Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enigma smime signed messages verification #6043

Open
wants to merge 4 commits into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions plugins/enigma/config.inc.php.dist
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,13 @@ $config['enigma_attach_pubkey'] = false;
// When set to 0 passwords will be stored for the whole session.
$config['enigma_password_time'] = 5;

// Trusted Root CAs
// When this array is filled with root(!) CA files,
// enigma will first try to use these CAs to verify a signature.
// If this fails, verification with default system CAs will still be attempted,
// but lower trust will be signalled to user.
$config['enigma_smime_ca'] = array();

// With this option you can lock composing options
// of the plugin forcing the user to use configured settings.
// The array accepts: 'sign', 'encrypt', 'pubkey'.
Expand Down
24 changes: 21 additions & 3 deletions plugins/enigma/lib/enigma_driver_phpssl.php
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,7 @@ class enigma_driver_phpssl extends enigma_driver
private $rc;
private $homedir;
private $user;
private $cainfo;

function __construct($user)
{
Expand All @@ -37,6 +38,7 @@ function __construct($user)
function init()
{
$homedir = $this->rc->config->get('enigma_smime_homedir', INSTALL_PATH . '/plugins/enigma/home');
$this->cainfo = $this->rc->config->get('enigma_smime_ca', array());
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're using short array syntax now.


if (!$homedir)
return new enigma_error(enigma_error::INTERNAL,
Expand Down Expand Up @@ -65,6 +67,15 @@ function init()

$this->homedir = $homedir;

#XXX: Workaround for https://bugs.php.net/bug.php?id=75494
if (count($this->cainfo) > 0) {
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This will be a warning if the option in config is not an array.

$dummy_cert_dir = $this->homedir . '/' . 'cert_dummy';
if (!file_exists($dummy_cert_dir)) {
mkdir($dummy_cert_dir, 0700);
}
$this->cainfo[] = $dummy_cert_dir;
}

}

function encrypt($text, $keys, $sign_key = null)
Expand Down Expand Up @@ -96,11 +107,16 @@ function verify($struct, $message)
fclose($fh);

// @TODO: use stored certificates

// try with certificate verification
$sig = openssl_pkcs7_verify($msg_file, 0, $cert_file);
// try with global config'd certificates
$sig = openssl_pkcs7_verify($msg_file, 0, $cert_file, $this->cainfo);
$validity = true;

if ($sig !== true) {
// try with server trusted certificate verification
$sig = openssl_pkcs7_verify($msg_file, 0, $cert_file);
$validity = enigma_error::SERVER_VERIFIED;
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why would that be an error? Find another way to pass this info, e.g. involving enigma_signature::$partial.

}

if ($sig !== true) {
// try without certificate verification
$sig = openssl_pkcs7_verify($msg_file, PKCS7_NOVERIFY, $cert_file);
Expand Down Expand Up @@ -229,6 +245,8 @@ private function parse_sig_cert($file, $validity)
// $data->comment = '';
$data->email = $cert['subject']['emailAddress'];

rcube::write_log('errors', 'Decrypted sig: ' . $data->name);
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is not needed.


return $data;
}
}
19 changes: 18 additions & 1 deletion plugins/enigma/lib/enigma_engine.php
Original file line number Diff line number Diff line change
Expand Up @@ -685,7 +685,24 @@ private function parse_smime_signed(&$p, $body = null)
return;
}

// @TODO
if ($this->rc->action != 'show' && $this->rc->action != 'preview' && $this->rc->action != 'print') {
return;
}

$this->load_smime_driver();
$struct = $p['structure'];

$msg_part = $struct->parts[0];

$sig = $this->smime_driver->verify($struct, $p['object']);

if (($sig instanceof enigma_error) && $sig->getCode() != enigma_error::KEYNOTFOUND) {
self::raise_error($sig, __LINE__);
} else {
// Store signature data for display
$this->signatures[$struct->mime_id] = $sig;
$this->signatures[$msg_part->mime_id] = $sig;
}
}

/**
Expand Down
1 change: 1 addition & 0 deletions plugins/enigma/lib/enigma_error.php
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,7 @@ class enigma_error
const BADPASS = 5;
const EXPIRED = 6;
const UNVERIFIED = 7;
const SERVER_VERIFIED = 8;
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is conflict that needs to be resolved.



function __construct($code = null, $message = '', $data = array())
Expand Down
2 changes: 2 additions & 0 deletions plugins/enigma/lib/enigma_mime_message.php
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,8 @@ class enigma_mime_message extends Mail_mime
{
const PGP_SIGNED = 1;
const PGP_ENCRYPTED = 2;
const SMIME_SIGNED = 3;
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These new const aren't used/implemented yet. I would remove them.

const SMIME_ENCRYPTED = 4;

protected $type;
protected $message;
Expand Down
6 changes: 6 additions & 0 deletions plugins/enigma/lib/enigma_ui.php
Original file line number Diff line number Diff line change
Expand Up @@ -984,6 +984,12 @@ function status_message($p)
$msg = str_replace('$keyid', $sig->id, $msg);
$msg = rcube::Q($msg);
}
else if ($sig->valid === enigma_error::SERVER_VERIFIED) {
$attrib['class'] = 'enigmawarning';
$msg = str_replace('$sender', $sender, $this->enigma->gettext('sigserververified'));
$msg = str_replace('$keyid', $sig->id, $msg);
$msg = rcube::Q($msg);
}
else if ($sig->valid) {
$attrib['class'] = $sig->partial ? 'enigmawarning' : 'enigmanotice';
$label = 'sigvalid' . ($sig->partial ? 'partial' : '');
Expand Down
1 change: 1 addition & 0 deletions plugins/enigma/localization/en_US.inc
Original file line number Diff line number Diff line change
Expand Up @@ -98,6 +98,7 @@ $messages = array();
$messages['sigvalid'] = 'Verified signature from $sender.';
$messages['sigvalidpartial'] = 'Verified signature from $sender, but part of the body was not signed.';
$messages['siginvalid'] = 'Invalid signature from $sender.';
$messages['sigserververified'] = 'Server-verified signature. Certificate ID: $keyid.';
$messages['sigunverified'] = 'Unverified signature. Certificate not verified. Certificate ID: $keyid.';
$messages['signokey'] = 'Unverified signature. Public key not found. Key ID: $keyid.';
$messages['sigerror'] = 'Unverified signature. Internal error.';
Expand Down