| | | 1 | | // Licensed to the .NET Foundation under one or more agreements. |
| | | 2 | | // The .NET Foundation licenses this file to you under the MIT license. |
| | | 3 | | |
| | | 4 | | using System.Collections.Generic; |
| | | 5 | | using System.ComponentModel; |
| | | 6 | | using System.Diagnostics; |
| | | 7 | | using System.Runtime.CompilerServices; |
| | | 8 | | using System.Runtime.InteropServices; |
| | | 9 | | using System.Security.Authentication; |
| | | 10 | | using System.Security.Authentication.ExtendedProtection; |
| | | 11 | | using System.Security.Cryptography.X509Certificates; |
| | | 12 | | using System.Security.Principal; |
| | | 13 | | using Microsoft.Win32.SafeHandles; |
| | | 14 | | |
| | | 15 | | namespace System.Net.Security |
| | | 16 | | { |
| | | 17 | | internal static class SslStreamPal |
| | | 18 | | { |
| | 0 | 19 | | private static readonly byte[] s_http1 = Interop.Sec_Application_Protocols.ToByteArray(new List<SslApplicationPr |
| | 0 | 20 | | private static readonly byte[] s_http2 = Interop.Sec_Application_Protocols.ToByteArray(new List<SslApplicationPr |
| | 0 | 21 | | private static readonly byte[] s_http12 = Interop.Sec_Application_Protocols.ToByteArray(new List<SslApplicationP |
| | 0 | 22 | | private static readonly byte[] s_http21 = Interop.Sec_Application_Protocols.ToByteArray(new List<SslApplicationP |
| | | 23 | | |
| | 0 | 24 | | private static readonly bool UseNewCryptoApi = |
| | 0 | 25 | | // On newer Windows version we use new API to get TLS1.3. |
| | 0 | 26 | | // API is supported since Windows 10 1809 (17763) but there is no reason to use at the moment. |
| | 0 | 27 | | Environment.OSVersion.Version.Major >= 10 && Environment.OSVersion.Version.Build >= 18836; |
| | | 28 | | |
| | | 29 | | // On Windows Server 2022 (build 20348) and older, Schannel has a race condition where |
| | | 30 | | // ApplyControlToken(SSL_SESSION_DISABLE_RECONNECTS) doesn't reliably prevent the session |
| | | 31 | | // cache from being repopulated. The workaround is to delete the context and retry |
| | | 32 | | // InitializeSecurityContext after ApplyControlToken. This follows the same pattern used by |
| | | 33 | | // Schannel's own webcli.c test and http.sys. The issue was fixed in newer Schannel builds |
| | | 34 | | // shipping with Windows 11+ (build 22000+). |
| | 0 | 35 | | private static readonly bool NeedsDisableTlsResumeWorkaround = |
| | 0 | 36 | | Environment.OSVersion.Version.Build < 22000; |
| | | 37 | | |
| | | 38 | | private const string SecurityPackage = "Microsoft Unified Security Protocol Provider"; |
| | | 39 | | |
| | | 40 | | private const Interop.SspiCli.ContextFlags RequiredFlags = |
| | | 41 | | Interop.SspiCli.ContextFlags.ReplayDetect | |
| | | 42 | | Interop.SspiCli.ContextFlags.SequenceDetect | |
| | | 43 | | Interop.SspiCli.ContextFlags.Confidentiality | |
| | | 44 | | Interop.SspiCli.ContextFlags.AllocateMemory; |
| | | 45 | | |
| | | 46 | | private const Interop.SspiCli.ContextFlags ServerRequiredFlags = |
| | | 47 | | RequiredFlags | Interop.SspiCli.ContextFlags.AcceptStream | Interop.SspiCli.ContextFlags.AcceptExtendedError |
| | | 48 | | |
| | | 49 | | public static Exception GetException(SecurityStatusPal status) |
| | 0 | 50 | | { |
| | 0 | 51 | | int win32Code = (int)SecurityStatusAdapterPal.GetInteropFromSecurityStatusPal(status); |
| | 0 | 52 | | return new Win32Exception(win32Code); |
| | 0 | 53 | | } |
| | | 54 | | |
| | | 55 | | internal const bool StartMutualAuthAsAnonymous = true; |
| | | 56 | | internal const bool CertValidationInCallback = false; |
| | | 57 | | internal const bool CanEncryptEmptyMessage = true; |
| | | 58 | | internal const bool CanGenerateCustomAlerts = true; |
| | | 59 | | |
| | | 60 | | internal static bool CanGenerateCustomAlertsForContext(SafeDeleteContext? _) |
| | 0 | 61 | | { |
| | 0 | 62 | | return CanGenerateCustomAlerts; |
| | 0 | 63 | | } |
| | | 64 | | |
| | 0 | 65 | | private static readonly byte[] s_sessionTokenBuffer = InitSessionTokenBuffer(); |
| | | 66 | | |
| | | 67 | | private static byte[] InitSessionTokenBuffer() |
| | 0 | 68 | | { |
| | 0 | 69 | | var schannelSessionToken = new Interop.SChannel.SCHANNEL_SESSION_TOKEN() |
| | 0 | 70 | | { |
| | 0 | 71 | | dwTokenType = Interop.SChannel.SCHANNEL_SESSION, |
| | 0 | 72 | | dwFlags = Interop.SChannel.SSL_SESSION_DISABLE_RECONNECTS, |
| | 0 | 73 | | }; |
| | 0 | 74 | | return MemoryMarshal.AsBytes(new ReadOnlySpan<Interop.SChannel.SCHANNEL_SESSION_TOKEN>(in schannelSessionTok |
| | 0 | 75 | | } |
| | | 76 | | |
| | | 77 | | public static void VerifyPackageInfo() |
| | | 78 | | { |
| | | 79 | | SSPIWrapper.GetVerifyPackageInfo(GlobalSSPI.SSPISecureChannel, SecurityPackage, true); |
| | | 80 | | } |
| | | 81 | | |
| | | 82 | | private static unsafe void SetAlpn(ref InputSecurityBuffers inputBuffers, List<SslApplicationProtocol> alpn, Spa |
| | 0 | 83 | | { |
| | 0 | 84 | | if (alpn.Count == 1 && alpn[0] == SslApplicationProtocol.Http11) |
| | 0 | 85 | | { |
| | 0 | 86 | | inputBuffers.SetNextBuffer(new InputSecurityBuffer(s_http1, SecurityBufferType.SECBUFFER_APPLICATION_PRO |
| | 0 | 87 | | } |
| | 0 | 88 | | else if (alpn.Count == 1 && alpn[0] == SslApplicationProtocol.Http2) |
| | 0 | 89 | | { |
| | 0 | 90 | | inputBuffers.SetNextBuffer(new InputSecurityBuffer(s_http2, SecurityBufferType.SECBUFFER_APPLICATION_PRO |
| | 0 | 91 | | } |
| | 0 | 92 | | else if (alpn.Count == 2 && alpn[0] == SslApplicationProtocol.Http11 && alpn[1] == SslApplicationProtocol.Ht |
