#include <errno.h>
-/* Maximum line of a HTTP request line. Longer request lines are aborted with
- * an error. The standard doesn't specify a maximum line length but this
- * should be a good limit to make processing simpler. */
+/* Maximum length of a HTTP request line. Longer request lines are aborted
+ * with an error. The standard doesn't specify a maximum line length but this
+ * should be a good limit to make processing simpler. As HTTPS is used this
+ * doesn't limit long GET requests. */
#define MAX_REQUEST_LINE 4096
/* Format string used to send HTTP/1.0 error responses to the client.
char host[MAX_REQUEST_LINE];
char port[5 + 1];
- int version_minor;
+ int version_minor; /* HTTP/1.x */
int result;
/* client_x509_cred is used when talking to the client (acting as a TSL
LOG(LOG_DEBUG, "transferring data");
- /* Proxy data between client and server until one suite is done
+ /* Proxy data between client and server until one side is done
* (EOF or error). */
transfer_data(client_socket, server_socket);
goto out;
}
- /* server_certificate_path() may open the file, close it. */
+ /* server_certificate_path() may have opened the file, close it. */
if (NULL != file) {
fclose(file);
}
}
+ /* Initialize TLS client credentials to talk to the server. */
result = initialize_tls_session_server(server_socket, &server_session,
&server_x509_cred);
- /* Initialize TLS client credentials to talk to the server. */
if (0 != result) {
LOG(LOG_WARNING, "initialize_tls_session_server() failed");
send_forwarding_failure(client_fd);
if (0 != verify_tls_connection(server_session, host)) {
LOG(LOG_ERROR, "server certificate validation failed!");
/* We send the error message over our TLS connection to the client,
- * but with an invalid certificate. */
+ * but with an invalid certificate. No data is transfered from/to the
+ * target server. */
validation_failed = 1;
}
/* Initialize TLS server credentials to talk to the client. */
result = initialize_tls_session_client(client_socket,
- /* use special host if the server
+ /* use a special host if the server
* certificate was invalid */
(validation_failed) ? "invalid"
: host,
LOG(LOG_DEBUG, "transferring TLS data");
- /* Proxy data between client and server until one suite is done (EOF or
+ /* Proxy data between client and server until one side is done (EOF or
* error). */
transfer_data_tls(client_socket, server_socket,
client_session, server_session);
hostname);
return -1;
}
- snprintf(path, sizeof(path), PROXY_SERVER_CERT_FORMAT, hostname);
+ result = snprintf(path, sizeof(path), PROXY_SERVER_CERT_FORMAT, hostname);
+ if (result < 0) {
+ LOG_PERROR(LOG_ERROR,
+ "initialize_tls_session_client(): snprintf failed");
+ return -1;
+ } else if ((size_t)result >= sizeof(path)) {
+ LOG(LOG_ERROR,
+ "initialize_tls_session_client(): snprintf buffer too short");
+ return -1;
+ }
result = gnutls_certificate_allocate_credentials(x509_cred);
if (GNUTLS_E_SUCCESS != result) {
result = gnutls_certificate_set_x509_trust_file(*x509_cred,
PROXY_CA_FILE,
GNUTLS_X509_FMT_PEM);
+ if (0 >= result) {
+ LOG(LOG_ERROR,
+ "initialize_tls_session_client(): can't read CA file: '%s'",
+ PROXY_CA_FILE);
+ gnutls_certificate_free_credentials(*x509_cred);
+ return -1;
+ }
+ }
/* If the invalid hostname was specified do nothing, we use a self-signed
* certificate in this case. */
- } else {
- result = 1;
- }
- if (0 >= result) {
- LOG(LOG_ERROR,
- "initialize_tls_session_client(): can't read CA file: '%s'",
- PROXY_CA_FILE);
- gnutls_certificate_free_credentials(*x509_cred);
- return -1;
- }
+
/* And certificate for this website and proxy's private key. */
if (!use_invalid_cert) {
result = gnutls_certificate_set_x509_key_file(*x509_cred,
#define RESPONSE_ERROR "500 Internal Server Error"
#define RESPONSE_MSG "Server certificate validation failed, check logs."
+ int result;
char buffer[sizeof(HTTP_RESPONSE_FORMAT) - 1 /* '\0' */
- 4 * 2 /* four %s */
+ (sizeof(RESPONSE_ERROR) - 1 /* '\0' */) * 3
+ sizeof(RESPONSE_MSG) - 1 /* '\0' */
+ 1 /* '\0' */];
- snprintf(buffer, sizeof(buffer),
- HTTP_RESPONSE_FORMAT,
- RESPONSE_ERROR, RESPONSE_ERROR, RESPONSE_ERROR, RESPONSE_MSG);
+ result = snprintf(buffer, sizeof(buffer),
+ HTTP_RESPONSE_FORMAT,
+ RESPONSE_ERROR, RESPONSE_ERROR, RESPONSE_ERROR,
+ RESPONSE_MSG);
+ if (result < 0) {
+ LOG_PERROR(LOG_ERROR,
+ "tls_send_invalid_cert_message(): snprintf failed");
+ return;
+ } else if ((size_t)result >= sizeof(buffer)) {
+ LOG(LOG_ERROR,
+ "tls_send_invalid_cert_message(): snprintf buffer too short");
+ return;
+ }
gnutls_record_send(session, buffer, sizeof(buffer) - 1);
/* don't send trailing '\0' */