ssl.c 26 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953
  1. #define HL_NAME(n) ssl_##n
  2. #include <hl.h>
  3. #ifdef HL_WIN
  4. #undef _GUID
  5. #include <winsock2.h>
  6. #include <wincrypt.h>
  7. #else
  8. #include <sys/socket.h>
  9. #include <strings.h>
  10. #include <errno.h>
  11. typedef int SOCKET;
  12. #endif
  13. #include <stdio.h>
  14. #include <string.h>
  15. #ifdef HL_MAC
  16. #include <Security/Security.h>
  17. #endif
  18. #define SOCKET_ERROR (-1)
  19. #define NRETRYS 20
  20. #include "mbedtls/error.h"
  21. #include "mbedtls/md.h"
  22. #include "mbedtls/pk.h"
  23. #include "mbedtls/x509.h"
  24. #include "mbedtls/ssl.h"
  25. #include "mbedtls/oid.h"
  26. #if MBEDTLS_VERSION_MAJOR < 4
  27. #include "mbedtls/ctr_drbg.h"
  28. #include "mbedtls/entropy.h"
  29. #endif
  30. #ifdef MBEDTLS_PSA_CRYPTO_C
  31. #include <psa/crypto.h>
  32. #endif
  33. #ifdef HL_CONSOLE
  34. mbedtls_x509_crt *hl_init_cert_chain();
  35. #endif
  36. #ifndef MSG_NOSIGNAL
  37. # define MSG_NOSIGNAL 0
  38. #endif
  39. // Duplicate from socket.c
  40. typedef struct _hl_socket {
  41. SOCKET sock;
  42. } hl_socket;
  43. typedef struct _hl_ssl_cert hl_ssl_cert;
  44. struct _hl_ssl_cert {
  45. void(*finalize)(hl_ssl_cert *);
  46. mbedtls_x509_crt *c;
  47. };
  48. typedef struct _hl_ssl_pkey hl_ssl_pkey;
  49. struct _hl_ssl_pkey {
  50. void(*finalize)(hl_ssl_pkey *);
  51. mbedtls_pk_context *k;
  52. };
  53. #define _SOCK _ABSTRACT(hl_socket)
  54. #define TSSL _ABSTRACT(mbedtls_ssl_context)
  55. #define TCONF _ABSTRACT(mbedtls_ssl_config)
  56. #define TCERT _ABSTRACT(hl_ssl_cert)
  57. #define TPKEY _ABSTRACT(hl_ssl_pkey)
  58. static bool ssl_init_done = false;
  59. #if MBEDTLS_VERSION_MAJOR < 4
  60. static mbedtls_entropy_context entropy;
  61. static mbedtls_ctr_drbg_context ctr_drbg;
  62. #endif
  63. static bool is_ssl_blocking( int r ) {
  64. return r == MBEDTLS_ERR_SSL_WANT_READ || r == MBEDTLS_ERR_SSL_WANT_WRITE;
  65. }
  66. static int ssl_block_error( int r ) {
  67. return is_ssl_blocking(r) ? -1 : -2;
  68. }
  69. static void cert_finalize(hl_ssl_cert *c) {
  70. mbedtls_x509_crt_free(c->c);
  71. free(c->c);
  72. c->c = NULL;
  73. }
  74. static void pkey_finalize(hl_ssl_pkey *k) {
  75. mbedtls_pk_free(k->k);
  76. free(k->k);
  77. k->k = NULL;
  78. }
  79. static int ssl_error(int ret) {
  80. char buf[128];
  81. uchar buf16[128];
  82. mbedtls_strerror(ret, buf, sizeof(buf));
  83. hl_from_utf8(buf16, (int)strlen(buf), buf);
  84. hl_error("%s",buf16);
  85. return ret;
  86. }
  87. HL_PRIM mbedtls_ssl_context *HL_NAME(ssl_new)(mbedtls_ssl_config *config) {
  88. int ret;
  89. mbedtls_ssl_context *ssl;
  90. ssl = (mbedtls_ssl_context *)hl_gc_alloc_noptr(sizeof(mbedtls_ssl_context));
  91. mbedtls_ssl_init(ssl);
  92. if ((ret = mbedtls_ssl_setup(ssl, config)) != 0) {
  93. mbedtls_ssl_free(ssl);
  94. ssl_error(ret);
  95. return NULL;
  96. }
  97. return ssl;
  98. }
  99. HL_PRIM void HL_NAME(ssl_close)(mbedtls_ssl_context *ssl) {
  100. mbedtls_ssl_free(ssl);
  101. }
  102. HL_PRIM int HL_NAME(ssl_handshake)(mbedtls_ssl_context *ssl) {
  103. int r;
  104. r = mbedtls_ssl_handshake(ssl);
  105. if( is_ssl_blocking(r) )
  106. return -1;
  107. if( r == MBEDTLS_ERR_SSL_CONN_EOF )
  108. return -2;
  109. if( r != 0 )
  110. return ssl_error(r);
  111. return 0;
  112. }
  113. static bool is_block_error() {
  114. #ifdef HL_WIN
  115. int err = WSAGetLastError();
  116. if (err == WSAEWOULDBLOCK || err == WSAEALREADY || err == WSAETIMEDOUT)
  117. #else
  118. if (errno == EAGAIN || errno == EWOULDBLOCK || errno == EINPROGRESS || errno == EALREADY)
  119. #endif
  120. return true;
  121. return false;
  122. }
  123. static int net_read(void *fd, unsigned char *buf, size_t len) {
  124. int r;
