Home | History | Annotate | Line # | Download | only in tls
      1 /*	$NetBSD: tls_proxy_client_print.c,v 1.6 2026/05/09 18:49:21 christos Exp $	*/
      2 
      3 /*++
      4 /* NAME
      5 /*	tls_proxy_client_print 3
      6 /* SUMMARY
      7 /*	write TLS_CLIENT_XXX structures to stream
      8 /* SYNOPSIS
      9 /*	#include <tls_proxy.h>
     10 /*
     11 /*	int	tls_proxy_client_param_print(print_fn, stream, flags, ptr)
     12 /*	ATTR_PRINT_COMMON_FN print_fn;
     13 /*	VSTREAM	*stream;
     14 /*	int	flags;
     15 /*	const void *ptr;
     16 /*
     17 /*	int	tls_proxy_client_init_print(print_fn, stream, flags, ptr)
     18 /*	ATTR_PRINT_COMMON_FN print_fn;
     19 /*	VSTREAM	*stream;
     20 /*	int	flags;
     21 /*	const void *ptr;
     22 /*
     23 /*	int	tls_proxy_client_start_print(print_fn, stream, flags, ptr)
     24 /*	ATTR_PRINT_COMMON_FN print_fn;
     25 /*	VSTREAM	*stream;
     26 /*	int	flags;
     27 /*	const void *ptr;
     28 /* DESCRIPTION
     29 /*	tls_proxy_client_param_print() writes a TLS_CLIENT_PARAMS structure to
     30 /*	the named stream using the specified attribute print routine.
     31 /*	tls_proxy_client_param_print() is meant to be passed as a call-back to
     32 /*	attr_print(), thusly:
     33 /*
     34 /*	SEND_ATTR_FUNC(tls_proxy_client_param_print, (const void *) param), ...
     35 /*
     36 /*	tls_proxy_client_init_print() writes a full TLS_CLIENT_INIT_PROPS
     37 /*	structure to the named stream using the specified attribute
     38 /*	print routine. tls_proxy_client_init_print() is meant to
     39 /*	be passed as a call-back to attr_print(), thusly:
     40 /*
     41 /*	SEND_ATTR_FUNC(tls_proxy_client_init_print, (const void *) init_props), ...
     42 /*
     43 /*	tls_proxy_client_start_print() writes a TLS_CLIENT_START_PROPS
     44 /*	structure, without stream or file descriptor members, to
     45 /*	the named stream using the specified attribute print routine.
     46 /*	tls_proxy_client_start_print() is meant to be passed as a
     47 /*	call-back to attr_print(), thusly:
     48 /*
     49 /*	SEND_ATTR_FUNC(tls_proxy_client_start_print, (const void *) start_props), ...
     50 /* DIAGNOSTICS
     51 /*	Fatal: out of memory.
     52 /* LICENSE
     53 /* .ad
     54 /* .fi
     55 /*	The Secure Mailer license must be distributed with this software.
     56 /* AUTHOR(S)
     57 /*	Wietse Venema
     58 /*	Google, Inc.
