| | | 1 | | // Licensed to the .NET Foundation under one or more agreements. |
| | | 2 | | // The .NET Foundation licenses this file to you under the MIT license. |
| | | 3 | | |
| | | 4 | | using System.Buffers; |
| | | 5 | | using System.ComponentModel; |
| | | 6 | | using System.Diagnostics; |
| | | 7 | | using System.Diagnostics.CodeAnalysis; |
| | | 8 | | using System.Security.Authentication.ExtendedProtection; |
| | | 9 | | using System.Security.Principal; |
| | | 10 | | |
| | | 11 | | namespace System.Net.Security |
| | | 12 | | { |
| | | 13 | | /// <summary> |
| | | 14 | | /// Represents a stateful authentication exchange that uses the Negotiate, NTLM or Kerberos security protocols |
| | | 15 | | /// to authenticate the client or server, in client-server communication. |
| | | 16 | | /// </summary> |
| | | 17 | | public sealed class NegotiateAuthentication : IDisposable |
| | | 18 | | { |
| | | 19 | | private readonly NegotiateAuthenticationPal _pal; |
| | | 20 | | private readonly string _requestedPackage; |
| | | 21 | | private readonly bool _isServer; |
| | | 22 | | private readonly TokenImpersonationLevel _requiredImpersonationLevel; |
| | | 23 | | private readonly ProtectionLevel _requiredProtectionLevel; |
| | | 24 | | private readonly bool _requiredMutualAuthentication; |
| | | 25 | | private readonly ExtendedProtectionPolicy? _extendedProtectionPolicy; |
| | | 26 | | private readonly bool _isSecureConnection; |
| | | 27 | | private bool _isDisposed; |
| | | 28 | | private IIdentity? _remoteIdentity; |
| | | 29 | | |
| | | 30 | | /// <summary> |
| | | 31 | | /// Initializes a new instance of the <see cref="NegotiateAuthentication"/> |
| | | 32 | | /// for client-side authentication session. |
| | | 33 | | /// </summary> |
| | | 34 | | /// <param name="clientOptions">The property bag for the authentication options.</param> |
| | | 35 | | public NegotiateAuthentication(NegotiateAuthenticationClientOptions clientOptions) : |
| | 0 | 36 | | this(clientOptions, enforceMutualAuthentication: true) |
| | 0 | 37 | | { |
| | 0 | 38 | | } |
| | | 39 | | |
| | 0 | 40 | | internal NegotiateAuthentication(NegotiateAuthenticationClientOptions clientOptions, bool enforceMutualAuthentic |
| | 0 | 41 | | { |
| | 0 | 42 | | ArgumentNullException.ThrowIfNull(clientOptions); |
| | | 43 | | |
| | 0 | 44 | | _isServer = false; |
| | 0 | 45 | | _requestedPackage = clientOptions.Package; |
| | 0 | 46 | | _requiredImpersonationLevel = TokenImpersonationLevel.None; |
| | 0 | 47 | | _requiredProtectionLevel = clientOptions.RequiredProtectionLevel; |
| | 0 | 48 | | _requiredMutualAuthentication = enforceMutualAuthentication && clientOptions.RequireMutualAuthentication; |
| | 0 | 49 | | _pal = NegotiateAuthenticationPal.Create(clientOptions); |
| | 0 | 50 | | } |
| | | 51 | | |
| | | 52 | | /// <summary> |
| | | 53 | | /// Initializes a new instance of the <see cref="NegotiateAuthentication"/> |
| | | 54 | | /// for server-side authentication session. |
| | | 55 | | /// </summary> |
| | | 56 | | /// <param name="serverOptions">The property bag for the authentication options.</param> |
| | 0 | 57 | | public NegotiateAuthentication(NegotiateAuthenticationServerOptions serverOptions) |
| | 0 | 58 | | { |
| | 0 | 59 | | ArgumentNullException.ThrowIfNull(serverOptions); |
| | | 60 | | |
| | 0 | 61 | | if (serverOptions.Policy?.PolicyEnforcement == PolicyEnforcement.Always && |
| | 0 | 62 | | !ExtendedProtectionPolicy.OSSupportsExtendedProtection) |
| | 0 | 63 | | { |
| | 0 | 64 | | throw new PlatformNotSupportedException(SR.net_extprotection_not_supported); |