  125. hl_blocking(true);
  126. r = recv((SOCKET)(int_val)fd, (char *)buf, (int)len, MSG_NOSIGNAL);
  127. hl_blocking(false);
  128. if( r == SOCKET_ERROR && is_block_error() )
  129. return MBEDTLS_ERR_SSL_WANT_READ;
  130. return r;
  131. }
  132. static int net_write(void *fd, const unsigned char *buf, size_t len) {
  133. int r = send((SOCKET)(int_val)fd, (char *)buf, (int)len, MSG_NOSIGNAL);
  134. if( r == SOCKET_ERROR && is_block_error() )
  135. return MBEDTLS_ERR_SSL_WANT_WRITE;
  136. return r;
  137. }
  138. HL_PRIM void HL_NAME(ssl_set_socket)(mbedtls_ssl_context *ssl, hl_socket *socket) {
  139. mbedtls_ssl_set_bio(ssl, (void*)(int_val)socket->sock, net_write, net_read, NULL);
  140. }
  141. static int arr_read( void *arr, unsigned char *buf, size_t len ) {
  142. int r = ((int (*)(vdynamic*,unsigned char*,int))hl_aptr(arr,vclosure*)[1]->fun)( hl_aptr(arr,vdynamic*)[0], buf, (int)len );
  143. if( r == -2 ) return MBEDTLS_ERR_SSL_WANT_READ;
  144. return r;
  145. }
  146. static int arr_write( void *arr, const unsigned char *buf, size_t len ) {
  147. int r = ((int (*)(vdynamic*,const unsigned char*,int))hl_aptr(arr,vclosure*)[2]->fun)( hl_aptr(arr,vdynamic*)[0], buf, (int)len );
  148. if( r == -2 ) return MBEDTLS_ERR_SSL_WANT_WRITE;
  149. return r;
  150. }
  151. HL_PRIM void HL_NAME(ssl_set_bio)( mbedtls_ssl_context *ssl, varray *ctx ) {
  152. mbedtls_ssl_set_bio(ssl, ctx, arr_write, arr_read, NULL);
  153. }
  154. HL_PRIM void HL_NAME(ssl_set_hostname)(mbedtls_ssl_context *ssl, vbyte *hostname) {
  155. int ret;
  156. if ((ret = mbedtls_ssl_set_hostname(ssl, (char*)hostname)) != 0)
  157. ssl_error(ret);
  158. }
  159. HL_PRIM hl_ssl_cert *HL_NAME(ssl_get_peer_certificate)(mbedtls_ssl_context *ssl) {
  160. hl_ssl_cert *cert = (hl_ssl_cert*)hl_gc_alloc_noptr(sizeof(hl_ssl_cert));
  161. cert->c = (mbedtls_x509_crt*)mbedtls_ssl_get_peer_cert(ssl);
  162. return cert;
  163. }
  164. DEFINE_PRIM(TSSL, ssl_new, TCONF);
  165. DEFINE_PRIM(_VOID, ssl_close, TSSL);
  166. DEFINE_PRIM(_I32, ssl_handshake, TSSL);
  167. DEFINE_PRIM(_VOID, ssl_set_bio, TSSL _DYN);
  168. DEFINE_PRIM(_VOID, ssl_set_socket, TSSL _SOCK);
  169. DEFINE_PRIM(_VOID, ssl_set_hostname, TSSL _BYTES);
  170. DEFINE_PRIM(TCERT, ssl_get_peer_certificate, TSSL);
  171. HL_PRIM int HL_NAME(ssl_send_char)(mbedtls_ssl_context *ssl, int c) {
  172. unsigned char cc;
  173. int r;
  174. cc = (unsigned char)c;
  175. r = mbedtls_ssl_write(ssl, &cc, 1);
  176. if( r < 0 )
  177. return ssl_block_error(r);
  178. return 1;
  179. }
  180. HL_PRIM int HL_NAME(ssl_send)(mbedtls_ssl_context *ssl, vbyte *buf, int pos, int len) {
  181. int r = mbedtls_ssl_write(ssl, (const unsigned char *)buf + pos, len);
  182. if( r < 0 )
  183. return ssl_block_error(r);
  184. return r;
  185. }
  186. HL_PRIM int HL_NAME(ssl_recv_char)(mbedtls_ssl_context *ssl) {
  187. unsigned char c;
  188. int ret = mbedtls_ssl_read(ssl, &c, 1);
  189. if( ret != 1 )
  190. return ssl_block_error(ret);
  191. return c;
  192. }
  193. HL_PRIM int HL_NAME(ssl_recv)(mbedtls_ssl_context *ssl, vbyte *buf, int pos, int len) {
  194. int ret = mbedtls_ssl_read(ssl, (unsigned char*)buf+pos, len);
  195. if( ret == MBEDTLS_ERR_SSL_PEER_CLOSE_NOTIFY )
  196. return 0;
  197. if( ret < 0 )
  198. return ssl_block_error(ret);
  199. return ret;
  200. }
  201. DEFINE_PRIM(_I32, ssl_send_char, TSSL _I32);
  202. DEFINE_PRIM(_I32, ssl_send, TSSL _BYTES _I32 _I32);
  203. DEFINE_PRIM(_I32, ssl_recv_char, TSSL);
  204. DEFINE_PRIM(_I32, ssl_recv, TSSL _BYTES _I32 _I32);
  205. HL_PRIM mbedtls_ssl_config *HL_NAME(conf_new)(bool server) {
  206. int ret;
  207. mbedtls_ssl_config *conf;
  208. conf = (mbedtls_ssl_config *)hl_gc_alloc_noptr(sizeof(mbedtls_ssl_config));
  209. mbedtls_ssl_config_init(conf);