     59 /*	111 8th Avenue
     60 /*	New York, NY 10011, USA
     61 /*--*/
     62 
     63 #ifdef USE_TLS
     64 
     65 /* System library. */
     66 
     67 #include <sys_defs.h>
     68 
     69 /* Utility library */
     70 
     71 #include <argv_attr.h>
     72 #include <attr.h>
     73 #include <msg.h>
     74 
     75 /* Global library. */
     76 
     77 #include <mail_params.h>
     78 
     79 /* TLS library. */
     80 
     81 #include <tls.h>
     82 #include <tls_proxy.h>
     83 
     84 #ifdef USE_TLSRPT
     85 #define TLSRPT_WRAPPER_INTERNAL
     86 #include <tlsrpt_wrapper.h>
     87 #endif
     88 
     89 #define STR(x) vstring_str(x)
     90 #define LEN(x) VSTRING_LEN(x)
     91 
     92 /* tls_proxy_client_param_print - send TLS_CLIENT_PARAMS over stream */
     93 
     94 int     tls_proxy_client_param_print(ATTR_PRINT_COMMON_FN print_fn, VSTREAM *fp,
     95 				             int flags, const void *ptr)
     96 {
     97     const TLS_CLIENT_PARAMS *params = (const TLS_CLIENT_PARAMS *) ptr;
     98     int     ret;
     99 
    100     if (msg_verbose)
    101 	msg_info("begin tls_proxy_client_param_print");
    102 
    103     ret = print_fn(fp, flags | ATTR_FLAG_MORE,
    104 		   SEND_ATTR_STR(TLS_ATTR_CNF_FILE, params->tls_cnf_file),
    105 		   SEND_ATTR_STR(TLS_ATTR_CNF_NAME, params->tls_cnf_name),
    106 		   SEND_ATTR_STR(VAR_TLS_HIGH_CLIST, params->tls_high_clist),
    107 		   SEND_ATTR_STR(VAR_TLS_MEDIUM_CLIST,
    108 				 params->tls_medium_clist),
    109 		   SEND_ATTR_STR(VAR_TLS_NULL_CLIST, params->tls_null_clist),
    110 		   SEND_ATTR_STR(VAR_TLS_EECDH_AUTO, params->tls_eecdh_auto),
    111 		   SEND_ATTR_STR(VAR_TLS_EECDH_STRONG,
    112 				 params->tls_eecdh_strong),
    113 		   SEND_ATTR_STR(VAR_TLS_EECDH_ULTRA,
    114 				 params->tls_eecdh_ultra),
    115 		   SEND_ATTR_STR(VAR_TLS_FFDHE_AUTO, params->tls_ffdhe_auto),
    116 		   SEND_ATTR_STR(VAR_TLS_BUG_TWEAKS, params->tls_bug_tweaks),
    117 		   SEND_ATTR_STR(VAR_TLS_SSL_OPTIONS,
    118 				 params->tls_ssl_options),
    119 		   SEND_ATTR_STR(VAR_TLS_DANE_DIGESTS,
    120 				 params->tls_dane_digests),
    121 		   SEND_ATTR_STR(VAR_TLS_MGR_SERVICE,
    122 				 params->tls_mgr_service),
    123 		   SEND_ATTR_STR(VAR_TLS_TKT_CIPHER, params->tls_tkt_cipher),
    124 		   SEND_ATTR_INT(VAR_TLS_DAEMON_RAND_BYTES,
    125 				 params->tls_daemon_rand_bytes),
    126 		   SEND_ATTR_INT(VAR_TLS_APPEND_DEF_CA,
    127 				 params->tls_append_def_CA),
    128 		   SEND_ATTR_INT(VAR_TLS_PREEMPT_CLIST,
    129 				 params->tls_preempt_clist),
    130 		   SEND_ATTR_INT(VAR_TLS_MULTI_WILDCARD,
    131 				 params->tls_multi_wildcard),
    132 		   ATTR_TYPE_END);
    133     /* Do not flush the stream. */
    134     if (msg_verbose)
    135 	msg_info("tls_proxy_client_param_print ret=%d", ret);
    136     return (ret);
    137 }
    138 
    139 /* tls_proxy_client_init_print - send TLS_CLIENT_INIT_PROPS over stream */
    140 
    141 int     tls_proxy_client_init_print(ATTR_PRINT_COMMON_FN print_fn, VSTREAM *fp,
