2 * The Shibboleth License, Version 1.
4 * University Corporation for Advanced Internet Development, Inc.
8 * Redistribution and use in source and binary forms, with or without
9 * modification, are permitted provided that the following conditions are met:
11 * Redistributions of source code must retain the above copyright notice, this
12 * list of conditions and the following disclaimer.
14 * Redistributions in binary form must reproduce the above copyright notice,
15 * this list of conditions and the following disclaimer in the documentation
16 * and/or other materials provided with the distribution, if any, must include
17 * the following acknowledgment: "This product includes software developed by
18 * the University Corporation for Advanced Internet Development
19 * <http://www.ucaid.edu>Internet2 Project. Alternately, this acknowledegement
20 * may appear in the software itself, if and wherever such third-party
21 * acknowledgments normally appear.
23 * Neither the name of Shibboleth nor the names of its contributors, nor
24 * Internet2, nor the University Corporation for Advanced Internet Development,
25 * Inc., nor UCAID may be used to endorse or promote products derived from this
26 * software without specific prior written permission. For written permission,
27 * please contact shibboleth@shibboleth.org
29 * Products derived from this software may not be called Shibboleth, Internet2,
30 * UCAID, or the University Corporation for Advanced Internet Development, nor
31 * may Shibboleth appear in their name, without prior written permission of the
32 * University Corporation for Advanced Internet Development.
35 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
36 * AND WITH ALL FAULTS. ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
37 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
38 * PARTICULAR PURPOSE, AND NON-INFRINGEMENT ARE DISCLAIMED AND THE ENTIRE RISK
39 * OF SATISFACTORY QUALITY, PERFORMANCE, ACCURACY, AND EFFORT IS WITH LICENSEE.
40 * IN NO EVENT SHALL THE COPYRIGHT OWNER, CONTRIBUTORS OR THE UNIVERSITY
41 * CORPORATION FOR ADVANCED INTERNET DEVELOPMENT, INC. BE LIABLE FOR ANY DIRECT,
42 * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
43 * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
44 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
45 * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
46 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
47 * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
51 /* ShibConfig.cpp - Shibboleth runtime configuration
60 #include <sys/types.h>
63 #define SHIB_INSTANTIATE
66 #include <log4cpp/Category.hh>
67 #include <openssl/err.h>
70 using namespace shibboleth;
71 using namespace log4cpp;
74 SAML_EXCEPTION_FACTORY(UnsupportedProtocolException);
75 SAML_EXCEPTION_FACTORY(MetadataException);
78 ShibInternalConfig g_config;
81 ShibConfig::~ShibConfig() {}
84 extern "C" IMetadata* XMLMetadataFactory(const DOMElement* source);
85 extern "C" ITrust* XMLTrustFactory(const DOMElement* source);
86 extern "C" ICredentials* XMLCredentialsFactory(const DOMElement* source);
87 extern "C" ICredResolver* FileCredResolverFactory(const DOMElement* e);
88 extern "C" ICredResolver* KeyInfoResolverFactory(const DOMElement* e);
89 extern "C" IAAP* XMLAAPFactory(const DOMElement* source);
90 extern "C" IAAP* XMLAAPDOMFactory(const DOMElement* source);
92 extern "C" SAMLAttribute* ShibAttributeFactory(DOMElement* e)
94 DOMNode* n=e->getFirstChild();
95 while (n && n->getNodeType()!=DOMNode::ELEMENT_NODE)
96 n=n->getNextSibling();
97 if (n && static_cast<DOMElement*>(n)->hasAttributeNS(NULL,SHIB_L(Scope)))
98 return new ScopedAttribute(e);
99 return new SAMLAttribute(e);
103 bool ShibInternalConfig::init()
105 saml::NDC ndc("init");
107 REGISTER_EXCEPTION_FACTORY(edu.internet2.middleware.shibboleth.common,UnsupportedProtocolException);
108 REGISTER_EXCEPTION_FACTORY(edu.internet2.middleware.shibboleth.common,MetadataException);
110 // Register extension schema.