| | 0 | 93 | | { |
| | 0 | 94 | | inputBuffers.SetNextBuffer(new InputSecurityBuffer(s_http12, SecurityBufferType.SECBUFFER_APPLICATION_PR |
| | 0 | 95 | | } |
| | 0 | 96 | | else if (alpn.Count == 2 && alpn[0] == SslApplicationProtocol.Http2 && alpn[1] == SslApplicationProtocol.Htt |
| | 0 | 97 | | { |
| | 0 | 98 | | inputBuffers.SetNextBuffer(new InputSecurityBuffer(s_http21, SecurityBufferType.SECBUFFER_APPLICATION_PR |
| | 0 | 99 | | } |
| | | 100 | | else |
| | 0 | 101 | | { |
| | 0 | 102 | | int protocolLength = Interop.Sec_Application_Protocols.GetProtocolLength(alpn); |
| | 0 | 103 | | int bufferLength = sizeof(Interop.Sec_Application_Protocols) + protocolLength; |
| | | 104 | | |
| | 0 | 105 | | Span<byte> alpnBuffer = bufferLength <= localBuffer.Length ? localBuffer : new byte[bufferLength]; |
| | 0 | 106 | | Interop.Sec_Application_Protocols.SetProtocols(alpnBuffer, alpn, protocolLength); |
| | 0 | 107 | | inputBuffers.SetNextBuffer(new InputSecurityBuffer(alpnBuffer, SecurityBufferType.SECBUFFER_APPLICATION_ |
| | 0 | 108 | | } |
| | 0 | 109 | | } |
| | | 110 | | |
| | | 111 | | public static SecurityStatusPal SelectApplicationProtocol( |
| | | 112 | | SafeFreeCredentials? credentialsHandle, |
| | | 113 | | SafeDeleteSslContext? context, |
| | | 114 | | SslAuthenticationOptions sslAuthenticationOptions, |
| | | 115 | | ReadOnlySpan<byte> clientProtocols) |
| | 0 | 116 | | { |
| | 0 | 117 | | throw new PlatformNotSupportedException(nameof(SelectApplicationProtocol)); |
| | | 118 | | } |
| | | 119 | | |
| | | 120 | | public static unsafe ProtocolToken AcceptSecurityContext( |
| | | 121 | | ref SafeFreeCredentials? credentialsHandle, |
| | | 122 | | ref SafeDeleteSslContext? context, |
| | | 123 | | ReadOnlySpan<byte> inputBuffer, |
| | | 124 | | out int consumed, |
| | | 125 | | SslAuthenticationOptions sslAuthenticationOptions) |
| | 0 | 126 | | { |
| | 0 | 127 | | Interop.SspiCli.ContextFlags unusedAttributes = default; |
| | | 128 | | |
| | 0 | 129 | | scoped InputSecurityBuffers inputBuffers = default; |
| | 0 | 130 | | inputBuffers.SetNextBuffer(new InputSecurityBuffer(inputBuffer, SecurityBufferType.SECBUFFER_TOKEN)); |
| | 0 | 131 | | inputBuffers.SetNextBuffer(new InputSecurityBuffer(default, SecurityBufferType.SECBUFFER_EMPTY)); |
| | 0 | 132 | | if (context == null && sslAuthenticationOptions.ApplicationProtocols != null && sslAuthenticationOptions.App |
| | 0 | 133 | | { |
| | 0 | 134 | | Span<byte> localBuffer = stackalloc byte[64]; |
| | 0 | 135 | | SetAlpn(ref inputBuffers, sslAuthenticationOptions.ApplicationProtocols, localBuffer); |
| | 0 | 136 | | } |
| | | 137 | | |
| | 0 | 138 | | ProtocolToken token = default; |
| | 0 | 139 | | token.RentBuffer = true; |
| | | 140 | | |
| | 0 | 141 | | int errorCode = SSPIWrapper.AcceptSecurityContext( |
| | 0 | 142 | | GlobalSSPI.SSPISecureChannel, |
| | 0 | 143 | | credentialsHandle, |
| | 0 | 144 | | ref context, |
| | 0 | 145 | | ServerRequiredFlags | (sslAuthenticationOptions.RemoteCertRequired ? Interop.SspiCli.ContextFlags.Mutual |
| | 0 | 146 | | Interop.SspiCli.Endianness.SECURITY_NATIVE_DREP, |
| | 0 | 147 | | ref inputBuffers, |
| | 0 | 148 | | ref token, |
| | 0 | 149 | | ref unusedAttributes); |
| | | 150 | | |
| | 0 | 151 | | consumed = inputBuffer.Length; |
| | 0 | 152 | | if (inputBuffers._item1.Type == SecurityBufferType.SECBUFFER_EXTRA) |
| | 0 | 153 | | { |
| | | 154 | | // not all data were consumed |
| | 0 | 155 | | consumed -= inputBuffers._item1.Token.Length; |
| | 0 | 156 | | } |
| | | 157 | | |
| | 0 | 158 | | token.Status = SecurityStatusAdapterPal.GetSecurityStatusPalFromNativeInt(errorCode); |
| | 0 | 159 | | return token; |
| | 0 | 160 | | } |
| | | 161 | | |
| | | 162 | | public static bool TryUpdateClintCertificate( |
| | | 163 | | SafeFreeCredentials? _1, |
| | | 164 | | SafeDeleteSslContext? _2, |
| | | 165 | | SslAuthenticationOptions _3) |
| | 0 | 166 | | { |
| | | 167 | | // We will need to allocate new credential handle |
| | 0 | 168 | | return false; |
| | 0 | 169 | | } |
| | | 170 | | |
| | | 171 | | public static unsafe ProtocolToken InitializeSecurityContext( |
| | | 172 | | ref SafeFreeCredentials? credentialsHandle, |
| | | 173 | | ref SafeDeleteSslContext? context, |
| | | 174 | | string? targetName, |
| | | 175 | | ReadOnlySpan<byte> inputBuffer, |
| | | 176 | | out int consumed, |
| | | 177 | | SslAuthenticationOptions sslAuthenticationOptions) |
| | 0 | 178 | | { |
| | 0 | 179 | | bool newContext = context == null; |
| | 0 | 180 | | Interop.SspiCli.ContextFlags unusedAttributes = default; |
| | | 181 | | |
| | 0 | 182 | | scoped InputSecurityBuffers inputBuffers = default; |
| | 0 | 183 | | inputBuffers.SetNextBuffer(new InputSecurityBuffer(inputBuffer, SecurityBufferType.SECBUFFER_TOKEN)); |
| | 0 | 184 | | inputBuffers.SetNextBuffer(new InputSecurityBuffer(default, SecurityBufferType.SECBUFFER_EMPTY)); |
| | 0 | 185 | | if (context == null && sslAuthenticationOptions.ApplicationProtocols != null && sslAuthenticationOptions.App |
| | 0 | 186 | | { |
| | 0 | 187 | | Span<byte> localBuffer = stackalloc byte[64]; |
| | 0 | 188 | | SetAlpn(ref inputBuffers, sslAuthenticationOptions.ApplicationProtocols, localBuffer); |
| | 0 | 189 | | } |
| | | 190 | | |
| | 0 | 191 | | ProtocolToken token = default; |
| | 0 | 192 | | token.RentBuffer = true; |
| | 0 | 193 | | int errorCode = SSPIWrapper.InitializeSecurityContext( |
| | 0 | 194 | | GlobalSSPI.SSPISecureChannel, |
| | 0 | 195 | | ref credentialsHandle, |
