@cryptotaxi247 / netdata-1 / commits / 7039044be

SSL_fix_format Fix wrong format used with SSL! (#6219)

* SSL_fix_format Fix wrong format used with SSL! * SSL_fix_format Remove unnecessary space! * SSL_fix_format fixing last requests! * SSL_fix_format fixing spaces! * SSL_fix_format killing spaces!

thiagoftsm committed Jun 6, 2019 at 16:58 UTC 7039044be96ee82058768d98865b992b100a294a
2 files changed +38 -39
libnetdata/socket/security.c
+29 -30
@@ -12,8 +12,8 @@ int netdata_validate_server = NETDATA_SSL_VALID_CERTIFICATE;
12
13 static void security_info_callback(const SSL *ssl, int where, int ret) {
14 (void)ssl;
15 - if ( where & SSL_CB_ALERT ) {
16 - debug(D_WEB_CLIENT,"SSL INFO CALLBACK %s %s",SSL_alert_type_string( ret ),SSL_alert_desc_string_long(ret));
15 + if (where & SSL_CB_ALERT) {
16 + debug(D_WEB_CLIENT,"SSL INFO CALLBACK %s %s", SSL_alert_type_string(ret), SSL_alert_desc_string_long(ret));
17 }
18 }
19
@@ -30,28 +30,28 @@ void security_openssl_library()
30
31 SSL_library_init();
32 #else
33 - if ( OPENSSL_init_ssl(OPENSSL_INIT_LOAD_CONFIG,NULL) != 1 ){
33 + if (OPENSSL_init_ssl(OPENSSL_INIT_LOAD_CONFIG, NULL) != 1) {
34 error("SSL library cannot be initialized.");
35 }
36 #endif
37 }
38
39 -void security_openssl_common_options(SSL_CTX *ctx){
39 +void security_openssl_common_options(SSL_CTX *ctx) {
40 #if OPENSSL_VERSION_NUMBER >= 0x10100000L
41 static char *ciphers = {"ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA"};
42 #endif
43 #if OPENSSL_VERSION_NUMBER < 0x10100000L
44 SSL_CTX_set_options (ctx,SSL_OP_NO_SSLv2|SSL_OP_NO_SSLv3|SSL_OP_NO_COMPRESSION);
45 #else
46 - SSL_CTX_set_min_proto_version(ctx,TLS1_2_VERSION);
46 + SSL_CTX_set_min_proto_version(ctx, TLS1_2_VERSION);
47 //We are avoiding the TLS v1.3 for while, because Google Chrome
48 //is giving the message net::ERR_SSL_VERSION_INTERFERENCE with it.
49 - SSL_CTX_set_max_proto_version(ctx,TLS1_2_VERSION);
49 + SSL_CTX_set_max_proto_version(ctx, TLS1_2_VERSION);
50 #endif
51 SSL_CTX_set_mode(ctx, SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER);
52
53 #if OPENSSL_VERSION_NUMBER >= 0x10100000L
54 - if (!SSL_CTX_set_cipher_list(ctx,ciphers) ){
54 + if (!SSL_CTX_set_cipher_list(ctx, ciphers)) {
55 error("SSL error. cannot set the cipher list");
56 }
57 #endif
@@ -71,7 +71,7 @@ static SSL_CTX * security_initialize_openssl_client() {
71 return ctx;
72 }
73
74 -static SSL_CTX * security_initialize_openssl_server(){
74 +static SSL_CTX * security_initialize_openssl_server() {
75 SSL_CTX *ctx;
76 char lerror[512];
77 static int netdata_id_context = 1;
@@ -79,7 +79,7 @@ static SSL_CTX * security_initialize_openssl_server(){
79 //TO DO: Confirm the necessity to check return for other OPENSSL function
80 #if OPENSSL_VERSION_NUMBER < 0x10100000L
81 ctx = SSL_CTX_new(SSLv23_server_method());
82 - if ( !ctx ) {
82 + if (!ctx) {
83 error("Cannot create a new SSL context, netdata won't encrypt communication");
