2010-12-10 02:12:09 +00:00
|
|
|
/* ***** BEGIN LICENSE BLOCK *****
|
|
|
|
* Version: MPL 1.1/GPL 2.0/LGPL 2.1
|
|
|
|
*
|
|
|
|
* The contents of this file are subject to the Mozilla Public License Version
|
|
|
|
* 1.1 (the "License"); you may not use this file except in compliance with
|
|
|
|
* the License. You may obtain a copy of the License at
|
|
|
|
* http://www.mozilla.org/MPL/
|
|
|
|
*
|
|
|
|
* Software distributed under the License is distributed on an "AS IS" basis,
|
|
|
|
* WITHOUT WARRANTY OF ANY KIND, either express or implied. See the License
|
|
|
|
* for the specific language governing rights and limitations under the
|
|
|
|
* License.
|
|
|
|
*
|
|
|
|
* The Original Code is Firefox Sync.
|
|
|
|
*
|
|
|
|
* The Initial Developer of the Original Code is
|
|
|
|
* Mozilla Foundation.
|
|
|
|
* Portions created by the Initial Developer are Copyright (C) 2010
|
|
|
|
* the Initial Developer. All Rights Reserved.
|
|
|
|
*
|
|
|
|
* Contributor(s):
|
|
|
|
* Philipp von Weitershausen <philipp@weitershausen.de>
|
|
|
|
*
|
|
|
|
* Alternatively, the contents of this file may be used under the terms of
|
|
|
|
* either the GNU General Public License Version 2 or later (the "GPL"), or
|
|
|
|
* the GNU Lesser General Public License Version 2.1 or later (the "LGPL"),
|
|
|
|
* in which case the provisions of the GPL or the LGPL are applicable instead
|
|
|
|
* of those above. If you wish to allow use of your version of this file only
|
|
|
|
* under the terms of either the GPL or the LGPL, and not to allow others to
|
|
|
|
* use your version of this file under the terms of the MPL, indicate your
|
|
|
|
* decision by deleting the provisions above and replace them with the notice
|
|
|
|
* and other provisions required by the GPL or the LGPL. If you do not delete
|
|
|
|
* the provisions above, a recipient may use your version of this file under
|
|
|
|
* the terms of any one of the MPL, the GPL or the LGPL.
|
|
|
|
*
|
|
|
|
* ***** END LICENSE BLOCK ***** */
|
|
|
|
|
|
|
|
const Cc = Components.classes;
|
|
|
|
const Ci = Components.interfaces;
|
|
|
|
const Cr = Components.results;
|
|
|
|
const Cu = Components.utils;
|
|
|
|
|
|
|
|
Cu.import("resource://services-sync/log4moz.js");
|
2011-07-07 00:20:47 +00:00
|
|
|
Cu.import("resource://services-sync/rest.js");
|
2010-12-10 02:12:09 +00:00
|
|
|
Cu.import("resource://services-sync/constants.js");
|
|
|
|
Cu.import("resource://services-sync/util.js");
|
|
|
|
|
|
|
|
const EXPORTED_SYMBOLS = ["JPAKEClient"];
|
|
|
|
|
2011-07-07 00:20:47 +00:00
|
|
|
const REQUEST_TIMEOUT = 60; // 1 minute
|
2011-10-02 08:15:39 +00:00
|
|
|
const KEYEXCHANGE_VERSION = 3;
|
|
|
|
|
2010-12-10 02:12:09 +00:00
|
|
|
const JPAKE_SIGNERID_SENDER = "sender";
|
|
|
|
const JPAKE_SIGNERID_RECEIVER = "receiver";
|
|
|
|
const JPAKE_LENGTH_SECRET = 8;
|
|
|
|
const JPAKE_LENGTH_CLIENTID = 256;
|
|
|
|
const JPAKE_VERIFY_VALUE = "0123456789ABCDEF";
|
|
|
|
|
|
|
|
|
2011-10-02 08:15:39 +00:00
|
|
|
/**
|
2010-12-10 02:12:09 +00:00
|
|
|
* Client to exchange encrypted data using the J-PAKE algorithm.
|
|
|
|
* The exchange between two clients of this type looks like this:
|
|
|
|
*
|
|
|
|
*
|
2011-10-02 08:15:39 +00:00
|
|
|
* Mobile Server Desktop
|
|
|
|
* ===================================================================
|
|
|
|
* |
|
|
|
|
* retrieve channel <---------------|
|
|
|
|
* generate random secret |
|
|
|
|
* show PIN = secret + channel | ask user for PIN
|
|
|
|
* upload Mobile's message 1 ------>|
|
|
|
|
* |----> retrieve Mobile's message 1
|
|
|
|
* |<----- upload Desktop's message 1
|
|
|
|
* retrieve Desktop's message 1 <---|
|
|
|
|
* upload Mobile's message 2 ------>|
|
|
|
|
* |----> retrieve Mobile's message 2
|
|
|
|
* | compute key
|
|
|
|
* |<----- upload Desktop's message 2
|
|
|
|
* retrieve Desktop's message 2 <---|
|
|
|
|
* compute key |
|
|
|
|
* encrypt known value ------------>|
|
|
|
|
* |-------> retrieve encrypted value
|
|
|
|
* | verify against local known value
|
|
|
|
*
|
|
|
|
* At this point Desktop knows whether the PIN was entered correctly.