| | 0 | 196 | | ref context, |
| | 0 | 197 | | targetName, |
| | 0 | 198 | | RequiredFlags | Interop.SspiCli.ContextFlags.InitManualCredValidation, |
| | 0 | 199 | | Interop.SspiCli.Endianness.SECURITY_NATIVE_DREP, |
| | 0 | 200 | | ref inputBuffers, |
| | 0 | 201 | | ref token, |
| | 0 | 202 | | ref unusedAttributes); |
| | | 203 | | |
| | 0 | 204 | | token.Status = SecurityStatusAdapterPal.GetSecurityStatusPalFromNativeInt(errorCode); |
| | | 205 | | |
| | 0 | 206 | | bool allowTlsResume = sslAuthenticationOptions.AllowTlsResume && !LocalAppContextSwitches.DisableTlsResume; |
| | | 207 | | |
| | 0 | 208 | | if (!allowTlsResume && newContext && context != null) |
| | 0 | 209 | | { |
| | 0 | 210 | | var securityBuffer = new SecurityBuffer(s_sessionTokenBuffer, SecurityBufferType.SECBUFFER_TOKEN); |
| | | 211 | | |
| | 0 | 212 | | SecurityStatusPal result = SecurityStatusAdapterPal.GetSecurityStatusPalFromNativeInt(SSPIWrapper.ApplyC |
| | 0 | 213 | | GlobalSSPI.SSPISecureChannel, |
| | 0 | 214 | | ref context, |
| | 0 | 215 | | in securityBuffer)); |
| | | 216 | | |
| | 0 | 217 | | if (result.ErrorCode != SecurityStatusPalErrorCode.OK) |
| | 0 | 218 | | { |
| | 0 | 219 | | token.Status = result; |
| | 0 | 220 | | } |
| | 0 | 221 | | else if (NeedsDisableTlsResumeWorkaround) |
| | 0 | 222 | | { |
| | | 223 | | // On affected builds, Schannel's internal LookupCacheByName finds a fresh |
| | | 224 | | // resumable entry and embeds the session ID in the ClientHello before |
| | | 225 | | // ApplyControlToken can expire it. Deleting the context and retrying ISC |
| | | 226 | | // ensures the new ClientHello is generated without a stale session ID. |
| | | 227 | | // We can reuse inputBuffers since this only runs on the very first ISC call |
| | | 228 | | // (newContext == true) where the input is empty. |
| | 0 | 229 | | context?.Dispose(); |
| | 0 | 230 | | context = null; |
| | 0 | 231 | | token.ReleasePayload(); |
| | 0 | 232 | | token = default; |
| | 0 | 233 | | token.RentBuffer = true; |
| | | 234 | | |
| | 0 | 235 | | errorCode = SSPIWrapper.InitializeSecurityContext( |
| | 0 | 236 | | GlobalSSPI.SSPISecureChannel, |
| | 0 | 237 | | ref credentialsHandle, |
| | 0 | 238 | | ref context, |
| | 0 | 239 | | targetName, |
| | 0 | 240 | | RequiredFlags | Interop.SspiCli.ContextFlags.InitManualCredValidation, |
| | 0 | 241 | | Interop.SspiCli.Endianness.SECURITY_NATIVE_DREP, |
| | 0 | 242 | | ref inputBuffers, |
| | 0 | 243 | | ref token, |
| | 0 | 244 | | ref unusedAttributes); |
| | | 245 | | |
| | 0 | 246 | | token.Status = SecurityStatusAdapterPal.GetSecurityStatusPalFromNativeInt(errorCode); |
| | 0 | 247 | | } |
| | 0 | 248 | | } |
| | | 249 | | |
| | 0 | 250 | | consumed = inputBuffer.Length; |
| | 0 | 251 | | if (inputBuffers._item1.Type == SecurityBufferType.SECBUFFER_EXTRA) |
| | 0 | 252 | | { |
| | | 253 | | // not all data were consumed |
| | 0 | 254 | | consumed -= inputBuffers._item1.Token.Length; |
| | 0 | 255 | | } |
| | | 256 | | |
| | 0 | 257 | | return token; |
| | 0 | 258 | | } |
| | | 259 | | |
| | | 260 | | public static ProtocolToken Renegotiate( |
| | | 261 | | ref SafeFreeCredentials? credentialsHandle, |
| | | 262 | | ref SafeDeleteSslContext? context, |
| | | 263 | | SslAuthenticationOptions sslAuthenticationOptions) |
| | 0 | 264 | | { |
| | 0 | 265 | | return AcceptSecurityContext(ref credentialsHandle, ref context, ReadOnlySpan<byte>.Empty, out _, sslAuthent |
| | 0 | 266 | | } |
| | | 267 | | |
| | | 268 | | public static SafeFreeCredentials AcquireCredentialsHandle(SslAuthenticationOptions sslAuthenticationOptions, bo |
| | 0 | 269 | | { |
| | 0 | 270 | | SslStreamCertificateContext? certificateContext = sslAuthenticationOptions.CertificateContext; |
| | | 271 | | |
| | | 272 | | try |
| | 0 | 273 | | { |
| | 0 | 274 | | EncryptionPolicy policy = sslAuthenticationOptions.EncryptionPolicy; |
| | | 275 | | |
| | | 276 | | // New crypto API supports TLS1.3 but it does not allow to force NULL encryption. |
| | | 277 | | #pragma warning disable SYSLIB0040 // NoEncryption and AllowNoEncryption are obsolete |
| | 0 | 278 | | SafeFreeCredentials cred = !UseNewCryptoApi || policy == EncryptionPolicy.NoEncryption ? |
| | 0 | 279 | | AcquireCredentialsHandleSchannelCred(sslAuthenticationOptions) : |
| | 0 | 280 | | AcquireCredentialsHandleSchCredentials(sslAuthenticationOptions); |
| | | 281 | | #pragma warning restore SYSLIB0040 |
| | | 282 | | |
| | 0 | 283 | | if (certificateContext != null && certificateContext.Trust != null && certificateContext.Trust._sendTrus |
| | 0 | 284 | | { |
| | 0 | 285 | | AttachCertificateStore(cred, certificateContext.Trust._store!); |
| | 0 | 286 | | } |
| | | 287 | | |
| | | 288 | | // Windows can fail to get local credentials in case of TLS Resume. |
| | | 289 | | // We will store associated certificate in credentials and use it in case |
| | | 290 | | // of TLS resume. It will be disposed when the credentials are. |
| | 0 | 291 | | if (newCredentialsRequested && sslAuthenticationOptions.CertificateContext != null) |
| | 0 | 292 | | { |
| | 0 | 293 | | SafeFreeCredential_SECURITY handle = (SafeFreeCredential_SECURITY)cred; |
| | 0 | 294 | | handle.HasLocalCertificate = true; |
| | 0 | 295 | | } |
| | | 296 | | |
| | 0 | 297 | | return cred; |
| | | 298 | | } |
| | 0 | 299 | | catch (Win32Exception e) when (e.NativeErrorCode == (int)Interop.SECURITY_STATUS.NoCredentials && certificat |
| | 0 | 300 | | { |
| | 0 | 301 | | Debug.Assert(certificateContext.TargetCertificate.HasPrivateKey); |
