2 * Heirloom mailx - a mail user agent derived from Berkeley Mail.
4 * Copyright (c) 2000-2004 Gunnar Ritter, Freiburg i. Br., Germany.
5 * Copyright (c) 2012 Steffen "Daode" Nurpmeso.
9 * Gunnar Ritter. All rights reserved.
11 * Redistribution and use in source and binary forms, with or without
12 * modification, are permitted provided that the following conditions
14 * 1. Redistributions of source code must retain the above copyright
15 * notice, this list of conditions and the following disclaimer.
16 * 2. Redistributions in binary form must reproduce the above copyright
17 * notice, this list of conditions and the following disclaimer in the
18 * documentation and/or other materials provided with the distribution.
19 * 3. All advertising materials mentioning features or use of this software
20 * must display the following acknowledgement:
21 * This product includes software developed by Gunnar Ritter
22 * and his contributors.
23 * 4. Neither the name of Gunnar Ritter nor the names of his contributors
24 * may be used to endorse or promote products derived from this software
25 * without specific prior written permission.
27 * THIS SOFTWARE IS PROVIDED BY GUNNAR RITTER AND CONTRIBUTORS ``AS IS'' AND
28 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
29 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
30 * ARE DISCLAIMED. IN NO EVENT SHALL GUNNAR RITTER OR CONTRIBUTORS BE LIABLE
31 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
32 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
33 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
34 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
35 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
36 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
42 static char sccsid
[] = "@(#)openssl.c 1.26 (gritter) 5/26/09";
49 typedef int avoid_empty_file_compiler_warning
;
50 #elif defined USE_OPENSSL
58 static struct termios otio
;
59 static sigjmp_buf ssljmp
;
61 #include <openssl/crypto.h>
62 #include <openssl/ssl.h>
63 #include <openssl/err.h>
64 #include <openssl/x509v3.h>
65 #include <openssl/x509.h>
66 #include <openssl/pem.h>
67 #include <openssl/rand.h>
75 #include <sys/socket.h>
77 #include <netinet/in.h>
78 #ifdef HAVE_ARPA_INET_H
79 #include <arpa/inet.h>
80 #endif /* HAVE_ARPA_INET_H */
87 * Mail -- a mail program
93 * OpenSSL client implementation according to: John Viega, Matt Messier,
94 * Pravir Chandra: Network Security with OpenSSL. Sebastopol, CA 2002.
97 static int initialized
;
99 static int message_number
;
100 static int verify_error_found
;
102 static void sslcatch(int s
);
103 static int ssl_rand_init(void);
104 static void ssl_init(void);
105 static int ssl_verify_cb(int success
, X509_STORE_CTX
*store
);
106 static const SSL_METHOD
*ssl_select_method(const char *uhp
);
107 static void ssl_load_verifications(struct sock
*sp
);
108 static void ssl_certificate(struct sock
*sp
, const char *uhp
);
109 static enum okay
ssl_check_host(const char *server
, struct sock
*sp
);
111 static int smime_verify(struct message
*m
, int n
, STACK_OF(X509
) *chain
,
114 static int smime_verify(struct message
*m
, int n
, STACK
*chain
,
117 static EVP_CIPHER
*smime_cipher(const char *name
);
118 static int ssl_password_cb(char *buf
, int size
, int rwflag
, void *userdata
);
119 static FILE *smime_sign_cert(const char *xname
