| 251 |
|
static void |
| 252 |
|
ssl_handshake(int fd, struct Client *client_p) |
| 253 |
|
{ |
| 254 |
+ |
X509 *cert = NULL; |
| 255 |
|
int ret = SSL_accept(client_p->localClient->fd.ssl); |
| 256 |
+ |
int err = SSL_get_error(client_p->localClient->fd.ssl, ret); |
| 257 |
+ |
|
| 258 |
+ |
ilog(LOG_TYPE_IRCD, "SSL Error %d %s", err, ERR_error_string(err, NULL)); |
| 259 |
+ |
|
| 260 |
+ |
if ((cert = SSL_get_peer_certificate(client_p->localClient->fd.ssl))) |
| 261 |
+ |
{ |
| 262 |
+ |
int res = SSL_get_verify_result(client_p->localClient->fd.ssl); |
| 263 |
+ |
char buf[EVP_MAX_MD_SIZE * 2 + 1] = { '\0' }; |
| 264 |
+ |
unsigned char md[EVP_MAX_MD_SIZE * 2 + 1] = { '\0' }; |
| 265 |
+ |
|
| 266 |
+ |
if (res == X509_V_OK || res == X509_V_ERR_SELF_SIGNED_CERT_IN_CHAIN || |
| 267 |
+ |
res == X509_V_ERR_UNABLE_TO_VERIFY_LEAF_SIGNATURE || |
| 268 |
+ |
res == X509_V_ERR_DEPTH_ZERO_SELF_SIGNED_CERT) |
| 269 |
+ |
{ |
| 270 |
+ |
unsigned int i = 0, n = 0; |
| 271 |
+ |
|
| 272 |
+ |
if (X509_digest(cert, EVP_sha256(), md, &n)) |
| 273 |
+ |
{ |
| 274 |
+ |
for (; i < n; ++i) |
| 275 |
+ |
snprintf(buf + 2 * i, 3, "%02X", md[i]); |
| 276 |
+ |
client_p->certfp = xstrdup(buf); |
| 277 |
+ |
} |
| 278 |
+ |
} |
| 279 |
+ |
else |
| 280 |
+ |
ilog(LOG_TYPE_IRCD, "Client %s!%s@%s gave bad SSL client certificate: %d", |
| 281 |
+ |
client_p->name, client_p->username, client_p->host, res); |
| 282 |
+ |
X509_free(cert); |
| 283 |
+ |
} |
| 284 |
|
|
| 285 |
|
if (ret <= 0) |
| 286 |
+ |
{ |
| 287 |
|
switch (SSL_get_error(client_p->localClient->fd.ssl, ret)) |
| 288 |
|
{ |
| 289 |
|
case SSL_ERROR_WANT_WRITE: |
| 300 |
|
exit_client(client_p, client_p, "Error during SSL handshake"); |
| 301 |
|
return; |
| 302 |
|
} |
| 303 |
+ |
} |
| 304 |
|
|
| 305 |
|
start_auth(client_p); |
| 306 |
|
} |