Check requested security strength in DRBG. Add function to retrieve the
[openssl.git] / apps / s_socket.c
1 /* apps/s_socket.c -  socket-related functions used by s_client and s_server */
2 /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com)
3  * All rights reserved.
4  *
5  * This package is an SSL implementation written
6  * by Eric Young (eay@cryptsoft.com).
7  * The implementation was written so as to conform with Netscapes SSL.
8  * 
9  * This library is free for commercial and non-commercial use as long as
10  * the following conditions are aheared to.  The following conditions
11  * apply to all code found in this distribution, be it the RC4, RSA,
12  * lhash, DES, etc., code; not just the SSL code.  The SSL documentation
13  * included with this distribution is covered by the same copyright terms
14  * except that the holder is Tim Hudson (tjh@cryptsoft.com).
15  * 
16  * Copyright remains Eric Young's, and as such any Copyright notices in
17  * the code are not to be removed.
18  * If this package is used in a product, Eric Young should be given attribution
19  * as the author of the parts of the library used.
20  * This can be in the form of a textual message at program startup or
21  * in documentation (online or textual) provided with the package.
22  * 
23  * Redistribution and use in source and binary forms, with or without
24  * modification, are permitted provided that the following conditions
25  * are met:
26  * 1. Redistributions of source code must retain the copyright
27  *    notice, this list of conditions and the following disclaimer.
28  * 2. Redistributions in binary form must reproduce the above copyright
29  *    notice, this list of conditions and the following disclaimer in the
30  *    documentation and/or other materials provided with the distribution.
31  * 3. All advertising materials mentioning features or use of this software
32  *    must display the following acknowledgement:
33  *    "This product includes cryptographic software written by
34  *     Eric Young (eay@cryptsoft.com)"
35  *    The word 'cryptographic' can be left out if the rouines from the library
36  *    being used are not cryptographic related :-).
37  * 4. If you include any Windows specific code (or a derivative thereof) from 
38  *    the apps directory (application code) you must include an acknowledgement:
39  *    "This product includes software written by Tim Hudson (tjh@cryptsoft.com)"
40  * 
41  * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND
42  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
43  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
44  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
45  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
46  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
47  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
48  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
49  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
50  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
51  * SUCH DAMAGE.
52  * 
53  * The licence and distribution terms for any publically available version or
54  * derivative of this code cannot be changed.  i.e. this code cannot simply be
55  * copied and put under another distribution licence
56  * [including the GNU Public Licence.]
57  */
58
59 #include <stdio.h>
60 #include <stdlib.h>
61 #include <string.h>
62 #include <errno.h>
63 #include <signal.h>
64
65 /* With IPv6, it looks like Digital has mixed up the proper order of
66    recursive header file inclusion, resulting in the compiler complaining
67    that u_int isn't defined, but only if _POSIX_C_SOURCE is defined, which
68    is needed to have fileno() declared correctly...  So let's define u_int */
69 #if defined(OPENSSL_SYS_VMS_DECC) && !defined(__U_INT)
70 #define __U_INT
71 typedef unsigned int u_int;
72 #endif
73
74 #define USE_SOCKETS
75 #define NON_MAIN
76 #include "apps.h"
77 #undef USE_SOCKETS
78 #undef NON_MAIN
79 #include "s_apps.h"
80 #include <openssl/ssl.h>
81
82 #ifdef FLAT_INC
83 #include "e_os.h"
84 #else
85 #include "../e_os.h"
86 #endif
87
88 #ifndef OPENSSL_NO_SOCK
89
90 #if defined(OPENSSL_SYS_NETWARE) && defined(NETWARE_BSDSOCK)
91 #include "netdb.h"
92 #endif
93
94 static struct hostent *GetHostByName(char *name);
95 #if defined(OPENSSL_SYS_WINDOWS) || (defined(OPENSSL_SYS_NETWARE) && !defined(NETWARE_BSDSOCK))
96 static void ssl_sock_cleanup(void);
