/[winpt]/trunk/Src/wptPassphraseCB.cpp
ViewVC logotype

Contents of /trunk/Src/wptPassphraseCB.cpp

Parent Directory Parent Directory | Revision Log Revision Log


Revision 271 - (show annotations)
Sun Nov 5 08:57:45 2006 UTC (18 years, 3 months ago) by twoaday
File size: 14294 byte(s)


1 /* wptPassphraseCB.cpp - GPGME Passphrase Callback
2 * Copyright (C) 2001, 2002-2006 Timo Schulz
3 * Copyright (C) 2005 g10 Code GmbH
4 *
5 * This file is part of WinPT.
6 *
7 * WinPT is free software; you can redistribute it and/or
8 * modify it under the terms of the GNU General Public License
9 * as published by the Free Software Foundation; either version 2
10 * of the License, or (at your option) any later version.
11 *
12 * WinPT is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15 * General Public License for more details.
16 *
17 * You should have received a copy of the GNU General Public License
18 * along with WinPT; if not, write to the Free Software Foundation,
19 * Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
20 */
21
22 #ifdef HAVE_CONFIG_H
23 #include <config.h>
24 #endif
25
26 #include <windows.h>
27 #include <ctype.h>
28
29 #include "resource.h"
30 #include "wptNLS.h"
31 #include "wptW32API.h"
32 #include "wptVersion.h"
33 #include "wptGPG.h"
34 #include "wptCommonCtl.h"
35 #include "wptContext.h"
36 #include "wptDlgs.h"
37 #include "wptErrors.h"
38 #include "wptTypes.h"
39 #include "wptKeylist.h"
40 #include "wptAgent.h"
41 #include "wptRegistry.h"
42 #include "wptUTF8.h"
43
44
45 /* Return the control ID dependent on the mode (sign or decrypt). */
46 #define item_ctrl_id(cmd) \
47 ((cmd) == GPG_CMD_DECRYPT? IDC_DECRYPT_PWD : IDC_DECRYPT_SIGN_PWD)
48
49 #define item_ctrl_id2(cmd) \
50 ((cmd) == GPG_CMD_DECRYPT? IDC_DECRYPT_HIDE : IDC_DECRYPT_SIGN_HIDE)
51
52 const char* get_symkey_algo (int algo);
53 void ListBox_AddString_utf8 (HWND lb, const char *txt);
54
55
56 /* Overwrite passphrase and free memory. */
57 static void
58 burn_passphrase (char **pwd)
59 {
60 char *pass = *pwd;
61
62 wipememory (pass, strlen (pass));
63 delete []pass;
64 *pwd = NULL;
65 }
66
67
68 /* Dialog procedure for the passphrase callback. */
69 static BOOL CALLBACK
70 passphrase_callback_proc (HWND dlg, UINT msg, WPARAM wparam, LPARAM lparam)
71 {
72 static passphrase_cb_s *c;
73 gpgme_decrypt_result_t res=NULL;
74 gpgme_sign_result_t res_sig=NULL;
75 gpgme_recipient_t recip=NULL, r;
76 winpt_key_s key;
77 void *item;
78 const char *id;
79 char *info;
80 int n;
81
82 switch (msg) {
83 case WM_ACTIVATE:
84 safe_edit_control_init (dlg, item_ctrl_id (c->gpg_cmd));
85 break;
86
87 case WM_DESTROY:
88 safe_edit_control_free (dlg, item_ctrl_id (c->gpg_cmd));
89 break;
90
91 case WM_INITDIALOG:
92 c = (passphrase_cb_s *)lparam;
93 if (!c)
94 BUG (0);
95 SetDlgItemText (dlg, IDCANCEL, _("&Cancel"));
96 SetWindowText (dlg, c->title);
97 if (c->gpg_cmd == GPG_CMD_DECRYPT) {
98 SetDlgItemText (dlg, IDC_DECRYPT_HIDE, _("&Hide Typing"));
99 SetDlgItemText (dlg, IDC_DECRYPT_LISTINF,
100 _("Encrypted with the following public key(s)"));
101 CheckDlgButton (dlg, IDC_DECRYPT_HIDE, BST_CHECKED);
102 }
103 else if (c->gpg_cmd == GPG_CMD_SIGN) {
104 SetDlgItemText (dlg, IDC_DECRYPT_SIGN_HIDE, _("&Hide Typing"));
105 CheckDlgButton (dlg, IDC_DECRYPT_SIGN_HIDE, BST_CHECKED);
106 }
107 /* Because it depends on the order the keys are stored in the
