2 * Copyright (c) 2012-2014 , JANET(UK)
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
9 * 1. Redistributions of source code must retain the above copyright
10 * notice, this list of conditions and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in the
14 * documentation and/or other materials provided with the distribution.
16 * 3. Neither the name of JANET(UK) nor the names of its contributors
17 * may be used to endorse or promote products derived from this software
18 * without specific prior written permission.
20 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
21 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
22 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
23 * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
24 * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT,
25 * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
26 * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
27 * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
29 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
30 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
31 * OF THE POSSIBILITY OF SUCH DAMAGE.
34 #include <sys/socket.h>
35 #include <netinet/in.h>
36 #include <arpa/inet.h>
38 #include <openssl/dh.h>
43 #include <trust_router/tr_name.h>
44 #include <trust_router/tid.h>
45 #include <trust_router/tr_constraint.h>
48 enum msg_type tr_msg_get_msg_type(TR_MSG *msg)
53 void tr_msg_set_msg_type(TR_MSG *msg, enum msg_type type)
58 TID_REQ *tr_msg_get_req(TR_MSG *msg)
63 void tr_msg_set_req(TR_MSG *msg, TID_REQ *req)
68 TID_RESP *tr_msg_get_resp(TR_MSG *msg)
73 void tr_msg_set_resp(TR_MSG *msg, TID_RESP *resp)
78 static json_t *tr_msg_encode_dh(DH *dh)
83 if ((!dh) || (!dh->p) || (!dh->g) || (!dh->pub_key))
88 jbn = json_string(BN_bn2hex(dh->p));
89 json_object_set_new(jdh, "dh_p", jbn);
91 jbn = json_string(BN_bn2hex(dh->g));
92 json_object_set_new(jdh, "dh_g", jbn);
94 jbn = json_string(BN_bn2hex(dh->pub_key));
95 json_object_set_new(jdh, "dh_pub_key", jbn);
100 static DH *tr_msg_decode_dh(json_t *jdh)
105 json_t *jpub_key = NULL;
107 if (!(dh = malloc(sizeof(DH)))) {
108 fprintf (stderr, "tr_msg_decode_dh(): Error allocating DH structure.\n");
112 memset(dh, 0, sizeof(DH));
114 /* store required fields from dh object */
115 if ((NULL == (jp = json_object_get(jdh, "dh_p"))) ||
116 (NULL == (jg = json_object_get(jdh, "dh_g"))) ||
117 (NULL == (jpub_key = json_object_get(jdh, "dh_pub_key")))) {
118 fprintf (stderr, "tr_msg_decode_dh(): Error parsing dh_info.\n");
123 BN_hex2bn(&(dh->p), json_string_value(jp));
124 BN_hex2bn(&(dh->g), json_string_value(jg));
125 BN_hex2bn(&(dh->pub_key), json_string_value(jpub_key));
130 static json_t * tr_msg_encode_tidreq(TID_REQ *req)
135 if ((!req) || (!req->rp_realm) || (!req->realm) || !(req->comm))
138 assert(jreq = json_object());
140 jstr = json_string(req->rp_realm->buf);
141 json_object_set_new(jreq, "rp_realm", jstr);
143 jstr = json_string(req->realm->buf);
144 json_object_set_new(jreq, "target_realm", jstr);
146 jstr = json_string(req->comm->buf);
