CertificateOfOwnership.cpp 3.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118
  1. /*
  2. * Copyright (c)2013-2020 ZeroTier, Inc.
  3. *
  4. * Use of this software is governed by the Business Source License included
  5. * in the LICENSE.TXT file in the project's root directory.
  6. *
  7. * Change Date: 2024-01-01
  8. *
  9. * On the date above, in accordance with the Business Source License, use
  10. * of this software will be governed by version 2.0 of the Apache License.
  11. */
  12. /****/
  13. #include "CertificateOfOwnership.hpp"
  14. namespace ZeroTier {
  15. void CertificateOfOwnership::addThing(const InetAddress &ip)
  16. {
  17. if (_thingCount >= ZT_CERTIFICATEOFOWNERSHIP_MAX_THINGS) return;
  18. if (ip.ss_family == AF_INET) {
  19. _thingTypes[_thingCount] = THING_IPV4_ADDRESS;
  20. memcpy(_thingValues[_thingCount],&(reinterpret_cast<const struct sockaddr_in *>(&ip)->sin_addr.s_addr),4);
  21. ++_thingCount;
  22. } else if (ip.ss_family == AF_INET6) {
  23. _thingTypes[_thingCount] = THING_IPV6_ADDRESS;
  24. memcpy(_thingValues[_thingCount],reinterpret_cast<const struct sockaddr_in6 *>(&ip)->sin6_addr.s6_addr,16);
  25. ++_thingCount;
  26. }
  27. }
  28. void CertificateOfOwnership::addThing(const MAC &mac)
  29. {
  30. if (_thingCount >= ZT_CERTIFICATEOFOWNERSHIP_MAX_THINGS) return;
  31. _thingTypes[_thingCount] = THING_MAC_ADDRESS;
  32. mac.copyTo(_thingValues[_thingCount]);
  33. ++_thingCount;
  34. }
  35. bool CertificateOfOwnership::sign(const Identity &signer)
  36. {
  37. uint8_t buf[ZT_CERTIFICATEOFOWNERSHIP_MARSHAL_SIZE_MAX + 16];
  38. if (signer.hasPrivate()) {
  39. _signedBy = signer.address();
  40. _signatureLength = signer.sign(buf,(unsigned int)marshal(buf,true),_signature,sizeof(_signature));
  41. return true;
  42. }
  43. return false;
  44. }
  45. int CertificateOfOwnership::marshal(uint8_t data[ZT_CERTIFICATEOFOWNERSHIP_MARSHAL_SIZE_MAX],bool forSign) const noexcept
  46. {
  47. int p = 0;
  48. if (forSign) {
  49. for(int k=0;k<16;++k)
  50. data[p++] = 0x7f;
  51. }
  52. Utils::storeBigEndian<uint64_t>(data + p,_networkId);
  53. Utils::storeBigEndian<uint64_t>(data + p + 8,(uint64_t)_ts);
  54. Utils::storeBigEndian<uint64_t>(data + p + 16,_flags);
  55. Utils::storeBigEndian<uint32_t>(data + p + 24,_id);
  56. Utils::storeBigEndian<uint16_t>(data + p + 28,(uint16_t)_thingCount);
  57. p += 30;
  58. for(unsigned int i=0,j=_thingCount;i<j;++i) {
  59. data[p++] = _thingTypes[i];
  60. memcpy(data + p,_thingValues[i],ZT_CERTIFICATEOFOWNERSHIP_MAX_THING_VALUE_SIZE);
  61. p += ZT_CERTIFICATEOFOWNERSHIP_MAX_THING_VALUE_SIZE;
  62. }
  63. _issuedTo.copyTo(data + p); p += ZT_ADDRESS_LENGTH;
  64. _signedBy.copyTo(data + p); p += ZT_ADDRESS_LENGTH;
  65. if (!forSign) {
  66. data[p++] = 1;
  67. Utils::storeBigEndian<uint16_t>(data + p,(uint16_t)_signatureLength); p += 2;
  68. memcpy(data + p,_signature,_signatureLength); p += (int)_signatureLength;
  69. }
  70. data[p++] = 0;
  71. data[p++] = 0;
  72. if (forSign) {
  73. for(int k=0;k<16;++k)
  74. data[p++] = 0x7f;
  75. }
  76. return p;
  77. }
  78. int CertificateOfOwnership::unmarshal(const uint8_t *data,int len) noexcept
  79. {
  80. if (len < 30)
  81. return -1;
  82. _networkId = Utils::loadBigEndian<uint64_t>(data);
  83. _ts = (int64_t)Utils::loadBigEndian<uint64_t>(data + 8);
  84. _flags = Utils::loadBigEndian<uint64_t>(data + 16);
  85. _id = Utils::loadBigEndian<uint32_t>(data + 24);
  86. _thingCount = Utils::loadBigEndian<uint16_t>(data + 28);
  87. if (_thingCount > ZT_CERTIFICATEOFOWNERSHIP_MAX_THINGS)
  88. return -1;
  89. int p = 30;
  90. for(unsigned int i=0,j=_thingCount;i<j;++i) {
  91. if ((p + 1 + ZT_CERTIFICATEOFOWNERSHIP_MAX_THING_VALUE_SIZE) > len)
  92. return -1;
  93. _thingTypes[i] = data[p++];
  94. memcpy(_thingValues[i],data + p,ZT_CERTIFICATEOFOWNERSHIP_MAX_THING_VALUE_SIZE);
  95. p += ZT_CERTIFICATEOFOWNERSHIP_MAX_THING_VALUE_SIZE;
  96. }
  97. if ((p + ZT_ADDRESS_LENGTH + ZT_ADDRESS_LENGTH + 1 + 2) > len)
  98. return -1;
  99. _issuedTo.setTo(data + p); p += ZT_ADDRESS_LENGTH;
  100. _signedBy.setTo(data + p); p += ZT_ADDRESS_LENGTH + 1;
  101. p += 2 + Utils::loadBigEndian<uint16_t>(data + p);
  102. if (p > len)
  103. return -1;
  104. return p;
  105. }
  106. } // namespace ZeroTier