError(new SecurityNegotiationException(
  509. SR.GetString(SR.NegotiationFailedIO, ioException.Message), ioException));
  510. }
  511. if (SecurityUtils.ShouldValidateSslCipherStrength())
  512. {
  513. SecurityUtils.ValidateSslCipherStrength(sslStream.CipherStrength);
  514. }
  515. remoteSecurity = this.clientSecurity;
  516. if (this.IsChannelBindingSupportEnabled)
  517. {
  518. this.channelBindingToken = ChannelBindingUtility.GetToken(sslStream);
  519. }
  520. return sslStream;
  521. }
  522. protected override IAsyncResult OnBeginAcceptUpgrade(Stream stream, AsyncCallback callback, object state)
  523. {
  524. AcceptUpgradeAsyncResult result = new AcceptUpgradeAsyncResult(this, callback, state);
  525. result.Begin(stream);
  526. return result;
  527. }
  528. protected override Stream OnEndAcceptUpgrade(IAsyncResult result, out SecurityMessageProperty remoteSecurity)
  529. {
  530. return AcceptUpgradeAsyncResult.End(result, out remoteSecurity, out this.channelBindingToken);
  531. }
  532. // callback from schannel
  533. bool ValidateRemoteCertificate(object sender, X509Certificate certificate, X509Chain chain,
  534. SslPolicyErrors sslPolicyErrors)
  535. {
  536. if (this.parent.RequireClientCertificate)
  537. {
  538. if (certificate == null)
  539. {
  540. if (DiagnosticUtility.ShouldTraceError)
  541. {
  542. TraceUtility.TraceEvent(TraceEventType.Error, TraceCode.SslClientCertMissing,
  543. SR.GetString(SR.TraceCodeSslClientCertMissing), this);
  544. }
  545. return false;
  546. }
  547. // Note: add ref to handle since the caller will reset the cert after the callback return.
  548. X509Certificate2 certificate2 = new X509Certificate2(certificate);
  549. this.clientCertificate = certificate2;
  550. try
  551. {
  552. SecurityToken token = new X509SecurityToken(certificate2, false);
  553. ReadOnlyCollection<IAuthorizationPolicy> authorizationPolicies = this.parent.ClientCertificateAuthenticator.ValidateToken(token);
  554. this.clientSecurity = new SecurityMessageProperty();
  555. this.clientSecurity.TransportToken = new SecurityTokenSpecification(token, authorizationPolicies);
  556. this.clientSecurity.ServiceSecurityContext = new ServiceSecurityContext(authorizationPolicies);
  557. }
  558. catch (SecurityTokenException e)
  559. {
  560. DiagnosticUtility.TraceHandledException(e, TraceEventType.Information);
  561. return false;
  562. }
  563. }
  564. return true;
  565. }
  566. public override SecurityMessageProperty GetRemoteSecurity()
  567. {
  568. if (this.clientSecurity.TransportToken != null)
  569. {
  570. return this.clientSecurity;
  571. }
  572. if (this.clientCertificate != null)
  573. {
  574. SecurityToken token = new X509SecurityToken(this.clientCertificate);
  575. ReadOnlyCollection<IAuthorizationPolicy> authorizationPolicies = SecurityUtils.NonValidatingX509Authenticator.ValidateToken(token);
  576. this.clientSecurity = new SecurityMessageProperty();
  577. this.clientSecurity.TransportToken = new SecurityTokenSpecification(token, authorizationPolicies);
  578. this.clientSecurity.ServiceSecurityContext = new ServiceSecurityContext(authorizationPolicies);
  579. return this.clientSecurity;
  580. }
  581. return base.GetRemoteSecurity();
  582. }
  583. class AcceptUpgradeAsyncResult : StreamSecurityUpgradeAcceptorAsyncResult
  584. {
