/[winpt]/trunk/Src/wptKeyserver.cpp
ViewVC logotype

Annotation of /trunk/Src/wptKeyserver.cpp

Parent Directory Parent Directory | Revision Log Revision Log


Revision 36 - (hide annotations)
Thu Oct 27 15:25:13 2005 UTC (19 years, 4 months ago) by werner
File size: 31105 byte(s)
First set of changes to use autotools for building.
1 werner 36 /* wptKeyserver.cpp - W32 Keyserver Access
2     * Copyright (C) 2000-2005 Timo Schulz
3     * Copyright (C) 2001 Marco Cunha
4     *
5     * This file is part of WinPT.
6     *
7     * WinPT is free software; you can redistribute it and/or
8     * modify it under the terms of the GNU General Public License
9     * as published by the Free Software Foundation; either version 2
10     * of the License, or (at your option) any later version.
11     *
12     * WinPT is distributed in the hope that it will be useful,
13     * but WITHOUT ANY WARRANTY; without even the implied warranty of
14     * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15     * General Public License for more details.
16     *
17     * You should have received a copy of the GNU General Public License
18     * along with WinPT; if not, write to the Free Software Foundation,
19     * Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
20     */
21    
22     #ifdef HAVE_CONFIG_H
23     #include <config.h>
24     #endif
25    
26     #include <windows.h>
27     #include <windows.h>
28     #include <stdio.h>
29     #include <sys/stat.h>
30     #include <ctype.h>
31    
32     #include "wptKeyserver.h"
33     #include "wptErrors.h"
34     #include "wptTypes.h"
35     #include "wptNLS.h"
36     #include "wptW32API.h"
37     #include "wptVersion.h"
38     #include "wptGPG.h"
39     #include "wptRegistry.h"
40    
41     static char base64code[] =
42     "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
43    
44     keyserver server[MAX_KEYSERVERS] = {0};
45     static keyserver_proxy_ctx proxy = {0};
46     static const char * server_list[] = {
47     "hkp://wwwkeys.nl.pgp.net",
48     "hkp://wwwkeys.pl.pgp.net",
49     "hkp://wwwkeys.at.pgp.net",
50     "hkp://wwwkeys.ch.pgp.net",
51     "hkp://wwwkeys.de.pgp.net",
52     "hkp://wwwkeys.dk.pgp.net",
53     "hkp://wwwkeys.cz.pgp.net",
54     "hkp://wwwkeys.es.pgp.net",
55     "hkp://wwwkeys.eu.pgp.net",
56     "hkp://wwwkeys.uk.pgp.net",
57     "hkp://wwwkeys.us.pgp.net",
58     "hkp://gnv.us.ks.cryptnet.net",
59     "hkp://subkeys.pgp.net",
60     "ldap://keyserver.pgp.com",
61     NULL
62     };
63     static char hkp_errmsg[1024];
64     static int hkp_err = 0;
65     static u32 conf_timestamp = 0;
66     char * default_keyserver = NULL;
67     unsigned short default_keyserver_port = 0;
68    
69    
70     static void
71     base64_encode( const char *inputstr, char *outputstr, int maxlen )
72     {
73     int index = 0, temp = 0, res = 0, i = 0, inputlen = 0, len = 0;
74    
75     inputlen = strlen (inputstr); /* fixme: check if len > maxlen */
76     for (i = 0; i <inputlen; i++) {
77     res = temp;
78     res = (res << 8) | (inputstr[i] & 0xFF);
79     switch (index++) {
80     case 0: outputstr[len++] = base64code[res >> 2 & 0x3F]; res &= 0x3; break;
81     case 1: outputstr[len++] = base64code[res >> 4 & 0x3F]; res &= 0xF; break;
82     case 2: outputstr[len++] = base64code[res >> 6 & 0x3F];
83     outputstr[len++] = base64code[res & 0x3F]; res = index = 0; break;
84     }
85     temp = res;
86     }
87    
88     switch( index ) {
89     case 0: break;
90     case 2: outputstr[len++] = base64code[temp << 2 & 0x3F];
91     outputstr[len++] = '='; break;
92     case 1: outputstr[len++] = base64code[temp << 4 & 0x3F];
93     outputstr[len++] = '=';
94     outputstr[len++] = '=';
95     }
96    
97     outputstr[len] = '\0';
98     } /* base64_encode */
99    
100    
101     /* Skip the URL schema and return only the host part of it. */
102     static const char *
103     skip_type_prefix (const char * hostname)
104     {
105     if (hostname && !strncmp (hostname, "http://", 7))
106     hostname += 7;
107     else if (hostname && !strncmp (hostname, "hkp://", 6))
108     hostname += 6;
109     else if (hostname && !strncmp (hostname, "finger://", 9))
110     hostname += 9;
111     else if (hostname && !strncmp (hostname, "ldap://", 7))
112     hostname += 7;
113     return hostname;
114     }
115    
116    
117     /* Check that the keyserver response indicates an OK.
118     Return 0 on success. */
119     static int
120     check_hkp_response (const char *resp, int recv)
121     {
122     int ec, len;
123     char *p, * end;
124    
125     ec = recv ? WPTERR_WINSOCK_RECVKEY : WPTERR_WINSOCK_SENDKEY;
126     if (!strstr (resp, "HTTP/1.0 200 OK") &&
127     !strstr (resp, "HTTP/1.1 200 OK")) /* http error */
128     return ec;
129     if (strstr (resp, "Public Key Server -- Error")
130     || strstr (resp, "Public Key Server -- Error")
131     || strstr (resp, "No matching keys in database")) {
132     p = strstr (resp, "<p>");
133     if (p && strlen (p) < sizeof (hkp_errmsg)) {
134     end = strstr (p, "</p>");
135     len = end? (end - p + 1) : strlen (p);
136     strncpy (hkp_errmsg, p, len);
137     hkp_err = 1;
138     }
139     return ec;
140     }
141     return 0;
142     }
143    
144    
145     /* Read a single line (\r\n) from a socket.
