1997-11-18 15:06:00 +01:00
|
|
|
/* sig-check.c - Check a signature
|
2003-12-13 04:53:27 +01:00
|
|
|
* Copyright (C) 1998, 1999, 2000, 2001, 2002,
|
|
|
|
* 2003 Free Software Foundation, Inc.
|
1997-11-18 15:06:00 +01:00
|
|
|
*
|
1998-12-23 13:41:40 +01:00
|
|
|
* This file is part of GnuPG.
|
1997-11-18 15:06:00 +01:00
|
|
|
*
|
1998-12-23 13:41:40 +01:00
|
|
|
* GnuPG is free software; you can redistribute it and/or modify
|
1997-11-18 15:06:00 +01:00
|
|
|
* it under the terms of the GNU General Public License as published by
|
|
|
|
* the Free Software Foundation; either version 2 of the License, or
|
|
|
|
* (at your option) any later version.
|
|
|
|
*
|
1998-12-23 13:41:40 +01:00
|
|
|
* GnuPG is distributed in the hope that it will be useful,
|
1997-11-18 15:06:00 +01:00
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU General Public License
|
|
|
|
* along with this program; if not, write to the Free Software
|
|
|
|
* Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include <config.h>
|
|
|
|
#include <stdio.h>
|
|
|
|
#include <stdlib.h>
|
|
|
|
#include <string.h>
|
|
|
|
#include <assert.h>
|
|
|
|
#include "util.h"
|
|
|
|
#include "packet.h"
|
2002-06-29 15:46:34 +02:00
|
|
|
#include "memory.h"
|
|
|
|
#include "mpi.h"
|
1997-11-18 15:06:00 +01:00
|
|
|
#include "keydb.h"
|
2002-06-29 15:46:34 +02:00
|
|
|
#include "cipher.h"
|
1997-11-24 23:24:04 +01:00
|
|
|
#include "main.h"
|
1998-05-29 13:53:54 +02:00
|
|
|
#include "status.h"
|
1998-06-25 12:19:08 +02:00
|
|
|
#include "i18n.h"
|
2000-07-14 19:34:53 +02:00
|
|
|
#include "options.h"
|
1997-11-18 15:06:00 +01:00
|
|
|
|
1998-06-15 17:41:04 +02:00
|
|
|
struct cmp_help_context_s {
|
|
|
|
PKT_signature *sig;
|
2002-06-29 15:46:34 +02:00
|
|
|
MD_HANDLE md;
|
1998-06-15 17:41:04 +02:00
|
|
|
};
|
|
|
|
|
2003-07-20 02:10:13 +02:00
|
|
|
static int do_check( PKT_public_key *pk, PKT_signature *sig, MD_HANDLE digest,
|
2003-08-13 05:31:36 +02:00
|
|
|
int *r_expired, int *r_revoked, PKT_public_key *ret_pk);
|
1999-11-13 17:43:23 +01:00
|
|
|
|
1997-11-18 15:06:00 +01:00
|
|
|
/****************
|
1998-04-25 10:08:35 +02:00
|
|
|
* Check the signature which is contained in SIG.
|
2002-06-29 15:46:34 +02:00
|
|
|
* The MD_HANDLE should be currently open, so that this function
|
1998-04-25 10:08:35 +02:00
|
|
|
* is able to append some data, before finalizing the digest.
|
1997-11-18 15:06:00 +01:00
|
|
|
*/
|
|
|
|
int
|
2002-06-29 15:46:34 +02:00
|
|
|
signature_check( PKT_signature *sig, MD_HANDLE digest )
|
1999-07-02 11:50:57 +02:00
|
|
|
{
|
2003-08-13 05:31:36 +02:00
|
|
|
return signature_check2( sig, digest, NULL, NULL, NULL, NULL );
|
1999-07-02 11:50:57 +02:00
|
|
|
}
|
|
|
|
|
2002-06-29 15:46:34 +02:00
|
|
|
int
|
2003-07-20 02:10:13 +02:00
|
|
|
signature_check2( PKT_signature *sig, MD_HANDLE digest, u32 *r_expiredate,
|
2003-08-13 05:31:36 +02:00
|
|
|
int *r_expired, int *r_revoked, PKT_public_key *ret_pk )
|
1997-11-18 15:06:00 +01:00
|
|
|
{
|
2002-06-29 15:46:34 +02:00
|
|
|
PKT_public_key *pk = m_alloc_clear( sizeof *pk );
|
1998-01-31 22:24:36 +01:00
|
|
|
int rc=0;
|
1997-11-18 15:06:00 +01:00
|
|
|
|
2003-12-13 04:53:27 +01:00
|
|
|
if( (rc=check_digest_algo(sig->digest_algo)) )
|
|
|
|
; /* we don't have this digest */
|
|
|
|
else if((rc=check_pubkey_algo(sig->pubkey_algo)))
|
|
|
|
; /* we don't have this pubkey algo */
|
|
|
|
else if(!md_algo_present(digest,sig->digest_algo))
|
|
|
|
{
|
|
|
|