, const char *xname2
, int warn
);
120 static char *smime_sign_include_certs(char *name
);
122 static int smime_sign_include_chain_creat(STACK_OF(X509
) **chain
, char *cfiles
);
124 static int smime_sign_include_chain_creat(STACK
**chain
, char *cfiles
);
126 #if defined (X509_V_FLAG_CRL_CHECK) && defined (X509_V_FLAG_CRL_CHECK_ALL)
127 static enum okay
load_crl1(X509_STORE
*store
, const char *name
);
129 static enum okay
load_crls(X509_STORE
*store
, const char *vfile
,
136 tcsetattr(0, TCSADRAIN
, &otio
);
137 siglongjmp(ssljmp
, s
);
146 if ((cp
= value("ssl-rand-egd")) != NULL
) {
148 if (RAND_egd(cp
) == -1) {
149 fprintf(stderr
, catgets(catd
, CATSET
, 245,
150 "entropy daemon at \"%s\" not available\n"),
154 } else if ((cp
= value("ssl-rand-file")) != NULL
) {
156 if (RAND_load_file(cp
, 1024) == -1) {
157 fprintf(stderr
, catgets(catd
, CATSET
, 246,
158 "entropy file at \"%s\" not available\n"), cp
);
162 if (stat(cp
, &st
) == 0 && S_ISREG(st
.st_mode
) &&
163 access(cp
, W_OK
) == 0) {
164 if (RAND_write_file(cp
) == -1) {
165 fprintf(stderr
, catgets(catd
, CATSET
,
167 "writing entropy data to \"%s\" failed\n"), cp
);
179 verbose
= value("verbose") != NULL
;
180 if (initialized
== 0) {
185 rand_init
= ssl_rand_init();
189 ssl_verify_cb(int success
, X509_STORE_CTX
*store
)
193 X509
*cert
= X509_STORE_CTX_get_current_cert(store
);
194 int depth
= X509_STORE_CTX_get_error_depth(store
);
195 int err
= X509_STORE_CTX_get_error(store
);
197 verify_error_found
= 1;
199 fprintf(stderr
, "Message %d: ", message_number
);
200 fprintf(stderr
, catgets(catd
, CATSET
, 229,
201 "Error with certificate at depth: %i\n"),
203 X509_NAME_oneline(X509_get_issuer_name(cert
), data
,
205 fprintf(stderr
, catgets(catd
, CATSET
, 230, " issuer = %s\n"),
207 X509_NAME_oneline(X509_get_subject_name(cert
), data
,
209 fprintf(stderr
, catgets(catd
, CATSET
, 231, " subject = %s\n"),
211 fprintf(stderr
, catgets(catd
, CATSET
, 232, " err %i: %s\n"),
212 err
, X509_verify_cert_error_string(err
));
213 if (ssl_vrfy_decide() != OKAY
)
219 static const SSL_METHOD
*
220 ssl_select_method(const char *uhp
)
222 const SSL_METHOD
*method
;
225 cp
= ssl_method_string(uhp
);
227 #ifndef OPENSSL_NO_SSL2
228 if (equal(cp
, "ssl2"))
229 method
= SSLv2_client_method();
232 if (equal(cp
, "ssl3"))
233 method
= SSLv3_client_method();
234 else if (equal(cp
, "tls1"))
235 method
= TLSv1_client_method();
237 fprintf(stderr
, catgets(catd
, CATSET
, 244,
238 "Invalid SSL method \"%s\"\n"), cp
);
239 method
= SSLv23_client_method();
242 method
= SSLv23_client_method();
247 ssl_load_verifications(struct sock
*sp
)
249 char *ca_dir
, *ca_file
;
252 if (ssl_vrfy_level
== VRFY_IGNORE
)
254 if ((ca_dir
= value("ssl-ca-dir")) != NULL
)
255 ca_dir
= expand(ca_dir
);
256 if ((ca_file
= value("ssl-ca-file")) != NULL
)
257 ca_file
= expand(ca_file
);
258 if (ca_dir
|| ca_file
) {
259 if (SSL_CTX_load_verify_locations(sp
->s_ctx
,
260 ca_file
, ca_dir
) != 1) {
261 fprintf(stderr
, catgets(catd
, CATSET
, 233,
264 fprintf(stderr
, catgets(catd
, CATSET
, 234,
267 fprintf(stderr
, catgets(catd
, CATSET
,
271 fprintf(stderr
, catgets(catd
, CATSET
, 236,
273 fprintf(stderr
, catgets(catd
, CATSET
, 237, "\n"));
276 if (value("ssl-no-default-ca") == NULL
) {
277 if (SSL_CTX_set_default_verify_paths(sp
->s_ctx
) != 1)
278 fprintf(stderr
, catgets(catd
, CATSET
