]> source.dussan.org Git - tigervnc.git/commitdiff
[Development] Implement X509 VeNCrypt subtypes on the server side.
authorAdam Tkac <atkac@redhat.com>
Wed, 21 Jul 2010 09:08:24 +0000 (09:08 +0000)
committerAdam Tkac <atkac@redhat.com>
Wed, 21 Jul 2010 09:08:24 +0000 (09:08 +0000)
git-svn-id: svn://svn.code.sf.net/p/tigervnc/code/trunk@4105 3789f03b-4d11-0410-bbf8-ca57d06f2519

common/rfb/Makefile.am
common/rfb/SSecurityVeNCrypt.cxx
common/rfb/SSecurityVeNCrypt.h
common/rfb/SSecurityX509.cxx [new file with mode: 0644]
common/rfb/SSecurityX509.h [new file with mode: 0644]
common/rfb/Security.cxx

index 7df6b6b94529094040f7eac2a17cd594f50de6bd..4160a9d637e095ec97630653a863bb109183e927 100644 (file)
@@ -1,10 +1,10 @@
 noinst_LTLIBRARIES = librfb.la
 
 VENCRYPT_HDRS = CSecurityTLS.h CSecurityTLSBase.h \
-       SSecurityTLS.h SSecurityTLSBase.h
+       SSecurityTLS.h SSecurityTLSBase.h SSecurityX509.h
 
 VENCRYPT_SRCS = CSecurityTLS.cxx CSecurityTLSBase.cxx \
-       SSecurityTLS.cxx SSecurityTLSBase.cxx
+       SSecurityTLS.cxx SSecurityTLSBase.cxx SSecurityX509.cxx
 