146     Return 0 on success. */
147     static int
148     sock_getline (int fd, char *buf, int buflen, int *nbytes)
149     {
150     char ch;
151     int count = 0;
152    
153     if (nbytes)
154     *nbytes = 0;
155     *buf = 0;
156     while (recv (fd, &ch, 1, 0) > 0) {
157     *buf++ = ch;
158     count++;
159     if (ch == '\n' || count == (buflen - 1)) {
160     *buf = 0;
161     if (nbytes)
162     *nbytes = count;
163     return 0;
164     }
165     }
166    
167     return -1;
168     }
169    
170    
171     /* Perform a select() on the given fd to find out
172     is there is data for reading. Wait at least @nsecs seconds. */
173     static int
174     sock_select (int fd, int nsecs)
175     {
176     FD_SET rfd;
177     timeval tv = {nsecs, 0};
178    
179     FD_ZERO (&rfd);
180     FD_SET (fd, &rfd);
181     if (select (fd + 1, &rfd, NULL, NULL, &tv) == SOCKET_ERROR)
182     return SOCKET_ERROR;
183     if (FD_ISSET (fd, &rfd))
184     return 1;
185     return 0;
186     }
187    
188    
189     /* Read from a socket with a fixed timeout of 10 seconds.
190     Return value: 0 on success. */
191     static int
192     sock_read (int fd, char *buf, int buflen, int *nbytes)
193     {
194     DWORD nread;
195     int nleft = buflen;
196     int rc, n = 0;
197    
198     while (nleft > 0) {
199     if (n >= 10)
200     return WPTERR_WINSOCK_TIMEOUT;
201     rc = sock_select (fd, 1);
202     if (rc == SOCKET_ERROR)
203     return SOCKET_ERROR;
204     else if( !rc )
205     n++;
206     else {
207     nread = recv (fd, buf, nleft, 0);
208     if (nread == SOCKET_ERROR)
209     return SOCKET_ERROR;
210     else if (!nread)
211     break;
212     nleft -= nread;
213     buf += nread;
214     }
215     }
216     if (nbytes)
217     *nbytes = buflen - nleft;
218    
219     return 0;
220     }
221    
222    
223     /* Write @buf to a socket @fd. */
224     static int
225     sock_write (int fd, const char *buf, int buflen)
226     {
227     DWORD nwritten;
228     int nleft = buflen;
229    
230     while (nleft > 0) {
231     nwritten = send (fd, buf, nleft, 0);
232     if (nwritten == SOCKET_ERROR)
233     return SOCKET_ERROR;
234     nleft -= nwritten;
235     buf += nwritten;
236     }
237    
238     return 0;
239     }
240    
241    
242     void
243     set_default_kserver (void)
244     {
245     char * p = get_reg_entry_keyserver ("Default");
246     free_if_alloc (default_keyserver);
247     default_keyserver = p && *p != ' ' ? p : m_strdup (DEF_HKP_KEYSERVER);
248     p = get_reg_entry_keyserver ("Default_Port");
249     if (p && *p) {
250     default_keyserver_port = (u16)strtoul (p, NULL, 10);
251     free_if_alloc (p);
252     }
253     else
254     default_keyserver_port = HKP_PORT;
255     }
256    
257    
258     /* Initialize the Winsock2 interface.*/
259     int
260     wsock_init (void)
261     {
262     WSADATA wsa;
263    
264     if (WSAStartup (0x202, &wsa))
265     return WPTERR_WINSOCK_INIT;
266     set_default_kserver ();
267     return 0;
268     }
269    
270    
271     /* Cleanup the Winsock2 interface. */
272     void
273     wsock_end (void)
274     {
275     int i;
276    
277     free_if_alloc (default_keyserver);
278     default_keyserver = NULL;
279     for (i=0; i < MAX_KEYSERVERS; i++) {
280     if (server[i].used)
281     free_if_alloc (server[i].name);
282     }
283     WSACleanup ();
284     }
285    
286    
287     /* Return a string representation of a winsock error. */
288     const char*
289     wsock_strerror (void)
290     {
291     static char buf[384];
292     int ec = WSAGetLastError ();
293    
294     switch (ec) {
295     case WSAENETDOWN:
296     return _("The network subsystem has failed");
297     case WSAHOST_NOT_FOUND:
298     return _("Authoritative Answer Host not found");
299     case WSAETIMEDOUT:
300     return _("The connection has been dropped because of a network failure");
301     default:
302     _snprintf (buf, sizeof (buf) -1, _("Unknown Winsock error ec=%d"),ec);
303     return buf;
304     }
305     return NULL;
306     }
307    
308    
309     /* Return the last keyserver error as a string. */
310     const char*
311     kserver_strerror (void)
312     {
313     if (hkp_err)
314     return hkp_errmsg;
315     return NULL;
316     }
317    
318    
319     /* Read a keyserver from the list at index @idx.