/* Sanity check that the md has a context for the hash that the
|
|
|
|
sig is expecting. This can happen if a onepass sig header does
|
|
|
|
not match the actual sig, and also if the clearsign "Hash:"
|
|
|
|
header is missing or does not match the actual sig. */
|
2002-08-07 21:53:27 +02:00
|
|
|
|
|
|
|
log_info(_("WARNING: signature digest conflict in message\n"));
|
2003-01-16 20:20:10 +01:00
|
|
|
rc=G10ERR_GENERAL;
|
2003-12-13 04:53:27 +01:00
|
|
|
}
|
2002-08-07 21:53:27 +02:00
|
|
|
else if( get_pubkey( pk, sig->keyid ) )
|
2002-06-29 15:46:34 +02:00
|
|
|
rc = G10ERR_NO_PUBKEY;
|
2002-10-05 00:12:09 +02:00
|
|
|
else if(!pk->is_valid && !pk->is_primary)
|
2002-07-23 20:42:18 +02:00
|
|
|
rc=G10ERR_BAD_PUBKEY; /* you cannot have a good sig from an
|
|
|
|
invalid subkey */
|
1999-07-02 11:50:57 +02:00
|
|
|
else {
|
2003-07-22 01:19:15 +02:00
|
|
|
if(r_expiredate)
|
|
|
|
*r_expiredate = pk->expiredate;
|
2003-08-13 05:31:36 +02:00
|
|
|
rc = do_check( pk, sig, digest, r_expired, r_revoked, ret_pk );
|
1999-07-02 11:50:57 +02:00
|
|
|
}
|
1998-02-16 21:05:02 +01:00
|
|
|
|
1998-06-29 14:30:57 +02:00
|
|
|
free_public_key( pk );
|
1999-02-26 17:59:48 +01:00
|
|
|
|
1999-05-20 14:11:41 +02:00
|
|
|
if( !rc && sig->sig_class < 2 && is_status_enabled() ) {
|
1999-03-02 10:41:49 +01:00
|
|
|
/* This signature id works best with DLP algorithms because
|
|
|
|
* they use a random parameter for every signature. Instead of
|
|
|
|
* this sig-id we could have also used the hash of the document
|
|
|
|
* and the timestamp, but the drawback of this is, that it is
|
|
|
|
* not possible to sign more than one identical document within
|
2002-06-29 15:46:34 +02:00
|
|
|
* one second. Some remote batch processing applications might
|
1999-03-02 10:41:49 +01:00
|
|
|
* like this feature here */
|
2002-06-29 15:46:34 +02:00
|
|
|
MD_HANDLE md;
|
1999-03-02 10:41:49 +01:00
|
|
|
u32 a = sig->timestamp;
|
1999-02-26 17:59:48 +01:00
|
|
|
int i, nsig = pubkey_get_nsig( sig->pubkey_algo );
|
1999-03-08 20:50:18 +01:00
|
|
|
byte *p, *buffer;
|
1999-02-26 17:59:48 +01:00
|
|
|
|
2002-06-29 15:46:34 +02:00
|
|
|
md = md_open( DIGEST_ALGO_RMD160, 0);
|
|
|
|
md_putc( digest, sig->pubkey_algo );
|
|
|
|
md_putc( digest, sig->digest_algo );
|
|
|
|
md_putc( digest, (a >> 24) & 0xff );
|
|
|
|
md_putc( digest, (a >> 16) & 0xff );
|
|
|
|
md_putc( digest, (a >> 8) & 0xff );
|
|
|
|
md_putc( digest, a & 0xff );
|
1999-02-26 17:59:48 +01:00
|
|
|
for(i=0; i < nsig; i++ ) {
|
2002-06-29 15:46:34 +02:00
|
|
|
unsigned n = mpi_get_nbits( sig->data[i]);
|
|
|
|
|
|
|
|
md_putc( md, n>>8);
|
|
|
|
md_putc( md, n );
|
|
|
|
p = mpi_get_buffer( sig->data[i], &n, NULL );
|
|
|
|
md_write( md, p, n );
|
|
|
|
m_free(p);
|
1999-02-26 17:59:48 +01:00
|
|
|
}
|
2002-06-29 15:46:34 +02:00
|
|
|
md_final( md );
|
|
|
|
p = make_radix64_string( md_read( md, 0 ), 20 );
|
|
|
|
buffer = m_alloc( strlen(p) + 60 );
|
1999-05-22 22:54:54 +02:00
|
|
|
sprintf( buffer, "%s %s %lu",
|
|
|
|
p, strtimestamp( sig->timestamp ), (ulong)sig->timestamp );
|
1999-03-08 20:50:18 +01:00
|
|
|
write_status_text( STATUS_SIG_ID, buffer );
|
2002-06-29 15:46:34 +02:00
|
|
|
m_free(buffer);
|
|
|
|
m_free(p);
|
|
|
|
md_close(md);
|
1999-02-26 17:59:48 +01:00
|
|
|
}
|
|
|
|
|
1998-02-16 21:05:02 +01:00
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
2003-08-13 05:31:36 +02:00
|
|
|
do_check_messages( PKT_public_key *pk, PKT_signature *sig,
|
|
|
|
int *r_expired, int *r_revoked )
|
1998-02-16 21:05:02 +01:00
