| | | 1 | | // Licensed to the .NET Foundation under one or more agreements. |
| | | 2 | | // The .NET Foundation licenses this file to you under the MIT license. |
| | | 3 | | |
| | | 4 | | using System.Collections.Concurrent; |
| | | 5 | | using System.Collections.Generic; |
| | | 6 | | using System.Diagnostics; |
| | | 7 | | using System.Diagnostics.CodeAnalysis; |
| | | 8 | | using System.Security.Authentication; |
| | | 9 | | using System.Security.Cryptography.X509Certificates; |
| | | 10 | | |
| | | 11 | | namespace System.Net.Security |
| | | 12 | | { |
| | | 13 | | // Implements SSL session caching mechanism based on a static table of SSL credentials. |
| | | 14 | | internal static class SslSessionsCache |
| | | 15 | | { |
| | | 16 | | private const int CheckExpiredModulo = 32; |
| | 0 | 17 | | private static readonly ConcurrentDictionary<SslCredKey, SafeCredentialReference> s_cachedCreds = |
| | 0 | 18 | | new ConcurrentDictionary<SslCredKey, SafeCredentialReference>(); |
| | | 19 | | |
| | | 20 | | // |
| | | 21 | | // Uses certificate thumb-print comparison. |
| | | 22 | | // |
| | | 23 | | private readonly struct SslCredKey : IEquatable<SslCredKey> |
| | | 24 | | { |
| | | 25 | | private readonly byte[] _thumbPrint; |
| | | 26 | | private readonly int _allowedProtocols; |
| | | 27 | | private readonly EncryptionPolicy _encryptionPolicy; |
| | | 28 | | private readonly bool _isServerMode; |
| | | 29 | | private readonly bool _sendTrustList; |
| | | 30 | | private readonly bool _checkRevocation; |
| | | 31 | | private readonly bool _allowTlsResume; |
| | | 32 | | private readonly bool _allowRsaPssPadding; |
| | | 33 | | private readonly bool _allowRsaPkcs1Padding; |
| | | 34 | | |
| | | 35 | | // |
| | | 36 | | // SECURITY: X509Certificate.GetCertHash() is virtual hence before going here, |
| | | 37 | | // the caller of this ctor has to ensure that a user cert object was inspected and |
| | | 38 | | // optionally cloned. |
| | | 39 | | // |
| | | 40 | | internal SslCredKey( |
| | | 41 | | byte[]? thumbPrint, |
| | | 42 | | int allowedProtocols, |
| | | 43 | | bool isServerMode, |
| | | 44 | | EncryptionPolicy encryptionPolicy, |
| | | 45 | | bool sendTrustList, |
| | | 46 | | bool checkRevocation, |
| | | 47 | | bool allowTlsResume, |
| | | 48 | | bool allowRsaPssPadding, |
| | | 49 | | bool allowRsaPkcs1Padding) |
| | 0 | 50 | | { |
| | 0 | 51 | | _thumbPrint = thumbPrint ?? Array.Empty<byte>(); |
| | 0 | 52 | | _allowedProtocols = allowedProtocols; |
| | 0 | 53 | | _encryptionPolicy = encryptionPolicy; |
| | 0 | 54 | | _isServerMode = isServerMode; |
| | 0 | 55 | | _checkRevocation = checkRevocation; |
| | 0 | 56 | | _sendTrustList = sendTrustList; |
| | 0 | 57 | | _allowTlsResume = allowTlsResume; |
| | 0 | 58 | | _allowRsaPssPadding = allowRsaPssPadding; |
| | 0 | 59 | | _allowRsaPkcs1Padding = allowRsaPkcs1Padding; |
| | 0 | 60 | | } |
| | | 61 | | |
| | | 62 | | public override int GetHashCode() |
| | 0 | 63 | | { |
| | 0 | 64 | | HashCode hash = default; |
| | 0 | 65 | | hash.AddBytes(_thumbPrint); |
| | 0 | 66 | | hash.Add(_allowedProtocols); |
| | 0 | 67 | | hash.Add((int)_encryptionPolicy); |
| | 0 | 68 | | hash.Add(_isServerMode); |
| | 0 | 69 | | hash.Add(_sendTrustList); |
| | 0 | 70 | | hash.Add(_checkRevocation); |
| | 0 | 71 | | hash.Add(_allowTlsResume); |
| | 0 | 72 | | hash.Add(_allowRsaPssPadding); |
| | 0 | 73 | | hash.Add(_allowRsaPkcs1Padding); |
| | | 74 | | |
| | 0 | 75 | | return hash.ToHashCode(); |
| | 0 | 76 | | } |
| | | 77 | | |
| | | 78 | | public override bool Equals([NotNullWhen(true)] object? obj) => |
| | 0 | 79 | | obj is SslCredKey other && Equals(other); |
| | | 80 | | |
| | | 81 | | public bool Equals(SslCredKey other) |
| | 0 | 82 | | { |
| | 0 | 83 | | byte[] thumbPrint = _thumbPrint; |
| | 0 | 84 | | byte[] otherThumbPrint = other._thumbPrint; |
| | | 85 | | |
| | 0 | 86 | | return |
