From 1f449dc7e97db34c4aa4cf08eb7cc6269905709f Mon Sep 17 00:00:00 2001 From: Quentin Dufour Date: Mon, 22 Jan 2024 13:59:58 +0100 Subject: Rework some details (env var, cargo desc) --- src/main.rs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'src') diff --git a/src/main.rs b/src/main.rs index 3baa8e2..a7462bc 100644 --- a/src/main.rs +++ b/src/main.rs @@ -33,7 +33,7 @@ struct Args { #[clap(long)] dev: bool, - #[clap(short, long, env = "CONFIG_FILE", default_value = "aerogramme.toml")] + #[clap(short, long, env = "AEROGRAMME_CONFIG", default_value = "aerogramme.toml")] /// Path to the main Aerogramme configuration file config_file: PathBuf, } -- cgit v1.2.3 From f67f04129afaacc4cdeb69aa79e5c102ec7331bd Mon Sep 17 00:00:00 2001 From: Quentin Dufour Date: Tue, 23 Jan 2024 16:14:58 +0100 Subject: Add TLS support --- src/config.rs | 14 +++++++++++--- src/imap/mod.rs | 40 +++++++++++++++++++++++++++++++++++++--- src/main.rs | 9 +++++---- src/server.rs | 18 ++++++++++++++---- 4 files changed, 67 insertions(+), 14 deletions(-) (limited to 'src') diff --git a/src/config.rs b/src/config.rs index b9c1f09..0269773 100644 --- a/src/config.rs +++ b/src/config.rs @@ -9,7 +9,7 @@ use serde::{Deserialize, Serialize}; #[derive(Serialize, Deserialize, Debug, Clone)] pub struct CompanionConfig { pub pid: Option, - pub imap: ImapConfig, + pub imap: ImapUnsecureConfig, #[serde(flatten)] pub users: LoginStaticConfig, @@ -18,8 +18,9 @@ pub struct CompanionConfig { #[derive(Serialize, Deserialize, Debug, Clone)] pub struct ProviderConfig { pub pid: Option, - pub imap: ImapConfig, - pub lmtp: LmtpConfig, + pub imap: Option, + pub imap_unsecure: Option, + pub lmtp: Option, pub users: UserManagement, } @@ -40,6 +41,13 @@ pub struct LmtpConfig { #[derive(Serialize, Deserialize, Debug, Clone)] pub struct ImapConfig { pub bind_addr: SocketAddr, + pub certs: PathBuf, + pub key: PathBuf, +} + +#[derive(Serialize, Deserialize, Debug, Clone)] +pub struct ImapUnsecureConfig { + pub bind_addr: SocketAddr, } #[derive(Serialize, Deserialize, Debug, Clone)] diff --git a/src/imap/mod.rs b/src/imap/mod.rs index 3f685e6..b08a4ff 100644 --- a/src/imap/mod.rs +++ b/src/imap/mod.rs @@ -26,8 +26,10 @@ use imap_codec::imap_types::response::{Code, CommandContinuationRequest, Respons use imap_codec::imap_types::{core::Text, response::Greeting}; use imap_flow::server::{ServerFlow, ServerFlowEvent, ServerFlowOptions}; use imap_flow::stream::AnyStream; +use tokio_rustls::TlsAcceptor; +use rustls_pemfile::{certs, private_key}; -use crate::config::ImapConfig; +use crate::config::{ImapConfig, ImapUnsecureConfig}; use crate::imap::capability::ServerCapability; use crate::imap::request::Request; use crate::imap::response::{Body, ResponseOrIdle}; @@ -39,6 +41,7 @@ pub struct Server { bind_addr: SocketAddr, login_provider: ArcLoginProvider, capabilities: ServerCapability, + tls: Option, } #[derive(Clone)] @@ -49,11 +52,29 @@ struct ClientContext { server_capabilities: ServerCapability, } -pub fn new(config: ImapConfig, login: ArcLoginProvider) -> Server { +pub fn new(config: ImapConfig, login: ArcLoginProvider) -> Result { + let loaded_certs = certs(&mut std::io::BufReader::new(std::fs::File::open(config.certs)?)).collect::, _>>()?; + let loaded_key = private_key(&mut std::io::BufReader::new(std::fs::File::open(config.key)?))?.unwrap(); + + let tls_config = rustls::ServerConfig::builder() + .with_no_client_auth() + .with_single_cert(loaded_certs, loaded_key)?; + let acceptor = TlsAcceptor::from(Arc::new(tls_config)); + + Ok(Server { + bind_addr: config.bind_addr, + login_provider: login, + capabilities: ServerCapability::default(), + tls: Some(acceptor), + }) +} + +pub fn new_unsecure(config: ImapUnsecureConfig, login: ArcLoginProvider) -> Server { Server { bind_addr: config.bind_addr, login_provider: login, capabilities: ServerCapability::default(), + tls: None, } } @@ -78,6 +99,19 @@ impl Server { _ = must_exit.changed() => continue, }; tracing::info!("IMAP: accepted connection from {}", remote_addr); + let stream = match self.tls.clone() { + Some(acceptor) => { + let stream = match acceptor.accept(socket).await { + Ok(v) => v, + Err(e) => { + tracing::error!(err=?e, "TLS negociation failed"); + continue; + } + }; + AnyStream::new(stream) + }, + None => AnyStream::new(socket), + }; let client = ClientContext { addr: remote_addr.clone(), @@ -85,7 +119,7 @@ impl Server { must_exit: must_exit.clone(), server_capabilities: self.capabilities.clone(), }; - let conn = tokio::spawn(NetLoop::handler(client, AnyStream::new(socket))); + let conn = tokio::spawn(NetLoop::handler(client, stream)); connections.push(conn); } drop(tcp); diff --git a/src/main.rs b/src/main.rs index a7462bc..3e3674c 100644 --- a/src/main.rs +++ b/src/main.rs @@ -167,13 +167,14 @@ async fn main() -> Result<()> { use std::net::*; AnyConfig::Provider(ProviderConfig { pid: None, - imap: ImapConfig { + imap: None, + imap_unsecure: Some(ImapUnsecureConfig { bind_addr: SocketAddr::new(IpAddr::V6(Ipv6Addr::new(0, 0, 0, 0, 0, 0, 0, 1)), 1143), - }, - lmtp: LmtpConfig { + }), + lmtp: Some(LmtpConfig { bind_addr: SocketAddr::new(IpAddr::V6(Ipv6Addr::new(0, 0, 0, 0, 0, 0, 0, 1)), 1025), hostname: "example.tld".to_string(), - }, + }), users: UserManagement::Demo, }) } else { diff --git a/src/server.rs b/src/server.rs index bd2fd5d..0df1caf 100644 --- a/src/server.rs +++ b/src/server.rs @@ -15,6 +15,7 @@ use crate::login::{demo_provider::*, ldap_provider::*, static_provider::*}; pub struct Server { lmtp_server: Option>, + imap_unsecure_server: Option, imap_server: Option, pid_file: Option, } @@ -25,10 +26,11 @@ impl Server { let login = Arc::new(StaticLoginProvider::new(config.users).await?); let lmtp_server = None; - let imap_server = Some(imap::new(config.imap, login.clone())); + let imap_unsecure_server = Some(imap::new_unsecure(config.imap, login.clone())); Ok(Self { lmtp_server, - imap_server, + imap_unsecure_server, + imap_server: None, pid_file: config.pid, }) } @@ -41,11 +43,13 @@ impl Server { UserManagement::Ldap(x) => Arc::new(LdapLoginProvider::new(x)?), }; - let lmtp_server = Some(LmtpServer::new(config.lmtp, login.clone())); - let imap_server = Some(imap::new(config.imap, login.clone())); + let lmtp_server = config.lmtp.map(|lmtp| LmtpServer::new(lmtp, login.clone())); + let imap_unsecure_server = config.imap_unsecure.map(|imap| imap::new_unsecure(imap, login.clone())); + let imap_server = config.imap.map(|imap| imap::new(imap, login.clone())).transpose()?; Ok(Self { lmtp_server, + imap_unsecure_server, imap_server, pid_file: config.pid, }) @@ -79,6 +83,12 @@ impl Server { Some(s) => s.run(exit_signal.clone()).await, } }, + async { + match self.imap_unsecure_server { + None => Ok(()), + Some(s) => s.run(exit_signal.clone()).await, + } + }, async { match self.imap_server { None => Ok(()), -- cgit v1.2.3 From 9a265a09e24f6bebf6a6e327da5dd9dfd4dfa866 Mon Sep 17 00:00:00 2001 From: Quentin Dufour Date: Tue, 23 Jan 2024 21:09:57 +0100 Subject: WIP Dovecot Authentication Protocol Server --- src/auth.rs | 32 ++++++++++++++++++++++++++++++++ src/config.rs | 6 ++++++ src/main.rs | 4 ++++ src/server.rs | 4 ++++ 4 files changed, 46 