|
|
|
|
* If it wasn't, Desktop deletes the session. If it was, the account
|
|
|
|
* setup can proceed. If Desktop doesn't yet have an account set up,
|
|
|
|
* it will keep the channel open and let the user connect to or
|
|
|
|
* create an account.
|
|
|
|
*
|
|
|
|
* | encrypt credentials
|
|
|
|
* |<------------- upload credentials
|
|
|
|
* retrieve credentials <-----------|
|
|
|
|
* verify HMAC |
|
|
|
|
* decrypt credentials |
|
|
|
|
* delete session ----------------->|
|
|
|
|
* start syncing |
|
2010-12-10 02:12:09 +00:00
|
|
|
*
|
|
|
|
*
|
|
|
|
* Create a client object like so:
|
|
|
|
*
|
2011-10-02 08:15:39 +00:00
|
|
|
* let client = new JPAKEClient(controller);
|
2010-12-10 02:12:09 +00:00
|
|
|
*
|
2011-10-02 08:15:39 +00:00
|
|
|
* The 'controller' object must implement the following methods:
|
2010-12-10 02:12:09 +00:00
|
|
|
*
|
2011-10-02 08:15:52 +00:00
|
|
|
* displayPIN(pin) -- Called when a PIN has been generated and is ready to
|
|
|
|
* be displayed to the user. Only called on the client where the pairing
|
|
|
|
* was initiated with 'receiveNoPIN()'.
|
|
|
|
*
|
|
|
|
* onPairingStart() -- Called when the pairing has started and messages are
|
|
|
|
* being sent back and forth over the channel. Only called on the client
|
|
|
|
* where the pairing was initiated with 'receiveNoPIN()'.
|
2010-12-10 02:12:09 +00:00
|
|
|
*
|
2011-10-02 08:15:39 +00:00
|
|
|
* onPaired() -- Called when the device pairing has been established and
|
|
|
|
* we're ready to send the credentials over. To do that, the controller
|
|
|
|
* must call 'sendAndComplete()' while the channel is active.
|
|
|
|
*
|
2010-12-10 02:12:09 +00:00
|
|
|
* onComplete(data) -- Called after transfer has been completed. On
|
|
|
|
* the sending side this is called with no parameter and as soon as the
|
2011-10-02 08:15:39 +00:00
|
|
|
* data has been uploaded. This does not mean the receiving side has
|
|
|
|
* actually retrieved them yet.
|
2010-12-10 02:12:09 +00:00
|
|
|
*
|
|
|
|
* onAbort(error) -- Called whenever an error is encountered. All errors lead
|
|
|
|
* to an abort and the process has to be started again on both sides.
|
|
|
|
*
|
|
|
|
* To start the data transfer on the receiving side, call
|
|
|
|
*
|
|
|
|
* client.receiveNoPIN();
|
|
|
|
*
|
|
|
|
* This will allocate a new channel on the server, generate a PIN, have it
|
|
|
|
* displayed and then do the transfer once the protocol has been completed
|
|
|
|
* with the sending side.
|
|
|
|
*
|
|
|
|
* To initiate the transfer from the sending side, call
|
|
|
|
*
|
2011-10-02 08:15:39 +00:00
|
|
|
* client.pairWithPIN(pin, true);
|
|
|
|
*
|
|
|
|
* Once the pairing has been established, the controller's 'onPaired()' method
|
|
|
|
* will be called. To then transmit the data, call
|
|
|
|
*
|
|
|
|
* client.sendAndComplete(data);
|
2010-12-10 02:12:09 +00:00
|
|
|
*
|
|
|
|
* To abort the process, call
|
|
|
|
*
|
|
|
|
* client.abort();
|
|
|
|
*
|
|
|
|
* Note that after completion or abort, the 'client' instance may not be reused.
|
|
|
|
* You will have to create a new one in case you'd like to restart the process.
|
|
|
|
*/
|
2011-10-02 08:15:39 +00:00
|
|
|
function JPAKEClient(controller) {
|
|
|
|
this.controller = controller;
|
2010-12-10 02:12:09 +00:00
|
|
|
|
2011-06-13 18:42:18 +00:00
|
|
|
this._log = Log4Moz.repository.getLogger("Sync.JPAKEClient");
|
2010-12-10 02:12:09 +00:00
|
|
|
this._log.level = Log4Moz.Level[Svc.Prefs.get(
|
|
|
|
"log.logger.service.jpakeclient", "Debug")];
|
|
|
|
|
2011-10-02 08:15:36 +00:00
|
|
|
this._serverURL = Svc.Prefs.get("jpake.serverURL");
|
2010-12-10 02:12:09 +00:00
|
|
|
this._pollInterval = Svc.Prefs.get("jpake.pollInterval");
|
|
|
|
this._maxTries = Svc.Prefs.get("jpake.maxTries");
|
2011-10-02 08:15:36 +00:00
|
|
|
if (this._serverURL.slice(-1) != "/") {
|
|
|
|
this._serverURL += "/";
|
|
|
|
}
|
2010-12-10 02:12:09 +00:00
|
|
|
|
|
|
|
this._jpake = Cc["@mozilla.org/services-crypto/sync-jpake;1"]
|
|
|
|
.createInstance(Ci.nsISyncJPAKE);
|
|
|
|
|
|
|
|
this._setClientID();
|
|
|
|
}
|
|
|
|
JPAKEClient.prototype = {
|
|
|
|
|
2011-08-26 17:25:42 +00:00
|
|
|
_chain: Async.chain,
|
2010-12-10 02:12:09 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Public API
|
|
|
|
*/
|
|
|
|
|
2011-10-02 08:15:39 +00:00
|
|
|
/**
|
|
|
|
* Initiate pairing and receive data without providing a PIN. The PIN will
|
|
|
|
* be generated and passed on to the controller to be displayed to the user.