| | | 65 | | } |
| | | 66 | | |
| | 0 | 67 | | _isServer = true; |
| | 0 | 68 | | _requestedPackage = serverOptions.Package; |
| | 0 | 69 | | _requiredImpersonationLevel = serverOptions.RequiredImpersonationLevel; |
| | 0 | 70 | | _requiredProtectionLevel = serverOptions.RequiredProtectionLevel; |
| | 0 | 71 | | _extendedProtectionPolicy = serverOptions.Policy; |
| | 0 | 72 | | _isSecureConnection = serverOptions.Binding != null; |
| | 0 | 73 | | _pal = NegotiateAuthenticationPal.Create(serverOptions); |
| | 0 | 74 | | } |
| | | 75 | | |
| | | 76 | | /// <summary> |
| | | 77 | | /// Releases the unmanaged resources used by the <see cref="NegotiateAuthentication"/> |
| | | 78 | | /// and optionally releases the managed resources. |
| | | 79 | | /// </summary> |
| | | 80 | | public void Dispose() |
| | 0 | 81 | | { |
| | 0 | 82 | | if (!_isDisposed) |
| | 0 | 83 | | { |
| | 0 | 84 | | _isDisposed = true; |
| | 0 | 85 | | _pal?.Dispose(); |
| | 0 | 86 | | if (_remoteIdentity is IDisposable disposableRemoteIdentity) |
| | 0 | 87 | | { |
| | 0 | 88 | | disposableRemoteIdentity.Dispose(); |
| | 0 | 89 | | } |
| | 0 | 90 | | } |
| | 0 | 91 | | } |
| | | 92 | | |
| | | 93 | | /// <summary> |
| | | 94 | | /// Gets a value that indicates whether the authentication exchange has completed. |
| | | 95 | | /// </summary> |
| | | 96 | | /// <value> |
| | | 97 | | /// <see langword="true" /> if the authentication exchange has completed; otherwise, <see langword="false" />. |
| | | 98 | | /// </value> |
| | | 99 | | /// <remarks> |
| | | 100 | | /// This property indicates whether the authentication exchange has completed, not whether authentication |
| | | 101 | | /// succeeded. A <see langword="true" /> value can be returned after either successful authentication or a |
| | | 102 | | /// terminal authentication failure. |
| | | 103 | | /// |
| | | 104 | | /// To determine whether authentication actually succeeded, inspect the <see cref="NegotiateAuthenticationStatus |
| | | 105 | | /// returned by the most recent call to <see cref="GetOutgoingBlob(ReadOnlySpan{byte}, out NegotiateAuthenticati |
| | | 106 | | /// or <see cref="GetOutgoingBlob(string, out NegotiateAuthenticationStatusCode)" />. The status is |
| | | 107 | | /// <see cref="NegotiateAuthenticationStatusCode.Completed" /> on success; any other value indicates that |
| | | 108 | | /// authentication didn't complete successfully. |
| | | 109 | | /// </remarks> |
| | 0 | 110 | | public bool IsAuthenticated => _isDisposed ? false : _pal.IsAuthenticated; |
| | | 111 | | |
| | | 112 | | /// <summary> |
| | | 113 | | /// Indicates the negotiated level of protection. |
| | | 114 | | /// </summary> |
| | | 115 | | /// <remarks> |
| | | 116 | | /// The negotiated level of protection is only available when the session |
| | | 117 | | /// authentication was finished (see <see cref="IsAuthenticated" />). The |
| | | 118 | | /// protection level can be higher than the initially requested protection |
| | | 119 | | /// level specified by <see cref="NegotiateAuthenticationClientOptions.RequiredProtectionLevel" /> or |
| | | 120 | | /// <see cref="NegotiateAuthenticationServerOptions.RequiredProtectionLevel" />. |
| | | 121 | | /// </remarks> |
| | | 122 | | public ProtectionLevel ProtectionLevel => |
| | 0 | 123 | | !IsSigned ? ProtectionLevel.None : |
| | 0 | 124 | | !IsEncrypted ? ProtectionLevel.Sign : |
| | 0 | 125 | | ProtectionLevel.EncryptAndSign; |
| | | 126 | | |
| | | 127 | | /// <summary> |
| | | 128 | | /// Indicates whether data signing was negotiated. |