  585. SslStreamSecurityUpgradeAcceptor acceptor;
  586. SslStream sslStream;
  587. ChannelBinding channelBindingToken;
  588. public AcceptUpgradeAsyncResult(SslStreamSecurityUpgradeAcceptor acceptor, AsyncCallback callback,
  589. object state)
  590. : base(callback, state)
  591. {
  592. this.acceptor = acceptor;
  593. }
  594. protected override IAsyncResult OnBegin(Stream stream, AsyncCallback callback)
  595. {
  596. if (TD.SslOnAcceptUpgradeIsEnabled())
  597. {
  598. TD.SslOnAcceptUpgrade(acceptor.EventTraceActivity);
  599. }
  600. this.sslStream = new SslStream(stream, false, this.acceptor.ValidateRemoteCertificate);
  601. return this.sslStream.BeginAuthenticateAsServer(this.acceptor.parent.ServerCertificate,
  602. this.acceptor.parent.RequireClientCertificate, SslProtocols.Default, false, callback, this);
  603. }
  604. protected override Stream OnCompleteAuthenticateAsServer(IAsyncResult result)
  605. {
  606. this.sslStream.EndAuthenticateAsServer(result);
  607. if (SecurityUtils.ShouldValidateSslCipherStrength())
  608. {
  609. SecurityUtils.ValidateSslCipherStrength(sslStream.CipherStrength);
  610. }
  611. if (this.acceptor.IsChannelBindingSupportEnabled)
  612. {
  613. this.channelBindingToken = ChannelBindingUtility.GetToken(this.sslStream);
  614. }
  615. return this.sslStream;
  616. }
  617. protected override SecurityMessageProperty ValidateCreateSecurity()
  618. {
  619. return this.acceptor.clientSecurity;
  620. }
  621. public static Stream End(IAsyncResult result, out SecurityMessageProperty remoteSecurity, out ChannelBinding channelBinding)
  622. {
  623. Stream stream = StreamSecurityUpgradeAcceptorAsyncResult.End(result, out remoteSecurity);
  624. channelBinding = ((AcceptUpgradeAsyncResult)result).channelBindingToken;
  625. return stream;
  626. }
  627. }
  628. }
  629. class SslStreamSecurityUpgradeInitiator : StreamSecurityUpgradeInitiatorBase
  630. {
  631. SslStreamSecurityUpgradeProvider parent;
  632. SecurityMessageProperty serverSecurity;
  633. SecurityTokenProvider clientCertificateProvider;
  634. X509SecurityToken clientToken;
  635. SecurityTokenAuthenticator serverCertificateAuthenticator;
  636. ChannelBinding channelBindingToken;
  637. static LocalCertificateSelectionCallback clientCertificateSelectionCallback;
  638. public SslStreamSecurityUpgradeInitiator(SslStreamSecurityUpgradeProvider parent,
  639. EndpointAddress remoteAddress, Uri via)
  640. : base(FramingUpgradeString.SslOrTls, remoteAddress, via)
  641. {
  642. this.parent = parent;
  643. InitiatorServiceModelSecurityTokenRequirement serverCertRequirement = new InitiatorServiceModelSecurityTokenRequirement();
  644. serverCertRequirement.TokenType = SecurityTokenTypes.X509Certificate;
  645. serverCertRequirement.RequireCryptographicToken = true;
  646. serverCertRequirement.KeyUsage = SecurityKeyUsage.Exchange;
  647. serverCertRequirement.TargetAddress = remoteAddress;
  648. serverCertRequirement.Via = via;
  649. serverCertRequirement.TransportScheme = this.parent.Scheme;
  650. serverCertRequirement.PreferSslCertificateAuthenticator = true;
  651. SecurityTokenResolver dummy;
  652. this.serverCertificateAuthenticator = (parent.ClientSecurityTokenManager.CreateSecurityTokenAuthenticator(serverCertRequirement, out dummy));
  653. if (parent.RequireClientCertificate)
  654. {