|
|
|
|
*
|
|
|
|
* This is typically called on mobile devices where typing is tedious.
|
|
|
|
*/
|
2010-12-10 02:12:09 +00:00
|
|
|
receiveNoPIN: function receiveNoPIN() {
|
|
|
|
this._my_signerid = JPAKE_SIGNERID_RECEIVER;
|
|
|
|
this._their_signerid = JPAKE_SIGNERID_SENDER;
|
|
|
|
|
|
|
|
this._secret = this._createSecret();
|
|
|
|
|
|
|
|
// Allow a large number of tries first while we wait for the PIN
|
|
|
|
// to be entered on the other device.
|
|
|
|
this._maxTries = Svc.Prefs.get("jpake.firstMsgMaxTries");
|
|
|
|
this._chain(this._getChannel,
|
|
|
|
this._computeStepOne,
|
|
|
|
this._putStep,
|
|
|
|
this._getStep,
|
|
|
|
function(callback) {
|
2011-10-02 08:15:52 +00:00
|
|
|
// We fetched the first response from the other client.
|
|
|
|
// Notify controller of the pairing starting.
|
|
|
|
Utils.nextTick(this.controller.onPairingStart,
|
|
|
|
this.controller);
|
|
|
|
|
2010-12-10 02:12:09 +00:00
|
|
|
// Now we can switch back to the smaller timeout.
|
|
|
|
this._maxTries = Svc.Prefs.get("jpake.maxTries");
|
|
|
|
callback();
|
|
|
|
},
|
|
|
|
this._computeStepTwo,
|
|
|
|
this._putStep,
|
|
|
|
this._getStep,
|
|
|
|
this._computeFinal,
|
|
|
|
this._computeKeyVerification,
|
|
|
|
this._putStep,
|
2011-10-02 08:15:39 +00:00
|
|
|
function(callback) {
|
|
|
|
// Allow longer time-out for the last message.
|
|
|
|
this._maxTries = Svc.Prefs.get("jpake.lastMsgMaxTries");
|
|
|
|
callback();
|
|
|
|
},
|
2010-12-10 02:12:09 +00:00
|
|
|
this._getStep,
|
|
|
|
this._decryptData,
|
|
|
|
this._complete)();
|
|
|
|
},
|
|
|
|
|
2011-10-02 08:15:39 +00:00
|
|
|
/**
|
|
|
|
* Initiate pairing based on the PIN entered by the user.
|
|
|
|
*
|
|
|
|
* This is typically called on desktop devices where typing is easier than
|
|
|
|
* on mobile.
|
|
|
|
*
|
|
|
|
* @param pin
|
|
|
|
* 12 character string (in human-friendly base32) containing the PIN
|
|
|
|
* entered by the user.
|
|
|
|
* @param expectDelay
|
|
|
|
* Flag that indicates that a significant delay between the pairing
|
|
|
|
* and the sending should be expected. v2 and earlier of the protocol
|
|
|
|
* did not allow for this and the pairing to a v2 or earlier client
|
|
|
|
* will be aborted if this flag is 'true'.
|
|
|
|
*/
|
|
|
|
pairWithPIN: function pairWithPIN(pin, expectDelay) {
|
2010-12-10 02:12:09 +00:00
|
|
|
this._my_signerid = JPAKE_SIGNERID_SENDER;
|
|
|
|
this._their_signerid = JPAKE_SIGNERID_RECEIVER;
|
|
|
|
|
|
|
|
this._channel = pin.slice(JPAKE_LENGTH_SECRET);
|
2011-10-02 08:15:36 +00:00
|
|
|
this._channelURL = this._serverURL + this._channel;
|
2010-12-10 02:12:09 +00:00
|
|
|
this._secret = pin.slice(0, JPAKE_LENGTH_SECRET);
|
|
|
|
|
|
|
|
this._chain(this._computeStepOne,
|
|
|
|
this._getStep,
|
2011-10-02 08:15:39 +00:00
|
|
|
function (callback) {
|
|
|
|
// Ensure that the other client can deal with a delay for
|
|
|
|
// the last message if that's requested by the caller.
|
|
|
|
if (!expectDelay) {
|
|
|
|
return callback();
|
|
|
|
}
|
|
|
|
if (!this._incoming.version || this._incoming.version < 3) {
|
|
|
|
return this.abort(JPAKE_ERROR_DELAYUNSUPPORTED);
|
|
|
|
}
|
|
|
|
return callback();
|
|
|
|
},
|
2010-12-10 02:12:09 +00:00
|
|
|
this._putStep,
|
|
|
|
this._computeStepTwo,
|
|
|
|
this._getStep,
|
|
|
|
this._putStep,
|
|
|
|
this._computeFinal,
|
|
|
|
this._getStep,
|
2011-10-02 08:15:39 +00:00
|
|
|
this._verifyPairing)();
|
|
|
|
},
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Send data after a successful pairing.
