1 /* $NetBSD: tls_proxy_client_print.c,v 1.6 2026/05/09 18:49:21 christos Exp $ */ 2 3 /*++ 4 /* NAME 5 /* tls_proxy_client_print 3 6 /* SUMMARY 7 /* write TLS_CLIENT_XXX structures to stream 8 /* SYNOPSIS 9 /* #include <tls_proxy.h> 10 /* 11 /* int tls_proxy_client_param_print(print_fn, stream, flags, ptr) 12 /* ATTR_PRINT_COMMON_FN print_fn; 13 /* VSTREAM *stream; 14 /* int flags; 15 /* const void *ptr; 16 /* 17 /* int tls_proxy_client_init_print(print_fn, stream, flags, ptr) 18 /* ATTR_PRINT_COMMON_FN print_fn; 19 /* VSTREAM *stream; 20 /* int flags; 21 /* const void *ptr; 22 /* 23 /* int tls_proxy_client_start_print(print_fn, stream, flags, ptr) 24 /* ATTR_PRINT_COMMON_FN print_fn; 25 /* VSTREAM *stream; 26 /* int flags; 27 /* const void *ptr; 28 /* DESCRIPTION 29 /* tls_proxy_client_param_print() writes a TLS_CLIENT_PARAMS structure to 30 /* the named stream using the specified attribute print routine. 31 /* tls_proxy_client_param_print() is meant to be passed as a call-back to 32 /* attr_print(), thusly: 33 /* 34 /* SEND_ATTR_FUNC(tls_proxy_client_param_print, (const void *) param), ... 35 /* 36 /* tls_proxy_client_init_print() writes a full TLS_CLIENT_INIT_PROPS 37 /* structure to the named stream using the specified attribute 38 /* print routine. tls_proxy_client_init_print() is meant to 39 /* be passed as a call-back to attr_print(), thusly: 40 /* 41 /* SEND_ATTR_FUNC(tls_proxy_client_init_print, (const void *) init_props), ... 42 /* 43 /* tls_proxy_client_start_print() writes a TLS_CLIENT_START_PROPS 44 /* structure, without stream or file descriptor members, to 45 /* the named stream using the specified attribute print routine. 46 /* tls_proxy_client_start_print() is meant to be passed as a 47 /* call-back to attr_print(), thusly: 48 /* 49 /* SEND_ATTR_FUNC(tls_proxy_client_start_print, (const void *) start_props), ... 50 /* DIAGNOSTICS 51 /* Fatal: out of memory. 52 /* LICENSE 53 /* .ad 54 /* .fi 55 /* The Secure Mailer license must be distributed with this software. 56 /* AUTHOR(S) 57 /* Wietse Venema 58 /* Google, Inc. 59 /* 111 8th Avenue 60 /* New York, NY 10011, USA 61 /*--*/ 62 63 #ifdef USE_TLS 64 65 /* System library. */ 66 67 #include <sys_defs.h> 68 69 /* Utility library */ 70 71 #include <argv_attr.h> 72 #include <attr.h> 73 #include <msg.h> 74 75 /* Global library. */ 76 77 #include <mail_params.h> 78 79 /* TLS library. */ 80 81 #include <tls.h> 82 #include <tls_proxy.h> 83 84 #ifdef USE_TLSRPT 85 #define TLSRPT_WRAPPER_INTERNAL 86 #include <tlsrpt_wrapper.h> 87 #endif 88 89 #define STR(x) vstring_str(x) 90 #define LEN(x) VSTRING_LEN(x) 91 92 /* tls_proxy_client_param_print - send TLS_CLIENT_PARAMS over stream */ 93 94 int tls_proxy_client_param_print(ATTR_PRINT_COMMON_FN print_fn, VSTREAM *fp, 95 int flags, const void *ptr) 96 { 97 const TLS_CLIENT_PARAMS *params = (const TLS_CLIENT_PARAMS *) ptr; 98 int ret; 99 100 if (msg_verbose) 101 msg_info("begin tls_proxy_client_param_print"); 