X-Git-Url: https://code.wpia.club/?a=blobdiff_plain;f=src%2Fapps%2Fclient.cpp;h=80422b3bc0e13046ee40dee913a5e7f3648b7aa3;hb=HEAD;hp=36488f5627ee4435f7c0f9dcf45b19bd7190ee41;hpb=709700dfbbeb5bf8aee1f5a1966f0192d783ae03;p=cassiopeia.git diff --git a/src/apps/client.cpp b/src/apps/client.cpp index 36488f5..80422b3 100644 --- a/src/apps/client.cpp +++ b/src/apps/client.cpp @@ -7,7 +7,7 @@ #include #include "db/database.h" -#include "db/mysql.h" +#include "db/psql.h" #include "crypto/simpleOpensslSigner.h" #include "crypto/remoteSigner.h" #include "crypto/sslUtil.h" @@ -16,6 +16,9 @@ #include "io/bios.h" #include "io/slipBio.h" #include "config.h" +#include +#include +#include #ifdef NO_DAEMON #define DAEMON false @@ -33,10 +36,7 @@ void checkCRLs( std::shared_ptr sign ) { logger::note( "Signing CRLs" ); for( auto& x : CAs ) { - logger::notef( "Checking: %s ...", x.first ); - if( !x.second->crlNeedsResign() ) { - logger::warnf( "Skipping Resigning CRL: %s ...", x.second->name ); continue; } @@ -45,23 +45,113 @@ void checkCRLs( std::shared_ptr sign ) { try { std::vector serials; std::pair, std::string> rev = sign->revoke( x.second, serials ); - } catch( const char* c ) { - logger::error( "Exception: ", c ); + } catch( const std::exception& e ) { + logger::error( "Exception: ", e.what() ); } } } -int main( int argc, const char* argv[] ) { +bool pathExists( const std::string& name ) { + struct stat buffer; + return stat( name.c_str(), &buffer ) == 0; +} + +void signOCSP( std::shared_ptr sign, std::string profileName, std::string req, std::string crtName, std::string failName ) { + auto cert = std::make_shared(); + cert->ocspCA = profileName; + cert->wishFrom = "now"; + cert->wishTo = "1y"; + cert->md = "sha512"; + + logger::note( "INFO: Message Digest: ", cert->md ); + + cert->csr_content = req; + cert->csr_type = "CSR"; + auto nAVA = std::make_shared(); + nAVA->name = "CN"; + nAVA->value = "OCSP Responder"; + cert->AVAs.push_back( nAVA ); + + std::shared_ptr res = sign->sign( cert ); + + if( !res ) { + writeFile( failName, "failed" ); + logger::error( "OCSP Cert signing failed." ); + return; + } + + writeFile( crtName, res->certificate ); + logger::notef( "Cert log: %s", res->log ); +} + +void checkOCSP( std::shared_ptr sign ) { + std::unique_ptr> dp( opendir( "ca" ), []( DIR * d ) { + closedir( d ); + } ); + + // When opendir fails and returns 0 the unique_ptr will be considered unintialized and will not call closedir. + // Even if closedir would be called, according to POSIX it MAY handle nullptr properly (for glibc it does). + if( !dp ) { + logger::error( "CA directory not found" ); + return; + } + + struct dirent *ep; + + while( ( ep = readdir( dp.get() ) ) ) { + if( ep->d_name[0] == '.' ) { + continue; + } + + std::string profileName( ep->d_name ); + std::string csr = "ca/" + profileName + "/ocsp.csr"; + + if( ! pathExists( csr ) ) { + continue; + } + + std::string crtName = "ca/" + profileName + "/ocsp.crt"; + + if( pathExists( crtName ) ) { + continue; + } + + std::string failName = "ca/" + profileName + "/ocsp.fail"; + + if( pathExists( failName ) ) { + continue; + } + + logger::notef( "Discovered OCSP CSR that needs action: %s", csr ); + std::string req = readFile( csr ); + std::shared_ptr parsed = X509Req::parseCSR( req ); + + if( parsed->verify() <= 0 ) { + logger::errorf( "Invalid CSR for %s", profileName ); + continue; + } + + signOCSP( sign, profileName, req, crtName, failName ); + } +} + + +int main( int argc, const char *argv[] ) { bool once = false; + bool resetOnly = false; if( argc == 2 && std::string( "--once" ) == argv[1] ) { once = true; } + if( argc == 2 && std::string( "--reset" ) == argv[1] ) { + resetOnly = true; + } + std::string path; #ifdef NDEBUG - path = "/etc/cacert/cassiopeia/cassiopeia.conf"; + path = "/etc/wpia/cassiopeia/cassiopeia.conf"; #else path = "config.txt"; #endif @@ -76,137 +166,136 @@ int main( int argc, const char* argv[] ) { return -1; } - std::shared_ptr jp = std::make_shared( sqlHost, sqlUser, sqlPass, sqlDB ); + std::shared_ptr jp = std::make_shared( sqlHost, sqlUser, sqlPass, sqlDB ); std::shared_ptr b = openSerial( serialPath ); - std::shared_ptr slip1( BIO_new( toBio() ), BIO_free ); - static_cast( slip1->ptr )->setTarget( std::make_shared( b ) ); + std::shared_ptr m( toBio(), BIO_meth_free ); + std::shared_ptr slip1( BIO_new( m.get() ), BIO_free ); + static_cast( slip1->ptr )->setTarget( std::make_shared( b ), false ); auto sign = std::make_shared( slip1, generateSSLContext( false ) ); // std::shared_ptr sign( new SimpleOpensslSigner() ); + if( resetOnly ) { + std::cout << "Doing BIO reset" << std::endl; + int result = BIO_reset( slip1.get() ); + std::cout << "Did BIO reset, result " << result << ", exiting." << std::endl; + return result; + } + time_t lastCRLCheck = 0; while( true ) { - time_t current; - time( ¤t ); - - if( lastCRLCheck + 30 * 60 < current ) { - // todo set good log TODO FIXME - sign->setLog( std::shared_ptr( - &std::cout, - []( std::ostream* o ) { + try { + time_t current; + time( ¤t ); + + if( lastCRLCheck + 30 * 60 < current ) { + // todo set good log TODO FIXME + auto ostreamFree = []( std::ostream * o ) { ( void ) o; - } ) ); - checkCRLs( sign ); - lastCRLCheck = current; - } + }; + sign->setLog( std::shared_ptr( &std::cout, ostreamFree ) ); + checkCRLs( sign ); + lastCRLCheck = current; + } - std::shared_ptr job = jp->fetchJob(); + checkOCSP( sign ); - if( !job ) { - logger::note( "Nothing to work on." ); - sleep( 5 ); - continue; - } + std::shared_ptr job; - std::shared_ptr logPtr = openLogfile( std::string( "logs/" ) + job->id + std::string( "_" ) + job->warning + std::string( ".log" ) ); + try { + job = jp->fetchJob(); + } catch( std::exception& e ) { + logger::errorf( "Exception while fetchJob: %s", e.what() ); + } - logger::logger_set log_set({logger::log_target(*logPtr, logger::level::debug)}, logger::auto_register::on); + if( !job ) { + sleep( 5 ); + continue; + } - logger::note( "TASK ID: ", job->id ); - logger::note( "TRY: ", job->warning ); - logger::note( "TARGET: ", job->target ); - logger::note( "TASK: ", job->task ); + logger::logger_set log_set( {logger::log_target( job->log, logger::level::debug )}, logger::auto_register::on ); - if( job->task == "sign" ) { - try { - std::shared_ptr cert = jp->fetchTBSCert( job ); - cert->wishFrom = job->from; - cert->wishTo = job->to; - logger::note( "INFO: Message Digest: ", cert->md ); - logger::note( "INFO: Profile ID: ", cert->profile ); - - for( auto& SAN : cert->SANs ) { - logger::notef( "INFO: SAN %s: %s", SAN->type, SAN->content ); - } + logger::note( "TASK ID: ", job->id ); + logger::note( "TRY: ", job->attempt ); + logger::note( "TARGET: ", job->target ); + logger::note( "TASK: ", job->task ); - for( auto& AVA : cert->AVAs ) { - logger::notef( "INFO: AVA %s: %s", AVA->name, AVA->value ); - } + if( job->task == "sign" ) { + try { + std::shared_ptr cert = jp->fetchTBSCert( job ); - if( !cert ) { - logger::error( "Unable to load CSR" ); - jp->failJob( job ); - continue; - } + if( !cert ) { + logger::error( "Unable to load CSR" ); + jp->failJob( job ); + continue; + } - logger::notef( "FINE: Found the CSR at '%s'", cert->csr ); - cert->csr_content = readFile( keyDir + "/../" + cert->csr ); - logger::note( "FINE: CSR content:\n", cert->csr_content ); + cert->wishFrom = job->from; + cert->wishTo = job->to; + logger::note( "INFO: Message Digest: ", cert->md ); + logger::note( "INFO: Profile ID: ", cert->profile ); - std::shared_ptr res = sign->sign( cert ); + for( auto& SAN : cert->SANs ) { + logger::notef( "INFO: SAN %s: %s", SAN->type, SAN->content ); + } - if( !res ) { - logger::error( "ERROR: The signer failed. No certificate was returned." ); - jp->failJob( job ); - continue; - } + for( auto& AVA : cert->AVAs ) { + logger::notef( "INFO: AVA %s: %s", AVA->name, AVA->value ); + } - logger::note( "FINE: CERTIFICATE LOG:\n", res->log ); - logger::note( "FINE: CERTIFICATE:\n", res->certificate ); - std::string fn = writeBackFile( job->target.c_str(), res->certificate, keyDir ); + logger::note( "FINE: CSR content:\n", cert->csr_content ); - if( fn.empty() ) { - logger::error( "ERROR: Writeback of the certificate failed." ); - jp->failJob( job ); - continue; - } + std::shared_ptr res = sign->sign( cert ); - res->crt_name = fn; - jp->writeBack( job, res ); //! \FIXME: Check return value - logger::note( "FINE: signing done." ); + if( !res ) { + logger::error( "ERROR: The signer failed. No certificate was returned." ); + jp->failJob( job ); + continue; + } - if( DAEMON ) { - jp->finishJob( job ); - } + logger::note( "FINE: CERTIFICATE LOG:\n", res->log, + "FINE: CERTIFICATE:\n", res->certificate ); - continue; - } catch( const char* c ) { - logger::error( "ERROR: ", c ); - } catch( std::string& c ) { - logger::error( "ERROR: ", c ); - } + jp->writeBack( job, res ); //! \FIXME: Check return value + logger::note( "FINE: signing done." ); - try { + if( DAEMON ) { + jp->finishJob( job ); + } + } catch( std::exception& c ) { + jp->failJob( job ); + logger::error( "ERROR: ", c.what() ); + } + } else if( job->task == "revoke" ) { + try { + logger::note( "revoking" ); + auto data = jp->getRevocationInfo( job ); + std::vector serials; + serials.push_back( data.first ); + logger::note( "revoking" ); + std::pair, std::string> rev = sign->revoke( CAs.at( data.second ), serials ); + std::string date = rev.second; + const unsigned char *pos = ( const unsigned char * ) date.data(); + std::shared_ptr time( d2i_ASN1_TIME( NULL, &pos, date.size() ), ASN1_TIME_free ); + + jp->writeBackRevocation( job, timeToString( time ) ); + jp->finishJob( job ); + continue; + } catch( const std::exception& c ) { + jp->failJob( job ); + logger::error( "Exception: ", c.what() ); + } + } else { + logger::errorf( "Unknown job type (\"%s\")", job->task ); jp->failJob( job ); - } catch( const char* c ) { - logger::error( "ERROR: ", c ); - } catch( std::string& c ) { - logger::error( "ERROR: ", c ); } - } else if( job->task == "revoke" ) { - try { - auto data = jp->getRevocationInfo( job ); - std::vector serials; - serials.push_back( data.first ); - std::pair, std::string> rev = sign->revoke( CAs.at( data.second ), serials ); - std::string date = rev.second; - const unsigned char* pos = ( const unsigned char* ) date.data(); - std::shared_ptr time( d2i_ASN1_TIME( NULL, &pos, date.size() ), ASN1_TIME_free ); - - jp->writeBackRevocation( job, timeToString( time ) ); - jp->finishJob( job ); - } catch( const char* c ) { - logger::error( "Exception: ", c ); - } catch( const std::string& c ) { - logger::error( "Exception: ", c ); + + if( !DAEMON || once ) { + return 0; } - } else { - logger::errorf( "Unknown job type (\"%s\")", job->task ); - jp->failJob( job ); + } catch( std::exception& e ) { + logger::errorf( "std::exception in mainloop: %s", e.what() ); } - if( !DAEMON || once ) { - return 0; - } } }