diff options
Diffstat (limited to 'src/security')
| -rw-r--r-- | src/security/cert/X509Certificate.cpp | 48 | ||||
| -rw-r--r-- | src/security/cert/certificateChain.cpp | 53 | ||||
| -rw-r--r-- | src/security/cert/defaultCertificateVerifier.cpp | 178 | ||||
| -rw-r--r-- | src/security/cert/gnutls/X509Certificate_GnuTLS.cpp | 290 | ||||
| -rw-r--r-- | src/security/cert/openssl/X509Certificate_OpenSSL.cpp | 574 | ||||
| -rw-r--r-- | src/security/defaultAuthenticator.cpp | 115 | ||||
| -rw-r--r-- | src/security/digest/md5/md5MessageDigest.cpp | 347 | ||||
| -rw-r--r-- | src/security/digest/messageDigest.cpp | 57 | ||||
| -rw-r--r-- | src/security/digest/messageDigestFactory.cpp | 84 | ||||
| -rw-r--r-- | src/security/digest/sha1/sha1MessageDigest.cpp | 271 | ||||
| -rw-r--r-- | src/security/sasl/SASLContext.cpp | 208 | ||||
| -rw-r--r-- | src/security/sasl/SASLMechanismFactory.cpp | 144 | ||||
| -rw-r--r-- | src/security/sasl/SASLSession.cpp | 192 | ||||
| -rw-r--r-- | src/security/sasl/SASLSocket.cpp | 236 | ||||
| -rw-r--r-- | src/security/sasl/builtinSASLMechanism.cpp | 195 | ||||
| -rw-r--r-- | src/security/sasl/defaultSASLAuthenticator.cpp | 153 |
16 files changed, 0 insertions, 3145 deletions
diff --git a/src/security/cert/X509Certificate.cpp b/src/security/cert/X509Certificate.cpp deleted file mode 100644 index 2eebabfd..00000000 --- a/src/security/cert/X509Certificate.cpp +++ /dev/null @@ -1,48 +0,0 @@ -// -// VMime library (http://www.vmime.org) -// Copyright (C) 2002-2013 Vincent Richard <[email protected]> -// -// This program is free software; you can redistribute it and/or -// modify it under the terms of the GNU General Public License as -// published by the Free Software Foundation; either version 3 of -// the License, or (at your option) any later version. -// -// This program is distributed in the hope that it will be useful, -// but WITHOUT ANY WARRANTY; without even the implied warranty of -// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -// General Public License for more details. -// -// You should have received a copy of the GNU General Public License along -// with this program; if not, write to the Free Software Foundation, Inc., -// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. -// -// Linking this library statically or dynamically with other modules is making -// a combined work based on this library. Thus, the terms and conditions of -// the GNU General Public License cover the whole combination. -// - -#include "vmime/config.hpp" - - -#if VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_TLS_SUPPORT - - -#include "vmime/security/cert/X509Certificate.hpp" - - -namespace vmime { -namespace security { -namespace cert { - - -X509Certificate::~X509Certificate() -{ -} - - -} // cert -} // security -} // vmime - - -#endif // VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_TLS_SUPPORT diff --git a/src/security/cert/certificateChain.cpp b/src/security/cert/certificateChain.cpp deleted file mode 100644 index 3cb4e360..00000000 --- a/src/security/cert/certificateChain.cpp +++ /dev/null @@ -1,53 +0,0 @@ -// -// VMime library (http://www.vmime.org) -// Copyright (C) 2002-2013 Vincent Richard <[email protected]> -// -// This program is free software; you can redistribute it and/or -// modify it under the terms of the GNU General Public License as -// published by the Free Software Foundation; either version 3 of -// the License, or (at your option) any later version. -// -// This program is distributed in the hope that it will be useful, -// but WITHOUT ANY WARRANTY; without even the implied warranty of -// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -// General Public License for more details. -// -// You should have received a copy of the GNU General Public License along -// with this program; if not, write to the Free Software Foundation, Inc., -// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. -// -// Linking this library statically or dynamically with other modules is making -// a combined work based on this library. Thus, the terms and conditions of -// the GNU General Public License cover the whole combination. -// - -#include "vmime/security/cert/certificateChain.hpp" - - -namespace vmime { -namespace security { -namespace cert { - - -certificateChain::certificateChain(const std::vector <shared_ptr <certificate> >& certs) - : m_certs(certs) -{ -} - - -unsigned int certificateChain::getCount() const -{ - return static_cast <unsigned int>(m_certs.size()); -} - - -shared_ptr <certificate> certificateChain::getAt(const unsigned int index) -{ - return m_certs[index]; -} - - -} // cert -} // security -} // vmime - diff --git a/src/security/cert/defaultCertificateVerifier.cpp b/src/security/cert/defaultCertificateVerifier.cpp deleted file mode 100644 index 1a95b353..00000000 --- a/src/security/cert/defaultCertificateVerifier.cpp +++ /dev/null @@ -1,178 +0,0 @@ -// -// VMime library (http://www.vmime.org) -// Copyright (C) 2002-2013 Vincent Richard <[email protected]> -// -// This program is free software; you can redistribute it and/or -// modify it under the terms of the GNU General Public License as -// published by the Free Software Foundation; either version 3 of -// the License, or (at your option) any later version. -// -// This program is distributed in the hope that it will be useful, -// but WITHOUT ANY WARRANTY; without even the implied warranty of -// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -// General Public License for more details. -// -// You should have received a copy of the GNU General Public License along -// with this program; if not, write to the Free Software Foundation, Inc., -// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. -// -// Linking this library statically or dynamically with other modules is making -// a combined work based on this library. Thus, the terms and conditions of -// the GNU General Public License cover the whole combination. -// - -#include "vmime/config.hpp" - -#if VMIME_HAVE_TLS_SUPPORT - -#include "vmime/security/cert/defaultCertificateVerifier.hpp" - -#include "vmime/security/cert/X509Certificate.hpp" - -#include "vmime/exception.hpp" - - -namespace vmime { -namespace security { -namespace cert { - - -defaultCertificateVerifier::defaultCertificateVerifier() -{ -} - - -defaultCertificateVerifier::~defaultCertificateVerifier() -{ -} - - -defaultCertificateVerifier::defaultCertificateVerifier(const defaultCertificateVerifier&) - : certificateVerifier() -{ - // Not used -} - - -void defaultCertificateVerifier::verify - (shared_ptr <certificateChain> chain, const string& hostname) -{ - if (chain->getCount() == 0) - return; - - const string type = chain->getAt(0)->getType(); - - if (type == "X.509") - verifyX509(chain, hostname); - else - throw exceptions::unsupported_certificate_type(type); -} - - -void defaultCertificateVerifier::verifyX509 - (shared_ptr <certificateChain> chain, const string& hostname) -{ - // For every certificate in the chain, verify that the certificate - // has been issued by the next certificate in the chain - if (chain->getCount() >= 2) - { - for (unsigned int i = 0 ; i < chain->getCount() - 1 ; ++i) - { - shared_ptr <X509Certificate> cert = - dynamicCast <X509Certificate>(chain->getAt(i)); - - shared_ptr <X509Certificate> next = - dynamicCast <X509Certificate>(chain->getAt(i + 1)); - - if (!cert->checkIssuer(next)) - { - throw exceptions::certificate_verification_exception - ("Subject/issuer verification failed."); - } - } - } - - // For every certificate in the chain, verify that the certificate - // is valid at the current time - const datetime now = datetime::now(); - - for (unsigned int i = 0 ; i < chain->getCount() ; ++i) - { - shared_ptr <X509Certificate> cert = - dynamicCast <X509Certificate>(chain->getAt(i)); - - const datetime begin = cert->getActivationDate(); - const datetime end = cert->getExpirationDate(); - - if (now < begin || now > end) - { - throw exceptions::certificate_verification_exception - ("Validity date check failed."); - } - } - - // Check whether the certificate can be trusted - - // -- First, verify that the the last certificate in the chain was - // -- issued by a third-party that we trust - shared_ptr <X509Certificate> lastCert = - dynamicCast <X509Certificate>(chain->getAt(chain->getCount() - 1)); - - bool trusted = false; - - for (unsigned int i = 0 ; !trusted && i < m_x509RootCAs.size() ; ++i) - { - shared_ptr <X509Certificate> rootCa = m_x509RootCAs[i]; - - if (lastCert->verify(rootCa)) - trusted = true; - } - - // -- Next, if the issuer certificate cannot be verified against - // -- root CAs, compare the subject's certificate against the - // -- trusted certificates - shared_ptr <X509Certificate> firstCert = - dynamicCast <X509Certificate>(chain->getAt(0)); - - for (unsigned int i = 0 ; !trusted && i < m_x509TrustedCerts.size() ; ++i) - { - shared_ptr <X509Certificate> cert = m_x509TrustedCerts[i]; - - if (firstCert->equals(cert)) - trusted = true; - } - - if (!trusted) - { - throw exceptions::certificate_verification_exception - ("Cannot verify certificate against trusted certificates."); - } - - // Ensure the first certificate's subject name matches server hostname - if (!firstCert->verifyHostName(hostname)) - { - throw exceptions::certificate_verification_exception - ("Server identity cannot be verified."); - } -} - - -void defaultCertificateVerifier::setX509RootCAs - (const std::vector <shared_ptr <X509Certificate> >& caCerts) -{ - m_x509RootCAs = caCerts; -} - - -void defaultCertificateVerifier::setX509TrustedCerts - (const std::vector <shared_ptr <X509Certificate> >& trustedCerts) -{ - m_x509TrustedCerts = trustedCerts; -} - - -} // cert -} // security -} // vmime - -#endif diff --git a/src/security/cert/gnutls/X509Certificate_GnuTLS.cpp b/src/security/cert/gnutls/X509Certificate_GnuTLS.cpp deleted file mode 100644 index f96ddddb..00000000 --- a/src/security/cert/gnutls/X509Certificate_GnuTLS.cpp +++ /dev/null @@ -1,290 +0,0 @@ -// -// VMime library (http://www.vmime.org) -// Copyright (C) 2002-2013 Vincent Richard <[email protected]> -// -// This program is free software; you can redistribute it and/or -// modify it under the terms of the GNU General Public License as -// published by the