2005-08-09 23:06:47 +00:00
|
|
|
/* vim:set ts=4 sw=4 sts=4 et cindent: */
|
2012-05-21 11:12:37 +00:00
|
|
|
/* This Source Code Form is subject to the terms of the Mozilla Public
|
|
|
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
|
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
|
2005-08-09 23:06:47 +00:00
|
|
|
|
|
|
|
//
|
|
|
|
// Negotiate Authentication Support Module
|
|
|
|
//
|
|
|
|
// Described by IETF Internet draft: draft-brezak-kerberos-http-00.txt
|
|
|
|
// (formerly draft-brezak-spnego-http-04.txt)
|
|
|
|
//
|
|
|
|
// Also described here:
|
|
|
|
// http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnsecure/html/http-sso-1.asp
|
|
|
|
//
|
|
|
|
|
2005-08-18 15:22:33 +00:00
|
|
|
#include "nsAuthSSPI.h"
|
2017-09-11 02:13:42 +00:00
|
|
|
#include "nsDNSService2.h"
|
2005-08-09 23:06:47 +00:00
|
|
|
#include "nsIServiceManager.h"
|
|
|
|
#include "nsIDNSService.h"
|
|
|
|
#include "nsIDNSRecord.h"
|
2017-12-07 03:36:57 +00:00
|
|
|
#include "nsMemory.h"
|
2005-08-09 23:06:47 +00:00
|
|
|
#include "nsNetCID.h"
|
|
|
|
#include "nsCOMPtr.h"
|
2011-11-09 17:18:59 +00:00
|
|
|
#include "nsICryptoHash.h"
|
2013-07-25 16:54:11 +00:00
|
|
|
#include "mozilla/Telemetry.h"
|
2005-08-09 23:06:47 +00:00
|
|
|
|
2008-08-27 21:44:54 +00:00
|
|
|
#include <windows.h>
|
|
|
|
|
2005-08-18 15:22:33 +00:00
|
|
|
#define SEC_SUCCESS(Status) ((Status) >= 0)
|
|
|
|
|
|
|
|
#ifndef KERB_WRAP_NO_ENCRYPT
|
|
|
|
#define KERB_WRAP_NO_ENCRYPT 0x80000001
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#ifndef SECBUFFER_PADDING
|
|
|
|
#define SECBUFFER_PADDING 9
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#ifndef SECBUFFER_STREAM
|
|
|
|
#define SECBUFFER_STREAM 10
|
|
|
|
#endif
|
|
|
|
|
2005-08-09 23:06:47 +00:00
|
|
|
//-----------------------------------------------------------------------------
|
|
|
|
|
2013-12-03 15:09:50 +00:00
|
|
|
static const wchar_t *const pTypeName [] = {
|
2008-09-05 19:09:06 +00:00
|
|
|
L"Kerberos",
|
|
|
|
L"Negotiate",
|
|
|
|
L"NTLM"
|
2005-08-18 15:22:33 +00:00
|
|
|
};
|
|
|
|
|
2005-08-09 23:06:47 +00:00
|
|
|
#ifdef DEBUG
|
|
|
|
#define CASE_(_x) case _x: return # _x;
|
|
|
|
static const char *MapErrorCode(int rc)
|
|
|
|
{
|
|
|
|
switch (rc) {
|
|
|
|
CASE_(SEC_E_OK)
|
|
|
|
CASE_(SEC_I_CONTINUE_NEEDED)
|
|
|
|
CASE_(SEC_I_COMPLETE_NEEDED)
|
|
|
|
CASE_(SEC_I_COMPLETE_AND_CONTINUE)
|
|
|
|
CASE_(SEC_E_INCOMPLETE_MESSAGE)
|
|
|
|
CASE_(SEC_I_INCOMPLETE_CREDENTIALS)
|
|
|
|
CASE_(SEC_E_INVALID_HANDLE)
|
|
|
|
CASE_(SEC_E_TARGET_UNKNOWN)
|
|
|
|
CASE_(SEC_E_LOGON_DENIED)
|
|
|
|
CASE_(SEC_E_INTERNAL_ERROR)
|
|
|
|
CASE_(SEC_E_NO_CREDENTIALS)
|
|
|
|
CASE_(SEC_E_NO_AUTHENTICATING_AUTHORITY)
|
|
|
|
CASE_(SEC_E_INSUFFICIENT_MEMORY)
|
|
|
|
CASE_(SEC_E_INVALID_TOKEN)
|
|
|
|
}
|
|
|
|
return "<unknown>";
|
|
|
|
}
|
|
|
|
#else
|
|
|
|
#define MapErrorCode(_rc) ""
|
|
|
|
#endif
|
|
|
|
|
|
|
|
//-----------------------------------------------------------------------------
|
|
|
|
|
2008-08-27 21:44:54 +00:00
|
|
|
static PSecurityFunctionTableW sspi;
|
2005-08-09 23:06:47 +00:00
|
|
|
|
|
|
|
static nsresult
|
|
|
|
InitSSPI()
|
|
|
|
{
|
2005-08-18 15:22:33 +00:00
|
|
|
LOG((" InitSSPI\n"));
|
|
|
|
|
2012-02-23 14:53:55 +00:00
|
|
|
sspi = InitSecurityInterfaceW();
|
2005-08-09 23:06:47 +00:00
|
|
|
if (!sspi) {
|
2008-08-27 21:44:54 +00:00
|
|
|
LOG(("InitSecurityInterfaceW failed"));
|
2005-08-09 23:06:47 +00:00
|
|
|
return NS_ERROR_UNEXPECTED;
|
|
|
|
}
|
|
|
|
|
|
|
|
return NS_OK;
|
|
|
|
}
|
|
|
|
|
|
|
|
//-----------------------------------------------------------------------------
|
|
|
|
|
2017-09-11 02:13:42 +00:00
|
|
|
nsresult
|
|
|
|
nsAuthSSPI::MakeSN(const char *principal, nsCString &result)
|
2013-01-22 16:59:01 +00:00
|
|
|
{
|
|
|
|
nsresult rv;
|
|
|
|
|
|
|
|
nsAutoCString buf(principal);
|
|
|
|
|
|
|
|
// The service name looks like "protocol@hostname", we need to map
|
|
|
|
// this to a value that SSPI expects. To be consistent with IE, we
|
|
|
|
// need to map '@' to '/' and canonicalize the hostname.