|
|
|
{
|
1998-06-25 12:19:08 +02:00
|
|
|
u32 cur_time;
|
1997-11-18 15:06:00 +01:00
|
|
|
|
2003-07-22 01:19:15 +02:00
|
|
|
if(r_expired)
|
|
|
|
*r_expired = 0;
|
2003-08-13 05:31:36 +02:00
|
|
|
if(r_revoked)
|
|
|
|
*r_revoked = 0;
|
2002-06-29 15:46:34 +02:00
|
|
|
if( pk->version == 4 && pk->pubkey_algo == PUBKEY_ALGO_ELGAMAL_E ) {
|
2002-08-28 21:34:58 +02:00
|
|
|
log_info(_("key %08lX: this is a PGP generated "
|
|
|
|
"ElGamal key which is NOT secure for signatures!\n"),
|
|
|
|
(ulong)keyid_from_pk(pk,NULL));
|
2002-06-29 15:46:34 +02:00
|
|
|
return G10ERR_PUBKEY_ALGO;
|
1998-05-04 20:49:26 +02:00
|
|
|
}
|
1998-03-19 16:27:29 +01:00
|
|
|
|
1999-01-12 11:20:24 +01:00
|
|
|
if( pk->timestamp > sig->timestamp ) {
|
|
|
|
ulong d = pk->timestamp - sig->timestamp;
|
|
|
|
log_info( d==1
|
2002-08-28 21:34:58 +02:00
|
|
|
? _("public key %08lX is %lu second newer than the signature\n")
|
|
|
|
: _("public key %08lX is %lu seconds newer than the signature\n"),
|
|
|
|
(ulong)keyid_from_pk(pk,NULL),d );
|
2000-07-14 19:34:53 +02:00
|
|
|
if( !opt.ignore_time_conflict )
|
2002-06-29 15:46:34 +02:00
|
|
|
return G10ERR_TIME_CONFLICT; /* pubkey newer than signature */
|
1999-01-12 11:20:24 +01:00
|
|
|
}
|
1998-03-19 16:27:29 +01:00
|
|
|
|
1998-06-25 12:19:08 +02:00
|
|
|
cur_time = make_timestamp();
|
1998-06-29 14:30:57 +02:00
|
|
|
if( pk->timestamp > cur_time ) {
|
1999-01-09 16:06:59 +01:00
|
|
|
ulong d = pk->timestamp - cur_time;
|
2002-08-28 21:34:58 +02:00
|
|
|
log_info( d==1 ? _("key %08lX has been created %lu second "
|
1999-01-12 11:20:24 +01:00
|
|
|
"in future (time warp or clock problem)\n")
|
2002-08-28 21:34:58 +02:00
|
|
|
: _("key %08lX has been created %lu seconds "
|
|
|
|
"in future (time warp or clock problem)\n"),
|
|
|
|
(ulong)keyid_from_pk(pk,NULL),d );
|
2000-07-14 19:34:53 +02:00
|
|
|
if( !opt.ignore_time_conflict )
|
2002-06-29 15:46:34 +02:00
|
|
|
return G10ERR_TIME_CONFLICT;
|
1998-06-25 12:19:08 +02:00
|
|
|
}
|
|
|
|
|
1998-10-16 18:00:17 +02:00
|
|
|
if( pk->expiredate && pk->expiredate < cur_time ) {
|
2002-06-29 15:46:34 +02:00
|
|
|
char buf[11];
|
|
|
|
if (opt.verbose) {
|
|
|
|
u32 tmp_kid[2];
|
|
|
|
|
|
|
|
keyid_from_pk( pk, tmp_kid );
|
|
|
|
log_info(_("NOTE: signature key %08lX expired %s\n"),
|
|
|
|
(ulong)tmp_kid[1], asctimestamp( pk->expiredate ) );
|
|
|
|
}
|
|
|
|
/* SIGEXPIRED is deprecated. Use KEYEXPIRED. */
|
|
|
|
sprintf(buf,"%lu",(ulong)pk->expiredate);
|
|
|
|
write_status_text(STATUS_KEYEXPIRED,buf);
|
1998-06-25 12:19:08 +02:00
|
|
|
write_status(STATUS_SIGEXPIRED);
|
2003-07-22 01:19:15 +02:00
|
|
|
if(r_expired)
|
|
|
|
*r_expired = 1;
|
1998-06-25 12:19:08 +02:00
|
|
|
}
|
|
|
|
|
2003-08-13 05:31:36 +02:00
|
|
|
if(pk->is_revoked && r_revoked)
|
|
|
|
*r_revoked=1;
|
|
|
|
|
2002-08-23 22:59:48 +02:00
|
|
|
return 0;
|
|
|
|
}
|
1998-06-25 12:19:08 +02:00
|
|
|
|
2002-08-23 22:59:48 +02:00
|
|
|
|
|
|
|
static int
|
|
|
|
do_check( PKT_public_key *pk, PKT_signature *sig, MD_HANDLE digest,
|
2003-08-13 05:31:36 +02:00
|
|
|
int *r_expired, int *r_revoked, PKT_public_key *ret_pk )
|
2002-08-23 22:59:48 +02:00
|
|
|
{
|
|
|
|
MPI result = NULL;
|
|
|
|
int rc=0;
|
|
|
|
struct cmp_help_context_s ctx;
|
|
|
|
|
2003-08-13 05:31:36 +02:00
|
|
|
if( (rc=do_check_messages(pk,sig,r_expired,r_revoked)) )
|
2002-08-23 22:59:48 +02:00
|
|
|
return rc;
|
1998-06-15 17:41:04 +02:00
|
|
|
|
|
|
|
/* make sure the digest algo is enabled (in case of a detached signature)*/