Free Software Foundation; either version 3 of -// the License, or (at your option) any later version. -// -// This program is distributed in the hope that it will be useful, -// but WITHOUT ANY WARRANTY; without even the implied warranty of -// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -// General Public License for more details. -// -// You should have received a copy of the GNU General Public License along -// with this program; if not, write to the Free Software Foundation, Inc., -// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. -// -// Linking this library statically or dynamically with other modules is making -// a combined work based on this library. Thus, the terms and conditions of -// the GNU General Public License cover the whole combination. -// - -#include "vmime/config.hpp" - - -#if VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_TLS_SUPPORT && VMIME_TLS_SUPPORT_LIB_IS_GNUTLS - - -#include <gnutls/gnutls.h> -#include <gnutls/x509.h> - -#include <ctime> - -#include "vmime/security/cert/gnutls/X509Certificate_GnuTLS.hpp" - -#include "vmime/utility/outputStreamByteArrayAdapter.hpp" - - -namespace vmime { -namespace security { -namespace cert { - - -#ifndef VMIME_BUILDING_DOC - -struct GnuTLSX509CertificateInternalData -{ - GnuTLSX509CertificateInternalData() - { - gnutls_x509_crt_init(&cert); - } - - ~GnuTLSX509CertificateInternalData() - { - gnutls_x509_crt_deinit(cert); - } - - - gnutls_x509_crt cert; -}; - -#endif // VMIME_BUILDING_DOC - - -X509Certificate_GnuTLS::X509Certificate_GnuTLS() - : m_data(new GnuTLSX509CertificateInternalData) -{ -} - - -X509Certificate_GnuTLS::X509Certificate_GnuTLS(const X509Certificate&) - : X509Certificate(), m_data(NULL) -{ - // Not used -} - - -X509Certificate_GnuTLS::~X509Certificate_GnuTLS() -{ - delete m_data; -} - - -void* X509Certificate_GnuTLS::getInternalData() -{ - return &m_data->cert; -} - - -// static -shared_ptr <X509Certificate> X509Certificate::import(utility::inputStream& is) -{ - byteArray bytes; - byte_t chunk[4096]; - - while (!is.eof()) - { - const size_t len = is.read(chunk, sizeof(chunk)); - bytes.insert(bytes.end(), chunk, chunk + len); - } - - return import(&bytes[0], bytes.size()); -} - - -// static -shared_ptr <X509Certificate> X509Certificate::import - (const byte_t* data, const size_t length) -{ - gnutls_datum buffer; - buffer.data = const_cast <byte_t*>(data); - buffer.size = static_cast <unsigned int>(length); - - // Try DER format - shared_ptr <X509Certificate_GnuTLS> derCert = make_shared <X509Certificate_GnuTLS>(); - - if (gnutls_x509_crt_import(derCert->m_data->cert, &buffer, GNUTLS_X509_FMT_DER) >= 0) - return derCert; - - // Try PEM format - shared_ptr <X509Certificate_GnuTLS> pemCert = make_shared <X509Certificate_GnuTLS>(); - - if (gnutls_x509_crt_import(pemCert->m_data->cert, &buffer, GNUTLS_X509_FMT_PEM) >= 0) - return pemCert; - - return null; -} - - -void X509Certificate_GnuTLS::write - (utility::outputStream& os, const Format format) const -{ - size_t dataSize = 0; - gnutls_x509_crt_fmt fmt = GNUTLS_X509_FMT_DER; - - switch (format) - { - case FORMAT_DER: fmt = GNUTLS_X509_FMT_DER; break; - case FORMAT_PEM: fmt = GNUTLS_X509_FMT_PEM; break; - } - - gnutls_x509_crt_export(m_data->cert, fmt, NULL, &dataSize); - - std::vector <byte_t> data(dataSize); - - gnutls_x509_crt_export(m_data->cert, fmt, &data[0], &dataSize); - - os.write(reinterpret_cast <byte_t*>(&data[0]), dataSize); -} - - -const byteArray X509Certificate_GnuTLS::getSerialNumber() const -{ - char serial[64]; - size_t serialSize = sizeof(serial); - - gnutls_x509_crt_get_serial(m_data->cert, serial, &serialSize); - - return byteArray(serial, serial + serialSize); -} - - -bool X509Certificate_GnuTLS::checkIssuer(shared_ptr <const X509Certificate> issuer_) const -{ - shared_ptr <const X509Certificate_GnuTLS> issuer = - dynamicCast <const X509Certificate_GnuTLS>(issuer_); - - return (gnutls_x509_crt_check_issuer - (m_data->cert, issuer->m_data->cert) >= 1); -} - - -bool X509Certificate_GnuTLS::verify(shared_ptr <const X509Certificate> caCert_) const -{ - shared_ptr <const X509Certificate_GnuTLS> caCert = - dynamicCast <const X509Certificate_GnuTLS>(caCert_); - - unsigned int verify = 0; - - const int res = gnutls_x509_crt_verify - (m_data->cert, &(caCert->m_data->cert), 1, - GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT, - &verify); - - return (res == 0 && verify == 0); -} - - -bool X509Certificate_GnuTLS::verifyHostName(const string& hostname) const -{ - return gnutls_x509_crt_check_hostname(m_data->cert, hostname.c_str()) != 0; -} - - -const datetime X509Certificate_GnuTLS::getActivationDate() const -{ - const time_t t = gnutls_x509_crt_get_activation_time(m_data->cert); - return datetime(t); -} - - -const datetime X509Certificate_GnuTLS::getExpirationDate() const -{ - const time_t t = gnutls_x509_crt_get_expiration_time(m_data->cert); - return datetime(t); -} - - -const byteArray X509Certificate_GnuTLS::getFingerprint(const DigestAlgorithm algo) const -{ - gnutls_digest_algorithm galgo; - - switch (algo) - { - case DIGEST_MD5: - - galgo = GNUTLS_DIG_MD5; - break; - - default: - case DIGEST_SHA1: - - galgo = GNUTLS_DIG_SHA; - break; - } - - size_t bufferSize = 0; - gnutls_x509_crt_get_fingerprint - (m_data->cert, galgo, NULL, &bufferSize); - - std::vector <byte_t> buffer(bufferSize); - - if (gnutls_x509_crt_get_fingerprint - (m_data->cert, galgo, &buffer[0], &bufferSize) == 0) - { - byteArray res; - res.insert(res.end(), &buffer[0], &buffer[0] + bufferSize); - - return res; - } - - return byteArray(); -} - - -const byteArray X509Certificate_GnuTLS::getEncoded() const -{ - byteArray bytes; - utility::outputStreamByteArrayAdapter os(bytes); - - write(os, FORMAT_DER); - - return bytes; -} - - -const string X509Certificate_GnuTLS::getType() const -{ - return "X.509"; -} - - -int X509Certificate_GnuTLS::getVersion() const -{ - return gnutls_x509_crt_get_version(m_data->cert); -} - - -bool X509Certificate_GnuTLS::equals(shared_ptr <const certificate> other) const -{ - shared_ptr <const X509Certificate_GnuTLS> otherX509 = - dynamicCast <const X509Certificate_GnuTLS>(other); - - if (!otherX509) - return false; - - const byteArray fp1 = getFingerprint(DIGEST_MD5); - const byteArray fp2 = otherX509->getFingerprint(DIGEST_MD5); - - return fp1 == fp2; -} - - -} // cert -} // security -} // vmime - - -#endif // VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_TLS_SUPPORT && VMIME_TLS_SUPPORT_LIB_IS_GNUTLS diff --git a/src/security/cert/openssl/X509Certificate_OpenSSL.cpp b/src/security/cert/openssl/X509Certificate_OpenSSL.cpp deleted file mode 100644 index 5f81b2bf..00000000 --- a/src/security/cert/openssl/X509Certificate_OpenSSL.cpp +++ /dev/null @@ -1,574 +0,0 @@ -// -// VMime library (http://www.vmime.org) -// Copyright (C) 2002-2013 Vincent Richard <[email protected]> -// -// This program is free software; you can redistribute it and/or -// modify it under the terms of the GNU General Public License as -// published by the Free Software Foundation; either version 3 of -// the License, or (at your option) any later version. -// -// This program is distributed in the hope that it will be useful, -// but WITHOUT ANY WARRANTY; without even the implied warranty of -// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -// General Public License for more details. -// -// You should have received a copy of the GNU General Public License along -// with this program; if not, write to the Free Software Foundation, Inc., -// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. -// -// Linking this library statically or dynamically with other modules is making -// a combined work based on this library. Thus, the terms and conditions of -// the GNU General Public License cover the whole combination. -// - -#include "vmime/config.hpp" - - -#if VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_TLS_SUPPORT && VMIME_TLS_SUPPORT_LIB_IS_OPENSSL - - -#include <cstdio> -#include <ctime> -#include <map> -#include <algorithm> - -#include "vmime/security/cert/openssl/X509Certificate_OpenSSL.hpp" - -#include "vmime/net/tls/openssl/OpenSSLInitializer.hpp" - -#include "vmime/utility/outputStreamByteArrayAdapter.hpp" - -#include "vmime/exception.hpp" - -#include <openssl/x509.h> -#include <openssl/x509v3.h> -#include <openssl/conf.h> -#include <openssl/bio.h> -#include <openssl/pem.h> -#include <openssl/err.h> - - -#ifdef _WIN32 -# define strcasecmp _stricmp -# define strncasecmp _strnicmp -#endif - - -namespace vmime { -namespace security { -namespace cert { - - -static net::tls::OpenSSLInitializer::autoInitializer openSSLInitializer; - - -#ifndef VMIME_BUILDING_DOC - -class monthMap -{ -public: - - monthMap() - { - m_monthMap["jan"] = vmime::datetime::JAN; - m_monthMap["feb"] = vmime::datetime::FEB; - m_monthMap["mar"] = vmime::datetime::MAR; - m_monthMap["apr"] = vmime::datetime::APR; - m_monthMap["may"] = vmime::datetime::MAY; - m_monthMap["jun"] = vmime::datetime::JUN; - m_monthMap["jul"] = vmime::datetime::JUL; - m_monthMap["aug"] = vmime::datetime::AUG; - m_monthMap["sep"] = vmime::datetime::SEP; - m_monthMap["oct"] = vmime::datetime::OCT; - m_monthMap["nov"] = vmime::datetime::NOV; - m_monthMap["dec"] = vmime::datetime::DEC; - } - - int getMonth(vmime::string mstr) - { - std::transform(mstr.begin(), mstr.end(), mstr.begin(), ::tolower); - - std::map <vmime::string, vmime::datetime::Months>::const_iterator - c_it = m_monthMap.find(mstr); - - if (c_it != m_monthMap.end()) - return c_it->second; - - return -1; - } - -private: - - std::map<vmime::string, vmime::datetime::Months> m_monthMap; -}; - -static monthMap sg_monthMap; - - - -struct OpenSSLX509CertificateInternalData -{ - OpenSSLX509CertificateInternalData() - { - cert = 0; - } - - ~OpenSSLX509CertificateInternalData() - { - if (cert) - X509_free(cert); - } - - X509* cert; -}; - -#endif // VMIME_BUILDING_DOC - - -X509Certificate_OpenSSL::X509Certificate_OpenSSL() - : m_data(new OpenSSLX509CertificateInternalData) -{ -} - - -X509Certificate_OpenSSL::X509Certificate_OpenSSL(X509* cert) - : m_data(new OpenSSLX509CertificateInternalData) -{ - m_data->cert = X509_dup(cert); -} - - -X509Certificate_OpenSSL::X509Certificate_OpenSSL(const