| | 0 | 87 | | thumbPrint.Length == otherThumbPrint.Length && |
| | 0 | 88 | | _encryptionPolicy == other._encryptionPolicy && |
| | 0 | 89 | | _allowedProtocols == other._allowedProtocols && |
| | 0 | 90 | | _isServerMode == other._isServerMode && |
| | 0 | 91 | | _sendTrustList == other._sendTrustList && |
| | 0 | 92 | | _checkRevocation == other._checkRevocation && |
| | 0 | 93 | | _allowTlsResume == other._allowTlsResume && |
| | 0 | 94 | | _allowRsaPssPadding == other._allowRsaPssPadding && |
| | 0 | 95 | | _allowRsaPkcs1Padding == other._allowRsaPkcs1Padding && |
| | 0 | 96 | | thumbPrint.AsSpan().SequenceEqual(otherThumbPrint); |
| | 0 | 97 | | } |
| | | 98 | | } |
| | | 99 | | |
| | | 100 | | // |
| | | 101 | | // Returns null or a previously cached credential with an acquired reference. |
| | | 102 | | // The caller must release the reference after the security context has retained the credential. |
| | | 103 | | // |
| | | 104 | | internal static SafeFreeCredentials? TryCachedCredential( |
| | | 105 | | byte[]? thumbPrint, |
| | | 106 | | SslProtocols sslProtocols, |
| | | 107 | | bool isServer, |
| | | 108 | | EncryptionPolicy encryptionPolicy, |
| | | 109 | | bool checkRevocation, |
| | | 110 | | bool allowTlsResume, |
| | | 111 | | bool sendTrustList, |
| | | 112 | | bool allowRsaPssPadding, |
| | | 113 | | bool allowRsaPkcs1Padding) |
| | 0 | 114 | | { |
| | 0 | 115 | | if (s_cachedCreds.IsEmpty) |
| | 0 | 116 | | { |
| | 0 | 117 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(null, $"Not found, Current Cache Count = {s_cach |
| | 0 | 118 | | return null; |
| | | 119 | | } |
| | | 120 | | |
| | 0 | 121 | | var key = new SslCredKey(thumbPrint, (int)sslProtocols, isServer, encryptionPolicy, sendTrustList, checkRevo |
| | | 122 | | |
| | 0 | 123 | | SafeFreeCredentials? credentials = GetCachedCredential(key); |
| | 0 | 124 | | if (credentials == null || credentials.IsClosed || credentials.IsInvalid || credentials.Expiry < DateTime.Ut |
| | 0 | 125 | | { |
| | 0 | 126 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(null, $"Not found or invalid, Current Cache Coun |
| | 0 | 127 | | return null; |
| | | 128 | | } |
| | | 129 | | |
| | 0 | 130 | | bool addedRef = false; |
| | | 131 | | try |
| | 0 | 132 | | { |
| | 0 | 133 | | credentials.DangerousAddRef(ref addedRef); |
| | 0 | 134 | | } |
| | 0 | 135 | | catch (ObjectDisposedException) |
| | 0 | 136 | | { |
| | | 137 | | // Cache scavenging may release the last reference between lookup and DangerousAddRef. |
| | 0 | 138 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(null, "Cached credential was closed before it co |
| | 0 | 139 | | return null; |
| | | 140 | | } |
| | | 141 | | |
| | 0 | 142 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(null, $"Found a cached Handle = {credentials}"); |
| | | 143 | | |
| | 0 | 144 | | return credentials; |
| | 0 | 145 | | } |
| | | 146 | | |
| | | 147 | | private static SafeFreeCredentials? GetCachedCredential(SslCredKey key) |
| | 0 | 148 | | { |
| | 0 | 149 | | return s_cachedCreds.TryGetValue(key, out SafeCredentialReference? cached) ? cached.Target : null; |
| | 0 | 150 | | } |
| | | 151 | | |
| | | 152 | | // |
| | | 153 | | // The app is calling this method after starting an SSL handshake. |
| | | 154 | | // |
| | | 155 | | // ATTN: The thumbPrint must be from inspected and possibly cloned user Cert object or we get a security hole in |
| | | 156 | | // |
| | | 157 | | internal static void CacheCredential( |
| | | 158 | | SafeFreeCredentials creds, |
| | | 159 | | byte[]? thumbPrint, |
| | | 160 | | SslProtocols sslProtocols, |
| | | 161 | | bool isServer, |
| | | 162 | | EncryptionPolicy encryptionPolicy, |
| | | 163 | | bool checkRevocation, |
| | | 164 | | bool allowTlsResume, |
| | | 165 | | bool sendTrustList, |
| | | 166 | | bool allowRsaPssPadding, |
| | | 167 | | bool allowRsaPkcs1Padding) |
| | 0 | 168 | | { |