insertions(+) create mode 100644 src/auth.rs (limited to 'src') diff --git a/src/auth.rs b/src/auth.rs new file mode 100644 index 0000000..27ff1e6 --- /dev/null +++ b/src/auth.rs @@ -0,0 +1,32 @@ +use std::net::SocketAddr; + +/// Seek compatibility with the Dovecot Authentication Protocol +/// +/// ## Trace +/// +/// ```text +/// S: VERSION 1 2 +/// S: MECH PLAIN plaintext +/// S: MECH LOGIN plaintext +/// S: SPID 15 +/// S: CUID 17654 +/// S: COOKIE f56692bee41f471ed01bd83520025305 +/// S: DONE +/// C: VERSION 1 2 +/// C: CPID 1 +/// C: AUTH 2 PLAIN service=smtp +/// S: CONT 2 +/// C: CONT 2 base64string== +/// S: OK 2 user=alice@example.tld +/// ``` +/// +/// ## Dovecot References +/// +/// https://doc.dovecot.org/developer_manual/design/auth_protocol/ +/// https://doc.dovecot.org/configuration_manual/authentication/authentication_mechanisms/#authentication-authentication-mechanisms +/// https://doc.dovecot.org/configuration_manual/howto/simple_virtual_install/#simple-virtual-install-smtp-auth +/// https://doc.dovecot.org/configuration_manual/howto/postfix_and_dovecot_sasl/#howto-postfix-and-dovecot-sasl + +pub struct AuthServer { + bind_addr: SocketAddr, +} diff --git a/src/config.rs b/src/config.rs index 0269773..faaa1ba 100644 --- a/src/config.rs +++ b/src/config.rs @@ -21,6 +21,7 @@ pub struct ProviderConfig { pub imap: Option, pub imap_unsecure: Option, pub lmtp: Option, + pub auth: Option, pub users: UserManagement, } @@ -32,6 +33,11 @@ pub enum UserManagement { Ldap(LoginLdapConfig), } +#[derive(Serialize, Deserialize, Debug, Clone)] +pub struct AuthConfig { + pub bind_addr: SocketAddr, +} + #[derive(Serialize, Deserialize, Debug, Clone)] pub struct LmtpConfig { pub bind_addr: SocketAddr, diff --git a/src/main.rs b/src/main.rs index 3e3674c..34d5a11 100644 --- a/src/main.rs +++ b/src/main.rs @@ -1,5 +1,6 @@ #![feature(async_fn_in_trait)] +mod auth; mod bayou; mod config; mod cryptoblob; @@ -175,6 +176,9 @@ async fn main() -> Result<()> { bind_addr: SocketAddr::new(IpAddr::V6(Ipv6Addr::new(0, 0, 0, 0, 0, 0, 0, 1)), 1025), hostname: "example.tld".to_string(), }), + auth: Some(AuthConfig { + bind_addr: SocketAddr::new(IpAddr::V6(Ipv6Addr::new(0, 0, 0, 0, 0, 0, 0, 1)), 12345), + }), users: UserManagement::Demo, }) } else { diff --git a/src/server.rs b/src/server.rs index 0df1caf..6210059 100644 --- a/src/server.rs +++ b/src/server.rs @@ -9,6 +9,7 @@ use tokio::sync::watch; use crate::config::*; use crate::imap; +use crate::auth; use crate::lmtp::*; use crate::login::ArcLoginProvider; use crate::login::{demo_provider::*, ldap_provider::*, static_provider::*}; @@ -17,6 +18,7 @@ pub struct Server { lmtp_server: Option>, imap_unsecure_server: Option, imap_server: Option, + auth_server: Option, pid_file: Option, } @@ -31,6 +33,7 @@ impl Server { lmtp_server, imap_unsecure_server, imap_server: None, + auth_server: None, pid_file: config.pid, }) } @@ -51,6 +54,7 @@ impl Server { lmtp_server, imap_unsecure_server, imap_server, + auth_server: None, pid_file: config.pid, }) } -- cgit v1.2.3 From 9afd2ea337953ae25517c7bf65406dd8cd0fd375 Mon Sep 17 00:00:00 2001 From: Quentin Dufour Date: Wed, 24 Jan 2024 15:21:55 +0100 Subject: Dovecot auth types --- src/auth.rs | 247 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++- src/main.rs | 12 ++- 2 files changed, 256 insertions(+), 3 deletions(-) (limited to 'src') diff --git a/src/auth.rs b/src/auth.rs index 27ff1e6..a85330b 100644 --- a/src/auth.rs +++ b/src/auth.rs @@ -1,4 +1,15 @@ use std::net::SocketAddr; +use std::sync::Arc; + +use anyhow::Result; +use futures::stream::{FuturesUnordered, StreamExt}; +use tokio::io::BufStream; +use tokio::io::AsyncBufReadExt; +use tokio::net::{TcpListener, TcpStream}; +use tokio::sync::watch; + +use crate::config::AuthConfig; +use crate::login::ArcLoginProvider; /// Seek compatibility with the Dovecot Authentication Protocol /// @@ -16,17 +27,249 @@ use std::net::SocketAddr; /// C: CPID 1 /// C: AUTH 2 PLAIN service=smtp /// S: CONT 2 -/// C: CONT 2 base64string== +/// C: CONT 2 base64stringFollowingRFC4616== /// S: OK 2 user=alice@example.tld /// ``` /// +/// ## RFC References +/// +/// PLAIN SASL - https://datatracker.ietf.org/doc/html/rfc4616 +/// +/// /// ## Dovecot References /// /// https://doc.dovecot.org/developer_manual/design/auth_protocol/ /// https://doc.dovecot.org/configuration_manual/authentication/authentication_mechanisms/#authentication-authentication-mechanisms /// https://doc.dovecot.org/configuration_manual/howto/simple_virtual_install/#simple-virtual-install-smtp-auth /// https://doc.dovecot.org/configuration_manual/howto/postfix_and_dovecot_sasl/#howto-postfix-and-dovecot-sasl - pub struct AuthServer { + login_provider: ArcLoginProvider, bind_addr: SocketAddr, } + + +impl AuthServer { + pub fn new( + config: AuthConfig, + login_provider: ArcLoginProvider, + ) -> Self { + Self { + bind_addr: config.bind_addr, + login_provider, + } + } + + + pub async fn run(self: &Arc, mut must_exit: watch::Receiver) -> Result<()> { + let tcp = TcpListener::bind(self.bind_addr).await?; + tracing::info!("SASL Authentication Protocol listening on {:#}", self.bind_addr); + + let mut connections = FuturesUnordered::new(); + + while !*must_exit.borrow() { + let wait_conn_finished = async { + if connections.is_empty() { + futures::future::pending().await + } else { + connections.next().await + } + }; + + let (socket, remote_addr) = tokio::select! { + a = tcp.accept() => a?, + _ = wait_conn_finished => continue, + _ = must_exit.changed() => continue, + }; + + tracing::info!("AUTH: accepted connection from {}", remote_addr); + let conn = tokio::spawn(NetLoop::new(socket).run()); + + + connections.push(conn); + } + drop(tcp); + + tracing::info!("AUTH server shutting down, draining remaining connections..."); + while connections.next().await.is_some() {} + + Ok(()) + } +} + +struct NetLoop { + stream: BufStream, +} + +impl NetLoop { + fn new(stream: TcpStream) -> Self{ + Self { + stream: BufStream::new(stream), + } + } + + async fn run(self) -> Result<()> { + let mut lines = self.stream.lines(); + while let Some(line) = lines.next_line().await? { + } + + Ok(()) + } +} + +#[derive(Debug)] +enum Mechanism { + Plain, + Login, +} + + +#[derive(Debug)] +enum AuthOptions { + /// Unique session ID. Mainly used for logging. + Session(u64), + /// Local IP connected to by the client. In standard string format, e.g. 127.0.0.1 or ::1. + LocalIp(String), + /// Remote client IP + RemoteIp(String), + /// Local port connected to by the client. + LocalPort(u16), + /// Remote client port + RemotePort(u16), + /// When Dovecot proxy is used, the real_rip/real_port are the proxy’s IP/port and real_lip/real_lport are the backend’s IP/port where the proxy was connected to. + RealRemoteIp(String), + RealLocalIp(String), + RealLocalPort(u16), + RealRemotePort(u16), + /// TLS SNI name + LocalName(String), + /// Enable debugging for this lookup. + Debug, + /// List of fields that will become available via %{forward_*} variables. The list is double-tab-escaped, like: tab_escaped[tab_escaped(key=value)[...] + /// Note: we do not unescape the tabulation, and thus we don't parse the data + ForwardViews(Vec), + /// Remote user has secured transport to auth client (e.g. localhost, SSL, TLS). + Secured(String), + /// The value can be “insecure”, “trusted” or “TLS”. + Transport(String), + /// TLS cipher being used. + TlsCipher(String), + /// The number of bits in the TLS cipher. + /// @FIXME: I don't know how if it's a string or an integer + TlsCipherBits(String), + /// TLS perfect forward secrecy algorithm (e.g. DH, ECDH) + TlsPfs(String), + /// TLS protocol name (e.g. SSLv3, TLSv1.2) + TlsProtocol(String), + /// Remote user has presented a valid SSL certificate. + ValidClientCert(String), + /// Ignore auth penalty tracking for this request + NoPenalty, + /// Username taken from client’s SSL certificate. + CertUsername, + /// IMAP ID string + ClientId, + /// Initial response for authentication mechanism. + /// NOTE: This must be the last parameter. Everything after it is ignored. + /// This is to avoid accidental security holes if user-given data is directly put to base64 string without filtering out tabs. + /// @FIXME: I don't understand this parameter + Resp(Vec), +} + +#[derive(Debug)] +enum ClientCommands { + /// Both client and server should check that they support the same major version number. If they don’t, the other side isn’t expected to be talking the same protocol and should be disconnected. Minor version can be ignored. This document specifies the version number 1.2. + Version { + major: u64, + minor: u64, + }, + /// CPID finishes the handshake from client. + Cpid(u64), + Auth { + /// ID is a connection-specific unique request identifier. It must be a 32bit number, so typically you’d just increment it by one. + id: u64, + /// A SASL mechanism (eg. LOGIN, PLAIN, etc.) + /// See: https://doc.dovecot.org/configuration_manual/authentication/authentication_mechanisms/#authentication-authentication-mechanisms + mechanism: Mechanism, + /// Service is the service requesting authentication, eg. pop3, imap, smtp. + service: String, + /// All the optional parameters + options: Vec, + + }, + Cont { + /// The must match the of the AUTH command. + id: u64, + /// Data that will be serialized to / deserialized from base64 + data: Vec, + } +} + +#[derive(Debug)] +enum MechanismParameters { + /// Anonymous authentication + Anonymous, + /// Transfers plaintext passwords + PlainText, + /// Subject to passive (dictionary) attack + Dictionary, + /// Subject to active (non-dictionary) attack + Active, + /// Provides forward secrecy between sessions + ForwardSecrecy, + /// Provides mutual authentication + MutualAuth, + /// Don’t advertise this as available SASL mechanism (eg. APOP) + Private, +} + +#[derive(Debug)] +enum FailCode { + /// This is a temporary internal failure, e.g. connection was lost to SQL database. + TempFail, + /// Authentication succeeded, but authorization failed (master user’s password was ok, but destination user was not ok). + AuthzFail, + /// User is disabled (password may or may not have been correct) + UserDisabled, + /// User’s password has expired. + PassExpired, +} + +#[derive(Debug)] +enum ServerCommands { + /// Both client and server should check that they support the same major version number. If they don’t, the other side isn’t expected to be talking the same protocol and should be disconnected. Minor version can be ignored. This document specifies the version number 1.2. + Version { + major: u64, + minor: u64, + }, + /// CPID and SPID specify client and server Process Identifiers (PIDs). They should be unique identifiers for the specific process. UNIX process IDs are good choices. + /// SPID can be used by authentication client to tell master which server process handled the authentication. + Spid(u64), + /// CUID is a server process-specific unique connection identifier. It’s different each time a connection is established for the server. + /// CUID is currently useful only for APOP authentication. + Cuid(u64), + Mech { + kind: Mechanism, + parameters: Vec, + }, + /// COOKIE returns connection-specific 128 bit cookie in hex. It must be given to REQUEST command. (Protocol v1.1+ / Dovecot v2.0+) + Cookie([u8;16]), + /// DONE finishes the handshake from server. + Done, + + Fail { + id: u64, + user_id: Option, + code: FailCode, + }, + Cont { + id: u64, + data: Vec, + }, + /// FAIL and OK may contain multiple unspecified parameters which authentication client may handle specially. + /// The only one specified here is user= parameter, which should always be sent if the userid is known. + Ok { + id: u64, + user_id: Option, + parameters: Vec, + }, +} diff --git a/src/main.rs b/src/main.rs index 34d5a11..72bce83 100644 --- a/src/main.rs +++ b/src/main.rs @@ -148,6 +148,16 @@ enum AccountManagement { }, } +#[cfg(tokio_unstable)] +fn tracer() { + console_subscriber::init(); +} + +#[cfg(not(tokio_unstable))] +fn tracer() { + tracing_subscriber::fmt::init(); +} + #[tokio::main] async fn main() -> Result<()> { if std::env::var("RUST_LOG").is_err() { @@ -161,7 +171,7 @@ async fn main() -> Result<()> { std::process::abort(); })); - tracing_subscriber::fmt::init(); + tracer(); let args = Args::parse(); let any_config = if args.dev { -- cgit v1.2.3 From f9d6c1c92769d0104acc4db6f236d48b97e1dbe0 Mon Sep 17 00:00:00 2001 From: Quentin Dufour Date: Wed, 24 Jan 2024 17:32:47 +0100 Subject: Basic parsing of Dovecot Client Commands --- src/auth.rs | 189 +++++++++++++++++++++++++++++++++++++++++++++++++++++----- src/server.rs | 9 ++- 2 files changed, 183 insertions(+), 15 deletions(-) (limited to 'src') diff --git a/src/auth.rs b/src/auth.rs index a85330b..42b3362 100644 --- a/src/auth.rs +++ b/src/auth.rs @@ -1,7 +1,7 @@ use std::net::SocketAddr; use std::sync::Arc; -use anyhow::Result; +use anyhow::{Result, anyhow}; use futures::stream::{FuturesUnordered, StreamExt}; use tokio::io::BufStream; use tokio::io::AsyncBufReadExt; @@ -60,7 +60,7 @@ impl AuthServer { } - pub async fn run(self: &Arc, mut must_exit: watch::Receiver) -> Result<()> { + pub async fn run(self: Self, mut must_exit: watch::Receiver) -> Result<()> { let tcp = TcpListener::bind(self.bind_addr).await?; tracing::info!("SASL Authentication Protocol listening on {:#}", self.bind_addr); @@ -82,7 +82,7 @@ impl AuthServer { }; tracing::info!("AUTH: accepted connection from {}", remote_addr); - let conn = tokio::spawn(NetLoop::new(socket).run()); + let conn = tokio::spawn(NetLoop::new(socket).run_error()); connections.push(conn); @@ -107,24 +107,39 @@ impl NetLoop { } } - async fn run(self) -> Result<()> { - let mut lines = self.stream.lines(); - while let Some(line) = lines.next_line().await? { + async fn run_error(self) { + match self.run().await { + Ok(()) => tracing::info!("Auth session succeeded"), + Err(e) => tracing::error!(err=?e, "Auth session failed"), } + } - Ok(()) + async fn run(mut self) -> Result<()> { + let mut buff: Vec = Vec::new(); + loop { + buff.clear(); + self.stream.read_until(b'\n', &mut buff).await?; + let (input, cmd) = client_command(&buff).map_err(|_| anyhow!("Unable to parse command"))?; + println!("input: {:?}, cmd: {:?