|
2013-04-03 00:59:27 +00:00
|
|
|
int32_t index = buf.FindChar('@');
|
2013-01-22 16:59:01 +00:00
|
|
|
if (index == kNotFound)
|
|
|
|
return NS_ERROR_UNEXPECTED;
|
2017-07-06 12:00:35 +00:00
|
|
|
|
2017-09-11 02:13:42 +00:00
|
|
|
nsCOMPtr<nsIDNSService> dnsService = do_GetService(NS_DNSSERVICE_CONTRACTID, &rv);
|
2013-01-22 16:59:01 +00:00
|
|
|
if (NS_FAILED(rv))
|
|
|
|
return rv;
|
|
|
|
|
2017-09-11 02:13:42 +00:00
|
|
|
auto dns = static_cast<nsDNSService*>(dnsService.get());
|
|
|
|
|
2013-01-22 16:59:01 +00:00
|
|
|
// This could be expensive if our DNS cache cannot satisfy the request.
|
|
|
|
// However, we should have at least hit the OS resolver once prior to
|
|
|
|
// reaching this code, so provided the OS resolver has this information
|
|
|
|
// cached, we should not have to worry about blocking on this function call
|
|
|
|
// for very long. NOTE: because we ask for the canonical hostname, we
|
|
|
|
// might end up requiring extra network activity in cases where the OS
|
|
|
|
// resolver might not have enough information to satisfy the request from
|
|
|
|
// its cache. This is not an issue in versions of Windows up to WinXP.
|
|
|
|
nsCOMPtr<nsIDNSRecord> record;
|
2017-02-15 02:39:40 +00:00
|
|
|
mozilla::OriginAttributes attrs;
|
2017-09-11 02:13:42 +00:00
|
|
|
rv = dns->DeprecatedSyncResolve(Substring(buf, index + 1),
|
|
|
|
nsIDNSService::RESOLVE_CANONICAL_NAME,
|
|
|
|
attrs,
|
|
|
|
getter_AddRefs(record));
|
2013-01-22 16:59:01 +00:00
|
|
|
if (NS_FAILED(rv))
|
|
|
|
return rv;
|
|
|
|
|
|
|
|
nsAutoCString cname;
|
|
|
|
rv = record->GetCanonicalName(cname);
|
|
|
|
if (NS_SUCCEEDED(rv)) {
|
|
|
|
result = StringHead(buf, index) + NS_LITERAL_CSTRING("/") + cname;
|
|
|
|
LOG(("Using SPN of [%s]\n", result.get()));
|
|
|
|
}
|
|
|
|
return rv;
|
|
|
|
}
|
|
|
|
|
|
|
|
//-----------------------------------------------------------------------------
|
|
|
|
|
2005-08-18 15:22:33 +00:00
|
|
|
nsAuthSSPI::nsAuthSSPI(pType package)
|
2005-08-09 23:06:47 +00:00
|
|
|
: mServiceFlags(REQ_DEFAULT)
|
2005-08-09 23:06:58 +00:00
|
|
|
, mMaxTokenLen(0)
|
2005-08-18 15:22:33 +00:00
|
|
|
, mPackage(package)
|
2012-07-30 14:20:58 +00:00
|
|
|
, mCertDERData(nullptr)
|
2011-11-09 17:18:59 +00:00
|
|
|
, mCertDERLength(0)
|
2005-08-09 23:06:47 +00:00
|
|
|
{
|
|
|
|
memset(&mCred, 0, sizeof(mCred));
|
|
|
|
memset(&mCtxt, 0, sizeof(mCtxt));
|
|
|
|
}
|
|
|
|
|
2005-08-18 15:22:33 +00:00
|
|
|
nsAuthSSPI::~nsAuthSSPI()
|
2005-08-09 23:06:47 +00:00
|
|
|
{
|
|
|
|
Reset();
|
|
|
|
|
|
|
|
if (mCred.dwLower || mCred.dwUpper) {
|
|
|
|
#ifdef __MINGW32__
|
|
|
|
(sspi->FreeCredentialsHandle)(&mCred);
|
|
|
|
#else
|
|
|
|
(sspi->FreeCredentialHandle)(&mCred);
|
|
|
|
#endif
|
|
|
|
memset(&mCred, 0, sizeof(mCred));
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
void
|
2005-08-18 15:22:33 +00:00
|
|
|
nsAuthSSPI::Reset()
|
2005-08-09 23:06:47 +00:00
|
|
|
{
|
2011-11-09 17:18:59 +00:00
|
|
|
mIsFirst = true;
|
|
|
|
|
|
|
|
if (mCertDERData){
|
2015-03-27 00:01:12 +00:00
|
|
|
free(mCertDERData);
|
2012-07-30 14:20:58 +00:00
|
|
|
mCertDERData = nullptr;
|
2017-07-06 12:00:35 +00:00
|
|
|
mCertDERLength = 0;
|
2011-11-09 17:18:59 +00:00
|
|
|
}
|
|
|
|
|
2005-08-09 23:06:47 +00:00
|
|
|
if (mCtxt.dwLower || mCtxt.dwUpper) {
|
|
|
|
(sspi->DeleteSecurityContext)(&mCtxt);
|
|
|
|
memset(&mCtxt, 0, sizeof(mCtxt));
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2014-04-27 07:06:00 +00:00
|
|
|
NS_IMPL_ISUPPORTS(nsAuthSSPI, nsIAuthModule)
|
2005-08-09 23:06:47 +00:00
|
|
|
|
|
|
|
NS_IMETHODIMP
|
2005-08-18 15:22:33 +00:00
|
|
|
nsAuthSSPI::Init(const char *serviceName,
|
2012-08-22 15:56:38 +00:00
|
|
|
uint32_t serviceFlags,
|
2014-01-04 15:02:17 +00:00
|
|
|
const char16_t *domain,
|
|
|
|
const char16_t *username,
|
|
|
|
const char16_t *password)
|
2005-08-09 23:06:47 +00:00
|
|
|
{
|
2005-08-18 15:22:33 +00:00
|
|
|
LOG((" nsAuthSSPI::Init\n"));
|
|
|
|
|
2011-11-09 17:18:59 +00:00
|
|
|
mIsFirst = true;
|
|
|
|
mCertDERLength = 0;
|
2012-07-30 14:20:58 +00:00
|
|
|
mCertDERData = nullptr;
|
2011-11-09 17:18:59 +00:00
|
|
|
|
2009-11-19 22:12:43 +00:00
|
|
|
// The caller must supply a service name to be used. (For why we now require
|
|
|
|
// a service name for NTLM, see bug 487872.)