| | 0 | 302 | | using SafeCertContextHandle safeCertContextHandle = Interop.Crypt32.CertDuplicateCertificateContext(cert |
| | | 303 | | // on Windows we do not support ephemeral keys. |
| | 0 | 304 | | throw new AuthenticationException(safeCertContextHandle.HasEphemeralPrivateKey ? SR.net_auth_ephemeral : |
| | | 305 | | } |
| | 0 | 306 | | catch (Win32Exception e) |
| | 0 | 307 | | { |
| | 0 | 308 | | throw new AuthenticationException(SR.net_auth_SSPI, e); |
| | | 309 | | } |
| | 0 | 310 | | } |
| | | 311 | | |
| | | 312 | | private static unsafe void AttachCertificateStore(SafeFreeCredentials cred, X509Store store) |
| | 0 | 313 | | { |
| | 0 | 314 | | Interop.SspiCli.SecPkgCred_ClientCertPolicy clientCertPolicy = default; |
| | 0 | 315 | | fixed (char* ptr = store.Name) |
| | 0 | 316 | | { |
| | 0 | 317 | | clientCertPolicy.pwszSslCtlStoreName = ptr; |
| | 0 | 318 | | Interop.SECURITY_STATUS errorCode = Interop.SspiCli.SetCredentialsAttributesW( |
| | 0 | 319 | | cred._handle, |
| | 0 | 320 | | (uint)Interop.SspiCli.ContextAttribute.SECPKG_ATTR_CLIENT_CERT_POLICY, |
| | 0 | 321 | | clientCertPolicy, |
| | 0 | 322 | | (uint)sizeof(Interop.SspiCli.SecPkgCred_ClientCertPolicy)); |
| | | 323 | | |
| | 0 | 324 | | if (errorCode != Interop.SECURITY_STATUS.OK) |
| | 0 | 325 | | { |
| | 0 | 326 | | throw new Win32Exception((int)errorCode); |
| | | 327 | | } |
| | 0 | 328 | | } |
| | | 329 | | |
| | 0 | 330 | | return; |
| | 0 | 331 | | } |
| | | 332 | | |
| | | 333 | | // This is legacy crypto API used on older Windows versions. |
| | | 334 | | // It only supports TLS up to 1.2 |
| | | 335 | | public static unsafe SafeFreeCredentials AcquireCredentialsHandleSchannelCred(SslAuthenticationOptions authOptio |
| | 0 | 336 | | { |
| | 0 | 337 | | X509Certificate2? certificate = authOptions.CertificateContext?.TargetCertificate; |
| | 0 | 338 | | bool isServer = authOptions.IsServer; |
| | 0 | 339 | | int protocolFlags = GetProtocolFlagsFromSslProtocols(authOptions.EnabledSslProtocols, isServer); |
| | 0 | 340 | | Interop.SspiCli.SCHANNEL_CRED.Flags flags = Interop.SspiCli.SCHANNEL_CRED.Flags.SCH_CRED_CACHE_ONLY_URL_RETR |
| | | 341 | | Interop.SspiCli.CredentialUse direction; |
| | | 342 | | |
| | 0 | 343 | | bool allowTlsResume = authOptions.AllowTlsResume && !LocalAppContextSwitches.DisableTlsResume; |
| | | 344 | | |
| | 0 | 345 | | if (!isServer) |
| | 0 | 346 | | { |
| | 0 | 347 | | direction = Interop.SspiCli.CredentialUse.SECPKG_CRED_OUTBOUND; |
| | 0 | 348 | | flags |= |
| | 0 | 349 | | Interop.SspiCli.SCHANNEL_CRED.Flags.SCH_CRED_MANUAL_CRED_VALIDATION | |
| | 0 | 350 | | Interop.SspiCli.SCHANNEL_CRED.Flags.SCH_CRED_NO_DEFAULT_CREDS | |
| | 0 | 351 | | Interop.SspiCli.SCHANNEL_CRED.Flags.SCH_SEND_AUX_RECORD; |
| | | 352 | | |
| | | 353 | | // Request OCSP Stapling from the server |
| | 0 | 354 | | if (authOptions.CertificateRevocationCheckMode != X509RevocationMode.NoCheck) |
| | 0 | 355 | | { |
| | 0 | 356 | | flags |= |
| | 0 | 357 | | Interop.SspiCli.SCHANNEL_CRED.Flags.SCH_CRED_REVOCATION_CHECK_END_CERT | |
| | 0 | 358 | | Interop.SspiCli.SCHANNEL_CRED.Flags.SCH_CRED_IGNORE_NO_REVOCATION_CHECK | |
| | 0 | 359 | | Interop.SspiCli.SCHANNEL_CRED.Flags.SCH_CRED_IGNORE_REVOCATION_OFFLINE; |
| | 0 | 360 | | } |
| | 0 | 361 | | } |
| | | 362 | | else |
| | 0 | 363 | | { |
| | 0 | 364 | | direction = Interop.SspiCli.CredentialUse.SECPKG_CRED_INBOUND; |
| | 0 | 365 | | flags |= |
| | 0 | 366 | | Interop.SspiCli.SCHANNEL_CRED.Flags.SCH_SEND_AUX_RECORD | |
| | 0 | 367 | | Interop.SspiCli.SCHANNEL_CRED.Flags.SCH_CRED_NO_SYSTEM_MAPPER; |
| | 0 | 368 | | if (!allowTlsResume) |
| | 0 | 369 | | { |
| | | 370 | | // Works only on server |
| | 0 | 371 | | flags |= Interop.SspiCli.SCHANNEL_CRED.Flags.SCH_CRED_DISABLE_RECONNECTS; |
| | 0 | 372 | | } |
| | 0 | 373 | | } |
| | | 374 | | |
| | 0 | 375 | | EncryptionPolicy policy = authOptions.EncryptionPolicy; |
| | | 376 | | |
| | | 377 | | #pragma warning disable SYSLIB0040 // NoEncryption and AllowNoEncryption are obsolete |
| | | 378 | | // Always opt-in SCH_USE_STRONG_CRYPTO for TLS. |
| | 0 | 379 | | if (((protocolFlags == 0) || |
| | 0 | 380 | | (protocolFlags & ~(Interop.SChannel.SP_PROT_SSL2 | Interop.SChannel.SP_PROT_SSL3)) != 0) |
| | 0 | 381 | | && (policy != EncryptionPolicy.AllowNoEncryption) && (policy != EncryptionPolicy.NoEncryption)) |
| | 0 | 382 | | { |
| | 0 | 383 | | flags |= Interop.SspiCli.SCHANNEL_CRED.Flags.SCH_USE_STRONG_CRYPTO; |
| | 0 | 384 | | } |
| | | 385 | | #pragma warning restore SYSLIB0040 |
| | | 386 | | |
| | 0 | 387 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(null, $"flags=({flags}), ProtocolFlags=({protocolFla |
| | 0 | 388 | | Interop.SspiCli.SCHANNEL_CRED secureCredential = CreateSecureCredential( |
| | 0 | 389 | | flags, |
| | 0 | 390 | | protocolFlags, |
| | 0 | 391 | | policy); |
| | | 392 | | |
| | 0 | 393 | | if (!isServer && !allowTlsResume) |
| | 0 | 394 | | { |
| | 0 | 395 | | secureCredential.dwSessionLifespan = -1; |
| | 0 | 396 | | } |
| | | 397 | | |
| | | 398 | | Interop.Crypt32.CERT_CONTEXT* certificateHandle; |
| | 0 | 399 | | if (certificate != null) |
| | 0 | 400 | | { |
| | 0 | 401 | | secureCredential.cCreds = 1; |
| | 0 | 402 | | certificateHandle = (Interop.Crypt32.CERT_CONTEXT*)certificate.Handle; |
| | 0 | 403 | | secureCredential.paCred = &certificateHandle; |
| | 0 | 404 | | } |
| | | 405 | | |
| | 0 | 406 | | return AcquireCredentialsHandle(direction, &secureCredential); |
| | 0 | 407 | | } |
| | | 408 | | |
