/* libimap library. * Copyright (C) 2003-2004 Pawel Salek. * * This program is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License as published by * the Free Software Foundation; either version 2, or (at your option) * any later version. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU General Public License for more details. * * You should have received a copy of the GNU General Public License * along with this program; if not, write to the Free Software * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA * 02111-1307, USA. */ /* * STARTTLS Command * see RFC2595, A. Appendix -- Compliance Checklist Rules (for client) Section ----- ------- Mandatory-to-implement Cipher Suite 2.1 OK SHOULD have mode where encryption required 2.2 OK client MUST check server identity 2.4 client MUST use hostname used to open connection 2.4 OK client MUST NOT use hostname from insecure remote lookup 2.4 OK client SHOULD support subjectAltName of dNSName type 2.4 OK client SHOULD ask for confirmation or terminate on fail 2.4 OK MUST check result of STARTTLS for acceptable privacy 2.5 OK client MUST NOT issue commands after STARTTLS until server response and negotiation done 3.1,4,5.1 OK client MUST discard cached information 3.1,4,5.1,9 OK client SHOULD re-issue CAPABILITY/CAPA command 3.1,4 OK IMAP client MUST NOT issue LOGIN if LOGINDISABLED 3.2 OK client SHOULD warn when session privacy not active and/or refuse to proceed without acceptable security level 9 SHOULD be configurable to refuse weak mechanisms or cipher suites 9 */ #include "config.h" #ifdef USE_TLS /* OE build fails with pthread.h if _BSD_SOURCE is not defined */ # define _BSD_SOURCE 1 #include #include #include #include #ifdef BALSA_USE_THREADS #include #endif #include "siobuf.h" #include "imap_private.h" static SSL_CTX *global_ssl_context = NULL; #ifdef BALSA_USE_THREADS static pthread_mutex_t global_tls_lock = PTHREAD_MUTEX_INITIALIZER; /* provide support only for _POSIX_THREADS */ #define MUTEX_TYPE pthread_mutex_t #define MUTEX_SETUP(m) pthread_mutex_init (&(m), NULL) #define MUTEX_CLEANUP(m) pthread_mutex_destroy(&(m)) #define MUTEX_LOCK(m) pthread_mutex_lock(&(m)) #define MUTEX_UNLOCK(m) pthread_mutex_unlock(&(m)) #define THREAD_ID pthread_self() /* OpenSSL static locks */ static MUTEX_TYPE *mutexes = NULL; static void locking_function(int mode, int n, const char *file, int line) { if(mode & CRYPTO_LOCK) MUTEX_LOCK(mutexes[n]); else MUTEX_UNLOCK(mutexes[n]); } static unsigned long id_function(void) { return (unsigned long)THREAD_ID; } /* OpenSSL dynamic locks */ struct CRYPTO_dynlock_value { MUTEX_TYPE mutex; }; static struct CRYPTO_dynlock_value* dyn_create_function(const char *file, int line) { struct CRYPTO_dynlock_value *value = (struct CRYPTO_dynlock_value*)malloc(sizeof(struct CRYPTO_dynlock_value)); if(!value) return NULL; MUTEX_SETUP(value->mutex); return value; } static void dyn_lock_function(int mode, struct CRYPTO_dynlock_value *l, const char *file, int line) { if(mode & CRYPTO_LOCK) MUTEX_LOCK(l->mutex); else MUTEX_UNLOCK(l->mutex); } static void dyn_destroy_function(struct CRYPTO_dynlock_value *l, const char *file, int line) { MUTEX_CLEANUP(l->mutex); free(l); } static int imaptls_thread_setup(void) { int i, mutex_cnt = CRYPTO_num_locks(); mutexes = (MUTEX_TYPE*)malloc(mutex_cnt*sizeof(MUTEX_TYPE)); if(!mutexes) return 0; for(i=0; ivalue->data; val = meth->i2v(meth, meth->d2i(NULL, &data, ext->value->length), NULL); stack_len = sk_CONF_VALUE_num(val); for(j=0; jname, "DNS") == 0 && host_matches_domain(host, nval->value, host_len)) { ok = 1; break; } } } if(ok) break; } if(!ok) { /* matching by subjectAltName failed, try commonName */ char data[256]; if( (subj = X509_get_subject_name(cert)) && X509_NAME_get_text_by_NID(subj, NID_commonName, data, sizeof(data))>0){ data[sizeof(data)-1] = 0; if(host_matches_domain(host, data, host_len)) ok =1; } } X509_free(cert); if(ok) vfy_result = SSL_get_verify_result(ssl); else vfy_result = X509_V_ERR_APPLICATION_VERIFICATION; if(vfy_result == X509_V_OK) return 1; /* There was a problem with the verification, one has to leave it up to the * application what to do with this. */ ok = 0; if(user_cb) user_cb(IME_TLS_VERIFY_ERROR, user_arg, &ok, vfy_result, ssl); return ok; } static int check_cipher_strength(SSL *ssl, ImapUserCb user_cb, void *user_arg) { int ok, bits = SSL_get_cipher_bits(ssl, NULL); if (bits > 40) return 1; ok = 0; if (user_cb != NULL) user_cb(IME_TLS_WEAK_CIPHER, user_arg, bits, &ok); return ok; } int imap_setup_ssl(struct siobuf *sio, const char* host, SSL *ssl, ImapUserCb user_cb, void *user_arg) { if(ERR_peek_error()) { fprintf(stderr, "OpenSSL error in %s():\n", __FUNCTION__); ERR_print_errors_fp(stderr); fprintf(stderr, "\nEnd of print_errors\n"); } if(sio_set_tlsclient_ssl (sio, ssl)) { if(!imap_check_server_identity(ssl, host, user_cb, user_arg)) { printf("Server identity not confirmed\n"); return 0; } if(!check_cipher_strength(ssl, user_cb, user_arg)) { printf("Cipher too weak\n"); return 0; } return 1; } else { printf("set_tlsclient failed!\n"); return 0; } } ImapResponse imap_handle_starttls(ImapMboxHandle *handle) { ImapResponse rc; SSL *ssl; IMAP_REQUIRED_STATE1(handle, IMHS_CONNECTED, IMR_BAD); if(!imap_mbox_handle_can_do(handle, IMCAP_STARTTLS)) return IMR_NO; ssl = imap_create_ssl(); if(!ssl) { printf("ssl=%p ctx=%p\n", ssl, global_ssl_context); return IMR_NO; } if( (rc=imap_cmd_exec(handle, "StartTLS")) != IMR_OK) { SSL_free(ssl); return rc; } if(imap_setup_ssl(handle->sio, handle->host, ssl, handle->user_cb, handle->user_arg)) { handle->using_tls = 1; handle->has_capabilities = 0; return IMR_OK; } else { /* ssl is owned now by sio, no need to free it SSL_free(ssl); */ sio_detach(handle->sio); handle->sio = NULL; close(handle->sd); handle->state = IMHS_DISCONNECTED; return IMR_NO; } } #endif /* USE_TLS */