320     Return value: keyserver name at the given position. */
321     const char*
322     kserver_get_hostname (int idx, int type, u16 *port)
323     {
324     if (type == -1) {
325     *port = default_keyserver_port;
326     return default_keyserver;
327     }
328     else if (!type && idx < DIM (server_list)) {
329     *port = HKP_PORT;
330     return server_list[idx];
331     }
332     return NULL;
333     }
334    
335    
336     /* Check if the computer is connected to the internet.
337     Return 0 on success -1 otherwise. */
338     int
339     kserver_check_inet_connection (void)
340     {
341     int fd;
342    
343     if (!kserver_connect (default_keyserver, default_keyserver_port, &fd)) {
344     closesocket (fd);
345     return 0;
346     }
347     return -1;
348     }
349    
350    
351     /*
352     * If the request contains the keyid, it have to be
353     * always postfix with '0x'+keyid. This code checks
354     * if the keyid is a decimal value and if so if it contains
355     * the '0x'. If not it is inserted.
356     */
357     const char*
358     kserver_check_keyid (const char *keyid)
359     {
360     static char id[20];
361    
362     if (strstr (keyid, "@"))
363     return keyid; /* email address */
364     if (strncmp (keyid, "0x", 2)) {
365     memset (&id, 0, sizeof (id));
366     _snprintf (id, sizeof (id)-1, "0x%s", keyid);
367     return id;
368     }
369     return keyid;
370     } /* kserver_check_keyid */
371    
372    
373     static void
374     kserver_update_proxyuser (const char *proxy_user, const char *proxy_pass)
375     {
376     char t[257]; /* user:pass = 127+1+127+1 = 257 */
377     int n = 0;
378    
379     n = 4*strlen (proxy_user) / 3 + 32 + strlen (proxy_pass) + 2;
380     free_if_alloc (proxy.base64_user);
381     proxy.base64_user = new char[n];
382     if (!proxy.base64_user)
383     BUG (0);
384     _snprintf (t, sizeof (t)-1, "%s:%s", proxy_user, proxy_pass);
385     base64_encode (t, proxy.base64_user, 257);
386     free_if_alloc (proxy.user);
387     free_if_alloc (proxy.pass);
388     proxy.user = m_strdup (proxy_user);
389     proxy.pass = m_strdup (proxy_pass);
390     } /* kserver_update_proxyuser */
391    
392    
393     /* Check that the given buffer contains a valid keyserver URL. */
394     static int
395     check_URL (const char * buf)
396     {
397     if (strlen (buf) < 7)
398     return -1;
399     if (!strstr (buf, "ldap://")
400     && !strstr (buf, "http://")
401     && !strstr (buf, "finger://")
402     && !strstr (buf, "hkp://"))
403     return -1;
404     return 0;
405     }
406    
407    
408     /* Get the port number from the given protocol. */
409     static int
410     port_from_proto (int proto)
411     {
412     switch (proto) {
413     case KSPROTO_LDAP: return 0;
414     case KSPROTO_FINGER: return FINGER_PORT;
415     case KSPROTO_HTTP: return HKP_PORT;
416     }
417     return 0;
418     }
419    
420    
421     /* Get the port number from the given URL. */
422     static int
423     proto_from_URL (const char * buf)
424     {
425     if (strstr( buf, "ldap"))
426     return KSPROTO_LDAP;
427     else if (strstr( buf, "finger"))
428     return KSPROTO_FINGER;
429     return KSPROTO_HKP;
430     }
431    
432    
433     void
434     keyserver_set_default (const char * hostname, u16 port)
435     {
436     if (hostname) {
437     free_if_alloc (default_keyserver);
438     default_keyserver = m_strdup (hostname);
439     if (!default_keyserver)
440     BUG (0);
441     default_keyserver_port = port;
442     }
443     server[0].name = m_strdup (default_keyserver);
444     server[0].used = 1;
445     server[0].port = port;
446     server[0].proto = proto_from_URL (default_keyserver);
447     } /* keyserver_set_default */
448    
449    
450     static const char *
451     skip_whitespace (const char * str)
452     {
453     while (str && *str)
454     {
455     if (*str == ' ' ||
456     *str == '\t' ||
457     *str == '\n' ||
458     *str == '\r')
459     {
460     str++;
461     continue;
462     }
463     break;
464     }
465     return str;
466     }
467    
468    
469     int
470     kserver_load_conf (const char * conf)
471     {
472     struct stat statbuf;
473     FILE *fp;
474     char buf[1024], * s, * p;
475     char *user = NULL, *pass = NULL;
476     int pos, proxy_auth = 0;
477     int no_config=0, chk_pos=0;
478    
479     for (pos = 0; pos < MAX_KEYSERVERS; pos++) {
480     server[pos].used = 0;
481     server[pos].port = HKP_PORT;
482     }
483    
484     fp = fopen (conf, "rb");
485     if (!fp) {
486     for (pos = 0; server_list[pos]; pos++) {
487     server[pos].used = 1;
488     server[pos].name = m_strdup (server_list[pos]);
489     server[pos].proto = proto_from_URL (server_list[pos]);
490     }
491     no_config=1;
492     }
493     get_reg_proxy_prefs (&proxy.host, &proxy.port, &user, &pass);
494     if (user && pass)
495     kserver_update_proxyuser (user, pass);
496     else if (user && !pass || !user && pass) {
497     msg_box( NULL, _("Invalid proxy configuration."
