Klaus Demo nginx / 7fab8d0
Stream: client SSL certificates verification support. New directives: "ssl_verify_client", "ssl_verify_depth", "ssl_client_certificate", "ssl_trusted_certificate", and "ssl_crl". New variables: $ssl_client_cert, $ssl_client_raw_cert, $ssl_client_s_dn, $ssl_client_i_dn, $ssl_client_serial, $ssl_client_fingerprint, $ssl_client_verify, $ssl_client_v_start, $ssl_client_v_end, and $ssl_client_v_remain. Vladimir Homutov 3 years ago
2 changed file(s) with 157 addition(s) and 0 deletion(s). Raw diff Collapse all Expand all
4848 };
4949
5050
51 static ngx_conf_enum_t ngx_stream_ssl_verify[] = {
52 { ngx_string("off"), 0 },
53 { ngx_string("on"), 1 },
54 { ngx_string("optional"), 2 },
55 { ngx_string("optional_no_ca"), 3 },
56 { ngx_null_string, 0 }
57 };
58
59
5160 static ngx_command_t ngx_stream_ssl_commands[] = {
5261
5362 { ngx_string("ssl_handshake_timeout"),
106115 offsetof(ngx_stream_ssl_conf_t, ciphers),
107116 NULL },
108117
118 { ngx_string("ssl_verify_client"),
119 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1,
120 ngx_conf_set_enum_slot,
121 NGX_STREAM_SRV_CONF_OFFSET,
122 offsetof(ngx_stream_ssl_conf_t, verify),
123 &ngx_stream_ssl_verify },
124
125 { ngx_string("ssl_verify_depth"),
126 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1,
127 ngx_conf_set_num_slot,
128 NGX_STREAM_SRV_CONF_OFFSET,
129 offsetof(ngx_stream_ssl_conf_t, verify_depth),
130 NULL },
131
132 { ngx_string("ssl_client_certificate"),
133 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1,
134 ngx_conf_set_str_slot,
135 NGX_STREAM_SRV_CONF_OFFSET,
136 offsetof(ngx_stream_ssl_conf_t, client_certificate),
137 NULL },
138
139 { ngx_string("ssl_trusted_certificate"),
140 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1,
141 ngx_conf_set_str_slot,
142 NGX_STREAM_SRV_CONF_OFFSET,
143 offsetof(ngx_stream_ssl_conf_t, trusted_certificate),
144 NULL },
145
109146 { ngx_string("ssl_prefer_server_ciphers"),
110147 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_FLAG,
111148 ngx_conf_set_flag_slot,
139176 ngx_conf_set_sec_slot,
140177 NGX_STREAM_SRV_CONF_OFFSET,
141178 offsetof(ngx_stream_ssl_conf_t, session_timeout),
179 NULL },
180
181 { ngx_string("ssl_crl"),
182 NGX_STREAM_MAIN_CONF|NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1,
183 ngx_conf_set_str_slot,
184 NGX_STREAM_SRV_CONF_OFFSET,
185 offsetof(ngx_stream_ssl_conf_t, crl),
142186 NULL },
143187
144188 ngx_null_command
196240 { ngx_string("ssl_server_name"), NULL, ngx_stream_ssl_variable,
197241 (uintptr_t) ngx_ssl_get_server_name, NGX_STREAM_VAR_CHANGEABLE, 0 },
198242
243 { ngx_string("ssl_client_cert"), NULL, ngx_stream_ssl_variable,
244 (uintptr_t) ngx_ssl_get_certificate, NGX_STREAM_VAR_CHANGEABLE, 0 },
245
246 { ngx_string("ssl_client_raw_cert"), NULL, ngx_stream_ssl_variable,
247 (uintptr_t) ngx_ssl_get_raw_certificate,
248 NGX_STREAM_VAR_CHANGEABLE, 0 },
249
250 { ngx_string("ssl_client_s_dn"), NULL, ngx_stream_ssl_variable,
251 (uintptr_t) ngx_ssl_get_subject_dn, NGX_STREAM_VAR_CHANGEABLE, 0 },
252
253 { ngx_string("ssl_client_i_dn"), NULL, ngx_stream_ssl_variable,
254 (uintptr_t) ngx_ssl_get_issuer_dn, NGX_STREAM_VAR_CHANGEABLE, 0 },
255
256 { ngx_string("ssl_client_serial"), NULL, ngx_stream_ssl_variable,
257 (uintptr_t) ngx_ssl_get_serial_number, NGX_STREAM_VAR_CHANGEABLE, 0 },
258
259 { ngx_string("ssl_client_fingerprint"), NULL, ngx_stream_ssl_variable,
260 (uintptr_t) ngx_ssl_get_fingerprint, NGX_STREAM_VAR_CHANGEABLE, 0 },
261
262 { ngx_string("ssl_client_verify"), NULL, ngx_stream_ssl_variable,
263 (uintptr_t) ngx_ssl_get_client_verify, NGX_STREAM_VAR_CHANGEABLE, 0 },
264
265 { ngx_string("ssl_client_v_start"), NULL, ngx_stream_ssl_variable,
266 (uintptr_t) ngx_ssl_get_client_v_start, NGX_STREAM_VAR_CHANGEABLE, 0 },
267
268 { ngx_string("ssl_client_v_end"), NULL, ngx_stream_ssl_variable,
269 (uintptr_t) ngx_ssl_get_client_v_end, NGX_STREAM_VAR_CHANGEABLE, 0 },
270
271 { ngx_string("ssl_client_v_remain"), NULL, ngx_stream_ssl_variable,