}", input, cmd); + } } } -#[derive(Debug)] +// ----------------------------------------------------------------- +// +// DOVECOT AUTH TYPES +// +// ------------------------------------------------------------------ + +#[derive(Debug, Clone)] enum Mechanism { Plain, Login, } -#[derive(Debug)] -enum AuthOptions { +#[derive(Clone, Debug)] +enum AuthOption { /// Unique session ID. Mainly used for logging. Session(u64), /// Local IP connected to by the client. In standard string format, e.g. 127.0.0.1 or ::1. @@ -176,7 +191,7 @@ enum AuthOptions { } #[derive(Debug)] -enum ClientCommands { +enum ClientCommand { /// Both client and server should check that they support the same major version number. If they don’t, the other side isn’t expected to be talking the same protocol and should be disconnected. Minor version can be ignored. This document specifies the version number 1.2. Version { major: u64, @@ -189,11 +204,11 @@ enum ClientCommands { id: u64, /// A SASL mechanism (eg. LOGIN, PLAIN, etc.) /// See: https://doc.dovecot.org/configuration_manual/authentication/authentication_mechanisms/#authentication-authentication-mechanisms - mechanism: Mechanism, + mech: Mechanism, /// Service is the service requesting authentication, eg. pop3, imap, smtp. service: String, /// All the optional parameters - options: Vec, + options: Vec, }, Cont { @@ -235,7 +250,7 @@ enum FailCode { } #[derive(Debug)] -enum ServerCommands { +enum ServerCommand { /// Both client and server should check that they support the same major version number. If they don’t, the other side isn’t expected to be talking the same protocol and should be disconnected. Minor version can be ignored. This document specifies the version number 1.2. Version { major: u64, @@ -273,3 +288,149 @@ enum ServerCommands { parameters: Vec, }, } + +// ----------------------------------------------------------------- +// +// DOVECOT AUTH DECODING +// +// ------------------------------------------------------------------ + +use nom::{ + IResult, + branch::alt, + error::{ErrorKind, Error}, + character::complete::{tab, u64}, + bytes::complete::{tag, tag_no_case, take, take_while, take_while1}, + multi::{many1, separated_list0}, + combinator::{map, opt, recognize, value,}, + sequence::{pair, preceded, tuple}, +}; +use base64::Engine; + +fn version_command<'a>(input: &'a [u8]) -> IResult<&'a [u8], ClientCommand> { + let mut parser = tuple(( + tag_no_case(b"VERSION"), + tab, + u64, + tab, + u64 + )); + + let (input, (_, _, major, _, minor)) = parser(input)?; + Ok((input, ClientCommand::Version { major, minor })) +} + +fn cpid_command<'a>(input: &'a [u8]) -> IResult<&'a [u8], ClientCommand> { + preceded( + pair(tag_no_case(b"CPID"), tab), + map(u64, |v| ClientCommand::Cpid(v)) + )(input) +} + +fn mechanism<'a>(input: &'a [u8]) -> IResult<&'a [u8], Mechanism> { + alt(( + value(Mechanism::Plain, tag_no_case(b"PLAIN")), + value(Mechanism::Login, tag_no_case(b"LOGIN")), + ))(input) +} + +fn is_not_tab_or_esc_or_lf(c: u8) -> bool { + c != 0x09 && c != 0x01 && c != 0x0a // TAB or 0x01 or LF +} + +fn is_esc<'a>(input: &'a [u8]) -> IResult<&'a [u8], &[u8]> { + preceded(tag(&[0x01]), take(1usize))(input) +} + +fn parameter<'a>(input: &'a [u8]) -> IResult<&'a [u8], &[u8]> { + recognize(many1(alt(( + take_while1(is_not_tab_or_esc_or_lf), + is_esc + ))))(input) +} + +fn service<'a>(input: &'a [u8]) -> IResult<&'a [u8], String> { + let (input, buf) = preceded( + tag_no_case("service="), + parameter + )(input)?; + + std::str::from_utf8(buf) + .map(|v| (input, v.to_string())) + .map_err(|_| nom::Err::Failure(Error::new(input, ErrorKind::TakeWhile1))) +} + +fn auth_option<'a>(input: &'a [u8]) -> IResult<&'a [u8], AuthOption> { + alt(( + value(AuthOption::Debug, tag_no_case(b"debug")), + value(AuthOption::NoPenalty, tag_no_case(b"no-penalty")), + value(AuthOption::CertUsername, tag_no_case(b"cert_username")), + ))(input) +} + +fn auth_command<'a>(input: &'a [u8]) -> IResult<&'a [u8], ClientCommand> { + let mut parser = tuple(( + tag_no_case(b"AUTH"), + tab, + u64, + tab, + mechanism, + tab, + service, + map( + opt(preceded(tab, separated_list0(tab, auth_option))), + |o| o.unwrap_or(vec![]) + ), + )); + let (input, (_, _, id, _, mech, _, service, options)) = parser(input)?; + Ok((input, ClientCommand::Auth { id, mech, service, options })) +} + +fn is_base64_core(c: u8) -> bool { + c >= 0x30 && c <= 0x39 // 0-9 + || c >= 0x41 && c <= 0x5a // A-Z + || c >= 0x61 && c <= 0x7a // a-z + || c == 0x2b // + + || c == 0x2f // / +} + +fn is_base64_pad(c: u8) -> bool { + c == 0x3d +} + +/// @FIXME Dovecot does not say if base64 content must be padded or not +fn cont_command<'a>(input: &'a [u8]) -> IResult<&'a [u8], ClientCommand> { + let mut parser = tuple(( + tag_no_case(b"CONT"), + tab, + u64, + tab, + take_while1(is_base64_core), + take_while(is_base64_pad), + )); + + let (input, (_, _, id, _, b64, _)) = parser(input)?; + let data = base64::engine::general_purpose::STANDARD_NO_PAD.decode(b64).map_err(|_| nom::Err::Failure(Error::new(input, ErrorKind::TakeWhile1)))?; + Ok((input, ClientCommand::Cont { id, data })) +} + +fn client_command<'a>(input: &'a [u8]) -> IResult<&'a [u8], ClientCommand> { + alt(( + version_command, + cpid_command, + auth_command, + cont_command, + ))(input) +} + +/* +fn server_command(buf: &u8) -> IResult<&u8, ServerCommand> { + unimplemented!(); +} +*/ + +// ----------------------------------------------------------------- +// +// DOVECOT AUTH ENCODING +// +// ------------------------------------------------------------------ diff --git a/src/server.rs b/src/server.rs index 6210059..cf9930a 100644 --- a/src/server.rs +++ b/src/server.rs @@ -49,12 +49,13 @@ impl Server { let lmtp_server = config.lmtp.map(|lmtp| LmtpServer::new(lmtp, login.clone())); let imap_unsecure_server = config.imap_unsecure.map(|imap| imap::new_unsecure(imap, login.clone())); let imap_server = config.imap.map(|imap| imap::new(imap, login.clone())).transpose()?; + let auth_server = config.auth.map(|auth| auth::AuthServer::new(auth, login.clone())); Ok(Self { lmtp_server, imap_unsecure_server, imap_server, - auth_server: None, + auth_server, pid_file: config.pid, }) } @@ -98,6 +99,12 @@ impl Server { None => Ok(()), Some(s) => s.run(exit_signal.clone()).await, } + }, + async { + match self.auth_server { + None => Ok(()), + Some(a) => a.run(exit_signal.clone()).await, + } } )?; -- cgit v1.2.3 From c1bab5808b993d33bc505196f58b215d368c8e27 Mon Sep 17 00:00:00 2001 From: Quentin Dufour Date: Wed, 24 Jan 2024 17:50:03 +0100 Subject: QoL connection management --- src/auth.rs | 24 +++++++++++++++++++----- 1 file changed, 19 insertions(+), 5 deletions(-) (limited to 'src') diff --git a/src/auth.rs b/src/auth.rs index 42b3362..52b6fab 100644 --- a/src/auth.rs +++ b/src/auth.rs @@ -82,7 +82,7 @@ impl AuthServer { }; tracing::info!("AUTH: accepted connection from {}", remote_addr); - let conn = tokio::spawn(NetLoop::new(socket).run_error()); + let conn = tokio::spawn(NetLoop::new(socket, must_exit.clone()).run_error()); connections.push(conn); @@ -98,12 +98,14 @@ impl AuthServer { struct NetLoop { stream: BufStream, + stop: watch::Receiver, } impl NetLoop { - fn new(stream: TcpStream) -> Self{ + fn new(stream: TcpStream, stop: watch::Receiver) -> Self { Self { stream: BufStream::new(stream), + stop, } } @@ -118,9 +120,21 @@ impl NetLoop { let mut buff: Vec = Vec::new(); loop { buff.clear(); - self.stream.read_until(b'\n', &mut buff).await?; - let (input, cmd) = client_command(&buff).map_err(|_| anyhow!