  655. InitiatorServiceModelSecurityTokenRequirement clientCertRequirement = new InitiatorServiceModelSecurityTokenRequirement();
  656. clientCertRequirement.TokenType = SecurityTokenTypes.X509Certificate;
  657. clientCertRequirement.RequireCryptographicToken = true;
  658. clientCertRequirement.KeyUsage = SecurityKeyUsage.Signature;
  659. clientCertRequirement.TargetAddress = remoteAddress;
  660. clientCertRequirement.Via = via;
  661. clientCertRequirement.TransportScheme = this.parent.Scheme;
  662. this.clientCertificateProvider = parent.ClientSecurityTokenManager.CreateSecurityTokenProvider(clientCertRequirement);
  663. if (clientCertificateProvider == null)
  664. {
  665. throw DiagnosticUtility.ExceptionUtility.ThrowHelperError(new InvalidOperationException(SR.GetString(SR.ClientCredentialsUnableToCreateLocalTokenProvider, clientCertRequirement)));
  666. }
  667. }
  668. }
  669. static LocalCertificateSelectionCallback ClientCertificateSelectionCallback
  670. {
  671. get
  672. {
  673. if (clientCertificateSelectionCallback == null)
  674. {
  675. clientCertificateSelectionCallback = new LocalCertificateSelectionCallback(SelectClientCertificate);
  676. }
  677. return clientCertificateSelectionCallback;
  678. }
  679. }
  680. internal ChannelBinding ChannelBinding
  681. {
  682. get
  683. {
  684. Fx.Assert(this.IsChannelBindingSupportEnabled, "A request for the ChannelBinding is not permitted without enabling ChannelBinding first (through the IChannelBindingProvider interface)");
  685. return this.channelBindingToken;
  686. }
  687. }
  688. internal bool IsChannelBindingSupportEnabled
  689. {
  690. get
  691. {
  692. return ((IChannelBindingProvider)parent).IsChannelBindingSupportEnabled;
  693. }
  694. }
  695. IAsyncResult BaseBeginOpen(TimeSpan timeout, AsyncCallback callback, object state)
  696. {
  697. return base.BeginOpen(timeout, callback, state);
  698. }
  699. void BaseEndOpen(IAsyncResult result)
  700. {
  701. base.EndOpen(result);
  702. }
  703. internal override IAsyncResult BeginOpen(TimeSpan timeout, AsyncCallback callback, object state)
  704. {
  705. return new OpenAsyncResult(this, timeout, callback, state);
  706. }
  707. internal override void EndOpen(IAsyncResult result)
  708. {
  709. OpenAsyncResult.End(result);
  710. }
  711. internal override void Open(TimeSpan timeout)
  712. {
  713. TimeoutHelper timeoutHelper = new TimeoutHelper(timeout);
  714. base.Open(timeoutHelper.RemainingTime());
  715. if (this.clientCertificateProvider != null)
  716. {
  717. SecurityUtils.OpenTokenProviderIfRequired(this.clientCertificateProvider, timeoutHelper.RemainingTime());
  718. this.clientToken = (X509SecurityToken)this.clientCertificateProvider.GetToken(timeoutHelper.RemainingTime());
  719. }
  720. }
  721. IAsyncResult BaseBeginClose(TimeSpan timeout, AsyncCallback callback, object state)
  722. {
  723. return base.BeginClose(timeout, callback, state);
  724. }
  725. void BaseEndClose(IAsyncResult result)
  726. {
  727. base.EndClose(result);
  728. }
  729. internal override IAsyncResult BeginClose(TimeSpan timeout, AsyncCallback callback, object state)
  730. {
  731. return new CloseAsyncResult(this, timeout, callback, state);
  732. }
  733. internal override void EndClose(IAsyncResult result)
  734. {
  735. CloseAsyncResult.End(result);
  736. }