111 saml::XML::registerSchema(XML::SHIB_NS,XML::SHIB_SCHEMA_ID);
113 SAMLAttribute::setFactory(&ShibAttributeFactory);
115 // Register metadata factories
116 regFactory("edu.internet2.middleware.shibboleth.metadata.provider.XML",&XMLMetadataFactory);
117 regFactory("edu.internet2.middleware.shibboleth.trust.provider.XML",&XMLTrustFactory);
118 regFactory("edu.internet2.middleware.shibboleth.creds.provider.XML",&XMLCredentialsFactory);
119 regFactory("edu.internet2.middleware.shibboleth.creds.provider.FileCredResolver",&FileCredResolverFactory);
120 regFactory("edu.internet2.middleware.shibboleth.creds.provider.KeyInfoResolver",&KeyInfoResolverFactory);
121 regFactory("edu.internet2.middleware.shibboleth.target.AAP.provider.XML",&XMLAAPFactory);
126 void ShibInternalConfig::regFactory(const char* type, MetadataFactory* factory)
129 m_metadataFactoryMap[type]=factory;
132 void ShibInternalConfig::regFactory(const char* type, TrustFactory* factory)
135 m_trustFactoryMap[type]=factory;
138 void ShibInternalConfig::regFactory(const char* type, CredentialsFactory* factory)
142 m_credFactoryMap[type]=factory;
143 SAMLConfig::getConfig().binding_defaults.ssl_ctx_callback=ssl_ctx_callback;
147 void ShibInternalConfig::regFactory(const char* type, CredResolverFactory* factory)
150 m_credResolverFactoryMap[type]=factory;
153 void ShibInternalConfig::regFactory(const char* type, AAPFactory* factory)
156 m_aapFactoryMap[type]=factory;
159 void ShibInternalConfig::unregFactory(const char* type)
163 m_metadataFactoryMap.erase(type);
164 m_trustFactoryMap.erase(type);
165 m_credFactoryMap.erase(type);
166 m_credResolverFactoryMap.erase(type);
167 m_aapFactoryMap.erase(type);
171 IMetadata* ShibInternalConfig::newMetadata(const char* type, const DOMElement* source) const
173 MetadataFactoryMap::const_iterator i=m_metadataFactoryMap.find(type);
174 if (i==m_metadataFactoryMap.end())
176 NDC ndc("newMetadata");
177 Category::getInstance(SHIB_LOGCAT".ShibInternalConfig").error("unknown metadata type: %s",type);
180 return i->second(source);
183 ITrust* ShibInternalConfig::newTrust(const char* type, const DOMElement* source) const
185 TrustFactoryMap::const_iterator i=m_trustFactoryMap.find(type);
186 if (i==m_trustFactoryMap.end())
189 Category::getInstance(SHIB_LOGCAT".ShibInternalConfig").error("unknown trust type: %s",type);
192 return i->second(source);
195 ICredentials* ShibInternalConfig::newCredentials(const char* type, const DOMElement* source) const
197 CredentialsFactoryMap::const_iterator i=m_credFactoryMap.find(type);
198 if (i==m_credFactoryMap.end())
200 NDC ndc("newCredentials");
201 Category::getInstance(SHIB_LOGCAT".ShibInternalConfig").error("unknown credentials type: %s",type);
204 return i->second(source);
207 IAAP* ShibInternalConfig::newAAP(const char* type, const DOMElement* source) const
209 AAPFactoryMap::const_iterator i=m_aapFactoryMap.find(type);
210 if (i==m_aapFactoryMap.end())
213 Category::getInstance(SHIB_LOGCAT".ShibInternalConfig").error("unknown AAP type: %s",type);
216 return i->second(source);
219 ICredResolver* ShibInternalConfig::newCredResolver(const char* type, const DOMElement* source) const
221 CredResolverFactoryMap::const_iterator i=m_credResolverFactoryMap.find(type);
222 if (i==m_credResolverFactoryMap.end())
224 NDC ndc("newCredResolver");
225 Category::getInstance(SHIB_LOGCAT".ShibInternalConfig").error("unknown cred resolver type: %s",type);
228 return i->second(source);
231 ShibConfig& ShibConfig::getConfig()
236 void shibboleth::log_openssl()
242 unsigned long code=ERR_get_error_line_data(&file,&line,&data,&flags);
245 Category& log=Category::getInstance("OpenSSL");
246 log.errorStream() << "error code: " << code << " in " << file << ", line " << line << CategoryStream::ENDLINE;
247 if (data && (flags & ERR_TXT_STRING))
248 log.errorStream() << "error data: " << data << CategoryStream::ENDLINE;
249 code=ERR_get_error_line_data(&file,&line,&data,&flags);
253 X509* shibboleth::B64_to_X509(const char* buf)
255 BIO* bmem = BIO_new_mem_buf((void*)buf,-1);
256 BIO* b64 = BIO_new(BIO_f_base64());
257 b64 = BIO_push(b64, bmem);
259 d2i_X509_bio(b64,&x);