84 return NULL;
85 }
@@ -87,18 +87,18 @@ static SSL_CTX * security_initialize_openssl_server(){
87 SSL_CTX_use_certificate_file(ctx, security_cert, SSL_FILETYPE_PEM);
88 #else
89 ctx = SSL_CTX_new(TLS_server_method());
90 - if ( !ctx ){
90 + if (!ctx) {
91 error("Cannot create a new SSL context, netdata won't encrypt communication");
92 return NULL;
93 }
94
95 - SSL_CTX_use_certificate_chain_file(ctx, security_cert );
95 + SSL_CTX_use_certificate_chain_file(ctx, security_cert);
96 #endif
97 security_openssl_common_options(ctx);
98
99 SSL_CTX_use_PrivateKey_file(ctx,security_key,SSL_FILETYPE_PEM);
100
101 - if ( !SSL_CTX_check_private_key(ctx) ){
101 + if (!SSL_CTX_check_private_key(ctx)) {
102 ERR_error_string_n(ERR_get_error(),lerror,sizeof(lerror));
103 error("SSL cannot check the private key: %s",lerror);
104 SSL_CTX_free(ctx);
@@ -116,10 +116,10 @@ static SSL_CTX * security_initialize_openssl_server(){
116 return ctx;
117 }
118
119 -void security_start_ssl(int type){
120 - if ( !type){
119 +void security_start_ssl(int type) {
120 + if (!type) {
121 struct stat statbuf;
122 - if ( (stat(security_key,&statbuf)) || (stat(security_cert,&statbuf)) ){
122 + if (stat(security_key,&statbuf) || stat(security_cert,&statbuf)) {
123 info("To use encryption it is necessary to set \"ssl certificate\" and \"ssl key\" in [web] !\n");
124 return;
125 }
@@ -131,13 +131,13 @@ void security_start_ssl(int type){
131 }
132 }
133
134 -void security_clean_openssl(){
135 - if ( netdata_srv_ctx )
134 +void security_clean_openssl() {
135 + if (netdata_srv_ctx)
136 {
137 SSL_CTX_free(netdata_srv_ctx);
138 }
139
140 - if ( netdata_cli_ctx )
140 + if (netdata_cli_ctx)
141 {
142 SSL_CTX_free(netdata_cli_ctx);
143 }
@@ -161,12 +161,12 @@ int security_process_accept(SSL *ssl,int msg) {
161 switch(sslerrno) {
162 case SSL_ERROR_WANT_READ:
163 {
164 - error("SSL handshake did not finish and it wanna read on socket %d!",sock);
164 + error("SSL handshake did not finish and it wanna read on socket %d!", sock);
165 return NETDATA_SSL_WANT_READ;
166 }
167 case SSL_ERROR_WANT_WRITE:
168 {
169 - error("SSL handshake did not finish and it wanna read on socket %d!",sock);
169 + error("SSL handshake did not finish and it wanna read on socket %d!", sock);
170 return NETDATA_SSL_WANT_WRITE;
171 }
172 case SSL_ERROR_NONE:
@@ -177,28 +177,28 @@ int security_process_accept(SSL *ssl,int msg) {
177 u_long err;
178 char buf[256];
179 int counter = 0;
180 - while ((err = ERR_get_error()) != 0){
180 + while ((err = ERR_get_error()) != 0) {
181 ERR_error_string_n(err, buf, sizeof(buf));
182 - info("%d SSL Handshake error (%s) on socket %d ",counter++,ERR_error_string((long)SSL_get_error(ssl,test),NULL),sock);
182 + info("%d SSL Handshake error (%s) on socket %d ", counter++, ERR_error_string((long)SSL_get_error(ssl, test), NULL), sock);
183 }
184 return NETDATA_SSL_NO_HANDSHAKE;
185 }
186 }
187 }
188