| | | 129 | | /// </summary> |
| | 0 | 130 | | public bool IsSigned => _isDisposed ? false : _pal.IsSigned; |
| | | 131 | | |
| | | 132 | | /// <summary> |
| | | 133 | | /// Indicates whether data encryption was negotiated. |
| | | 134 | | /// </summary> |
| | 0 | 135 | | public bool IsEncrypted => _isDisposed ? false : _pal.IsEncrypted; |
| | | 136 | | |
| | | 137 | | /// <summary> |
| | | 138 | | /// Indicates whether both server and client have been authenticated. |
| | | 139 | | /// </summary> |
| | | 140 | | public bool IsMutuallyAuthenticated => |
| | 0 | 141 | | !_isDisposed && |
| | 0 | 142 | | !string.Equals(Package, NegotiationInfoClass.NTLM) && |
| | 0 | 143 | | _pal.IsMutuallyAuthenticated; |
| | | 144 | | |
| | | 145 | | /// <summary> |
| | | 146 | | /// Indicates whether the local side of the authentication is representing |
| | | 147 | | /// the server. |
| | | 148 | | /// </summary> |
| | 0 | 149 | | public bool IsServer => _isServer; |
| | | 150 | | |
| | | 151 | | /// <summary> |
| | | 152 | | /// Name of the negotiated authentication package. |
| | | 153 | | /// </summary> |
| | | 154 | | /// <remarks> |
| | | 155 | | /// The negotiated authentication package is only available when the session |
| | | 156 | | /// authentication was finished (see <see cref="IsAuthenticated" />). For |
| | | 157 | | /// unfinished authentication sessions the value is undefined and usually |
| | | 158 | | /// returns the initial authentication package name specified in |
| | | 159 | | /// <see cref="NegotiateAuthenticationClientOptions.Package" /> or |
| | | 160 | | /// <see cref="NegotiateAuthenticationServerOptions.Package" />. |
| | | 161 | | /// |
| | | 162 | | /// If the Negotiate package was used for authentication the value of this |
| | | 163 | | /// property will be Kerberos, NTLM, or any other specific protocol that was |
| | | 164 | | /// negotiated between both sides of the authentication. |
| | | 165 | | /// </remarks> |
| | 0 | 166 | | public string Package => _pal.Package ?? _requestedPackage; |
| | | 167 | | |
| | | 168 | | /// <summary> |
| | | 169 | | /// Gets target name (service principal name) of the server. |
| | | 170 | | /// </summary> |
| | | 171 | | /// <remarks> |
| | | 172 | | /// For server-side of the authentication the property returns the target name |
| | | 173 | | /// specified by the client after authentication completes successfully. |
| | | 174 | | /// |
| | | 175 | | /// For client-side of the authentication the property returns the target name |
| | | 176 | | /// specified in <see cref="NegotiateAuthenticationClientOptions.TargetName" />. |
| | | 177 | | /// </remarks> |
| | 0 | 178 | | public string? TargetName => _pal.TargetName; |
| | | 179 | | |
| | | 180 | | /// <summary> |
| | | 181 | | /// Gets information about the identity of the remote party. |
| | | 182 | | /// </summary> |
| | | 183 | | /// <returns> |
| | | 184 | | /// An <see cref="IIdentity" /> object that describes the identity of the remote endpoint. |
| | | 185 | | /// </returns> |
| | | 186 | | /// <exception cref="InvalidOperationException">Authentication failed or has not occurred.</exception> |
| | | 187 | | /// <exception cref="Win32Exception">System error occurred when trying to retrieve the identity.</exception> |
| | | 188 | | public IIdentity RemoteIdentity |
| | | 189 | | { |
| | | 190 | | get |
| | 0 | 191 | | { |
| | 0 | 192 | | IIdentity? identity = _remoteIdentity; |
| | 0 | 193 | | if (identity is null) |
| | 0 | 194 | | { |
| | 0 | 195 | | if (!IsAuthenticated || _isDisposed) |