|
|
|
|
*
|
|
|
|
* @param obj
|
|
|
|
* Object containing the data to send. It will be serialized as JSON.
|
|
|
|
*/
|
|
|
|
sendAndComplete: function sendAndComplete(obj) {
|
|
|
|
if (!this._paired || this._finished) {
|
|
|
|
this._log.error("Can't send data, no active pairing!");
|
|
|
|
throw "No active pairing!";
|
|
|
|
}
|
|
|
|
this._data = JSON.stringify(obj);
|
|
|
|
this._chain(this._encryptData,
|
2010-12-10 02:12:09 +00:00
|
|
|
this._putStep,
|
|
|
|
this._complete)();
|
|
|
|
},
|
|
|
|
|
2011-10-02 08:15:39 +00:00
|
|
|
/**
|
|
|
|
* Abort the current pairing. The channel on the server will be deleted
|
|
|
|
* if the abort wasn't due to a network or server error. The controller's
|
|
|
|
* 'onAbort()' method is notified in all cases.
|
|
|
|
*
|
|
|
|
* @param error [optional]
|
|
|
|
* Error constant indicating the reason for the abort. Defaults to
|
|
|
|
* user abort.
|
|
|
|
*/
|
2010-12-10 02:12:09 +00:00
|
|
|
abort: function abort(error) {
|
|
|
|
this._log.debug("Aborting...");
|
|
|
|
this._finished = true;
|
|
|
|
let self = this;
|
2011-04-14 17:49:54 +00:00
|
|
|
|
|
|
|
// Default to "user aborted".
|
2011-10-02 08:15:36 +00:00
|
|
|
if (!error) {
|
2011-04-14 17:49:54 +00:00
|
|
|
error = JPAKE_ERROR_USERABORT;
|
2011-10-02 08:15:36 +00:00
|
|
|
}
|
2011-04-14 17:49:54 +00:00
|
|
|
|
2011-10-02 08:15:36 +00:00
|
|
|
if (error == JPAKE_ERROR_CHANNEL ||
|
|
|
|
error == JPAKE_ERROR_NETWORK ||
|
|
|
|
error == JPAKE_ERROR_NODATA) {
|
2011-10-02 08:15:39 +00:00
|
|
|
Utils.nextTick(function() { this.controller.onAbort(error); }, this);
|
2010-12-10 02:12:09 +00:00
|
|
|
} else {
|
2011-10-02 08:15:39 +00:00
|
|
|
this._reportFailure(error, function() { self.controller.onAbort(error); });
|
2010-12-10 02:12:09 +00:00
|
|
|
}
|
|
|
|
},
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Utilities
|
|
|
|
*/
|
|
|
|
|
|
|
|
_setClientID: function _setClientID() {
|
|
|
|
let rng = Cc["@mozilla.org/security/random-generator;1"]
|
|
|
|
.createInstance(Ci.nsIRandomGenerator);
|
|
|
|
let bytes = rng.generateRandomBytes(JPAKE_LENGTH_CLIENTID / 2);
|
|
|
|
this._clientID = [("0" + byte.toString(16)).slice(-2)
|
|
|
|
for each (byte in bytes)].join("");
|
|
|
|
},
|
|
|
|
|
|
|
|
_createSecret: function _createSecret() {
|
|
|
|
// 0-9a-z without 1,l,o,0
|
|
|
|
const key = "23456789abcdefghijkmnpqrstuvwxyz";
|
|
|
|
let rng = Cc["@mozilla.org/security/random-generator;1"]
|
|
|
|
.createInstance(Ci.nsIRandomGenerator);
|
|
|
|
let bytes = rng.generateRandomBytes(JPAKE_LENGTH_SECRET);
|
|
|
|
return [key[Math.floor(byte * key.length / 256)]
|
|
|
|
for each (byte in bytes)].join("");
|
|
|
|
},
|
|
|
|
|
2011-07-07 00:20:47 +00:00
|
|
|
_newRequest: function _newRequest(uri) {
|
|
|
|
let request = new RESTRequest(uri);
|
|
|
|
request.setHeader("X-KeyExchange-Id", this._clientID);
|
|
|
|
request.timeout = REQUEST_TIMEOUT;
|
|
|
|
return request;
|
|
|
|
},
|
|
|
|
|
2010-12-10 02:12:09 +00:00
|
|
|
/*
|
|
|
|
* Steps of J-PAKE procedure
|
|
|
|
*/
|
|
|
|
|
|
|
|
_getChannel: function _getChannel(callback) {
|
|
|
|
this._log.trace("Requesting channel.");
|
2011-10-02 08:15:36 +00:00
|
|
|
let request = this._newRequest(this._serverURL + "new_channel");
|
2011-07-07 00:20:47 +00:00
|
|
|
request.get(Utils.bind2(this, function handleChannel(error) {
|
2011-10-02 08:15:36 +00:00
|
|
|
if (this._finished) {
|
2010-12-10 02:12:09 +00:00
|
|
|
return;
|
2011-10-02 08:15:36 +00:00
|
|
|
}
|
2010-12-10 02:12:09 +00:00
|
|
|
|
|
|
|
if (error) {
|
|
|
|
this._log.error("Error acquiring channel ID. " + error);
|
|
|
|
this.abort(JPAKE_ERROR_CHANNEL);
|
|
|
|
return;
|
|
|
|
}
|
2011-07-07 00:20:47 +00:00
|
|
|
if (request.response.status != 200) {
|
2010-12-10 02:12:09 +00:00
|
|
|
this._log.error("Error acquiring channel ID. Server responded with HTTP "
|
2011-07-07 00:20:47 +00:00
|
|
|
+ request.response.status);
|
2010-12-10 02:12:09 +00:00
|
|
|
this.abort(JPAKE_ERROR_CHANNEL);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
try {
|
2011-07-07 00:20:47 +00:00
|
|
|
this._channel = JSON.parse(request.response.body);
|
2010-12-10 02:12:09 +00:00
|
|
|
} catch (ex) {
|
|
|
|
this._log.error("Server responded with invalid JSON.");
|
|
|
|
this.abort(JPAKE_ERROR_CHANNEL);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
this._log.debug("Using channel " + this._channel);
|
2011-10-02 08:15:36 +00:00
|
|
|
this._channelURL = this._serverURL + this._channel;
|
2010-12-10 02:12:09 +00:00
|
|
|
|
|
|
|
// Don't block on UI code.
