Line | Count | Source |
1 | | /* |
2 | | * Copyright (c) 2020-2022 Yubico AB. All rights reserved. |
3 | | * Use of this source code is governed by a BSD-style |
4 | | * license that can be found in the LICENSE file. |
5 | | */ |
6 | | |
7 | | #include "fido.h" |
8 | | #include "fido/config.h" |
9 | | #include "fido/es256.h" |
10 | | |
11 | 670 | #define CMD_ENABLE_ENTATTEST 0x01 |
12 | 668 | #define CMD_TOGGLE_ALWAYS_UV 0x02 |
13 | 1.58k | #define CMD_SET_PIN_MINLEN 0x03 |
14 | | |
15 | | static int |
16 | | config_prepare_hmac(uint8_t subcmd, const cbor_item_t *item, fido_blob_t *hmac) |
17 | 907 | { |
18 | 907 | uint8_t prefix[32 + 2 * sizeof(uint8_t)], cbor[128]; |
19 | 907 | size_t cbor_len; |
20 | | |
21 | 907 | memset(prefix, 0xff, sizeof(prefix)); |
22 | 907 | prefix[sizeof(prefix) - 2] = CTAP_CBOR_CONFIG; |
23 | 907 | prefix[sizeof(prefix) - 1] = subcmd; |
24 | | |
25 | 907 | if ((cbor_len = cbor_serialize(item, cbor, sizeof(cbor))) == 0) { |
26 | 173 | fido_log_debug("%s: cbor_serialize", __func__); |
27 | 173 | return -1; |
28 | 173 | } |
29 | 734 | if ((hmac->ptr = malloc(cbor_len + sizeof(prefix))) == NULL) { |
30 | 8 | fido_log_debug("%s: malloc", __func__); |
31 | 8 | return -1; |
32 | 8 | } |
33 | 726 | memcpy(hmac->ptr, prefix, sizeof(prefix)); |
34 | 726 | memcpy(hmac->ptr + sizeof(prefix), cbor, cbor_len); |
35 | 726 | hmac->len = cbor_len + sizeof(prefix); |
36 | | |
37 | 726 | return 0; |
38 | 734 | } |
39 | | |
40 | | static int |
41 | | config_tx(fido_dev_t *dev, uint8_t subcmd, cbor_item_t **paramv, size_t paramc, |
42 | | const char *pin, int *ms) |
43 | 2.92k | { |
44 | 2.92k | cbor_item_t *argv[4]; |
45 | 2.92k | es256_pk_t *pk = NULL; |
46 | 2.92k | fido_blob_t *ecdh = NULL, f, hmac; |
47 | 2.92k | const uint8_t cmd = CTAP_CBOR_CONFIG; |
48 | 2.92k | int r = FIDO_ERR_INTERNAL; |
49 | | |
50 | 2.92k | memset(&f, 0, sizeof(f)); |
51 | 2.92k | memset(&hmac, 0, sizeof(hmac)); |
52 | 2.92k | memset(&argv, 0, sizeof(argv)); |
53 | | |
54 | | /* subCommand */ |
55 | 2.92k | if ((argv[0] = cbor_build_uint8(subcmd)) == NULL) { |
56 | 15 | fido_log_debug("%s: cbor encode", __func__); |
57 | 15 | goto fail; |
58 | 15 | } |
59 | | |
60 | | /* subCommandParams */ |
61 | 2.91k | if (paramc != 0 && |
62 | 2.91k | (argv[1] = cbor_flatten_vector(paramv, paramc)) == NULL) { |
63 | 23 | fido_log_debug("%s: cbor_flatten_vector", __func__); |
64 | 23 | goto fail; |
65 | 23 | } |
66 | | |
67 | | /* pinProtocol, pinAuth */ |
68 | 2.88k | if (argv[1] != NULL && (pin != NULL || |
69 | 1.56k | (fido_dev_supports_permissions(dev) && fido_dev_has_uv(dev)))) { |
70 | 907 | if (config_prepare_hmac(subcmd, argv[1], &hmac) < 0) { |
71 | 181 | fido_log_debug("%s: config_prepare_hmac", __func__); |