| | 0 | 196 | | { |
| | 0 | 197 | | throw new InvalidOperationException(SR.net_auth_noauth); |
| | | 198 | | } |
| | | 199 | | |
| | 0 | 200 | | if (IsServer) |
| | 0 | 201 | | { |
| | 0 | 202 | | Debug.Assert(!OperatingSystem.IsTvOS(), "Server authentication is not supported on tvOS"); |
| | 0 | 203 | | _remoteIdentity = identity = _pal.RemoteIdentity; |
| | 0 | 204 | | } |
| | | 205 | | else |
| | 0 | 206 | | { |
| | 0 | 207 | | return new GenericIdentity(TargetName ?? string.Empty, Package); |
| | | 208 | | } |
| | 0 | 209 | | } |
| | 0 | 210 | | return identity; |
| | 0 | 211 | | } |
| | | 212 | | } |
| | | 213 | | |
| | | 214 | | /// <summary> |
| | | 215 | | /// One of the <see cref="TokenImpersonationLevel" /> values, indicating the negotiated |
| | | 216 | | /// level of impresonation. |
| | | 217 | | /// </summary> |
| | 0 | 218 | | public System.Security.Principal.TokenImpersonationLevel ImpersonationLevel => _pal.ImpersonationLevel; |
| | | 219 | | |
| | | 220 | | /// <summary> |
| | | 221 | | /// Evaluates an authentication token sent by the other party and returns a token in response. |
| | | 222 | | /// </summary> |
| | | 223 | | /// <param name="incomingBlob">Incoming authentication token, or empty value when initiating the authentication |
| | | 224 | | /// <param name="statusCode">Status code returned by the authentication provider.</param> |
| | | 225 | | /// <returns>Outgoing authentication token to be sent to the other party.</returns> |
| | | 226 | | /// <remarks> |
| | | 227 | | /// When initiating the authentication exchange, one of the parties starts |
| | | 228 | | /// with an empty incomingBlob parameter. |
| | | 229 | | /// |
| | | 230 | | /// Successful step of the authentication returns either <see cref="NegotiateAuthenticationStatusCode.Completed" |
| | | 231 | | /// or <see cref="NegotiateAuthenticationStatusCode.ContinueNeeded" /> status codes. |
| | | 232 | | /// Any other status code indicates an unrecoverable error. |
| | | 233 | | /// |
| | | 234 | | /// When <see cref="NegotiateAuthenticationStatusCode.ContinueNeeded" /> is returned the |
| | | 235 | | /// return value is an authentication token to be transported to the other party. |
| | | 236 | | /// </remarks> |
| | | 237 | | public byte[]? GetOutgoingBlob(ReadOnlySpan<byte> incomingBlob, out NegotiateAuthenticationStatusCode statusCode |
| | 0 | 238 | | { |
| | 0 | 239 | | if (_isDisposed) |
| | 0 | 240 | | { |
| | 0 | 241 | | throw new InvalidOperationException(SR.net_auth_noauth); |
| | | 242 | | } |
| | | 243 | | |
| | 0 | 244 | | byte[]? blob = _pal.GetOutgoingBlob(incomingBlob, out statusCode); |
| | | 245 | | |
| | | 246 | | // Additional policy validation |
| | 0 | 247 | | if (statusCode == NegotiateAuthenticationStatusCode.Completed) |
| | 0 | 248 | | { |
| | 0 | 249 | | if (IsServer && _extendedProtectionPolicy != null && !CheckSpn()) |
| | 0 | 250 | | { |
| | 0 | 251 | | statusCode = NegotiateAuthenticationStatusCode.TargetUnknown; |
| | 0 | 252 | | } |
| | 0 | 253 | | else if (_requiredImpersonationLevel != TokenImpersonationLevel.None && ImpersonationLevel < _requiredIm |
| | 0 | 254 | | { |
| | 0 | 255 | | statusCode = NegotiateAuthenticationStatusCode.ImpersonationValidationFailed; |
| | 0 | 256 | | } |
| | 0 | 257 | | else if (_requiredProtectionLevel != ProtectionLevel.None && ProtectionLevel < _requiredProtectionLevel) |
| | 0 | 258 | | { |
| | 0 | 259 | | statusCode = NegotiateAuthenticationStatusCode.SecurityQosFailed; |
| | 0 | 260 | | } |
| | 0 | 261 | | else if (_requiredMutualAuthentication && !IsMutuallyAuthenticated) |