189 - if ( SSL_is_init_finished(ssl) )
189 + if (SSL_is_init_finished(ssl))
190 {
191 - debug(D_WEB_CLIENT_ACCESS,"SSL Handshake finished %s errno %d on socket fd %d",ERR_error_string((long)SSL_get_error(ssl,test),NULL),errno,sock);
191 + debug(D_WEB_CLIENT_ACCESS,"SSL Handshake finished %s errno %d on socket fd %d", ERR_error_string((long)SSL_get_error(ssl, test), NULL), errno, sock);
192 }
193
194 return 0;
195 }
196
197 -int security_test_certificate(SSL *ssl){
197 +int security_test_certificate(SSL *ssl) {
198 X509* cert = SSL_get_peer_certificate(ssl);
199 int ret;
200 long status;
201 - if (!cert){
201 + if (!cert) {
202 return -1;
203 }
204
@@ -206,11 +206,10 @@ int security_test_certificate(SSL *ssl){
206 if((X509_V_OK != status))
207 {
208 char error[512];
209 - ERR_error_string_n(ERR_get_error(),error,sizeof(error));
210 - error("SSL RFC4158 check: We have a invalid certificate, the tests result with %ld and message %s",status,error);
209 + ERR_error_string_n(ERR_get_error(), error, sizeof(error));
210 + error("SSL RFC4158 check: We have a invalid certificate, the tests result with %ld and message %s", status, error);
211 ret = -1;
212 - }
213 - else {
212 + } else {
213 ret = 0;
214 }
215 return ret;
libnetdata/socket/socket.c
+9 -9
@@ -301,13 +301,13 @@ void listen_sockets_close(LISTEN_SOCKETS *sockets) {
301 sockets->failed = 0;
302 }
303
304 -WEB_CLIENT_ACL socket_ssl_acl(char *ssl){
304 +WEB_CLIENT_ACL socket_ssl_acl(char *ssl) {
305 #ifdef ENABLE_HTTPS
306 - if (!strcmp(ssl,"optional")){
306 + if (!strcmp(ssl,"optional")) {
307 netdata_use_ssl_on_http = NETDATA_SSL_OPTIONAL;
308 return WEB_CLIENT_ACL_DASHBOARD | WEB_CLIENT_ACL_REGISTRY | WEB_CLIENT_ACL_BADGE | WEB_CLIENT_ACL_MGMT | WEB_CLIENT_ACL_NETDATACONF | WEB_CLIENT_ACL_STREAMING;
309 }
310 - else if (!strcmp(ssl,"force")){
310 + else if (!strcmp(ssl,"force")) {
311 netdata_use_ssl_on_stream = NETDATA_SSL_FORCE;
312 return WEB_CLIENT_ACL_DASHBOARD | WEB_CLIENT_ACL_REGISTRY | WEB_CLIENT_ACL_BADGE | WEB_CLIENT_ACL_MGMT | WEB_CLIENT_ACL_NETDATACONF | WEB_CLIENT_ACL_STREAMING;
313 }
@@ -318,9 +318,9 @@ WEB_CLIENT_ACL socket_ssl_acl(char *ssl){
318
319 WEB_CLIENT_ACL read_acl(char *st) {
320 char *ssl = strchr(st,'^');
321 - if (ssl){
321 + if (ssl) {
322 ssl++;
323 - if ( !strncmp("SSL=",ssl,4)){
323 + if (!strncmp("SSL=",ssl,4)) {
324 ssl += 4;
325 }
326 socket_ssl_acl(ssl);
@@ -883,8 +883,8 @@ ssize_t recv_timeout(int sockfd, void *buf, size_t len, int flags, int timeout)
883 }
884
885 #ifdef ENABLE_HTTPS
886 - if (ssl->conn){
887 - if (!ssl->flags){
886 + if (ssl->conn) {
887 + if (!ssl->flags) {
888 return SSL_read(ssl->conn,buf,len);
889 }
890 }
@@ -926,8 +926,8 @@ ssize_t send_timeout(int sockfd, void *buf, size_t len, int flags, int timeout)
926 }
927
928 #ifdef ENABLE_HTTPS
929 - if(ssl->conn){
930 - if (!ssl->flags){
929 + if(ssl->conn) {
930 + if (!ssl->flags) {
931 return SSL_write(ssl->conn, buf, len);
932 }
933 }