97 #endif
98 static int ssl_sock_init(void);
99 static int init_client_ip(int *sock, const unsigned char ip[4], int port,
100                           int type);
101 static int init_server(int *sock, int port, int type);
102 static int init_server_long(int *sock, int port,char *ip, int type);
103 static int do_accept(int acc_sock, int *sock, char **host);
104 static int host_ip(char *str, unsigned char ip[4]);
105
106 #ifdef OPENSSL_SYS_WIN16
107 #define SOCKET_PROTOCOL 0 /* more microsoft stupidity */
108 #else
109 #define SOCKET_PROTOCOL IPPROTO_TCP
110 #endif
111
112 #if defined(OPENSSL_SYS_NETWARE) && !defined(NETWARE_BSDSOCK)
113 static int wsa_init_done=0;
114 #endif
115
116 #ifdef OPENSSL_SYS_WINDOWS
117 static struct WSAData wsa_state;
118 static int wsa_init_done=0;
119
120 #ifdef OPENSSL_SYS_WIN16
121 static HWND topWnd=0;
122 static FARPROC lpTopWndProc=NULL;
123 static FARPROC lpTopHookProc=NULL;
124 extern HINSTANCE _hInstance;  /* nice global CRT provides */
125
126 static LONG FAR PASCAL topHookProc(HWND hwnd, UINT message, WPARAM wParam,
127              LPARAM lParam)
128         {
129         if (hwnd == topWnd)
130                 {
131                 switch(message)
132                         {
133                 case WM_DESTROY:
134                 case WM_CLOSE:
135                         SetWindowLong(topWnd,GWL_WNDPROC,(LONG)lpTopWndProc);
136                         ssl_sock_cleanup();
137                         break;
138                         }
139                 }
140         return CallWindowProc(lpTopWndProc,hwnd,message,wParam,lParam);
141         }
142
143 static BOOL CALLBACK enumproc(HWND hwnd,LPARAM lParam)
144         {
145         topWnd=hwnd;
146         return(FALSE);
147         }
148
149 #endif /* OPENSSL_SYS_WIN32 */
150 #endif /* OPENSSL_SYS_WINDOWS */
151
152 #ifdef OPENSSL_SYS_WINDOWS
153 static void ssl_sock_cleanup(void)
154         {
155         if (wsa_init_done)
156                 {
157                 wsa_init_done=0;
158 #ifndef OPENSSL_SYS_WINCE
159                 WSACancelBlockingCall();
160 #endif
161                 WSACleanup();
162                 }
163         }
164 #elif defined(OPENSSL_SYS_NETWARE) && !defined(NETWARE_BSDSOCK)
165 static void sock_cleanup(void)
166     {
167     if (wsa_init_done)
168         {
169         wsa_init_done=0;
170                 WSACleanup();
171                 }
172         }
173 #endif
174
175 static int ssl_sock_init(void)
176         {
177 #ifdef WATT32
178         extern int _watt_do_exit;
179         _watt_do_exit = 0;
180         if (sock_init())
181                 return (0);
182 #elif defined(OPENSSL_SYS_WINDOWS)
183         if (!wsa_init_done)
184                 {
185                 int err;
186           
187 #ifdef SIGINT
188                 signal(SIGINT,(void (*)(int))ssl_sock_cleanup);
189 #endif
190                 wsa_init_done=1;
191                 memset(&wsa_state,0,sizeof(wsa_state));
192                 if (WSAStartup(0x0101,&wsa_state)!=0)
193                         {
194                         err=WSAGetLastError();
195                         BIO_printf(bio_err,"unable to start WINSOCK, error code=%d\n",err);
196                         return(0);
197                         }
198
199 #ifdef OPENSSL_SYS_WIN16
200                 EnumTaskWindows(GetCurrentTask(),enumproc,0L);
201                 lpTopWndProc=(FARPROC)GetWindowLong(topWnd,GWL_WNDPROC);
202                 lpTopHookProc=MakeProcInstance((FARPROC)topHookProc,_hInstance);
203
204                 SetWindowLong(topWnd,GWL_WNDPROC,(LONG)lpTopHookProc);
205 #endif /* OPENSSL_SYS_WIN16 */
206                 }
207 #elif defined(OPENSSL_SYS_NETWARE) && !defined(NETWARE_BSDSOCK)
208    WORD wVerReq;
209    WSADATA wsaData;
210    int err;
211
212    if (!wsa_init_done)
213       {
214    
215 # ifdef SIGINT
216       signal(SIGINT,(void (*)(int))sock_cleanup);
217 # endif
218
219       wsa_init_done=1;
220       wVerReq = MAKEWORD( 2, 0 );
221       err = WSAStartup(wVerReq,&wsaData);
222       if (err != 0)
223          {
224          BIO_printf(bio_err,"unable to start WINSOCK2, error code=%d\n",err);
225          return(0);
226          }
227       }
228 #endif /* OPENSSL_SYS_WINDOWS */
229         return(1);
230         }
231
232 int init_client(int *sock, char *host, int port, int type)
233         {
234         unsigned char ip[4];
235
236         if (!host_ip(host,&(ip[0])))