| | | 409 | | // This function uses new crypto API to support TLS 1.3 and beyond. |
| | | 410 | | public static unsafe SafeFreeCredentials AcquireCredentialsHandleSchCredentials(SslAuthenticationOptions authOpt |
| | 0 | 411 | | { |
| | 0 | 412 | | X509Certificate2? certificate = authOptions.CertificateContext?.TargetCertificate; |
| | 0 | 413 | | bool isServer = authOptions.IsServer; |
| | 0 | 414 | | int protocolFlags = GetProtocolFlagsFromSslProtocols(authOptions.EnabledSslProtocols, isServer); |
| | 0 | 415 | | Interop.SspiCli.SCH_CREDENTIALS.Flags flags = Interop.SspiCli.SCH_CREDENTIALS.Flags.SCH_CRED_CACHE_ONLY_URL_ |
| | | 416 | | Interop.SspiCli.CredentialUse direction; |
| | | 417 | | |
| | 0 | 418 | | bool allowTlsResume = authOptions.AllowTlsResume && !LocalAppContextSwitches.DisableTlsResume; |
| | | 419 | | |
| | 0 | 420 | | if (isServer) |
| | 0 | 421 | | { |
| | 0 | 422 | | direction = Interop.SspiCli.CredentialUse.SECPKG_CRED_INBOUND; |
| | 0 | 423 | | flags |= |
| | 0 | 424 | | Interop.SspiCli.SCH_CREDENTIALS.Flags.SCH_SEND_AUX_RECORD | |
| | 0 | 425 | | Interop.SspiCli.SCH_CREDENTIALS.Flags.SCH_CRED_NO_SYSTEM_MAPPER; |
| | 0 | 426 | | if (!allowTlsResume) |
| | 0 | 427 | | { |
| | | 428 | | // Works only on server |
| | 0 | 429 | | flags |= Interop.SspiCli.SCH_CREDENTIALS.Flags.SCH_CRED_DISABLE_RECONNECTS; |
| | 0 | 430 | | } |
| | 0 | 431 | | } |
| | | 432 | | else |
| | 0 | 433 | | { |
| | 0 | 434 | | direction = Interop.SspiCli.CredentialUse.SECPKG_CRED_OUTBOUND; |
| | 0 | 435 | | flags |= |
| | 0 | 436 | | Interop.SspiCli.SCH_CREDENTIALS.Flags.SCH_CRED_MANUAL_CRED_VALIDATION | |
| | 0 | 437 | | Interop.SspiCli.SCH_CREDENTIALS.Flags.SCH_CRED_NO_DEFAULT_CREDS | |
| | 0 | 438 | | Interop.SspiCli.SCH_CREDENTIALS.Flags.SCH_SEND_AUX_RECORD; |
| | | 439 | | |
| | | 440 | | // Request OCSP Stapling from the server |
| | 0 | 441 | | if (authOptions.CertificateRevocationCheckMode != X509RevocationMode.NoCheck) |
| | 0 | 442 | | { |
| | 0 | 443 | | flags |= |
| | 0 | 444 | | Interop.SspiCli.SCH_CREDENTIALS.Flags.SCH_CRED_REVOCATION_CHECK_END_CERT | |
| | 0 | 445 | | Interop.SspiCli.SCH_CREDENTIALS.Flags.SCH_CRED_IGNORE_NO_REVOCATION_CHECK | |
| | 0 | 446 | | Interop.SspiCli.SCH_CREDENTIALS.Flags.SCH_CRED_IGNORE_REVOCATION_OFFLINE; |
| | 0 | 447 | | } |
| | 0 | 448 | | } |
| | | 449 | | |
| | 0 | 450 | | EncryptionPolicy policy = authOptions.EncryptionPolicy; |
| | | 451 | | |
| | 0 | 452 | | if (policy == EncryptionPolicy.RequireEncryption) |
| | 0 | 453 | | { |
| | | 454 | | // Always opt-in SCH_USE_STRONG_CRYPTO for TLS. |
| | 0 | 455 | | if ((protocolFlags & Interop.SChannel.SP_PROT_SSL3) == 0) |
| | 0 | 456 | | { |
| | 0 | 457 | | flags |= Interop.SspiCli.SCH_CREDENTIALS.Flags.SCH_USE_STRONG_CRYPTO; |
| | 0 | 458 | | } |
| | 0 | 459 | | } |
| | | 460 | | #pragma warning disable SYSLIB0040 // NoEncryption and AllowNoEncryption are obsolete |
| | 0 | 461 | | else if (policy == EncryptionPolicy.AllowNoEncryption) |
| | 0 | 462 | | { |
| | | 463 | | // Allow null encryption cipher in addition to other ciphers. |
| | 0 | 464 | | flags |= Interop.SspiCli.SCH_CREDENTIALS.Flags.SCH_ALLOW_NULL_ENCRYPTION; |
| | 0 | 465 | | } |
| | | 466 | | #pragma warning restore SYSLIB0040 |
| | | 467 | | else |
| | 0 | 468 | | { |
| | 0 | 469 | | throw new ArgumentException(SR.Format(SR.net_invalid_enum, "EncryptionPolicy"), nameof(policy)); |
| | | 470 | | } |
| | | 471 | | |
| | 0 | 472 | | Interop.SspiCli.SCH_CREDENTIALS credential = default; |
| | 0 | 473 | | credential.dwVersion = Interop.SspiCli.SCH_CREDENTIALS.CurrentVersion; |
| | 0 | 474 | | credential.dwFlags = flags; |
| | 0 | 475 | | if (!isServer && !allowTlsResume) |
| | 0 | 476 | | { |
| | 0 | 477 | | credential.dwSessionLifespan = -1; |
| | 0 | 478 | | } |
| | | 479 | | |
| | | 480 | | Interop.Crypt32.CERT_CONTEXT* certificateHandle; |
| | 0 | 481 | | if (certificate != null) |
| | 0 | 482 | | { |
| | 0 | 483 | | credential.cCreds = 1; |
| | 0 | 484 | | certificateHandle = (Interop.Crypt32.CERT_CONTEXT*)certificate.Handle; |
| | 0 | 485 | | credential.paCred = &certificateHandle; |
| | 0 | 486 | | } |
| | | 487 | | |
| | 0 | 488 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(null, $"flags=({flags}), ProtocolFlags=({protocolFla |
| | | 489 | | |
| | 0 | 490 | | Interop.SspiCli.TLS_PARAMETERS tlsParameters = default; |
| | 0 | 491 | | credential.cTlsParameters = 1; |
| | 0 | 492 | | credential.pTlsParameters = &tlsParameters; |
| | | 493 | | |
| | 0 | 494 | | if (protocolFlags != 0) |
| | 0 | 495 | | { |
| | 0 | 496 | | tlsParameters.grbitDisabledProtocols = (uint)protocolFlags ^ uint.MaxValue; |
| | 0 | 497 | | } |
| | | 498 | | |
| | 0 | 499 | | Span<Interop.SspiCli.CRYPTO_SETTINGS> cryptoSettings = stackalloc Interop.SspiCli.CRYPTO_SETTINGS[2]; |
| | | 500 | | |
| | | 501 | | // init to null ptrs to prevent freeing uninitialized memory in finally block |
| | 0 | 502 | | Span<IntPtr> algIdPtrs = stackalloc IntPtr[2] { IntPtr.Zero, IntPtr.Zero }; |
| | 0 | 503 | | int cryptoSettingsCount = 0; |
| | | 504 | | |
| | | 505 | | try |
| | 0 | 506 | | { |
| | 0 | 507 | | if (!authOptions.AllowRsaPkcs1Padding) |
| | 0 | 508 | | { |
| | 0 | 509 | | algIdPtrs[cryptoSettingsCount] = Marshal.StringToHGlobalUni("SCH_RSA_PKCS_PAD"); |
| | | 510 | | |
| | 0 | 511 | | cryptoSettings[cryptoSettingsCount] = new() |
| | 0 | 512 | | { |
| | 0 | 513 | | eAlgorithmUsage = Interop.SspiCli.CRYPTO_SETTINGS.TlsAlgorithmUsage.TlsParametersCngAlgUsageCert |
| | 0 | 514 | | }; |