|
2009-11-04 22:12:24 +00:00
|
|
|
NS_ENSURE_TRUE(serviceName && *serviceName, NS_ERROR_INVALID_ARG);
|
2005-08-09 23:06:47 +00:00
|
|
|
|
|
|
|
nsresult rv;
|
|
|
|
|
|
|
|
// XXX lazy initialization like this assumes that we are single threaded
|
|
|
|
if (!sspi) {
|
|
|
|
rv = InitSSPI();
|
|
|
|
if (NS_FAILED(rv))
|
|
|
|
return rv;
|
|
|
|
}
|
2008-08-27 21:44:54 +00:00
|
|
|
SEC_WCHAR *package;
|
2005-08-09 23:06:47 +00:00
|
|
|
|
2008-08-27 21:44:54 +00:00
|
|
|
package = (SEC_WCHAR *) pTypeName[(int)mPackage];
|
2009-12-18 01:34:32 +00:00
|
|
|
|
2013-01-22 16:59:01 +00:00
|
|
|
if (mPackage == PACKAGE_TYPE_NTLM) {
|
|
|
|
// (bug 535193) For NTLM, just use the uri host, do not do canonical host lookups.
|
|
|
|
// The incoming serviceName is in the format: "protocol@hostname", SSPI expects
|
|
|
|
// "<service class>/<hostname>", so swap the '@' for a '/'.
|
|
|
|
mServiceName.Assign(serviceName);
|
|
|
|
int32_t index = mServiceName.FindChar('@');
|
|
|
|
if (index == kNotFound)
|
|
|
|
return NS_ERROR_UNEXPECTED;
|
|
|
|
mServiceName.Replace(index, 1, '/');
|
|
|
|
}
|
|
|
|
else {
|
|
|
|
// Kerberos requires the canonical host, MakeSN takes care of this through a
|
|
|
|
// DNS lookup.
|
|
|
|
rv = MakeSN(serviceName, mServiceName);
|
|
|
|
if (NS_FAILED(rv))
|
|
|
|
return rv;
|
|
|
|
}
|
2009-11-04 22:12:24 +00:00
|
|
|
|
|
|
|
mServiceFlags = serviceFlags;
|
2005-08-09 23:06:47 +00:00
|
|
|
|
|
|
|
SECURITY_STATUS rc;
|
|
|
|
|
2008-08-27 21:44:54 +00:00
|
|
|
PSecPkgInfoW pinfo;
|
|
|
|
rc = (sspi->QuerySecurityPackageInfoW)(package, &pinfo);
|
2005-08-09 23:06:58 +00:00
|
|
|
if (rc != SEC_E_OK) {
|
|
|
|
LOG(("%s package not found\n", package));
|
|
|
|
return NS_ERROR_UNEXPECTED;
|
|
|
|
}
|
|
|
|
mMaxTokenLen = pinfo->cbMaxToken;
|
|
|
|
(sspi->FreeContextBuffer)(pinfo);
|
|
|
|
|
2013-07-25 16:54:11 +00:00
|
|
|
MS_TimeStamp useBefore;
|
2005-08-09 23:06:58 +00:00
|
|
|
|
2009-11-19 22:12:43 +00:00
|
|
|
SEC_WINNT_AUTH_IDENTITY_W ai;
|
2012-07-30 14:20:58 +00:00
|
|
|
SEC_WINNT_AUTH_IDENTITY_W *pai = nullptr;
|
2017-07-06 12:00:35 +00:00
|
|
|
|
2009-11-19 22:12:43 +00:00
|
|
|
// domain, username, and password will be null if nsHttpNTLMAuth's ChallengeReceived
|
|
|
|
// returns false for identityInvalid. Use default credentials in this case by passing
|
|
|
|
// null for pai.