72 | 181 | goto fail; |
73 | 181 | } |
74 | 726 | if ((r = fido_do_ecdh(dev, &pk, &ecdh, ms)) != FIDO_OK) { |
75 | 650 | fido_log_debug("%s: fido_do_ecdh", __func__); |
76 | 650 | goto fail; |
77 | 650 | } |
78 | 76 | if ((r = cbor_add_uv_params(dev, cmd, &hmac, pk, ecdh, pin, |
79 | 76 | NULL, &argv[3], &argv[2], ms)) != FIDO_OK) { |
80 | 69 | fido_log_debug("%s: cbor_add_uv_params", __func__); |
81 | 69 | goto fail; |
82 | 69 | } |
83 | 76 | } |
84 | | |
85 | | /* framing and transmission */ |
86 | 1.98k | if (cbor_build_frame(cmd, argv, nitems(argv), &f) < 0 || |
87 | 1.98k | fido_tx(dev, CTAP_CMD_CBOR, f.ptr, f.len, ms) < 0) { |
88 | 142 | fido_log_debug("%s: fido_tx", __func__); |
89 | 142 | r = FIDO_ERR_TX; |
90 | 142 | goto fail; |
91 | 142 | } |
92 | | |
93 | 1.84k | r = FIDO_OK; |
94 | 2.92k | fail: |
95 | 2.92k | cbor_vector_free(argv, nitems(argv)); |
96 | 2.92k | es256_pk_free(&pk); |
97 | 2.92k | fido_blob_free(&ecdh); |
98 | 2.92k | free(f.ptr); |
99 | 2.92k | free(hmac.ptr); |
100 | | |
101 | 2.92k | return r; |
102 | 1.84k | } |
103 | | |
104 | | static int |
105 | | config_enable_entattest_wait(fido_dev_t *dev, const char *pin, int *ms) |
106 | 670 | { |
107 | 670 | int r; |
108 | | |
109 | 670 | if ((r = config_tx(dev, CMD_ENABLE_ENTATTEST, NULL, 0, pin, |
110 | 670 | ms)) != FIDO_OK) |
111 | 36 | return r; |
112 | | |
113 | 634 | return fido_rx_cbor_status(dev, ms); |
114 | 670 | } |
115 | | |
116 | | int |
117 | | fido_dev_enable_entattest(fido_dev_t *dev, const char *pin) |
118 | 670 | { |
119 | 670 | int ms = dev->timeout_ms; |
120 | | |
121 | 670 | return (config_enable_entattest_wait(dev, pin, &ms)); |
122 | 670 | } |
123 | | |
124 | | static int |
125 | | config_toggle_always_uv_wait(fido_dev_t *dev, const char *pin, int *ms) |
126 | 668 | { |
127 | 668 | int r; |
128 | | |
129 | 668 | if ((r = config_tx(dev, CMD_TOGGLE_ALWAYS_UV, NULL, 0, pin, |
130 | 668 | ms)) != FIDO_OK) |
131 | 29 | return r; |
132 | | |
133 | 639 | return (fido_rx_cbor_status(dev, ms)); |
134 | 668 | } |
135 | | |
136 | | int |
137 | | fido_dev_toggle_always_uv(fido_dev_t *dev, const char *pin) |
138 | 668 | { |
139 | 668 | int ms = dev->timeout_ms; |
140 | | |
141 | 668 | return config_toggle_always_uv_wait(dev, pin, &ms); |
142 | 668 | } |
143 | | |
144 | | static int |
145 | | config_pin_minlen_tx(fido_dev_t *dev, size_t len, bool force, |
146 | | const fido_str_array_t *rpid, const char *pin, int *ms) |
147 | 2.00k | { |
148 | 2.00k | cbor_item_t *argv[3]; |
149 | 2.00k | int r; |
150 | | |
151 | 2.00k | memset(argv, 0, sizeof(argv)); |
152 | | |
153 | 2.00k | if ((rpid == NULL && len == 0 && !force) || len > UINT8_MAX) { |