("Unable to parse command"))?; - println!("input: {:?}, cmd: {:?}", input, cmd); + tokio::select! { + read_res = self.stream.read_until(b'\n', &mut buff) => { + let bread = read_res?; + if bread == 0 { + tracing::info!("Reading buffer empty, connection has been closed. Exiting AUTH session."); + return Ok(()) + } + let (input, cmd) = client_command(&buff).map_err(|_| anyhow!("Unable to parse command"))?; + println!("input: {:?}, cmd: {:?}", input, cmd); + }, + _ = self.stop.changed() => { + tracing::debug!("Server is stopping, quitting this runner"); + return Ok(()) + } + } } } } -- cgit v1.2.3 From 0adb92e8ff34c1f1671e7afccd27874372d68bbd Mon Sep 17 00:00:00 2001 From: Quentin Dufour Date: Wed, 24 Jan 2024 18:30:28 +0100 Subject: AuthOptions parsing --- src/auth.rs | 90 ++++++++++++++++++++++++++++++++++++++++++++++++++----------- 1 file changed, 75 insertions(+), 15 deletions(-) (limited to 'src') diff --git a/src/auth.rs b/src/auth.rs index 52b6fab..b2d0fae 100644 --- a/src/auth.rs +++ b/src/auth.rs @@ -177,7 +177,7 @@ enum AuthOption { /// Note: we do not unescape the tabulation, and thus we don't parse the data ForwardViews(Vec), /// Remote user has secured transport to auth client (e.g. localhost, SSL, TLS). - Secured(String), + Secured(Option), /// The value can be “insecure”, “trusted” or “TLS”. Transport(String), /// TLS cipher being used. @@ -197,6 +197,9 @@ enum AuthOption { CertUsername, /// IMAP ID string ClientId, + /// An unknown key + UnknownPair(String, Vec), + UnknownBool(Vec), /// Initial response for authentication mechanism. /// NOTE: This must be the last parameter. Everything after it is ignored. /// This is to avoid accidental security holes if user-given data is directly put to base64 string without filtering out tabs. @@ -313,7 +316,7 @@ use nom::{ IResult, branch::alt, error::{ErrorKind, Error}, - character::complete::{tab, u64}, + character::complete::{tab, u64, u16}, bytes::complete::{tag, tag_no_case, take, take_while, take_while1}, multi::{many1, separated_list0}, combinator::{map, opt, recognize, value,}, @@ -363,22 +366,68 @@ fn parameter<'a>(input: &'a [u8]) -> IResult<&'a [u8], &[u8]> { ))))(input) } -fn service<'a>(input: &'a [u8]) -> IResult<&'a [u8], String> { - let (input, buf) = preceded( - tag_no_case("service="), - parameter - )(input)?; +fn parameter_str(input: &[u8]) -> IResult<&[u8], String> { + let (input, buf) = parameter(input)?; + + std::str::from_utf8(buf) + .map(|v| (input, v.to_string())) + .map_err(|_| nom::Err::Failure(Error::new(input, ErrorKind::TakeWhile1))) +} + +fn is_param_name_char(c: u8) -> bool { + is_not_tab_or_esc_or_lf(c) && c != 0x3d // = +} + +fn parameter_name(input: &[u8]) -> IResult<&[u8], String> { + let (input, buf) = take_while1(is_param_name_char)(input)?; std::str::from_utf8(buf) .map(|v| (input, v.to_string())) .map_err(|_| nom::Err::Failure(Error::new(input, ErrorKind::TakeWhile1))) } +fn service<'a>(input: &'a [u8]) -> IResult<&'a [u8], String> { + preceded( + tag_no_case("service="), + parameter_str + )(input) +} + fn auth_option<'a>(input: &'a [u8]) -> IResult<&'a [u8], AuthOption> { + use AuthOption::*; alt(( - value(AuthOption::Debug, tag_no_case(b"debug")), - value(AuthOption::NoPenalty, tag_no_case(b"no-penalty")), - value(AuthOption::CertUsername, tag_no_case(b"cert_username")), + alt(( + value(Debug, tag_no_case(b"debug")), + value(NoPenalty, tag_no_case(b"no-penalty")), + value(ClientId, tag_no_case(b"client_id")), + map(preceded(tag_no_case(b"session="), u64), |id| Session(id)), + map(preceded(tag_no_case(b"lip="), parameter_str), |ip| LocalIp(ip)), + map(preceded(tag_no_case(b"rip="), parameter_str), |ip| RemoteIp(ip)), + map(preceded(tag_no_case(b"lport="), u16), |port| LocalPort(port)), + map(preceded(tag_no_case(b"rport="), u16), |port| RemotePort(port)), + map(preceded(tag_no_case(b"real_rip="), parameter_str), |ip| RealRemoteIp(ip)), + map(preceded(tag_no_case(b"real_lip="), parameter_str), |ip| RealLocalIp(ip)), + map(preceded(tag_no_case(b"real_lport="), u16), |port| RealLocalPort(port)), + map(preceded(tag_no_case(b"real_rport="), u16), |port| RealRemotePort(port)), + )), + alt(( + map(preceded(tag_no_case(b"local_name="), parameter_str), |name| LocalName(name)), + map(preceded(tag_no_case(b"forward_views="), parameter), |views| ForwardViews(views.into())), + map(preceded(tag_no_case(b"secured="), parameter_str), |info| Secured(Some(info))), + value(Secured(None), tag_no_case(b"secured")), + value(CertUsername, tag_no_case(b"cert_username")), + map(preceded(tag_no_case(b"transport="), parameter_str), |ts| Transport(ts)), + map(preceded(tag_no_case(b"tls_cipher="), parameter_str), |cipher| TlsCipher(cipher)), + map(preceded(tag_no_case(b"tls_cipher_bits="), parameter_str), |bits| TlsCipherBits(bits)), + map(preceded(tag_no_case(b"tls_pfs="), parameter_str), |pfs| TlsPfs(pfs)), + map(preceded(tag_no_case(b"tls_protocol="), parameter_str), |proto| TlsProtocol(proto)), + map(preceded(tag_no_case(b"valid-client-cert="), parameter_str), |cert| ValidClientCert(cert)), + )), + alt(( + map(preceded(tag_no_case(b"resp="), base64), |data| Resp(data)), + map(tuple((parameter_name, tag(b"="), parameter)), |(n, _, v)| UnknownPair(n, v.into())), + map(parameter, |v| UnknownBool(v.into())), + )), ))(input) } @@ -409,7 +458,20 @@ fn is_base64_core(c: u8) -> bool { } fn is_base64_pad(c: u8) -> bool { - c == 0x3d + c == 0x3d // = +} + +fn base64(input: &[u8]) -> IResult<&[u8], Vec> { + let (input, (b64, _)) = tuple(( + take_while1(is_base64_core), + take_while(is_base64_pad), + ))(input)?; + + let data = base64::engine::general_purpose::STANDARD_NO_PAD + .decode(b64) + .map_err(|_| nom::Err::Failure(Error::new(input, ErrorKind::TakeWhile1)))?; + + Ok((input, data)) } /// @FIXME Dovecot does not say if base64 content must be padded or not @@ -419,12 +481,10 @@ fn cont_command<'a>(input: &'a [u8]) -> IResult<&'a [u8], ClientCommand> { tab, u64, tab, - take_while1(is_base64_core), - take_while(is_base64_pad), + base64 )); - let (input, (_, _, id, _, b64, _)) = parser(input)?; - let data = base64::engine::general_purpose::STANDARD_NO_PAD.decode(b64).map_err(|_| nom::Err::Failure(Error::new(input, ErrorKind::TakeWhile1)))?; + let (input, (_, _, id, _, data)) = parser(input)?; Ok((input, ClientCommand::Cont { id, data })) } -- cgit v1.2.3 From bbb050e3990125e51ae434654ae6fdea4f621650 Mon Sep 17 00:00:00 2001 From: Quentin Dufour Date: Wed, 24 Jan 2024 18:57:50 +0100 Subject: Basic response encoding --- src/auth.rs | 45 ++++++++++++++++++++++++++++++++++++++++++++- 1 file changed, 44 insertions(+), 1 deletion(-) (limited to 'src') diff --git a/src/auth.rs b/src/auth.rs index b2d0fae..05c88ce 100644 --- a/src/auth.rs +++ b/src/auth.rs @@ -4,7 +4,7 @@ use std::sync::Arc; use anyhow::{Result, anyhow}; use futures::stream::{FuturesUnordered, StreamExt}; use tokio::io::BufStream; -use tokio::io::AsyncBufReadExt; +use tokio::io::{AsyncBufReadExt, AsyncWriteExt}; use tokio::net::{TcpListener, TcpStream}; use tokio::sync::watch; @@ -117,6 +117,7 @@ impl NetLoop { } async fn run(mut self) -> Result<()> { + let mut resp_buff = BytesMut::new(); let mut buff: Vec = Vec::new(); loop { buff.clear(); @@ -129,6 +130,12 @@ impl NetLoop { } let (input, cmd) = client_command(&buff).map_err(|_| anyhow!