, 243,
279 "Error loading default CA locations\n"));
281 verify_error_found
= 0;
283 SSL_CTX_set_verify(sp
->s_ctx
, SSL_VERIFY_PEER
, ssl_verify_cb
);
284 store
= SSL_CTX_get_cert_store(sp
->s_ctx
);
285 load_crls(store
, "ssl-crl-file", "ssl-crl-dir");
289 ssl_certificate(struct sock
*sp
, const char *uhp
)
291 char *certvar
, *keyvar
, *cert
, *key
;
293 certvar
= ac_alloc(strlen(uhp
) + 10);
294 strcpy(certvar
, "ssl-cert-");
295 strcpy(&certvar
[9], uhp
);
296 if ((cert
= value(certvar
)) != NULL
||
297 (cert
= value("ssl-cert")) != NULL
) {
299 if (SSL_CTX_use_certificate_chain_file(sp
->s_ctx
, cert
) == 1) {
300 keyvar
= ac_alloc(strlen(uhp
) + 9);
301 strcpy(keyvar
, "ssl-key-");
302 if ((key
= value(keyvar
)) == NULL
&&
303 (key
= value("ssl-key")) == NULL
)
307 if (SSL_CTX_use_PrivateKey_file(sp
->s_ctx
, key
,
308 SSL_FILETYPE_PEM
) != 1)
309 fprintf(stderr
, catgets(catd
, CATSET
, 238,
310 "cannot load private key from file %s\n"),
314 fprintf(stderr
, catgets(catd
, CATSET
, 239,
315 "cannot load certificate from file %s\n"),
322 ssl_check_host(const char *server
, struct sock
*sp
)
328 STACK_OF(GENERAL_NAME
) *gens
;
330 /*GENERAL_NAMES*/STACK
*gens
;
335 if ((cert
= SSL_get_peer_certificate(sp
->s_ssl
)) == NULL
) {
336 fprintf(stderr
, catgets(catd
, CATSET
, 248,
337 "no certificate from \"%s\"\n"), server
);
340 gens
= X509_get_ext_d2i(cert
, NID_subject_alt_name
, NULL
, NULL
);
342 for (i
= 0; i
< sk_GENERAL_NAME_num(gens
); i
++) {
343 gen
= sk_GENERAL_NAME_value(gens
, i
);
344 if (gen
->type
== GEN_DNS
) {
347 "Comparing DNS name: \"%s\"\n",
349 if (rfc2595_hostname_match(server
,
350 (char *)gen
->d
.ia5
->data
)
356 if ((subj
= X509_get_subject_name(cert
)) != NULL
&&
357 X509_NAME_get_text_by_NID(subj
, NID_commonName
,
358 data
, sizeof data
) > 0) {
359 data
[sizeof data
- 1] = 0;
361 fprintf(stderr
, "Comparing common name: \"%s\"\n",
363 if (rfc2595_hostname_match(server
, data
) == OKAY
)
368 found
: X509_free(cert
);
373 ssl_open(const char *server
, struct sock
*sp
, const char *uhp
)
379 ssl_set_vrfy_level(uhp
);
381 SSL_CTX_new((SSL_METHOD
*)ssl_select_method(uhp
))) == NULL
) {
382 ssl_gen_err(catgets(catd
, CATSET
, 261, "SSL_CTX_new() failed"));
385 #ifdef SSL_MODE_AUTO_RETRY
386 /* available with OpenSSL 0.9.6 or later */
387 SSL_CTX_set_mode(sp
->s_ctx
, SSL_MODE_AUTO_RETRY
);
388 #endif /* SSL_MODE_AUTO_RETRY */
389 options
= SSL_OP_ALL
;
390 if (value("ssl-v2-allow") == NULL
)
391 options
|= SSL_OP_NO_SSLv2
;
392 SSL_CTX_set_options(sp
->s_ctx
, options
);
393 ssl_load_verifications(sp
);
394 ssl_certificate(sp
, uhp
);
395 if ((cp
= value("ssl-cipher-list")) != NULL
) {
396 if (SSL_CTX_set_cipher_list(sp
->s_ctx
, cp
) != 1)
397 fprintf(stderr
, catgets(catd
, CATSET
, 240,
398 "invalid ciphers: %s\n"), cp
);
400 if ((sp
->s_ssl
= SSL_new(sp
->s_ctx
)) == NULL
) {
401 ssl_gen_err(catgets(catd
, CATSET
, 262, "SSL_new() failed"));
404 SSL_set_fd(sp
->s_ssl
, sp
->s_fd
);
405 if (SSL_connect(sp
->s_ssl
) < 0) {
406 ssl_gen_err(catgets(catd
, CATSET
, 263,
407 "could not initiate SSL/TLS connection"));
410 if (ssl_vrfy_level
!= VRFY_IGNORE
) {
411 if (ssl_check_host(server
, sp
) != OKAY
) {
412 fprintf(stderr
, catgets(catd
, CATSET
, 249,
413 "host certificate does not match \"%s\"\n"),
415 if (ssl_vrfy_decide() != OKAY
)
424 ssl_gen_err(const char *fmt
, ...)