|
|
|
|
if (username && password) {
|
2009-12-02 19:26:24 +00:00
|
|
|
// Keep a copy of these strings for the duration
|
|
|
|
mUsername.Assign(username);
|
|
|
|
mPassword.Assign(password);
|
|
|
|
mDomain.Assign(domain);
|
|
|
|
ai.Domain = reinterpret_cast<unsigned short*>(mDomain.BeginWriting());
|
|
|
|
ai.DomainLength = mDomain.Length();
|
|
|
|
ai.User = reinterpret_cast<unsigned short*>(mUsername.BeginWriting());
|
|
|
|
ai.UserLength = mUsername.Length();
|
|
|
|
ai.Password = reinterpret_cast<unsigned short*>(mPassword.BeginWriting());
|
|
|
|
ai.PasswordLength = mPassword.Length();
|
2009-11-19 22:12:43 +00:00
|
|
|
ai.Flags = SEC_WINNT_AUTH_IDENTITY_UNICODE;
|
|
|
|
pai = &ai;
|
|
|
|
}
|
|
|
|
|
2013-04-03 01:06:20 +00:00
|
|
|
rc = (sspi->AcquireCredentialsHandleW)(nullptr,
|
2008-09-05 19:09:06 +00:00
|
|
|
package,
|
|
|
|
SECPKG_CRED_OUTBOUND,
|
2013-04-03 01:06:20 +00:00
|
|
|
nullptr,
|
2009-11-19 22:12:43 +00:00
|
|
|
pai,
|
2013-04-03 01:06:20 +00:00
|
|
|
nullptr,
|
|
|
|
nullptr,
|
2008-09-05 19:09:06 +00:00
|
|
|
&mCred,
|
|
|
|
&useBefore);
|
2005-08-09 23:06:47 +00:00
|
|
|
if (rc != SEC_E_OK)
|
|
|
|
return NS_ERROR_UNEXPECTED;
|
2013-07-25 16:54:11 +00:00
|
|
|
|
|
|
|
static bool sTelemetrySent = false;
|
|
|
|
if (!sTelemetrySent) {
|
|
|
|
mozilla::Telemetry::Accumulate(
|
2013-10-10 17:10:45 +00:00
|
|
|
mozilla::Telemetry::NTLM_MODULE_USED_2,
|
|
|
|
serviceFlags & nsIAuthModule::REQ_PROXY_AUTH
|
2013-07-25 16:54:11 +00:00
|
|
|
? NTLM_MODULE_WIN_API_PROXY
|
|
|
|
: NTLM_MODULE_WIN_API_DIRECT);
|
|
|
|
sTelemetrySent = true;
|
|
|
|
}
|
|
|
|
|
2009-11-19 22:12:43 +00:00
|
|
|
LOG(("AcquireCredentialsHandle() succeeded.\n"));
|
2005-08-09 23:06:47 +00:00
|
|
|
return NS_OK;
|
|
|
|
}
|
|
|
|
|
2011-11-09 17:18:59 +00:00
|
|
|
// The arguments inToken and inTokenLen are used to pass in the server
|
|
|
|
// certificate (when available) in the first call of the function. The
|
2017-07-06 12:00:35 +00:00
|
|
|
// second time these arguments hold an input token.
|
2005-08-09 23:06:47 +00:00
|
|
|
NS_IMETHODIMP
|
2005-08-18 15:22:33 +00:00
|
|
|
nsAuthSSPI::GetNextToken(const void *inToken,
|
2012-08-22 15:56:38 +00:00
|
|
|
uint32_t inTokenLen,
|
2005-08-18 15:22:33 +00:00
|
|
|
void **outToken,
|
2012-08-22 15:56:38 +00:00
|
|
|
uint32_t *outTokenLen)
|
2005-08-09 23:06:47 +00:00
|
|
|
{
|
2011-11-09 17:18:59 +00:00
|
|
|
// String for end-point bindings.
|
2017-07-06 12:00:35 +00:00
|
|
|
const char end_point[] = "tls-server-end-point:";
|
2011-11-09 17:18:59 +00:00
|
|
|
const int end_point_length = sizeof(end_point) - 1;
|
|
|
|
const int hash_size = 32; // Size of a SHA256 hash.
|
|
|
|
const int cbt_size = hash_size + end_point_length;
|
2017-07-06 12:00:35 +00:00
|
|
|
|
2005-08-09 23:06:47 +00:00
|
|
|
SECURITY_STATUS rc;
|
2013-07-25 16:54:11 +00:00
|
|
|
MS_TimeStamp ignored;
|
2005-08-09 23:06:47 +00:00
|
|
|
|
|
|
|
DWORD ctxAttr, ctxReq = 0;
|
|
|
|
CtxtHandle *ctxIn;
|
|
|
|
SecBufferDesc ibd, obd;
|
2011-11-09 17:18:59 +00:00
|
|
|
// Optional second input buffer for the CBT (Channel Binding Token)
|
|
|
|
SecBuffer ib[2], ob;
|
|
|
|
// Pointer to the block of memory that stores the CBT
|
2012-07-30 14:20:58 +00:00
|
|
|
char* sspi_cbt = nullptr;
|
2011-11-09 17:18:59 +00:00
|
|
|
SEC_CHANNEL_BINDINGS pendpoint_binding;
|
2005-08-09 23:06:47 +00:00
|
|
|
|
2005-08-18 15:22:33 +00:00
|
|
|
LOG(("entering nsAuthSSPI::GetNextToken()\n"));
|
2005-08-09 23:06:47 +00:00
|
|
|
|
2009-12-16 20:11:51 +00:00
|
|
|
if (!mCred.dwLower && !mCred.dwUpper) {
|
2009-12-15 06:05:19 +00:00
|
|
|
LOG(("nsAuthSSPI::GetNextToken(), not initialized. exiting."));
|
|
|
|
return NS_ERROR_NOT_INITIALIZED;
|
|
|
|
}
|
|
|
|
|
2005-08-09 23:06:47 +00:00
|
|
|
if (mServiceFlags & REQ_DELEGATE)
|
|
|
|
ctxReq |= ISC_REQ_DELEGATE;
|
|
|
|
if (mServiceFlags & REQ_MUTUAL_AUTH)
|
|
|
|
ctxReq |= ISC_REQ_MUTUAL_AUTH;
|
|
|
|
|
|
|
|
if (inToken) {
|
2011-11-09 17:18:59 +00:00
|
|
|
if (mIsFirst) {
|
|
|
|
// First time if it comes with a token,
|
|
|
|
// the token represents the server certificate.