| | | 515 | | |
| | 0 | 516 | | Interop.NtDll.RtlInitUnicodeString(out cryptoSettings[cryptoSettingsCount].strCngAlgId, algIdPtrs[cr |
| | 0 | 517 | | cryptoSettingsCount++; |
| | 0 | 518 | | } |
| | | 519 | | |
| | 0 | 520 | | if (!authOptions.AllowRsaPssPadding) |
| | 0 | 521 | | { |
| | 0 | 522 | | algIdPtrs[cryptoSettingsCount] = Marshal.StringToHGlobalUni("SCH_RSA_PSS_PAD"); |
| | | 523 | | |
| | 0 | 524 | | cryptoSettings[cryptoSettingsCount] = new() |
| | 0 | 525 | | { |
| | 0 | 526 | | eAlgorithmUsage = Interop.SspiCli.CRYPTO_SETTINGS.TlsAlgorithmUsage.TlsParametersCngAlgUsageCert |
| | 0 | 527 | | }; |
| | 0 | 528 | | Interop.NtDll.RtlInitUnicodeString(out cryptoSettings[cryptoSettingsCount].strCngAlgId, algIdPtrs[cr |
| | 0 | 529 | | cryptoSettingsCount++; |
| | 0 | 530 | | } |
| | | 531 | | |
| | 0 | 532 | | tlsParameters.pDisabledCrypto = (Interop.SspiCli.CRYPTO_SETTINGS*)Unsafe.AsPointer(ref MemoryMarshal.Get |
| | 0 | 533 | | tlsParameters.cDisabledCrypto = cryptoSettingsCount; |
| | | 534 | | |
| | 0 | 535 | | return AcquireCredentialsHandle(direction, &credential); |
| | | 536 | | } |
| | | 537 | | finally |
| | 0 | 538 | | { |
| | 0 | 539 | | foreach (IntPtr algIdPtr in algIdPtrs.Slice(0, cryptoSettingsCount)) |
| | 0 | 540 | | { |
| | 0 | 541 | | if (algIdPtr != IntPtr.Zero) |
| | 0 | 542 | | { |
| | 0 | 543 | | Marshal.FreeHGlobal(algIdPtr); |
| | 0 | 544 | | } |
| | 0 | 545 | | } |
| | 0 | 546 | | } |
| | 0 | 547 | | } |
| | | 548 | | |
| | | 549 | | public static unsafe ProtocolToken EncryptMessage(SafeDeleteSslContext securityContext, ReadOnlyMemory<byte> inp |
| | 0 | 550 | | { |
| | 0 | 551 | | ProtocolToken token = default; |
| | 0 | 552 | | token.RentBuffer = true; |
| | | 553 | | |
| | | 554 | | // Ensure that there is sufficient space for the message output. |
| | 0 | 555 | | int bufferSizeNeeded = checked(input.Length + headerSize + trailerSize); |
| | 0 | 556 | | token.EnsureAvailableSpace(bufferSizeNeeded); |
| | | 557 | | // Copy the input into the output buffer to prepare for SCHANNEL's expectations |
| | 0 | 558 | | input.Span.CopyTo(token.AvailableSpan.Slice(headerSize, input.Length)); |
| | | 559 | | |
| | | 560 | | const int NumSecBuffers = 4; // header + data + trailer + empty |
| | 0 | 561 | | Span<Interop.SspiCli.SecBuffer> unmanagedBuffers = stackalloc Interop.SspiCli.SecBuffer[NumSecBuffers]; |
| | 0 | 562 | | Interop.SspiCli.SecBufferDesc sdcInOut = new Interop.SspiCli.SecBufferDesc(NumSecBuffers) |
| | 0 | 563 | | { |
| | 0 | 564 | | pBuffers = Unsafe.AsPointer(ref MemoryMarshal.GetReference(unmanagedBuffers)) |
| | 0 | 565 | | }; |
| | 0 | 566 | | fixed (byte* outputPtr = token.Payload) |
| | 0 | 567 | | { |
| | 0 | 568 | | ref Interop.SspiCli.SecBuffer headerSecBuffer = ref unmanagedBuffers[0]; |
| | 0 | 569 | | headerSecBuffer.BufferType = SecurityBufferType.SECBUFFER_STREAM_HEADER; |
| | 0 | 570 | | headerSecBuffer.pvBuffer = (IntPtr)outputPtr; |
| | 0 | 571 | | headerSecBuffer.cbBuffer = headerSize; |
| | | 572 | | |
| | 0 | 573 | | ref Interop.SspiCli.SecBuffer dataSecBuffer = ref unmanagedBuffers[1]; |
| | 0 | 574 | | dataSecBuffer.BufferType = SecurityBufferType.SECBUFFER_DATA; |
| | 0 | 575 | | dataSecBuffer.pvBuffer = (IntPtr)(outputPtr + headerSize); |
| | 0 | 576 | | dataSecBuffer.cbBuffer = input.Length; |
| | | 577 | | |
| | 0 | 578 | | ref Interop.SspiCli.SecBuffer trailerSecBuffer = ref unmanagedBuffers[2]; |
| | 0 | 579 | | trailerSecBuffer.BufferType = SecurityBufferType.SECBUFFER_STREAM_TRAILER; |
| | 0 | 580 | | trailerSecBuffer.pvBuffer = (IntPtr)(outputPtr + headerSize + input.Length); |
| | 0 | 581 | | trailerSecBuffer.cbBuffer = trailerSize; |
| | | 582 | | |
| | 0 | 583 | | ref Interop.SspiCli.SecBuffer emptySecBuffer = ref unmanagedBuffers[3]; |
| | 0 | 584 | | emptySecBuffer.BufferType = SecurityBufferType.SECBUFFER_EMPTY; |
| | 0 | 585 | | emptySecBuffer.cbBuffer = 0; |
| | 0 | 586 | | emptySecBuffer.pvBuffer = IntPtr.Zero; |
| | | 587 | | |
| | 0 | 588 | | int errorCode = GlobalSSPI.SSPISecureChannel.EncryptMessage(securityContext, ref sdcInOut, 0); |
| | | 589 | | |
| | 0 | 590 | | if (errorCode != 0) |
| | 0 | 591 | | { |
| | 0 | 592 | | if (NetEventSource.Log.IsEnabled()) |
| | 0 | 593 | | NetEventSource.Info(securityContext, $"Encrypt ERROR {errorCode:X}"); |
| | 0 | 594 | | token.Size = 0; |
| | 0 | 595 | | token.Status = SecurityStatusAdapterPal.GetSecurityStatusPalFromNativeInt(errorCode); |
| | 0 | 596 | | return token; |
| | | 597 | | } |
| | | 598 | | |
| | 0 | 599 | | Debug.Assert(headerSecBuffer.cbBuffer >= 0 && dataSecBuffer.cbBuffer >= 0 && trailerSecBuffer.cbBuffer > |
| | 0 | 600 | | Debug.Assert(checked(headerSecBuffer.cbBuffer + dataSecBuffer.cbBuffer + trailerSecBuffer.cbBuffer) <= t |
| | | 601 | | |
| | 0 | 602 | | token.Size = checked(headerSecBuffer.cbBuffer + dataSecBuffer.cbBuffer + trailerSecBuffer.cbBuffer); |
| | 0 | 603 | | token.Status = new SecurityStatusPal(SecurityStatusPalErrorCode.OK); |
| | 0 | 604 | | } |
| | | 605 | | |
| | 0 | 606 | | return token; |
| | 0 | 607 | | } |
| | | 608 | | |
| | | 609 | | public static unsafe SecurityStatusPal DecryptMessage( |
| | | 610 | | SafeDeleteSslContext? securityContext, |
| | | 611 | | Span<byte> encrypted, |
| | | 612 | | Span<byte> destination, |
| | | 613 | | out int bytesWritten, |
| | | 614 | | out int leftoverOffset, |
| | | 615 | | out int leftoverLength) |
| | 0 | 616 | | { |
| | | 617 | | // SChannel always decrypts in-place; the caller-provided `destination` is unused. |