237                 {
238                 return(0);
239                 }
240         return(init_client_ip(sock,ip,port,type));
241         }
242
243 static int init_client_ip(int *sock, const unsigned char ip[4], int port,
244                           int type)
245         {
246         unsigned long addr;
247         struct sockaddr_in them;
248         int s,i;
249
250         if (!ssl_sock_init()) return(0);
251
252         memset((char *)&them,0,sizeof(them));
253         them.sin_family=AF_INET;
254         them.sin_port=htons((unsigned short)port);
255         addr=(unsigned long)
256                 ((unsigned long)ip[0]<<24L)|
257                 ((unsigned long)ip[1]<<16L)|
258                 ((unsigned long)ip[2]<< 8L)|
259                 ((unsigned long)ip[3]);
260         them.sin_addr.s_addr=htonl(addr);
261
262         if (type == SOCK_STREAM)
263                 s=socket(AF_INET,SOCK_STREAM,SOCKET_PROTOCOL);
264         else /* ( type == SOCK_DGRAM) */
265                 s=socket(AF_INET,SOCK_DGRAM,IPPROTO_UDP);
266                         
267         if (s == INVALID_SOCKET) { perror("socket"); return(0); }
268
269 #if defined(SO_KEEPALIVE) && !defined(OPENSSL_SYS_MPE)
270         if (type == SOCK_STREAM)
271                 {
272                 i=0;
273                 i=setsockopt(s,SOL_SOCKET,SO_KEEPALIVE,(char *)&i,sizeof(i));
274                 if (i < 0) { perror("keepalive"); return(0); }
275                 }
276 #endif
277
278         if (connect(s,(struct sockaddr *)&them,sizeof(them)) == -1)
279                 { closesocket(s); perror("connect"); return(0); }
280         *sock=s;
281         return(1);
282         }
283
284 int do_server(int port, int type, int *ret, int (*cb)(char *hostname, int s, unsigned char *context), unsigned char *context)
285         {
286         int sock;
287         char *name = NULL;
288         int accept_socket = 0;
289         int i;
290
291         if (!init_server(&accept_socket,port,type)) return(0);
292
293         if (ret != NULL)
294                 {
295                 *ret=accept_socket;
296                 /* return(1);*/
297                 }
298         for (;;)
299                 {
300                 if (type==SOCK_STREAM)
301                         {
302                         if (do_accept(accept_socket,&sock,&name) == 0)
303                                 {
304                                 SHUTDOWN(accept_socket);
305                                 return(0);
306                                 }
307                         }
308                 else
309                         sock = accept_socket;
310                 i=(*cb)(name,sock, context);
311                 if (name != NULL) OPENSSL_free(name);
312                 if (type==SOCK_STREAM)
313                         SHUTDOWN2(sock);
314                 if (i < 0)
315                         {
316                         SHUTDOWN2(accept_socket);
317                         return(i);
318                         }
319                 }
320         }
321
322 static int init_server_long(int *sock, int port, char *ip, int type)
323         {
324         int ret=0;
325         struct sockaddr_in server;
326         int s= -1;
327
328         if (!ssl_sock_init()) return(0);
329
330         memset((char *)&server,0,sizeof(server));
331         server.sin_family=AF_INET;
332         server.sin_port=htons((unsigned short)port);
333         if (ip == NULL)
334                 server.sin_addr.s_addr=INADDR_ANY;
335         else
336 /* Added for T3E, address-of fails on bit field (beckman@acl.lanl.gov) */
337 #ifndef BIT_FIELD_LIMITS
338                 memcpy(&server.sin_addr.s_addr,ip,4);
339 #else
340                 memcpy(&server.sin_addr,ip,4);
341 #endif
342         
343                 if (type == SOCK_STREAM)
344                         s=socket(AF_INET,SOCK_STREAM,SOCKET_PROTOCOL);
345                 else /* type == SOCK_DGRAM */
346                         s=socket(AF_INET, SOCK_DGRAM,IPPROTO_UDP);
347
348         if (s == INVALID_SOCKET) goto err;
349 #if defined SOL_SOCKET && defined SO_REUSEADDR
350                 {
351                 int j = 1;
352                 setsockopt(s, SOL_SOCKET, SO_REUSEADDR,
353                            (void *) &j, sizeof j);
354                 }
355 #endif
356         if (bind(s,(struct sockaddr *)&server,sizeof(server)) == -1)
357                 {