  737. internal override void Close(TimeSpan timeout)
  738. {
  739. TimeoutHelper timeoutHelper = new TimeoutHelper(timeout);
  740. base.Close(timeoutHelper.RemainingTime());
  741. if (this.clientCertificateProvider != null)
  742. {
  743. SecurityUtils.CloseTokenProviderIfRequired(this.clientCertificateProvider, timeoutHelper.RemainingTime());
  744. }
  745. }
  746. protected override IAsyncResult OnBeginInitiateUpgrade(Stream stream, AsyncCallback callback, object state)
  747. {
  748. if (TD.SslOnInitiateUpgradeIsEnabled())
  749. {
  750. TD.SslOnInitiateUpgrade();
  751. }
  752. InitiateUpgradeAsyncResult result = new InitiateUpgradeAsyncResult(this, callback, state);
  753. result.Begin(stream);
  754. return result;
  755. }
  756. protected override Stream OnEndInitiateUpgrade(IAsyncResult result,
  757. out SecurityMessageProperty remoteSecurity)
  758. {
  759. return InitiateUpgradeAsyncResult.End(result, out remoteSecurity, out this.channelBindingToken);
  760. }
  761. protected override Stream OnInitiateUpgrade(Stream stream, out SecurityMessageProperty remoteSecurity)
  762. {
  763. if (TD.SslOnInitiateUpgradeIsEnabled())
  764. {
  765. TD.SslOnInitiateUpgrade();
  766. }
  767. X509CertificateCollection clientCertificates = null;
  768. LocalCertificateSelectionCallback selectionCallback = null;
  769. if (this.clientToken != null)
  770. {
  771. clientCertificates = new X509CertificateCollection();
  772. clientCertificates.Add(clientToken.Certificate);
  773. selectionCallback = ClientCertificateSelectionCallback;
  774. }
  775. SslStream sslStream = new SslStream(stream, false, this.ValidateRemoteCertificate, selectionCallback);
  776. try
  777. {
  778. sslStream.AuthenticateAsClient(string.Empty, clientCertificates, SslProtocols.Default, false);
  779. }
  780. catch (SecurityTokenValidationException tokenValidationException)
  781. {
  782. throw DiagnosticUtility.ExceptionUtility.ThrowHelperError(new SecurityNegotiationException(tokenValidationException.Message,
  783. tokenValidationException));
  784. }
  785. catch (AuthenticationException exception)
  786. {
  787. throw DiagnosticUtility.ExceptionUtility.ThrowHelperError(new SecurityNegotiationException(exception.Message,
  788. exception));
  789. }
  790. catch (IOException ioException)
  791. {
  792. throw DiagnosticUtility.ExceptionUtility.ThrowHelperError(new SecurityNegotiationException(
  793. SR.GetString(SR.NegotiationFailedIO, ioException.Message), ioException));
  794. }
  795. if (SecurityUtils.ShouldValidateSslCipherStrength())
  796. {
  797. SecurityUtils.ValidateSslCipherStrength(sslStream.CipherStrength);
  798. }
  799. remoteSecurity = this.serverSecurity;
  800. if (this.IsChannelBindingSupportEnabled)
  801. {
  802. this.channelBindingToken = ChannelBindingUtility.GetToken(sslStream);
  803. }
  804. return sslStream;
  805. }
  806. static X509Certificate SelectClientCertificate(object sender, string targetHost,
  807. X509CertificateCollection localCertificates, X509Certificate remoteCertificate, string[] acceptableIssuers)
  808. {
  809. return localCertificates[0];
  810. }
  811. bool ValidateRemoteCertificate(object sender, X509Certificate certificate, X509Chain chain,
  812. SslPolicyErrors sslPolicyErrors)
  813. {
  814. // Note: add ref to handle since the caller will reset the cert after the callback return.