|
|
|
|
mIsFirst = false;
|
|
|
|
mCertDERLength = inTokenLen;
|
2015-03-27 00:01:12 +00:00
|
|
|
mCertDERData = moz_xmalloc(inTokenLen);
|
2011-11-09 17:18:59 +00:00
|
|
|
memcpy(mCertDERData, inToken, inTokenLen);
|
|
|
|
|
2017-07-06 12:00:35 +00:00
|
|
|
// We are starting a new authentication sequence.
|
2011-11-09 17:18:59 +00:00
|
|
|
// If we have already initialized our
|
|
|
|
// security context, then we're in trouble because it means that the
|
|
|
|
// first sequence failed. We need to bail or else we might end up in
|
|
|
|
// an infinite loop.
|
|
|
|
if (mCtxt.dwLower || mCtxt.dwUpper) {
|
|
|
|
LOG(("Cannot restart authentication sequence!"));
|
|
|
|
return NS_ERROR_UNEXPECTED;
|
|
|
|
}
|
2012-07-30 14:20:58 +00:00
|
|
|
ctxIn = nullptr;
|
2017-07-06 12:00:35 +00:00
|
|
|
// The certificate needs to be erased before being passed
|
2011-11-09 17:18:59 +00:00
|
|
|
// to InitializeSecurityContextW().
|
2012-07-30 14:20:58 +00:00
|
|
|
inToken = nullptr;
|
2011-11-09 17:18:59 +00:00
|
|
|
inTokenLen = 0;
|
|
|
|
} else {
|
|
|
|
ibd.ulVersion = SECBUFFER_VERSION;
|
|
|
|
ibd.cBuffers = 0;
|
|
|
|
ibd.pBuffers = ib;
|
2017-07-06 12:00:35 +00:00
|
|
|
|
2011-11-09 17:18:59 +00:00
|
|
|
// If we have stored a certificate, the Channel Binding Token
|
|
|
|
// needs to be generated and sent in the first input buffer.
|
|
|
|
if (mCertDERLength > 0) {
|
2017-07-06 12:00:35 +00:00
|
|
|
// First we create a proper Endpoint Binding structure.
|
2011-11-09 17:18:59 +00:00
|
|
|
pendpoint_binding.dwInitiatorAddrType = 0;
|
|
|
|
pendpoint_binding.cbInitiatorLength = 0;
|
|
|
|
pendpoint_binding.dwInitiatorOffset = 0;
|
|
|
|
pendpoint_binding.dwAcceptorAddrType = 0;
|
|
|
|
pendpoint_binding.cbAcceptorLength = 0;
|
|
|
|
pendpoint_binding.dwAcceptorOffset = 0;
|
|
|
|
pendpoint_binding.cbApplicationDataLength = cbt_size;
|
2017-07-06 12:00:35 +00:00
|
|
|
pendpoint_binding.dwApplicationDataOffset =
|
2011-11-09 17:18:59 +00:00
|
|
|
sizeof(SEC_CHANNEL_BINDINGS);
|
|
|
|
|
|
|
|
// Then add it to the array of sec buffers accordingly.
|
|
|
|
ib[ibd.cBuffers].BufferType = SECBUFFER_CHANNEL_BINDINGS;
|
|
|
|
ib[ibd.cBuffers].cbBuffer =
|
|
|
|
pendpoint_binding.cbApplicationDataLength
|
|
|
|
+ pendpoint_binding.dwApplicationDataOffset;
|
2017-07-06 12:00:35 +00:00
|
|
|
|
2015-03-27 00:01:12 +00:00
|
|
|
sspi_cbt = (char *) moz_xmalloc(ib[ibd.cBuffers].cbBuffer);
|
2011-11-09 17:18:59 +00:00
|
|
|
|
|
|
|
// Helper to write in the memory block that stores the CBT
|
|
|
|
char* sspi_cbt_ptr = sspi_cbt;
|
2017-07-06 12:00:35 +00:00
|
|
|
|
2011-11-09 17:18:59 +00:00
|
|
|
ib[ibd.cBuffers].pvBuffer = sspi_cbt;
|
|
|
|
ibd.cBuffers++;
|
|
|
|
|
|
|
|
memcpy(sspi_cbt_ptr, &pendpoint_binding,
|
|
|
|
pendpoint_binding.dwApplicationDataOffset);
|
|
|
|
sspi_cbt_ptr += pendpoint_binding.dwApplicationDataOffset;
|
|
|
|
|
|
|
|
memcpy(sspi_cbt_ptr, end_point, end_point_length);
|
|
|
|
sspi_cbt_ptr += end_point_length;
|
2017-07-06 12:00:35 +00:00
|
|
|
|
2011-11-09 17:18:59 +00:00
|
|
|
// Start hashing. We are always doing SHA256, but depending
|
|
|
|
// on the certificate, a different alogirthm might be needed.