358 #ifndef OPENSSL_SYS_WINDOWS
359                 perror("bind");
360 #endif
361                 goto err;
362                 }
363         /* Make it 128 for linux */
364         if (type==SOCK_STREAM && listen(s,128) == -1) goto err;
365         *sock=s;
366         ret=1;
367 err:
368         if ((ret == 0) && (s != -1))
369                 {
370                 SHUTDOWN(s);
371                 }
372         return(ret);
373         }
374
375 static int init_server(int *sock, int port, int type)
376         {
377         return(init_server_long(sock, port, NULL, type));
378         }
379
380 static int do_accept(int acc_sock, int *sock, char **host)
381         {
382         int ret;
383         struct hostent *h1,*h2;
384         static struct sockaddr_in from;
385         int len;
386 /*      struct linger ling; */
387
388         if (!ssl_sock_init()) return(0);
389
390 #ifndef OPENSSL_SYS_WINDOWS
391 redoit:
392 #endif
393
394         memset((char *)&from,0,sizeof(from));
395         len=sizeof(from);
396         /* Note: under VMS with SOCKETSHR the fourth parameter is currently
397          * of type (int *) whereas under other systems it is (void *) if
398          * you don't have a cast it will choke the compiler: if you do
399          * have a cast then you can either go for (int *) or (void *).
400          */
401         ret=accept(acc_sock,(struct sockaddr *)&from,(void *)&len);
402         if (ret == INVALID_SOCKET)
403                 {
404 #if defined(OPENSSL_SYS_WINDOWS) || (defined(OPENSSL_SYS_NETWARE) && !defined(NETWARE_BSDSOCK))
405                 int i;
406                 i=WSAGetLastError();
407                 BIO_printf(bio_err,"accept error %d\n",i);
408 #else
409                 if (errno == EINTR)
410                         {
411                         /*check_timeout(); */
412                         goto redoit;
413                         }
414                 fprintf(stderr,"errno=%d ",errno);
415                 perror("accept");
416 #endif
417                 return(0);
418                 }
419
420 /*
421         ling.l_onoff=1;
422         ling.l_linger=0;
423         i=setsockopt(ret,SOL_SOCKET,SO_LINGER,(char *)&ling,sizeof(ling));
424         if (i < 0) { perror("linger"); return(0); }
425         i=0;
426         i=setsockopt(ret,SOL_SOCKET,SO_KEEPALIVE,(char *)&i,sizeof(i));
427         if (i < 0) { perror("keepalive"); return(0); }
428 */
429
430         if (host == NULL) goto end;
431 #ifndef BIT_FIELD_LIMITS
432         /* I should use WSAAsyncGetHostByName() under windows */
433         h1=gethostbyaddr((char *)&from.sin_addr.s_addr,
434                 sizeof(from.sin_addr.s_addr),AF_INET);
435 #else
436         h1=gethostbyaddr((char *)&from.sin_addr,
437                 sizeof(struct in_addr),AF_INET);
438 #endif
439         if (h1 == NULL)
440                 {
441                 BIO_printf(bio_err,"bad gethostbyaddr\n");
442                 *host=NULL;
443                 /* return(0); */
444                 }
445         else
446                 {
447                 if ((*host=(char *)OPENSSL_malloc(strlen(h1->h_name)+1)) == NULL)
448                         {
449                         perror("OPENSSL_malloc");
450                         return(0);
451                         }
452                 BUF_strlcpy(*host,h1->h_name,strlen(h1->h_name)+1);
453
454                 h2=GetHostByName(*host);
455                 if (h2 == NULL)
456                         {
457                         BIO_printf(bio_err,"gethostbyname failure\n");
458                         return(0);
459                         }
460                 if (h2->h_addrtype != AF_INET)
461                         {
462                         BIO_printf(bio_err,"gethostbyname addr is not AF_INET\n");
463                         return(0);
464                         }
465                 }
466 end:
467         *sock=ret;
468         return(1);
469         }
470
471 int extract_host_port(char *str, char **host_ptr, unsigned char *ip,
472              short *port_ptr)
473         {
474         char *h,*p;
475
476         h=str;
477         p=strchr(str,':');
478         if (p == NULL)
479                 {
480                 BIO_printf(bio_err,"no port defined\n");
481                 return(0);
482                 }
483         *(p++)='\0';
484
485         if ((ip != NULL) && !host_ip(str,ip))
486                 goto err;