154 | 333 | r = FIDO_ERR_INVALID_ARGUMENT; |
155 | 333 | goto fail; |
156 | 333 | } |
157 | 1.66k | if (len && (argv[0] = cbor_build_uint8((uint8_t)len)) == NULL) { |
158 | 2 | fido_log_debug("%s: cbor_encode_uint8", __func__); |
159 | 2 | r = FIDO_ERR_INTERNAL; |
160 | 2 | goto fail; |
161 | 2 | } |
162 | 1.66k | if (rpid != NULL && (argv[1] = cbor_encode_str_array(rpid)) == NULL) { |
163 | 75 | fido_log_debug("%s: cbor_encode_str_array", __func__); |
164 | 75 | r = FIDO_ERR_INTERNAL; |
165 | 75 | goto fail; |
166 | 75 | } |
167 | 1.59k | if (force && (argv[2] = cbor_build_bool(true)) == NULL) { |
168 | 3 | fido_log_debug("%s: cbor_build_bool", __func__); |
169 | 3 | r = FIDO_ERR_INTERNAL; |
170 | 3 | goto fail; |
171 | 3 | } |
172 | 1.58k | if ((r = config_tx(dev, CMD_SET_PIN_MINLEN, argv, nitems(argv), |
173 | 1.58k | pin, ms)) != FIDO_OK) { |
174 | 1.01k | fido_log_debug("%s: config_tx", __func__); |
175 | 1.01k | goto fail; |
176 | 1.01k | } |
177 | | |
178 | 2.00k | fail: |
179 | 2.00k | cbor_vector_free(argv, nitems(argv)); |
180 | | |
181 | 2.00k | return r; |
182 | 1.58k | } |
183 | | |
184 | | static int |
185 | | config_pin_minlen(fido_dev_t *dev, size_t len, bool force, |
186 | | const fido_str_array_t *rpid, const char *pin, int *ms) |
187 | 2.00k | { |
188 | 2.00k | int r; |
189 | | |
190 | 2.00k | if ((r = config_pin_minlen_tx(dev, len, force, rpid, pin, |
191 | 2.00k | ms)) != FIDO_OK) |
192 | 1.42k | return r; |
193 | | |
194 | 573 | return fido_rx_cbor_status(dev, ms); |
195 | 2.00k | } |
196 | | |
197 | | int |
198 | | fido_dev_set_pin_minlen(fido_dev_t *dev, size_t len, const char *pin) |
199 | 684 | { |
200 | 684 | int ms = dev->timeout_ms; |
201 | | |
202 | 684 | return config_pin_minlen(dev, len, false, NULL, pin, &ms); |
203 | 684 | } |
204 | | |
205 | | int |
206 | | fido_dev_force_pin_change(fido_dev_t *dev, const char *pin) |
207 | 687 | { |
208 | 687 | int ms = dev->timeout_ms; |
209 | | |
210 | 687 | return config_pin_minlen(dev, 0, true, NULL, pin, &ms); |
211 | 687 | } |
212 | | |
213 | | int |
214 | | fido_dev_set_pin_minlen_rpid(fido_dev_t *dev, const char * const *rpid, |
215 | | size_t n, const char *pin) |
216 | 686 | { |
217 | 686 | fido_str_array_t sa; |
218 | 686 | int ms = dev->timeout_ms; |
219 | 686 | int r; |
220 | | |
221 | 686 | memset(&sa, 0, sizeof(sa)); |
222 | 686 | if (fido_str_array_pack(&sa, rpid, n) < 0) { |
223 | 56 | fido_log_debug("%s: fido_str_array_pack", __func__); |
224 | 56 | r = FIDO_ERR_INTERNAL; |
225 | 56 | goto fail; |
226 | 56 | } |
227 | 630 | r = config_pin_minlen(dev, 0, false, &sa, pin, &ms); |
228 | 686 | fail: |
229 | 686 | fido_str_array_free(&sa); |
230 | | |
231 | 686 | return r; |
232 | 630 | } |