|
2012-09-02 02:35:17 +00:00
|
|
|
nsAutoCString hashString;
|
2011-11-09 17:18:59 +00:00
|
|
|
|
|
|
|
nsresult rv;
|
|
|
|
nsCOMPtr<nsICryptoHash> crypto;
|
|
|
|
crypto = do_CreateInstance(NS_CRYPTO_HASH_CONTRACTID, &rv);
|
|
|
|
if (NS_SUCCEEDED(rv))
|
|
|
|
rv = crypto->Init(nsICryptoHash::SHA256);
|
|
|
|
if (NS_SUCCEEDED(rv))
|
|
|
|
rv = crypto->Update((unsigned char*)mCertDERData, mCertDERLength);
|
|
|
|
if (NS_SUCCEEDED(rv))
|
|
|
|
rv = crypto->Finish(false, hashString);
|
|
|
|
if (NS_FAILED(rv)) {
|
2015-03-27 00:01:12 +00:00
|
|
|
free(mCertDERData);
|
2012-07-30 14:20:58 +00:00
|
|
|
mCertDERData = nullptr;
|
2011-11-09 17:18:59 +00:00
|
|
|
mCertDERLength = 0;
|
2015-03-27 00:01:12 +00:00
|
|
|
free(sspi_cbt);
|
2011-11-09 17:18:59 +00:00
|
|
|
return rv;
|
|
|
|
}
|
2017-07-06 12:00:35 +00:00
|
|
|
|
2011-11-09 17:18:59 +00:00
|
|
|
// Once the hash has been computed, we store it in memory right
|
|
|
|
// after the Endpoint structure and the "tls-server-end-point:"
|
|
|
|
// char array.
|
|
|
|
memcpy(sspi_cbt_ptr, hashString.get(), hash_size);
|
2017-07-06 12:00:35 +00:00
|
|
|
|
2011-11-09 17:18:59 +00:00
|
|
|
// Free memory used to store the server certificate
|
2015-03-27 00:01:12 +00:00
|
|
|
free(mCertDERData);
|
2012-07-30 14:20:58 +00:00
|
|
|
mCertDERData = nullptr;
|
2011-11-09 17:18:59 +00:00
|
|
|
mCertDERLength = 0;
|
|
|
|
} // End of CBT computation.
|
|
|
|
|
|
|
|
// We always need this SECBUFFER.
|
|
|
|
ib[ibd.cBuffers].BufferType = SECBUFFER_TOKEN;
|
|
|
|
ib[ibd.cBuffers].cbBuffer = inTokenLen;
|
|
|
|
ib[ibd.cBuffers].pvBuffer = (void *) inToken;
|
|
|
|
ibd.cBuffers++;
|
|
|
|
ctxIn = &mCtxt;
|
|
|
|
}
|
|
|
|
} else { // First time and without a token (no server certificate)
|
2017-07-06 12:00:35 +00:00
|
|
|
// We are starting a new authentication sequence. If we have already
|
|
|
|
// initialized our security context, then we're in trouble because it
|
|
|
|
// means that the first sequence failed. We need to bail or else we
|
2011-11-09 17:18:59 +00:00
|
|
|
// might end up in an infinite loop.
|
|
|
|
if (mCtxt.dwLower || mCtxt.dwUpper || mCertDERData || mCertDERLength) {
|
2005-08-09 23:06:47 +00:00
|
|
|
LOG(("Cannot restart authentication sequence!"));
|
|
|
|
return NS_ERROR_UNEXPECTED;
|
|
|
|
}
|
2013-04-03 01:06:20 +00:00
|
|
|
ctxIn = nullptr;
|
2011-11-09 17:18:59 +00:00
|
|
|
mIsFirst = false;
|
2005-08-09 23:06:47 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
obd.ulVersion = SECBUFFER_VERSION;
|
|
|
|
obd.cBuffers = 1;
|
|
|
|
obd.pBuffers = &ob;
|
|
|
|
ob.BufferType = SECBUFFER_TOKEN;
|
2005-08-09 23:06:58 +00:00
|
|
|
ob.cbBuffer = mMaxTokenLen;
|
2015-03-27 00:01:12 +00:00
|
|
|
ob.pvBuffer = moz_xmalloc(ob.cbBuffer);
|
2005-08-09 23:06:47 +00:00
|
|
|
memset(ob.pvBuffer, 0, ob.cbBuffer);
|
2008-09-05 19:09:06 +00:00
|
|
|
|
|
|
|
NS_ConvertUTF8toUTF16 wSN(mServiceName);
|
2009-11-04 22:12:24 +00:00
|
|
|
SEC_WCHAR *sn = (SEC_WCHAR *) wSN.get();
|
2005-08-09 23:06:56 +00:00
|
|
|
|
2008-08-27 21:44:54 +00:00
|
|
|
rc = (sspi->InitializeSecurityContextW)(&mCred,
|
2008-09-05 19:09:06 +00:00
|
|
|
ctxIn,
|
|
|
|
sn,
|
|
|
|
ctxReq,
|
|
|
|
0,
|
|
|
|
SECURITY_NATIVE_DREP,
|
2013-04-03 01:06:20 +00:00
|
|
|
inToken ? &ibd : nullptr,
|
2008-09-05 19:09:06 +00:00
|
|
|
0,
|
|
|
|
&mCtxt,
|
|
|
|
&obd,
|
|
|
|
&ctxAttr,
|
|
|
|
&ignored);
|
2005-08-09 23:06:47 +00:00
|
|
|
