Blame SOURCES/openldap-openssl-its7506-fix-DH-params-1.patch

02ade0
commit aa6c4c5a7425d5fb21c5e3f10cb025fb930d79c8
02ade0
Author: Ben Jencks <ben@bjencks.net>
02ade0
Date:   Sun Jan 27 18:27:03 2013 -0500
02ade0
02ade0
    ITS#7506 tls_o.c: Fix Diffie-Hellman parameter usage.
02ade0
    
02ade0
    If a DHParamFile or olcDHParamFile is specified, then it will be used,
02ade0
    otherwise a hardcoded 1024 bit parameter will be used. This allows the use of
02ade0
    larger parameters; previously only 512 or 1024 bit parameters would ever be
02ade0
    used.
02ade0
02ade0
diff --git a/libraries/libldap/tls_o.c b/libraries/libldap/tls_o.c
02ade0
index 48ce1ceab..c6a3540c9 100644
02ade0
--- a/libraries/libldap/tls_o.c
02ade0
+++ b/libraries/libldap/tls_o.c
02ade0
@@ -59,15 +59,13 @@ static int tlso_verify_cb( int ok, X509_STORE_CTX *ctx );
02ade0
 static int tlso_verify_ok( int ok, X509_STORE_CTX *ctx );
02ade0
 static RSA * tlso_tmp_rsa_cb( SSL *ssl, int is_export, int key_length );
02ade0
 
02ade0
-static DH * tlso_tmp_dh_cb( SSL *ssl, int is_export, int key_length );
02ade0
-
02ade0
-typedef struct dhplist {
02ade0
-	struct dhplist *next;
02ade0
-	int keylength;
02ade0
-	DH *param;
02ade0
-} dhplist;
02ade0
-
02ade0
-static dhplist *tlso_dhparams;
02ade0
+/* From the OpenSSL 0.9.7 distro */
02ade0
+static const char tlso_dhpem1024[] =
02ade0
+"-----BEGIN DH PARAMETERS-----\n\
02ade0
+MIGHAoGBAJf2QmHKtQXdKCjhPx1ottPb0PMTBH9A6FbaWMsTuKG/K3g6TG1Z1fkq\n\
02ade0
+/Gz/PWk/eLI9TzFgqVAuPvr3q14a1aZeVUMTgo2oO5/y2UHe6VaJ+trqCTat3xlx\n\
02ade0
+/mNbIK9HA2RgPC3gWfVLZQrY+gz3ASHHR5nXWHEyvpuZm7m3h+irAgEC\n\
02ade0
+-----END DH PARAMETERS-----\n";
02ade0
 
02ade0
 static int tlso_seed_PRNG( const char *randfile );
02ade0
 
02ade0
@@ -76,7 +74,6 @@ static int tlso_seed_PRNG( const char *randfile );
02ade0
  * provide mutexes for the OpenSSL library.
02ade0
  */
02ade0
 static ldap_pvt_thread_mutex_t	tlso_mutexes[CRYPTO_NUM_LOCKS];
02ade0
-static ldap_pvt_thread_mutex_t	tlso_dh_mutex;
02ade0
 
02ade0
 static void tlso_locking_cb( int mode, int type, const char *file, int line )
02ade0
 {
02ade0
@@ -107,7 +104,6 @@ static void tlso_thr_init( void )
02ade0
 	for( i=0; i< CRYPTO_NUM_LOCKS ; i++ ) {
02ade0
 		ldap_pvt_thread_mutex_init( &tlso_mutexes[i] );
02ade0
 	}
02ade0
-	ldap_pvt_thread_mutex_init( &tlso_dh_mutex );
02ade0
 	CRYPTO_set_locking_callback( tlso_locking_cb );
02ade0
 	CRYPTO_set_id_callback( tlso_thread_self );
02ade0
 }
02ade0
@@ -308,28 +304,32 @@ tlso_ctx_init( struct ldapoptions *lo, struct ldaptls *lt, int is_server )
02ade0
 		return -1;
02ade0
 	}
02ade0
 
02ade0
-	if ( lo->ldo_tls_dhfile ) {
02ade0
+	if (is_server) {
02ade0
 		DH *dh = NULL;
02ade0
 		BIO *bio;
02ade0
-		dhplist *p;
02ade0
+		SSL_CTX_set_options( ctx, SSL_OP_SINGLE_DH_USE );
02ade0
+		if ( lo->ldo_tls_dhfile ) {
02ade0
 