498     "You need to set a user and a password"
499     "to use proxy authentication!"), _("Proxy Error"), MB_ERR );
500     }
501     /* check if the host has a http:// prefix and skip it */
502     if( proxy.host && !strncmp( proxy.host, "http://", 7 ) ) {
503     const char *s = proxy.host+7;
504     char * p = m_strdup (s);
505     if (!p)
506     BUG (0);
507     free_if_alloc (proxy.host);
508     proxy.host = p;
509     }
510     free_if_alloc (user);
511     free_if_alloc (pass);
512    
513     pos = 0;
514     while( fp && !feof( fp ) ) {
515     s = fgets (buf, sizeof (buf)-1, fp);
516     if (!s)
517     break;
518     if (strstr (buf, "\r\n"))
519     buf[strlen (buf)-2] = '\0';
520     if (strstr (buf, "\n"))
521     buf[strlen (buf)-1] = '\0';
522     s = (char *)skip_whitespace (buf);
523     if (*s == '#' || strlen (s) < 7)
524     continue;
525     if (check_URL (s)) {
526     msg_box (NULL, _("All entries of this file must have a valid prefix.\n"
527     "Currently HKP/HTTP, LDAP and FINGER are supported.\n"),
528     _("Keyserver Error"), MB_ERR);
529     continue;
530     }
531     chk_pos=6;
532     if (strstr (s, "finger"))
533     chk_pos = 10;
534     p = strchr (s+chk_pos, ':');
535     server[pos].used = 1;
536     server[pos].proto = proto_from_URL (s);
537     server[pos].port = port_from_proto (server[pos].proto);
538     if (!p)
539     server[pos].name = m_strdup (s);
540     else {
541     server[pos].port = atol (p+1);
542     if (server[pos].port < 0 || server[pos].port > 65536)
543     server[pos].port = HKP_PORT;
544     server[pos].name = new char [(p-s)+2];
545     if (!server[pos].name)
546     BUG (0);
547     memset (server[pos].name, 0, (p-s)+2);
548     memcpy (server[pos].name, s, (p-s));
549     }
550     pos++;
551     if (pos > MAX_KEYSERVERS)
552     {
553     msg_box (NULL, _("The keyserver limit is exceeded"), _("Keyserver Warning"), MB_INFO);
554     break;
555     }
556     }
557     if (fp)
558     fclose (fp);
559     if (!pos)
560     {
561     /* only issue an error if the config file exist but it has no valid entries. */
562     keyserver_set_default (NULL, HKP_PORT);
563     if (!no_config)
564     return WPTERR_CONFIG_FILE;
565     }
566    
567     if (!stat (conf, &statbuf))
568     conf_timestamp = statbuf.st_mtime;
569     return 0;
570     } /* kserver_load_conf */
571    
572    
573     const char *
574     kserver_get_proxy (int * r_port)
575     {
576     if (proxy.host) {
577     if (r_port)
578     *r_port = proxy.port;
579     return proxy.host;
580     }
581     return NULL;
582     } /* kserver_get_proxy */
583    
584    
585     const char *
586     kserver_get_proxy_info (int id)
587     {
588     switch (id) {
589     case PROXY_USER: return proxy.user;
590     case PROXY_PASS: return proxy.pass;
591     }
592     return NULL;
593     } /* kserver_get_proxy_info */
594    
595    
596     /* Connect to the keyserver @hostname. */
597     int
598     kserver_connect (const char *hostname, u16 port, int *conn_fd)
599     {
600     int rc, fd;
601     u32 iaddr;
602     char host[128] = {0};
603     struct hostent *hp;
604     struct sockaddr_in sock;
605    
606     log_debug ("kserver_connect: %s:%d\r\n", hostname, port);
607    
608     if (!port)
609     port = HKP_PORT;
610     if (conn_fd)
611     *conn_fd = 0;
612     hostname = skip_type_prefix (hostname);
613    
614     memset (&sock, 0, sizeof (sock));
615     sock.sin_family = AF_INET;
616     sock.sin_port = proxy.host? htons (proxy.port) : htons (port);
617     if (proxy.host)
618     strncpy (host, proxy.host, 127);
619     else
620     strncpy (host, hostname, 127);
621    
622     if ((iaddr = inet_addr (host)) != INADDR_NONE)
623     memcpy (&sock.sin_addr, &iaddr, sizeof (iaddr));
624     else if ((hp = gethostbyname (host))) {
625     if (hp->h_addrtype != AF_INET || hp->h_length != 4) {
626     log_debug ("gethostbyname: unknown address type.\r\n");
627     return WPTERR_WINSOCK_RESOLVE;
628     }
629     memcpy (&sock.sin_addr, hp->h_addr, hp->h_length);
630     }
631     else {
632     log_debug ("gethostbyname: failed.\r\n");
633     return WPTERR_WINSOCK_RESOLVE;
634     }
635     fd = socket (AF_INET, SOCK_STREAM, 0);
636     if (fd == INVALID_SOCKET)
637     return WPTERR_WINSOCK_SOCKET;
638     rc = connect (fd, (struct sockaddr *) &sock, sizeof (sock));
639     if (rc == SOCKET_ERROR) {
640     log_debug ("connect: failed.\r\n");
641     closesocket (fd);
642     return WPTERR_WINSOCK_CONNECT;
643     }
644    
645     if (conn_fd)
646     *conn_fd = fd;
647     WSASetLastError (0);
