Support a trusted SHA1 fingerprint to be configured for each IRC server
This commit is contained in:
@@ -26,11 +26,17 @@ bool Basic_Credentials_Manager::certs_loaded = false;
|
||||
|
||||
Basic_Credentials_Manager::Basic_Credentials_Manager(const TCPSocketHandler* const socket_handler):
|
||||
Botan::Credentials_Manager(),
|
||||
socket_handler(socket_handler)
|
||||
socket_handler(socket_handler),
|
||||
trusted_fingerprint{}
|
||||
{
|
||||
this->load_certs();
|
||||
}
|
||||
|
||||
void Basic_Credentials_Manager::set_trusted_fingerprint(const std::string& fingerprint)
|
||||
{
|
||||
this->trusted_fingerprint = fingerprint;
|
||||
}
|
||||
|
||||
void Basic_Credentials_Manager::verify_certificate_chain(const std::string& type,
|
||||
const std::string& purported_hostname,
|
||||
const std::vector<Botan::X509_Certificate>& certs)
|
||||
@@ -44,6 +50,13 @@ void Basic_Credentials_Manager::verify_certificate_chain(const std::string& type
|
||||
catch (const std::exception& tls_exception)
|
||||
{
|
||||
log_warning("TLS certificate check failed: " << tls_exception.what());
|
||||
if (!this->trusted_fingerprint.empty() && !certs.empty() &&
|
||||
this->trusted_fingerprint == certs[0].fingerprint() &&
|
||||
certs[0].matches_dns_name(purported_hostname))
|
||||
// We trust the certificate, based on the trusted fingerprint and
|
||||
// the fact that the hostname matches
|
||||
return;
|
||||
|
||||
if (this->socket_handler->abort_on_invalid_cert())
|
||||
throw;
|
||||
}
|
||||
|
||||
@@ -19,6 +19,7 @@ public:
|
||||
const std::vector<Botan::X509_Certificate>&) override final;
|
||||
std::vector<Botan::Certificate_Store*> trusted_certificate_authorities(const std::string& type,
|
||||
const std::string& context) override final;
|
||||
void set_trusted_fingerprint(const std::string& fingerprint);
|
||||
|
||||
private:
|
||||
const TCPSocketHandler* const socket_handler;
|
||||
@@ -26,6 +27,7 @@ private:
|
||||
static void load_certs();
|
||||
static Botan::Certificate_Store_In_Memory certificate_store;
|
||||
static bool certs_loaded;
|
||||
std::string trusted_fingerprint;
|
||||
};
|
||||
|
||||
#endif //BOTAN_FOUND
|
||||
|
||||
@@ -248,7 +248,9 @@ private:
|
||||
static Botan::AutoSeeded_RNG rng;
|
||||
static Botan::TLS::Policy policy;
|
||||
static Botan::TLS::Session_Manager_In_Memory session_manager;
|
||||
protected:
|
||||
Basic_Credentials_Manager credential_manager;
|
||||
private:
|
||||
/**
|
||||
* We use a unique_ptr because we may not want to create the object at
|
||||
* all. The Botan::TLS::Client object generates a handshake message and
|
||||
|
||||
Reference in New Issue
Block a user