|
2002-06-29 15:46:34 +02:00
|
|
|
md_enable( digest, sig->digest_algo );
|
1998-06-15 17:41:04 +02:00
|
|
|
|
|
|
|
/* complete the digest */
|
|
|
|
if( sig->version >= 4 )
|
2002-06-29 15:46:34 +02:00
|
|
|
md_putc( digest, sig->version );
|
|
|
|
md_putc( digest, sig->sig_class );
|
1998-06-15 17:41:04 +02:00
|
|
|
if( sig->version < 4 ) {
|
|
|
|
u32 a = sig->timestamp;
|
2002-06-29 15:46:34 +02:00
|
|
|
md_putc( digest, (a >> 24) & 0xff );
|
|
|
|
md_putc( digest, (a >> 16) & 0xff );
|
|
|
|
md_putc( digest, (a >> 8) & 0xff );
|
|
|
|
md_putc( digest, a & 0xff );
|
1998-03-09 22:44:06 +01:00
|
|
|
}
|
1997-11-18 15:06:00 +01:00
|
|
|
else {
|
1998-06-15 17:41:04 +02:00
|
|
|
byte buf[6];
|
|
|
|
size_t n;
|
2002-06-29 15:46:34 +02:00
|
|
|
md_putc( digest, sig->pubkey_algo );
|
|
|
|
md_putc( digest, sig->digest_algo );
|
|
|
|
if( sig->hashed ) {
|
|
|
|
n = sig->hashed->len;
|
|
|
|
md_putc (digest, (n >> 8) );
|
|
|
|
md_putc (digest, n );
|
|
|
|
md_write (digest, sig->hashed->data, n);
|
1998-06-15 17:41:04 +02:00
|
|
|
n += 6;
|
|
|
|
}
|
2002-07-29 05:07:11 +02:00
|
|
|
else {
|
|
|
|
/* Two octets for the (empty) length of the hashed
|
|
|
|
section. */
|
|
|
|
md_putc (digest, 0);
|
|
|
|
md_putc (digest, 0);
|
|
|
|
n = 6;
|
|
|
|
}
|
1998-06-15 17:41:04 +02:00
|
|
|
/* add some magic */
|
|
|
|
buf[0] = sig->version;
|
|
|
|
buf[1] = 0xff;
|
|
|
|
buf[2] = n >> 24;
|
|
|
|
buf[3] = n >> 16;
|
|
|
|
buf[4] = n >> 8;
|
|
|
|
buf[5] = n;
|
2002-06-29 15:46:34 +02:00
|
|
|
md_write( digest, buf, 6 );
|
1997-11-18 15:06:00 +01:00
|
|
|
}
|
2002-06-29 15:46:34 +02:00
|
|
|
md_final( digest );
|
1998-06-15 17:41:04 +02:00
|
|
|
|
1998-06-29 14:30:57 +02:00
|
|
|
result = encode_md_value( pk->pubkey_algo, digest, sig->digest_algo,
|
2003-12-04 05:34:08 +01:00
|
|
|
mpi_get_nbits(pk->pkey[0]) );
|
2002-06-29 15:46:34 +02:00
|
|
|
if (!result)
|
|
|
|
return G10ERR_GENERAL;
|
1998-06-15 17:41:04 +02:00
|
|
|
ctx.sig = sig;
|
|
|
|
ctx.md = digest;
|
2003-12-17 20:21:41 +01:00
|
|
|
rc = pubkey_verify( pk->pubkey_algo, result, sig->data, pk->pkey );
|
2002-06-29 15:46:34 +02:00
|
|
|
mpi_free( result );
|
2000-07-14 19:34:53 +02:00
|
|
|
|
1998-12-14 21:22:42 +01:00
|
|
|
if( !rc && sig->flags.unknown_critical ) {
|
2002-08-28 21:34:58 +02:00
|
|
|
log_info(_("assuming bad signature from key %08lX due to an unknown critical bit\n"),(ulong)keyid_from_pk(pk,NULL));
|
2002-06-29 15:46:34 +02:00
|
|
|
rc = G10ERR_BAD_SIGN;
|
1998-12-14 21:22:42 +01:00
|
|
|
}
|
1998-06-15 17:41:04 +02:00
|
|
|
|
2003-07-20 02:10:13 +02:00
|
|
|
if(!rc && ret_pk)
|
|
|
|
copy_public_key(ret_pk,pk);
|
|
|
|
|
1997-11-18 15:06:00 +01:00
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
1997-12-09 13:46:23 +01:00
|
|
|
|
1998-04-25 10:08:35 +02:00
|
|
|
static void
|
2002-06-29 15:46:34 +02:00
|
|
|
hash_uid_node( KBNODE unode, MD_HANDLE md, PKT_signature *sig )
|
1998-04-25 10:08:35 +02:00
|
|
|
{
|
|
|
|
PKT_user_id *uid = unode->pkt->pkt.user_id;
|
|
|
|
|
|
|
|
assert( unode->pkt->pkttype == PKT_USER_ID );
|
2002-06-29 15:46:34 +02:00
|
|
|
if( uid->attrib_data ) {
|
2000-07-14 19:34:53 +02:00
|
|
|
if( sig->version >=4 ) {
|
|
|
|
byte buf[5];
|
2002-06-29 15:46:34 +02:00
|
|
|
buf[0] = 0xd1; /* packet of type 17 */
|
|
|
|
buf[1] = uid->attrib_len >> 24; /* always use 4 length bytes */
|
|
|
|
buf[2] = uid->attrib_len >> 16;
|
|
|
|
buf[3] = uid->attrib_len >> 8;
|
|
|
|
buf[4] = uid->attrib_len;
|
|
|
|