if (rc == SEC_I_CONTINUE_NEEDED || rc == SEC_E_OK) {
|
2009-11-19 22:12:43 +00:00
|
|
|
|
|
|
|
if (rc == SEC_E_OK)
|
|
|
|
LOG(("InitializeSecurityContext: succeeded.\n"));
|
|
|
|
else
|
|
|
|
LOG(("InitializeSecurityContext: continue.\n"));
|
2015-05-14 17:13:24 +00:00
|
|
|
|
2011-11-09 17:18:59 +00:00
|
|
|
if (sspi_cbt)
|
2015-03-27 00:01:12 +00:00
|
|
|
free(sspi_cbt);
|
2017-07-06 12:00:35 +00:00
|
|
|
|
2006-03-07 02:38:31 +00:00
|
|
|
if (!ob.cbBuffer) {
|
2015-03-27 00:01:12 +00:00
|
|
|
free(ob.pvBuffer);
|
2013-04-03 01:06:20 +00:00
|
|
|
ob.pvBuffer = nullptr;
|
2006-03-07 02:38:31 +00:00
|
|
|
}
|
2005-08-09 23:06:47 +00:00
|
|
|
*outToken = ob.pvBuffer;
|
|
|
|
*outTokenLen = ob.cbBuffer;
|
2005-08-18 15:22:33 +00:00
|
|
|
|
|
|
|
if (rc == SEC_E_OK)
|
|
|
|
return NS_SUCCESS_AUTH_FINISHED;
|
|
|
|
|
2005-08-09 23:06:47 +00:00
|
|
|
return NS_OK;
|
|
|
|
}
|
|
|
|
|
|
|
|
LOG(("InitializeSecurityContext failed [rc=%d:%s]\n", rc, MapErrorCode(rc)));
|
|
|
|
Reset();
|
2015-03-27 00:01:12 +00:00
|
|
|
free(ob.pvBuffer);
|
2005-08-09 23:06:47 +00:00
|
|
|
return NS_ERROR_FAILURE;
|
|
|
|
}
|
2005-08-18 15:22:33 +00:00
|
|
|
|
|
|
|
NS_IMETHODIMP
|
|
|
|
nsAuthSSPI::Unwrap(const void *inToken,
|
2012-08-22 15:56:38 +00:00
|
|
|
uint32_t inTokenLen,
|
2005-08-18 15:22:33 +00:00
|
|
|
void **outToken,
|
2012-08-22 15:56:38 +00:00
|
|
|
uint32_t *outTokenLen)
|
2005-08-18 15:22:33 +00:00
|
|
|
{
|
|
|
|
SECURITY_STATUS rc;
|
|
|
|
SecBufferDesc ibd;
|
|
|
|
SecBuffer ib[2];
|
|
|
|
|
|
|
|
ibd.cBuffers = 2;
|
|
|
|
ibd.pBuffers = ib;
|
2017-07-06 12:00:35 +00:00
|
|
|
ibd.ulVersion = SECBUFFER_VERSION;
|
2005-08-18 15:22:33 +00:00
|
|
|
|
|
|
|
// SSPI Buf
|
|
|
|
ib[0].BufferType = SECBUFFER_STREAM;
|
|
|
|
ib[0].cbBuffer = inTokenLen;
|
2015-03-27 00:01:12 +00:00
|
|
|
ib[0].pvBuffer = moz_xmalloc(ib[0].cbBuffer);
|
2017-07-06 12:00:35 +00:00
|
|
|
|
2005-08-18 15:22:33 +00:00
|
|
|
memcpy(ib[0].pvBuffer, inToken, inTokenLen);
|
|
|
|
|
|
|
|
// app data
|
|
|
|
ib[1].BufferType = SECBUFFER_DATA;
|
|
|
|
ib[1].cbBuffer = 0;
|
2013-04-03 01:06:20 +00:00
|
|
|
ib[1].pvBuffer = nullptr;
|
2005-08-18 15:22:33 +00:00
|
|
|
|
|
|
|
rc = (sspi->DecryptMessage)(
|
|
|
|
&mCtxt,
|
|
|
|
&ibd,
|
|
|
|
0, // no sequence numbers
|
2013-04-03 01:06:20 +00:00
|
|
|
nullptr
|
2005-08-18 15:22:33 +00:00
|
|
|
);
|
|
|
|
|
|
|
|
if (SEC_SUCCESS(rc)) {
|
2009-09-07 14:30:58 +00:00
|
|
|
// check if ib[1].pvBuffer is really just ib[0].pvBuffer, in which
|
|
|
|
// case we can let the caller free it. Otherwise, we need to
|
|
|
|
// clone it, and free the original
|
|
|
|
if (ib[0].pvBuffer == ib[1].pvBuffer) {
|
|
|
|
*outToken = ib[1].pvBuffer;
|
|
|
|
}
|
|
|
|
else {
|
2018-08-28 05:59:19 +00:00
|
|
|
*outToken = moz_xmemdup(ib[1].pvBuffer, ib[1].cbBuffer);
|
2015-03-27 00:01:12 +00:00
|
|
|
free(ib[0].pvBuffer);
|
2009-09-07 14:30:58 +00:00
|
|
|
}
|
2005-08-18 15:22:33 +00:00
|
|
|
*outTokenLen = ib[1].cbBuffer;
|
|
|
|
}
|
|
|
|
else
|
2015-03-27 00:01:12 +00:00
|
|
|
free(ib[0].pvBuffer);
|
2005-08-18 15:22:33 +00:00
|
|
|
|
2006-01-25 20:26:08 +00:00
|
|
|
if (!SEC_SUCCESS(rc))
|
|
|
|
return NS_ERROR_FAILURE;
|
|
|
|
|
|
|
|
return NS_OK;
|
2005-08-18 15:22:33 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// utility class used to free memory on exit
|
|
|
|
class secBuffers
|
|
|
|
{
|
|
|
|
public:
|
|
|
|
|
|
|
|
SecBuffer ib[3];
|
|
|
|
|
|
|
|