429 vfprintf(stderr
, fmt
, ap
);
431 SSL_load_error_strings();
432 fprintf(stderr
, ": %s\n",
433 (ERR_error_string(ERR_get_error(), NULL
)));
437 smime_sign(FILE *ip
, struct header
*headp
)
439 FILE *sp
, *fp
, *bp
, *hp
;
443 STACK_OF(X509
) *chain
= NULL
;
452 if ((addr
= myorigin(headp
)) == NULL
) {
453 fprintf(stderr
, "No \"from\" address for signing specified\n");
456 if ((fp
= smime_sign_cert(addr
, NULL
, 1)) == NULL
)
458 if ((pkey
= PEM_read_PrivateKey(fp
, NULL
, ssl_password_cb
, NULL
))
460 ssl_gen_err("Error reading private key from");
465 if ((cert
= PEM_read_X509(fp
, NULL
, ssl_password_cb
, NULL
)) == NULL
) {
466 ssl_gen_err("Error reading signer certificate from");
472 if ((cp
= smime_sign_include_certs(addr
)) != NULL
&&
473 !smime_sign_include_chain_creat(&chain
, cp
)) {
478 if ((sp
= Ftemp(&cp
, "Rs", "w+", 0600, 1)) == NULL
) {
481 sk_X509_pop_free(chain
, X509_free
);
489 if (smime_split(ip
, &hp
, &bp
, -1, 0) == STOP
) {
492 sk_X509_pop_free(chain
, X509_free
);
497 if ((bb
= BIO_new_fp(bp
, BIO_NOCLOSE
)) == NULL
||
498 (sb
= BIO_new_fp(sp
, BIO_NOCLOSE
)) == NULL
) {
499 ssl_gen_err("Error creating BIO signing objects");
502 sk_X509_pop_free(chain
, X509_free
);
507 if ((pkcs7
= PKCS7_sign(cert
, pkey
, chain
, bb
,
508 PKCS7_DETACHED
)) == NULL
) {
509 ssl_gen_err("Error creating the PKCS#7 signing object");
514 sk_X509_pop_free(chain
, X509_free
);
519 if (PEM_write_bio_PKCS7(sb
, pkcs7
) == 0) {
520 ssl_gen_err("Error writing signed S/MIME data");
525 sk_X509_pop_free(chain
, X509_free
);
533 sk_X509_pop_free(chain
, X509_free
);
539 return smime_sign_assemble(hp
, bp
, sp
);
544 smime_verify(struct message
*m
, int n
, STACK_OF(X509
) *chain
, X509_STORE
*store
)
546 smime_verify(struct message
*m
, int n
, STACK
*chain
, X509_STORE
*store
)
550 char *cp
, *sender
, *to
, *cc
, *cnttype
;
557 STACK_OF(X509
) *certs
;
558 STACK_OF(GENERAL_NAME
) *gens
;
567 verify_error_found
= 0;
569 loop
: sender
= getsender(m
);
570 to
= hfield("to", m
);
571 cc
= hfield("cc", m
);
572 cnttype
= hfield("content-type", m
);
573 if ((ip
= setinput(&mb
, m
, NEED_BODY
)) == NULL
)
575 if (cnttype
&& strncmp(cnttype
, "application/x-pkcs7-mime", 24) == 0) {
576 if ((x
= smime_decrypt(m
, to
, cc
, 1)) == NULL
)
578 if (x
!= (struct message
*)-1) {
584 if ((fp
= Ftemp(&cp
, "Rv", "w+", 0600, 1)) == NULL
) {
596 if ((fb
= BIO_new_fp(fp
, BIO_NOCLOSE
)) == NULL
) {
597 ssl_gen_err("Error creating BIO verification object "
598 "for message %d", n
);
602 if ((pkcs7
= SMIME_read_PKCS7(fb
, &pb
)) == NULL
) {
603 ssl_gen_err("Error reading PKCS#7 object for message %d", n
);
608 if (PKCS7_verify(pkcs7
, chain
, store
, pb
, NULL
, 0) != 1) {
609 ssl_gen_err("Error verifying message %d", n
);
616 if (sender
== NULL
) {
618 "Warning: Message %d has no sender.\n", n
);
621 certs
= PKCS7_get0_signers(pkcs7
, chain
, 0);
623 fprintf(stderr