md_write( md, buf, 5 );
|
2000-07-14 19:34:53 +02:00
|
|
|
}
|
2002-06-29 15:46:34 +02:00
|
|
|
md_write( md, uid->attrib_data, uid->attrib_len );
|
2000-07-14 19:34:53 +02:00
|
|
|
}
|
|
|
|
else {
|
|
|
|
if( sig->version >=4 ) {
|
|
|
|
byte buf[5];
|
|
|
|
buf[0] = 0xb4; /* indicates a userid packet */
|
|
|
|
buf[1] = uid->len >> 24; /* always use 4 length bytes */
|
|
|
|
buf[2] = uid->len >> 16;
|
|
|
|
buf[3] = uid->len >> 8;
|
|
|
|
buf[4] = uid->len;
|
2002-06-29 15:46:34 +02:00
|
|
|
md_write( md, buf, 5 );
|
2000-07-14 19:34:53 +02:00
|
|
|
}
|
2002-06-29 15:46:34 +02:00
|
|
|
md_write( md, uid->name, uid->len );
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
static void
|
|
|
|
cache_sig_result ( PKT_signature *sig, int result )
|
|
|
|
{
|
|
|
|
if ( !result ) {
|
|
|
|
sig->flags.checked = 1;
|
|
|
|
sig->flags.valid = 1;
|
|
|
|
}
|
|
|
|
else if ( result == G10ERR_BAD_SIGN ) {
|
|
|
|
sig->flags.checked = 1;
|
|
|
|
sig->flags.valid = 0;
|
|
|
|
}
|
|
|
|
else {
|
|
|
|
sig->flags.checked = 0;
|
|
|
|
sig->flags.valid = 0;
|
1998-04-25 10:08:35 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2002-09-13 14:59:31 +02:00
|
|
|
|
|
|
|
/* Check the revocation keys to see if any of them have revoked our
|
|
|
|
pk. sig is the revocation sig. pk is the key it is on. This code
|
|
|
|
will need to be modified if gpg ever becomes multi-threaded. Note
|
|
|
|
that this guarantees that a designated revocation sig will never be
|
|
|
|
considered valid unless it is actually valid, as well as being
|
|
|
|
issued by a revocation key in a valid direct signature. Note that
|
|
|
|
this is written so that a revoked revoker can still issue
|
|
|
|
revocations: i.e. If A revokes B, but A is revoked, B is still
|
|
|
|
revoked. I'm not completely convinced this is the proper behavior,
|
|
|
|
but it matches how PGP does it. -dms */
|
|
|
|
|
|
|
|
/* Returns 0 if sig is valid (i.e. pk is revoked), non-0 if not
|
|
|
|
revoked */
|
|
|
|
int
|
|
|
|
check_revocation_keys(PKT_public_key *pk,PKT_signature *sig)
|
|
|
|
{
|
|
|
|
static int busy=0;
|
|
|
|
int i,rc=G10ERR_GENERAL;
|
|
|
|
|
|
|
|
assert(IS_KEY_REV(sig));
|
|
|
|
assert((sig->keyid[0]!=pk->keyid[0]) || (sig->keyid[0]!=pk->keyid[1]));
|
|
|
|
|
|
|
|
if(busy)
|
|
|
|
{
|
|
|
|
/* return -1 (i.e. not revoked), but mark the pk as uncacheable
|
|
|
|
as we don't really know its revocation status until it is
|
|
|
|
checked directly. */
|
|
|
|
|
|
|
|
pk->dont_cache=1;
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
busy=1;
|
|
|
|
|
|
|
|
/* printf("looking at %08lX with a sig from %08lX\n",(ulong)pk->keyid[1],
|
|
|
|
(ulong)sig->keyid[1]); */
|
|
|
|
|
|
|
|
/* is the issuer of the sig one of our revokers? */
|
|
|
|
if( !pk->revkey && pk->numrevkeys )
|
|
|
|
BUG();
|
|
|
|
else
|
|
|
|
for(i=0;i<pk->numrevkeys;i++)
|
|
|
|
{
|
|
|
|
u32 keyid[2];
|
|
|
|
|
|
|
|
keyid_from_fingerprint(pk->revkey[i].fpr,MAX_FINGERPRINT_LEN,keyid);
|
|
|
|
|
|
|
|
if(keyid[0]==sig->keyid[0] && keyid[1]==sig->keyid[1])
|
|
|
|
{
|
|
|
|
MD_HANDLE md;
|
|
|
|
|
|
|
|
md=md_open(sig->digest_algo,0);
|
|
|
|
hash_public_key(md,pk);
|
|
|
|
rc=signature_check(sig,md);
|
|
|
|
cache_sig_result(sig,rc);
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
busy=0;
|
|
|
|
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
1997-12-19 12:41:47 +01:00
|
|
|
/****************
|
1998-04-14 19:51:16 +02:00
|
|
|
* check the signature pointed to by NODE. This is a key signature.
