gcrypt: Fix format string in debug output.
[paraslash.git] / user_list.c
index f5aabc0979fa8d1feb1e60722cfd00451d5dfe1a..057ca6f8a340f2b508eb6fa5580249a3e8d01b85 100644 (file)
@@ -1,16 +1,17 @@
 /*
- * Copyright (C) 2006-2009 Andre Noll <maan@systemlinux.org>
+ * Copyright (C) 2006-2014 Andre Noll <maan@tuebingen.mpg.de>
  *
  * Licensed under the GPL v2. For licencing details see COPYING.
  */
 
 /** \file user_list.c User handling for para_server. */
 
+#include <regex.h>
 #include <sys/types.h>
-#include <dirent.h>
 
 #include "para.h"
 #include "error.h"
+#include "crypt.h"
 #include "fd.h"
 #include "string.h"
 #include "list.h"
@@ -37,7 +38,7 @@ static void populate_user_list(char *user_list_file)
                /* keyword, name, key, perms */
                char w[255], n[255], k[255], p[255], tmp[4][255];
                struct user *u;
-               RSA *rsa;
+               struct asymmetric_key *pubkey;
 
                ret = para_fgets(line, sizeof(line), file_ptr);
                if (ret <= 0)
@@ -47,15 +48,27 @@ static void populate_user_list(char *user_list_file)
                if (strcmp(w, "user"))
                        continue;
                PARA_DEBUG_LOG("found entry for user %s\n", n);
-               ret = get_rsa_key(k, &rsa, LOAD_PUBLIC_KEY);
+               ret = get_asymmetric_key(k, LOAD_PUBLIC_KEY, &pubkey);
                if (ret < 0) {
                        PARA_NOTICE_LOG("skipping entry for user %s: %s\n", n,
                                para_strerror(-ret));
                        continue;
                }
+               /*
+                * In order to encrypt len := CHALLENGE_SIZE + 2 * SESSION_KEY_LEN
+                * bytes using RSA_public_encrypt() with EME-OAEP padding mode,
+                * RSA_size(rsa) must be greater than len + 41. So ignore keys
+                * which are too short. For details see RSA_public_encrypt(3).
+                */
+               if (ret <= CHALLENGE_SIZE + 2 * SESSION_KEY_LEN + 41) {
+                       PARA_WARNING_LOG("public key %s too short (%d)\n",
+                               k, ret);
+                       free_asymmetric_key(pubkey);
+                       continue;
+               }
                u = para_malloc(sizeof(*u));
                u->name = para_strdup(n);
-               u->rsa = rsa;
+               u->pubkey = pubkey;
                u->perms = 0;
                num = sscanf(p, "%200[A-Z_],%200[A-Z_],%200[A-Z_],%200[A-Z_]",
                        tmp[0], tmp[1], tmp[2], tmp[3]);
@@ -101,7 +114,7 @@ void init_user_list(char *user_list_file)
                list_for_each_entry_safe(u, tmp, &user_list, node) {
                        list_del(&u->node);
                        free(u->name);
-                       rsa_free(u->rsa);
+                       free_asymmetric_key(u->pubkey);
                        free(u);
                }
        } else