Browse code

tls: add support for unique identifier PVs and select (GH #1843)

- add support for unique identifier PVs and select, related to issue GH #1843
- new PVs: $tls_peer_subject_uid and $tls_my_subject_uid
- new selects: uid, uniqueIdentifier and unique_identifier

Henning Westerholt authored on 10/02/2019 13:30:45
Showing 1 changed files
... ...
@@ -68,6 +68,7 @@ enum {
68 68
 	COMP_URI,         /* URI from subject/alternative */
69 69
 	COMP_E,           /* Email address */
70 70
 	COMP_IP,          /* IP from subject/alternative */
71
+	COMP_UI,          /* Unique identifier */
71 72
 	TLSEXT_SN         /* Server name of the peer */
72 73
 };
73 74
 
... ...
@@ -96,8 +97,9 @@ enum {
96 96
 	PV_COMP_URI  = 1<<17,        /* URI from subject/alternative */
97 97
 	PV_COMP_E    = 1<<18,        /* Email address */
98 98
 	PV_COMP_IP   = 1<<19,        /* IP from subject/alternative */
99
+	PV_COMP_UI   = 1<<20,        /* Unique identifier */
99 100
 
100
-	PV_TLSEXT_SNI = 1<<20,       /* Peer's server name (TLS extension) */
101
+	PV_TLSEXT_SNI = 1<<21,       /* Peer's server name (TLS extension) */
101 102
 };
102 103
 
103 104
 
... ...
@@ -712,6 +714,7 @@ static int get_comp(str* res, int local, int issuer, int nid, sip_msg_t* msg)
712 712
 		case NID_countryName:            elem = "CountryName";             break;
713 713
 		case NID_stateOrProvinceName:    elem = "StateOrProvinceName";     break;
714 714
 		case NID_localityName:           elem = "LocalityName";            break;
715
+		case NID_x500UniqueIdentifier:   elem = "UniqueIdentifier";        break;
715 716
 		default:                         elem = "Unknown";                 break;
716 717
 		}
717 718
 		DBG("Element %s not found in certificate subject/issuer\n", elem);
... ...
@@ -759,6 +762,7 @@ static int sel_comp(str* res, select_t* s, sip_msg_t* msg)
759 759
 		case COMP_C:       nid = NID_countryName;            break;
760 760
 		case COMP_ST:      nid = NID_stateOrProvinceName;    break;
761 761
 		case COMP_L:       nid = NID_localityName;           break;
762
+		case COMP_UI:      nid = NID_x500UniqueIdentifier;   break;
762 763
 		default:
763 764
 			BUG("Bug in sel_comp: %d\n", s->params[s->n - 1].v.i);
764 765
 			return -1;
... ...
@@ -806,6 +810,7 @@ static int pv_comp(sip_msg_t* msg, pv_param_t* param, pv_value_t* res)
806 806
 		case PV_COMP_C:  nid = NID_countryName;            break;
807 807
 		case PV_COMP_ST: nid = NID_stateOrProvinceName;    break;
808 808
 		case PV_COMP_L:  nid = NID_localityName;           break;
809
+		case PV_COMP_UI: nid = NID_x500UniqueIdentifier;   break;
809 810
 		default:      nid = NID_undef;
810 811
 	}
811 812
 
... ...
@@ -1132,6 +1137,10 @@ select_row_t tls_sel[] = {
1132 1132
 	{ sel_name, SEL_PARAM_STR, STR_STATIC_INIT("organizational_unit_name"), sel_comp, DIVERSION | COMP_OU},
1133 1133
 	{ sel_name, SEL_PARAM_STR, STR_STATIC_INIT("unit"),                     sel_comp, DIVERSION | COMP_OU},
1134 1134
 
1135
+	{ sel_name, SEL_PARAM_STR, STR_STATIC_INIT("uid"),               sel_comp, DIVERSION | COMP_UI},
1136
+	{ sel_name, SEL_PARAM_STR, STR_STATIC_INIT("uniqueIdentifier"),  sel_comp, DIVERSION | COMP_UI},
1137
+	{ sel_name, SEL_PARAM_STR, STR_STATIC_INIT("unique_identifier"), sel_comp, DIVERSION | COMP_UI},
1138
+
1135 1139
 	{ NULL, SEL_PARAM_INT, STR_NULL, NULL, 0}
1136 1140
 };
1137 1141
 
... ...
@@ -1251,6 +1260,13 @@ pv_export_t tls_pv[] = {
1251 1251
 	{{"tls_my_issuer_unit", sizeof("tls_my_issuer_unit")-1},
1252 1252
 		PVT_OTHER, pv_comp, 0,
1253 1253
 		0, 0, pv_init_iname, PV_CERT_LOCAL | PV_CERT_ISSUER  | PV_COMP_OU },
1254
+	/* unique identifier for peer and local */
1255
+	{{"tls_peer_subject_uid", sizeof("tls_peer_subject_uid")-1},
1256
+		PVT_OTHER, pv_comp, 0,
1257
+		0, 0, pv_init_iname, PV_CERT_PEER | PV_CERT_SUBJECT | PV_COMP_UI },
1258
+	{{"tls_my_subject_uid", sizeof("tls_my_subject_uid")-1},
1259
+		PVT_OTHER, pv_comp, 0,
1260
+		0, 0, pv_init_iname, PV_CERT_LOCAL | PV_CERT_SUBJECT | PV_COMP_UI },
1254 1261
 	/* subject alternative name parameters for peer and local */	
1255 1262
 	{{"tls_peer_san_email", sizeof("tls_peer_san_email")-1},
1256 1263
 		PVT_OTHER, pv_alt, 0,