, "No certificates found in message %d.\n", n
);
626 for (i
= 0; i
< sk_X509_num(certs
); i
++) {
627 cert
= sk_X509_value(certs
, i
);
628 gens
= X509_get_ext_d2i(cert
, NID_subject_alt_name
, NULL
, NULL
);
630 for (j
= 0; j
< sk_GENERAL_NAME_num(gens
); j
++) {
631 gen
= sk_GENERAL_NAME_value(gens
, j
);
632 if (gen
->type
== GEN_EMAIL
) {
638 if (!asccasecmp((char *)
645 if ((subj
= X509_get_subject_name(cert
)) != NULL
&&
646 X509_NAME_get_text_by_NID(subj
,
647 NID_pkcs9_emailAddress
,
648 data
, sizeof data
) > 0) {
649 data
[sizeof data
- 1] = 0;
651 fprintf(stderr
, "Comparing address: \"%s\"\n",
653 if (asccasecmp(data
, sender
) == 0)
657 fprintf(stderr
, "Message %d: certificate does not match <%s>\n",
660 found
: if (verify_error_found
== 0)
661 printf("Message %d was verified successfully.\n", n
);
662 return verify_error_found
;
668 int *msgvec
= vp
, *ip
;
671 STACK_OF(X509
) *chain
= NULL
;
676 char *ca_dir
, *ca_file
;
679 ssl_vrfy_level
= VRFY_STRICT
;
680 if ((store
= X509_STORE_new()) == NULL
) {
681 ssl_gen_err("Error creating X509 store");
684 X509_STORE_set_verify_cb_func(store
, ssl_verify_cb
);
685 if ((ca_dir
= value("smime-ca-dir")) != NULL
)
686 ca_dir
= expand(ca_dir
);
687 if ((ca_file
= value("smime-ca-file")) != NULL
)
688 ca_file
= expand(ca_file
);
689 if (ca_dir
|| ca_file
) {
690 if (X509_STORE_load_locations(store
, ca_file
, ca_dir
) != 1) {
691 ssl_gen_err("Error loading %s",
692 ca_file
? ca_file
: ca_dir
);
696 if (value("smime-no-default-ca") == NULL
) {
697 if (X509_STORE_set_default_paths(store
) != 1) {
698 ssl_gen_err("Error loading default CA locations");
702 if (load_crls(store
, "smime-crl-file", "smime-crl-dir") != OKAY
)
704 for (ip
= msgvec
; *ip
; ip
++) {
705 setdot(&message
[*ip
-1]);
706 ec
|= smime_verify(&message
[*ip
-1], *ip
, chain
, store
);
712 smime_cipher(const char *name
)
714 const EVP_CIPHER
*cipher
;
718 vn
= ac_alloc(vs
= strlen(name
) + 30);
719 snprintf(vn
, vs
, "smime-cipher-%s", name
);
720 if ((cp
= value(vn
)) != NULL
) {
721 if (strcmp(cp
, "rc2-40") == 0)
722 cipher
= EVP_rc2_40_cbc();
723 else if (strcmp(cp
, "rc2-64") == 0)
724 cipher
= EVP_rc2_64_cbc();
725 else if (strcmp(cp
, "des") == 0)
726 cipher
= EVP_des_cbc();
727 else if (strcmp(cp
, "des-ede3") == 0)
728 cipher
= EVP_des_ede3_cbc();
730 fprintf(stderr
, "Invalid cipher \"%s\".\n", cp
);
734 cipher
= EVP_des_ede3_cbc();
736 return (EVP_CIPHER
*)cipher
;
740 smime_encrypt(FILE *ip
, const char *certfile
, const char *to
)
742 FILE *yp
, *fp
, *bp
, *hp
;
748 STACK_OF(X509
) *certs
;
754 certfile
= expand((char *)certfile
);
756 if ((cipher
= smime_cipher(to
)) == NULL
)
758 if ((fp
= Fopen(certfile
, "r")) == NULL
) {
762 if ((cert
= PEM_read_X509(fp
, NULL
, ssl_password_cb
, NULL
)) == NULL
) {
763 ssl_gen_err("Error reading encryption certificate from \"%s\"",
769 certs
= sk_X509_new_null();
