| Message ID | 20210415093454.18324-1-maximilian.fillinger@foxcrypto.com |
|---|---|
| State | Accepted |
| Delegated to: | Antonio Quartulli |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net> Delivered-To: patchwork@openvpn.net Delivered-To: patchwork@openvpn.net Received: from director15.mail.ord1d.rsapps.net ([172.28.255.1]) by backend30.mail.ord1d.rsapps.net with LMTP id MB+dBNsMeGCNVQAAIUCqbw (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Thu, 15 Apr 2021 05:52:27 -0400 Received: from proxy1.mail.ord1c.rsapps.net ([172.28.255.1]) by director15.mail.ord1d.rsapps.net with LMTP id SLhuBNsMeGA/KAAAIcMcQg (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Thu, 15 Apr 2021 05:52:27 -0400 Received: from smtp33.gate.ord1c ([172.28.255.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) by proxy1.mail.ord1c.rsapps.net with LMTPS id EO64AtsMeGCvGAAA2VeTtA (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Thu, 15 Apr 2021 05:52:27 -0400 X-Spam-Threshold: 95 X-Spam-Score: 0 X-Spam-Flag: NO X-Virus-Scanned: OK X-Orig-To: openvpnslackdevel@openvpn.net X-Originating-Ip: [216.105.38.7] Authentication-Results: smtp33.gate.ord1c.rsapps.net; iprev=pass policy.iprev="216.105.38.7"; spf=pass smtp.mailfrom="openvpn-devel-bounces@lists.sourceforge.net" smtp.helo="lists.sourceforge.net"; dkim=fail (signature verification failed) header.d=sourceforge.net; dkim=fail (signature verification failed) header.d=sf.net; dkim=fail (key not found in DNS) header.d=foxcrypto.com; dmarc=fail (p=none; dis=none) header.from=foxcrypto.com X-Suspicious-Flag: YES X-Classification-ID: 4895c3c6-9dd0-11eb-a3a7-54520067fec4-1-1 Received: from [216.105.38.7] ([216.105.38.7:60092] helo=lists.sourceforge.net) by smtp33.gate.ord1c.rsapps.net (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) (ecelerity 4.2.38.62370 r(:)) with ESMTPS (cipher=DHE-RSA-AES256-GCM-SHA384) id 54/D5-06632-ADC08706; Thu, 15 Apr 2021 05:52:26 -0400 Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.92.3) (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) id 1lWyf3-0003m7-0W; Thu, 15 Apr 2021 09:51:45 +0000 Received: from [172.30.20.202] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.92.3) (envelope-from <maximilian.fillinger@foxcrypto.com>) id 1lWyeT-0003fq-6a for openvpn-devel@lists.sourceforge.net; Thu, 15 Apr 2021 09:51:09 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Type:MIME-Version:References:In-Reply-To: Message-ID:Date:Subject:CC:To:From:Sender:Reply-To:Content-Transfer-Encoding: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=16Z2nAYR0fjfdq75TvaslL6GCjcVfeHq+lLsv/YtAas=; b=WXjFJGgXfa+3Mjl6DysAYp65MP VvsKpkT5QoF3sGyPVH8EdTAoxtD6J/bfMSp3D1FBpoZMgzk014jyKWoP61OQ05MD0+ywTj4qIvUaw 30KiozyzV93lCOd+A/A5IOoBoYjxZzKbJBHcSBfpYpDTSVKX52KpBFME3xrVQbYA5AuQ=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Type:MIME-Version:References:In-Reply-To:Message-ID:Date:Subject: CC:To:From:Sender:Reply-To:Content-Transfer-Encoding:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=16Z2nAYR0fjfdq75TvaslL6GCjcVfeHq+lLsv/YtAas=; b=Wxqdx/shL8Inm/cK2FaLM6wFva SjhQHJ3erEGmLyy8dULjqQ0aj2NE4KeeSJMMETp8+Y658EFJuLjWvLNHGDJCOqXxqX4Fld5OggzKa LiuDoo8bfvvTSiIFwTe59zCe+gpeKgSrl+3FqyXj0LbAi8AU8vPYm8wc9EnN53PlnTH0=; Received: from nl-dft-mx-01.fox-it.com ([178.250.144.135]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.92.3) id 1lWyPO-00065D-ML for openvpn-devel@lists.sourceforge.net; Thu, 15 Apr 2021 09:35:48 +0000 From: Max Fillinger <maximilian.fillinger@foxcrypto.com> To: <openvpn-devel@lists.sourceforge.net> Date: Thu, 15 Apr 2021 11:34:54 +0200 Message-ID: <20210415093454.18324-1-maximilian.fillinger@foxcrypto.com> X-Mailer: git-send-email 2.11.0 In-Reply-To: <4743b2e0-89bf-29f9-f406-867d35c9bb1d@unstable.cc> References: <4743b2e0-89bf-29f9-f406-867d35c9bb1d@unstable.cc> MIME-Version: 1.0 X-ClientProxiedBy: FOXDFT1EX01.FOX.local (10.0.0.129) To FOXDFT1EX01.FOX.local (10.0.0.129) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; d=foxcrypto.com; s=NL-DFT-MX-01; c=relaxed/relaxed; h=from:to:cc:subject:date:message-id:references:mime-version:content-type; bh=16Z2nAYR0fjfdq75TvaslL6GCjcVfeHq+lLsv/YtAas=; b=ryZcrogzbXAB4y6dNVW4GL9vgq2gu1nOc4Xl1rlpWudTQNf7w0Y7yRSCQMkdYjtPNj+kupIt3Snn 97A6Wp5QAzvLncY87x+wi7rvQN+9be/GdbrwKcCdrRUZhmVBGxJ2BVt7XXyVKxqOAE1Pv1TSv7ZO yYjeCkuqR65SO4bW8x7b+AfIqWJMFEHi3H1zFD9QPilHeoySF7ToNt/YwlM2nnWy/ogE/l05h5ON QiOOEC7nWec9j913XY2aHe/HlHVl/NPk4HWqJG7Oa1WCfC2KuZJCVntRzZKhzOuZ9hgMLbXsCvLj E1GUTZvNOGmTNH8ErA8YHSbMrRNnpDXPGQUDGQ== X-Spam-Report: Spam Filtering performed by mx.sourceforge.net. See http://spamassassin.org/tag/ for more details. 