  210. if ((ret = mbedtls_ssl_config_defaults(conf, server ? MBEDTLS_SSL_IS_SERVER : MBEDTLS_SSL_IS_CLIENT,
  211. MBEDTLS_SSL_TRANSPORT_STREAM, 0)) != 0) {
  212. mbedtls_ssl_config_free(conf);
  213. ssl_error(ret);
  214. return NULL;
  215. }
  216. #if MBEDTLS_VERSION_MAJOR < 4
  217. mbedtls_ssl_conf_rng(conf, mbedtls_ctr_drbg_random, &ctr_drbg);
  218. #endif
  219. return conf;
  220. }
  221. HL_PRIM void HL_NAME(conf_close)(mbedtls_ssl_config *conf) {
  222. mbedtls_ssl_config_free(conf);
  223. }
  224. HL_PRIM void HL_NAME(conf_set_ca)(mbedtls_ssl_config *conf, hl_ssl_cert *cert) {
  225. mbedtls_ssl_conf_ca_chain(conf, cert->c, NULL);
  226. }
  227. HL_PRIM void HL_NAME(conf_set_verify)(mbedtls_ssl_config *conf, int mode) {
  228. if (mode == 2)
  229. mbedtls_ssl_conf_authmode(conf, MBEDTLS_SSL_VERIFY_OPTIONAL);
  230. else if (mode == 1)
  231. mbedtls_ssl_conf_authmode(conf, MBEDTLS_SSL_VERIFY_REQUIRED);
  232. else
  233. mbedtls_ssl_conf_authmode(conf, MBEDTLS_SSL_VERIFY_NONE);
  234. }
  235. HL_PRIM void HL_NAME(conf_set_cert)(mbedtls_ssl_config *conf, hl_ssl_cert *cert, hl_ssl_pkey *key) {
  236. int r;
  237. if ((r = mbedtls_ssl_conf_own_cert(conf, cert->c, key->k)) != 0)
  238. ssl_error(r);
  239. }
  240. typedef struct {
  241. hl_type *t;
  242. hl_ssl_cert *cert;
  243. hl_ssl_pkey *key;
  244. } sni_callb_ret;
  245. static int sni_callback(void *arg, mbedtls_ssl_context *ctx, const unsigned char *name, size_t len) {
  246. if (name && arg) {
  247. vclosure *c = (vclosure*)arg;
  248. sni_callb_ret *ret;
  249. if( c->hasValue )
  250. ret = ((sni_callb_ret*(*)(void*, vbyte*))c->fun)(c->value, (vbyte*)name);
  251. else
  252. ret = ((sni_callb_ret*(*)(vbyte*))c->fun)((vbyte*)name);
  253. if (ret && ret->cert && ret->key) {
  254. return mbedtls_ssl_set_hs_own_cert(ctx, ret->cert->c, ret->key->k);
  255. }
  256. }
  257. return -1;
  258. }
  259. HL_PRIM void HL_NAME(conf_set_servername_callback)(mbedtls_ssl_config *conf, vclosure *cb) {
  260. mbedtls_ssl_conf_sni(conf, sni_callback, (void *)cb);
  261. }
  262. DEFINE_PRIM(TCONF, conf_new, _BOOL);
  263. DEFINE_PRIM(_VOID, conf_close, TCONF);
  264. DEFINE_PRIM(_VOID, conf_set_ca, TCONF TCERT);
  265. DEFINE_PRIM(_VOID, conf_set_verify, TCONF _I32);
  266. DEFINE_PRIM(_VOID, conf_set_cert, TCONF TCERT TPKEY);
  267. DEFINE_PRIM(_VOID, conf_set_servername_callback, TCONF _FUN(_OBJ(TCERT TPKEY), _BYTES));
  268. HL_PRIM hl_ssl_cert *HL_NAME(cert_load_file)(vbyte *file) {
  269. #ifdef HL_CONSOLE
  270. return NULL;
  271. #else
  272. int r;
  273. hl_ssl_cert *cert;
  274. mbedtls_x509_crt *x = (mbedtls_x509_crt*)malloc(sizeof(mbedtls_x509_crt));
  275. mbedtls_x509_crt_init(x);
  276. if ((r = mbedtls_x509_crt_parse_file(x, (char*)file)) != 0) {
  277. mbedtls_x509_crt_free(x);
  278. free(x);
  279. ssl_error(r);
  280. return NULL;
  281. }
  282. cert = (hl_ssl_cert*)hl_gc_alloc_finalizer(sizeof(hl_ssl_cert));
  283. cert->c = x;
  284. cert->finalize = cert_finalize;
  285. return cert;
  286. #endif
  287. }
  288. HL_PRIM hl_ssl_cert *HL_NAME(cert_load_path)(vbyte *path) {
  289. #ifdef HL_CONSOLE
  290. return NULL;
  291. #else
  292. int r;
  293. hl_ssl_cert *cert;
  294. mbedtls_x509_crt *x = (mbedtls_x509_crt*)malloc(sizeof(mbedtls_x509_crt));
  295. mbedtls_x509_crt_init(x);
  296. if ((r = mbedtls_x509_crt_parse_path(x, (char*)path)) != 0) {
  297. mbedtls_x509_crt_free(x);
  298. free(x);
  299. ssl_error(r);
  300. return NULL;
  301. }
  302. cert = (hl_ssl_cert*)hl_gc_alloc_finalizer(sizeof(hl_ssl_cert));
  303. cert->c = x;
  304. cert->finalize = cert_finalize;
  305. return cert;
  306. #endif
  307. }
  308. HL_PRIM hl_ssl_cert *HL_NAME(cert_load_defaults)() {
  309. hl_ssl_cert *v = NULL;
  310. mbedtls_x509_crt *chain = NULL;
  311. #if defined(HL_WIN)
  312. HCERTSTORE store;