    142 				            int flags, const void *ptr)
    143 {
    144     const TLS_CLIENT_INIT_PROPS *props = (const TLS_CLIENT_INIT_PROPS *) ptr;
    145     int     ret;
    146 
    147     if (msg_verbose)
    148 	msg_info("begin tls_proxy_client_init_print");
    149 
    150 #define STRING_OR_EMPTY(s) ((s) ? (s) : "")
    151 
    152     ret = print_fn(fp, flags | ATTR_FLAG_MORE,
    153 		   SEND_ATTR_STR(TLS_ATTR_LOG_PARAM,
    154 				 STRING_OR_EMPTY(props->log_param)),
    155 		   SEND_ATTR_STR(TLS_ATTR_LOG_LEVEL,
    156 				 STRING_OR_EMPTY(props->log_level)),
    157 		   SEND_ATTR_INT(TLS_ATTR_VERIFYDEPTH, props->verifydepth),
    158 		   SEND_ATTR_STR(TLS_ATTR_CACHE_TYPE,
    159 				 STRING_OR_EMPTY(props->cache_type)),
    160 		   SEND_ATTR_STR(TLS_ATTR_CHAIN_FILES,
    161 				 STRING_OR_EMPTY(props->chain_files)),
    162 		   SEND_ATTR_STR(TLS_ATTR_CERT_FILE,
    163 				 STRING_OR_EMPTY(props->cert_file)),
    164 		   SEND_ATTR_STR(TLS_ATTR_KEY_FILE,
    165 				 STRING_OR_EMPTY(props->key_file)),
    166 		   SEND_ATTR_STR(TLS_ATTR_DCERT_FILE,
    167 				 STRING_OR_EMPTY(props->dcert_file)),
    168 		   SEND_ATTR_STR(TLS_ATTR_DKEY_FILE,
    169 				 STRING_OR_EMPTY(props->dkey_file)),
    170 		   SEND_ATTR_STR(TLS_ATTR_ECCERT_FILE,
    171 				 STRING_OR_EMPTY(props->eccert_file)),
    172 		   SEND_ATTR_STR(TLS_ATTR_ECKEY_FILE,
    173 				 STRING_OR_EMPTY(props->eckey_file)),
    174 		   SEND_ATTR_STR(TLS_ATTR_CAFILE,
    175 				 STRING_OR_EMPTY(props->CAfile)),
    176 		   SEND_ATTR_STR(TLS_ATTR_CAPATH,
    177 				 STRING_OR_EMPTY(props->CApath)),
    178 		   SEND_ATTR_STR(TLS_ATTR_MDALG,
    179 				 STRING_OR_EMPTY(props->mdalg)),
    180 		   ATTR_TYPE_END);
    181     /* Do not flush the stream. */
    182     if (msg_verbose)
    183 	msg_info("tls_proxy_client_init_print ret=%d", ret);
    184     return (ret);
    185 }
    186 
    187 /* tls_proxy_client_tlsa_print - send TLS_TLSA over stream */
    188 
    189 static int tls_proxy_client_tlsa_print(ATTR_PRINT_COMMON_FN print_fn,
    190 			            VSTREAM *fp, int flags, const void *ptr)
    191 {
    192     const TLS_TLSA *head = (const TLS_TLSA *) ptr;
    193     const TLS_TLSA *tp;
    194     int     count;
    195     int     ret;
    196 
    197     for (tp = head, count = 0; tp != 0; tp = tp->next)
    198 	++count;
    199     if (msg_verbose)
    200 	msg_info("tls_proxy_client_tlsa_print count=%d", count);
    201 
    202     ret = print_fn(fp, flags | ATTR_FLAG_MORE,
    203 		   SEND_ATTR_INT(TLS_ATTR_COUNT, count),
    204 		   ATTR_TYPE_END);
    205 
    206     for (tp = head; ret == 0 && tp != 0; tp = tp->next)
    207 	ret = print_fn(fp, flags | ATTR_FLAG_MORE,
    208 		       SEND_ATTR_INT(TLS_ATTR_USAGE, tp->usage),
    209 		       SEND_ATTR_INT(TLS_ATTR_SELECTOR, tp->selector),
    210 		       SEND_ATTR_INT(TLS_ATTR_MTYPE, tp->mtype),
    211 		       SEND_ATTR_DATA(TLS_ATTR_DATA, tp->length, tp->data),
    212 		       ATTR_TYPE_END);