 HDRS = Blacklist.h CapsContainer.h CapsList.h CConnection.h \
        CMsgHandler.h CMsgReader.h CMsgReaderV3.h CMsgWriter.h \
index c704d1e5ac484bc7782d373b5df85a2c57ea6adc..ac4f16f3b811daf2652e8068ef2c79c651561546 100644 (file)
@@ -38,16 +38,6 @@ using namespace std;
 \r
 static LogWriter vlog("SVeNCrypt");\r
 \r
-StringParameter SSecurityVeNCrypt::X509_CertFile\r
-("x509cert",\r
- "specifies path to the x509 certificate in PEM format",\r
- "", ConfServer);\r
-\r
-StringParameter SSecurityVeNCrypt::X509_KeyFile\r
-("x509key",\r
- "specifies path to the key of the x509 certificate in PEM format",\r
- "", ConfServer);\r
-\r
 SSecurityVeNCrypt::SSecurityVeNCrypt(Security *sec) : security(sec)\r
 {\r
   ssecurity = NULL;\r
index 6201a7b7ffcb762ddffb7cbc402491c06cdc01bc..37ff90966318be016c0e63fa5a121a858a97c861 100644 (file)
@@ -42,8 +42,6 @@ namespace rfb {
     virtual int getType() const { return secTypeVeNCrypt; }\r
     virtual const char* getUserName() const { return NULL; }\r
 \r
-    static StringParameter X509_CertFile, X509_KeyFile;\r
-\r
   protected:\r
     SSecurity *ssecurity;\r
     Security *security;\r
diff --git a/common/rfb/SSecurityX509.cxx b/common/rfb/SSecurityX509.cxx
new file mode 100644 (file)
index 0000000..82a2b02
--- /dev/null
@@ -0,0 +1,90 @@
+/* 
+ * Copyright (C) 2005 Martin Koegler
+ * Copyright (C) 2010 TigerVNC Team
+ *    
+ * This is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation; either version 2 of the License, or
+ * (at your option) any later version.
+ * 
+ * This software is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+ * GNU General Public License for more details.
+ * 
+ * You should have received a copy of the GNU General Public License
+ * along with this software; if not, write to the Free Software
+ * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA  02111-1307,
+ * USA.
+ */
+
+#ifdef HAVE_CONFIG_H
+#include <config.h>
+#endif
+
+#ifndef HAVE_GNUTLS
+#error "This source should not be compiled without HAVE_GNUTLS defined"
+#endif
+
+#include <rfb/SSecurityX509.h>
+#include <rfb/Exception.h>
+
+#define DH_BITS 1024
+
+using namespace rfb;
+
+StringParameter SSecurityX509::X509_CertFile
+("x509cert", "specifies path to the x509 certificate in PEM format", "", ConfServer);
+
+StringParameter SSecurityX509::X509_KeyFile
+("x509key", "specifies path to the key of the x509 certificate in PEM format", "", ConfServer);
+
+SSecurityX509::SSecurityX509() : dh_params(0), cert_cred(0)
+{
+  certfile = X509_CertFile.getData();
+  keyfile = X509_KeyFile.getData();
+}
+
+SSecurityX509::~SSecurityX509()
+{
+  shutdown();
+  if (dh_params)
+    gnutls_dh_params_deinit(dh_params);
+  if (cert_cred)
+    gnutls_certificate_free_credentials(cert_cred);
+  delete[] keyfile;
+  delete[] certfile;
+}
+
+void SSecurityX509::freeResources()
+{
+  if (dh_params)
+    gnutls_dh_params_deinit(dh_params);
+  dh_params=0;
+  if (cert_cred)
+    gnutls_certificate_free_credentials(cert_cred);
+  cert_cred=0;
+}
+
+void SSecurityX509::setParams(gnutls_session session)
+{
+    static const int kx_priority[] = {GNUTLS_KX_DHE_DSS, GNUTLS_KX_RSA, GNUTLS_KX_DHE_RSA, GNUTLS_KX_SRP, 0};
+    gnutls_kx_set_priority(session, kx_priority);
+
+    if (gnutls_certificate_allocate_credentials(&cert_cred) < 0)
+      goto error;
+    if (gnutls_dh_params_init(&dh_params) < 0)
+      goto error;
+    if (gnutls_dh_params_generate2(dh_params, DH_BITS) < 0)
+      goto error;
+    gnutls_certificate_set_dh_params(cert_cred, dh_params);
+    if (gnutls_certificate_set_x509_key_file(cert_cred, certfile, keyfile,GNUTLS_X509_FMT_PEM) < 0)
+      throw AuthFailureException("load of key failed");
+    if (gnutls_credentials_set(session, GNUTLS_CRD_CERTIFICATE, cert_cred) < 0)
+      goto error;
+    return;
+
+ error:
+    throw AuthFailureException("setParams failed");
+}
+
diff --git a/common/rfb/SSecurityX509.h b/common/rfb/SSecurityX509.h
new file mode 100644 (file)
index 0000000..64fa6ec
--- /dev/null
@@ -0,0 +1,61 @@
+/* \r
+ * Copyright (C) 2006 OCCAM Financial Technology\r
+ * Copyright (C) 2010 TigerVNC Team\r
+ *    \r
+ * This is free software; you can redistribute it and/or modify\r
+ * it under the terms of the GNU General Public License as published by\r
+ * the Free Software Foundation; either version 2 of the License, or\r
+ * (at your option) any later version.\r
+ * \r
+ * This software is distributed in the hope that it will be useful,\r
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of\r
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the\r
+ * GNU General Public License for more details.\r
+ * \r
+ * You should have received a copy of the GNU General Public License\r
+ * along with this software; if not, write to the Free Software\r
+ * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA  02111-1307,\r
+ * USA.\r
+ */\r
+\r
+#ifndef __S_SECURITY_X509_H__\r
+#define __S_SECURITY_X509_H__\r
+\r
+#ifdef HAVE_CONFIG_H\r
+#include <config.h>\r
+#endif\r
+\r
+#ifndef HAVE_GNUTLS\r
+#error "This header should not be compiled without HAVE_GNUTLS defined"\r
+#endif\r
+\r
+#include <rfb/SSecurityTLSBase.h>\r
+#include <rfb/SSecurityVeNCrypt.h>\r
+\r
+namespace rfb {\r
+\r
+  class SSecurityX509 : public SSecurityTLSBase {\r
+  public:\r
+    SSecurityX509();\r
+    virtual ~SSecurityX509();\r
+    virtual int getType() const { return secTypeX509None; }\r
+\r
+    static StringParameter X509_CertFile;\r
+    static StringParameter X509_KeyFile;\r
+\r
+  protected:\r
+    virtual void freeResources();\r
+    virtual void setParams(gnutls_session session);\r
+\r
+  private:\r
+    static void initGlobal();\r
+\r
+    gnutls_dh_params dh_params;\r
+    gnutls_certificate_credentials cert_cred;\r
+    char* keyfile;\r
+    char* certfile;\r
+  };\r
+\r
+}\r
+\r
+#endif /* __S_SECURITY_TLS_H__ */\r
index e6a51bcc6183cfc6be4b3880ca63d3aafac99222..c6ab41076eb7266bc3fb6f783078df7b9a353fe6 100644 (file)
@@ -41,6 +41,7 @@
 #ifdef HAVE_GNUTLS
 #include <rfb/CSecurityTLS.h>
 #include <rfb/SSecurityTLS.h>
+#include <rfb/SSecurityX509.h>
 #endif
 #include <rfb/util.h>
 
@@ -126,6 +127,10 @@ SSecurity* Security::GetSSecurity(U32 secType)
     return new SSecurityStack(secTypeTLSNone, new SSecurityTLS());
   case secTypeTLSVnc:
     return new SSecurityStack(secTypeTLSVnc, new SSecurityTLS(), new SSecurityVncAuth());
+  case secTypeX509None:
+    return new SSecurityStack(secTypeX509None, new SSecurityX509());
+  case secTypeX509Vnc:
+    return new SSecurityStack(secTypeX509None, new SSecurityX509(), new SSecurityVncAuth());
 #endif
   }