648     return 0;
649     } /* kserver_connect */
650    
651    
652     /* Perform URL-encoding on the given pubkey blob. */
653     static char*
654     kserver_urlencode (const char *pubkey, size_t octets, size_t *newlen)
655     {
656     char *p, numbuf[5];
657     size_t j = 0;
658     size_t i, size;
659    
660     p = new char [2*octets];
661     if (!p)
662     BUG (0);
663    
664     for (size=0, i=0; i < octets; i++) {
665     if (isalnum (pubkey[i]) || pubkey[i] == '-') {
666     p[size] = pubkey[i];
667     size++;
668     }
669     else if (pubkey[i] == ' ') {
670     p[size] = '+';
671     size++;
672     }
673     else {
674     sprintf(numbuf, "%%%02X", pubkey[i]);
675     for (j = 0; j<strlen(numbuf); j++) {
676     p[size] = numbuf[j];
677     size++;
678     }
679     }
680     }
681     p[size] = '\0';
682     *newlen = size;
683     return p;
684     }
685    
686    
687     /* Format a request for the given keyid (send). */
688     static char*
689     kserver_send_request (const char *hostname, u16 port, const char *pubkey, int octets)
690     {
691     char *request = NULL, *enc_pubkey = NULL;
692     int reqlen;
693     size_t enc_octets;
694    
695     log_debug ("kserver_send_request: %s:%d\n", hostname, port);
696    
697     if (!port)
698     port = HKP_PORT;
699     reqlen = 512 + strlen (hostname) + 2*strlen (pubkey);
700     request = new char[reqlen];
701     if (!request)
702     BUG (0);
703     enc_pubkey = kserver_urlencode (pubkey, octets, &enc_octets);
704     if (!enc_pubkey || !enc_octets) {
705     free_if_alloc (request);
706     return NULL;
707     }
708    
709     if (proxy.user) {
710     _snprintf (request, reqlen-1,
711     "POST http://%s:%d/pks/add HTTP/1.0\r\n"
712     "Referer: \r\n"
713     "User-Agent: WinPT/W32\r\n"
714     "Host: %s:%d\r\n"
715     "Proxy-Authorization: Basic %s\r\n"
716     "Content-type: application/x-www-form-urlencoded\r\n"
717     "Content-length: %d\r\n"
718     "\r\n"
719     "keytext=%s"
720     "\n",
721     skip_type_prefix (hostname), port, hostname, port,
722     proxy.base64_user, enc_octets+9, enc_pubkey);
723     }
724     else {
725     _snprintf (request, reqlen-1,
726     "POST /pks/add HTTP/1.0\r\n"
727     "Referer: \r\n"
728     "User-Agent: WinPT/W32\r\n"
729     "Host: %s:%d\r\n"
730     "Content-type: application/x-www-form-urlencoded\r\n"
731     "Content-length: %d\r\n"
732     "\r\n"
733     "keytext=%s"
734     "\n",
735     skip_type_prefix (hostname), port, enc_octets+9, enc_pubkey);
736     }
737     free_if_alloc (enc_pubkey);
738    
739     log_debug ("%s\n", request);
740     return request;
741     } /* kserver_send_request */
742    
743    
744     /* Interface receiving a public key. */
745     int
746     kserver_recvkey (const char *hostname, u16 port, const char *keyid, char *key, int maxkeylen)
747     {
748     int rc, n;
749     int conn_fd;
750     char *request = NULL;
751    
752     if (!port)
753     port = HKP_PORT;
754     hkp_err = 0; /* reset */
755     rc = kserver_connect (hostname, port, &conn_fd);
756     if (rc)
757     goto leave;
758    
759     request = new char[300+1];
760     if (!request)
761     BUG (0);
762    
763     if (proxy.host && proxy.user) {
764     _snprintf (request, 300,
765     "GET http://%s:%d/pks/lookup?op=get&search=%s HTTP/1.0\r\n"
766     "Proxy-Authorization: Basic %s\r\n\r\n",
767     skip_type_prefix (hostname), port, keyid, proxy.base64_user);
768     }
769     else if (proxy.host) {
770     _snprintf (request, 300,
771     "GET http://%s:%d/pks/lookup?op=get&search=%s HTTP/1.0\r\n\r\n",
772     skip_type_prefix (hostname), port, keyid);
773     }
774     else {
775     _snprintf (request, 300,
776     "GET /pks/lookup?op=get&search=%s HTTP/1.0\r\n\r\n", keyid);
777     }
778    
779     log_debug ("%s\r\n", request);
780    
781     rc = sock_write (conn_fd, request, strlen (request));
782     if (rc == SOCKET_ERROR) {
783     rc = WPTERR_WINSOCK_RECVKEY;
784     goto leave;
785     }
786    
787     rc = sock_read( conn_fd, key, maxkeylen, &n );
788     if( rc == SOCKET_ERROR ) {
789     rc = WPTERR_WINSOCK_RECVKEY;
790     goto leave;
791     }
792    
793     log_debug("%s\r\n", key);
794     rc = check_hkp_response (key, 1);
795     if (rc)
796     goto leave;
797    
798     WSASetLastError (0);
799    
800     leave:
801     closesocket (conn_fd);
802     free_if_alloc (request);
803     return rc;
804     } /* kserver_recvkey */
805    
806    
807     /* Interface to send a public key. */
808     int
809     kserver_sendkey (const char *hostname, u16 port, const char *pubkey, int len )