272 (uintptr_t) ngx_ssl_get_client_v_remain, NGX_STREAM_VAR_CHANGEABLE, 0 },
273
199274 { ngx_null_string, NULL, NULL, 0, 0, 0 }
200275 };
201276
206281 static ngx_int_t
207282 ngx_stream_ssl_handler(ngx_stream_session_t *s)
208283 {
284 long rc;
285 X509 *cert;
209286 ngx_connection_t *c;
210287 ngx_stream_ssl_conf_t *sslcf;
211288
224301 }
225302
226303 return ngx_stream_ssl_init_connection(&sslcf->ssl, c);
304 }
305
306 if (sslcf->verify) {
307 rc = SSL_get_verify_result(c->ssl->connection);
308
309 if (rc != X509_V_OK
310 && (sslcf->verify != 3 || !ngx_ssl_verify_error_optional(rc)))
311 {
312 ngx_log_error(NGX_LOG_INFO, c->log, 0,
313 "client SSL certificate verify error: (%l:%s)",
314 rc, X509_verify_cert_error_string(rc));
315
316 ngx_ssl_remove_cached_session(sslcf->ssl.ctx,
317 (SSL_get0_session(c->ssl->connection)));
318 return NGX_ERROR;
319 }
320
321 if (sslcf->verify == 1) {
322 cert = SSL_get_peer_certificate(c->ssl->connection);
323
324 if (cert == NULL) {
325 ngx_log_error(NGX_LOG_INFO, c->log, 0,
326 "client sent no required SSL certificate");
327
328 ngx_ssl_remove_cached_session(sslcf->ssl.ctx,
329 (SSL_get0_session(c->ssl->connection)));
330 return NGX_ERROR;
331 }
332
333 X509_free(cert);
334 }
227335 }
228336
229337 return NGX_OK;
383491 * scf->protocols = 0;
384492 * scf->dhparam = { 0, NULL };
385493 * scf->ecdh_curve = { 0, NULL };
494 * scf->client_certificate = { 0, NULL };
495 * scf->trusted_certificate = { 0, NULL };
496 * scf->crl = { 0, NULL };
386497 * scf->ciphers = { 0, NULL };
387498 * scf->shm_zone = NULL;
388499 */
392503 scf->certificate_keys = NGX_CONF_UNSET_PTR;
393504 scf->passwords = NGX_CONF_UNSET_PTR;
394505 scf->prefer_server_ciphers = NGX_CONF_UNSET;
506 scf->verify = NGX_CONF_UNSET_UINT;
507 scf->verify_depth = NGX_CONF_UNSET_UINT;
395508 scf->builtin_session_cache = NGX_CONF_UNSET;
396509 scf->session_timeout = NGX_CONF_UNSET;
397510 scf->session_tickets = NGX_CONF_UNSET;
422535 (NGX_CONF_BITMASK_SET|NGX_SSL_TLSv1
423536 |NGX_SSL_TLSv1_1|NGX_SSL_TLSv1_2));
424537
538 ngx_conf_merge_uint_value(conf->verify, prev->verify, 0);
539 ngx_conf_merge_uint_value(conf->verify_depth, prev->verify_depth, 1);
540
425541 ngx_conf_merge_ptr_value(conf->certificates, prev->certificates, NULL);
426542 ngx_conf_merge_ptr_value(conf->certificate_keys, prev->certificate_keys,
427543 NULL);
429545 ngx_conf_merge_ptr_value(conf->passwords, prev->passwords, NULL);
430546
431547 ngx_conf_merge_str_value(conf->dhparam, prev->dhparam, "");
548
549 ngx_conf_merge_str_value(conf->client_certificate, prev->client_certificate,
550 "");
551 ngx_conf_merge_str_value(conf->trusted_certificate,
552 prev->trusted_certificate, "");
553 ngx_conf_merge_str_value(conf->crl, prev->crl, "");
432554
433555 ngx_conf_merge_str_value(conf->ecdh_curve, prev->ecdh_curve,
434556 NGX_DEFAULT_ECDH_CURVE);
479601 return NGX_CONF_ERROR;
480602 }
481603
604 if (conf->verify) {
605
606 if (conf->client_certificate.len == 0 && conf->verify != 3) {
607 ngx_log_error(NGX_LOG_EMERG, cf->log, 0,
608 "no ssl_client_certificate for ssl_client_verify");
609 return NGX_CONF_ERROR;
610 }
611
612 if (ngx_ssl_client_certificate(cf, &conf->ssl,
613 &conf->client_certificate,
614 conf->verify_depth)
615 != NGX_OK)
616 {
617 return NGX_CONF_ERROR;
618 }
619
620 if (ngx_ssl_trusted_certificate(cf, &conf->ssl,
621 &conf->trusted_certificate,
622 conf->verify_depth)
623 != NGX_OK)
624 {
625 return NGX_CONF_ERROR;
626 }
627
628 if (ngx_ssl_crl(cf, &conf->ssl, &conf->crl) != NGX_OK) {
629 return NGX_CONF_ERROR;
630 }
631 }
632
482633 if (ngx_ssl_dhparam(cf, &conf->ssl, &conf->dhparam) != NGX_OK) {
483634 return NGX_CONF_ERROR;
484635 }
2222
2323 ngx_uint_t protocols;
2424
25 ngx_uint_t verify;
26 ngx_uint_t verify_depth;
27
2528 ssize_t builtin_session_cache;
2629
2730 time_t session_timeout;
3134
3235 ngx_str_t dhparam;
3336 ngx_str_t ecdh_curve;
37 ngx_str_t client_certificate;
38 ngx_str_t trusted_certificate;
39 ngx_str_t crl;
3440
3541 ngx_str_t ciphers;
3642