487         if (host_ptr != NULL) *host_ptr=h;
488
489         if (!extract_port(p,port_ptr))
490                 goto err;
491         return(1);
492 err:
493         return(0);
494         }
495
496 static int host_ip(char *str, unsigned char ip[4])
497         {
498         unsigned int in[4]; 
499         int i;
500
501         if (sscanf(str,"%u.%u.%u.%u",&(in[0]),&(in[1]),&(in[2]),&(in[3])) == 4)
502                 {
503                 for (i=0; i<4; i++)
504                         if (in[i] > 255)
505                                 {
506                                 BIO_printf(bio_err,"invalid IP address\n");
507                                 goto err;
508                                 }
509                 ip[0]=in[0];
510                 ip[1]=in[1];
511                 ip[2]=in[2];
512                 ip[3]=in[3];
513                 }
514         else
515                 { /* do a gethostbyname */
516                 struct hostent *he;
517
518                 if (!ssl_sock_init()) return(0);
519
520                 he=GetHostByName(str);
521                 if (he == NULL)
522                         {
523                         BIO_printf(bio_err,"gethostbyname failure\n");
524                         goto err;
525                         }
526                 /* cast to short because of win16 winsock definition */
527                 if ((short)he->h_addrtype != AF_INET)
528                         {
529                         BIO_printf(bio_err,"gethostbyname addr is not AF_INET\n");
530                         return(0);
531                         }
532                 ip[0]=he->h_addr_list[0][0];
533                 ip[1]=he->h_addr_list[0][1];
534                 ip[2]=he->h_addr_list[0][2];
535                 ip[3]=he->h_addr_list[0][3];
536                 }
537         return(1);
538 err:
539         return(0);
540         }
541
542 int extract_port(char *str, short *port_ptr)
543         {
544         int i;
545         struct servent *s;
546
547         i=atoi(str);
548         if (i != 0)
549                 *port_ptr=(unsigned short)i;
550         else
551                 {
552                 s=getservbyname(str,"tcp");
553                 if (s == NULL)
554                         {
555                         BIO_printf(bio_err,"getservbyname failure for %s\n",str);
556                         return(0);
557                         }
558                 *port_ptr=ntohs((unsigned short)s->s_port);
559                 }
560         return(1);
561         }
562
563 #define GHBN_NUM        4
564 static struct ghbn_cache_st
565         {
566         char name[128];
567         struct hostent ent;
568         unsigned long order;
569         } ghbn_cache[GHBN_NUM];
570
571 static unsigned long ghbn_hits=0L;
572 static unsigned long ghbn_miss=0L;
573
574 static struct hostent *GetHostByName(char *name)
575         {
576         struct hostent *ret;
577         int i,lowi=0;
578         unsigned long low= (unsigned long)-1;
579
580         for (i=0; i<GHBN_NUM; i++)
581                 {
582                 if (low > ghbn_cache[i].order)
583                         {
584                         low=ghbn_cache[i].order;
585                         lowi=i;
586                         }
587                 if (ghbn_cache[i].order > 0)
588                         {
589                         if (strncmp(name,ghbn_cache[i].name,128) == 0)
590                                 break;
591                         }
592                 }
593         if (i == GHBN_NUM) /* no hit*/
594                 {
595                 ghbn_miss++;
596                 ret=gethostbyname(name);
597                 if (ret == NULL) return(NULL);
598                 /* else add to cache */
599                 if(strlen(name) < sizeof ghbn_cache[0].name)
600                         {
601                         strcpy(ghbn_cache[lowi].name,name);
602                         memcpy((char *)&(ghbn_cache[lowi].ent),ret,sizeof(struct hostent));
603                         ghbn_cache[lowi].order=ghbn_miss+ghbn_hits;
604                         }
605                 return(ret);
606                 }
607         else
608                 {
609                 ghbn_hits++;
610                 ret= &(ghbn_cache[i].ent);
611                 ghbn_cache[i].order=ghbn_miss+ghbn_hits;
612                 return(ret);
613                 }
614         }
615
616 #endif