    213 
    214     /* Do not flush the stream. */
    215     if (msg_verbose)
    216 	msg_info("tls_proxy_client_tlsa_print ret=%d", count);
    217     return (ret);
    218 }
    219 
    220 /* tls_proxy_client_dane_print - send TLS_DANE over stream */
    221 
    222 static int tls_proxy_client_dane_print(ATTR_PRINT_COMMON_FN print_fn,
    223 			            VSTREAM *fp, int flags, const void *ptr)
    224 {
    225     const TLS_DANE *dane = (const TLS_DANE *) ptr;
    226     int     ret;
    227 
    228     ret = print_fn(fp, flags | ATTR_FLAG_MORE,
    229 		   SEND_ATTR_INT(TLS_ATTR_DANE, dane != 0),
    230 		   ATTR_TYPE_END);
    231     if (msg_verbose)
    232 	msg_info("tls_proxy_client_dane_print dane=%d", dane != 0);
    233 
    234     if (ret == 0 && dane != 0) {
    235 	/* Send the base_domain and RRs, we don't need the other fields */
    236 	ret = print_fn(fp, flags | ATTR_FLAG_MORE,
    237 		       SEND_ATTR_STR(TLS_ATTR_DOMAIN,
    238 				     STRING_OR_EMPTY(dane->base_domain)),
    239 		       SEND_ATTR_FUNC(tls_proxy_client_tlsa_print,
    240 				      (const void *) dane->tlsa),
    241 		       ATTR_TYPE_END);
    242     }
    243     /* Do not flush the stream. */
    244     if (msg_verbose)
    245 	msg_info("tls_proxy_client_dane_print ret=%d", ret);
    246     return (ret);
    247 }
    248 
    249 #ifdef USE_TLSRPT
    250 
    251 /* tls_proxy_client_tlsrpt_print - send TLSRPT_WRAPPER over stream */
    252 
    253 static int tls_proxy_client_tlsrpt_print(ATTR_PRINT_COMMON_FN print_fn,
    254 			            VSTREAM *fp, int flags, const void *ptr)
    255 {
    256     const TLSRPT_WRAPPER *trw = (const TLSRPT_WRAPPER *) ptr;
    257     int     have_trw = trw != 0;
    258     int     ret;
    259 
    260     ret = print_fn(fp, flags | ATTR_FLAG_MORE,
    261 		   SEND_ATTR_INT(TLS_ATTR_TLSRPT, have_trw),
    262 		   ATTR_TYPE_END);
    263     if (msg_verbose)
    264 	msg_info("tls_proxy_client_tlsrpt_print have_trw=%d", have_trw);
    265 
    266     if (ret == 0 && have_trw) {
    267 	ret = print_fn(fp, flags | ATTR_FLAG_MORE,
    268 		       SEND_ATTR_STR(TRW_RPT_SOCKET_NAME,
    269 				     STRING_OR_EMPTY(trw->rpt_socket_name)),
    270 		       SEND_ATTR_STR(TRW_RPT_POLICY_DOMAIN,
    271 				   STRING_OR_EMPTY(trw->rpt_policy_domain)),
    272 		       SEND_ATTR_STR(TRW_RPT_POLICY_STRING,
    273 				   STRING_OR_EMPTY(trw->rpt_policy_string)),
    274 		       SEND_ATTR_INT(TRW_TLS_POLICY_TYPE,
    275 				     (int) trw->tls_policy_type),
    276 		       SEND_ATTR_FUNC(argv_attr_print,
    277 				    (const void *) trw->tls_policy_strings),
    278 		       SEND_ATTR_STR(TRW_TLS_POLICY_DOMAIN,
    279 				   STRING_OR_EMPTY(trw->tls_policy_domain)),
    280 		       SEND_ATTR_FUNC(argv_attr_print,
    281 				      (const void *) trw->mx_host_patterns),
    282 		       SEND_ATTR_STR(TRW_SRC_MTA_ADDR,
    283 				     STRING_OR_EMPTY(trw->snd_mta_addr)),
    284 		       SEND_ATTR_STR(TRW_DST_MTA_NAME,