|
1998-06-29 14:30:57 +02:00
|
|
|
* If the function detects a self-signature, it uses the PK from
|
1998-07-15 20:05:01 +02:00
|
|
|
* ROOT and does not read any public key.
|
1997-12-19 12:41:47 +01:00
|
|
|
*/
|
|
|
|
int
|
1998-01-16 22:15:24 +01:00
|
|
|
check_key_signature( KBNODE root, KBNODE node, int *is_selfsig )
|
1999-07-02 11:50:57 +02:00
|
|
|
{
|
2003-07-22 01:19:15 +02:00
|
|
|
return check_key_signature2(root, node, NULL, NULL, is_selfsig, NULL, NULL );
|
1999-07-02 11:50:57 +02:00
|
|
|
}
|
|
|
|
|
2002-12-29 16:58:44 +01:00
|
|
|
/* If check_pk is set, then use it to check the signature in node
|
2003-07-20 02:10:13 +02:00
|
|
|
rather than getting it from root or the keydb. If ret_pk is set,
|
|
|
|
fill in the public key that was used to verify the signature.
|
|
|
|
ret_pk is only meaningful when the verification was successful. */
|
2003-08-13 05:31:36 +02:00
|
|
|
/* TODO: add r_revoked here as well. It has the same problems as
|
|
|
|
r_expiredate and r_expired and the cache. */
|
1999-07-02 11:50:57 +02:00
|
|
|
int
|
2002-12-29 16:58:44 +01:00
|
|
|
check_key_signature2( KBNODE root, KBNODE node, PKT_public_key *check_pk,
|
2003-07-20 02:10:13 +02:00
|
|
|
PKT_public_key *ret_pk, int *is_selfsig,
|
|
|
|
u32 *r_expiredate, int *r_expired )
|
1997-12-19 12:41:47 +01:00
|
|
|
{
|
2002-06-29 15:46:34 +02:00
|
|
|
MD_HANDLE md;
|
1998-06-29 14:30:57 +02:00
|
|
|
PKT_public_key *pk;
|
1997-12-20 18:23:29 +01:00
|
|
|
PKT_signature *sig;
|
|
|
|
int algo;
|
|
|
|
int rc;
|
|
|
|
|
1998-01-16 22:15:24 +01:00
|
|
|
if( is_selfsig )
|
|
|
|
*is_selfsig = 0;
|
2003-07-22 01:19:15 +02:00
|
|
|
if( r_expiredate )
|
|
|
|
*r_expiredate = 0;
|
|
|
|
if( r_expired )
|
|
|
|
*r_expired = 0;
|
1997-12-19 12:41:47 +01:00
|
|
|
assert( node->pkt->pkttype == PKT_SIGNATURE );
|
1998-06-29 14:30:57 +02:00
|
|
|
assert( root->pkt->pkttype == PKT_PUBLIC_KEY );
|
1997-12-19 12:41:47 +01:00
|
|
|
|
1998-06-29 14:30:57 +02:00
|
|
|
pk = root->pkt->pkt.public_key;
|
1997-12-20 18:23:29 +01:00
|
|
|
sig = node->pkt->pkt.signature;
|
1998-04-25 10:08:35 +02:00
|
|
|
algo = sig->digest_algo;
|
1999-07-01 12:53:35 +02:00
|
|
|
|
2002-06-29 15:46:34 +02:00
|
|
|
/* check whether we have cached the result of a previous signature check.*/
|
|
|
|
if ( !opt.no_sig_cache ) {
|
|
|
|
if (sig->flags.checked) { /*cached status available*/
|
|
|
|
if( is_selfsig ) {
|
|
|
|
u32 keyid[2];
|
|
|
|
|
|
|
|
keyid_from_pk( pk, keyid );
|
|
|
|
if( keyid[0] == sig->keyid[0] && keyid[1] == sig->keyid[1] )
|
|
|
|
*is_selfsig = 1;
|
|
|
|
}
|
2003-08-13 05:31:36 +02:00