| | 0 | 262 | | { |
| | 0 | 263 | | statusCode = NegotiateAuthenticationStatusCode.SecurityQosFailed; |
| | 0 | 264 | | } |
| | 0 | 265 | | } |
| | | 266 | | |
| | 0 | 267 | | return blob; |
| | 0 | 268 | | } |
| | | 269 | | |
| | | 270 | | /// <summary> |
| | | 271 | | /// Evaluates an authentication token sent by the other party and returns a token in response. |
| | | 272 | | /// </summary> |
| | | 273 | | /// <param name="incomingBlob">Incoming authentication token, or empty value when initiating the authentication |
| | | 274 | | /// <param name="statusCode">Status code returned by the authentication provider.</param> |
| | | 275 | | /// <returns>Outgoing authentication token to be sent to the other party, encoded as base64.</returns> |
| | | 276 | | /// <remarks> |
| | | 277 | | /// When initiating the authentication exchange, one of the parties starts |
| | | 278 | | /// with an empty incomingBlob parameter. |
| | | 279 | | /// |
| | | 280 | | /// Successful step of the authentication returns either <see cref="NegotiateAuthenticationStatusCode.Completed" |
| | | 281 | | /// or <see cref="NegotiateAuthenticationStatusCode.ContinueNeeded" /> status codes. |
| | | 282 | | /// Any other status code indicates an unrecoverable error. |
| | | 283 | | /// |
| | | 284 | | /// When <see cref="NegotiateAuthenticationStatusCode.ContinueNeeded" /> is returned the |
| | | 285 | | /// return value is an authentication token to be transported to the other party. |
| | | 286 | | /// </remarks> |
| | | 287 | | public string? GetOutgoingBlob(string? incomingBlob, out NegotiateAuthenticationStatusCode statusCode) |
| | 0 | 288 | | { |
| | 0 | 289 | | byte[]? rentedBuffer = null; |
| | | 290 | | try |
| | 0 | 291 | | { |
| | 0 | 292 | | ReadOnlySpan<byte> decodedIncomingBlob = default; |
| | 0 | 293 | | if (!string.IsNullOrEmpty(incomingBlob)) |
| | 0 | 294 | | { |
| | 0 | 295 | | rentedBuffer = ArrayPool<byte>.Shared.Rent((incomingBlob.Length / 4) * 3); |
| | 0 | 296 | | if (!Convert.TryFromBase64String(incomingBlob, rentedBuffer, out int decodedLength)) |
| | 0 | 297 | | { |
| | 0 | 298 | | statusCode = NegotiateAuthenticationStatusCode.InvalidToken; |
| | 0 | 299 | | return null; |
| | | 300 | | } |
| | | 301 | | |
| | 0 | 302 | | decodedIncomingBlob = rentedBuffer.AsSpan(0, decodedLength); |
| | 0 | 303 | | } |
| | | 304 | | |
| | 0 | 305 | | byte[]? decodedOutgoingBlob = GetOutgoingBlob(decodedIncomingBlob, out statusCode); |
| | | 306 | | |
| | 0 | 307 | | string? outgoingBlob = null; |
| | 0 | 308 | | if (decodedOutgoingBlob != null && decodedOutgoingBlob.Length > 0) |
| | 0 | 309 | | { |
| | 0 | 310 | | outgoingBlob = Convert.ToBase64String(decodedOutgoingBlob); |
| | 0 | 311 | | } |
| | | 312 | | |
| | 0 | 313 | | return outgoingBlob; |
| | | 314 | | } |
| | | 315 | | finally |
| | 0 | 316 | | { |
| | 0 | 317 | | if (rentedBuffer is not null) |
| | 0 | 318 | | { |
| | 0 | 319 | | ArrayPool<byte>.Shared.Return(rentedBuffer, clearArray: true); |
| | 0 | 320 | | } |
| | 0 | 321 | | } |
| | 0 | 322 | | } |
| | | 323 | | |
| | | 324 | | /// <summary> |
| | | 325 | | /// Wrap an input message with signature and optionally with an encryption. |
| | | 326 | | /// </summary> |
| | | 327 | | /// <param name="input">Input message to be wrapped.</param> |
| | | 328 | | /// <param name="outputWriter">Buffer writer where the wrapped message is written.</param> |
| | | 329 | | /// <param name="requestEncryption">Specifies whether encryption is requested.</param> |