| | 0 | 618 | | _ = destination; |
| | 0 | 619 | | bytesWritten = 0; |
| | | 620 | | const int NumSecBuffers = 4; // data + empty + empty + empty |
| | | 621 | | |
| | 0 | 622 | | Span<Interop.SspiCli.SecBuffer> unmanagedBuffers = stackalloc Interop.SspiCli.SecBuffer[NumSecBuffers]; |
| | 0 | 623 | | for (int i = 1; i < NumSecBuffers; i++) |
| | 0 | 624 | | { |
| | 0 | 625 | | ref Interop.SspiCli.SecBuffer emptyBuffer = ref unmanagedBuffers[i]; |
| | 0 | 626 | | emptyBuffer.BufferType = SecurityBufferType.SECBUFFER_EMPTY; |
| | 0 | 627 | | emptyBuffer.pvBuffer = IntPtr.Zero; |
| | 0 | 628 | | emptyBuffer.cbBuffer = 0; |
| | 0 | 629 | | } |
| | | 630 | | |
| | 0 | 631 | | fixed (byte* bufferPtr = encrypted) |
| | 0 | 632 | | { |
| | 0 | 633 | | ref Interop.SspiCli.SecBuffer dataBuffer = ref unmanagedBuffers[0]; |
| | 0 | 634 | | dataBuffer.BufferType = SecurityBufferType.SECBUFFER_DATA; |
| | 0 | 635 | | dataBuffer.pvBuffer = (IntPtr)bufferPtr; |
| | 0 | 636 | | dataBuffer.cbBuffer = encrypted.Length; |
| | | 637 | | |
| | 0 | 638 | | Interop.SspiCli.SecBufferDesc sdcInOut = new Interop.SspiCli.SecBufferDesc(NumSecBuffers) |
| | 0 | 639 | | { |
| | 0 | 640 | | pBuffers = Unsafe.AsPointer(ref MemoryMarshal.GetReference(unmanagedBuffers)) |
| | 0 | 641 | | }; |
| | 0 | 642 | | Interop.SECURITY_STATUS errorCode = (Interop.SECURITY_STATUS)GlobalSSPI.SSPISecureChannel.DecryptMessage |
| | | 643 | | |
| | | 644 | | // Decrypt may repopulate the sec buffers, likely with header + data + trailer + empty. |
| | | 645 | | // We need to find the data. |
| | 0 | 646 | | leftoverLength = 0; |
| | 0 | 647 | | leftoverOffset = 0; |
| | 0 | 648 | | for (int i = 0; i < NumSecBuffers; i++) |
| | 0 | 649 | | { |
| | | 650 | | // Successfully decoded data and placed it at the following position in the buffer, |
| | 0 | 651 | | if ((errorCode == Interop.SECURITY_STATUS.OK && unmanagedBuffers[i].BufferType == SecurityBufferType |
| | 0 | 652 | | // or we failed to decode the data, here is the encoded data. |
| | 0 | 653 | | || (errorCode != Interop.SECURITY_STATUS.OK && unmanagedBuffers[i].BufferType == SecurityBufferT |
| | 0 | 654 | | { |
| | 0 | 655 | | leftoverOffset = (int)((byte*)unmanagedBuffers[i].pvBuffer - bufferPtr); |
| | 0 | 656 | | leftoverLength = unmanagedBuffers[i].cbBuffer; |
| | | 657 | | |
| | | 658 | | // destination is ignored on Windows. We always decrypt in place and we set leftoverOffset to in |
| | 0 | 659 | | Debug.Assert(leftoverOffset >= 0 && leftoverLength >= 0, $"Expected offset and length greater th |
| | 0 | 660 | | Debug.Assert(checked(leftoverOffset + leftoverLength) <= encrypted.Length, $"Expected offset+len |
| | | 661 | | |
| | 0 | 662 | | break; |
| | | 663 | | } |
| | 0 | 664 | | } |
| | | 665 | | |
| | 0 | 666 | | return SecurityStatusAdapterPal.GetSecurityStatusPalFromInterop(errorCode); |
| | | 667 | | } |
| | 0 | 668 | | } |
| | | 669 | | |
| | | 670 | | public static SecurityStatusPal ApplyAlertToken(SafeDeleteSslContext? securityContext, TlsAlertType alertType, T |
| | 0 | 671 | | { |
| | 0 | 672 | | var alertToken = new Interop.SChannel.SCHANNEL_ALERT_TOKEN |
| | 0 | 673 | | { |
| | 0 | 674 | | dwTokenType = Interop.SChannel.SCHANNEL_ALERT, |
| | 0 | 675 | | dwAlertType = (uint)alertType, |
| | 0 | 676 | | dwAlertNumber = (uint)alertMessage |
| | 0 | 677 | | }; |
| | 0 | 678 | | byte[] buffer = MemoryMarshal.AsBytes(new ReadOnlySpan<Interop.SChannel.SCHANNEL_ALERT_TOKEN>(in alertToken) |
| | 0 | 679 | | var securityBuffer = new SecurityBuffer(buffer, SecurityBufferType.SECBUFFER_TOKEN); |
| | | 680 | | |
| | 0 | 681 | | var errorCode = (Interop.SECURITY_STATUS)SSPIWrapper.ApplyControlToken( |
| | 0 | 682 | | GlobalSSPI.SSPISecureChannel, |
| | 0 | 683 | | ref securityContext, |
| | 0 | 684 | | in securityBuffer); |
| | | 685 | | |
| | 0 | 686 | | return SecurityStatusAdapterPal.GetSecurityStatusPalFromInterop(errorCode, attachException: true); |
| | 0 | 687 | | } |
| | | 688 | | |
| | 0 | 689 | | private static readonly byte[] s_schannelShutdownBytes = BitConverter.GetBytes(Interop.SChannel.SCHANNEL_SHUTDOW |
| | | 690 | | |
| | | 691 | | public static SecurityStatusPal ApplyShutdownToken(SafeDeleteSslContext? securityContext) |
| | 0 | 692 | | { |
| | 0 | 693 | | var securityBuffer = new SecurityBuffer(s_schannelShutdownBytes, SecurityBufferType.SECBUFFER_TOKEN); |
| | | 694 | | |
| | 0 | 695 | | var errorCode = (Interop.SECURITY_STATUS)SSPIWrapper.ApplyControlToken( |
| | 0 | 696 | | GlobalSSPI.SSPISecureChannel, |
| | 0 | 697 | | ref securityContext, |
| | 0 | 698 | | in securityBuffer); |
| | | 699 | | |
| | 0 | 700 | | return SecurityStatusAdapterPal.GetSecurityStatusPalFromInterop(errorCode, attachException: true); |
| | 0 | 701 | | } |
| | | 702 | | |
| | | 703 | | public static SafeFreeContextBufferChannelBinding? QueryContextChannelBinding(SafeDeleteContext securityContext, |
| | 0 | 704 | | { |
| | 0 | 705 | | return SSPIWrapper.QueryContextChannelBinding(GlobalSSPI.SSPISecureChannel, securityContext, (Interop.SspiCl |
| | 0 | 706 | | } |
| | | 707 | | |
| | | 708 | | public static void QueryContextStreamSizes(SafeDeleteContext securityContext, out StreamSizes streamSizes) |
| | 0 | 709 | | { |
| | 0 | 710 | | SecPkgContext_StreamSizes interopStreamSizes = default; |
| | 0 | 711 | | bool success = SSPIWrapper.QueryBlittableContextAttributes(GlobalSSPI.SSPISecureChannel, securityContext, In |
| | 0 | 712 | | Debug.Assert(success); |
| | 0 | 713 | | streamSizes = new StreamSizes(interopStreamSizes); |