810     {
811     int n, rc;
812     int conn_fd;
813     char *request = NULL;
814     char log[2048];
815    
816     hkp_err = 0; /* reset */
817     rc = kserver_connect (hostname, port, &conn_fd);
818     if (rc)
819     goto leave;
820    
821     request = kserver_send_request (hostname, port, pubkey, len);
822     if (request == NULL) {
823     rc = WPTERR_GENERAL;
824     goto leave;
825     }
826    
827     rc = sock_write( conn_fd, request, lstrlen(request) );
828     if( rc == SOCKET_ERROR ) {
829     rc = WPTERR_WINSOCK_SENDKEY;
830     goto leave;
831     }
832    
833     rc = sock_read( conn_fd, log, sizeof (log)-1, &n );
834     if( rc == SOCKET_ERROR ) {
835     rc = WPTERR_WINSOCK_SENDKEY;
836     goto leave;
837     }
838    
839     log_debug ("kserver_sendkey:\r\n%s\r\n", log);
840    
841     rc = check_hkp_response (log, 0);
842     if( rc )
843     goto leave;
844    
845     WSASetLastError (0);
846    
847     leave:
848     closesocket (conn_fd);
849     free_if_alloc (request);
850     return rc;
851     } /* kserver_sendkey */
852    
853    
854     int
855     kserver_search_init (const char * hostname, u16 port, const char * keyid, int * conn_fd)
856     {
857     int rc, sock_fd;
858     int n=0;
859 twoaday 2 char * request = NULL;
860 werner 36
861     rc = kserver_connect (hostname, port, &sock_fd);
862     if (rc) {
863     *conn_fd = 0;
864     goto leave;
865     }
866    
867     n=300;
868     request = new char[n+1];
869     if (!request)
870     BUG (0);
871    
872     if (proxy.host && proxy.user) {
873     _snprintf (request, n,
874     "GET http://%s:%d/pks/lookup?op=index&search=%s HTTP/1.0\r\n"
875     "Proxy-Authorization: Basic %s\r\n\r\n",
876     skip_type_prefix (hostname), port, keyid, proxy.base64_user);
877     }
878     else if (proxy.host) {
879     _snprintf (request, n,
880     "GET http://%s:%d/pks/lookup?op=index&search=%s HTTP/1.0\r\n\r\n",
881     skip_type_prefix (hostname), port, keyid);
882     }
883     else {
884     _snprintf (request, n,
885     "GET /pks/lookup?op=index&search=%s HTTP/1.0\r\n\r\n", keyid);
886     }
887    
888     log_debug ("kserver_search_init:\r\n%s\r\n", request);
889    
890     if (sock_write (sock_fd, request, strlen (request)) == SOCKET_ERROR) {
891     rc = WPTERR_GENERAL;
892     goto leave;
893     }
894    
895     *conn_fd = sock_fd;
896    
897     leave:
898     free_if_alloc (request);
899     return rc;
900     } /* kserver_search_init */
901    
902    
903     int
904     kserver_search_chkresp (int fd)
905     {
906     char buf[128];
907     int n=0;
908    
909     /* parse response 'HTTP/1.0 500 OK' */
910     if (sock_getline (fd, buf, 127, &n))
911     return WPTERR_KEYSERVER_NOTFOUND;
912    
913     log_debug ("kserver_search_chkpresp: %s\r\n", buf);
914     if (strncmp (buf, "HTTP/1.", 7))
915     return WPTERR_KEYSERVER_NOTFOUND;
916     if (strncmp (buf+(8+1), "200", 3))
917     return WPTERR_KEYSERVER_NOTFOUND;
918     return 0;
919     } /* kserver_search_chkresp */
920    
921    
922     int
923     kserver_search (int fd, keyserver_key * key)
924     {
925     char buf[1024], *p;
926     int uidlen, nbytes, pos = 0;
927    
928     log_debug ("keyserver_search:\n");
929    
930     if (sock_getline (fd, buf, sizeof (buf) - 1, &nbytes))
931     return WPTERR_GENERAL;
932    
933     log_debug ("%s\n", buf);
934    
935     if (!strncmp (buf, "pub", 3)) {
936     int revoked = strstr (buf, "KEY REVOKED") != NULL? 1 : 0;
937     key->bits = atol (buf+3);
938     p = strchr (buf, '>');
939     if (!p)
940     goto fail;
941     pos = p - buf + 1;
942     memcpy (key->keyid, buf + pos, 8);
943     key->keyid[8] = '\0';
944     p = strstr (buf, "</a>");
945     if (!p)
946     goto fail;
947     pos = p - buf + 5;
948     memcpy (key->date, buf + pos, 10);
949     key->date[10] = '\0';
950     if (revoked) {
951     strcpy (key->uid, "KEY REVOKED: not checked");
952     return 0;
953     }
954     pos += 10;
955     p = buf + pos + 1;
956     while (p && *p != '>')
957     p++;
958     p++;
959     uidlen = strlen (p) - 10;
960     memcpy (key->uid, p, uidlen);
961     key->uid[uidlen] = '\0';
962     strcat (key->uid, ">");
963     p = strchr (key->uid, '&');
964     if (p) {
965     key->uid[(p-key->uid)] = '<';
966     memmove (key->uid+(p-key->uid)+1, key->uid+(p-key->uid)+4, strlen (key->uid)-3);
967     }
968     return 0;
969     }
970    
971     fail:
972     key->bits = 0;
973     memset (key, 0, sizeof *key);
974     return 0;
975     } /* kserver_search */
976    
977    
978     static int