|
|
|
|
let pin = this._secret + this._channel;
|
2011-10-02 08:15:39 +00:00
|
|
|
Utils.nextTick(function() { this.controller.displayPIN(pin); }, this);
|
2010-12-10 02:12:09 +00:00
|
|
|
callback();
|
|
|
|
}));
|
|
|
|
},
|
|
|
|
|
|
|
|
// Generic handler for uploading data.
|
|
|
|
_putStep: function _putStep(callback) {
|
|
|
|
this._log.trace("Uploading message " + this._outgoing.type);
|
2011-10-02 08:15:36 +00:00
|
|
|
let request = this._newRequest(this._channelURL);
|
2011-10-02 08:15:39 +00:00
|
|
|
if (this._their_etag) {
|
|
|
|
request.setHeader("If-Match", this._their_etag);
|
|
|
|
} else {
|
|
|
|
request.setHeader("If-None-Match", "*");
|
|
|
|
}
|
2011-07-07 00:20:47 +00:00
|
|
|
request.put(this._outgoing, Utils.bind2(this, function (error) {
|
2011-10-02 08:15:36 +00:00
|
|
|
if (this._finished) {
|
2010-12-10 02:12:09 +00:00
|
|
|
return;
|
2011-10-02 08:15:36 +00:00
|
|
|
}
|
2010-12-10 02:12:09 +00:00
|
|
|
|
|
|
|
if (error) {
|
|
|
|
this._log.error("Error uploading data. " + error);
|
|
|
|
this.abort(JPAKE_ERROR_NETWORK);
|
|
|
|
return;
|
|
|
|
}
|
2011-07-07 00:20:47 +00:00
|
|
|
if (request.response.status != 200) {
|
2010-12-10 02:12:09 +00:00
|
|
|
this._log.error("Could not upload data. Server responded with HTTP "
|
2011-07-07 00:20:47 +00:00
|
|
|
+ request.response.status);
|
2010-12-10 02:12:09 +00:00
|
|
|
this.abort(JPAKE_ERROR_SERVER);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
// There's no point in returning early here since the next step will
|
|
|
|
// always be a GET so let's pause for twice the poll interval.
|
2011-10-02 08:15:39 +00:00
|
|
|
this._my_etag = request.response.headers["etag"];
|
2011-06-06 19:27:36 +00:00
|
|
|
Utils.namedTimer(function () { callback(); }, this._pollInterval * 2,
|
|
|
|
this, "_pollTimer");
|
2010-12-10 02:12:09 +00:00
|
|
|
}));
|
|
|
|
},
|
|
|
|
|
|
|
|
// Generic handler for polling for and retrieving data.