770 sk_X509_push(certs
, cert
);
771 if ((yp
= Ftemp(&cp
, "Ry", "w+", 0600, 1)) == NULL
) {
778 if (smime_split(ip
, &hp
, &bp
, -1, 0) == STOP
) {
782 if ((bb
= BIO_new_fp(bp
, BIO_NOCLOSE
)) == NULL
||
783 (yb
= BIO_new_fp(yp
, BIO_NOCLOSE
)) == NULL
) {
784 ssl_gen_err("Error creating BIO encryption objects");
788 if ((pkcs7
= PKCS7_encrypt(certs
, bb
, cipher
, 0)) == NULL
) {
789 ssl_gen_err("Error creating the PKCS#7 encryption object");
795 if (PEM_write_bio_PKCS7(yb
, pkcs7
) == 0) {
796 ssl_gen_err("Error writing encrypted S/MIME data");
807 return smime_encrypt_assemble(hp
, yp
);
811 smime_decrypt(struct message
*m
, const char *to
, const char *cc
, int signcall
)
813 FILE *fp
, *bp
, *hp
, *op
;
817 EVP_PKEY
*pkey
= NULL
;
819 long size
= m
->m_size
;
822 if ((yp
= setinput(&mb
, m
, NEED_BODY
)) == NULL
)
825 if ((fp
= smime_sign_cert(to
, cc
, 0)) != NULL
) {
826 if ((pkey
= PEM_read_PrivateKey(fp
, NULL
, ssl_password_cb
,
828 ssl_gen_err("Error reading private key");
833 if ((cert
= PEM_read_X509(fp
, NULL
, ssl_password_cb
,
835 ssl_gen_err("Error reading decryption certificate");
842 if ((op
= Ftemp(&cp
, "Rp", "w+", 0600, 1)) == NULL
) {
852 if (smime_split(yp
, &hp
, &bp
, size
, 1) == STOP
) {
860 if ((ob
= BIO_new_fp(op
, BIO_NOCLOSE
)) == NULL
||
861 (bb
= BIO_new_fp(bp
, BIO_NOCLOSE
)) == NULL
) {
862 ssl_gen_err("Error creating BIO decryption objects");
870 if ((pkcs7
= SMIME_read_PKCS7(bb
, &pb
)) == NULL
) {
871 ssl_gen_err("Error reading PKCS#7 object");
879 if (PKCS7_type_is_signed(pkcs7
)) {
890 setinput(&mb
, m
, NEED_BODY
);
891 return (struct message
*)-1;
893 if (PKCS7_verify(pkcs7
, NULL
, NULL
, NULL
, ob
,
894 PKCS7_NOVERIFY
|PKCS7_NOSIGS
) != 1)
896 fseek(hp
, 0L, SEEK_END
);
897 fprintf(hp
, "X-Encryption-Cipher: none\n");
900 } else if (pkey
== NULL
) {
901 fprintf(stderr
, "No appropriate private key found.\n");
903 } else if (cert
== NULL
) {
904 fprintf(stderr
, "No appropriate certificate found.\n");
906 } else if (PKCS7_decrypt(pkcs7
, pkey
, cert
, ob
, 0) != 1) {
907 err
: ssl_gen_err("Error decrypting PKCS#7 object");
928 return smime_decrypt_assemble(m
, hp
, op
);
933 ssl_password_cb(char *buf
, int size
, int rwflag
, void *userdata
)
935 sighandler_type saveint
;
941 saveint
= safe_signal(SIGINT
, SIG_IGN
);
942 if (sigsetjmp(ssljmp
, 1) == 0) {
943 if (saveint
!= SIG_IGN
)
944 safe_signal(SIGINT
, sslcatch
);
945 pass
= getpassword(&otio
, &reset_tio
, "PEM pass phrase:");
947 safe_signal(SIGINT
, saveint
);
953 memcpy(buf
, pass
, len
);
958 smime_sign_cert(const char *xname
, const char *xname2
, int warn
)
964 const char *name
= xname
, *name2
= xname2
;
967 np
= sextract(savestr(name
), GTO
|GSKIN
);
970 * This needs to be more intelligent since it will
971 * currently take the first name for which a private
972 * key is available regardless of whether it is the
973 * right one for the message.
