2015-03-13 16:37:32 +00:00
|
|
|
package server
|
|
|
|
|
|
|
|
import (
|
2017-12-15 22:33:55 +00:00
|
|
|
"github.com/hashicorp/errwrap"
|
2015-07-23 20:51:45 +00:00
|
|
|
// We must import sha512 so that it registers with the runtime so that
|
|
|
|
// certificates that use it can be parsed.
|
|
|
|
_ "crypto/sha512"
|
2015-03-13 16:37:32 +00:00
|
|
|
"fmt"
|
2016-06-02 16:40:25 +00:00
|
|
|
"io"
|
2015-03-13 16:37:32 +00:00
|
|
|
"net"
|
2016-07-12 23:32:47 +00:00
|
|
|
|
2017-08-23 16:00:09 +00:00
|
|
|
"github.com/hashicorp/vault/helper/proxyutil"
|
2017-07-31 15:28:06 +00:00
|
|
|
"github.com/hashicorp/vault/helper/reload"
|
2017-12-15 22:33:55 +00:00
|
|
|
"github.com/mitchellh/cli"
|
2015-03-13 16:37:32 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
// ListenerFactory is the factory function to create a listener.
|
2017-12-15 22:33:55 +00:00
|
|
|
type ListenerFactory func(map[string]interface{}, io.Writer, cli.Ui) (net.Listener, map[string]string, reload.ReloadFunc, error)
|
2015-03-13 16:37:32 +00:00
|
|
|
|
|
|
|
// BuiltinListeners is the list of built-in listener types.
|
|
|
|
var BuiltinListeners = map[string]ListenerFactory{
|
2017-06-22 19:29:53 +00:00
|
|
|
"tcp": tcpListenerFactory,
|
2015-03-13 16:37:32 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// NewListener creates a new listener of the given type with the given
|
|
|
|
// configuration. The type is looked up in the BuiltinListeners map.
|
2017-12-15 22:33:55 +00:00
|
|
|
func NewListener(t string, config map[string]interface{}, logger io.Writer, ui cli.Ui) (net.Listener, map[string]string, reload.ReloadFunc, error) {
|
2015-03-13 16:37:32 +00:00
|
|
|
f, ok := BuiltinListeners[t]
|
|
|
|
if !ok {
|
2018-04-05 15:49:21 +00:00
|
|
|
return nil, nil, nil, fmt.Errorf("unknown listener type: %q", t)
|
2015-03-13 16:37:32 +00:00
|
|
|
}
|
|
|
|
|
2017-12-15 22:33:55 +00:00
|
|
|
return f(config, logger, ui)
|
2015-03-13 16:37:32 +00:00
|
|
|
}
|
2015-03-13 16:56:08 +00:00
|
|
|
|
2017-08-23 16:00:09 +00:00
|
|
|
func listenerWrapProxy(ln net.Listener, config map[string]interface{}) (net.Listener, error) {
|
|
|
|
behaviorRaw, ok := config["proxy_protocol_behavior"]
|
|
|
|
if !ok {
|
|
|
|
return ln, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
behavior, ok := behaviorRaw.(string)
|
|
|
|
if !ok {
|
|
|
|
return nil, fmt.Errorf("failed parsing proxy_protocol_behavior value: not a string")
|
|
|
|
}
|
|
|
|
|
|
|
|
proxyProtoConfig := &proxyutil.ProxyProtoConfig{
|
|
|
|
Behavior: behavior,
|
|
|
|
}
|
2018-05-09 14:53:44 +00:00
|
|
|
|
|
|
|
if proxyProtoConfig.Behavior == "allow_authorized" || proxyProtoConfig.Behavior == "deny_unauthorized" {
|
|
|
|
authorizedAddrsRaw, ok := config["proxy_protocol_authorized_addrs"]
|
|
|
|
if !ok {
|
|
|
|
return nil, fmt.Errorf("proxy_protocol_behavior set but no proxy_protocol_authorized_addrs value")
|
|
|
|
}
|
|
|
|
|
|
|
|
if err := proxyProtoConfig.SetAuthorizedAddrs(authorizedAddrsRaw); err != nil {
|
|
|
|
return nil, errwrap.Wrapf("failed parsing proxy_protocol_authorized_addrs: {{err}}", err)
|
|
|
|
}
|
2017-08-23 16:00:09 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
newLn, err := proxyutil.WrapInProxyProto(ln, proxyProtoConfig)
|
|
|
|
if err != nil {
|
2018-04-05 15:49:21 +00:00
|
|
|
return nil, errwrap.Wrapf("failed configuring PROXY protocol wrapper: {{err}}", err)
|
2017-08-23 16:00:09 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
return newLn, nil
|
|
|
|
}
|