X509Certificate_OpenSSL&) - : X509Certificate(), m_data(NULL) -{ - // Not used -} - - -X509Certificate_OpenSSL::~X509Certificate_OpenSSL() -{ - delete m_data; -} - - -void* X509Certificate_OpenSSL::getInternalData() -{ - return &m_data->cert; -} - - -// static -shared_ptr <X509Certificate> X509Certificate_OpenSSL::importInternal(X509* cert) -{ - if (cert) - return make_shared <X509Certificate_OpenSSL>(reinterpret_cast <X509 *>(cert)); - - return null; -} - - -// static -shared_ptr <X509Certificate> X509Certificate::import(utility::inputStream& is) -{ - byteArray bytes; - byte_t chunk[4096]; - - while (!is.eof()) - { - const size_t len = is.read(chunk, sizeof(chunk)); - bytes.insert(bytes.end(), chunk, chunk + len); - } - - return import(&bytes[0], bytes.size()); -} - - -// static -shared_ptr <X509Certificate> X509Certificate::import - (const byte_t* data, const size_t length) -{ - shared_ptr <X509Certificate_OpenSSL> cert = make_shared <X509Certificate_OpenSSL>(); - - BIO* membio = BIO_new_mem_buf(const_cast <byte_t*>(data), static_cast <int>(length)); - - if (!PEM_read_bio_X509(membio, &(cert->m_data->cert), 0, 0)) - { - BIO_vfree(membio); - return null; - } - - BIO_vfree(membio); - - return cert; -} - - -void X509Certificate_OpenSSL::write - (utility::outputStream& os, const Format format) const -{ - BIO* membio = 0; - long dataSize = 0; - unsigned char* out = 0; - - if (format == FORMAT_DER) - { - if ((dataSize = i2d_X509(m_data->cert, &out)) < 0) - goto err; - - os.write(reinterpret_cast <byte_t*>(out), dataSize); - os.flush(); - OPENSSL_free(out); - } - else if (format == FORMAT_PEM) - { - membio = BIO_new(BIO_s_mem()); - BIO_set_close(membio, BIO_CLOSE); - - if (!PEM_write_bio_X509(membio, m_data->cert)) - goto pem_err; - - dataSize = BIO_get_mem_data(membio, &out); - os.write(reinterpret_cast <byte_t*>(out), dataSize); - os.flush(); - BIO_vfree(membio); - } - else - { - throw vmime::exceptions::unsupported_certificate_type("Unknown cert type"); - } - - return; // #### Early Return #### - -pem_err: - { - if (membio) - BIO_vfree(membio); - } - -err: - { - char errstr[256]; - long ec = ERR_get_error(); - ERR_error_string(ec, errstr); - throw vmime::exceptions::certificate_exception( - "OpenSSLX509Certificate_OpenSSL::write exception - " + string(errstr)); - } -} - - -const byteArray X509Certificate_OpenSSL::getSerialNumber() const -{ - ASN1_INTEGER *serial = X509_get_serialNumber(m_data->cert); - BIGNUM *bnser = ASN1_INTEGER_to_BN(serial, NULL); - int n = BN_num_bytes(bnser); - byte_t* outbuf = new byte_t[n]; - BN_bn2bin(bnser, outbuf); - byteArray ser(outbuf, outbuf + n); - delete [] outbuf; - BN_free(bnser); - return ser; -} - - -bool X509Certificate_OpenSSL::checkIssuer(shared_ptr <const X509Certificate> cert_) const -{ - shared_ptr <const X509Certificate_OpenSSL> cert = - dynamicCast <const X509Certificate_OpenSSL>(cert_); - - // Get issuer for this cert - BIO *out; - unsigned char *issuer; - - out = BIO_new(BIO_s_mem()); - X509_NAME_print_ex(out, X509_get_issuer_name(m_data->cert), 0, XN_FLAG_RFC2253); - long n = BIO_get_mem_data(out, &issuer); - vmime::string thisIssuerName((char*)issuer, n); - BIO_free(out); - - // Get subject of issuer - unsigned char *subject; - out = BIO_new(BIO_s_mem()); - X509_NAME_print_ex(out, X509_get_subject_name(cert->m_data->cert), 0, XN_FLAG_RFC2253); - n = BIO_get_mem_data(out, &subject); - vmime::string subjOfIssuer((char*)subject, n); - BIO_free(out); - - return subjOfIssuer == thisIssuerName; -} - - -bool X509Certificate_OpenSSL::verify(shared_ptr <const X509Certificate> caCert_) const -{ - shared_ptr <const X509Certificate_OpenSSL> caCert = - dynamicCast <const X509Certificate_OpenSSL>(caCert_); - - - bool verified = false; - bool error = true; - - X509_STORE *store = X509_STORE_new(); - - if (store) - { - X509_STORE_CTX *verifyCtx = X509_STORE_CTX_new(); - - if (verifyCtx) - { - if (X509_STORE_add_cert(store, caCert->m_data->cert)) - { - X509_STORE_CTX_init(verifyCtx, store, m_data->cert, NULL); - - int ret = X509_verify_cert(verifyCtx); - - if (ret == 1) - { - verified = true; - error = false; - } - else if (ret == 0) - { - verified = false; - error = false; - } - - //X509_verify_cert_error_string(vrfy_ctx->error) - - X509_STORE_CTX_free(verifyCtx); - } - } - - X509_STORE_free(store); - } - - return verified && !error; -} - - -// static -bool X509Certificate_OpenSSL::cnMatch(const char* cnBuf, const char* host) -{ - // Right-to-left match, looking for a '*' wildcard - const bool hasWildcard = (strlen(cnBuf) > 1 && cnBuf[0] == '*' && cnBuf[1] == '.'); - const char* cnBufReverseEndPtr = (cnBuf + (hasWildcard ? 2 : 0)); - const char* hostPtr = host + strlen(host); - const char* cnPtr = cnBuf + strlen(cnBuf); - - bool matches = true; - - while (matches && --hostPtr >= host && --cnPtr >= cnBufReverseEndPtr) - matches = (toupper(*hostPtr) == toupper(*cnPtr)); - - return matches; -} - - -bool X509Certificate_OpenSSL::verifyHostName(const string& hostname) const -{ - // First, check subject common name against hostname - char CNBuffer[1024]; - CNBuffer[sizeof(CNBuffer) - 1] = '\0'; - - X509_NAME* xname = X509_get_subject_name(m_data->cert); - - if (X509_NAME_get_text_by_NID(xname, NID_commonName, CNBuffer, sizeof(CNBuffer)) != -1) - { - if (cnMatch(CNBuffer, hostname.c_str())) - return true; - } - - // Now, look in subject alternative names - for (int i = 0, extCount = X509_get_ext_count(m_data->cert) ; i < extCount ; ++i) - { - X509_EXTENSION* ext = X509_get_ext(m_data->cert, i); - const char* extStr = OBJ_nid2sn(OBJ_obj2nid(X509_EXTENSION_get_object(ext))); - - if (strcmp(extStr, "subjectAltName") == 0) - { -#ifdef _WIN32 - X509V3_EXT_METHOD* method; -#else - const X509V3_EXT_METHOD* method; -#endif - - if ((method = X509V3_EXT_get(ext)) != NULL) - { - const unsigned char* extVal = ext->value->data; - void *extValStr; - - if (method->it) - { - extValStr = ASN1_item_d2i - (NULL, &extVal, ext->value->length, ASN1_ITEM_ptr(method->it)); - } - else - { - extValStr = method->d2i - (NULL, &extVal, ext->value->length); - } - - if (extValStr && method->i2v) - { - STACK_OF(CONF_VALUE)* val = method->i2v(method, extValStr, NULL); - - for (int j = 0 ; j < sk_CONF_VALUE_num(val) ; ++j) - { - CONF_VALUE* cnf = sk_CONF_VALUE_value(val, j); - - if ((strcasecmp(cnf->name, "DNS") == 0 && - strcasecmp(cnf->value, hostname.c_str()) == 0) - || - (strncasecmp(cnf->name, "IP", 2) == 0 && - strcasecmp(cnf->value, hostname.c_str()) == 0)) - { - return true; - } - } - } - } - } - } - - return false; -} - - -const datetime X509Certificate_OpenSSL::convertX509Date(void* time) const -{ - char* buffer; - BIO* out = BIO_new(BIO_s_mem()); - BIO_set_close(out, BIO_CLOSE); - - ASN1_TIME* asn1_time = reinterpret_cast<ASN1_TIME*>(time); - ASN1_TIME_print(out, asn1_time); - - int sz = BIO_get_mem_data(out, &buffer); - char* dest = new char[sz + 1]; - dest[sz] = 0; - memcpy(dest, buffer, sz); - vmime::string t(dest); - - BIO_free(out); - delete dest; - - if (t.size() > 0) - { - char month[4] = {0}; - char zone[4] = {0}; - int day, hour, minute, second, year; - int nrconv = sscanf(t.c_str(), "%s %2d %02d:%02d:%02d %d%s", month, &day, &hour, &minute, &second,&year,zone); - - if (nrconv >= 6) - return datetime(year, sg_monthMap.getMonth(vmime::string(month)), day, hour, minute, second); - } - - // let datetime try and parse it - return datetime(t); -} - - -const datetime X509Certificate_OpenSSL::getActivationDate() const -{ - return convertX509Date(X509_get_notBefore(m_data->cert)); -} - - -const datetime X509Certificate_OpenSSL::getExpirationDate() const -{ - return convertX509Date(X509_get_notAfter(m_data->cert)); -} - - -const byteArray X509Certificate_OpenSSL::getFingerprint(const DigestAlgorithm algo) const -{ - BIO *out; - int j; - unsigned int n; - const EVP_MD *digest; - unsigned char * fingerprint, *result; - unsigned char md[EVP_MAX_MD_SIZE]; - - switch (algo) - { - case DIGEST_MD5: - - digest = EVP_md5(); - break; - - default: - case DIGEST_SHA1: - - digest = EVP_sha1(); - break; - } - - out = BIO_new(BIO_s_mem()); - BIO_set_close(out, BIO_CLOSE); - - if (X509_digest(m_data->cert, digest, md, &n)) - { - for (j=0; j<(int)n; j++) - { - BIO_printf (out, "%02X",md[j]); - if (j+1 != (int)n) BIO_printf(out, ":"); - } - } - - n = BIO_get_mem_data(out, &fingerprint); - result = new unsigned char[n]; - memcpy (result, fingerprint, n); - BIO_free(out); - - byteArray res; - res.insert(res.end(), &result[0], &result[0] + n); - - delete [] result; - - return res; -} - - -const byteArray X509Certificate_OpenSSL::getEncoded() const -{ - byteArray bytes; - utility::outputStreamByteArrayAdapter os(bytes); - - write(os, FORMAT_DER); - - return bytes; -} - - -const string X509Certificate_OpenSSL::getType() const -{ - return "X.509"; -} - - -int X509Certificate_OpenSSL::getVersion() const -{ - return (int)X509_get_version(m_data->cert); -} - - -bool X509Certificate_OpenSSL::equals(shared_ptr <const certificate> other) const -{ - shared_ptr <const X509Certificate_OpenSSL> otherX509 = - dynamicCast <const X509Certificate_OpenSSL>(other); - - if (!otherX509) - return false; - - const byteArray fp1 = getFingerprint(DIGEST_MD5); - const byteArray fp2 = otherX509->getFingerprint(DIGEST_MD5); - - return fp1 == fp2; -} - - -} // cert -} // security -} // vmime - - -#endif // VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_TLS_SUPPORT && VMIME_TLS_SUPPORT_LIB_IS_OPENSSL - diff --git a/src/security/defaultAuthenticator.cpp b/src/security/defaultAuthenticator.cpp deleted file mode 100644 index 790196d2..00000000 --- a/src/security/defaultAuthenticator.cpp +++ /dev/null @@ -1,115 +0,0 @@ -// -// VMime library (http://www.vmime.org) -// Copyright (C) 2002-2013 Vincent Richard <[email protected]> -// -// This program is free software; you can redistribute it and/or -// modify it under the terms of the GNU General Public License as -// published by the Free Software Foundation; either version 3 of -// the License, or (at your option) any later version. -// -// This program is distributed in the hope that it will be useful, -// but WITHOUT ANY WARRANTY; without even the implied warranty of -// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -// General Public License for more details. -// -// You should