02ade0
-		if (( bio=BIO_new_file( lt->lt_dhfile,"r" )) == NULL ) {
02ade0
+			if (( bio=BIO_new_file( lt->lt_dhfile,"r" )) == NULL ) {
02ade0
+				Debug( LDAP_DEBUG_ANY,
02ade0
+					"TLS: could not use DH parameters file `%s'.\n",
02ade0
+					lo->ldo_tls_dhfile,0,0);
02ade0
+				tlso_report_error();
02ade0
+				return -1;
02ade0
+			}
02ade0
+		} else {
02ade0
+			bio = BIO_new_mem_buf( tlso_dhpem1024, -1 );
02ade0
+		}
02ade0
+		if (!( dh=PEM_read_bio_DHparams( bio, NULL, NULL, NULL ))) {
02ade0
 			Debug( LDAP_DEBUG_ANY,
02ade0
-				"TLS: could not use DH parameters file `%s'.\n",
02ade0
+				"TLS: could not read DH parameters file `%s'.\n",
02ade0
 				lo->ldo_tls_dhfile,0,0);
02ade0
 			tlso_report_error();
02ade0
+			BIO_free( bio );
02ade0
 			return -1;
02ade0
 		}
02ade0
-		while (( dh=PEM_read_bio_DHparams( bio, NULL, NULL, NULL ))) {
02ade0
-			p = LDAP_MALLOC( sizeof(dhplist) );
02ade0
-			if ( p != NULL ) {
02ade0
-				p->keylength = DH_size( dh ) * 8;
02ade0
-				p->param = dh;
02ade0
-				p->next = tlso_dhparams;
02ade0
-				tlso_dhparams = p;
02ade0
-			}
02ade0
-		}
02ade0
 		BIO_free( bio );
02ade0
+		SSL_CTX_set_tmp_dh( ctx, dh );
02ade0
 	}
02ade0
 
02ade0
 	if ( tlso_opt_trace ) {
02ade0
@@ -349,9 +349,6 @@ tlso_ctx_init( struct ldapoptions *lo, struct ldaptls *lt, int is_server )
02ade0
 		lo->ldo_tls_require_cert == LDAP_OPT_X_TLS_ALLOW ?
02ade0
 		tlso_verify_ok : tlso_verify_cb );
02ade0
 	SSL_CTX_set_tmp_rsa_callback( ctx, tlso_tmp_rsa_cb );
02ade0
-	if ( lo->ldo_tls_dhfile ) {
02ade0
-		SSL_CTX_set_tmp_dh_callback( ctx, tlso_tmp_dh_cb );
02ade0
-	}
02ade0
 #ifdef HAVE_OPENSSL_CRL
02ade0
 	if ( lo->ldo_tls_crlcheck ) {
02ade0
 		X509_STORE *x509_s = SSL_CTX_get_cert_store( ctx );
02ade0
@@ -1160,108 +1157,6 @@ tlso_seed_PRNG( const char *randfile )
02ade0
 	return 0;
02ade0
 }
02ade0
 