  313. PCCERT_CONTEXT cert;
  314. if (store = CertOpenSystemStore(0, (LPCWSTR)L"Root")) {
  315. cert = NULL;
  316. while (cert = CertEnumCertificatesInStore(store, cert)) {
  317. if (chain == NULL) {
  318. chain = (mbedtls_x509_crt*)malloc(sizeof(mbedtls_x509_crt));
  319. mbedtls_x509_crt_init(chain);
  320. }
  321. mbedtls_x509_crt_parse_der(chain, (unsigned char *)cert->pbCertEncoded, cert->cbCertEncoded);
  322. }
  323. CertCloseStore(store, 0);
  324. }
  325. #elif defined(HL_MAC)
  326. CFArrayRef certs;
  327. // Load keychain
  328. if (SecTrustCopyAnchorCertificates(&certs) != errSecSuccess)
  329. return NULL;
  330. CFIndex count = CFArrayGetCount(certs);
  331. for(CFIndex i = 0; i < count; i++) {
  332. SecCertificateRef item = (SecCertificateRef)CFArrayGetValueAtIndex(certs, i);
  333. CFDataRef data = SecCertificateCopyData(item);
  334. if(data) {
  335. if (chain == NULL) {
  336. chain = (mbedtls_x509_crt*)malloc(sizeof(mbedtls_x509_crt));
  337. mbedtls_x509_crt_init(chain);
  338. }
  339. mbedtls_x509_crt_parse_der(chain, (unsigned char *)CFDataGetBytePtr(data), CFDataGetLength(data));
  340. CFRelease(data);
  341. }
  342. }
  343. CFRelease(certs);
  344. #elif defined(HL_CONSOLE)
  345. chain = hl_init_cert_chain();
  346. #endif
  347. if (chain != NULL) {
  348. v = (hl_ssl_cert*)hl_gc_alloc_finalizer(sizeof(hl_ssl_cert));
  349. v->c = chain;
  350. v->finalize = cert_finalize;
  351. }
  352. return v;
  353. }
  354. static vbyte *asn1_buf_to_string(mbedtls_asn1_buf *dat) {
  355. unsigned int i, c;
  356. hl_buffer *buf = hl_alloc_buffer();
  357. for (i = 0; i < dat->len; i++) {
  358. c = dat->p[i];
  359. if (c < 32 || c == 127 || (c > 128 && c < 160))
  360. hl_buffer_char(buf, '?');
  361. else
  362. hl_buffer_char(buf, c);
  363. }
  364. return (vbyte*)hl_buffer_content(buf,NULL);
  365. }
  366. // The following code is adapted from `library/x509_oid.c` in MbedTLS 4.0.0
  367. // Originally Copyright The Mbed TLS Contributors
  368. // SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
  369. #define ADD_LEN(s) s, MBEDTLS_OID_SIZE(s)
  370. #define OID_DESCRIPTOR(s, name, description) {ADD_LEN(s)}
  371. #define NULL_OID_DESCRIPTOR {NULL, 0}
  372. typedef struct {
  373. const char *asn1; /*!< OID ASN.1 representation */
  374. size_t asn1_len; /*!< length of asn1 */
  375. } mbedtls_x509_oid_descriptor_t;
  376. typedef struct {
  377. mbedtls_x509_oid_descriptor_t descriptor;
  378. const char *short_name;
  379. } oid_x520_attr_t;
  380. static const oid_x520_attr_t oid_x520_attr_type[] = {
  381. {
  382. OID_DESCRIPTOR(MBEDTLS_OID_AT_CN, "id-at-commonName", "Common Name"),
  383. "CN",
  384. },
  385. {
  386. OID_DESCRIPTOR(MBEDTLS_OID_AT_COUNTRY, "id-at-countryName", "Country"),
  387. "C",
  388. },
  389. {
  390. OID_DESCRIPTOR(MBEDTLS_OID_AT_LOCALITY, "id-at-locality", "Locality"),
  391. "L",
  392. },
  393. {
  394. OID_DESCRIPTOR(MBEDTLS_OID_AT_STATE, "id-at-state", "State"),
  395. "ST",
  396. },
  397. {
  398. OID_DESCRIPTOR(MBEDTLS_OID_AT_ORGANIZATION, "id-at-organizationName",
  399. "Organization"),
  400. "O",
  401. },
  402. {
  403. OID_DESCRIPTOR(MBEDTLS_OID_AT_ORG_UNIT, "id-at-organizationalUnitName",
  404. "Org Unit"),
  405. "OU",
  406. },
  407. {
  408. OID_DESCRIPTOR(MBEDTLS_OID_PKCS9_EMAIL, "emailAddress",
  409. "E-mail address"),
  410. "emailAddress",
  411. },
  412. {
  413. OID_DESCRIPTOR(MBEDTLS_OID_AT_SERIAL_NUMBER, "id-at-serialNumber",
  414. "Serial number"),
  415. "serialNumber",
  416. },
  417. {
  418. OID_DESCRIPTOR(MBEDTLS_OID_AT_POSTAL_ADDRESS, "id-at-postalAddress",
  419. "Postal address"),
  420. "postalAddress",
  421. },
  422. {
  423. OID_DESCRIPTOR(MBEDTLS_OID_AT_POSTAL_CODE, "id-at-postalCode",
  424. "Postal code"),
  425. "postalCode",