secBuffers() { memset(&ib, 0, sizeof(ib)); }
|
|
|
|
|
2017-07-06 12:00:35 +00:00
|
|
|
~secBuffers()
|
2005-08-18 15:22:33 +00:00
|
|
|
{
|
|
|
|
if (ib[0].pvBuffer)
|
2015-03-27 00:01:12 +00:00
|
|
|
free(ib[0].pvBuffer);
|
2005-08-18 15:22:33 +00:00
|
|
|
|
|
|
|
if (ib[1].pvBuffer)
|
2015-03-27 00:01:12 +00:00
|
|
|
free(ib[1].pvBuffer);
|
2005-08-18 15:22:33 +00:00
|
|
|
|
|
|
|
if (ib[2].pvBuffer)
|
2015-03-27 00:01:12 +00:00
|
|
|
free(ib[2].pvBuffer);
|
2005-08-18 15:22:33 +00:00
|
|
|
}
|
|
|
|
};
|
|
|
|
|
|
|
|
NS_IMETHODIMP
|
|
|
|
nsAuthSSPI::Wrap(const void *inToken,
|
2012-08-22 15:56:38 +00:00
|
|
|
uint32_t inTokenLen,
|
2011-09-29 06:19:26 +00:00
|
|
|
bool confidential,
|
2005-08-18 15:22:33 +00:00
|
|
|
void **outToken,
|
2012-08-22 15:56:38 +00:00
|
|
|
uint32_t *outTokenLen)
|
2005-08-18 15:22:33 +00:00
|
|
|
{
|
|
|
|
SECURITY_STATUS rc;
|
|
|
|
|
|
|
|
SecBufferDesc ibd;
|
|
|
|
secBuffers bufs;
|
|
|
|
SecPkgContext_Sizes sizes;
|
|
|
|
|
2008-08-27 21:44:54 +00:00
|
|
|
rc = (sspi->QueryContextAttributesW)(
|
2005-08-18 15:22:33 +00:00
|
|
|
&mCtxt,
|
|
|
|
SECPKG_ATTR_SIZES,
|
|
|
|
&sizes);
|
|
|
|
|
2017-07-06 12:00:35 +00:00
|
|
|
if (!SEC_SUCCESS(rc))
|
2006-01-25 20:26:08 +00:00
|
|
|
return NS_ERROR_FAILURE;
|
2017-07-06 12:00:35 +00:00
|
|
|
|
2005-08-18 15:22:33 +00:00
|
|
|
ibd.cBuffers = 3;
|
|
|
|
ibd.pBuffers = bufs.ib;
|
|
|
|
ibd.ulVersion = SECBUFFER_VERSION;
|
2017-07-06 12:00:35 +00:00
|
|
|
|
2005-08-18 15:22:33 +00:00
|
|
|
// SSPI
|
|
|
|
bufs.ib[0].cbBuffer = sizes.cbSecurityTrailer;
|
|
|
|
bufs.ib[0].BufferType = SECBUFFER_TOKEN;
|
2015-03-27 00:01:12 +00:00
|
|
|
bufs.ib[0].pvBuffer = moz_xmalloc(sizes.cbSecurityTrailer);
|
2005-08-18 15:22:33 +00:00
|
|
|
|
|
|
|
// APP Data
|
|
|
|
bufs.ib[1].BufferType = SECBUFFER_DATA;
|
2015-03-27 00:01:12 +00:00
|
|
|
bufs.ib[1].pvBuffer = moz_xmalloc(inTokenLen);
|
2005-08-18 15:22:33 +00:00
|
|
|
bufs.ib[1].cbBuffer = inTokenLen;
|
2017-07-06 12:00:35 +00:00
|
|
|
|
2005-08-18 15:22:33 +00:00
|
|
|
memcpy(bufs.ib[1].pvBuffer, inToken, inTokenLen);
|
|
|
|
|
|
|
|
// SSPI
|
|
|
|
bufs.ib[2].BufferType = SECBUFFER_PADDING;
|
|
|
|
bufs.ib[2].cbBuffer = sizes.cbBlockSize;
|
2015-03-27 00:01:12 +00:00
|
|
|
bufs.ib[2].pvBuffer = moz_xmalloc(bufs.ib[2].cbBuffer);
|
2005-08-18 15:22:33 +00:00
|
|
|
|
|
|
|
rc = (sspi->EncryptMessage)(&mCtxt,
|
|
|
|
confidential ? 0 : KERB_WRAP_NO_ENCRYPT,
|
|
|
|
&ibd, 0);
|
|
|
|
|
|
|
|
if (SEC_SUCCESS(rc)) {
|
|
|
|
int len = bufs.ib[0].cbBuffer + bufs.ib[1].cbBuffer + bufs.ib[2].cbBuffer;
|
2015-03-27 00:01:12 +00:00
|
|
|
char *p = (char *) moz_xmalloc(len);
|
2005-08-18 15:22:33 +00:00
|
|
|
|
2006-03-07 02:38:31 +00:00
|
|
|
*outToken = (void *) p;
|
|
|
|
*outTokenLen = len;
|
2005-08-18 15:22:33 +00:00
|
|
|
|
2006-03-07 02:38:31 +00:00
|
|
|
memcpy(p, bufs.ib[0].pvBuffer, bufs.ib[0].cbBuffer);
|
|
|
|
p += bufs.ib[0].cbBuffer;
|
2005-08-18 15:22:33 +00:00
|
|
|
|
2006-03-07 02:38:31 +00:00
|
|
|
memcpy(p,bufs.ib[1].pvBuffer, bufs.ib[1].cbBuffer);
|
|
|
|
p += bufs.ib[1].cbBuffer;
|
2006-01-25 20:26:08 +00:00
|
|
|
|
2006-03-07 02:38:31 +00:00
|
|
|
memcpy(p,bufs.ib[2].pvBuffer, bufs.ib[2].cbBuffer);
|
2017-07-06 12:00:35 +00:00
|
|
|
|
2006-01-25 20:26:08 +00:00
|
|
|
return NS_OK;
|
2005-08-18 15:22:33 +00:00
|
|
|
}
|
|
|
|
|
2006-01-25 20:26:08 +00:00
|
|
|
return NS_ERROR_FAILURE;
|
2005-08-18 15:22:33 +00:00
|
|
|
}
|