  815. X509Certificate2 certificate2 = new X509Certificate2(certificate);
  816. SecurityToken token = new X509SecurityToken(certificate2, false);
  817. ReadOnlyCollection<IAuthorizationPolicy> authorizationPolicies = this.serverCertificateAuthenticator.ValidateToken(token);
  818. this.serverSecurity = new SecurityMessageProperty();
  819. this.serverSecurity.TransportToken = new SecurityTokenSpecification(token, authorizationPolicies);
  820. this.serverSecurity.ServiceSecurityContext = new ServiceSecurityContext(authorizationPolicies);
  821. AuthorizationContext authzContext = this.serverSecurity.ServiceSecurityContext.AuthorizationContext;
  822. this.parent.IdentityVerifier.EnsureOutgoingIdentity(this.RemoteAddress, this.Via, authzContext);
  823. return true;
  824. }
  825. class InitiateUpgradeAsyncResult : StreamSecurityUpgradeInitiatorAsyncResult
  826. {
  827. X509CertificateCollection clientCertificates;
  828. SslStreamSecurityUpgradeInitiator initiator;
  829. LocalCertificateSelectionCallback selectionCallback;
  830. SslStream sslStream;
  831. ChannelBinding channelBindingToken;
  832. public InitiateUpgradeAsyncResult(SslStreamSecurityUpgradeInitiator initiator, AsyncCallback callback,
  833. object state)
  834. : base(callback, state)
  835. {
  836. this.initiator = initiator;
  837. if (initiator.clientToken != null)
  838. {
  839. this.clientCertificates = new X509CertificateCollection();
  840. this.clientCertificates.Add(initiator.clientToken.Certificate);
  841. this.selectionCallback = ClientCertificateSelectionCallback;
  842. }
  843. }
  844. protected override IAsyncResult OnBeginAuthenticateAsClient(Stream stream, AsyncCallback callback)
  845. {
  846. this.sslStream = new SslStream(stream, false, this.initiator.ValidateRemoteCertificate,
  847. this.selectionCallback);
  848. try
  849. {
  850. return this.sslStream.BeginAuthenticateAsClient(string.Empty, this.clientCertificates,
  851. SslProtocols.Default, false, callback, this);
  852. }
  853. catch (SecurityTokenValidationException tokenValidationException)
  854. {
  855. throw DiagnosticUtility.ExceptionUtility.ThrowHelperError(new SecurityNegotiationException(tokenValidationException.Message,
  856. tokenValidationException));
  857. }
  858. }
  859. protected override Stream OnCompleteAuthenticateAsClient(IAsyncResult result)
  860. {
  861. try
  862. {
  863. this.sslStream.EndAuthenticateAsClient(result);
  864. }
  865. catch (SecurityTokenValidationException tokenValidationException)
  866. {
  867. throw DiagnosticUtility.ExceptionUtility.ThrowHelperError(new SecurityNegotiationException(tokenValidationException.Message,
  868. tokenValidationException));
  869. }
  870. if (SecurityUtils.ShouldValidateSslCipherStrength())
  871. {
  872. SecurityUtils.ValidateSslCipherStrength(sslStream.CipherStrength);
  873. }
  874. if (this.initiator.IsChannelBindingSupportEnabled)
  875. {
  876. this.channelBindingToken = ChannelBindingUtility.GetToken(this.sslStream);
  877. }
  878. return this.sslStream;
  879. }
  880. protected override SecurityMessageProperty ValidateCreateSecurity()
  881. {
  882. return this.initiator.serverSecurity;
  883. }
  884. public static Stream End(IAsyncResult result, out SecurityMessageProperty remoteSecurity, out ChannelBinding channelBinding)
  885. {
  886. Stream stream = StreamSecurityUpgradeInitiatorAsyncResult.End(result, out remoteSecurity);
  887. channelBinding = ((InitiateUpgradeAsyncResult)result).channelBindingToken;
  888. return stream;
  889. }
  890. }
  891. class OpenAsyncResult : AsyncResult
  892. {
  893. SslStreamSecurityUpgradeInitiator parent;
  894. TimeoutHelper timeoutHelper;
  895. AsyncCallback onBaseOpen;
  896. AsyncCallback onOpenTokenProvider;