  426. },
  427. {
  428. OID_DESCRIPTOR(MBEDTLS_OID_AT_SUR_NAME, "id-at-surName", "Surname"),
  429. "SN",
  430. },
  431. {
  432. OID_DESCRIPTOR(MBEDTLS_OID_AT_GIVEN_NAME, "id-at-givenName",
  433. "Given name"),
  434. "GN",
  435. },
  436. {
  437. OID_DESCRIPTOR(MBEDTLS_OID_AT_INITIALS, "id-at-initials", "Initials"),
  438. "initials",
  439. },
  440. {
  441. OID_DESCRIPTOR(MBEDTLS_OID_AT_GENERATION_QUALIFIER,
  442. "id-at-generationQualifier", "Generation qualifier"),
  443. "generationQualifier",
  444. },
  445. {
  446. OID_DESCRIPTOR(MBEDTLS_OID_AT_TITLE, "id-at-title", "Title"),
  447. "title",
  448. },
  449. {
  450. OID_DESCRIPTOR(MBEDTLS_OID_AT_DN_QUALIFIER, "id-at-dnQualifier",
  451. "Distinguished Name qualifier"),
  452. "dnQualifier",
  453. },
  454. {
  455. OID_DESCRIPTOR(MBEDTLS_OID_AT_PSEUDONYM, "id-at-pseudonym",
  456. "Pseudonym"),
  457. "pseudonym",
  458. },
  459. #ifdef MBEDTLS_OID_UID
  460. {
  461. OID_DESCRIPTOR(MBEDTLS_OID_UID, "id-uid", "User Id"),
  462. "uid",
  463. },
  464. #endif
  465. {
  466. OID_DESCRIPTOR(MBEDTLS_OID_DOMAIN_COMPONENT, "id-domainComponent",
  467. "Domain component"),
  468. "DC",
  469. },
  470. {
  471. OID_DESCRIPTOR(MBEDTLS_OID_AT_UNIQUE_IDENTIFIER,
  472. "id-at-uniqueIdentifier", "Unique Identifier"),
  473. "uniqueIdentifier",
  474. },
  475. {
  476. NULL_OID_DESCRIPTOR,
  477. NULL,
  478. }};
  479. static const oid_x520_attr_t *
  480. oid_x520_attr_from_asn1(const mbedtls_asn1_buf *oid) {
  481. const oid_x520_attr_t *p = (oid_x520_attr_type);
  482. const mbedtls_x509_oid_descriptor_t *cur =
  483. (const mbedtls_x509_oid_descriptor_t *)p;
  484. if (p == NULL || oid == NULL)
  485. return NULL;
  486. while (cur->asn1 != NULL) {
  487. if (cur->asn1_len == oid->len && memcmp(cur->asn1, oid->p, oid->len) == 0) {
  488. return p;
  489. }
  490. p++;
  491. cur = (const mbedtls_x509_oid_descriptor_t *)p;
  492. }
  493. return NULL;
  494. }
  495. static int oid_get_attr_short_name(const mbedtls_asn1_buf *oid,
  496. const char **short_name) {
  497. const oid_x520_attr_t *data = oid_x520_attr_from_asn1(oid);
  498. if (data == NULL)
  499. return -0x2100;
  500. *short_name = data->short_name;
  501. return 0;
  502. }
  503. // end code adapted from MbedTLS
  504. HL_PRIM vbyte *HL_NAME(cert_get_subject)(hl_ssl_cert *cert, vbyte *objname) {
  505. mbedtls_x509_name *obj = &cert->c->subject;
  506. const char *rname = (char*)objname;
  507. while (obj != NULL) {
  508. const char *oname;
  509. int r = oid_get_attr_short_name(&obj->oid, &oname);
  510. if (r == 0 && strcmp(oname, rname) == 0)
  511. return asn1_buf_to_string(&obj->val);
  512. obj = obj->next;
  513. }
  514. return NULL;
  515. }
  516. HL_PRIM vbyte *HL_NAME(cert_get_issuer)(hl_ssl_cert *cert, vbyte *objname) {
  517. mbedtls_x509_name *obj = &cert->c->issuer;
  518. const char *rname = (char*)objname;
  519. while (obj != NULL) {
  520. const char *oname;
  521. int r = oid_get_attr_short_name(&obj->oid, &oname);
  522. if (r == 0 && strcmp(oname, rname) == 0)
  523. return asn1_buf_to_string(&obj->val);
  524. obj = obj->next;
  525. }
  526. return NULL;
  527. }
  528. HL_PRIM varray *HL_NAME(cert_get_altnames)(hl_ssl_cert *cert) {
  529. mbedtls_asn1_sequence *cur;
  530. int count = 0;
  531. int pos = 0;
  532. varray *a = NULL;
  533. vbyte **current = NULL;
  534. mbedtls_x509_crt *crt = cert->c;
  535. #if MBEDTLS_VERSION_MAJOR >= 3
  536. if (mbedtls_x509_crt_has_ext_type(crt, MBEDTLS_X509_EXT_SUBJECT_ALT_NAME)) {
  537. #else
  538. if (crt->ext_types & MBEDTLS_X509_EXT_SUBJECT_ALT_NAME) {
  539. #endif
  540. cur = &crt->subject_alt_names;
  541. while (cur != NULL) {
  542. if (pos == count) {
  543. int ncount = count == 0 ? 16 : count * 2;
  544. varray *narr = hl_alloc_array(&hlt_bytes, ncount);