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: foxcrypto.com] -0.0 SPF_PASS SPF: sender matches SPF record 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.1 DKIM_INVALID DKIM or DK signature exists, but is not valid X-Headers-End: 1lWyPO-00065D-ML Subject: [Openvpn-devel] [PATCH v3 2/2] Abort if CRL file can't be stat-ed in ssl_init X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: <openvpn-devel.lists.sourceforge.net> List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe> List-Archive: <http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel> List-Post: <mailto:openvpn-devel@lists.sourceforge.net> List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help> List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe> Cc: a@unstable.cc Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox |
| Series |
None
|
|
Commit Message
Maximilian Fillinger
April 14, 2021, 11:34 p.m. UTC
Now that the path for the CRL file is handled correctly when using
chroot, there's no good reason for the file to be inaccessible during
ssl_init().
This commit ensures that the CRL file is accessed successfully at least
once, which fixes a bug where the mbedtls version of OpenVPN wouldn't
use a reloaded CRL if it initially failed to access the file.
Signed-off-by: Max Fillinger <maximilian.fillinger@foxcrypto.com>
---
src/openvpn/ssl.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
Comments
Hi, On 15/04/2021 11:34, Max Fillinger wrote: > Now that the path for the CRL file is handled correctly when using > chroot, there's no good reason for the file to be inaccessible during > ssl_init(). > > This commit ensures that the CRL file is accessed successfully at least > once, which fixes a bug where the mbedtls version of OpenVPN wouldn't > use a reloaded CRL if it initially failed to access the file. > > Signed-off-by: Max Fillinger <maximilian.fillinger@foxcrypto.com> It simply does what it says: when calling init_ssl() upon instance initialization (i.e. upon openvpn startup, and upon USR1 on clients) if the CRL is not accessible, then openvpn will abort. This behaviour is what we need because "starting an instance without having the CRL where it is expected" is equivalent to a configuration error. Being unable to re-load the CRL at runtime is instead acceptable, because some subsystem might be just recreating the CRL, therefore openvpn will skip the reload and continue using what is currently in memory. The CRL will be reloaded at the next occasion. Acked-by: Antonio Quartulli <antonio@openvpn.net>
The actual code change looks very magical to me, and shrunk dramatically
between v1 and v3 of that code :-) - but if Antonio has tested this
and ACKs it, who am I to complain. I have compile-tested it, at least.
Your patch has been applied to the master and release/2.5 branch (bugfix).
commit 940619c88067d95a1c9865795624bc3822a89bd7 (master)
commit 8a06459d0c969b083377b63be16e5da1245ce0ee (release/2.5)
Author: Max Fillinger
Date: Thu Apr 15 11:34:54 2021 +0200
Abort if CRL file can't be stat-ed in ssl_init
Signed-off-by: Max Fillinger <maximilian.fillinger@foxcrypto.com>
Acked-by: Antonio Quartulli <antonio@openvpn.net>
Message-Id: <20210415093454.18324-1-maximilian.fillinger@foxcrypto.com>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg22118.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
--
kind regards,
Gert Doering
diff --git a/src/openvpn/ssl.c b/src/openvpn/ssl.c index 1e0e6170..6ce1d079 100644 --- a/src/openvpn/ssl.c +++ b/src/openvpn/ssl.c @@ -559,7 +559,15 @@ tls_ctx_reload_crl(struct tls_root_ctx *ssl_ctx, const char *crl_file, } else if (platform_stat(crl_file, &crl_stat) < 0) { - msg(M_WARN, "WARNING: Failed to stat CRL file, not (re)loading CRL."); + /* If crl_last_mtime is zero, the CRL file has not been read before. */ + if (ssl_ctx->crl_last_mtime == 0) + { + msg(M_FATAL, "ERROR: Failed to stat CRL file during initialization, exiting."); + } + else + { + msg(M_WARN, "WARNING: Failed to stat CRL file, not reloading CRL."); + } return; }