| | | 330 | | /// <param name="isEncrypted">Specifies whether encryption was applied in the wrapping.</param> |
| | | 331 | | /// <returns> |
| | | 332 | | /// <see cref="NegotiateAuthenticationStatusCode.Completed" /> on success, other |
| | | 333 | | /// <see cref="NegotiateAuthenticationStatusCode" /> values on failure. |
| | | 334 | | /// </returns> |
| | | 335 | | /// <remarks> |
| | | 336 | | /// Like the <see href="https://datatracker.ietf.org/doc/html/rfc2743#page-65">GSS_Wrap</see> API |
| | | 337 | | /// the authentication protocol implementation may choose to override the requested value in the |
| | | 338 | | /// requestEncryption parameter. This may result in either downgrade or upgrade of the protection |
| | | 339 | | /// level. |
| | | 340 | | /// </remarks> |
| | | 341 | | /// <exception cref="InvalidOperationException">Authentication failed or has not occurred.</exception> |
| | | 342 | | public NegotiateAuthenticationStatusCode Wrap(ReadOnlySpan<byte> input, IBufferWriter<byte> outputWriter, bool r |
| | 0 | 343 | | { |
| | 0 | 344 | | if (!IsAuthenticated || _isDisposed) |
| | 0 | 345 | | { |
| | 0 | 346 | | throw new InvalidOperationException(SR.net_auth_noauth); |
| | | 347 | | } |
| | | 348 | | |
| | 0 | 349 | | return _pal.Wrap(input, outputWriter, requestEncryption, out isEncrypted); |
| | 0 | 350 | | } |
| | | 351 | | |
| | | 352 | | /// <summary> |
| | | 353 | | /// Unwrap an input message with signature or encryption applied by the other party. |
| | | 354 | | /// </summary> |
| | | 355 | | /// <param name="input">Input message to be unwrapped.</param> |
| | | 356 | | /// <param name="outputWriter">Buffer writer where the unwrapped message is written.</param> |
| | | 357 | | /// <param name="wasEncrypted"> |
| | | 358 | | /// On output specifies whether the wrapped message had encryption applied. |
| | | 359 | | /// </param> |
| | | 360 | | /// <returns> |
| | | 361 | | /// <see cref="NegotiateAuthenticationStatusCode.Completed" /> on success. |
| | | 362 | | /// <see cref="NegotiateAuthenticationStatusCode.MessageAltered" /> if the message signature was |
| | | 363 | | /// invalid. |
| | | 364 | | /// <see cref="NegotiateAuthenticationStatusCode.InvalidToken" /> if the wrapped message was |
| | | 365 | | /// in invalid format. |
| | | 366 | | /// Other <see cref="NegotiateAuthenticationStatusCode" /> values on failure. |
| | | 367 | | /// </returns> |
| | | 368 | | /// <exception cref="InvalidOperationException">Authentication failed or has not occurred.</exception> |
| | | 369 | | public NegotiateAuthenticationStatusCode Unwrap(ReadOnlySpan<byte> input, IBufferWriter<byte> outputWriter, out |
| | 0 | 370 | | { |
| | 0 | 371 | | if (!IsAuthenticated || _isDisposed) |
| | 0 | 372 | | { |
| | 0 | 373 | | throw new InvalidOperationException(SR.net_auth_noauth); |
| | | 374 | | } |
| | | 375 | | |
| | 0 | 376 | | return _pal.Unwrap(input, outputWriter, out wasEncrypted); |
| | 0 | 377 | | } |
| | | 378 | | |
| | | 379 | | /// <summary> |
| | | 380 | | /// Unwrap an input message with signature or encryption applied by the other party. |
| | | 381 | | /// </summary> |
| | | 382 | | /// <param name="input">Input message to be unwrapped. On output contains the decoded data.</param> |
| | | 383 | | /// <param name="unwrappedOffset">Offset in the input buffer where the unwrapped message was written.</param> |
| | | 384 | | /// <param name="unwrappedLength">Length of the unwrapped message.</param> |
| | | 385 | | /// <param name="wasEncrypted"> |
| | | 386 | | /// On output specifies whether the wrapped message had encryption applied. |