    285 				     STRING_OR_EMPTY(trw->rcv_mta_name)),
    286 		       SEND_ATTR_STR(TRW_DST_MTA_ADDR,
    287 				     STRING_OR_EMPTY(trw->rcv_mta_addr)),
    288 		       SEND_ATTR_STR(TRW_DST_MTA_EHLO,
    289 				     STRING_OR_EMPTY(trw->rcv_mta_ehlo)),
    290 		       SEND_ATTR_INT(TRW_SKIP_REUSED_HS,
    291 				     trw->skip_reused_hs),
    292 		       SEND_ATTR_INT(TRW_FLAGS,
    293 				     trw->flags),
    294 		       ATTR_TYPE_END);
    295     }
    296     /* Do not flush the stream. */
    297     if (msg_verbose)
    298 	msg_info("tls_proxy_client_tlsrpt_print ret=%d", ret);
    299     return (ret);
    300 }
    301 
    302 #endif
    303 
    304 /* tls_proxy_client_start_print - send TLS_CLIENT_START_PROPS over stream */
    305 
    306 int     tls_proxy_client_start_print(ATTR_PRINT_COMMON_FN print_fn,
    307 			            VSTREAM *fp, int flags, const void *ptr)
    308 {
    309     const TLS_CLIENT_START_PROPS *props = (const TLS_CLIENT_START_PROPS *) ptr;
    310     int     ret;
    311 
    312     if (msg_verbose)
    313 	msg_info("begin tls_proxy_client_start_print");
    314 
    315 #define STRING_OR_EMPTY(s) ((s) ? (s) : "")
    316 
    317     ret = print_fn(fp, flags | ATTR_FLAG_MORE,
    318 		   SEND_ATTR_INT(TLS_ATTR_TIMEOUT, props->timeout),
    319 		   SEND_ATTR_INT(TLS_ATTR_ENABLE_RPK, props->enable_rpk),
    320 		   SEND_ATTR_INT(TLS_ATTR_TLS_LEVEL, props->tls_level),
    321 		   SEND_ATTR_STR(TLS_ATTR_NEXTHOP,
    322 				 STRING_OR_EMPTY(props->nexthop)),
    323 		   SEND_ATTR_STR(TLS_ATTR_HOST,
    324 				 STRING_OR_EMPTY(props->host)),
    325 		   SEND_ATTR_STR(TLS_ATTR_NAMADDR,
    326 				 STRING_OR_EMPTY(props->namaddr)),
    327 		   SEND_ATTR_STR(TLS_ATTR_SNI,
    328 				 STRING_OR_EMPTY(props->sni)),
    329 		   SEND_ATTR_STR(TLS_ATTR_SERVERID,
    330 				 STRING_OR_EMPTY(props->serverid)),
    331 		   SEND_ATTR_STR(TLS_ATTR_HELO,
    332 				 STRING_OR_EMPTY(props->helo)),
    333 		   SEND_ATTR_STR(TLS_ATTR_PROTOCOLS,
    334 				 STRING_OR_EMPTY(props->protocols)),
    335 		   SEND_ATTR_STR(TLS_ATTR_CIPHER_GRADE,
    336 				 STRING_OR_EMPTY(props->cipher_grade)),
    337 		   SEND_ATTR_STR(TLS_ATTR_CIPHER_EXCLUSIONS,
    338 				 STRING_OR_EMPTY(props->cipher_exclusions)),
    339 		   SEND_ATTR_FUNC(argv_attr_print,
    340 				  (const void *) props->matchargv),
    341 		   SEND_ATTR_STR(TLS_ATTR_MDALG,
    342 				 STRING_OR_EMPTY(props->mdalg)),
    343 		   SEND_ATTR_FUNC(tls_proxy_client_dane_print,
    344 				  (const void *) props->dane),
    345 #ifdef USE_TLSRPT
    346 		   SEND_ATTR_FUNC(tls_proxy_client_tlsrpt_print,
    347 				  (const void *) props->tlsrpt),
    348 #endif
    349 		   SEND_ATTR_STR(TLS_ATTR_FFAIL_TYPE,
    350 				 STRING_OR_EMPTY(props->ffail_type)),
    351 		   ATTR_TYPE_END);
    352     /* Do not flush the stream. */
    353     if (msg_verbose)
    354 	msg_info("tls_proxy_client_start_print ret=%d", ret);
    355     return (ret);
    356 }
    357 
    358 #endif
    359