  545. vbyte **ncur = hl_aptr(narr, vbyte*);
  546. memcpy(ncur, current, count * sizeof(void*));
  547. current = ncur;
  548. a = narr;
  549. count = ncount;
  550. }
  551. current[pos++] = asn1_buf_to_string(&cur->buf);
  552. cur = cur->next;
  553. }
  554. }
  555. if (a == NULL) a = hl_alloc_array(&hlt_bytes, 0);
  556. a->size = pos;
  557. return a;
  558. }
  559. static varray *x509_time_to_array(mbedtls_x509_time *t) {
  560. varray *a = NULL;
  561. int *p;
  562. if (!t)
  563. hl_error("Invalid x509 time");
  564. a = hl_alloc_array(&hlt_i32, 6);
  565. p = hl_aptr(a, int);
  566. p[0] = t->year;
  567. p[1] = t->mon;
  568. p[2] = t->day;
  569. p[3] = t->hour;
  570. p[4] = t->min;
  571. p[5] = t->sec;
  572. return a;
  573. }
  574. HL_PRIM varray *HL_NAME(cert_get_notbefore)(hl_ssl_cert *cert) {
  575. return x509_time_to_array(&cert->c->valid_from);
  576. }
  577. HL_PRIM varray *HL_NAME(cert_get_notafter)(hl_ssl_cert *cert) {
  578. return x509_time_to_array(&cert->c->valid_to);
  579. }
  580. HL_PRIM hl_ssl_cert *HL_NAME(cert_get_next)(hl_ssl_cert *cert) {
  581. hl_ssl_cert *ncert;
  582. if (cert->c->next == NULL)
  583. return NULL;
  584. ncert = (hl_ssl_cert*)hl_gc_alloc_noptr(sizeof(hl_ssl_cert));
  585. ncert->c = cert->c->next;
  586. return ncert;
  587. }
  588. HL_PRIM hl_ssl_cert *HL_NAME(cert_add_pem)(hl_ssl_cert *cert, vbyte *data) {
  589. mbedtls_x509_crt *crt;
  590. int r, len;
  591. unsigned char *buf;
  592. if (cert != NULL)
  593. crt = cert->c;
  594. else{
  595. crt = (mbedtls_x509_crt*)malloc(sizeof(mbedtls_x509_crt));
  596. mbedtls_x509_crt_init(crt);
  597. }
  598. len = (int)strlen((char*)data) + 1;
  599. buf = (unsigned char *)malloc(len);
  600. memcpy(buf, (char*)data, len - 1);
  601. buf[len - 1] = '\0';
  602. r = mbedtls_x509_crt_parse(crt, buf, len);
  603. free(buf);
  604. if (r < 0) {
  605. if (cert == NULL) {
  606. mbedtls_x509_crt_free(crt);
  607. free(crt);
  608. }
  609. ssl_error(r);
  610. return NULL;
  611. }
  612. if (cert == NULL) {
  613. cert = (hl_ssl_cert*)hl_gc_alloc_finalizer(sizeof(hl_ssl_cert));
  614. cert->c = crt;
  615. cert->finalize = cert_finalize;
  616. }
  617. return cert;
  618. }
  619. HL_PRIM hl_ssl_cert *HL_NAME(cert_add_der)(hl_ssl_cert *cert, vbyte *data, int len) {
  620. mbedtls_x509_crt *crt;
  621. int r;
  622. if (cert != NULL)
  623. crt = cert->c;
  624. else {
  625. crt = (mbedtls_x509_crt*)malloc(sizeof(mbedtls_x509_crt));
  626. mbedtls_x509_crt_init(crt);
  627. }
  628. if ((r = mbedtls_x509_crt_parse_der(crt, (const unsigned char*)data, len)) < 0) {
  629. if (cert == NULL) {
  630. mbedtls_x509_crt_free(crt);
  631. free(crt);
  632. }
  633. ssl_error(r);
  634. return NULL;
  635. }
  636. if (cert == NULL) {
  637. cert = (hl_ssl_cert*)hl_gc_alloc_finalizer(sizeof(hl_ssl_cert));
  638. cert->c = crt;
  639. cert->finalize = cert_finalize;
  640. }
  641. return cert;
  642. }
  643. DEFINE_PRIM(TCERT, cert_load_defaults, _NO_ARG);
  644. DEFINE_PRIM(TCERT, cert_load_file, _BYTES);
  645. DEFINE_PRIM(TCERT, cert_load_path, _BYTES);
  646. DEFINE_PRIM(_BYTES, cert_get_subject, TCERT _BYTES);
  647. DEFINE_PRIM(_BYTES, cert_get_issuer, TCERT _BYTES);
  648. DEFINE_PRIM(_ARR, cert_get_altnames, TCERT);
  649. DEFINE_PRIM(_ARR, cert_get_notbefore, TCERT);
  650. DEFINE_PRIM(_ARR, cert_get_notafter, TCERT);
  651. DEFINE_PRIM(TCERT, cert_get_next, TCERT);
  652. DEFINE_PRIM(TCERT, cert_add_pem, TCERT _BYTES);
  653. DEFINE_PRIM(TCERT, cert_add_der, TCERT _BYTES _I32);
  654. HL_PRIM hl_ssl_pkey *HL_NAME(key_from_der)(vbyte *data, int len, bool pub) {
  655. int r;
  656. hl_ssl_pkey *key;
  657. mbedtls_pk_context *pk = (mbedtls_pk_context *)malloc(sizeof(mbedtls_pk_context));
  658. mbedtls_pk_init(pk);
  659. if (pub)