|
|
|
/* BUG: This is wrong for non-self-sigs.. needs to be the
|
|
|
|
actual pk */
|
|
|
|
if((rc=do_check_messages(pk,sig,r_expired,NULL)))
|
2002-08-23 22:59:48 +02:00
|
|
|
return rc;
|
2002-06-29 15:46:34 +02:00
|
|
|
return sig->flags.valid? 0 : G10ERR_BAD_SIGN;
|
|
|
|
}
|
2000-09-18 16:35:34 +02:00
|
|
|
}
|
1999-07-01 12:53:35 +02:00
|
|
|
|
2003-12-13 04:53:27 +01:00
|
|
|
if( (rc=check_pubkey_algo(sig->pubkey_algo)) )
|
|
|
|
return rc;
|
2002-06-29 15:46:34 +02:00
|
|
|
if( (rc=check_digest_algo(algo)) )
|
1997-12-20 18:23:29 +01:00
|
|
|
return rc;
|
|
|
|
|
2002-06-29 15:46:34 +02:00
|
|
|
if( sig->sig_class == 0x20 ) { /* key revocation */
|
2002-09-28 19:49:38 +02:00
|
|
|
u32 keyid[2];
|
|
|
|
keyid_from_pk( pk, keyid );
|
|
|
|
|
|
|
|
/* is it a designated revoker? */
|
|
|
|
if(keyid[0]!=sig->keyid[0] || keyid[1]!=sig->keyid[1])
|
2002-09-13 14:59:31 +02:00
|
|
|
rc=check_revocation_keys(pk,sig);
|
|
|
|
else
|
|
|
|
{
|
|
|
|
md = md_open( algo, 0 );
|
|
|
|
hash_public_key( md, pk );
|
2003-08-13 05:31:36 +02:00
|
|
|
rc = do_check( pk, sig, md, r_expired, NULL, ret_pk );
|
2002-09-13 14:59:31 +02:00
|
|
|
cache_sig_result ( sig, rc );
|
|
|
|
md_close(md);
|
|
|
|
}
|
1997-12-20 18:23:29 +01:00
|
|
|
}
|
1998-11-03 20:38:58 +01:00
|
|
|
else if( sig->sig_class == 0x28 ) { /* subkey revocation */
|
|
|
|
KBNODE snode = find_prev_kbnode( root, node, PKT_PUBLIC_SUBKEY );
|
|
|
|
|
|
|
|
if( snode ) {
|
2002-06-29 15:46:34 +02:00
|
|
|
md = md_open( algo, 0 );
|
1998-11-03 20:38:58 +01:00
|
|
|
hash_public_key( md, pk );
|
|
|
|
hash_public_key( md, snode->pkt->pkt.public_key );
|
2003-08-13 05:31:36 +02:00
|
|
|
rc = do_check( pk, sig, md, r_expired, NULL, ret_pk );
|
2002-06-29 15:46:34 +02:00
|
|
|
cache_sig_result ( sig, rc );
|
|
|
|
md_close(md);
|
1998-11-03 20:38:58 +01:00
|
|
|
}
|
|
|
|
else {
|
* gpgv.c: Remove extra semicolon (typo).
* options.skel: Note that keyserver.pgp.com isn't synchronized, and
explain the roundrobin a bit better.
* sig-check.c (check_key_signature2), import.c (import_one,
import_revoke_cert, chk_self_sigs, delete_inv_parts, collapse_uids,
merge_blocks): Make much quieter during import of slightly munged, but
recoverable, keys. Use log_error for unrecoverable import failures.
* keyring.c (keyring_rebuild_cache): Comment.
* sign.c (mk_notation_and_policy): Making a v3 signature with notations or
policy urls is an error, not an info (i.e. increment the errorcount).
Don't print the notation or policy url to stdout since it can be mixed
into the output stream when piping and munge the stream.