("Unable to parse command"))?; println!("input: {:?}, cmd: {:?}", input, cmd); + ServerCommand::Version { + major: 1, + minor: 2, + }.encode(&mut resp_buff)?; + self.stream.write_all(&resp_buff).await?; + self.stream.flush().await?; }, _ = self.stop.changed() => { tracing::debug!("Server is stopping, quitting this runner"); @@ -508,3 +515,39 @@ fn server_command(buf: &u8) -> IResult<&u8, ServerCommand> { // DOVECOT AUTH ENCODING // // ------------------------------------------------------------------ +use tokio_util::bytes::{BufMut, BytesMut}; +trait Encode { + fn encode(&self, out: &mut BytesMut) -> Result<()>; +} + +fn tab_enc(out: &mut BytesMut) { + out.put(&[0x09][..]) +} + +fn lf_enc(out: &mut BytesMut) { + out.put(&[0x0A][..]) +} + +impl Encode for ServerCommand { + fn encode(&self, out: &mut BytesMut) -> Result<()> { + match self { + Self::Version { major, minor } => { + out.put(&b"VERSION"[..]); + tab_enc(out); + out.put(major.to_string().as_bytes()); + tab_enc(out); + out.put(minor.to_string().as_bytes()); + lf_enc(out); + }, + Self::Spid(v) => unimplemented!(), + Self::Cuid(v) => unimplemented!(), + Self::Mech { kind, parameters } => unimplemented!(), + Self::Cookie(v) => unimplemented!(), + Self::Done => unimplemented!(), + Self::Fail {id, user_id, code } => unimplemented!(), + Self::Cont { id, data } => unimplemented!(), + Self::Ok { id, user_id, parameters } => unimplemented!(), + } + Ok(()) + } +} -- cgit v1.2.3 From b86acd5ed06adbc59518cde78e5b6f31d4865197 Mon Sep 17 00:00:00 2001 From: Quentin Dufour Date: Wed, 24 Jan 2024 21:36:46 +0100 Subject: implemented business logic --- src/auth.rs | 242 +++++++++++++++++++++++++++++++++++++++++++++++++++--------- 1 file changed, 206 insertions(+), 36 deletions(-) (limited to 'src') diff --git a/src/auth.rs b/src/auth.rs index 05c88ce..697eff3 100644 --- a/src/auth.rs +++ b/src/auth.rs @@ -1,7 +1,6 @@ use std::net::SocketAddr; -use std::sync::Arc; -use anyhow::{Result, anyhow}; +use anyhow::{Result, anyhow, bail}; use futures::stream::{FuturesUnordered, StreamExt}; use tokio::io::BufStream; use tokio::io::{AsyncBufReadExt, AsyncWriteExt}; @@ -82,7 +81,7 @@ impl AuthServer { }; tracing::info!("AUTH: accepted connection from {}", remote_addr); - let conn = tokio::spawn(NetLoop::new(socket, must_exit.clone()).run_error()); + let conn = tokio::spawn(NetLoop::new(socket, self.login_provider.clone(), must_exit.clone()).run_error()); connections.push(conn); @@ -97,15 +96,23 @@ impl AuthServer { } struct NetLoop { + login: ArcLoginProvider, stream: BufStream, stop: watch::Receiver, + state: State, + read_buf: Vec, + write_buf: BytesMut, } impl NetLoop { - fn new(stream: TcpStream, stop: watch::Receiver) -> Self { + fn new(stream: TcpStream, login: ArcLoginProvider, stop: watch::Receiver) -> Self { Self { + login, stream: BufStream::new(stream), + state: State::Init, stop, + read_buf: Vec::new(), + write_buf: BytesMut::new(), } } @@ -117,25 +124,39 @@ impl NetLoop { } async fn run(mut self) -> Result<()> { - let mut resp_buff = BytesMut::new(); - let mut buff: Vec = Vec::new(); loop { - buff.clear(); tokio::select! { - read_res = self.stream.read_until(b'\n', &mut buff) => { + read_res = self.stream.read_until(b'\n', &mut self.read_buf) => { + // Detect EOF / socket close let bread = read_res?; if bread == 0 { tracing::info!("Reading buffer empty, connection has been closed. Exiting AUTH session."); return Ok(()) } - let (input, cmd) = client_command(&buff).map_err(|_| anyhow!("Unable to parse command"))?; - println!("input: {:?}, cmd: {:?}", input, cmd); - ServerCommand::Version { - major: 1, - minor: 2, - }.encode(&mut resp_buff)?; - self.stream.write_all(&resp_buff).await?; - self.stream.flush().await?; + + // Parse command + let (_, cmd) = client_command(&self.read_buf).map_err(|_| anyhow!("Unable to parse command"))?; + tracing::debug!(cmd=?cmd, "Received command"); + + // Make some progress in our local state + self.state.progress(cmd, &self.login).await; + if matches!(self.state, State::Error) { + bail!("Internal state is in error, previous logs explain what went wrong"); + } + + // Build response + let srv_cmds = self.state.response(); + srv_cmds.iter().try_for_each(|r| r.encode(&mut self.write_buf))?; + + // Send responses if at least one command response has been generated + if !srv_cmds.is_empty() { + self.stream.write_all(&self.write_buf).await?; + self.stream.flush().await?; + } + + // Reset buffers + self.read_buf.clear(); + self.write_buf.clear(); }, _ = self.stop.changed() => { tracing::debug!("Server is stopping, quitting this runner"); @@ -146,13 +167,150 @@ impl NetLoop { } } +// ----------------------------------------------------------------- +// +// BUSINESS LOGIC +// +// ----------------------------------------------------------------- +use rand::prelude::*; + +#[derive(Debug)] +enum AuthRes { + Success(String), + Failed(Option, Option), +} + +#[derive(Debug)] +enum State { + Error, + Init, + HandshakePart(Version), + HandshakeDone, + AuthPlainProgress { + id: u64, + }, + AuthDone { + id: u64, + res: AuthRes + }, +} + +const SERVER_MAJOR: u64 = 1; +const SERVER_MINOR: u64 = 2; +impl State { + async fn progress(&mut self, cmd: ClientCommand, login: &ArcLoginProvider) { + + let new_state = 'state: { + match (std::mem::replace(self, State::Error), cmd) { + (Self::Init, ClientCommand::Version(v)) => Self::HandshakePart(v), + (Self::HandshakePart(version), ClientCommand::Cpid(_cpid)) => { + if version.major != SERVER_MAJOR { + tracing::error!(client_major=version.major, server_major=SERVER_MAJOR, "Unsupported client major version"); + break 'state Self::Error + } + + Self::HandshakeDone + }, + (Self::HandshakeDone { .. }, ClientCommand::Auth { id, mech, .. }) | + (Self::AuthDone { .. }, ClientCommand::Auth { id, mech, ..}) => { + if mech != Mechanism::Plain { + tracing::error!(mechanism=?mech, "Unsupported Authentication Mechanism"); + break 'state Self::AuthDone { id, res: AuthRes::Failed(None, None) } + } + + Self::AuthPlainProgress { id } + }, + (Self::AuthPlainProgress { id }, ClientCommand::Cont { id: cid, data }) => { + // Check that ID matches + if cid != id { + tracing::error!(auth_id=id, cont_id=cid, "CONT id does not match AUTH id"); + break 'state Self::AuthDone { id, res: AuthRes::Failed(None, None) } + } + + // Check that we can extract user's login+pass + let (ubin, pbin) = match auth_plain(&data) { + Ok(([], ([], user, pass))) => (user, pass), + Ok(_) => { + tracing::error!("Impersonating user is not supported"); + break 'state Self::AuthDone { id, res: AuthRes::Failed(None, None) } + } + Err(e) => { + tracing::error!(err=?e, "Could not parse the SASL PLAIN data chunk"); + break 'state Self::AuthDone { id, res: AuthRes::Failed(None, None) } + }, + }; + + // Try to convert it to UTF-8 + let (user, password) = match (std::str::from_utf8(ubin), std::str::from_utf8(pbin)) { + (Ok(u), Ok(p)) => (u, p), + _ => { + tracing::error!