147 json_object_set_new(jreq, "community", jstr);
150 jstr = json_string(req->orig_coi->buf);
151 json_object_set_new(jreq, "orig_coi", jstr);
154 json_object_set_new(jreq, "dh_info", tr_msg_encode_dh(req->tidc_dh));
157 json_object_set(jreq, "constraints", (json_t *) req->cons);
162 static TID_REQ *tr_msg_decode_tidreq(json_t *jreq)
164 TID_REQ *treq = NULL;
165 json_t *jrp_realm = NULL;
166 json_t *jrealm = NULL;
167 json_t *jcomm = NULL;
168 json_t *jorig_coi = NULL;
171 if (!(treq =tid_req_new())) {
172 fprintf (stderr, "tr_msg_decode_tidreq(): Error allocating TID_REQ structure.\n");
176 /* store required fields from request */
177 if ((NULL == (jrp_realm = json_object_get(jreq, "rp_realm"))) ||
178 (NULL == (jrealm = json_object_get(jreq, "target_realm"))) ||
179 (NULL == (jcomm = json_object_get(jreq, "community")))) {
180 fprintf (stderr, "tr_msg_decode(): Error parsing required fields.\n");
185 treq->rp_realm = tr_new_name((char *)json_string_value(jrp_realm));
186 treq->realm = tr_new_name((char *)json_string_value(jrealm));
187 treq->comm = tr_new_name((char *)json_string_value(jcomm));
189 /* Get DH Info from the request */
190 if (NULL == (jdh = json_object_get(jreq, "dh_info"))) {
191 fprintf (stderr, "tr_msg_decode(): Error parsing dh_info.\n");
195 treq->tidc_dh = tr_msg_decode_dh(jdh);
197 /* store optional "orig_coi" field */
198 if (NULL != (jorig_coi = json_object_get(jreq, "orig_coi"))) {
199 treq->orig_coi = tr_new_name((char *)json_string_value(jorig_coi));
202 treq->cons = (TR_CONSTRAINT_SET *) json_object_get(jreq, "constraints");
204 if (!tr_constraint_set_validate(treq->cons)) {
205 tr_debug("Constraint set validation failed\n");
209 json_incref((json_t *) treq->cons);
210 tid_req_cleanup_json(treq, (json_t *) treq->cons);
215 static json_t *tr_msg_encode_one_server(TID_SRVR_BLK *srvr)
217 json_t *jsrvr = NULL;
220 fprintf(stderr, "Encoding one server.\n");
222 jsrvr = json_object();
224 /* Server IP Address -- TBD handle IPv6 */
225 jstr = json_string(inet_ntoa(srvr->aaa_server_addr));
226 json_object_set_new(jsrvr, "server_addr", jstr);
228 /* Server DH Block */
229 jstr = json_string(srvr->key_name->buf);
230 json_object_set_new(jsrvr, "key_name", jstr);
231 json_object_set_new(jsrvr, "server_dh", tr_msg_encode_dh(srvr->aaa_server_dh));
233 // fprintf(stderr,"tr_msg_encode_one_server(): jsrvr contains:\n");
234 // fprintf(stderr,"%s\n", json_dumps(jsrvr, 0));
238 static TID_SRVR_BLK *tr_msg_decode_one_server(json_t *jsrvr)
241 json_t *jsrvr_addr = NULL;
242 json_t *jsrvr_kn = NULL;
243 json_t *jsrvr_dh = NULL;
248 if (NULL == (srvr = malloc(sizeof(TID_SRVR_BLK))))
250 memset(srvr, 0, sizeof(TID_SRVR_BLK));
252 if ((NULL == (jsrvr_addr = json_object_get(jsrvr, "server_addr"))) ||
253 (NULL == (jsrvr_kn = json_object_get(jsrvr, "key_name"))) ||
254 (NULL == (jsrvr_dh = json_object_get(jsrvr, "server_dh")))) {
255 fprintf (stderr, "tr_msg_decode_one_server(): Error parsing required fields.\n");
260 /* TBD -- handle IPv6 Addresses */