| | | 387 | | /// </param> |
| | | 388 | | /// <returns> |
| | | 389 | | /// <see cref="NegotiateAuthenticationStatusCode.Completed" /> on success. |
| | | 390 | | /// <see cref="NegotiateAuthenticationStatusCode.MessageAltered" /> if the message signature was |
| | | 391 | | /// invalid. |
| | | 392 | | /// <see cref="NegotiateAuthenticationStatusCode.InvalidToken" /> if the wrapped message was |
| | | 393 | | /// in invalid format. |
| | | 394 | | /// Other <see cref="NegotiateAuthenticationStatusCode" /> values on failure. |
| | | 395 | | /// </returns> |
| | | 396 | | /// <exception cref="InvalidOperationException">Authentication failed or has not occurred.</exception> |
| | | 397 | | public NegotiateAuthenticationStatusCode UnwrapInPlace(Span<byte> input, out int unwrappedOffset, out int unwrap |
| | 0 | 398 | | { |
| | 0 | 399 | | if (!IsAuthenticated || _isDisposed) |
| | 0 | 400 | | { |
| | 0 | 401 | | throw new InvalidOperationException(SR.net_auth_noauth); |
| | | 402 | | } |
| | | 403 | | |
| | 0 | 404 | | return _pal.UnwrapInPlace(input, out unwrappedOffset, out unwrappedLength, out wasEncrypted); |
| | 0 | 405 | | } |
| | | 406 | | |
| | | 407 | | /// <summary> |
| | | 408 | | /// Computes the integrity check of a given message. |
| | | 409 | | /// </summary> |
| | | 410 | | /// <param name="message">Input message for MIC calculation.</param> |
| | | 411 | | /// <param name="signatureWriter">Buffer writer where the MIC is written.</param> |
| | | 412 | | /// <remarks> |
| | | 413 | | /// Implements the GSSAPI GetMIC operation. |
| | | 414 | | /// |
| | | 415 | | /// The method modifies the internal state and may update sequence numbers depending on the |
| | | 416 | | /// selected algorithm. Two successive invocations thus don't produce the same result and |
| | | 417 | | /// it's important to carefully pair GetMIC and VerifyMIC calls on the both sides of the |
| | | 418 | | /// authenticated session. |
| | | 419 | | /// </remarks> |
| | | 420 | | /// <exception cref="InvalidOperationException">Authentication failed or has not occurred.</exception> |
| | | 421 | | public void ComputeIntegrityCheck(ReadOnlySpan<byte> message, IBufferWriter<byte> signatureWriter) |
| | 0 | 422 | | { |
| | 0 | 423 | | if (!IsAuthenticated || _isDisposed) |
| | 0 | 424 | | { |
| | 0 | 425 | | throw new InvalidOperationException(SR.net_auth_noauth); |
| | | 426 | | } |
| | | 427 | | |
| | 0 | 428 | | _pal.GetMIC(message, signatureWriter); |
| | 0 | 429 | | } |
| | | 430 | | |
| | | 431 | | /// <summary> |
| | | 432 | | /// Verifies the message integrity check of a given message. |
| | | 433 | | /// </summary> |
| | | 434 | | /// <param name="message">Input message for MIC calculation.</param> |
| | | 435 | | /// <param name="signature">MIC to be verified.</param> |
| | | 436 | | /// <returns>For successfully verified MIC, the method returns true.</returns> |
| | | 437 | | /// <remarks> |
| | | 438 | | /// Implements the GSSAPI VerifyMIC operation. |
| | | 439 | | /// |
| | | 440 | | /// The method modifies the internal state and may update sequence numbers depending on the |
| | | 441 | | /// selected algorithm. Two successive invocations thus don't produce the same result and |
| | | 442 | | /// it's important to carefully pair GetMIC and VerifyMIC calls on the both sides of the |
| | | 443 | | /// authenticated session. |
| | | 444 | | /// </remarks> |
| | | 445 | | /// <exception cref="InvalidOperationException">Authentication failed or has not occurred.</exception> |