02ade0
-struct dhinfo {
02ade0
-	int keylength;
02ade0
-	const char *pem;
02ade0
-	size_t size;
02ade0
-};
02ade0
-
02ade0
-
02ade0
-/* From the OpenSSL 0.9.7 distro */
02ade0
-static const char tlso_dhpem512[] =
02ade0
-"-----BEGIN DH PARAMETERS-----\n\
02ade0
-MEYCQQDaWDwW2YUiidDkr3VvTMqS3UvlM7gE+w/tlO+cikQD7VdGUNNpmdsp13Yn\n\
02ade0
-a6LT1BLiGPTdHghM9tgAPnxHdOgzAgEC\n\
02ade0
------END DH PARAMETERS-----\n";
02ade0
-
02ade0
-static const char tlso_dhpem1024[] =
02ade0
-"-----BEGIN DH PARAMETERS-----\n\
02ade0
-MIGHAoGBAJf2QmHKtQXdKCjhPx1ottPb0PMTBH9A6FbaWMsTuKG/K3g6TG1Z1fkq\n\
02ade0
-/Gz/PWk/eLI9TzFgqVAuPvr3q14a1aZeVUMTgo2oO5/y2UHe6VaJ+trqCTat3xlx\n\
02ade0
-/mNbIK9HA2RgPC3gWfVLZQrY+gz3ASHHR5nXWHEyvpuZm7m3h+irAgEC\n\
02ade0
------END DH PARAMETERS-----\n";
02ade0
-
02ade0
-static const char tlso_dhpem2048[] =
02ade0
-"-----BEGIN DH PARAMETERS-----\n\
02ade0
-MIIBCAKCAQEA7ZKJNYJFVcs7+6J2WmkEYb8h86tT0s0h2v94GRFS8Q7B4lW9aG9o\n\
02ade0
-AFO5Imov5Jo0H2XMWTKKvbHbSe3fpxJmw/0hBHAY8H/W91hRGXKCeyKpNBgdL8sh\n\
02ade0
-z22SrkO2qCnHJ6PLAMXy5fsKpFmFor2tRfCzrfnggTXu2YOzzK7q62bmqVdmufEo\n\
02ade0
-pT8igNcLpvZxk5uBDvhakObMym9mX3rAEBoe8PwttggMYiiw7NuJKO4MqD1llGkW\n\
02ade0
-aVM8U2ATsCun1IKHrRxynkE1/MJ86VHeYYX8GZt2YA8z+GuzylIOKcMH6JAWzMwA\n\
02ade0
-Gbatw6QwizOhr9iMjZ0B26TE3X8LvW84wwIBAg==\n\
02ade0
------END DH PARAMETERS-----\n";
02ade0
-
02ade0
-static const char tlso_dhpem4096[] =
02ade0
-"-----BEGIN DH PARAMETERS-----\n\
02ade0
-MIICCAKCAgEA/urRnb6vkPYc/KEGXWnbCIOaKitq7ySIq9dTH7s+Ri59zs77zty7\n\
02ade0
-vfVlSe6VFTBWgYjD2XKUFmtqq6CqXMhVX5ElUDoYDpAyTH85xqNFLzFC7nKrff/H\n\
02ade0
-TFKNttp22cZE9V0IPpzedPfnQkE7aUdmF9JnDyv21Z/818O93u1B4r0szdnmEvEF\n\
02ade0
-bKuIxEHX+bp0ZR7RqE1AeifXGJX3d6tsd2PMAObxwwsv55RGkn50vHO4QxtTARr1\n\
02ade0
-rRUV5j3B3oPMgC7Offxx+98Xn45B1/G0Prp11anDsR1PGwtaCYipqsvMwQUSJtyE\n\
02ade0
-EOQWk+yFkeMe4vWv367eEi0Sd/wnC+TSXBE3pYvpYerJ8n1MceI5GQTdarJ77OW9\n\
02ade0
-bGTHmxRsLSCM1jpLdPja5jjb4siAa6EHc4qN9c/iFKS3PQPJEnX7pXKBRs5f7AF3\n\
02ade0
-W3RIGt+G9IVNZfXaS7Z/iCpgzgvKCs0VeqN38QsJGtC1aIkwOeyjPNy2G6jJ4yqH\n\
02ade0
-ovXYt/0mc00vCWeSNS1wren0pR2EiLxX0ypjjgsU1mk/Z3b/+zVf7fZSIB+nDLjb\n\
02ade0
-NPtUlJCVGnAeBK1J1nG3TQicqowOXoM6ISkdaXj5GPJdXHab2+S7cqhKGv5qC7rR\n\
02ade0
-jT6sx7RUr0CNTxzLI7muV2/a4tGmj0PSdXQdsZ7tw7gbXlaWT1+MM2MCAQI=\n\
02ade0
------END DH PARAMETERS-----\n";
02ade0
-
02ade0
-static const struct dhinfo tlso_dhpem[] = {
02ade0
-	{ 512, tlso_dhpem512, sizeof(tlso_dhpem512) },
02ade0
-	{ 1024, tlso_dhpem1024, sizeof(tlso_dhpem1024) },
02ade0
-	{ 2048, tlso_dhpem2048, sizeof(tlso_dhpem2048) },
02ade0
-	{ 4096, tlso_dhpem4096, sizeof(tlso_dhpem4096) },
02ade0
-	{ 0, NULL, 0 }
02ade0
-};
02ade0
-
02ade0
-static DH *
02ade0
-tlso_tmp_dh_cb( SSL *ssl, int is_export, int key_length )
02ade0
-{
02ade0
-	struct dhplist *p = NULL;
02ade0
-	BIO *b = NULL;
02ade0
-	DH *dh = NULL;
02ade0
-	int i;
02ade0
-
02ade0
-	/* Do we have params of this length already? */
02ade0
-	LDAP_MUTEX_LOCK( &tlso_dh_mutex );
02ade0
-	for ( p = tlso_dhparams; p; p=p->next ) {
02ade0
-		if ( p->keylength == key_length ) {
02ade0
-			LDAP_MUTEX_UNLOCK( &tlso_dh_mutex );
02ade0
-			return p->param;
02ade0
-		}
02ade0
-	}
02ade0
-
02ade0
-	/* No - check for hardcoded params */
02ade0
-
02ade0
-	for (i=0; tlso_dhpem[i].keylength; i++) {
02ade0
-		if ( tlso_dhpem[i].keylength == key_length ) {
02ade0
-			b = BIO_new_mem_buf( (char *)tlso_dhpem[i].pem, tlso_dhpem[i].size );
02ade0
-			break;
02ade0
-		}
02ade0
-	}
02ade0
-
02ade0
-	if ( b ) {
02ade0
-		dh = PEM_read_bio_DHparams( b, NULL, NULL, NULL );
02ade0
-		BIO_free( b );
02ade0
-	}
02ade0
-
02ade0
-	/* Generating on the fly is expensive/slow... */
02ade0
-	if ( !dh ) {
02ade0
-		dh = DH_generate_parameters( key_length, DH_GENERATOR_2, NULL, NULL );
02ade0
-	}
02ade0
-	if ( dh ) {
02ade0
-		p = LDAP_MALLOC( sizeof(struct dhplist) );
02ade0
-		if ( p != NULL ) {
02ade0
-			p->keylength = key_length;
02ade0
-			p->param = dh;
02ade0
-			p->next = tlso_dhparams;
02ade0
-			tlso_dhparams = p;
02ade0
-		}
02ade0
-	}
02ade0
-
02ade0
-	LDAP_MUTEX_UNLOCK( &tlso_dh_mutex );
02ade0
-	return dh;
02ade0
-}
02ade0
 
02ade0
 tls_impl ldap_int_tls_impl = {
02ade0
 	"OpenSSL",