open-vault/command/server/listener.go

151 lines
3.8 KiB
Go
Raw Normal View History

2015-03-13 16:37:32 +00:00
package server
import (
2015-07-23 20:51:45 +00:00
// We must import sha512 so that it registers with the runtime so that
// certificates that use it can be parsed.
_ "crypto/sha512"
2015-03-13 16:56:08 +00:00
"crypto/tls"
2015-03-13 16:37:32 +00:00
"fmt"
2016-06-02 16:40:25 +00:00
"io"
2015-03-13 16:37:32 +00:00
"net"
"strconv"
"sync"
2016-07-12 23:32:47 +00:00
"github.com/hashicorp/vault/helper/tlsutil"
2016-09-30 04:06:40 +00:00
"github.com/hashicorp/vault/vault"
2015-03-13 16:37:32 +00:00
)
// ListenerFactory is the factory function to create a listener.
2016-09-30 04:06:40 +00:00
type ListenerFactory func(map[string]string, io.Writer) (net.Listener, map[string]string, vault.ReloadFunc, error)
2015-03-13 16:37:32 +00:00
// BuiltinListeners is the list of built-in listener types.
var BuiltinListeners = map[string]ListenerFactory{
2016-06-02 16:40:25 +00:00
"tcp": tcpListenerFactory,
"atlas": atlasListenerFactory,
2015-03-13 16:37:32 +00:00
}
// NewListener creates a new listener of the given type with the given
// configuration. The type is looked up in the BuiltinListeners map.
2016-09-30 04:06:40 +00:00
func NewListener(t string, config map[string]string, logger io.Writer) (net.Listener, map[string]string, vault.ReloadFunc, error) {
2015-03-13 16:37:32 +00:00
f, ok := BuiltinListeners[t]
if !ok {
return nil, nil, nil, fmt.Errorf("unknown listener type: %s", t)
2015-03-13 16:37:32 +00:00
}
2016-06-02 16:40:25 +00:00
return f(config, logger)
2015-03-13 16:37:32 +00:00
}
2015-03-13 16:56:08 +00:00
func listenerWrapTLS(
2015-04-04 19:06:41 +00:00
ln net.Listener,
props map[string]string,
2016-09-30 04:06:40 +00:00
config map[string]string) (net.Listener, map[string]string, vault.ReloadFunc, error) {
2015-04-04 19:06:41 +00:00
props["tls"] = "disabled"
if v, ok := config["tls_disable"]; ok {
disabled, err := strconv.ParseBool(v)
if err != nil {
return nil, nil, nil, fmt.Errorf("invalid value for 'tls_disable': %v", err)
}
if disabled {
return ln, props, nil, nil
}
2015-03-13 16:56:08 +00:00
}
_, ok := config["tls_cert_file"]
2015-03-13 16:56:08 +00:00
if !ok {
return nil, nil, nil, fmt.Errorf("'tls_cert_file' must be set")
2015-03-13 16:56:08 +00:00
}
_, ok = config["tls_key_file"]
2015-03-13 16:56:08 +00:00
if !ok {
return nil, nil, nil, fmt.Errorf("'tls_key_file' must be set")
2015-03-13 16:56:08 +00:00
}
cg := &certificateGetter{
id: config["address"],
}
if err := cg.reload(config); err != nil {
return nil, nil, nil, fmt.Errorf("error loading TLS cert: %s", err)
2015-03-13 16:56:08 +00:00
}
2015-07-23 03:26:02 +00:00
tlsvers, ok := config["tls_min_version"]
2015-07-23 03:19:41 +00:00
if !ok {
tlsvers = "tls12"
}
2015-07-23 20:51:45 +00:00
2015-03-13 16:56:08 +00:00
tlsConf := &tls.Config{}
tlsConf.GetCertificate = cg.getCertificate
tlsConf.NextProtos = []string{"h2", "http/1.1"}
2016-07-12 23:32:47 +00:00
tlsConf.MinVersion, ok = tlsutil.TLSLookup[tlsvers]
2015-07-23 03:19:41 +00:00
if !ok {
return nil, nil, nil, fmt.Errorf("'tls_min_version' value %s not supported, please specify one of [tls10,tls11,tls12]", tlsvers)
2015-07-23 03:19:41 +00:00
}
tlsConf.ClientAuth = tls.RequestClientCert
2015-03-13 16:56:08 +00:00
if v, ok := config["tls_cipher_suites"]; ok {
ciphers, err := tlsutil.ParseCiphers(v)
if err != nil {
return nil, nil, nil, fmt.Errorf("invalid value for 'tls_cipher_suites': %v", err)
}
tlsConf.CipherSuites = ciphers
}
if v, ok := config["tls_prefer_server_cipher_suites"]; ok {
preferServer, err := strconv.ParseBool(v)
if err != nil {
return nil, nil, nil, fmt.Errorf("invalid value for 'tls_prefer_server_cipher_suites': %v", err)
}
tlsConf.PreferServerCipherSuites = preferServer
}
if v, ok := config["tls_require_and_verify_client_cert"]; ok {
requireClient, err := strconv.ParseBool(v)
if err != nil {
return nil, nil, nil, fmt.Errorf("invalid value for 'tls_require_and_verify_client_cert': %v", err)
}
if requireClient {
tlsConf.ClientAuth = tls.RequireAndVerifyClientCert
}
}
2015-03-13 16:56:08 +00:00
ln = tls.NewListener(ln, tlsConf)
2015-04-04 19:06:41 +00:00
props["tls"] = "enabled"
return ln, props, cg.reload, nil
}
type certificateGetter struct {
sync.RWMutex
cert *tls.Certificate
id string
}
func (cg *certificateGetter) reload(config map[string]string) error {
if config["address"] != cg.id {
return nil
}
cert, err := tls.LoadX509KeyPair(config["tls_cert_file"], config["tls_key_file"])
if err != nil {
return err
}
cg.Lock()
defer cg.Unlock()
cg.cert = &cert
return nil
}
func (cg *certificateGetter) getCertificate(clientHello *tls.ClientHelloInfo) (*tls.Certificate, error) {
cg.RLock()
defer cg.RUnlock()
if cg.cert == nil {
return nil, fmt.Errorf("nil certificate")
}
return cg.cert, nil
2015-03-13 16:56:08 +00:00
}