("Username or password contain invalid UTF-8 characters"); + break 'state Self::AuthDone { id, res: AuthRes::Failed(None, None) } + } + }; + + // Try to connect user + match login.login(user, password).await { + Ok(_) => Self::AuthDone { id, res: AuthRes::Success(user.to_string())}, + Err(e) => { + tracing::warn!(err=?e, "login failed"); + Self::AuthDone { id, res: AuthRes::Failed(Some(user.to_string()), None) } + } + } + }, + _ => { + tracing::error!("This command is not valid in this context"); + Self::Error + }, + } + }; + tracing::debug!(state=?new_state, "Made progress"); + *self = new_state; + } + + fn response(&self) -> Vec { + let mut srv_cmd: Vec = Vec::new(); + + match self { + Self::HandshakeDone { .. } => { + srv_cmd.push(ServerCommand::Version(Version { major: SERVER_MAJOR, minor: SERVER_MINOR })); + srv_cmd.push(ServerCommand::Spid(1u64)); + srv_cmd.push(ServerCommand::Cuid(1u64)); + + let mut cookie = [0u8; 16]; + thread_rng().fill(&mut cookie); + srv_cmd.push(ServerCommand::Cookie(cookie)); + + srv_cmd.push(ServerCommand::Mech { + kind: Mechanism::Plain, + parameters: vec![MechanismParameters::PlainText], + }); + srv_cmd.push(ServerCommand::Done); + }, + Self::AuthPlainProgress { id } => { + srv_cmd.push(ServerCommand::Cont { id: *id, data: None }); + }, + Self::AuthDone { id, res: AuthRes::Success(user) } => { + srv_cmd.push(ServerCommand::Ok { id: *id, user_id: Some(user.to_string()), extra_parameters: vec![]}); + }, + Self::AuthDone { id, res: AuthRes::Failed(maybe_user, maybe_failcode) } => { + srv_cmd.push(ServerCommand::Fail { id: *id, user_id: maybe_user.clone(), code: maybe_failcode.clone(), extra_parameters: vec![]}); + }, + _ => (), + }; + + srv_cmd + } +} + + // ----------------------------------------------------------------- // // DOVECOT AUTH TYPES // -// ------------------------------------------------------------------ +// ----------------------------------------------------------------- -#[derive(Debug, Clone)] +#[derive(Debug, Clone, PartialEq)] enum Mechanism { Plain, Login, @@ -214,13 +372,16 @@ enum AuthOption { Resp(Vec), } +#[derive(Debug, Clone)] +struct Version { + major: u64, + minor: u64, +} + #[derive(Debug)] enum ClientCommand { /// Both client and server should check that they support the same major version number. If they don’t, the other side isn’t expected to be talking the same protocol and should be disconnected. Minor version can be ignored. This document specifies the version number 1.2. - Version { - major: u64, - minor: u64, - }, + Version(Version), /// CPID finishes the handshake from client. Cpid(u64), Auth { @@ -261,7 +422,7 @@ enum MechanismParameters { Private, } -#[derive(Debug)] +#[derive(Debug, Clone)] enum FailCode { /// This is a temporary internal failure, e.g. connection was lost to SQL database. TempFail, @@ -276,10 +437,7 @@ enum FailCode { #[derive(Debug)] enum ServerCommand { /// Both client and server should check that they support the same major version number. If they don’t, the other side isn’t expected to be talking the same protocol and should be disconnected. Minor version can be ignored. This document specifies the version number 1.2. - Version { - major: u64, - minor: u64, - }, + Version(Version), /// CPID and SPID specify client and server Process Identifiers (PIDs). They should be unique identifiers for the specific process. UNIX process IDs are good choices. /// SPID can be used by authentication client to tell master which server process handled the authentication. Spid(u64), @@ -298,18 +456,19 @@ enum ServerCommand { Fail { id: u64, user_id: Option, - code: FailCode, + code: Option, + extra_parameters: Vec>, }, Cont { id: u64, - data: Vec, + data: Option>, }, /// FAIL and OK may contain multiple unspecified parameters which authentication client may handle specially. /// The only one specified here is user= parameter, which should always be sent if the userid is known. Ok { id: u64, user_id: Option, - parameters: Vec, + extra_parameters: Vec>, }, } @@ -324,9 +483,9 @@ use nom::{ branch::alt, error::{ErrorKind, Error}, character::complete::{tab, u64, u16}, - bytes::complete::{tag, tag_no_case, take, take_while, take_while1}, + bytes::complete::{is_not, tag, tag_no_case, take, take_while, take_while1}, multi::{many1, separated_list0}, - combinator::{map, opt, recognize, value,}, + combinator::{map, opt, recognize, value, rest}, sequence::{pair, preceded, tuple}, }; use base64::Engine; @@ -341,7 +500,7 @@ fn version_command<'a>(input: &'a [u8]) -> IResult<&'a [u8], ClientCommand> { )); let (input, (_, _, major, _, minor)) = parser(input)?; - Ok((input, ClientCommand::Version { major, minor })) + Ok((input, ClientCommand::Version(Version { major, minor }))) } fn cpid_command<'a>(input: &'a [u8]) -> IResult<&'a [u8], ClientCommand> { @@ -510,6 +669,17 @@ fn server_command(buf: &u8) -> IResult<&u8, ServerCommand> { } */ +// ----------------------------------------------------------------- +// +// SASL DECODING +// +// ----------------------------------------------------------------- + +// impersonated user, login, password +fn auth_plain<'a>(input: &'a [u8]) -> IResult<&'a [u8], (&'a [u8], &'a [u8], &'a [u8])> { + tuple((is_not([0x0]), is_not([0x0]), rest))(input) +} + // ----------------------------------------------------------------- // // DOVECOT AUTH ENCODING @@ -531,7 +701,7 @@ fn lf_enc(out: &mut BytesMut) { impl Encode for ServerCommand { fn encode(&self, out: &mut BytesMut) -> Result<()> { match self { - Self::Version { major, minor } => { + Self::Version (Version { major, minor }) => { out.put(&b"VERSION"[..]); tab_enc(out); out.put(major.to_string().as_bytes()); @@ -544,9 +714,9 @@ impl Encode for ServerCommand { Self::Mech { kind, parameters } => unimplemented!(), Self::Cookie(v) => unimplemented!(), Self::Done => unimplemented!(), - Self::Fail {id, user_id, code } => unimplemented!(), Self::Cont { id, data } => unimplemented!(), - Self::Ok { id, user_id, parameters } => unimplemented!(), + Self::Ok { id, user_id, extra_parameters } => unimplemented!(), + Self::Fail {id, user_id, code, extra_parameters } => unimplemented!