108 keyring whether res->recipients is complete or not, we also
109 support that the recipients were externally extracted and then
110 we use this list. */
111 if (c->recipients)
112 recip = c->recipients; /* recipients were already extracted. */
113 else {
114 res = gpgme_op_decrypt_result (c->gpg);
115 if (res && res->recipients)
116 recip = res->recipients;
117 }
118 if (recip != NULL && c->gpg_cmd == GPG_CMD_DECRYPT) {
119 for (r = recip; r; r = r->next) {
120 memset (&key, 0, sizeof (key));
121 if (!winpt_get_pubkey (r->keyid, &key)) {
122 gpgme_user_id_t u = key.ctx->uids;
123
124 id = u->name;
125 if (!id)
126 id = _("Invalid User ID");
127 n = 32+strlen (id)+1+4+strlen (r->keyid)+1;
128 if (u->email)
129 n += strlen (u->email)+1;
130 info = new char [n+1];
131 if (!info)
132 BUG (NULL);
133 if (!u->email || strlen (u->email) < 1)
134 sprintf (info, "%s (%s, 0x%s)", id,
135 get_key_pubalgo (r->pubkey_algo), r->keyid+8);
136 else
137 sprintf (info, "%s <%s> (%s, 0x%s)", id, u->email,
138 get_key_pubalgo (r->pubkey_algo), r->keyid+8);
139 }
140 else {
141 info = new char [32 + strlen (r->keyid)+1 + 4];
142 if (!info)
143 BUG (NULL);
144 sprintf (info, _("Unknown key ID (%s, 0x%s)"),
145 get_key_pubalgo (r->pubkey_algo), r->keyid+8);
146 }
147 ListBox_AddString_utf8 (GetDlgItem (dlg, IDC_DECRYPT_LIST), info);
148 free_if_alloc (info);
149 winpt_release_pubkey (&key);
150 }
151 }
152 else if (c->gpg_cmd == GPG_CMD_DECRYPT)
153 EnableWindow (GetDlgItem (dlg, IDC_DECRYPT_LIST), FALSE);
154 SetDlgItemText (dlg, c->gpg_cmd == GPG_CMD_DECRYPT?
155 IDC_DECRYPT_PWDINFO : IDC_DECRYPT_SIGN_PWDINFO,
156 c->bad_pwd? _("Bad passphrase; Enter passphrase again") :
157 _("Please enter your passphrase"));
158 if (c->gpg_cmd == GPG_CMD_DECRYPT) {
159 SetFocus (GetDlgItem (dlg, IDC_DECRYPT_PWD));
160 if (res && !res->recipients) {
161 const char *s = _("Symmetric encryption.\n"
162 "%s encrypted data.");
163 const char *alg = get_symkey_algo (c->sym.sym_algo);
164 info = new char[strlen (s) + strlen (alg) + 2];
165 if (!info)
166 BUG (NULL);
167 sprintf (info, s, alg);
168 SetDlgItemText (dlg, IDC_DECRYPT_MSG, info);
169 free_if_alloc (info);
170 }
171 else
172 SetDlgItemText (dlg, IDC_DECRYPT_MSG, c->info);
173 }
174 else {
175 SetFocus (GetDlgItem (dlg, IDC_DECRYPT_SIGN_PWD));
176 SetDlgItemText (dlg, IDC_DECRYPT_SIGN_MSG, c->info);
177 }
178 center_window (dlg, NULL);
179 SetForegroundWindow (dlg);
180 return FALSE;
181
182 case WM_COMMAND:
183 switch (HIWORD (wparam)) {
184 case BN_CLICKED:
185 if (LOWORD (wparam) == IDC_DECRYPT_HIDE
186 || LOWORD (wparam) == IDC_DECRYPT_SIGN_HIDE) {
187 HWND hwnd;
188 int hide = IsDlgButtonChecked (dlg, item_ctrl_id2 (c->gpg_cmd));
189 hwnd = GetDlgItem (dlg, item_ctrl_id (c->gpg_cmd));
190 SendMessage (hwnd, EM_SETPASSWORDCHAR, hide? '*' : 0, 0);
191 SetFocus (hwnd);
192 }
193 }
194
195 switch (LOWORD (wparam)) {
196 case IDOK:
197 /* XXX: the item is even cached when the passphrase is not
198 correct, which means that the user needs to delete all
199 cached entries to continue. */
200 if (c->pwd)
201 burn_passphrase (&c->pwd);
202 n = item_get_text_length (dlg, item_ctrl_id (c->gpg_cmd));
203 if (!n) {
204 c->pwd = new char[2];
205 if (!c->pwd)
206 BUG (NULL);
207 strcpy (c->pwd, "");
208 }
209 else {
210 char *p = new char[n+2];
211 if (!p)
212 BUG (NULL);
213 /* Get the passphrase and convert it utf8.