have received a copy of the GNU General Public License along -// with this program; if not, write to the Free Software Foundation, Inc., -// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. -// -// Linking this library statically or dynamically with other modules is making -// a combined work based on this library. Thus, the terms and conditions of -// the GNU General Public License cover the whole combination. -// - -#include "vmime/config.hpp" - - -#if VMIME_HAVE_MESSAGING_FEATURES - - -#include "vmime/security/defaultAuthenticator.hpp" - -#include "vmime/net/service.hpp" - -#include "vmime/platform.hpp" - - -namespace vmime { -namespace security { - - -defaultAuthenticator::defaultAuthenticator() -{ -} - - -defaultAuthenticator::~defaultAuthenticator() -{ -} - - -const string defaultAuthenticator::getUsername() const -{ - shared_ptr <const net::service> service = m_service.lock(); - - const string prefix = service->getInfos().getPropertyPrefix(); - const propertySet& props = service->getSession()->getProperties(); - - if (props.hasProperty(prefix + net::serviceInfos::property::AUTH_USERNAME.getName())) - return props[prefix + net::serviceInfos::property::AUTH_USERNAME.getName()]; - - throw exceptions::no_auth_information(); -} - - -const string defaultAuthenticator::getPassword() const -{ - shared_ptr <const net::service> service = m_service.lock(); - - const string prefix = service->getInfos().getPropertyPrefix(); - const propertySet& props = service->getSession()->getProperties(); - - if (props.hasProperty(prefix + net::serviceInfos::property::AUTH_PASSWORD.getName())) - return props[prefix + net::serviceInfos::property::AUTH_PASSWORD.getName()]; - - throw exceptions::no_auth_information(); -} - - -const string defaultAuthenticator::getHostname() const -{ - return platform::getHandler()->getHostName(); -} - - -const string defaultAuthenticator::getAnonymousToken() const -{ - return "anonymous@" + platform::getHandler()->getHostName(); -} - - -const string defaultAuthenticator::getServiceName() const -{ - // Information cannot be provided - throw exceptions::no_auth_information(); -} - - -void defaultAuthenticator::setService(shared_ptr <net::service> serv) -{ - m_service = serv; -} - - -weak_ptr <net::service> defaultAuthenticator::getService() const -{ - return m_service; -} - - -} // security -} // vmime - - -#endif // VMIME_HAVE_MESSAGING_FEATURES - diff --git a/src/security/digest/md5/md5MessageDigest.cpp b/src/security/digest/md5/md5MessageDigest.cpp deleted file mode 100644 index a83f0623..00000000 --- a/src/security/digest/md5/md5MessageDigest.cpp +++ /dev/null @@ -1,347 +0,0 @@ -// -// VMime library (http://www.vmime.org) -// Copyright (C) 2002-2013 Vincent Richard <[email protected]> -// -// This program is free software; you can redistribute it and/or -// modify it under the terms of the GNU General Public License as -// published by the Free Software Foundation; either version 3 of -// the License, or (at your option) any later version. -// -// This program is distributed in the hope that it will be useful, -// but WITHOUT ANY WARRANTY; without even the implied warranty of -// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -// General Public License for more details. -// -// You should have received a copy of the GNU General Public License along -// with this program; if not, write to the Free Software Foundation, Inc., -// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. -// -// Linking this library statically or dynamically with other modules is making -// a combined work based on this library. Thus, the terms and conditions of -// the GNU General Public License cover the whole combination. -// -// -// Derived from cryptoapi implementation, originally based on the -// public domain implementation written by Colin Plumb in 1993. -// -// Copyright (C) Cryptoapi developers. -// -// Algorithm Copyright: -// -// Copyright (C) 1991-2, RSA Data Security, Inc. Created 1991. All -// rights reserved. -// -// License to copy and use this software is granted provided that it -// is identified as the "RSA Data Security, Inc. MD5 Message-Digest -// Algorithm" in all material mentioning or referencing this software -// or this function. -// -// License is also granted to make and use derivative works provided -// that such works are identified as "derived from the RSA Data -// Security, Inc. MD5 Message-Digest Algorithm" in all material -// mentioning or referencing the derived work. -// -// RSA Data Security, Inc. makes no representations concerning either -// the merchantability of this software or the suitability of this -// software forany particular purpose. It is provided "as is" -// without express or implied warranty of any kind. -// These notices must be retained in any copies of any part of this -// documentation and/or software. - -#include "vmime/security/digest/md5/md5MessageDigest.hpp" - -#include <cstring> - - -namespace vmime { -namespace security { -namespace digest { -namespace md5 { - - -md5MessageDigest::md5MessageDigest() -{ - init(); -} - - -void md5MessageDigest::reset() -{ - init(); -} - - -void md5MessageDigest::init() -{ - m_hash[0] = 0x67452301; - m_hash[1] = 0xefcdab89; - m_hash[2] = 0x98badcfe; - m_hash[3] = 0x10325476; - - m_byteCount = 0; - m_finalized = false; -} - - -static void copyUint8Array(vmime_uint8* dest, const vmime_uint8* src, size_t count) -{ - for ( ; count >= 4 ; count -= 4, dest += 4, src += 4) - { - dest[0] = src[0]; - dest[1] = src[1]; - dest[2] = src[2]; - dest[3] = src[3]; - } - - for ( ; count ; --count, ++dest, ++src) - dest[0] = src[0]; -} - - -static inline vmime_uint32 swapUint32(const vmime_uint32 D) -{ - return ((D << 24) | ((D << 8) & 0x00FF0000) | ((D >> 8) & 0x0000FF00) | (D >> 24)); -} - - -static inline void swapUint32Array(vmime_uint32* buf, size_t words) -{ - for ( ; words >= 4 ; words -= 4, buf += 4) - { - buf[0] = swapUint32(buf[0]); - buf[1] = swapUint32(buf[1]); - buf[2] = swapUint32(buf[2]); - buf[3] = swapUint32(buf[3]); - } - - for ( ; words ; --words, ++buf) - buf[0] = swapUint32(buf[0]); -} - - -void md5MessageDigest::update(const byte_t b) -{ - update(&b, 1); -} - - -void md5MessageDigest::update(const string& s) -{ - update(reinterpret_cast <const byte_t*>(s.data()), s.length()); -} - - -void md5MessageDigest::update(const byte_t* data, const size_t offset, const size_t len) -{ - update(data + offset, len); -} - - -void md5MessageDigest::update(const byte_t* data, const size_t length) -{ - const size_t avail = 64 - (m_byteCount & 0x3f); - size_t len = length; - - m_byteCount += len; - - if (avail > len) - { - copyUint8Array(m_block.b8 + (64 - avail), data, len); - return; - } - - copyUint8Array(m_block.b8 + (64 - avail), data, avail); - transformHelper(); - - data += avail; - len -= avail; - - while (len >= 64) - { - copyUint8Array(m_block.b8, data, 64); - transformHelper(); - - data += 64; - len -= 64; - } - - copyUint8Array(m_block.b8, data, len); -} - - -void md5MessageDigest::finalize(const string& s) -{ - update(s); - finalize(); -} - - -void md5MessageDigest::finalize(const byte_t* buffer, const size_t len) -{ - update(buffer, len); - finalize(); -} - - -void md5MessageDigest::finalize(const byte_t* buffer, - const size_t offset, const size_t len) -{ - update(buffer, offset, len); - finalize(); -} - - -void md5MessageDigest::finalize() -{ - const long offset = m_byteCount & 0x3f; - - vmime_uint8* p = m_block.b8 + offset; - long padding = 56 - (offset + 1); - - *p++ = 0x80; - - if (padding < 0) - { - memset(p, 0x00, padding + 8); - transformHelper(); - p = m_block.b8; - padding = 56; - } - - memset(p, 0, padding); - - m_block.b32[14] = static_cast <vmime_uint32>(m_byteCount << 3); - m_block.b32[15] = static_cast <vmime_uint32>(m_byteCount >> 29); - -#if VMIME_BYTE_ORDER_BIG_ENDIAN - swapUint32Array(m_block.b32, (64 - 8) / 4); -#endif - - transform(); - -#if VMIME_BYTE_ORDER_BIG_ENDIAN - swapUint32Array(m_hash, 4); -#endif - - m_finalized = true; -} - - -void md5MessageDigest::transformHelper() -{ -#if VMIME_BYTE_ORDER_BIG_ENDIAN - swapUint32Array(m_block.b32, 64 / 4); -#endif - transform(); -} - - -void md5MessageDigest::transform() -{ - const vmime_uint32* const in = m_block.b32; - - vmime_uint32 a = m_hash[0]; - vmime_uint32 b = m_hash[1]; - vmime_uint32 c = m_hash[2]; - vmime_uint32 d = m_hash[3]; - -#define F1(x, y, z) (z ^ (x & (y ^ z))) -#define F2(x, y, z) F1(z, x, y) -#define F3(x, y, z) (x ^ y ^ z) -#define F4(x, y, z) (y ^ (x | ~z)) - -#define MD5STEP(f, w, x, y, z, in, s) \ - (w += f(x, y, z) + in, w = (w<<s | w>>(32-s)) + x) - - MD5STEP(F1, a, b, c, d, in[0] + 0xd76aa478, 7); - MD5STEP(F1, d, a, b, c, in[1] + 0xe8c7b756, 12); - MD5STEP(F1, c, d, a, b, in[2] + 0x242070db, 17); - MD5STEP(F1, b, c, d, a, in[3] + 0xc1bdceee, 22); - MD5STEP(F1, a, b, c, d, in[4] + 0xf57c0faf, 7); - MD5STEP(F1, d, a, b, c, in[5] + 0x4787c62a, 12); - MD5STEP(F1, c, d, a, b, in[6] + 0xa8304613, 17); - MD5STEP(F1, b, c, d, a, in[7] + 0xfd469501, 22); - MD5STEP(F1, a, b, c, d, in[8] + 0x698098d8, 7); - MD5STEP(F1, d, a, b, c, in[9] + 0x8b44f7af, 12); - MD5STEP(F1, c, d, a, b, in[10] + 0xffff5bb1, 17); - MD5STEP(F1, b, c, d, a, in[11] + 0x895cd7be, 22); - MD5STEP(F1, a, b, c, d, in[12] + 0x6b901122, 7); - MD5STEP(F1, d, a, b, c, in[13] + 0xfd987193, 12); - MD5STEP(F1, c, d, a, b, in[14] + 0xa679438e, 17); - MD5STEP(F1, b, c, d, a, in[15] + 0x49b40821, 22); - - MD5STEP(F2, a, b, c, d, in[1] + 0xf61e2562, 5); - MD5STEP(F2, d, a, b, c, in[6] + 0xc040b340, 9); - MD5STEP(F2, c, d, a, b, in[11] + 0x265e5a51, 14); - MD5STEP(F2, b, c, d, a, in[0] + 0xe9b6c7aa, 20); - MD5STEP(F2, a, b, c, d, in[5] + 0xd62f105d, 5); - MD5STEP(F2, d, a, b, c, in[10] + 0x02441453, 9); - MD5STEP(F2, c, d, a, b, in[15] + 0xd8a1e681, 14); - MD5STEP(F2, b, c, d, a, in[4] + 0xe7d3fbc8, 20); - MD5STEP(F2, a, b, c, d, in[9] + 0x21e1cde6, 5); - MD5STEP(F2, d, a, b, c, in[14] + 0xc33707d6, 9); - MD5STEP(F2, c, d, a, b, in[3] + 0xf4d50d87, 14); - MD5STEP(F2, b, c, d, a, in[8] + 0x455a14ed, 20); - MD5STEP(F2, a, b, c, d, in[13] + 0xa9e3e905, 5); - MD5STEP(F2, d, a, b, c, in[2] + 0xfcefa3f8, 9); - MD5STEP(F2, c, d, a, b, in[7] + 0x676f02d9, 14); - MD5STEP(F2, b, c, d, a, in[12] + 0x8d2a4c8a, 20); - - MD5STEP(F3, a, b, c, d, in[5] + 