| | 0 | 714 | | } |
| | | 715 | | |
| | | 716 | | public static void QueryContextConnectionInfo(SafeDeleteContext securityContext, ref SslConnectionInfo connectio |
| | 0 | 717 | | { |
| | 0 | 718 | | connectionInfo.UpdateSslConnectionInfo(securityContext); |
| | 0 | 719 | | } |
| | | 720 | | |
| | | 721 | | private static int GetProtocolFlagsFromSslProtocols(SslProtocols protocols, bool isServer) |
| | 0 | 722 | | { |
| | 0 | 723 | | int protocolFlags = (int)protocols; |
| | | 724 | | |
| | 0 | 725 | | if (isServer) |
| | 0 | 726 | | { |
| | 0 | 727 | | protocolFlags &= Interop.SChannel.ServerProtocolMask; |
| | 0 | 728 | | } |
| | | 729 | | else |
| | 0 | 730 | | { |
| | 0 | 731 | | protocolFlags &= Interop.SChannel.ClientProtocolMask; |
| | 0 | 732 | | } |
| | | 733 | | |
| | 0 | 734 | | return protocolFlags; |
| | 0 | 735 | | } |
| | | 736 | | |
| | | 737 | | private static unsafe Interop.SspiCli.SCHANNEL_CRED CreateSecureCredential( |
| | | 738 | | Interop.SspiCli.SCHANNEL_CRED.Flags flags, |
| | | 739 | | int protocols, EncryptionPolicy policy) |
| | 0 | 740 | | { |
| | 0 | 741 | | var credential = new Interop.SspiCli.SCHANNEL_CRED() |
| | 0 | 742 | | { |
| | 0 | 743 | | hRootStore = IntPtr.Zero, |
| | 0 | 744 | | aphMappers = IntPtr.Zero, |
| | 0 | 745 | | palgSupportedAlgs = IntPtr.Zero, |
| | 0 | 746 | | paCred = null, |
| | 0 | 747 | | cCreds = 0, |
| | 0 | 748 | | cMappers = 0, |
| | 0 | 749 | | cSupportedAlgs = 0, |
| | 0 | 750 | | dwSessionLifespan = 0, |
| | 0 | 751 | | reserved = 0, |
| | 0 | 752 | | dwVersion = Interop.SspiCli.SCHANNEL_CRED.CurrentVersion |
| | 0 | 753 | | }; |
| | | 754 | | |
| | 0 | 755 | | if (policy == EncryptionPolicy.RequireEncryption) |
| | 0 | 756 | | { |
| | | 757 | | // Prohibit null encryption cipher. |
| | 0 | 758 | | credential.dwMinimumCipherStrength = 0; |
| | 0 | 759 | | credential.dwMaximumCipherStrength = 0; |
| | 0 | 760 | | } |
| | | 761 | | #pragma warning disable SYSLIB0040 // NoEncryption and AllowNoEncryption are obsolete |
| | 0 | 762 | | else if (policy == EncryptionPolicy.AllowNoEncryption) |
| | 0 | 763 | | { |
| | | 764 | | // Allow null encryption cipher in addition to other ciphers. |
| | 0 | 765 | | credential.dwMinimumCipherStrength = -1; |
| | 0 | 766 | | credential.dwMaximumCipherStrength = 0; |
| | 0 | 767 | | } |
| | 0 | 768 | | else if (policy == EncryptionPolicy.NoEncryption) |
| | 0 | 769 | | { |
| | | 770 | | // Suppress all encryption and require null encryption cipher only |
| | 0 | 771 | | credential.dwMinimumCipherStrength = -1; |
| | 0 | 772 | | credential.dwMaximumCipherStrength = -1; |
| | 0 | 773 | | } |
| | | 774 | | #pragma warning restore SYSLIB0040 |
| | | 775 | | else |
| | 0 | 776 | | { |
| | 0 | 777 | | throw new ArgumentException(SR.Format(SR.net_invalid_enum, "EncryptionPolicy"), nameof(policy)); |
| | | 778 | | } |
| | | 779 | | |
| | 0 | 780 | | credential.dwFlags = flags; |
| | 0 | 781 | | credential.grbitEnabledProtocols = protocols; |
| | | 782 | | |
| | 0 | 783 | | return credential; |
| | 0 | 784 | | } |
| | | 785 | | |
| | | 786 | | // |
| | | 787 | | // Security: we temporarily reset thread token to open the handle under process account. |
| | | 788 | | // |
| | | 789 | | private static unsafe SafeFreeCredentials AcquireCredentialsHandle(Interop.SspiCli.CredentialUse credUsage, Inte |
| | 0 | 790 | | { |
| | | 791 | | // First try without impersonation, if it fails, then try the process account. |
| | | 792 | | // I.E. We don't know which account the certificate context was created under. |
| | | 793 | | try |
| | 0 | 794 | | { |
| | | 795 | | // |
| | | 796 | | // For app-compat we want to ensure the credential are accessed under >>process<< account. |
| | | 797 | | // |
| | 0 | 798 | | using SafeAccessTokenHandle invalidHandle = SafeAccessTokenHandle.InvalidHandle; |
| | 0 | 799 | | return WindowsIdentity.RunImpersonated<SafeFreeCredentials>(invalidHandle, () => |
| | 0 | 800 | | { |
| | 0 | 801 | | return SSPIWrapper.AcquireCredentialsHandle(GlobalSSPI.SSPISecureChannel, SecurityPackage, credUsage |
| | 0 | 802 | | }); |
| | | 803 | | } |
| | 0 | 804 | | catch |
| | 0 | 805 | | { |
| | 0 | 806 | | return SSPIWrapper.AcquireCredentialsHandle(GlobalSSPI.SSPISecureChannel, SecurityPackage, credUsage, se |
| | | 807 | | } |
| | 0 | 808 | | } |
| | | 809 | | |
| | | 810 | | private static unsafe SafeFreeCredentials AcquireCredentialsHandle(Interop.SspiCli.CredentialUse credUsage, Inte |
| | 0 | 811 | | { |
| | | 812 | | // First try without impersonation, if it fails, then try the process account. |
| | | 813 | | // I.E. We don't know which account the certificate context was created under. |
| | | 814 | | try |
| | 0 | 815 | | { |
| | | 816 | | // |
| | | 817 | | // For app-compat we want to ensure the credential are accessed under >>process<< account. |
| | | 818 | | // |
| | 0 | 819 | | using SafeAccessTokenHandle invalidHandle = SafeAccessTokenHandle.InvalidHandle; |
| | 0 | 820 | | return WindowsIdentity.RunImpersonated<SafeFreeCredentials>(invalidHandle, () => |
| | 0 | 821 | | { |
| | 0 | 822 | | return SSPIWrapper.AcquireCredentialsHandle(GlobalSSPI.SSPISecureChannel, SecurityPackage, credUsage |
| | 0 | 823 | | }); |
| | | 824 | | } |
| | 0 | 825 | | catch |
| | 0 | 826 | | { |
| | 0 | 827 | | return SSPIWrapper.AcquireCredentialsHandle(GlobalSSPI.SSPISecureChannel, SecurityPackage, credUsage, se |
| | | 828 | | } |
| | 0 | 829 | | } |
| | | 830 | | |
| | | 831 | | } |
| | | 832 | | } |
| | | 833 | | |