975 vn
= ac_alloc(vs
= strlen(np
->n_name
) + 30);
976 snprintf(vn
, vs
, "smime-sign-cert-%s", np
->n_name
);
977 if ((cp
= value(vn
)) != NULL
)
987 if ((cp
= value("smime-sign-cert")) != NULL
)
990 fprintf(stderr
, "Could not find a certificate for %s", xname
);
992 fprintf(stderr
, "or %s", xname2
);
996 open
: cp
= expand(cp
);
997 if ((fp
= Fopen(cp
, "r")) == NULL
) {
1005 smime_sign_include_certs(char *name
)
1007 /* See comments in smime_sign_cert() for algorithm pitfalls */
1009 struct name
*np
= sextract(savestr(name
), GTO
|GSKIN
);
1012 char *vn
= ac_alloc(vs
= strlen(np
->n_name
) + 30);
1013 snprintf(vn
, vs
, "smime-sign-include-certs-%s",
1015 if ((name
= value(vn
)) != NULL
)
1020 return value("smime-sign-include-certs");
1024 smime_sign_include_chain_creat(
1025 #ifdef HAVE_STACK_OF
1026 STACK_OF(X509
) **chain
,
1032 *chain
= sk_X509_new_null();
1037 char *exp
, *ncf
= strchr(cfiles
, ',');
1040 /* This fails for '=,file' constructs, but those are sick */
1044 if ((exp
= expand(cfiles
)) != NULL
)
1046 if ((fp
= Fopen(cfiles
, "r")) == NULL
) {
1050 if ((tmp
= PEM_read_X509(fp
, NULL
, ssl_password_cb
, NULL
)
1052 ssl_gen_err("Error reading certificate from \"%s\"",
1057 sk_X509_push(*chain
, tmp
);
1065 if (sk_X509_num(*chain
) == 0) {
1066 fprintf(stderr
, "smime-sign-include-certs defined but empty\n");
1070 jleave
: return (*chain
!= NULL
);
1072 jerr
: sk_X509_pop_free(*chain
, X509_free
);
1078 smime_certsave(struct message
*m
, int n
, FILE *op
)
1081 char *cp
, *to
, *cc
, *cnttype
;
1087 #ifdef HAVE_STACK_OF
1088 STACK_OF(X509
) *certs
;
1089 STACK_OF(X509
) *chain
= NULL
;
1092 STACK
*chain
= NULL
;
1095 enum okay ok
= OKAY
;
1098 loop
: to
= hfield("to", m
);
1099 cc
= hfield("cc", m
);
1100 cnttype
= hfield("content-type", m
);
1101 if ((ip
= setinput(&mb
, m
, NEED_BODY
)) == NULL
)
1103 if (cnttype
&& strncmp(cnttype
, "application/x-pkcs7-mime", 24) == 0) {
1104 if ((x
= smime_decrypt(m
, to
, cc
, 1)) == NULL
)
1106 if (x
!= (struct message
*)-1) {
1112 if ((fp
= Ftemp(&cp
, "Rv", "w+", 0600, 1)) == NULL
) {
1118 while (size
-- > 0) {
1124 if ((fb
= BIO_new_fp(fp
, BIO_NOCLOSE
)) == NULL
) {
1125 ssl_gen_err("Error creating BIO object for message %d", n
);
1129 if ((pkcs7
= SMIME_read_PKCS7(fb
, &pb
)) == NULL
) {
1130 ssl_gen_err("Error reading PKCS#7 object for message %d", n
);
1137 certs
= PKCS7_get0_signers(pkcs7
, chain
, 0);
1138 if (certs
== NULL
) {
1139 fprintf(stderr
, "No certificates found in message %d.\n", n
);
1142 for (i
= 0; i
< sk_X509_num(certs
); i
++) {
1143 cert
= sk_X509_value(certs