(), } Ok(()) } -- cgit v1.2.3 From 337b7bce6d46b61dd6ba1203e180ee35c820c578 Mon Sep 17 00:00:00 2001 From: Quentin Dufour Date: Wed, 24 Jan 2024 22:06:22 +0100 Subject: Encoding of server commmands --- src/auth.rs | 133 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++---- 1 file changed, 125 insertions(+), 8 deletions(-) (limited to 'src') diff --git a/src/auth.rs b/src/auth.rs index 697eff3..31b8206 100644 --- a/src/auth.rs +++ b/src/auth.rs @@ -24,10 +24,18 @@ use crate::login::ArcLoginProvider; /// S: DONE /// C: VERSION 1 2 /// C: CPID 1 +/// /// C: AUTH 2 PLAIN service=smtp /// S: CONT 2 /// C: CONT 2 base64stringFollowingRFC4616== /// S: OK 2 user=alice@example.tld +/// +/// C: AUTH 42 LOGIN service=smtp +/// S: CONT 42 VXNlcm5hbWU6 +/// C: CONT 42 b64User +/// S: CONT 42 UGFzc3dvcmQ6 +/// C: CONT 42 b64Pass +/// S: FAIL 42 user=alice /// ``` /// /// ## RFC References @@ -698,6 +706,44 @@ fn lf_enc(out: &mut BytesMut) { out.put(&[0x0A][..]) } +impl Encode for Mechanism { + fn encode(&self, out: &mut BytesMut) -> Result<()> { + match self { + Self::Plain => out.put(&b"PLAIN"[..]), + Self::Login => out.put(&b"LOGIN"[..]), + } + Ok(()) + } +} + +impl Encode for MechanismParameters { + fn encode(&self, out: &mut BytesMut) -> Result<()> { + match self { + Self::Anonymous => out.put(&b"anonymous"[..]), + Self::PlainText => out.put(&b"plaintext"[..]), + Self::Dictionary => out.put(&b"dictionary"[..]), + Self::Active => out.put(&b"active"[..]), + Self::ForwardSecrecy => out.put(&b"forward-secrecy"[..]), + Self::MutualAuth => out.put(&b"mutual-auth"[..]), + Self::Private => out.put(&b"private"[..]), + } + Ok(()) + } +} + + +impl Encode for FailCode { + fn encode(&self, out: &mut BytesMut) -> Result<()> { + match self { + Self::TempFail => out.put(&b"temp_fail"[..]), + Self::AuthzFail => out.put(&b"authz_fail"[..]), + Self::UserDisabled => out.put(&b"user_disabled"[..]), + Self::PassExpired => out.put(&b"pass_expired"[..]), + }; + Ok(()) + } +} + impl Encode for ServerCommand { fn encode(&self, out: &mut BytesMut) -> Result<()> { match self { @@ -709,14 +755,85 @@ impl Encode for ServerCommand { out.put(minor.to_string().as_bytes()); lf_enc(out); }, - Self::Spid(v) => unimplemented!(), - Self::Cuid(v) => unimplemented!(), - Self::Mech { kind, parameters } => unimplemented!(), - Self::Cookie(v) => unimplemented!(), - Self::Done => unimplemented!(), - Self::Cont { id, data } => unimplemented!(), - Self::Ok { id, user_id, extra_parameters } => unimplemented!(), - Self::Fail {id, user_id, code, extra_parameters } => unimplemented!(), + Self::Spid(pid) => { + out.put(&b"SPID"[..]); + tab_enc(out); + out.put(pid.to_string().as_bytes()); + lf_enc(out); + }, + Self::Cuid(pid) => { + out.put(&b"CUID"[..]); + tab_enc(out); + out.put(pid.to_string().as_bytes()); + lf_enc(out); + }, + Self::Cookie(cval) => { + out.put(&b"COOKIE"[..]); + tab_enc(out); + out.put(hex::encode(cval).as_bytes()); + lf_enc(out); + + }, + Self::Mech { kind, parameters } => { + out.put(&b"MECH"[..]); + tab_enc(out); + kind.encode(out)?; + for p in parameters.iter() { + tab_enc(out); + p.encode(out)?; + } + lf_enc(out); + }, + Self::Done => { + out.put(&b"DONE"[..]); + lf_enc(out); + }, + Self::Cont { id, data } => { + out.put(&b"CONT"[..]); + tab_enc(out); + out.put(id.to_string().as_bytes()); + if let Some(rdata) = data { + tab_enc(out); + let b64 = base64::engine::general_purpose::STANDARD.encode(rdata); + out.put(b64.as_bytes()); + } + lf_enc(out); + }, + Self::Ok { id, user_id, extra_parameters } => { + out.put(&b"OK"[..]); + tab_enc(out); + out.put(id.to_string().as_bytes()); + if let Some(user) = user_id { + tab_enc(out); + out.put(&b"user="[..]); + out.put(user.as_bytes()); + } + for p in extra_parameters.iter() { + tab_enc(out); + out.put(&p[..]); + } + lf_enc(out); + }, + Self::Fail {id, user_id, code, extra_parameters } => { + out.put(&b"FAIL"[..]); + tab_enc(out); + out.put(id.to_string().as_bytes()); + if let Some(user) = user_id { + tab_enc(out); + out.put(&b"user="[..]); + out.put(user.as_bytes()); + } + if let Some(code_val) = code { + tab_enc(out); + out.put(&b"code="[..]); + code_val.encode(out)?; + } + for p in extra_parameters.iter() { + tab_enc(out); + out.put(&p[..]); + } + lf_enc(out); + }, } Ok(()) } -- cgit v1.2.3 From 06d37d3399499c94fff408056155db76f43c4afa Mon Sep 17 00:00:00 2001 From: Quentin Dufour Date: Wed, 24 Jan 2024 22:15:33 +0100 Subject: correctly parse sasl --- src/auth.rs | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) (limited to 'src') diff --git a/src/auth.rs b/src/auth.rs index 31b8206..4d2747f 100644 --- a/src/auth.rs +++ b/src/auth.rs @@ -683,9 +683,16 @@ fn server_command(buf: &u8) -> IResult<&u8, ServerCommand> { // // ----------------------------------------------------------------- +fn not_null(c: u8) -> bool { + c != 0x0 +} + // impersonated user, login, password fn auth_plain<'a>(input: &'a [u8]) -> IResult<&'a [u8], (&'a [u8], &'a [u8], &'a [u8])> { - tuple((is_not([0x0]), is_not([0x0]), rest))(input) + map( + tuple((take_while(not_null), take(1usize), take_while(not_null), take(1usize), rest)), + |(imp, _, user, _, pass)| (imp, user, pass), + )(input) } // ----------------------------------------------------------------- -- cgit v1.2.3 From efd9ae5defd8647b709ad0e6cf17f3b28278c591 Mon Sep 17 00:00:00 2001 From: Quentin Dufour Date: Wed, 24 Jan 2024 23:09:29 +0100 Subject: Fix postfix bug --- src/auth.rs | 26 +++++++++++++++++--------- 1 file changed, 17 insertions(+), 9 deletions(-) (limited to 'src') diff --git a/src/auth.rs b/src/auth.rs index 4d2747f..a3edcbc 100644 --- a/src/auth.rs +++ b/src/auth.rs @@ -144,7 +144,7 @@ impl NetLoop { // Parse command let (_, cmd) = client_command(&self.read_buf).map_err(|_| anyhow!("Unable to parse command"))?; - tracing::debug!(cmd=?cmd, "Received command"); + tracing::trace!(cmd=?cmd, "Received command"); // Make some progress in our local state self.state.progress(cmd, &self.login).await; @@ -154,7 +154,10 @@ impl NetLoop { // Build response let srv_cmds = self.state.response(); - srv_cmds.iter().try_for_each(|r| r.encode(&mut self.write_buf))?; + srv_cmds.iter().try_for_each(|r| { + tracing::trace!(cmd=?r, "Sent command"); + r.encode(&mut self.write_buf) + })?; // Send responses if at least one command response has been generated if !srv_cmds.is_empty() { @@ -282,17 +285,19 @@ impl State { match self { Self::HandshakeDone { .. } => { srv_cmd.push(ServerCommand::Version(Version { major: SERVER_MAJOR, minor: SERVER_MINOR })); - srv_cmd.push(ServerCommand::Spid(1u64)); - srv_cmd.push(ServerCommand::Cuid(1u64)); - - let mut cookie = [0u8; 16]; - thread_rng().fill(&mut cookie); - srv_cmd.push(ServerCommand::Cookie(cookie)); srv_cmd.push(ServerCommand::Mech { kind: Mechanism::Plain, parameters: vec![MechanismParameters::PlainText], }); + + srv_cmd.push(ServerCommand::Spid(15u64)); + srv_cmd.push(ServerCommand::Cuid(19350u64)); + + let mut cookie = [0u8; 16]; + thread_rng().fill(&mut cookie); + srv_cmd.push(ServerCommand::Cookie(cookie)); + srv_cmd.push(ServerCommand::Done); }, Self::AuthPlainProgress { id } => { @@ -366,6 +371,8 @@ enum AuthOption { ValidClientCert(String), /// Ignore auth penalty tracking for this request NoPenalty, + /// Unknown option sent by Postfix + NoLogin, /// Username taken from client’s SSL certificate. CertUsername, /// IMAP ID string @@ -574,6 +581,7 @@ fn auth_option<'a>(input: &'a [u8]) -> IResult<&'a [u8], AuthOption> { value(Debug, tag_no_case(b"debug")), value(NoPenalty, tag_no_case(b"no-penalty")), value(ClientId, tag_no_case(b"client_id")), + value(NoLogin, tag_no_case(b"nologin")), map(preceded(tag_no_case(b"session="), u64), |id| Session(id)), map(preceded(tag_no_case(b"lip="), parameter_str), |ip| LocalIp(ip)), map(preceded(tag_no_case(b"rip="), parameter_str), |ip| RemoteIp(ip)), @@ -799,8 +807,8 @@ impl Encode for ServerCommand { out.put(&b"CONT"[..]); tab_enc(out); out.put(id.to_string().as_bytes()); + tab_enc(out); if let Some(rdata) = data { - tab_enc(out); let b64 = base64::engine::general_purpose::STANDARD.encode(rdata); out.put(b64.as_bytes()); } -- cgit v1.2.3