102 103 ret = print_fn(fp, flags | ATTR_FLAG_MORE, 104 SEND_ATTR_STR(TLS_ATTR_CNF_FILE, params->tls_cnf_file), 105 SEND_ATTR_STR(TLS_ATTR_CNF_NAME, params->tls_cnf_name), 106 SEND_ATTR_STR(VAR_TLS_HIGH_CLIST, params->tls_high_clist), 107 SEND_ATTR_STR(VAR_TLS_MEDIUM_CLIST, 108 params->tls_medium_clist), 109 SEND_ATTR_STR(VAR_TLS_NULL_CLIST, params->tls_null_clist), 110 SEND_ATTR_STR(VAR_TLS_EECDH_AUTO, params->tls_eecdh_auto), 111 SEND_ATTR_STR(VAR_TLS_EECDH_STRONG, 112 params->tls_eecdh_strong), 113 SEND_ATTR_STR(VAR_TLS_EECDH_ULTRA, 114 params->tls_eecdh_ultra), 115 SEND_ATTR_STR(VAR_TLS_FFDHE_AUTO, params->tls_ffdhe_auto), 116 SEND_ATTR_STR(VAR_TLS_BUG_TWEAKS, params->tls_bug_tweaks), 117 SEND_ATTR_STR(VAR_TLS_SSL_OPTIONS, 118 params->tls_ssl_options), 119 SEND_ATTR_STR(VAR_TLS_DANE_DIGESTS, 120 params->tls_dane_digests), 121 SEND_ATTR_STR(VAR_TLS_MGR_SERVICE, 122 params->tls_mgr_service), 123 SEND_ATTR_STR(VAR_TLS_TKT_CIPHER, params->tls_tkt_cipher), 124 SEND_ATTR_INT(VAR_TLS_DAEMON_RAND_BYTES, 125 params->tls_daemon_rand_bytes), 126 SEND_ATTR_INT(VAR_TLS_APPEND_DEF_CA, 127 params->tls_append_def_CA), 128 SEND_ATTR_INT(VAR_TLS_PREEMPT_CLIST, 129 params->tls_preempt_clist), 130 SEND_ATTR_INT(VAR_TLS_MULTI_WILDCARD, 131 params->tls_multi_wildcard), 132 ATTR_TYPE_END); 133 /* Do not flush the stream. */ 134 if (msg_verbose) 135 msg_info("tls_proxy_client_param_print ret=%d", ret); 136 return (ret); 137 } 138 139 /* tls_proxy_client_init_print - send TLS_CLIENT_INIT_PROPS over stream */ 140 141 int tls_proxy_client_init_print(ATTR_PRINT_COMMON_FN print_fn, VSTREAM *fp, 142 int flags, const void *ptr) 143 { 144 const TLS_CLIENT_INIT_PROPS *props = (const TLS_CLIENT_INIT_PROPS *) ptr; 145 int ret; 146 147 if (msg_verbose) 148 msg_info("begin tls_proxy_client_init_print"); 149 150 #define STRING_OR_EMPTY(s) ((s) ? (s) : "") 151 152 ret = print_fn(fp, flags | ATTR_FLAG_MORE, 153 SEND_ATTR_STR(TLS_ATTR_LOG_PARAM, 154 STRING_OR_EMPTY(props->log_param)), 155 SEND_ATTR_STR(TLS_ATTR_LOG_LEVEL, 156 STRING_OR_EMPTY(props->log_level)), 157 SEND_ATTR_INT(TLS_ATTR_VERIFYDEPTH, props->verifydepth), 158 SEND_ATTR_STR(TLS_ATTR_CACHE_TYPE, 159 STRING_OR_EMPTY(props->cache_type)), 160 SEND_ATTR_STR(TLS_ATTR_CHAIN_FILES, 161 STRING_OR_EMPTY(props->chain_files)), 162 SEND_ATTR_STR(TLS_ATTR_CERT_FILE, 163 STRING_OR_EMPTY(props->cert_file)), 164 SEND_ATTR_STR(TLS_ATTR_KEY_FILE, 165 STRING_OR_EMPTY(props->key_file)), 166 SEND_ATTR_STR(TLS_ATTR_DCERT_FILE, 167 STRING_OR_EMPTY(props->dcert_file)), 168 SEND_ATTR_STR(TLS_ATTR_DKEY_FILE, 169 STRING_OR_EMPTY(props->dkey_file)), 170 SEND_ATTR_STR(TLS_ATTR_ECCERT_FILE, 171 STRING_OR_EMPTY(props->eccert_file)), 172 SEND_ATTR_STR(TLS_ATTR_ECKEY_FILE, 173 STRING_OR_EMPTY(props->eckey_file)), 174 SEND_ATTR_STR(TLS_ATTR_CAFILE, 175 STRING_OR_EMPTY(props->CAfile)), 176 SEND_ATTR_STR(TLS_ATTR_CAPATH, 177 STRING_OR_EMPTY(props->CApath)), 178 SEND_ATTR_STR(TLS_ATTR_MDALG, 179 