|
|
|
|
_pollTries: 0,
|
|
|
|
_getStep: function _getStep(callback) {
|
|
|
|
this._log.trace("Retrieving next message.");
|
2011-10-02 08:15:36 +00:00
|
|
|
let request = this._newRequest(this._channelURL);
|
2011-10-02 08:15:39 +00:00
|
|
|
if (this._my_etag) {
|
|
|
|
request.setHeader("If-None-Match", this._my_etag);
|
2011-07-07 00:20:47 +00:00
|
|
|
}
|
2010-12-10 02:12:09 +00:00
|
|
|
|
2011-07-07 00:20:47 +00:00
|
|
|
request.get(Utils.bind2(this, function (error) {
|
2011-10-02 08:15:36 +00:00
|
|
|
if (this._finished) {
|
2010-12-10 02:12:09 +00:00
|
|
|
return;
|
2011-10-02 08:15:36 +00:00
|
|
|
}
|
2010-12-10 02:12:09 +00:00
|
|
|
|
|
|
|
if (error) {
|
|
|
|
this._log.error("Error fetching data. " + error);
|
|
|
|
this.abort(JPAKE_ERROR_NETWORK);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2011-07-07 00:20:47 +00:00
|
|
|
if (request.response.status == 304) {
|
2010-12-10 02:12:09 +00:00
|
|
|
this._log.trace("Channel hasn't been updated yet. Will try again later.");
|
|
|
|
if (this._pollTries >= this._maxTries) {
|
|
|
|
this._log.error("Tried for " + this._pollTries + " times, aborting.");
|
|
|
|
this.abort(JPAKE_ERROR_TIMEOUT);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
this._pollTries += 1;
|
2011-06-06 19:27:36 +00:00
|
|
|
Utils.namedTimer(function() { this._getStep(callback); },
|
|
|
|
this._pollInterval, this, "_pollTimer");
|
2010-12-10 02:12:09 +00:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
this._pollTries = 0;
|
|
|
|
|
2011-07-07 00:20:47 +00:00
|
|
|
if (request.response.status == 404) {
|
2010-12-10 02:12:09 +00:00
|
|
|
this._log.error("No data found in the channel.");
|
|
|
|
this.abort(JPAKE_ERROR_NODATA);
|
|
|
|
return;
|
|
|
|
}
|
2011-07-07 00:20:47 +00:00
|
|
|
if (request.response.status != 200) {
|
2010-12-10 02:12:09 +00:00
|
|
|
this._log.error("Could not retrieve data. Server responded with HTTP "
|
2011-07-07 00:20:47 +00:00
|
|
|
+ request.response.status);
|
2010-12-10 02:12:09 +00:00
|
|
|
this.abort(JPAKE_ERROR_SERVER);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2011-10-02 08:15:39 +00:00
|
|
|
this._their_etag = request.response.headers["etag"];
|
|
|
|
if (!this._their_etag) {
|
|
|
|
this._log.error("Server did not supply ETag for message: "
|
|
|
|
+ request.response.body);
|
|
|
|
this.abort(JPAKE_ERROR_SERVER);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2010-12-10 02:12:09 +00:00
|
|
|
try {
|
2011-07-07 00:20:47 +00:00
|
|
|
this._incoming = JSON.parse(request.response.body);
|
2010-12-10 02:12:09 +00:00
|
|
|
} catch (ex) {
|
|
|
|
this._log.error("Server responded with invalid JSON.");
|
|
|
|
this.abort(JPAKE_ERROR_INVALID);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
this._log.trace("Fetched message " + this._incoming.type);
|
|
|
|
callback();
|
|
|
|
}));
|
|
|
|
},
|
|
|
|
|
|
|
|
_reportFailure: function _reportFailure(reason, callback) {
|
|
|
|
this._log.debug("Reporting failure to server.");
|
2011-10-02 08:15:36 +00:00
|
|
|
let request = this._newRequest(this._serverURL + "report");
|
2011-07-07 00:20:47 +00:00
|
|
|
request.setHeader("X-KeyExchange-Cid", this._channel);
|
|
|
|
request.setHeader("X-KeyExchange-Log", reason);
|
|
|
|
request.post("", Utils.bind2(this, function (error) {
|
|
|
|
if (error) {
|
2010-12-10 02:12:09 +00:00
|
|
|
this._log.warn("Report failed: " + error);
|
2011-07-07 00:20:47 +00:00
|
|
|
} else if (request.response.status != 200) {
|
2010-12-10 02:12:09 +00:00
|
|
|
this._log.warn("Report failed. Server responded with HTTP "
|
2011-07-07 00:20:47 +00:00
|
|
|
+ request.response.status);
|
|
|
|
}
|
2010-12-10 02:12:09 +00:00
|
|
|
|
|
|
|
// Do not block on errors, we're done or aborted by now anyway.