  660. r = mbedtls_pk_parse_public_key(pk, (const unsigned char*)data, len);
  661. else
  662. #if MBEDTLS_VERSION_MAJOR >= 4
  663. r = mbedtls_pk_parse_key(pk, (const unsigned char*)data, len, NULL, 0);
  664. #elif MBEDTLS_VERSION_MAJOR >= 3
  665. r = mbedtls_pk_parse_key(pk, (const unsigned char*)data, len, NULL, 0, mbedtls_ctr_drbg_random, &ctr_drbg);
  666. #else
  667. r = mbedtls_pk_parse_key(pk, (const unsigned char*)data, len, NULL, 0);
  668. #endif
  669. if (r != 0) {
  670. mbedtls_pk_free(pk);
  671. free(pk);
  672. ssl_error(r);
  673. return NULL;
  674. }
  675. key = (hl_ssl_pkey*)hl_gc_alloc_finalizer(sizeof(hl_ssl_pkey));
  676. key->k = pk;
  677. key->finalize = pkey_finalize;
  678. return key;
  679. }
  680. HL_PRIM hl_ssl_pkey *HL_NAME(key_from_pem)(vbyte *data, bool pub, vbyte *pass) {
  681. int r, len;
  682. hl_ssl_pkey *key;
  683. unsigned char *buf;
  684. mbedtls_pk_context *pk = (mbedtls_pk_context *)malloc(sizeof(mbedtls_pk_context));
  685. mbedtls_pk_init(pk);
  686. len = (int)strlen((char*)data) + 1;
  687. buf = (unsigned char *)malloc(len);
  688. memcpy(buf, (char*)data, len - 1);
  689. buf[len - 1] = '\0';
  690. if (pub)
  691. r = mbedtls_pk_parse_public_key(pk, buf, len);
  692. #if MBEDTLS_VERSION_MAJOR >= 4
  693. else if (pass == NULL)
  694. r = mbedtls_pk_parse_key(pk, buf, len, NULL, 0);
  695. else
  696. r = mbedtls_pk_parse_key(pk, buf, len, (const unsigned char*)pass, strlen((char*)pass));
  697. #elif MBEDTLS_VERSION_MAJOR >= 3
  698. else if (pass == NULL)
  699. r = mbedtls_pk_parse_key(pk, buf, len, NULL, 0, mbedtls_ctr_drbg_random, &ctr_drbg);
  700. else
  701. r = mbedtls_pk_parse_key(pk, buf, len, (const unsigned char*)pass, strlen((char*)pass), mbedtls_ctr_drbg_random, &ctr_drbg);
  702. #else
  703. else if (pass == NULL)
  704. r = mbedtls_pk_parse_key(pk, buf, len, NULL, 0);
  705. else
  706. r = mbedtls_pk_parse_key(pk, buf, len, (const unsigned char*)pass, strlen((char*)pass));
  707. #endif
  708. free(buf);
  709. if (r != 0) {
  710. mbedtls_pk_free(pk);
  711. free(pk);
  712. ssl_error(r);
  713. return NULL;
  714. }
  715. key = (hl_ssl_pkey*)hl_gc_alloc_finalizer(sizeof(hl_ssl_pkey));
  716. key->k = pk;
  717. key->finalize = pkey_finalize;
  718. return key;
  719. }
  720. DEFINE_PRIM(TPKEY, key_from_der, _BYTES _I32 _BOOL);
  721. DEFINE_PRIM(TPKEY, key_from_pem, _BYTES _BOOL _BYTES);
  722. static mbedtls_md_type_t md_type_from_string(const char *alg) {
  723. if (strcmp(alg, "MD5") == 0) {
  724. return MBEDTLS_MD_MD5;
  725. } else if(strcmp(alg, "SHA1") == 0) {
  726. return MBEDTLS_MD_SHA1;
  727. } else if (strcmp(alg, "SHA224") == 0) {
  728. return MBEDTLS_MD_SHA224;
  729. } else if (strcmp(alg, "SHA256") == 0) {
  730. return MBEDTLS_MD_SHA256;
  731. } else if (strcmp(alg, "SHA384") == 0) {
  732. return MBEDTLS_MD_SHA384;
  733. } else if (strcmp(alg, "SHA512") == 0) {
  734. return MBEDTLS_MD_SHA512;
  735. } else if (strcmp(alg, "RIPEMD160") == 0) {
  736. return MBEDTLS_MD_RIPEMD160;
  737. } else {
  738. hl_error("Unknown hash algorithm: %s", alg);
  739. }
  740. }
  741. HL_PRIM vbyte *HL_NAME(dgst_make)(vbyte *data, int len, vbyte *alg, int *size) {
  742. const mbedtls_md_info_t *md;
  743. int mdlen, r = -1;
  744. vbyte *out;
  745. md = mbedtls_md_info_from_type(md_type_from_string((char*)alg));
  746. if (md == NULL) {
  747. hl_error("Invalid hash algorithm");
  748. return NULL;
  749. }
  750. mdlen = mbedtls_md_get_size(md);
  751. *size = mdlen;
  752. out = hl_gc_alloc_noptr(mdlen);
  753. if ((r = mbedtls_md(md, (const unsigned char *)data, len, out)) != 0){
  754. ssl_error(r);
  755. return NULL;
  756. }
  757. return out;
  758. }
  759. HL_PRIM vbyte *HL_NAME(dgst_sign)(vbyte *data, int len, hl_ssl_pkey *key, vbyte *alg, int *size) {
  760. const mbedtls_md_info_t *md;