979     add_node( keyserver_cfgfile *cfg, const char *entry )
980     {
981     keyserver_node *node;
982     char *p = NULL;
983    
984     p = strchr( entry, '=' );
985     if( p == NULL )
986     return WPTERR_GENERAL;
987     node = new keyserver_node;
988     if( !node )
989     BUG( NULL );
990    
991     memset( node, 0, sizeof *node );
992     node->used = 1;
993    
994     node->host.used = 1;
995     node->host.proto = proto_from_URL( entry );
996     memcpy( node->host.name, entry+7, p-entry-7 );
997     node->next = cfg->list;
998     cfg->list = node;
999    
1000     return 0;
1001     } /* add_node */
1002    
1003    
1004     void
1005     kserver_change_proxy( keyserver_proxy_ctx *ctx )
1006     {
1007     proxy.port = ctx->port;
1008     free_if_alloc (proxy.host);
1009     proxy.host = ctx->host? m_strdup( ctx->host ) : NULL;
1010     free_if_alloc( proxy.pass );
1011     proxy.pass = ctx->pass? m_strdup( ctx->pass ) : NULL;
1012     free_if_alloc( proxy.user );
1013     proxy.user = ctx->user? m_strdup( ctx->user ) : NULL;
1014     set_reg_proxy_prefs( proxy.host, proxy.port, proxy.user, proxy.pass );
1015     } /* kserver_change_proxy */
1016    
1017    
1018     int
1019     kserver_read_config( const char *fname, keyserver_cfgfile **ret_cfg )
1020     {
1021     FILE *fp;
1022     keyserver_cfgfile *cfg;
1023     char buf[256];
1024     int rc = 0;
1025    
1026     *ret_cfg = NULL;
1027     fp = fopen( fname, "rb" );
1028     if( fp == NULL )
1029     return WPTERR_FILE_OPEN;
1030    
1031     cfg = new keyserver_cfgfile;
1032     if ( !cfg )
1033     BUG( NULL );
1034     memset( cfg, 0, sizeof *cfg );
1035    
1036     while ( !feof( fp ) ) {
1037     if ( fgets( buf, sizeof(buf)-1, fp ) == NULL )
1038     break;
1039     if ( *buf == '\r' || *buf == '\n' || *buf == '#' )
1040     continue;
1041     buf[strlen(buf) -2] = '\0';
1042     if ( !strncmp( buf, "use_proxy=", 10 ) ) {
1043     char *p = strchr(buf, ':');
1044     if (!p)
1045     continue;
1046     cfg->proxy.port = atol( buf+(p-buf+1) );
1047     buf[p-buf] = '\0';
1048     cfg->proxy.host = m_strdup( buf+10 );
1049     }
1050     else if ( !strncmp( buf, "proxy_user=", 11 ) )
1051     cfg->proxy.user = m_strdup( buf+11 );
1052     else if ( !strncmp( buf, "proxy_pass=", 11 ) )
1053     cfg->proxy.pass = m_strdup( buf+11 );
1054     if ( !strncmp( buf, "http://", 7 )
1055     || !strncmp( buf, "hkp://", 6 )
1056     || !strncmp( buf, "ldap://", 7 ) ) {
1057     add_node( cfg, buf );
1058     cfg->nlist++;
1059     }
1060     }
1061    
1062     fclose( fp );
1063     *ret_cfg = cfg;
1064    
1065     return rc;
1066     } /* kserver_read_config */
1067    
1068    
1069     int
1070     kserver_write_config( const char * fname, keyserver_cfgfile * cfg )
1071     {
1072    
1073     return 0;
1074     }
1075    
1076    
1077     void
1078     kserver_cfgfile_release( keyserver_cfgfile *cfg )
1079     {
1080     keyserver_node *k, *k2;
1081    
1082     proxy_release( &cfg->proxy );
1083     for( k = cfg->list; cfg->nlist--; k = k2 ) {
1084     k2 = k->next;
1085     free_if_alloc( k );
1086     }
1087     free_if_alloc( cfg );
1088     } /* kserver_cfgfile_release */
1089    
1090    
1091     void
1092     proxy_release( keyserver_proxy_ctx *ctx )
1093     {
1094     free_if_alloc( ctx->host );
1095     free_if_alloc( ctx->pass );
1096     free_if_alloc( ctx->user );
1097     } /* proxy_release */
1098    
1099    
1100     int
1101     ldap_recvkey (const char * host, const char * keyid, char * key, int maxkeylen)
1102     {
1103     const char *s;
1104     char *ksprg = NULL, *p = NULL;
1105     char temp[512], outf[512];
1106     FILE * inp;
1107     int rc, start_key = 0;
1108     STARTUPINFO si;
1109     PROCESS_INFORMATION pi;
1110    
1111     p = get_gnupg_path ();
1112     ksprg = new char[strlen (p) + 1 + 128];
1113     if (!ksprg)
1114     BUG (0);
1115     strcpy (ksprg, p);
1116     strcat (ksprg, "\\");
1117     strcat (ksprg, "gpgkeys_ldap.exe");
1118     free_if_alloc (p);
1119     if (file_exist_check (ksprg)) {
1120     log_box ( "LDAP Keyserver Plugin", MB_ERR, "Could not find LDAP keyserver module!");
1121     rc = -1;
1122     goto leave;
1123     }
1124     GetTempPath (sizeof (temp)-1, temp);
1125     strcpy (outf, temp);
1126     strcat (outf, keyid);
1127     strcat (outf, ".out");
1128     strcat (temp, keyid);
1129     inp = fopen (temp, "w+b");
1130     if( !inp ) {
1131     log_box ("LDAP Keyserver Plugin", MB_ERR, "%s: %s", temp,
1132     winpt_strerror (WPTERR_FILE_OPEN));
1133     rc = -1;
1134     goto leave;