|
|
|
|
callback();
|
|
|
|
}));
|
|
|
|
},
|
|
|
|
|
|
|
|
_computeStepOne: function _computeStepOne(callback) {
|
|
|
|
this._log.trace("Computing round 1.");
|
|
|
|
let gx1 = {};
|
|
|
|
let gv1 = {};
|
|
|
|
let r1 = {};
|
|
|
|
let gx2 = {};
|
|
|
|
let gv2 = {};
|
|
|
|
let r2 = {};
|
|
|
|
try {
|
|
|
|
this._jpake.round1(this._my_signerid, gx1, gv1, r1, gx2, gv2, r2);
|
|
|
|
} catch (ex) {
|
|
|
|
this._log.error("JPAKE round 1 threw: " + ex);
|
|
|
|
this.abort(JPAKE_ERROR_INTERNAL);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
let one = {gx1: gx1.value,
|
|
|
|
gx2: gx2.value,
|
|
|
|
zkp_x1: {gr: gv1.value, b: r1.value, id: this._my_signerid},
|
|
|
|
zkp_x2: {gr: gv2.value, b: r2.value, id: this._my_signerid}};
|
2011-10-02 08:15:39 +00:00
|
|
|
this._outgoing = {type: this._my_signerid + "1",
|
|
|
|
version: KEYEXCHANGE_VERSION,
|
|
|
|
payload: one};
|
2010-12-10 02:12:09 +00:00
|
|
|
this._log.trace("Generated message " + this._outgoing.type);
|
|
|
|
callback();
|
|
|
|
},
|
|
|
|
|
|
|
|
_computeStepTwo: function _computeStepTwo(callback) {
|
|
|
|
this._log.trace("Computing round 2.");
|
|
|
|
if (this._incoming.type != this._their_signerid + "1") {
|
|
|
|
this._log.error("Invalid round 1 message: "
|
|
|
|
+ JSON.stringify(this._incoming));
|
|
|
|
this.abort(JPAKE_ERROR_WRONGMESSAGE);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
let step1 = this._incoming.payload;
|
|
|
|
if (!step1 || !step1.zkp_x1 || step1.zkp_x1.id != this._their_signerid
|
|
|
|
|| !step1.zkp_x2 || step1.zkp_x2.id != this._their_signerid) {
|
|
|
|
this._log.error("Invalid round 1 payload: " + JSON.stringify(step1));
|
|
|
|
this.abort(JPAKE_ERROR_WRONGMESSAGE);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
let A = {};
|
|
|
|
let gvA = {};
|
|
|
|
let rA = {};
|
|
|
|
|
|
|
|
try {
|
|
|
|
this._jpake.round2(this._their_signerid, this._secret,
|
|
|
|
step1.gx1, step1.zkp_x1.gr, step1.zkp_x1.b,
|
|
|
|
step1.gx2, step1.zkp_x2.gr, step1.zkp_x2.b,
|
|
|
|
A, gvA, rA);
|
|
|
|
} catch (ex) {
|
|
|
|
this._log.error("JPAKE round 2 threw: " + ex);
|
|
|
|
this.abort(JPAKE_ERROR_INTERNAL);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
let two = {A: A.value,
|
|
|
|
zkp_A: {gr: gvA.value, b: rA.value, id: this._my_signerid}};
|
2011-10-02 08:15:39 +00:00
|
|
|
this._outgoing = {type: this._my_signerid + "2",
|
|
|
|
version: KEYEXCHANGE_VERSION,
|
|
|
|
payload: two};
|
2010-12-10 02:12:09 +00:00
|
|
|
this._log.trace("Generated message " + this._outgoing.type);
|
|
|
|
callback();
|
|
|
|
},
|
|
|
|
|
|
|
|
_computeFinal: function _computeFinal(callback) {
|
|
|
|
if (this._incoming.type != this._their_signerid + "2") {
|
|
|
|
this._log.error("Invalid round 2 message: "
|
|
|
|
+ JSON.stringify(this._incoming));
|
|
|
|
this.abort(JPAKE_ERROR_WRONGMESSAGE);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
let step2 = this._incoming.payload;
|
|
|
|
if (!step2 || !step2.zkp_A || step2.zkp_A.id != this._their_signerid) {
|
|
|
|
this._log.error("Invalid round 2 payload: " + JSON.stringify(step1));
|
|
|
|
this.abort(JPAKE_ERROR_WRONGMESSAGE);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
let aes256Key = {};
|
|
|
|
let hmac256Key = {};
|
|
|
|
|
|
|
|
try {
|
|
|
|
this._jpake.final(step2.A, step2.zkp_A.gr, step2.zkp_A.b, HMAC_INPUT,
|
|
|
|
aes256Key, hmac256Key);
|
|
|
|
} catch (ex) {
|
|
|
|
this._log.error("JPAKE final round threw: " + ex);
|
|
|
|
this.abort(JPAKE_ERROR_INTERNAL);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
this._crypto_key = aes256Key.value;
|
2011-03-01 22:29:41 +00:00
|
|
|
let hmac_key = Utils.makeHMACKey(Utils.safeAtoB(hmac256Key.value));
|
|
|
|
this._hmac_hasher = Utils.makeHMACHasher(Ci.nsICryptoHMAC.SHA256, hmac_key);
|
2010-12-10 02:12:09 +00:00
|
|
|
|
|
|
|
callback();
|
|
|
|
},
|
|
|
|
|
|
|
|
_computeKeyVerification: function _computeKeyVerification(callback) {
|
|
|
|
this._log.trace("Encrypting key verification value.");
|
|
|
|
let iv, ciphertext;
|
|
|
|
try {
|
|
|
|
iv = Svc.Crypto.generateRandomIV();
|
|
|
|
ciphertext = Svc.Crypto.encrypt(JPAKE_VERIFY_VALUE,
|
|
|
|
this._crypto_key, iv);
|
|
|
|
} catch (ex) {
|
|
|
|
this._log.error("Failed to encrypt key verification value.");
|
|
|
|
this.abort(JPAKE_ERROR_INTERNAL);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