  897. AsyncCallback onGetClientToken;
  898. public OpenAsyncResult(SslStreamSecurityUpgradeInitiator parent, TimeSpan timeout,
  899. AsyncCallback callback, object state)
  900. : base(callback, state)
  901. {
  902. this.parent = parent;
  903. TimeoutHelper timeoutHelper = new TimeoutHelper(timeout);
  904. // since we're at channel.Open and not per-message, minimize our statics overhead and leverage GC for our callback
  905. this.onBaseOpen = Fx.ThunkCallback(new AsyncCallback(OnBaseOpen));
  906. if (parent.clientCertificateProvider != null)
  907. {
  908. this.onOpenTokenProvider = Fx.ThunkCallback(new AsyncCallback(OnOpenTokenProvider));
  909. this.onGetClientToken = Fx.ThunkCallback(new AsyncCallback(OnGetClientToken));
  910. }
  911. IAsyncResult result = parent.BaseBeginOpen(timeoutHelper.RemainingTime(), onBaseOpen, this);
  912. if (!result.CompletedSynchronously)
  913. {
  914. return;
  915. }
  916. if (HandleBaseOpenComplete(result))
  917. {
  918. base.Complete(true);
  919. }
  920. }
  921. public static void End(IAsyncResult result)
  922. {
  923. AsyncResult.End<OpenAsyncResult>(result);
  924. }
  925. bool HandleBaseOpenComplete(IAsyncResult result)
  926. {
  927. parent.BaseEndOpen(result);
  928. if (parent.clientCertificateProvider == null)
  929. {
  930. return true;
  931. }
  932. IAsyncResult openTokenProviderResult = SecurityUtils.BeginOpenTokenProviderIfRequired(
  933. parent.clientCertificateProvider, timeoutHelper.RemainingTime(), onOpenTokenProvider, this);
  934. if (!openTokenProviderResult.CompletedSynchronously)
  935. {
  936. return false;
  937. }
  938. return HandleOpenTokenProviderComplete(openTokenProviderResult);
  939. }
  940. bool HandleOpenTokenProviderComplete(IAsyncResult result)
  941. {
  942. SecurityUtils.EndOpenTokenProviderIfRequired(result);
  943. IAsyncResult getTokenResult = parent.clientCertificateProvider.BeginGetToken(timeoutHelper.RemainingTime(),
  944. onGetClientToken, this);
  945. if (!getTokenResult.CompletedSynchronously)
  946. {
  947. return false;
  948. }
  949. return HandleGetTokenComplete(getTokenResult);
  950. }
  951. bool HandleGetTokenComplete(IAsyncResult result)
  952. {
  953. parent.clientToken = (X509SecurityToken)parent.clientCertificateProvider.EndGetToken(result);
  954. return true;
  955. }
  956. void OnBaseOpen(IAsyncResult result)
  957. {
  958. if (result.CompletedSynchronously)
  959. {
  960. return;
  961. }
  962. Exception completionException = null;
  963. bool completeSelf = false;
  964. try
  965. {
  966. completeSelf = this.HandleBaseOpenComplete(result);
  967. }
  968. #pragma warning suppress 56500 // [....], transferring exception to another thread
  969. catch (Exception e)
  970. {
  971. if (Fx.IsFatal(e))
  972. {
  973. throw;
  974. }
  975. completeSelf = true;
  976. completionException = e;
  977. }
  978. if (completeSelf)
  979. {
  980. base.Complete(false, completionException);
  981. }
  982. }
  983. void OnOpenTokenProvider(IAsyncResult result)
  984. {
  985. if (result.CompletedSynchronously)
  986. {
  987. return;
  988. }
  989. Exception completionException = null;
  990. bool completeSelf = false;
  991. try
  992. {
  993. completeSelf = this.HandleOpenTokenProviderComplete(result);
  994. }
  995. #pragma warning suppress 56500 // [....], transferring exception to another thread
  996. catch (Exception e)
  997. {
  998. if (Fx.IsFatal(e))
  999. {
  1000. throw;
  1001. }
  1002. completeSelf = true;
  1003. completionException = e;
  1004. }
  1005. if (completeSelf)
  1006. {
  1007. base.Complete(false, completionException);
  1008. }
  1009. }
  1010. void OnGetClientToken(IAsyncResult result)
  1011. {
  1012. if (result.CompletedSynchronously)