261 inet_aton(json_string_value(jsrvr_addr), &(srvr->aaa_server_addr));
262 srvr->key_name = tr_new_name((char *)json_string_value(jsrvr_kn));
263 srvr->aaa_server_dh = tr_msg_decode_dh(jsrvr_dh);
268 static json_t *tr_msg_encode_servers(TID_SRVR_BLK *servers)
270 json_t *jservers = NULL;
271 json_t *jsrvr = NULL;
272 TID_SRVR_BLK *srvr = NULL;
274 jservers = json_array();
276 for (srvr = servers; srvr != NULL; srvr = srvr->next) {
277 if ((NULL == (jsrvr = tr_msg_encode_one_server(srvr))) ||
278 (-1 == json_array_append_new(jservers, jsrvr))) {
283 // fprintf(stderr,"tr_msg_encode_servers(): servers contains:\n");
284 // fprintf(stderr,"%s\n", json_dumps(jservers, 0));
288 static TID_SRVR_BLK *tr_msg_decode_servers(json_t *jservers)
290 TID_SRVR_BLK *servers = NULL;
291 TID_SRVR_BLK *next = NULL;
292 TID_SRVR_BLK *srvr = NULL;
294 size_t i, num_servers;
296 num_servers = json_array_size(jservers);
297 fprintf(stderr, "tr_msg_decode_servers(): Number of servers = %u.\n", (unsigned) num_servers);
299 if (0 == num_servers) {
300 fprintf(stderr, "tr_msg_decode_servers(): Server array is empty.\n");
304 for (i = 0; i < num_servers; i++) {
305 jsrvr = json_array_get(jservers, i);
306 srvr = tr_msg_decode_one_server(jsrvr);
308 /* skip to the end of the list, and add srvr to list of servers */
309 if (NULL == servers) {
313 for (next = servers; next->next != NULL; next = next->next);
321 static json_t * tr_msg_encode_tidresp(TID_RESP *resp)
323 json_t *jresp = NULL;
325 json_t *jservers = NULL;
327 if ((!resp) || (!resp->rp_realm) || (!resp->realm) || !(resp->comm))
330 jresp = json_object();
332 if (TID_ERROR == resp->result) {
333 jstr = json_string("error");
334 json_object_set_new(jresp, "result", jstr);
336 jstr = json_string(resp->err_msg->buf);
337 json_object_set_new(jresp, "err_msg", jstr);
341 jstr = json_string("success");
342 json_object_set_new(jresp, "result", jstr);
345 jstr = json_string(resp->rp_realm->buf);
346 json_object_set_new(jresp, "rp_realm", jstr);
348 jstr = json_string(resp->realm->buf);
349 json_object_set_new(jresp, "target_realm", jstr);
351 jstr = json_string(resp->comm->buf);
352 json_object_set_new(jresp, "comm", jstr);
354 if (resp->orig_coi) {
355 jstr = json_string(resp->orig_coi->buf);
356 json_object_set_new(jresp, "orig_coi", jstr);
359 if (NULL == resp->servers) {
360 fprintf(stderr, "tr_msg_encode_tidresp(): No servers to encode.\n");
363 jservers = tr_msg_encode_servers(resp->servers);
364 json_object_set_new(jresp, "servers", jservers);
369 static TID_RESP *tr_msg_decode_tidresp(json_t *jresp)
371 TID_RESP *tresp = NULL;
372 json_t *jresult = NULL;
373 json_t *jrp_realm = NULL;
374 json_t *jrealm = NULL;
375 json_t *jcomm = NULL;
376 json_t *jorig_coi = NULL;
377 json_t *jservers = NULL;
378 json_t *jerr_msg = NULL;
380 if (!(tresp = malloc(sizeof(TID_RESP)))) {
381 fprintf (stderr, "tr_msg_decode_tidresp(): Error allocating TID_RESP structure.\n");
385 memset(tresp, 0, sizeof(TID_RESP));
387 /* store required fields from response */
388 if ((NULL == (jresult = json_object_get(jresp, "result"))) ||