2003-08-22 01:20:58 +02:00
|
|
|
if (opt.verbose)
|
2002-09-17 05:21:13 +02:00
|
|
|
log_info (_("key %08lX: no subkey for subkey "
|
2002-09-24 23:20:48 +02:00
|
|
|
"revocation signature\n"),
|
2002-06-29 15:46:34 +02:00
|
|
|
(ulong)keyid_from_pk (pk, NULL));
|
|
|
|
rc = G10ERR_SIG_CLASS;
|
1998-11-03 20:38:58 +01:00
|
|
|
}
|
|
|
|
}
|
2002-06-29 15:46:34 +02:00
|
|
|
else if( sig->sig_class == 0x18 ) { /* key binding */
|
1998-06-29 14:30:57 +02:00
|
|
|
KBNODE snode = find_prev_kbnode( root, node, PKT_PUBLIC_SUBKEY );
|
1998-04-02 12:30:03 +02:00
|
|
|
|
|
|
|
if( snode ) {
|
1998-11-03 20:38:58 +01:00
|
|
|
if( is_selfsig ) { /* does this make sense????? */
|
|
|
|
u32 keyid[2]; /* it should always be a selfsig */
|
1998-05-29 13:53:54 +02:00
|
|
|
|
1998-06-29 14:30:57 +02:00
|
|
|
keyid_from_pk( pk, keyid );
|
1998-05-29 13:53:54 +02:00
|
|
|
if( keyid[0] == sig->keyid[0] && keyid[1] == sig->keyid[1] )
|
|
|
|
*is_selfsig = 1;
|
|
|
|
}
|
2002-06-29 15:46:34 +02:00
|
|
|
md = md_open( algo, 0 );
|
1998-06-29 14:30:57 +02:00
|
|
|
hash_public_key( md, pk );
|
|
|
|
hash_public_key( md, snode->pkt->pkt.public_key );
|
2003-08-13 05:31:36 +02:00
|
|
|
rc = do_check( pk, sig, md, r_expired, NULL, ret_pk );
|
2002-06-29 15:46:34 +02:00
|
|
|
cache_sig_result ( sig, rc );
|
|
|
|
md_close(md);
|
1998-04-02 12:30:03 +02:00
|
|
|
}
|
|
|
|
else {
|
2003-05-26 15:21:12 +02:00
|
|
|
if (opt.verbose)
|
2003-05-31 06:06:06 +02:00
|
|
|
log_info(_("key %08lX: no subkey for subkey "
|
|
|
|
"binding signature\n"),
|
|
|
|
(ulong)keyid_from_pk (pk, NULL));
|
2002-06-29 15:46:34 +02:00
|
|
|
rc = G10ERR_SIG_CLASS;
|
1998-04-02 12:30:03 +02:00
|
|
|
}
|
|
|
|
}
|
2002-06-29 15:46:34 +02:00
|
|
|
else if( sig->sig_class == 0x1f ) { /* direct key signature */
|
|
|
|
md = md_open( algo, 0 );
|
|
|
|
hash_public_key( md, pk );
|
2003-08-13 05:31:36 +02:00
|
|
|
rc = do_check( pk, sig, md, r_expired, NULL, ret_pk );
|
2002-06-29 15:46:34 +02:00
|
|
|
cache_sig_result ( sig, rc );
|
|
|
|
md_close(md);
|
|
|
|
}
|
|
|
|
else { /* all other classes */
|
1998-04-02 12:30:03 +02:00
|
|
|
KBNODE unode = find_prev_kbnode( root, node, PKT_USER_ID );
|
1998-02-18 14:58:46 +01:00
|
|
|
|
|
|
|
if( unode ) {
|
|
|
|
u32 keyid[2];
|
|
|
|
|
1998-06-29 14:30:57 +02:00
|
|
|
keyid_from_pk( pk, keyid );
|
2002-06-29 15:46:34 +02:00
|
|
|
md = md_open( algo, 0 );
|
1998-06-29 14:30:57 +02:00
|
|
|
hash_public_key( md, pk );
|
1998-04-25 10:08:35 +02:00
|
|
|
hash_uid_node( unode, md, sig );
|
2002-12-29 16:58:44 +01:00
|
|
|
if( keyid[0] == sig->keyid[0] && keyid[1] == sig->keyid[1] )
|
|
|
|
{
|
1998-02-18 14:58:46 +01:00
|
|
|
if( is_selfsig )
|
2002-12-29 16:58:44 +01:00
|
|
|
*is_selfsig = 1;
|
2003-08-13 05:31:36 +02:00
|
|
|
rc = do_check( pk, sig, md, r_expired, NULL, ret_pk );
|
2002-12-29 16:58:44 +01:00
|
|
|
}
|
|
|
|
else if (check_pk)
|
2003-08-13 05:31:36 +02:00
|
|
|
rc=do_check(check_pk,sig,md,r_expired,NULL,ret_pk);
|
2002-12-29 16:58:44 +01:00
|
|
|
else
|
2003-08-13 05:31:36 +02:00
|
|
|
rc=signature_check2(sig,md,r_expiredate,r_expired,NULL,ret_pk);
|
2002-12-29 16:58:44 +01:00
|
|
|
|
2002-06-29 15:46:34 +02:00
|
|
|
cache_sig_result ( sig, rc );
|
|
|
|
md_close(md);
|
1998-02-18 14:58:46 +01:00
|
|
|
}
|
|
|
|
else {
|
2002-06-29 15:46:34 +02:00
|
|
|
if (!opt.quiet)
|
|
|
|
log_info ("key %08lX: no user ID for key signature packet "
|
|
|
|
"of class %02x\n",
|
|
|
|
(ulong)keyid_from_pk (pk, NULL), sig->sig_class );
|
|
|
|
rc = G10ERR_SIG_CLASS;
|
1998-02-18 14:58:46 +01:00
|
|
|
}
|
1997-12-20 18:23:29 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
return rc;
|
1997-12-19 12:41:47 +01:00
|
|
|
}
|