1135     }
1136     fprintf (inp,
1137     "VERSION 0\n"
1138     "HOST %s\n"
1139     "OPTION verbose\n"
1140     "COMMAND GET\n"
1141     "\n"
1142     "%s\n", host? skip_type_prefix (host): "64.94.85.200", keyid);
1143     fclose (inp);
1144    
1145     memset (&si, 0, sizeof (si));
1146     si.cb = sizeof (si);
1147     si.dwFlags = STARTF_USESHOWWINDOW;
1148     si.wShowWindow = SW_HIDE;
1149     memset (&pi, 0, sizeof (pi));
1150     p = new char[strlen (ksprg) + strlen (temp) + strlen (outf) + 32];
1151     sprintf (p, "%s -o %s %s", ksprg, outf, temp);
1152     rc = CreateProcess (NULL, p, NULL, NULL, FALSE, 0, NULL, NULL, &si, &pi);
1153     if (!rc) {
1154     log_box ("LDAP Keyserver Plugin", MB_ERR, "Could not spawn process");
1155     rc = -1;
1156     goto leave;
1157     }
1158     CloseHandle (pi.hThread);
1159     WaitForSingleObject (pi.hProcess, INFINITE);
1160     CloseHandle (pi.hProcess);
1161    
1162     inp = fopen (outf, "rb");
1163     if (!inp) {
1164     log_box ("LDAP Keyserver Plugin", MB_ERR, "%s: %s", outf,
1165     winpt_strerror (WPTERR_FILE_OPEN));
1166     rc = -1;
1167     goto leave;
1168     }
1169     memset (key, 0, maxkeylen);
1170     while( !feof( inp ) ) {
1171     s = fgets( temp, sizeof (temp)-1, inp );
1172     if( !s )
1173     break;
1174     if( !start_key && strstr( s, "KEY" ) && strstr( s, "BEGIN" ) ) {
1175     start_key = 1;
1176     continue;
1177     }
1178     if( !start_key )
1179     continue;
1180     strcat( key, temp );
1181     maxkeylen -= strlen( temp );
1182     if( maxkeylen < 0 || (strstr( s, "KEY" ) && strstr( s, "END" )) )
1183     break;
1184     }
1185     fclose( inp );
1186    
1187     leave:
1188     if( !strlen( key ) )
1189     rc = WPTERR_WINSOCK_RECVKEY;
1190     free_if_alloc( p );
1191     free_if_alloc( ksprg );
1192     return rc;
1193     } /* ldap_recvkey */
1194    
1195    
1196     static int
1197     finger_readline (int fd, char * buf, int nbytes)
1198     {
1199     char c = 0;
1200     int n, pos = 0;
1201    
1202     while (nbytes > 0) {
1203     n = recv (fd, &c, 1, 0);
1204     if (n <= 0)
1205     break;
1206     if (c == '\n')
1207     break;
1208     buf[pos++] = c;
1209     nbytes--;
1210     }
1211     if (nbytes > 0)
1212     buf[pos++] = '\0';
1213     if (n <= 0)
1214     pos = n;
1215     return pos;
1216     }
1217    
1218    
1219     int
1220     finger_recvkey (const char * host, const char * user, char * key, int maxkeylen)
1221     {
1222     struct hostent * hp;
1223     struct sockaddr_in saddr;
1224     char buf[128];
1225     int fd, nread;
1226     int start_key = 0;
1227     int rc=0;
1228    
1229     fd = socket (PF_INET, SOCK_STREAM, 0);
1230     if (fd == -1)
1231     return WPTERR_WINSOCK_SOCKET;
1232     hp = gethostbyname (skip_type_prefix (host));
1233     if (!hp) {
1234     closesocket (fd);
1235     return WPTERR_WINSOCK_RESOLVE;
1236     }
1237    
1238     memset (&saddr, 0, sizeof (saddr));
1239     saddr.sin_family = AF_INET;
1240     saddr.sin_port = htons (FINGER_PORT);
1241     saddr.sin_addr = *(struct in_addr *)hp->h_addr;
1242     if (connect (fd, (struct sockaddr *)&saddr, sizeof (saddr))) {
1243     closesocket (fd);
1244     return WPTERR_WINSOCK_CONNECT;
1245     }
1246     send (fd, user, strlen (user), 0);
1247     send (fd, "\r\n", 2, 0);
1248    
1249     memset (key, 0, maxkeylen);
1250     while (maxkeylen > 0) {
1251     nread = finger_readline (fd, buf, sizeof (buf)-1);
1252     if (nread <= 0)
1253     break;
1254     strcat (buf, "\n");
1255     if (strstr (buf, "BEGIN PGP PUBLIC KEY BLOCK")) {
1256     strcat (key, buf);
1257     start_key = 1;
1258     maxkeylen -= nread;
1259     }
1260     else if (strstr (buf, "END PGP PUBLIC KEY BLOCK" ) && start_key) {
1261     strcat (key, buf);
1262     start_key--;
1263     maxkeylen -= nread;
1264     break;
1265     }
1266     else if (start_key) {
1267     strcat (key, buf);
1268     maxkeylen -= nread;
1269     }
1270     }
1271     closesocket (fd);
1272     if (start_key != 0)
1273     rc = WPTERR_WINSOCK_RECVKEY;
1274     return rc;
1275     }
1276    
1277    
1278     int
1279     check_IP_or_hostname (const char *name)
1280     {
1281     const char *not_allowed = "=!ยง$%&@#*~\\/}][{<>|,;:'";
1282     size_t i, j;
1283    
1284     for (i=0; i < strlen (name); i++) {
1285     for (j =0; j < strlen (not_allowed); j++) {
1286     if (name[i] == not_allowed[j])
1287     return -1;
1288     }
1289     }
1290     return 0;
1291     }

Properties

Name Value
svn:eol-style native

[email protected]
ViewVC Help
Powered by ViewVC 1.1.26