214 This does not just the us-ascii charset. */
215 SafeGetDlgItemText (dlg, item_ctrl_id (c->gpg_cmd), p, n+1);
216 c->pwd = native_to_utf8 (p);
217 sfree_if_alloc (p);
218 }
219 res = gpgme_op_decrypt_result (c->gpg);
220 if (!res)
221 res_sig = gpgme_op_sign_result (c->gpg);
222 if (!c->is_card && reg_prefs.cache_time > 0 &&
223 (res || res_sig)) {
224 if (agent_get_cache (c->keyid, &item))
225 agent_unlock_cache_entry (&item);
226 else
227 agent_put_cache (c->keyid, c->pwd, reg_prefs.cache_time);
228 }
229 c->cancel = 0;
230 EndDialog (dlg, TRUE);
231 return TRUE;
232
233 case IDCANCEL:
234 SetDlgItemText (dlg, item_ctrl_id (c->gpg_cmd), "");
235 c->cancel = 1;
236 EndDialog (dlg, FALSE);
237 return TRUE;
238 }
239 break;
240 }
241
242 return FALSE;
243 }
244
245
246 /* Extract the main keyid from @pass_info.
247 Return value: long main keyid or NULL for an error. */
248 static const char*
249 parse_gpg_keyid (const char *pass_info)
250 {
251 static char keyid[16+1];
252
253 /* XXX: check for leading alpha-chars? */
254 if (strlen (pass_info) < 16) {
255 log_debug ("parse_gpg_keyid: error '%s'\r\n", pass_info);
256 return NULL;
257 }
258 /* the format of the desc buffer looks like this:
259 request_keyid[16] main_keyid[16] keytype[1] keylength[4]
260 we use the main keyid to use only one cache entry. */
261 strncpy (keyid, pass_info+17, 16);
262 keyid[16] = 0;
263 return keyid;
264 }
265
266
267 /* Parse the information in @uid_hint and @pass_info to generate
268 a input message for the user in @desc. */
269 static int
270 parse_gpg_description (const char *uid_hint, const char *pass_info,
271 char *desc, int size)
272 {
273 gpgme_pubkey_algo_t algo;
274 char usedkey[16+1];
275 char mainkey[16+1];
276 char *p, *uid;
277 int n=0;
278
279 algo = (gpgme_pubkey_algo_t)0;
280 /* Each uid_hint contains a long key-ID so it is at least 16 bytes. */
281 if (strlen (uid_hint) < 17) {
282 *desc = 0;
283 log_debug ("parse_gpg_description: error '%s'\r\n", uid_hint);
284 return -1;
285 }
286
287 while (p = strsep ((char**)&pass_info, " ")) {
288 switch (n++) {
289 case 0: strncpy (mainkey, p, 16); mainkey[16] = 0; break;
290 case 1: strncpy (usedkey, p, 16); usedkey[16] = 0; break;
291 case 2: algo = (gpgme_pubkey_algo_t)atol (p); break;
292 }
293 }
294 uid_hint += 16; /* skip keyid */
295 uid_hint += 1; /* space */
296
297 uid = utf8_to_native (uid_hint);
298 if (strcmp (usedkey, mainkey))
299 _snprintf (desc, size-1,
300 _("You need a passphrase to unlock the secret key for user:\n"
301 "\"%s\"\n"
302 "%s key, ID 0x%s (main key ID 0x%s)\n"),
303 uid, get_key_pubalgo (algo), usedkey+8, mainkey+8);
304 else if (!strcmp (usedkey, mainkey))
305 _snprintf (desc, size-1,
306 _("You need a passphrase to unlock the secret key for user:\n"