STRING_OR_EMPTY(props->mdalg)), 180 ATTR_TYPE_END); 181 /* Do not flush the stream. */ 182 if (msg_verbose) 183 msg_info("tls_proxy_client_init_print ret=%d", ret); 184 return (ret); 185 } 186 187 /* tls_proxy_client_tlsa_print - send TLS_TLSA over stream */ 188 189 static int tls_proxy_client_tlsa_print(ATTR_PRINT_COMMON_FN print_fn, 190 VSTREAM *fp, int flags, const void *ptr) 191 { 192 const TLS_TLSA *head = (const TLS_TLSA *) ptr; 193 const TLS_TLSA *tp; 194 int count; 195 int ret; 196 197 for (tp = head, count = 0; tp != 0; tp = tp->next) 198 ++count; 199 if (msg_verbose) 200 msg_info("tls_proxy_client_tlsa_print count=%d", count); 201 202 ret = print_fn(fp, flags | ATTR_FLAG_MORE, 203 SEND_ATTR_INT(TLS_ATTR_COUNT, count), 204 ATTR_TYPE_END); 205 206 for (tp = head; ret == 0 && tp != 0; tp = tp->next) 207 ret = print_fn(fp, flags | ATTR_FLAG_MORE, 208 SEND_ATTR_INT(TLS_ATTR_USAGE, tp->usage), 209 SEND_ATTR_INT(TLS_ATTR_SELECTOR, tp->selector), 210 SEND_ATTR_INT(TLS_ATTR_MTYPE, tp->mtype), 211 SEND_ATTR_DATA(TLS_ATTR_DATA, tp->length, tp->data), 212 ATTR_TYPE_END); 213 214 /* Do not flush the stream. */ 215 if (msg_verbose) 216 msg_info("tls_proxy_client_tlsa_print ret=%d", count); 217 return (ret); 218 } 219 220 /* tls_proxy_client_dane_print - send TLS_DANE over stream */ 221 222 static int tls_proxy_client_dane_print(ATTR_PRINT_COMMON_FN print_fn, 223 VSTREAM *fp, int flags, const void *ptr) 224 { 225 const TLS_DANE *dane = (const TLS_DANE *) ptr; 226 int ret; 227 228 ret = print_fn(fp, flags | ATTR_FLAG_MORE, 229 SEND_ATTR_INT(TLS_ATTR_DANE, dane != 0), 230 ATTR_TYPE_END); 231 if (msg_verbose) 232 msg_info("tls_proxy_client_dane_print dane=%d", dane != 0); 233 234 if (ret == 0 && dane != 0) { 235 /* Send the base_domain and RRs, we don't need the other fields */ 236 ret = print_fn(fp, flags | ATTR_FLAG_MORE, 237 SEND_ATTR_STR(TLS_ATTR_DOMAIN, 238 STRING_OR_EMPTY(dane->base_domain)), 239 SEND_ATTR_FUNC(tls_proxy_client_tlsa_print, 240 (const void *) dane->tlsa), 241 ATTR_TYPE_END); 242 } 243 /* Do not flush the stream. */ 244 if (msg_verbose) 245 msg_info("tls_proxy_client_dane_print ret=%d", ret); 246 return (ret); 247 } 248 249 #ifdef USE_TLSRPT 250 251 /* tls_proxy_client_tlsrpt_print - send TLSRPT_WRAPPER over stream */ 252 253 static int tls_proxy_client_tlsrpt_print(ATTR_PRINT_COMMON_FN print_fn, 254 VSTREAM *fp, int flags, const void *ptr) 255 { 256 const TLSRPT_WRAPPER *trw = (const TLSRPT_WRAPPER *) ptr; 257 int have_trw = trw != 0; 258 int ret; 259 260 ret = print_fn(fp, flags | ATTR_FLAG_MORE, 261 SEND_ATTR_INT(TLS_ATTR_TLSRPT, have_trw), 262 ATTR_TYPE_END); 263 if (msg_verbose) 264 msg_info("tls_proxy_client_tlsrpt_print have_trw=%d", have_trw); 265 266 if (ret == 0 && have_trw) { 267 ret = print_fn(fp, flags | ATTR_FLAG_MORE, 268 SEND_ATTR_STR(TRW_RPT_SOCKET_NAME, 269 STRING_OR_EMPTY(trw->rpt_socket_name)), 270 SEND_ATTR_STR(TRW_RPT_POLICY_DOMAIN, 271 STRING_OR_EMPTY(trw->rpt_policy_domain)), 