389 (!json_is_string(jresult)) ||
390 (NULL == (jrp_realm = json_object_get(jresp, "rp_realm"))) ||
391 (!json_is_string(jrp_realm)) ||
392 (NULL == (jrealm = json_object_get(jresp, "target_realm"))) ||
393 (!json_is_string(jrealm)) ||
394 (NULL == (jcomm = json_object_get(jresp, "comm"))) ||
395 (!json_is_string(jcomm))) {
396 fprintf (stderr, "tr_msg_decode_tidresp(): Error parsing response.\n");
401 if (0 == (strcmp(json_string_value(jresult), "success"))) {
402 fprintf(stderr, "tr_msg_decode_tidresp(): Success! result = %s.\n", json_string_value(jresult));
403 if ((NULL != (jservers = json_object_get(jresp, "servers"))) ||
404 (!json_is_array(jservers))) {
405 tresp->servers = tr_msg_decode_servers(jservers);
410 tresp->result = TID_SUCCESS;
413 tresp->result = TID_ERROR;
414 fprintf(stderr, "tr_msg_decode_tidresp(): Error! result = %s.\n", json_string_value(jresult));
415 if ((NULL != (jerr_msg = json_object_get(jresp, "err_msg"))) ||
416 (!json_is_string(jerr_msg))) {
417 tresp->err_msg = tr_new_name((char *)json_string_value(jerr_msg));
421 tresp->rp_realm = tr_new_name((char *)json_string_value(jrp_realm));
422 tresp->realm = tr_new_name((char *)json_string_value(jrealm));
423 tresp->comm = tr_new_name((char *)json_string_value(jcomm));
425 /* store optional "orig_coi" field */
426 if ((NULL != (jorig_coi = json_object_get(jresp, "orig_coi"))) &&
427 (!json_is_object(jorig_coi))) {
428 tresp->orig_coi = tr_new_name((char *)json_string_value(jorig_coi));
434 char *tr_msg_encode(TR_MSG *msg)
439 /* TBD -- add error handling */
440 jmsg = json_object();
442 switch (msg->msg_type)
445 jmsg_type = json_string("tid_request");
446 json_object_set_new(jmsg, "msg_type", jmsg_type);
447 json_object_set_new(jmsg, "msg_body", tr_msg_encode_tidreq(msg->tid_req));
451 jmsg_type = json_string("tid_response");
452 json_object_set_new(jmsg, "msg_type", jmsg_type);
453 json_object_set_new(jmsg, "msg_body", tr_msg_encode_tidresp(msg->tid_resp));
456 /* TBD -- Add TR message types */
463 return(json_dumps(jmsg, 0));
466 TR_MSG *tr_msg_decode(char *jbuf, size_t buflen)
473 const char *mtype = NULL;
475 if (NULL == (jmsg = json_loadb(jbuf, buflen, JSON_DISABLE_EOF_CHECK, &rc))) {
476 fprintf (stderr, "tr_msg_decode(): error loading object\n");
480 if (!(msg = malloc(sizeof(TR_MSG)))) {
481 fprintf (stderr, "tr_msg_decode(): Error allocating TR_MSG structure.\n");
486 memset(msg, 0, sizeof(TR_MSG));
488 if ((NULL == (jtype = json_object_get(jmsg, "msg_type"))) ||
489 (NULL == (jbody = json_object_get(jmsg, "msg_body")))) {
490 fprintf (stderr, "tr_msg_decode(): Error parsing message header.\n");
492 tr_msg_free_decoded(msg);
496 mtype = json_string_value(jtype);
498 if (0 == strcmp(mtype, "tid_request")) {
499 msg->msg_type = TID_REQUEST;
500 msg->tid_req = tr_msg_decode_tidreq(jbody);
502 else if (0 == strcmp(mtype, "tid_response")) {
503 msg->msg_type = TID_RESPONSE;
504 msg->tid_resp = tr_msg_decode_tidresp(jbody);
507 msg->msg_type = TR_UNKNOWN;
513 void tr_msg_free_encoded(char *jmsg)
519 void tr_msg_free_decoded(TR_MSG *msg)