307 "\"%s\"\n"
308 "%s key, ID 0x%s\n"),
309 uid, get_key_pubalgo (algo), usedkey+8);
310 safe_free (uid);
311 return 0;
312 }
313
314
315 /* Extract the serial number from the card ID @id and return it. */
316 const char*
317 extract_serial_no (const char *id)
318 {
319 static char buf[8];
320 char *p;
321
322 p = strchr (id, '/');
323 if (!p) {
324 log_debug ("extract_serial_no: error '%s'\r\n", id);
325 return "";
326 }
327 memset (buf, 0, sizeof (buf));
328 strncpy (buf, id+(p-id)-6, 6);
329 return buf;
330 }
331
332
333 /* Passphrase callback with the ability to support caching. */
334 gpgme_error_t
335 passphrase_cb (void *hook, const char *uid_hint,
336 const char *passphrase_info,
337 int prev_was_bad, int fd)
338 {
339 passphrase_cb_s *c = (passphrase_cb_s*)hook;
340 HANDLE hd = (HANDLE)fd;
341 void *item;
342 const char *keyid=NULL, *pass;
343 DWORD n;
344 int rc = 0;
345
346 if (!c) {
347 log_debug ("passphrase_cb: error no valid callback\r\n");
348 return gpg_error (GPG_ERR_INV_ARG);
349 }
350 c->bad_pwd = prev_was_bad? 1 : 0;
351 if (prev_was_bad && !c->cancel) {
352 if (c->pwd)
353 burn_passphrase (&c->pwd);
354 agent_del_cache (c->keyid);
355 c->pwd_init = 1;
356 }
357
358 if (passphrase_info) {
359 if (strlen (passphrase_info) < 16 &&
360 !strstr (passphrase_info, "OPENPGP")) {
361 /* assume symetric encryption. */
362 int pos=2;
363 c->sym.sym_algo = atoi (passphrase_info);
364 if (c->sym.sym_algo > 9)
365 pos++;
366 /* XXX: be more strict. */
367 c->sym.s2k_mode = atoi (passphrase_info+pos);
368 c->sym.s2k_hash = atoi (passphrase_info+pos+2);
369 }
370
371 keyid = parse_gpg_keyid (passphrase_info);
372 pass = agent_get_cache (keyid+8, &item);
373 if (pass) {
374 agent_unlock_cache_entry (&item);
375 c->pwd_init = 0;
376 if (!WriteFile (hd, pass, strlen (pass), &n, NULL))
377 log_debug ("passphrase_cb: WriteFile() failed ec=%d\n", w32_errno);
378 if (!WriteFile (hd, "\n", 1, &n, NULL))
379 log_debug ("passphrase_cb: WriteFile() failed ec=%d\n", w32_errno);
380 return 0;
381 }
382 }
383
384 if (c->pwd_init) {
385 if (keyid && strlen (keyid) == 16)
386 strcpy (c->keyid, keyid+8);
387
388 /* if @passphrase_info contains 'OPENPGP' we assume a smart card
389 has been used. */
390 if (strstr (passphrase_info, "OPENPGP")) {
391 const char *s=passphrase_info;
392 while (s && *s && *s != 'D')
393 s++;
394 _snprintf (c->info, sizeof c->info-1,
395 _("Please enter the PIN to unlock your secret card key\n"
396 "Card: %s"), extract_serial_no (s));
397 c->is_card = 1;
398 }
399 else if (uid_hint)
400 parse_gpg_description (uid_hint, passphrase_info,
401 c->info, sizeof (c->info) - 1);
402 if (c->gpg_cmd == GPG_CMD_DECRYPT) {
403 rc = DialogBoxParam (glob_hinst, (LPCSTR)IDD_WINPT_DECRYPT,