272 SEND_ATTR_STR(TRW_RPT_POLICY_STRING, 273 STRING_OR_EMPTY(trw->rpt_policy_string)), 274 SEND_ATTR_INT(TRW_TLS_POLICY_TYPE, 275 (int) trw->tls_policy_type), 276 SEND_ATTR_FUNC(argv_attr_print, 277 (const void *) trw->tls_policy_strings), 278 SEND_ATTR_STR(TRW_TLS_POLICY_DOMAIN, 279 STRING_OR_EMPTY(trw->tls_policy_domain)), 280 SEND_ATTR_FUNC(argv_attr_print, 281 (const void *) trw->mx_host_patterns), 282 SEND_ATTR_STR(TRW_SRC_MTA_ADDR, 283 STRING_OR_EMPTY(trw->snd_mta_addr)), 284 SEND_ATTR_STR(TRW_DST_MTA_NAME, 285 STRING_OR_EMPTY(trw->rcv_mta_name)), 286 SEND_ATTR_STR(TRW_DST_MTA_ADDR, 287 STRING_OR_EMPTY(trw->rcv_mta_addr)), 288 SEND_ATTR_STR(TRW_DST_MTA_EHLO, 289 STRING_OR_EMPTY(trw->rcv_mta_ehlo)), 290 SEND_ATTR_INT(TRW_SKIP_REUSED_HS, 291 trw->skip_reused_hs), 292 SEND_ATTR_INT(TRW_FLAGS, 293 trw->flags), 294 ATTR_TYPE_END); 295 } 296 /* Do not flush the stream. */ 297 if (msg_verbose) 298 msg_info("tls_proxy_client_tlsrpt_print ret=%d", ret); 299 return (ret); 300 } 301 302 #endif 303 304 /* tls_proxy_client_start_print - send TLS_CLIENT_START_PROPS over stream */ 305 306 int tls_proxy_client_start_print(ATTR_PRINT_COMMON_FN print_fn, 307 VSTREAM *fp, int flags, const void *ptr) 308 { 309 const TLS_CLIENT_START_PROPS *props = (const TLS_CLIENT_START_PROPS *) ptr; 310 int ret; 311 312 if (msg_verbose) 313 msg_info("begin tls_proxy_client_start_print"); 314 315 #define STRING_OR_EMPTY(s) ((s) ? (s) : "") 316 317 ret = print_fn(fp, flags | ATTR_FLAG_MORE, 318 SEND_ATTR_INT(TLS_ATTR_TIMEOUT, props->timeout), 319 SEND_ATTR_INT(TLS_ATTR_ENABLE_RPK, props->enable_rpk), 320 SEND_ATTR_INT(TLS_ATTR_TLS_LEVEL, props->tls_level), 321 SEND_ATTR_STR(TLS_ATTR_NEXTHOP, 322 STRING_OR_EMPTY(props->nexthop)), 323 SEND_ATTR_STR(TLS_ATTR_HOST, 324 STRING_OR_EMPTY(props->host)), 325 SEND_ATTR_STR(TLS_ATTR_NAMADDR, 326 STRING_OR_EMPTY(props->namaddr)), 327 SEND_ATTR_STR(TLS_ATTR_SNI, 328 STRING_OR_EMPTY(props->sni)), 329 SEND_ATTR_STR(TLS_ATTR_SERVERID, 330 STRING_OR_EMPTY(props->serverid)), 331 SEND_ATTR_STR(TLS_ATTR_HELO, 332 STRING_OR_EMPTY(props->helo)), 333 SEND_ATTR_STR(TLS_ATTR_PROTOCOLS, 334 STRING_OR_EMPTY(props->protocols)), 335 SEND_ATTR_STR(TLS_ATTR_CIPHER_GRADE, 336 STRING_OR_EMPTY(props->cipher_grade)), 337 SEND_ATTR_STR(TLS_ATTR_CIPHER_EXCLUSIONS, 338 STRING_OR_EMPTY(props->cipher_exclusions)), 339 SEND_ATTR_FUNC(argv_attr_print, 340 (const void *) props->matchargv), 341 SEND_ATTR_STR(TLS_ATTR_MDALG, 342 STRING_OR_EMPTY(props->mdalg)), 343 SEND_ATTR_FUNC(tls_proxy_client_dane_print, 344 (const void *) props->dane), 345 #ifdef USE_TLSRPT 346 SEND_ATTR_FUNC(tls_proxy_client_tlsrpt_print, 347 (const void *) props->tlsrpt), 348 #endif 349 SEND_ATTR_STR(TLS_ATTR_FFAIL_TYPE, 350 STRING_OR_EMPTY(props->ffail_type)), 351 ATTR_TYPE_END); 352 /* Do not flush the stream. */ 353 if (msg_verbose) 354 msg_info("tls_proxy_client_start_print ret=%d", ret); 355 return (ret); 356 } 357 358 #endif 359