, i
);
1144 if (X509_print_fp(op
, cert
) == 0 ||
1145 PEM_write_X509(op
, cert
) == 0) {
1146 ssl_gen_err("Error writing certificate %d from "
1147 "message %d", i
, n
);
1154 #if defined (X509_V_FLAG_CRL_CHECK) && defined (X509_V_FLAG_CRL_CHECK_ALL)
1156 load_crl1(X509_STORE
*store
, const char *name
)
1158 X509_LOOKUP
*lookup
;
1161 printf("Loading CRL from \"%s\".\n", name
);
1162 if ((lookup
= X509_STORE_add_lookup(store
,
1163 X509_LOOKUP_file())) == NULL
) {
1164 ssl_gen_err("Error creating X509 lookup object");
1167 if (X509_load_crl_file(lookup
, name
, X509_FILETYPE_PEM
) != 1) {
1168 ssl_gen_err("Error loading CRL from \"%s\"", name
);
1173 #endif /* new OpenSSL */
1176 load_crls(X509_STORE
*store
, const char *vfile
, const char *vdir
)
1178 char *crl_file
, *crl_dir
;
1179 #if defined (X509_V_FLAG_CRL_CHECK) && defined (X509_V_FLAG_CRL_CHECK_ALL)
1184 #endif /* new OpenSSL */
1186 if ((crl_file
= value(vfile
)) != NULL
) {
1187 #if defined (X509_V_FLAG_CRL_CHECK) && defined (X509_V_FLAG_CRL_CHECK_ALL)
1188 crl_file
= expand(crl_file
);
1189 if (load_crl1(store
, crl_file
) != OKAY
)
1191 #else /* old OpenSSL */
1193 "This OpenSSL version is too old to use CRLs.\n");
1195 #endif /* old OpenSSL */
1197 if ((crl_dir
= value(vdir
)) != NULL
) {
1198 #if defined (X509_V_FLAG_CRL_CHECK) && defined (X509_V_FLAG_CRL_CHECK_ALL)
1199 crl_dir
= expand(crl_dir
);
1200 ds
= strlen(crl_dir
);
1201 if ((dirfd
= opendir(crl_dir
)) == NULL
) {
1205 fn
= smalloc(fs
= ds
+ 20);
1206 strcpy(fn
, crl_dir
);
1208 while ((dp
= readdir(dirfd
)) != NULL
) {
1209 if (dp
->d_name
[0] == '.' &&
1210 (dp
->d_name
[1] == '\0' ||
1211 (dp
->d_name
[1] == '.' &&
1212 dp
->d_name
[2] == '\0')))
1214 if (dp
->d_name
[0] == '.')
1216 if (ds
+ (es
= strlen(dp
->d_name
)) + 2 < fs
)
1217 fn
= srealloc(fn
, fs
= ds
+ es
+ 20);
1218 strcpy(&fn
[ds
+1], dp
->d_name
);
1219 if (load_crl1(store
, fn
) != OKAY
) {
1227 #else /* old OpenSSL */
1229 "This OpenSSL version is too old to use CRLs.\n");
1231 #endif /* old OpenSSL */
1233 #if defined (X509_V_FLAG_CRL_CHECK) && defined (X509_V_FLAG_CRL_CHECK_ALL)
1234 if (crl_file
|| crl_dir
)
1235 X509_STORE_set_flags(store
, X509_V_FLAG_CRL_CHECK
|
1236 X509_V_FLAG_CRL_CHECK_ALL
);
1237 #endif /* old OpenSSL */
1241 #else /* !NSS && !USE_OPENSSL */
1248 fprintf(stderr
, "No S/MIME support compiled in.\n");
1253 smime_sign(FILE *fp
)
1271 smime_encrypt(FILE *fp
, const char *certfile
, const char *to
)
1282 smime_decrypt(struct message
*m
, const char *to
, const char *cc
, int signcall
)
1300 #endif /* !USE_NSS && !USE_OPENSSL */