404 (HWND)c->hwnd, passphrase_callback_proc,
405 (LPARAM)c);
406 }
407 else if (c->gpg_cmd == GPG_CMD_SIGN) {
408 rc = DialogBoxParam (glob_hinst, (LPCSTR)IDD_WINPT_DECRYPT_SIGN,
409 (HWND)c->hwnd, passphrase_callback_proc,
410 (LPARAM)c);
411 }
412 if (rc == -1) {
413 if (!WriteFile (hd, "\n", 1, &n, NULL))
414 log_debug ("passphrase_cb: WriteFile() failed ec=%d\n", w32_errno);
415 log_debug ("passphrase_cb: could not create dialog box\n");
416 return 0;
417 }
418 c->pwd_init = 0;
419 }
420 if (c->cancel || !c->pwd) {
421 if (!WriteFile (hd, "\n", 1, &n, NULL))
422 log_debug ("passphrase_cb: WriteFile() failed ec=%d\n", w32_errno);
423 return 0;
424 }
425
426 if (!WriteFile (hd, c->pwd, strlen (c->pwd), &n, NULL))
427 log_debug ("passphrase_cb: WriteFile() failed ec=%d\n", w32_errno);
428 if (!WriteFile (hd, "\n", 1, &n, NULL))
429 log_debug ("passphrase_cb: WriteFile() failed ec=%d\n", w32_errno);
430 return 0;
431 }
432
433
434 /* Initialize the given passphrase callback @cb with the
435 used gpgme context @ctx, the command @cmd and a title
436 @title for the dialog. */
437 void
438 set_gpg_passphrase_cb (passphrase_cb_s *cb, gpgme_ctx_t ctx,
439 int cmd, HWND hwnd, const char *title)
440 {
441 memset (cb, 0, sizeof *cb);
442 cb->gpg_cmd = cmd;
443 cb->bad_pwd = 0;
444 cb->is_card = 0;
445 cb->cancel = 0;
446 cb->hwnd = hwnd;
447 cb->pwd_init = 1;
448 free_if_alloc (cb->title);
449 cb->title = m_strdup (title);
450 gpgme_set_passphrase_cb (ctx, passphrase_cb, cb);
451 cb->gpg = ctx;
452 }
453
454
455 /* Release the gpg recipient list. */
456 void
457 release_gpg_recipients (gpgme_recipient_t *recipients)
458 {
459 gpgme_recipient_t r, n;
460
461 r = *recipients;
462 while (r != NULL) {
463 n = r->next;
464 safe_free (r->keyid);
465 safe_free (r);
466 r = n;
467 }
468 *recipients = NULL;
469 }
470
471
472
473 /* Release a passphrase callback @ctx. */
474 void
475 release_gpg_passphrase_cb (passphrase_cb_s *ctx)
476 {
477 if (!ctx)
478 return;
479 sfree_if_alloc (ctx->pwd);
480 free_if_alloc (ctx->title);
481 release_gpg_recipients (&ctx->recipients);
482 }
483
484
485 /* _Simple_ check to measure passphrase (@pass) quality.
486 Return value: 0 on success. */
487 int
488 check_passwd_quality (const char *pass, int strict)
489 {
490 int i, nd=0, nc=0, n;
491
492 /* A good passphrase should be at least 8 characters. */
493 n = strlen (pass);
494 if (n < 8)
495 return -1;
496
497 for (i=0; i < n; i++) {
498 if (isdigit (pass[i]))
499 nd++;
500 if (isalpha (pass[i]))
501 nc++;
502 }
503
504 /* Check that the passphrase contains letters and numbers. */
505 if (nd == n || nc == n)
506 return -1;
507
508 return 0;
509 }

Properties

Name Value
svn:eol-style native

[email protected]
ViewVC Help
Powered by ViewVC 1.1.26