  1013. {
  1014. return;
  1015. }
  1016. Exception completionException = null;
  1017. bool completeSelf = false;
  1018. try
  1019. {
  1020. completeSelf = this.HandleGetTokenComplete(result);
  1021. }
  1022. #pragma warning suppress 56500 // [....], transferring exception to another thread
  1023. catch (Exception e)
  1024. {
  1025. if (Fx.IsFatal(e))
  1026. {
  1027. throw;
  1028. }
  1029. completeSelf = true;
  1030. completionException = e;
  1031. }
  1032. if (completeSelf)
  1033. {
  1034. base.Complete(false, completionException);
  1035. }
  1036. }
  1037. }
  1038. class CloseAsyncResult : AsyncResult
  1039. {
  1040. SslStreamSecurityUpgradeInitiator parent;
  1041. TimeoutHelper timeoutHelper;
  1042. AsyncCallback onBaseClose;
  1043. AsyncCallback onCloseTokenProvider;
  1044. public CloseAsyncResult(SslStreamSecurityUpgradeInitiator parent, TimeSpan timeout,
  1045. AsyncCallback callback, object state)
  1046. : base(callback, state)
  1047. {
  1048. this.parent = parent;
  1049. TimeoutHelper timeoutHelper = new TimeoutHelper(timeout);
  1050. // since we're at channel.Open and not per-message, minimize our statics overhead and leverage GC for our callback
  1051. this.onBaseClose = Fx.ThunkCallback(new AsyncCallback(OnBaseClose));
  1052. if (parent.clientCertificateProvider != null)
  1053. {
  1054. this.onCloseTokenProvider = Fx.ThunkCallback(new AsyncCallback(OnCloseTokenProvider));
  1055. }
  1056. IAsyncResult result = parent.BaseBeginClose(timeoutHelper.RemainingTime(), onBaseClose, this);
  1057. if (!result.CompletedSynchronously)
  1058. {
  1059. return;
  1060. }
  1061. if (HandleBaseCloseComplete(result))
  1062. {
  1063. base.Complete(true);
  1064. }
  1065. }
  1066. public static void End(IAsyncResult result)
  1067. {
  1068. AsyncResult.End<CloseAsyncResult>(result);
  1069. }
  1070. bool HandleBaseCloseComplete(IAsyncResult result)
  1071. {
  1072. parent.BaseEndClose(result);
  1073. if (parent.clientCertificateProvider == null)
  1074. {
  1075. return true;
  1076. }
  1077. IAsyncResult closeTokenProviderResult = SecurityUtils.BeginCloseTokenProviderIfRequired(
  1078. parent.clientCertificateProvider, timeoutHelper.RemainingTime(), onCloseTokenProvider, this);
  1079. if (!closeTokenProviderResult.CompletedSynchronously)
  1080. {
  1081. return false;
  1082. }
  1083. SecurityUtils.EndCloseTokenProviderIfRequired(closeTokenProviderResult);
  1084. return true;
  1085. }
  1086. void OnBaseClose(IAsyncResult result)
  1087. {
  1088. if (result.CompletedSynchronously)
  1089. {
  1090. return;
  1091. }
  1092. Exception completionException = null;
  1093. bool completeSelf = false;
  1094. try
  1095. {
  1096. completeSelf = this.HandleBaseCloseComplete(result);
  1097. }
  1098. #pragma warning suppress 56500 // [....], transferring exception to another thread
  1099. catch (Exception e)
  1100. {
  1101. if (Fx.IsFatal(e))
  1102. {
  1103. throw;
  1104. }
  1105. completeSelf = true;
  1106. completionException = e;
  1107. }
  1108. if (completeSelf)
  1109. {
  1110. base.Complete(false, completionException);
  1111. }
  1112. }
  1113. void OnCloseTokenProvider(IAsyncResult result)
  1114. {
  1115. if (result.CompletedSynchronously)
  1116. {
  1117. return;
  1118. }
  1119. Exception completionException = null;
  1120. try
  1121. {
  1122. SecurityUtils.EndCloseTokenProviderIfRequired(result);
  1123. }
  1124. #pragma warning suppress 56500 // [....], transferring exception to another thread
  1125. catch (Exception e)
  1126. {
  1127. if (Fx.IsFatal(e))
  1128. {
  1129. throw;
  1130. }
  1131. completionException = e;
  1132. }
  1133. base.Complete(false, completionException);
  1134. }
  1135. }
  1136. }
  1137. }