| | | 446 | | public bool VerifyIntegrityCheck(ReadOnlySpan<byte> message, ReadOnlySpan<byte> signature) |
| | 0 | 447 | | { |
| | 0 | 448 | | if (!IsAuthenticated || _isDisposed) |
| | 0 | 449 | | { |
| | 0 | 450 | | throw new InvalidOperationException(SR.net_auth_noauth); |
| | | 451 | | } |
| | | 452 | | |
| | 0 | 453 | | return _pal.VerifyMIC(message, signature); |
| | 0 | 454 | | } |
| | | 455 | | |
| | | 456 | | private bool CheckSpn() |
| | 0 | 457 | | { |
| | 0 | 458 | | Debug.Assert(_extendedProtectionPolicy != null); |
| | | 459 | | |
| | 0 | 460 | | if (_pal.Package == NegotiationInfoClass.Kerberos) |
| | 0 | 461 | | { |
| | 0 | 462 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, SR.net_log_listener_no_spn_kerberos); |
| | 0 | 463 | | return true; |
| | | 464 | | } |
| | | 465 | | |
| | 0 | 466 | | if (_extendedProtectionPolicy.PolicyEnforcement == PolicyEnforcement.Never) |
| | 0 | 467 | | { |
| | 0 | 468 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, SR.net_log_listener_no_spn_disabled); |
| | 0 | 469 | | return true; |
| | | 470 | | } |
| | | 471 | | |
| | 0 | 472 | | if (_isSecureConnection && _extendedProtectionPolicy.ProtectionScenario == ProtectionScenario.TransportSelec |
| | 0 | 473 | | { |
| | 0 | 474 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, SR.net_log_listener_no_spn_cbt); |
| | 0 | 475 | | return true; |
| | | 476 | | } |
| | | 477 | | |
| | 0 | 478 | | if (_extendedProtectionPolicy.CustomServiceNames == null) |
| | 0 | 479 | | { |
| | 0 | 480 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, SR.net_log_listener_no_spns); |
| | 0 | 481 | | return true; |
| | | 482 | | } |
| | | 483 | | |
| | 0 | 484 | | string? clientSpn = _pal.TargetName; |
| | | 485 | | |
| | 0 | 486 | | if (string.IsNullOrEmpty(clientSpn)) |
| | 0 | 487 | | { |
| | 0 | 488 | | if (_extendedProtectionPolicy.PolicyEnforcement == PolicyEnforcement.WhenSupported) |
| | 0 | 489 | | { |
| | 0 | 490 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, SR.net_log_listener_no_spn_whensupport |
| | 0 | 491 | | return true; |
| | | 492 | | } |
| | | 493 | | else |
| | 0 | 494 | | { |
| | 0 | 495 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, SR.net_log_listener_spn_failed_always) |
| | 0 | 496 | | return false; |
| | | 497 | | } |
| | | 498 | | } |
| | | 499 | | |
| | 0 | 500 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, SR.net_log_listener_spn, clientSpn); |
| | 0 | 501 | | bool found = _extendedProtectionPolicy.CustomServiceNames.Contains(clientSpn); |
| | | 502 | | |
| | 0 | 503 | | if (NetEventSource.Log.IsEnabled()) |
| | 0 | 504 | | { |
| | 0 | 505 | | if (found) |
| | 0 | 506 | | { |
| | 0 | 507 | | NetEventSource.Info(this, SR.net_log_listener_spn_passed); |
| | 0 | 508 | | } |
| | | 509 | | else |
| | 0 | 510 | | { |
| | 0 | 511 | | NetEventSource.Info(this, SR.net_log_listener_spn_failed); |
| | | 512 | | |
| | 0 | 513 | | if (_extendedProtectionPolicy.CustomServiceNames.Count == 0) |
| | 0 | 514 | | { |
| | 0 | 515 | | NetEventSource.Info(this, SR.net_log_listener_spn_failed_empty); |
| | 0 | 516 | | } |
| | | 517 | | else |
| | 0 | 518 | | { |
| | 0 | 519 | | NetEventSource.Info(this, SR.net_log_listener_spn_failed_dump); |
| | 0 | 520 | | foreach (string serviceName in _extendedProtectionPolicy.CustomServiceNames) |
| | 0 | 521 | | { |
| | 0 | 522 | | NetEventSource.Info(this, "\t" + serviceName); |
| | 0 | 523 | | } |
| | 0 | 524 | | } |
| | 0 | 525 | | } |
| | 0 | 526 | | } |
| | | 527 | | |
| | 0 | 528 | | return found; |
| | 0 | 529 | | } |
| | | 530 | | } |
| | | 531 | | } |
| | | 532 | | |