0xfffa3942, 4); - MD5STEP(F3, d, a, b, c, in[8] + 0x8771f681, 11); - MD5STEP(F3, c, d, a, b, in[11] + 0x6d9d6122, 16); - MD5STEP(F3, b, c, d, a, in[14] + 0xfde5380c, 23); - MD5STEP(F3, a, b, c, d, in[1] + 0xa4beea44, 4); - MD5STEP(F3, d, a, b, c, in[4] + 0x4bdecfa9, 11); - MD5STEP(F3, c, d, a, b, in[7] + 0xf6bb4b60, 16); - MD5STEP(F3, b, c, d, a, in[10] + 0xbebfbc70, 23); - MD5STEP(F3, a, b, c, d, in[13] + 0x289b7ec6, 4); - MD5STEP(F3, d, a, b, c, in[0] + 0xeaa127fa, 11); - MD5STEP(F3, c, d, a, b, in[3] + 0xd4ef3085, 16); - MD5STEP(F3, b, c, d, a, in[6] + 0x04881d05, 23); - MD5STEP(F3, a, b, c, d, in[9] + 0xd9d4d039, 4); - MD5STEP(F3, d, a, b, c, in[12] + 0xe6db99e5, 11); - MD5STEP(F3, c, d, a, b, in[15] + 0x1fa27cf8, 16); - MD5STEP(F3, b, c, d, a, in[2] + 0xc4ac5665, 23); - - MD5STEP(F4, a, b, c, d, in[0] + 0xf4292244, 6); - MD5STEP(F4, d, a, b, c, in[7] + 0x432aff97, 10); - MD5STEP(F4, c, d, a, b, in[14] + 0xab9423a7, 15); - MD5STEP(F4, b, c, d, a, in[5] + 0xfc93a039, 21); - MD5STEP(F4, a, b, c, d, in[12] + 0x655b59c3, 6); - MD5STEP(F4, d, a, b, c, in[3] + 0x8f0ccc92, 10); - MD5STEP(F4, c, d, a, b, in[10] + 0xffeff47d, 15); - MD5STEP(F4, b, c, d, a, in[1] + 0x85845dd1, 21); - MD5STEP(F4, a, b, c, d, in[8] + 0x6fa87e4f, 6); - MD5STEP(F4, d, a, b, c, in[15] + 0xfe2ce6e0, 10); - MD5STEP(F4, c, d, a, b, in[6] + 0xa3014314, 15); - MD5STEP(F4, b, c, d, a, in[13] + 0x4e0811a1, 21); - MD5STEP(F4, a, b, c, d, in[4] + 0xf7537e82, 6); - MD5STEP(F4, d, a, b, c, in[11] + 0xbd3af235, 10); - MD5STEP(F4, c, d, a, b, in[2] + 0x2ad7d2bb, 15); - MD5STEP(F4, b, c, d, a, in[9] + 0xeb86d391, 21); - - m_hash[0] += a; - m_hash[1] += b; - m_hash[2] += c; - m_hash[3] += d; -} - - -size_t md5MessageDigest::getDigestLength() const -{ - return 16; -} - - -const byte_t* md5MessageDigest::getDigest() const -{ - return reinterpret_cast <const byte_t*>(m_hash); -} - - -} // md5 -} // digest -} // security -} // vmime - diff --git a/src/security/digest/messageDigest.cpp b/src/security/digest/messageDigest.cpp deleted file mode 100644 index 18fc8628..00000000 --- a/src/security/digest/messageDigest.cpp +++ /dev/null @@ -1,57 +0,0 @@ -// -// VMime library (http://www.vmime.org) -// Copyright (C) 2002-2013 Vincent Richard <[email protected]> -// -// This program is free software; you can redistribute it and/or -// modify it under the terms of the GNU General Public License as -// published by the Free Software Foundation; either version 3 of -// the License, or (at your option) any later version. -// -// This program is distributed in the hope that it will be useful, -// but WITHOUT ANY WARRANTY; without even the implied warranty of -// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -// General Public License for more details. -// -// You should have received a copy of the GNU General Public License along -// with this program; if not, write to the Free Software Foundation, Inc., -// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. -// -// Linking this library statically or dynamically with other modules is making -// a combined work based on this library. Thus, the terms and conditions of -// the GNU General Public License cover the whole combination. -// - -#include "vmime/security/digest/messageDigest.hpp" - -#include <sstream> - - -namespace vmime { -namespace security { -namespace digest { - - -const string messageDigest::getHexDigest() const -{ - const byte_t* hash = getDigest(); - const size_t len = getDigestLength(); - - static const unsigned char hex[] = "0123456789abcdef"; - - std::ostringstream oss; - oss.imbue(std::locale::classic()); - - for (size_t i = 0 ; i < len ; ++i) - { - oss << hex[(hash[i] & 0xf0) >> 4]; - oss << hex[(hash[i] & 0x0f)]; - } - - return oss.str(); -} - - -} // digest -} // security -} // vmime - diff --git a/src/security/digest/messageDigestFactory.cpp b/src/security/digest/messageDigestFactory.cpp deleted file mode 100644 index 2831c5a1..00000000 --- a/src/security/digest/messageDigestFactory.cpp +++ /dev/null @@ -1,84 +0,0 @@ -// -// VMime library (http://www.vmime.org) -// Copyright (C) 2002-2013 Vincent Richard <[email protected]> -// -// This program is free software; you can redistribute it and/or -// modify it under the terms of the GNU General Public License as -// published by the Free Software Foundation; either version 3 of -// the License, or (at your option) any later version. -// -// This program is distributed in the hope that it will be useful, -// but WITHOUT ANY WARRANTY; without even the implied warranty of -// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -// General Public License for more details. -// -// You should have received a copy of the GNU General Public License along -// with this program; if not, write to the Free Software Foundation, Inc., -// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. -// -// Linking this library statically or dynamically with other modules is making -// a combined work based on this library. Thus, the terms and conditions of -// the GNU General Public License cover the whole combination. -// - -#include "vmime/security/digest/messageDigestFactory.hpp" -#include "vmime/exception.hpp" - -#include "vmime/security/digest/md5/md5MessageDigest.hpp" -#include "vmime/security/digest/sha1/sha1MessageDigest.hpp" - - -namespace vmime { -namespace security { -namespace digest { - - -messageDigestFactory::messageDigestFactory() -{ - registerAlgorithm <md5::md5MessageDigest>("md5"); - registerAlgorithm <sha1::sha1MessageDigest>("sha1"); -} - - -messageDigestFactory::~messageDigestFactory() -{ -} - - -messageDigestFactory* messageDigestFactory::getInstance() -{ - static messageDigestFactory instance; - return (&instance); -} - - -shared_ptr <messageDigest> messageDigestFactory::create(const string& name) -{ - const MapType::const_iterator it = m_algos.find - (utility::stringUtils::toLower(name)); - - if (it != m_algos.end()) - return (*it).second->create(); - - throw exceptions::no_digest_algorithm_available(name); -} - - -const std::vector <string> messageDigestFactory::getSupportedAlgorithms() const -{ - std::vector <string> res; - - for (MapType::const_iterator it = m_algos.begin() ; - it != m_algos.end() ; ++it) - { - res.push_back((*it).first); - } - - return res; -} - - -} // digest -} // security -} // vmime - diff --git a/src/security/digest/sha1/sha1MessageDigest.cpp b/src/security/digest/sha1/sha1MessageDigest.cpp deleted file mode 100644 index aa055af5..00000000 --- a/src/security/digest/sha1/sha1MessageDigest.cpp +++ /dev/null @@ -1,271 +0,0 @@ -// -// VMime library (http://www.vmime.org) -// Copyright (C) 2002-2013 Vincent Richard <[email protected]> -// -// This program is free software; you can redistribute it and/or -// modify it under the terms of the GNU General Public License as -// published by the Free Software Foundation; either version 3 of -// the License, or (at your option) any later version. -// -// This program is distributed in the hope that it will be useful, -// but WITHOUT ANY WARRANTY; without even the implied warranty of -// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -// General Public License for more details. -// -// You should have received a copy of the GNU General Public License along -// with this program; if not, write to the Free Software Foundation, Inc., -// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. -// -// Linking this library statically or dynamically with other modules is making -// a combined work based on this library. Thus, the terms and conditions of -// the GNU General Public License cover the whole combination. -// -// -// This is an implementation by Steve Reid <[email protected]> -// 100% public domain. - -#include "vmime/security/digest/sha1/sha1MessageDigest.hpp" - -#include <cstring> -#include <cassert> - - -namespace vmime { -namespace security { -namespace digest { -namespace sha1 { - - -#define rol(value, bits) (((value) << (bits)) | ((value) >> (32 - (bits)))) - -// blk0() and blk() perform the initial expand. -// I got the idea of expanding during the round function from SSLeay -#if VMIME_BYTE_ORDER_LITTLE_ENDIAN - #define blk0(i) (block->l[i] = (rol(block->l[i], 24) & 0xFF00FF00) \ - | (rol(block->l[i], 8) & 0x00FF00FF)) -#else - #define blk0(i) block->l[i] -#endif - -#define blk(i) (block->l[i & 15] = rol(block->l[(i + 13) & 15] ^ block->l[(i + 8) & 15] \ - ^ block->l[(i + 2) & 15] ^ block->l[i & 15], 1)) - -// (R0+R1), R2, R3, R4 are the different operations used in SHA1 -#define R0(v,w,x,y,z,i) z+=((w&(x^y))^y)+blk0(i)+0x5A827999+rol(v,5);w=rol(w,30); -#define R1(v,w,x,y,z,i) z+=((w&(x^y))^y)+blk(i)+0x5A827999+rol(v,5);w=rol(w,30); -#define R2(v,w,x,y,z,i) z+=(w^x^y)+blk(i)+0x6ED9EBA1+rol(v,5);w=rol(w,30); -#define R3(v,w,x,y,z,i) z+=(((w|x)&y)|(w&x))+blk(i)+0x8F1BBCDC+rol(v,5);w=rol(w,30); -#define R4(v,w,x,y,z,i) z+=(w^x^y)+blk(i)+0xCA62C1D6+rol(v,5);w=rol(w,30); - - -sha1MessageDigest::sha1MessageDigest() -{ - init(); -} - - -void sha1MessageDigest::reset() -{ - init(); -} - - -void sha1MessageDigest::init() -{ - m_state[0] = 0x67452301; - m_state[1] = 0xefcdab89; - m_state[2] = 0x98badcfe; - m_state[3] = 0x10325476; - m_state[4] = 0xc3d2e1f0; - - m_count[0] = 0; - m_count[1] = 0; -} - - -void sha1MessageDigest::update(const byte_t b) -{ - update(&b, 1); -} - - -void sha1MessageDigest::update(const string& s) -{ - update(reinterpret_cast <const byte_t*>(s.data()), s.length()); -} - - -void sha1MessageDigest::update(const byte_t* buffer, const size_t offset, - const unsigned long len) -{ - update(buffer + offset, len); -} - - -void sha1MessageDigest::update(const byte_t* buffer, const size_t len) -{ - unsigned int i, j; - - j = (m_count[0] >> 3) & 63; - - if ((m_count[0] += static_cast <unsigned int>(len << 3)) < static_cast <unsigned int>(len << 3)) - m_count[1]++; - - m_count[1] += static_cast <unsigned int>(len >> 29); - - if ((j + len) > 63) - { - memcpy(&m_buffer[j], buffer, (i = 64 - j)); - - transform(m_state, m_buffer); - - for ( ; i + 63 < len ; i += 64) - transform(m_state, &buffer[i]); - - j = 0; - } - else - { - i = 0; - } - - std::memcpy(&m_buffer[j], &buffer[i], len - i); -} - - -void sha1MessageDigest::finalize() -{ - unsigned int i, j; - unsigned char finalcount[8]; - - for (i = 0 ; i < 8 ; i++) - { - finalcount[i] = static_cast <unsigned char> - ((m_count[(i >= 4 ? 