  761. int r = -1;
  762. vbyte *out;
  763. unsigned char hash[MBEDTLS_MD_MAX_SIZE];
  764. size_t ssize = size ? *size : 0;
  765. md = mbedtls_md_info_from_type(md_type_from_string((char*)alg));
  766. if (md == NULL) {
  767. hl_error("Invalid hash algorithm");
  768. return NULL;
  769. }
  770. if ((r = mbedtls_md(md, (unsigned char *)data, len, hash)) != 0){
  771. ssl_error(r);
  772. return NULL;
  773. }
  774. #if MBEDTLS_VERSION_MAJOR >= 4
  775. out = hl_gc_alloc_noptr(MBEDTLS_PK_SIGNATURE_MAX_SIZE);
  776. if ((r = mbedtls_pk_sign(key->k, mbedtls_md_get_type(md), hash, mbedtls_md_get_size(md), out, MBEDTLS_PK_SIGNATURE_MAX_SIZE, (size ? &ssize : NULL))) != 0) {
  777. #elif MBEDTLS_VERSION_MAJOR >= 3
  778. out = hl_gc_alloc_noptr(MBEDTLS_PK_SIGNATURE_MAX_SIZE);
  779. if ((r = mbedtls_pk_sign(key->k, mbedtls_md_get_type(md), hash, mbedtls_md_get_size(md), out, MBEDTLS_PK_SIGNATURE_MAX_SIZE, (size ? &ssize : NULL), mbedtls_ctr_drbg_random, &ctr_drbg)) != 0) {
  780. #else
  781. out = hl_gc_alloc_noptr(MBEDTLS_MPI_MAX_SIZE);
  782. if ((r = mbedtls_pk_sign(key->k, mbedtls_md_get_type(md), hash, 0, out, (size ? &ssize : NULL), mbedtls_ctr_drbg_random, &ctr_drbg)) != 0){
  783. #endif
  784. ssl_error(r);
  785. return NULL;
  786. }
  787. if( size ) *size = (int)ssize;
  788. return out;
  789. }
  790. HL_PRIM bool HL_NAME(dgst_verify)(vbyte *data, int dlen, vbyte *sign, int slen, hl_ssl_pkey *key, vbyte *alg) {
  791. const mbedtls_md_info_t *md;
  792. int r = -1;
  793. unsigned char hash[MBEDTLS_MD_MAX_SIZE];
  794. md = mbedtls_md_info_from_type(md_type_from_string((char*)alg));
  795. if (md == NULL) {
  796. hl_error("Invalid hash algorithm");
  797. return false;
  798. }
  799. if ((r = mbedtls_md(md, (const unsigned char *)data, dlen, hash)) != 0)
  800. return ssl_error(r);
  801. if ((r = mbedtls_pk_verify(key->k, mbedtls_md_get_type(md), hash, 0, (unsigned char *)sign, slen)) != 0)
  802. return false;
  803. return true;
  804. }
  805. DEFINE_PRIM(_BYTES, dgst_make, _BYTES _I32 _BYTES _REF(_I32));
  806. DEFINE_PRIM(_BYTES, dgst_sign, _BYTES _I32 TPKEY _BYTES _REF(_I32));
  807. DEFINE_PRIM(_BOOL, dgst_verify, _BYTES _I32 _BYTES _I32 TPKEY _BYTES);
  808. #if _MSC_VER
  809. static void threading_mutex_init_alt(mbedtls_threading_mutex_t *mutex) {
  810. if (mutex == NULL)
  811. return;
  812. InitializeCriticalSection(&mutex->cs);
  813. mutex->is_valid = 1;
  814. }
  815. static void threading_mutex_free_alt(mbedtls_threading_mutex_t *mutex) {
  816. if (mutex == NULL || !mutex->is_valid)
  817. return;
  818. DeleteCriticalSection(&mutex->cs);
  819. mutex->is_valid = 0;
  820. }
  821. static int threading_mutex_lock_alt(mbedtls_threading_mutex_t *mutex) {
  822. if (mutex == NULL || !mutex->is_valid)
  823. return(MBEDTLS_ERR_THREADING_BAD_INPUT_DATA);
  824. EnterCriticalSection(&mutex->cs);
  825. return(0);
  826. }
  827. static int threading_mutex_unlock_alt(mbedtls_threading_mutex_t *mutex) {
  828. if (mutex == NULL || !mutex->is_valid)
  829. return(MBEDTLS_ERR_THREADING_BAD_INPUT_DATA);
  830. LeaveCriticalSection(&mutex->cs);
  831. return(0);
  832. }
  833. #endif
  834. HL_PRIM void HL_NAME(ssl_init)() {
  835. if (ssl_init_done)
  836. return;
  837. ssl_init_done = true;
  838. #if _MSC_VER
  839. mbedtls_threading_set_alt(threading_mutex_init_alt, threading_mutex_free_alt,
  840. threading_mutex_lock_alt, threading_mutex_unlock_alt);
  841. #endif
  842. // Init RNG
  843. #if MBEDTLS_VERSION_MAJOR < 4
  844. mbedtls_entropy_init(&entropy);
  845. mbedtls_ctr_drbg_init(&ctr_drbg);
  846. mbedtls_ctr_drbg_seed(&ctr_drbg, mbedtls_entropy_func, &entropy, NULL, 0);
  847. #endif
  848. #ifdef MBEDTLS_PSA_CRYPTO_C
  849. psa_crypto_init();
  850. #endif
  851. }
  852. DEFINE_PRIM(_VOID, ssl_init, _NO_ARG);