this._outgoing = {type: this._my_signerid + "3",
|
2011-10-02 08:15:39 +00:00
|
|
|
version: KEYEXCHANGE_VERSION,
|
2010-12-10 02:12:09 +00:00
|
|
|
payload: {ciphertext: ciphertext, IV: iv}};
|
|
|
|
this._log.trace("Generated message " + this._outgoing.type);
|
|
|
|
callback();
|
|
|
|
},
|
|
|
|
|
2011-10-02 08:15:39 +00:00
|
|
|
_verifyPairing: function _verifyPairing(callback) {
|
2010-12-10 02:12:09 +00:00
|
|
|
this._log.trace("Verifying their key.");
|
|
|
|
if (this._incoming.type != this._their_signerid + "3") {
|
|
|
|
this._log.error("Invalid round 3 data: " +
|
|
|
|
JSON.stringify(this._incoming));
|
|
|
|
this.abort(JPAKE_ERROR_WRONGMESSAGE);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
let step3 = this._incoming.payload;
|
2011-10-02 08:15:39 +00:00
|
|
|
let ciphertext;
|
2010-12-10 02:12:09 +00:00
|
|
|
try {
|
|
|
|
ciphertext = Svc.Crypto.encrypt(JPAKE_VERIFY_VALUE,
|
|
|
|
this._crypto_key, step3.IV);
|
2011-10-02 08:15:36 +00:00
|
|
|
if (ciphertext != step3.ciphertext) {
|
2010-12-10 02:12:09 +00:00
|
|
|
throw "Key mismatch!";
|
2011-10-02 08:15:36 +00:00
|
|
|
}
|
2010-12-10 02:12:09 +00:00
|
|
|
} catch (ex) {
|
|
|
|
this._log.error("Keys don't match!");
|
|
|
|
this.abort(JPAKE_ERROR_KEYMISMATCH);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2011-10-02 08:15:39 +00:00
|
|
|
this._log.debug("Verified pairing!");
|
|
|
|
this._paired = true;
|
|
|
|
Utils.nextTick(function () { this.controller.onPaired(); }, this);
|
|
|
|
callback();
|
|
|
|
},
|
|
|
|
|
|
|
|
_encryptData: function _encryptData(callback) {
|
2010-12-10 02:12:09 +00:00
|
|
|
this._log.trace("Encrypting data.");
|
|
|
|
let iv, ciphertext, hmac;
|
|
|
|
try {
|
|
|
|
iv = Svc.Crypto.generateRandomIV();
|
|
|
|
ciphertext = Svc.Crypto.encrypt(this._data, this._crypto_key, iv);
|
2011-03-01 22:29:41 +00:00
|
|
|
hmac = Utils.bytesAsHex(Utils.digestUTF8(ciphertext, this._hmac_hasher));
|
2010-12-10 02:12:09 +00:00
|
|
|
} catch (ex) {
|
|
|
|
this._log.error("Failed to encrypt data.");
|
|
|
|
this.abort(JPAKE_ERROR_INTERNAL);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
this._outgoing = {type: this._my_signerid + "3",
|
2011-10-02 08:15:39 +00:00
|
|
|
version: KEYEXCHANGE_VERSION,
|
2010-12-10 02:12:09 +00:00
|
|
|
payload: {ciphertext: ciphertext, IV: iv, hmac: hmac}};
|
|
|
|
this._log.trace("Generated message " + this._outgoing.type);
|
|
|
|
callback();
|
|
|
|
},
|
|
|
|
|
|
|
|
_decryptData: function _decryptData(callback) {
|
|
|
|
this._log.trace("Verifying their key.");
|
|
|
|
if (this._incoming.type != this._their_signerid + "3") {
|
|
|
|
this._log.error("Invalid round 3 data: "
|
|
|
|
+ JSON.stringify(this._incoming));
|
|
|
|
this.abort(JPAKE_ERROR_WRONGMESSAGE);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
let step3 = this._incoming.payload;
|
|
|
|
try {
|
2011-03-01 22:29:41 +00:00
|
|
|
let hmac = Utils.bytesAsHex(
|
|
|
|
Utils.digestUTF8(step3.ciphertext, this._hmac_hasher));
|
2011-10-02 08:15:36 +00:00
|
|
|
if (hmac != step3.hmac) {
|
2010-12-10 02:12:09 +00:00
|
|
|
throw "HMAC validation failed!";
|
2011-10-02 08:15:36 +00:00
|
|
|
}
|
2010-12-10 02:12:09 +00:00
|
|
|
} catch (ex) {
|
|
|
|
this._log.error("HMAC validation failed.");
|
|
|
|
this.abort(JPAKE_ERROR_KEYMISMATCH);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
this._log.trace("Decrypting data.");
|
|
|
|
let cleartext;
|
|
|
|
try {
|
|
|
|
cleartext = Svc.Crypto.decrypt(step3.ciphertext, this._crypto_key,
|
|
|
|
step3.IV);
|
|
|
|
} catch (ex) {
|
|
|
|
this._log.error("Failed to decrypt data.");
|
|
|
|
this.abort(JPAKE_ERROR_INTERNAL);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
try {
|
|
|
|
this._newData = JSON.parse(cleartext);
|
|
|
|
} catch (ex) {
|
|
|
|
this._log.error("Invalid data data: " + JSON.stringify(cleartext));
|
|
|
|
this.abort(JPAKE_ERROR_INVALID);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
this._log.trace("Decrypted data.");
|
|
|
|
callback();
|
|
|
|
},
|
|
|
|
|
|
|
|
_complete: function _complete() {
|
|
|
|
this._log.debug("Exchange completed.");
|
|
|
|
this._finished = true;
|
2011-10-02 08:15:39 +00:00
|
|
|
Utils.nextTick(function () { this.controller.onComplete(this._newData); },
|
|
|
|
this);
|
2010-12-10 02:12:09 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
};
|