0 : 1)] - >> ((3-(i & 3)) * 8) ) & 255); // Endian independent - } - - update(reinterpret_cast <const byte_t*>("\200"), 1); - - while ((m_count[0] & 504) != 448) - update(reinterpret_cast <const byte_t*>("\0"), 1); - - update(finalcount, 8); // Should cause a transform() - - for (i = 0 ; i < 20 ; i++) - { - m_digest[i] = static_cast <unsigned char> - ((m_state[i >> 2] >> ((3 - (i & 3)) * 8)) & 255); - } - - // Wipe variables - i = j = 0; - - std::memset(m_buffer, 0, 64); - std::memset(m_state, 0, 5 * sizeof(unsigned int)); - std::memset(m_count, 0, 2 * sizeof(unsigned int)); - std::memset(&finalcount, 0, 8); -} - - -void sha1MessageDigest::finalize(const string& s) -{ - finalize(reinterpret_cast <const byte_t*>(s.data()), s.length()); -} - - -void sha1MessageDigest::finalize(const byte_t* buffer, const size_t len) -{ - update(buffer, len); - finalize(); -} - - -void sha1MessageDigest::finalize(const byte_t* buffer, - const size_t offset, const size_t len) -{ - finalize(buffer + offset, len); -} - - -/** Hash a single 512-bit block. - * This is the core of the algorithm. - */ -void sha1MessageDigest::transform - (unsigned int state[5], const unsigned char buffer[64]) -{ - unsigned int a, b, c, d, e; - - typedef union - { - unsigned char c[64]; - unsigned int l[16]; - } CHAR64LONG16; - - assert(sizeof(unsigned int) == 4); - - CHAR64LONG16* block; - static unsigned char workspace[64]; - - block = reinterpret_cast <CHAR64LONG16*>(workspace); - memcpy(block, buffer, 64); - - // Copy context->state[] to working vars - a = state[0]; - b = state[1]; - c = state[2]; - d = state[3]; - e = state[4]; - - // 4 rounds of 20 operations each. Loop unrolled. - R0(a,b,c,d,e, 0); R0(e,a,b,c,d, 1); R0(d,e,a,b,c, 2); R0(c,d,e,a,b, 3); - R0(b,c,d,e,a, 4); R0(a,b,c,d,e, 5); R0(e,a,b,c,d, 6); R0(d,e,a,b,c, 7); - R0(c,d,e,a,b, 8); R0(b,c,d,e,a, 9); R0(a,b,c,d,e,10); R0(e,a,b,c,d,11); - R0(d,e,a,b,c,12); R0(c,d,e,a,b,13); R0(b,c,d,e,a,14); R0(a,b,c,d,e,15); - R1(e,a,b,c,d,16); R1(d,e,a,b,c,17); R1(c,d,e,a,b,18); R1(b,c,d,e,a,19); - R2(a,b,c,d,e,20); R2(e,a,b,c,d,21); R2(d,e,a,b,c,22); R2(c,d,e,a,b,23); - R2(b,c,d,e,a,24); R2(a,b,c,d,e,25); R2(e,a,b,c,d,26); R2(d,e,a,b,c,27); - R2(c,d,e,a,b,28); R2(b,c,d,e,a,29); R2(a,b,c,d,e,30); R2(e,a,b,c,d,31); - R2(d,e,a,b,c,32); R2(c,d,e,a,b,33); R2(b,c,d,e,a,34); R2(a,b,c,d,e,35); - R2(e,a,b,c,d,36); R2(d,e,a,b,c,37); R2(c,d,e,a,b,38); R2(b,c,d,e,a,39); - R3(a,b,c,d,e,40); R3(e,a,b,c,d,41); R3(d,e,a,b,c,42); R3(c,d,e,a,b,43); - R3(b,c,d,e,a,44); R3(a,b,c,d,e,45); R3(e,a,b,c,d,46); R3(d,e,a,b,c,47); - R3(c,d,e,a,b,48); R3(b,c,d,e,a,49); R3(a,b,c,d,e,50); R3(e,a,b,c,d,51); - R3(d,e,a,b,c,52); R3(c,d,e,a,b,53); R3(b,c,d,e,a,54); R3(a,b,c,d,e,55); - R3(e,a,b,c,d,56); R3(d,e,a,b,c,57); R3(c,d,e,a,b,58); R3(b,c,d,e,a,59); - R4(a,b,c,d,e,60); R4(e,a,b,c,d,61); R4(d,e,a,b,c,62); R4(c,d,e,a,b,63); - R4(b,c,d,e,a,64); R4(a,b,c,d,e,65); R4(e,a,b,c,d,66); R4(d,e,a,b,c,67); - R4(c,d,e,a,b,68); R4(b,c,d,e,a,69); R4(a,b,c,d,e,70); R4(e,a,b,c,d,71); - R4(d,e,a,b,c,72); R4(c,d,e,a,b,73); R4(b,c,d,e,a,74); R4(a,b,c,d,e,75); - R4(e,a,b,c,d,76); R4(d,e,a,b,c,77); R4(c,d,e,a,b,78); R4(b,c,d,e,a,79); - - // Add the working vars back into context.state[] - state[0] += a; - state[1] += b; - state[2] += c; - state[3] += d; - state[4] += e; - - // Wipe variables - a = b = c = d = e = 0; -} - - -size_t sha1MessageDigest::getDigestLength() const -{ - return 20; -} - - -const byte_t* sha1MessageDigest::getDigest() const -{ - return m_digest; -} - - -} // sha1 -} // digest -} // security -} // vmime - - diff --git a/src/security/sasl/SASLContext.cpp b/src/security/sasl/SASLContext.cpp deleted file mode 100644 index 3474cbeb..00000000 --- a/src/security/sasl/SASLContext.cpp +++ /dev/null @@ -1,208 +0,0 @@ -// -// VMime library (http://www.vmime.org) -// Copyright (C) 2002-2013 Vincent Richard <[email protected]> -// -// This program is free software; you can redistribute it and/or -// modify it under the terms of the GNU General Public License as -// published by the Free Software Foundation; either version 3 of -// the License, or (at your option) any later version. -// -// This program is distributed in the hope that it will be useful, -// but WITHOUT ANY WARRANTY; without even the implied warranty of -// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -// General Public License for more details. -// -// You should have received a copy of the GNU General Public License along -// with this program; if not, write to the Free Software Foundation, Inc., -// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. -// -// Linking this library statically or dynamically with other modules is making -// a combined work based on this library. Thus, the terms and conditions of -// the GNU General Public License cover the whole combination. -// - -#include "vmime/config.hpp" - - -#if VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_SASL_SUPPORT - - -#include <sstream> - -#include <gsasl.h> - -#include "vmime/security/sasl/SASLContext.hpp" -#include "vmime/security/sasl/SASLMechanism.hpp" - -#include "vmime/base.hpp" - -#include "vmime/utility/encoder/encoderFactory.hpp" - -#include "vmime/utility/stream.hpp" -#include "vmime/utility/outputStreamStringAdapter.hpp" -#include "vmime/utility/inputStreamStringAdapter.hpp" -#include "vmime/utility/inputStreamByteBufferAdapter.hpp" - - -namespace vmime { -namespace security { -namespace sasl { - - -SASLContext::SASLContext() -{ - if (gsasl_init(&m_gsaslContext) != GSASL_OK) - throw std::bad_alloc(); -} - - -SASLContext::~SASLContext() -{ - gsasl_done(m_gsaslContext); -} - - -shared_ptr <SASLSession> SASLContext::createSession - (const string& serviceName, - shared_ptr <authenticator> auth, shared_ptr <SASLMechanism> mech) -{ - return make_shared <SASLSession> - (serviceName, dynamicCast <SASLContext>(shared_from_this()), auth, mech); -} - - -shared_ptr <SASLMechanism> SASLContext::createMechanism(const string& name) -{ - return SASLMechanismFactory::getInstance()->create - (dynamicCast <SASLContext>(shared_from_this()), name); -} - - -shared_ptr <SASLMechanism> SASLContext::suggestMechanism - (const std::vector <shared_ptr <SASLMechanism> >& mechs) -{ - if (mechs.empty()) - return null; - - std::ostringstream oss; - - for (unsigned int i = 0 ; i < mechs.size() ; ++i) - oss << mechs[i]->getName() << " "; - - const string mechList = oss.str(); - const char* suggested = gsasl_client_suggest_mechanism - (m_gsaslContext, mechList.c_str()); - - if (suggested) - { - for (unsigned int i = 0 ; i < mechs.size() ; ++i) - { - if (mechs[i]->getName() == suggested) - return mechs[i]; - } - } - - return null; -} - - -void SASLContext::decodeB64(const string& input, byte_t** output, size_t* outputLen) -{ - string res; - - utility::inputStreamStringAdapter is(input); - utility::outputStreamStringAdapter os(res); - - shared_ptr <utility::encoder::encoder> dec = - utility::encoder::encoderFactory::getInstance()->create("base64"); - - dec->decode(is, os); - - byte_t* out = new byte_t[res.length()]; - - std::copy(res.begin(), res.end(), out); - - *output = out; - *outputLen = res.length(); -} - - -const string SASLContext::encodeB64(const byte_t* input, const size_t inputLen) -{ - string res; - - utility::inputStreamByteBufferAdapter is(input, inputLen); - utility::outputStreamStringAdapter os(res); - - shared_ptr <utility::encoder::encoder> enc = - utility::encoder::encoderFactory::getInstance()->create("base64"); - - enc->encode(is, os); - - return res; -} - - -const string SASLContext::getErrorMessage(const string& fname, const int code) -{ - string msg = fname + "() returned "; - -#define ERROR(x) \ - case x: msg += #x; break; - - switch (code) - { - ERROR(GSASL_NEEDS_MORE) - ERROR(GSASL_UNKNOWN_MECHANISM) - ERROR(GSASL_MECHANISM_CALLED_TOO_MANY_TIMES) - ERROR(GSASL_MALLOC_ERROR) - ERROR(GSASL_BASE64_ERROR) - ERROR(GSASL_CRYPTO_ERROR) - ERROR(GSASL_SASLPREP_ERROR) - ERROR(GSASL_MECHANISM_PARSE_ERROR) - ERROR(GSASL_AUTHENTICATION_ERROR) - ERROR(GSASL_INTEGRITY_ERROR) - ERROR(GSASL_NO_CLIENT_CODE) - ERROR(GSASL_NO_SERVER_CODE) - ERROR(GSASL_NO_CALLBACK) - ERROR(GSASL_NO_ANONYMOUS_TOKEN) - ERROR(GSASL_NO_AUTHID) - ERROR(GSASL_NO_AUTHZID) - ERROR(GSASL_NO_PASSWORD) - ERROR(GSASL_NO_PASSCODE) - ERROR(GSASL_NO_PIN) - ERROR(GSASL_NO_SERVICE) - ERROR(GSASL_NO_HOSTNAME) - ERROR(GSASL_GSSAPI_RELEASE_BUFFER_ERROR) - ERROR(GSASL_GSSAPI_IMPORT_NAME_ERROR) - ERROR(GSASL_GSSAPI_INIT_SEC_CONTEXT_ERROR) - ERROR(GSASL_GSSAPI_ACCEPT_SEC_CONTEXT_ERROR) - ERROR(GSASL_GSSAPI_UNWRAP_ERROR) - ERROR(GSASL_GSSAPI_WRAP_ERROR) - ERROR(GSASL_GSSAPI_ACQUIRE_CRED_ERROR) - ERROR(GSASL_GSSAPI_DISPLAY_NAME_ERROR) - ERROR(GSASL_GSSAPI_UNSUPPORTED_PROTECTION_ERROR) - ERROR(GSASL_KERBEROS_V5_INIT_ERROR) - ERROR(GSASL_KERBEROS_V5_INTERNAL_ERROR) - ERROR(GSASL_SECURID_SERVER_NEED_ADDITIONAL_PASSCODE) - ERROR(GSASL_SECURID_SERVER_NEED_NEW_PIN) - - default: - - msg += "unknown error"; - break; - } - -#undef ERROR - - return msg; -} - - -} // sasl -} // security -} // vmime - - -#endif // VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_SASL_SUPPORT - diff --git a/src/security/sasl/SASLMechanismFactory.cpp b/src/security/sasl/SASLMechanismFactory.cpp deleted file mode 100644 index 255a13f1..00000000 --- a/src/security/sasl/SASLMechanismFactory.cpp +++ /dev/null @@ -1,144 +0,0 @@ -// -// VMime library (http://www.vmime.org) -// Copyright (C) 2002-2013 Vincent Richard <[email protected]> -// -// This program is free software; you can redistribute it and/or -// modify it under the terms of the GNU General Public License as -// published by the Free Software Foundation; either version 3 of -// the License, or (at your option) any later version. -// -// This program is distributed in the hope that it will be useful, -// but WITHOUT ANY WARRANTY; without even the implied warranty of -// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -// General Public License for more details. -// -// You should have received a copy of the GNU General Public License along -// with this program; if not, write to the Free Software Foundation, Inc., -// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. -// -// Linking this library statically or