| | 0 | 169 | | Debug.Assert(creds != null, "creds == null"); |
| | | 170 | | |
| | 0 | 171 | | if (creds.IsInvalid) |
| | 0 | 172 | | { |
| | 0 | 173 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(null, $"Refused to cache an Invalid Handle {cred |
| | 0 | 174 | | return; |
| | | 175 | | } |
| | | 176 | | |
| | 0 | 177 | | SslCredKey key = new SslCredKey(thumbPrint, (int)sslProtocols, isServer, encryptionPolicy, sendTrustList, ch |
| | | 178 | | |
| | 0 | 179 | | SafeFreeCredentials? credentials = GetCachedCredential(key); |
| | | 180 | | |
| | 0 | 181 | | DateTime utcNow = DateTime.UtcNow; |
| | 0 | 182 | | if (credentials == null || credentials.IsClosed || credentials.IsInvalid || credentials.Expiry < utcNow) |
| | 0 | 183 | | { |
| | 0 | 184 | | lock (s_cachedCreds) |
| | 0 | 185 | | { |
| | 0 | 186 | | credentials = GetCachedCredential(key); |
| | 0 | 187 | | if (credentials == null || credentials.IsClosed || credentials.IsInvalid || credentials.Expiry < utc |
| | 0 | 188 | | { |
| | 0 | 189 | | SafeCredentialReference? cached = SafeCredentialReference.CreateReference(creds); |
| | | 190 | | |
| | 0 | 191 | | if (cached == null) |
| | 0 | 192 | | { |
| | | 193 | | // Means the handle got closed in between, return it back and let caller deal with the issue |
| | 0 | 194 | | return; |
| | | 195 | | } |
| | | 196 | | |
| | 0 | 197 | | s_cachedCreds[key] = cached; |
| | 0 | 198 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(null, $"Caching New Handle = {creds}, Cu |
| | | 199 | | |
| | 0 | 200 | | ShrinkCredentialCache(); |
| | | 201 | | |
| | 0 | 202 | | } |
| | | 203 | | else |
| | 0 | 204 | | { |
| | 0 | 205 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(null, $"CacheCredential() (locked retry) |
| | 0 | 206 | | } |
| | 0 | 207 | | } |
| | 0 | 208 | | } |
| | | 209 | | else |
| | 0 | 210 | | { |
| | 0 | 211 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(null, $"CacheCredential() Ignoring incoming hand |
| | 0 | 212 | | } |
| | | 213 | | |
| | | 214 | | static void ShrinkCredentialCache() |
| | 0 | 215 | | { |
| | | 216 | | |
| | | 217 | | // |
| | | 218 | | // A simplest way of preventing infinite cache grows. |
| | | 219 | | // |
| | | 220 | | // Security relief (DoS): |
| | | 221 | | // A number of active creds is never greater than a number of _outstanding_ |
| | | 222 | | // security sessions, i.e. SSL connections. |
| | | 223 | | // So we will try to shrink cache to the number of active creds once in a while. |
| | | 224 | | // |
| | | 225 | | // We won't shrink cache in the case when NO new handles are coming to it. |
| | | 226 | | // |
| | 0 | 227 | | if ((s_cachedCreds.Count % CheckExpiredModulo) == 0) |
| | 0 | 228 | | { |
| | 0 | 229 | | KeyValuePair<SslCredKey, SafeCredentialReference>[] toRemoveAttempt = s_cachedCreds.ToArray(); |
| | | 230 | | |
| | 0 | 231 | | for (int i = 0; i < toRemoveAttempt.Length; ++i) |
| | 0 | 232 | | { |
| | 0 | 233 | | SafeCredentialReference? cached = toRemoveAttempt[i].Value; |
| | 0 | 234 | | SafeFreeCredentials? creds = cached.Target; |
| | | 235 | | |
| | 0 | 236 | | if (creds == null) |
| | 0 | 237 | | { |
| | 0 | 238 | | s_cachedCreds.TryRemove(toRemoveAttempt[i].Key, out _); |
| | 0 | 239 | | continue; |
| | | 240 | | } |
| | | 241 | | |
| | 0 | 242 | | cached.Dispose(); |
| | 0 | 243 | | cached = SafeCredentialReference.CreateReference(creds); |
| | 0 | 244 | | if (cached != null) |
| | 0 | 245 | | { |
| | 0 | 246 | | s_cachedCreds[toRemoveAttempt[i].Key] = cached; |
| | 0 | 247 | | } |
| | | 248 | | else |
| | 0 | 249 | | { |
| | 0 | 250 | | s_cachedCreds.TryRemove(toRemoveAttempt[i].Key, out _); |
| | 0 | 251 | | } |
| | | 252 | | |
| | 0 | 253 | | } |
| | 0 | 254 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(null, $"Scavenged cache, New Cache Count = { |
| | 0 | 255 | | } |
| | 0 | 256 | | } |
| | 0 | 257 | | } |
| | | 258 | | } |
| | | 259 | | } |
| | | 260 | | |