dynamically with other modules is making -// a combined work based on this library. Thus, the terms and conditions of -// the GNU General Public License cover the whole combination. -// - -#include "vmime/config.hpp" - - -#if VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_SASL_SUPPORT - - -#include <stdexcept> -#include <new> - -#include <gsasl.h> - -#include "vmime/security/sasl/SASLMechanismFactory.hpp" -#include "vmime/security/sasl/builtinSASLMechanism.hpp" -#include "vmime/security/sasl/SASLContext.hpp" - -#include "vmime/utility/stringUtils.hpp" - -#include "vmime/base.hpp" -#include "vmime/exception.hpp" - - -namespace vmime { -namespace security { -namespace sasl { - - -SASLMechanismFactory::SASLMechanismFactory() -{ - if (gsasl_init(&m_gsaslContext) != GSASL_OK) - throw std::bad_alloc(); -} - - -SASLMechanismFactory::~SASLMechanismFactory() -{ - gsasl_done(m_gsaslContext); -} - - -// static -SASLMechanismFactory* SASLMechanismFactory::getInstance() -{ - static SASLMechanismFactory instance; - return &instance; -} - - -shared_ptr <SASLMechanism> SASLMechanismFactory::create - (shared_ptr <SASLContext> ctx, const string& name_) -{ - const string name(utility::stringUtils::toUpper(name_)); - - // Check for built-in mechanisms - if (isMechanismSupported(name)) - { - return make_shared <builtinSASLMechanism>(ctx, name); - } - // Check for registered mechanisms - else - { - MapType::iterator it = m_mechs.find(name); - - if (it != m_mechs.end()) - return (*it).second->create(ctx, name); - } - - throw exceptions::no_such_mechanism(name); - return null; -} - - -const std::vector <string> SASLMechanismFactory::getSupportedMechanisms() const -{ - std::vector <string> list; - - // Registered mechanisms - for (MapType::const_iterator it = m_mechs.begin() ; - it != m_mechs.end() ; ++it) - { - list.push_back((*it).first); - } - - // Built-in mechanisms - char* out = 0; - - if (gsasl_client_mechlist(m_gsaslContext, &out) == GSASL_OK) - { - // 'out' contains SASL mechanism names, separated by spaces - for (char *start = out, *p = out ; ; ++p) - { - if (*p == ' ' || !*p) - { - list.push_back(string(start, p)); - start = p + 1; - - // End of string - if (!*p) break; - } - } - - gsasl_free(out); - } - - return list; -} - - -bool SASLMechanismFactory::isMechanismSupported(const string& name) const -{ - return (gsasl_client_support_p(m_gsaslContext, name.c_str()) != 0 || - m_mechs.find(name) != m_mechs.end()); -} - - -} // sasl -} // security -} // vmime - - -#endif // VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_SASL_SUPPORT - diff --git a/src/security/sasl/SASLSession.cpp b/src/security/sasl/SASLSession.cpp deleted file mode 100644 index 087ef27b..00000000 --- a/src/security/sasl/SASLSession.cpp +++ /dev/null @@ -1,192 +0,0 @@ -// -// VMime library (http://www.vmime.org) -// Copyright (C) 2002-2013 Vincent Richard <[email protected]> -// -// This program is free software; you can redistribute it and/or -// modify it under the terms of the GNU General Public License as -// published by the Free Software Foundation; either version 3 of -// the License, or (at your option) any later version. -// -// This program is distributed in the hope that it will be useful, -// but WITHOUT ANY WARRANTY; without even the implied warranty of -// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -// General Public License for more details. -// -// You should have received a copy of the GNU General Public License along -// with this program; if not, write to the Free Software Foundation, Inc., -// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. -// -// Linking this library statically or dynamically with other modules is making -// a combined work based on this library. Thus, the terms and conditions of -// the GNU General Public License cover the whole combination. -// - -#include "vmime/config.hpp" - - -#if VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_SASL_SUPPORT - - -#include <sstream> - -#include <gsasl.h> - -#include "vmime/security/sasl/SASLSession.hpp" - -#include "vmime/security/sasl/SASLContext.hpp" -#include "vmime/security/sasl/SASLSocket.hpp" -#include "vmime/security/sasl/SASLAuthenticator.hpp" - - -namespace vmime { -namespace security { -namespace sasl { - - -SASLSession::SASLSession(const string& serviceName, shared_ptr <SASLContext> ctx, - shared_ptr <authenticator> auth, shared_ptr <SASLMechanism> mech) - : m_serviceName(serviceName), m_context(ctx), m_auth(auth), - m_mech(mech), m_gsaslContext(0), m_gsaslSession(0) -{ - if (gsasl_init(&m_gsaslContext) != GSASL_OK) - throw std::bad_alloc(); - - gsasl_client_start(m_gsaslContext, mech->getName().c_str(), &m_gsaslSession); - - gsasl_callback_set(m_gsaslContext, gsaslCallback); - gsasl_callback_hook_set(m_gsaslContext, this); -} - - -SASLSession::~SASLSession() -{ - gsasl_finish(m_gsaslSession); - m_gsaslSession = NULL; - - gsasl_done(m_gsaslContext); - m_gsaslContext = NULL; -} - - -void SASLSession::init() -{ - shared_ptr <SASLAuthenticator> saslAuth = dynamicCast <SASLAuthenticator>(m_auth); - - if (saslAuth) - { - saslAuth->setSASLMechanism(m_mech); - saslAuth->setSASLSession(dynamicCast <SASLSession>(shared_from_this())); - } -} - - -shared_ptr <authenticator> SASLSession::getAuthenticator() -{ - return m_auth; -} - - -shared_ptr <SASLMechanism> SASLSession::getMechanism() -{ - return m_mech; -} - - -shared_ptr <SASLContext> SASLSession::getContext() -{ - return m_context; -} - - -bool SASLSession::evaluateChallenge - (const byte_t* challenge, const size_t challengeLen, - byte_t** response, size_t* responseLen) -{ - return m_mech->step(dynamicCast <SASLSession>(shared_from_this()), - challenge, challengeLen, response, responseLen); -} - - -shared_ptr <net::socket> SASLSession::getSecuredSocket(shared_ptr <net::socket> sok) -{ - return make_shared <SASLSocket>(dynamicCast <SASLSession>(shared_from_this()), sok); -} - - -const string SASLSession::getServiceName() const -{ - return m_serviceName; -} - - -// static -int SASLSession::gsaslCallback - (Gsasl* ctx, Gsasl_session* sctx, Gsasl_property prop) -{ - SASLSession* sess = reinterpret_cast <SASLSession*>(gsasl_callback_hook_get(ctx)); - if (!sess) return GSASL_AUTHENTICATION_ERROR; - - shared_ptr <authenticator> auth = sess->getAuthenticator(); - - try - { - string res; - - switch (prop) - { - case GSASL_AUTHID: - - res = auth->getUsername(); - break; - - case GSASL_PASSWORD: - - res = auth->getPassword(); - break; - - case GSASL_ANONYMOUS_TOKEN: - - res = auth->getAnonymousToken(); - break; - - case GSASL_HOSTNAME: - - res = auth->getHostname(); - break; - - case GSASL_SERVICE: - - res = auth->getServiceName(); - break; - - case GSASL_AUTHZID: - case GSASL_GSSAPI_DISPLAY_NAME: - case GSASL_PASSCODE: - case GSASL_SUGGESTED_PIN: - case GSASL_PIN: - case GSASL_REALM: - - default: - - return GSASL_NO_CALLBACK; - } - - gsasl_property_set(sctx, prop, res.c_str()); - - return GSASL_OK; - } - //catch (exceptions::no_auth_information&) - catch (...) - { - return GSASL_NO_CALLBACK; - } -} - - -} // sasl -} // security -} // vmime - - -#endif // VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_SASL_SUPPORT - diff --git a/src/security/sasl/SASLSocket.cpp b/src/security/sasl/SASLSocket.cpp deleted file mode 100644 index 12d634c2..00000000 --- a/src/security/sasl/SASLSocket.cpp +++ /dev/null @@ -1,236 +0,0 @@ -// -// VMime library (http://www.vmime.org) -// Copyright (C) 2002-2013 Vincent Richard <[email protected]> -// -// This program is free software; you can redistribute it and/or -// modify it under the terms of the GNU General Public License as -// published by the Free Software Foundation; either version 3 of -// the License, or (at your option) any later version. -// -// This program is distributed in the hope that it will be useful, -// but WITHOUT ANY WARRANTY; without even the implied warranty of -// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -// General Public License for more details. -// -// You should have received a copy of the GNU General Public License along -// with this program; if not, write to the Free Software Foundation, Inc., -// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. -// -// Linking this library statically or dynamically with other modules is making -// a combined work based on this library. Thus, the terms and conditions of -// the GNU General Public License cover the whole combination. -// - -#include "vmime/config.hpp" - - -#if VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_SASL_SUPPORT - - -#include "vmime/security/sasl/SASLSocket.hpp" -#include "vmime/security/sasl/SASLSession.hpp" - -#include "vmime/utility/stringUtils.hpp" - -#include "vmime/exception.hpp" - -#include <algorithm> -#include <cstring> - -#include <gsasl.h> - - -namespace vmime { -namespace security { -namespace sasl { - - - -SASLSocket::SASLSocket(shared_ptr <SASLSession> sess, shared_ptr <net::socket> wrapped) - : m_session(sess), m_wrapped(wrapped), - m_pendingBuffer(0), m_pendingPos(0), m_pendingLen(0) -{ -} - - -SASLSocket::~SASLSocket() -{ - if (m_pendingBuffer) - delete [] m_pendingBuffer; -} - - -void SASLSocket::connect(const string& address, const port_t port) -{ - m_wrapped->connect(address, port); -} - - -void SASLSocket::disconnect() -{ - m_wrapped->disconnect(); -} - - -bool SASLSocket::isConnected() const -{ - return m_wrapped->isConnected(); -} - - -size_t SASLSocket::getBlockSize() const -{ - return m_wrapped->getBlockSize(); -} - - -const string SASLSocket::getPeerName() const -{ - return m_wrapped->getPeerName(); -} - - -const string SASLSocket::getPeerAddress() const -{ - return m_wrapped->getPeerAddress(); -} - - -void SASLSocket::receive(string& buffer) -{ - const size_t n = receiveRaw(m_recvBuffer, sizeof(m_recvBuffer)); - - buffer = utility::stringUtils::makeStringFromBytes(m_recvBuffer, n); -} - - -size_t SASLSocket::receiveRaw(byte_t* buffer, const size_t count) -{ - if (m_pendingLen != 0) - { - const size_t copyLen = - (count >= m_pendingLen ? m_pendingLen : count); - - std::copy(m_pendingBuffer + m_pendingPos, - m_pendingBuffer + m_pendingPos + copyLen, - buffer); - - m_pendingLen -= copyLen; - m_pendingPos += copyLen; - - if (m_pendingLen == 0) - { - delete [] m_pendingBuffer; - - m_pendingBuffer = 0; - m_pendingPos = 0; - m_pendingLen = 0; - } - - return copyLen; - } - - const size_t n = m_wrapped->receiveRaw(buffer, count); - - byte_t* output = 0; - size_t outputLen = 0; - - m_session->getMechanism()->decode - (m_session, buffer, n, &output, &outputLen); - - // If we can not copy all decoded data into the output buffer, put - // remaining data into a pending buffer for next calls to receive() - if (outputLen > count) - { - std::copy(output, output + count, buffer); - - m_pendingBuffer = output; - m_pendingLen = outputLen; - m_pendingPos = count; - - return count; - } - else - { - std::copy(output, output + outputLen, buffer); - - delete [] output; - - return outputLen; - } -} - - -void SASLSocket::send(const string& buffer) -{ - sendRaw(reinterpret_cast <const byte_t*>(buffer.data()), buffer.length()); -} - - -void SASLSocket::send(const char* str) -{ - sendRaw(reinterpret_cast <const byte_t*>(str), strlen(str)); -} - - -void SASLSocket::sendRaw(const byte_t* buffer, const size_t count) -{ - byte_t* output = 0; - size_t outputLen = 0; - - m_session->getMechanism()->encode - (m_session, buffer, count, &output, &outputLen); - - try - { - m_wrapped->sendRaw(output, outputLen); - } - catch (...) - { - delete [] output; - throw; - } - - delete [] output; -} - - -size_t SASLSocket::sendRawNonBlocking(const byte_t* buffer, const size_t count) -{ - byte_t* output = 0; - size_t outputLen = 0; - - m_session->getMechanism()->encode - (m_session, buffer, count, &output, &outputLen); - - size_t bytesSent = 0; - - try - { - bytesSent = m_wrapped->sendRawNonBlocking(output, outputLen); - } - catch (...) - { - delete [] output; - throw; - } - - delete [] output; - - return bytesSent; -} - - -unsigned int SASLSocket::getStatus() const -{ - return m_wrapped->getStatus(); -} - - -} // sasl -} // security -} // vmime - - -#endif // VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_SASL_SUPPORT - diff --git a/src/security/sasl/builtinSASLMechanism.cpp b/src/security/sasl/builtinSASLMechanism.cpp deleted file mode 100644 index e179e715..00000000 --- a/src/security/sasl/builtinSASLMechanism.cpp +++ /dev/null @@ -1,195 +0,0 @@ -// -// VMime library (http://www.vmime.org) -// Copyright (C) 2002-2013 Vincent Richard <[email protected]> -// -// This program is free software; you can redistribute it and/or -// modify it under the terms of the GNU General Public License as -// published by the Free Software Foundation; either version 3 of -// the License, or (at your option) any later version. -// -// This program is distributed in the hope that it will be useful, -// but WITHOUT ANY WARRANTY; without even the implied warranty of -// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -// General Public License for more details. -// -// You should have received a copy of the GNU General Public License along -// with this program; if not, write to the Free Software Foundation, Inc., -// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. -// -// Linking this library statically or dynamically with other modules is making -// a combined work based on this library. Thus, the terms and conditions of -// the GNU General Public License cover the whole combination. -// - -#include "vmime/config.hpp" - - -#if VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_SASL_SUPPORT - - -#include <gsasl.h> - -#include "vmime/security/sasl/builtinSASLMechanism.hpp" - -#include "vmime/security/sasl/SASLContext.hpp" -#include "vmime/security/sasl/SASLSession.hpp" - -#include "vmime/exception.hpp" - -#include <stdexcept> -#include <new> - - -namespace vmime { -namespace security { -namespace sasl { - - -builtinSASLMechanism::builtinSASLMechanism(shared_ptr <SASLContext> ctx, const string& name) - : m_context(ctx), m_name(name), m_complete(false) -{ -} - - -builtinSASLMechanism::~builtinSASLMechanism() -{ -} - - -const string builtinSASLMechanism::getName() const -{ - return m_name; -} - - -bool builtinSASLMechanism::step - (shared_ptr <SASLSession> sess, const byte_t* challenge, const size_t challengeLen, - byte_t** response, size_t* responseLen) -{ - char* output = 0; - size_t outputLen = 0; - - const int result = gsasl_step(sess->m_gsaslSession, - reinterpret_cast <const char*>(challenge), challengeLen, - &output, &outputLen); - - if (result == GSASL_OK || result == GSASL_NEEDS_MORE) - { - byte_t* res = new byte_t[outputLen]; - - for (size_t i = 0 ; i < outputLen ; ++i) - res[i] = output[i]; - - *response = res; - *responseLen = outputLen; - - gsasl_free(output); - } - else - { - *response = 0; - *responseLen = 0; - } - - if (result == GSASL_OK) - { - // Authentication process completed - m_complete = true; - return true; - } - else if (result == GSASL_NEEDS_MORE) - { - // Continue authentication process - return false; - } - else if (result == GSASL_MALLOC_ERROR) - { - throw std::bad_alloc(); - } - else - { - throw exceptions::sasl_exception("Error when processing challenge: " - + SASLContext::getErrorMessage("gsasl_step", result)); - } -} - - -bool builtinSASLMechanism::isComplete() const -{ - return m_complete; -} - - -void builtinSASLMechanism::encode - (shared_ptr <SASLSession> sess, const byte_t* input, const size_t inputLen, - byte_t** output, size_t* outputLen) -{ - char* coutput = 0; - size_t coutputLen = 0; - - if (gsasl_encode(sess->m_gsaslSession, - reinterpret_cast <const char*>(input), inputLen, - &coutput, &coutputLen) != GSASL_OK) - { - throw exceptions::sasl_exception("Encoding error."); - } - - try - { - byte_t* res = new byte_t[coutputLen]; - - std::copy(coutput, coutput + coutputLen, res); - - *output = res; - *outputLen = static_cast <int>(coutputLen); - } - catch (...) - { - gsasl_free(coutput); - throw; - } - - gsasl_free(coutput); -} - - -void builtinSASLMechanism::decode - (shared_ptr <SASLSession> sess, const byte_t* input, const size_t inputLen, - byte_t** output, size_t* outputLen) -{ - char* coutput = 0; - size_t coutputLen = 0; - - try - { - if (gsasl_decode(sess->m_gsaslSession, - reinterpret_cast <const char*>(input), inputLen, - &coutput, &coutputLen) != GSASL_OK) - { - throw exceptions::sasl_exception("Decoding error."); - } - - byte_t* res = new byte_t[coutputLen]; - - std::copy(coutput, coutput + coutputLen, res); - - *output = res; - *outputLen = static_cast <int>(coutputLen); - } - catch (...) - { - gsasl_free(coutput); - throw; - } - - gsasl_free(coutput); -} - - -} // sasl -} // security -} // vmime - - -#endif // VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_SASL_SUPPORT - diff --git a/src/security/sasl/defaultSASLAuthenticator.cpp b/src/security/sasl/defaultSASLAuthenticator.cpp deleted file mode 100644 index 7fe9b3eb..00000000 --- a/src/security/sasl/defaultSASLAuthenticator.cpp +++ /dev/null @@ -1,153 +0,0 @@ -// -// VMime library (http://www.vmime.org) -// Copyright (C) 2002-2013 Vincent Richard <[email protected]> -// -// This program is free software; you can redistribute it and/or -// modify it under the terms of the GNU General Public License as -// published by the Free Software Foundation; either version 3 of -// the License, or (at your option) any later version. -// -// This program is distributed in the hope that it will be useful, -// but WITHOUT ANY WARRANTY; without even the implied warranty of -// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -// General Public License for more details. -// -// You should have received a copy of the GNU General Public License along -// with this program; if not, write to the Free Software Foundation, Inc., -// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. -// -// Linking this library statically or dynamically with other modules is making -// a combined work based on this library. Thus, the terms and conditions of -// the GNU General Public License cover the whole combination. -// - -#include "vmime/config.hpp" - - -#if VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_SASL_SUPPORT - - -#include "vmime/security/sasl/defaultSASLAuthenticator.hpp" - -#include "vmime/security/sasl/SASLMechanism.hpp" -#include "vmime/security/sasl/SASLSession.hpp" -#include "vmime/security/sasl/SASLContext.hpp" - -#include "vmime/net/service.hpp" - - -namespace vmime { -namespace security { -namespace sasl { - - -defaultSASLAuthenticator::defaultSASLAuthenticator() -{ -} - - -defaultSASLAuthenticator::~defaultSASLAuthenticator() -{ -} - - -const std::vector <shared_ptr <SASLMechanism> > - defaultSASLAuthenticator::getAcceptableMechanisms - (const std::vector <shared_ptr <SASLMechanism> >& available, - shared_ptr <SASLMechanism> suggested) const -{ - if (suggested) - { - std::vector <shared_ptr <SASLMechanism> > res; - - res.push_back(suggested); - - for (unsigned int i = 0 ; i < available.size() ; ++i) - { - if (available[i]->getName() != suggested->getName()) - res.push_back(available[i]); - } - - return res; - } - else - { - return available; - } -} - - -const string defaultSASLAuthenticator::getUsername() const -{ - return m_default.getUsername(); -} - - -const string defaultSASLAuthenticator::getPassword() const -{ - return m_default.getPassword(); -} - - -const string defaultSASLAuthenticator::getHostname() const -{ - return m_default.getHostname(); -} - - -const string defaultSASLAuthenticator::getAnonymousToken() const -{ - return m_default.getAnonymousToken(); -} - - -const string defaultSASLAuthenticator::getServiceName() const -{ - return m_saslSession.lock()->getServiceName(); -} - - -void defaultSASLAuthenticator::setService(shared_ptr <net::service> serv) -{ - m_service = serv; - m_default.setService(serv); -} - - -weak_ptr <net::service> defaultSASLAuthenticator::getService() const -{ - return m_service; -} - - -void defaultSASLAuthenticator::setSASLSession(shared_ptr <SASLSession> sess) -{ - m_saslSession = sess; -} - - -shared_ptr <SASLSession> defaultSASLAuthenticator::getSASLSession() const -{ - return constCast <SASLSession>(m_saslSession.lock()); -} - - -void defaultSASLAuthenticator::setSASLMechanism(shared_ptr <SASLMechanism> mech) -{ - m_saslMech = mech; -} - - -shared_ptr <SASLMechanism> defaultSASLAuthenticator::getSASLMechanism() const -{ - return m_saslMech; -} - - -} // sasl -} // security -} // vmime - - -#endif // VMIME_HAVE_MESSAGING_FEATURES && VMIME_HAVE_SASL_SUPPORT - |
