yubikeyfinder.cpp 9.27 KB
Newer Older
1
/*
2
Copyright (C) 2011-2014 Yubico AB.  All rights reserved.
3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26

Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions are
met:

   1. Redistributions of source code must retain the above copyright
      notice, this list of conditions and the following disclaimer.

   2. Redistributions in binary form must reproduce the above
      copyright notice, this list of conditions and the following
      disclaimer in the documentation and/or other materials provided
      with the distribution.

THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
27 28 29 30
 */

#include "yubikeyfinder.h"

31 32 33
#include <ykcore.h>
#include <ykdef.h>

34
#include <QApplication>
35
#include <QDebug>
36

37 38
YubiKeyFinder* YubiKeyFinder::_instance = 0;

39
// first version is inclusive, second is exclusive
40 41 42 43 44 45 46 47 48
const unsigned int YubiKeyFinder::FEATURE_MATRIX[][2] = {
    { YK_VERSION(2,0,0), 0 },   //Feature_MultipleConfigurations
    { YK_VERSION(2,0,0), 0 },   //Feature_ProtectConfiguration2
    { YK_VERSION(1,3,0), 0 },   //Feature_StaticPassword
    { YK_VERSION(2,0,0), 0 },   //Feature_ScanCodeMode
    { YK_VERSION(2,0,0), 0 },   //Feature_ShortTicket
    { YK_VERSION(2,0,0), 0 },   //Feature_StrongPwd
    { YK_VERSION(2,1,0), 0 },   //Feature_OathHotp
    { YK_VERSION(2,2,0), 0 },   //Feature_ChallengeResponse
49 50 51 52
    { YK_VERSION(2,1,4), 0 },   //Feature_SerialNumber
    { YK_VERSION(2,1,7), 0 },   //Feature_MovingFactor
    { YK_VERSION(2,3,0), 0 },   //Feature_ChallengeResponseFixed
    { YK_VERSION(2,3,0), 0 },   //Feature_Updatable
53
    { YK_VERSION(2,1,4), 0 },   //Feature_Ndef
54
    { YK_VERSION(2,4,0), 0 },   //Feature_LedInvert
55
    { YK_VERSION(3,3,0), 0 },   //Feature_U2F
56 57 58
};

// when a featureset should be excluded from versions (NEO, I'm looking at you.)
59 60 61 62 63 64 65 66 67 68 69 70 71
const unsigned int YubiKeyFinder::FEATURE_MATRIX_EXCLUDE[][4] = {
    { YK_VERSION(2,1,4), YK_VERSION(2,2,0), 0, 0 }, //Feature_MultipleConfigurations
    { YK_VERSION(2,1,4), YK_VERSION(2,2,0), 0, 0 }, //Feature_ProtectConfiguration2
    { YK_VERSION(2,1,4), YK_VERSION(2,1,8), 0, 0 }, //Feature_StaticPassword
    { YK_VERSION(2,1,4), YK_VERSION(2,1,8), 0, 0 }, //Feature_ScanCodeMode
    { 0, 0, 0, 0 },                                 //Feature_ShortTicket
    { YK_VERSION(2,1,4), YK_VERSION(2,1,8), 0, 0 }, //Feature_StrongPwd
    { 0, 0, 0, 0 },                                 //Feature_OathHotp
    { 0, 0, 0, 0 },                                 //Feature_ChallengeResponse
    { 0, 0, 0, 0 },                                 //Feature_SerialNumber
    { 0, 0, 0, 0 },                                 //Feature_MovingFactor
    { 0, 0, 0, 0 },                                 //Feature_ChallengeResponseFixed
    { 0, 0, 0, 0 },                                 //Feature_Updatable
72
    { YK_VERSION(2,2,0), YK_VERSION(3,0,0), YK_VERSION(4,0,0), YK_VERSION(4,9,0) }, //Feature_Ndef
73 74
    { YK_VERSION(3,0,0), YK_VERSION(3,1,0), 0, 0 }, //Feature_LedInvert
    { 0, 0, 0, 0 },                                 //Feature_U2F
75 76 77
};

YubiKeyFinder::YubiKeyFinder() {
78 79 80
    // init the ykpers library
    yk_init();

81 82 83 84 85 86 87 88 89 90
    //Initialize fields
    init();

    //Create timer
    m_timer = new QTimer( this );
    connect(m_timer, SIGNAL(timeout()),
            this, SLOT(findKey()));
}

YubiKeyFinder::~YubiKeyFinder() {
91
    yk_release();
92 93 94 95 96 97 98 99 100

    if(m_timer != 0) {
        delete m_timer;
        m_timer = 0;
    }

    if(_instance) {
        delete _instance;
    }
101 102 103 104

    if(m_ykds) {
      ykds_free(m_ykds);
    }
105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126
}

YubiKeyFinder* YubiKeyFinder::getInstance() {
    if(_instance == NULL) {
        _instance = new YubiKeyFinder();
    }
    return _instance;
}

QString YubiKeyFinder::versionStr() {
    if(m_version > 0) {
        return tr("%1.%2.%3").
                arg(m_versionMajor).
                arg(m_versionMinor).
                arg(m_versionBuild);
    }
    return "";
}

bool YubiKeyFinder::checkFeatureSupport(Feature feature) {
    if(m_version > 0 &&
       (unsigned int) feature < sizeof(FEATURE_MATRIX)/sizeof(FEATURE_MATRIX[0])) {
127
        bool supported = (
128
                m_version >= FEATURE_MATRIX[feature][0] &&
129
                (FEATURE_MATRIX[feature][1] == 0 || m_version < FEATURE_MATRIX[feature][1])
130
                );
131
        if(supported) {
132 133 134 135
            if(FEATURE_MATRIX_EXCLUDE[feature][0] != 0)
                if(m_version >= FEATURE_MATRIX_EXCLUDE[feature][0])
                    if(m_version < FEATURE_MATRIX_EXCLUDE[feature][1])
                        return false;
136 137 138 139 140 141
            if(FEATURE_MATRIX_EXCLUDE[feature][2] != 0)
                if(m_version >= FEATURE_MATRIX_EXCLUDE[feature][2])
                    if(m_version < FEATURE_MATRIX_EXCLUDE[feature][3])
                        return false;
        }

142
        return supported;
143 144 145 146 147 148 149 150 151 152 153 154
    }
    return false;
}

void YubiKeyFinder::init() {
    m_state = State_Absent;
    m_yk = 0;
    m_version = 0;
    m_versionMajor = 0;
    m_versionMinor = 0;
    m_versionBuild = 0;
    m_serial = 0;
155
    m_touchLevel = 0;
156 157

    m_ykds = ykds_alloc();
158 159 160 161
}

void YubiKeyFinder::start() {
    //Start timer
162
    init();
163 164 165 166 167 168 169 170 171
    if(m_timer && !m_timer->isActive()) {
        m_timer->start(TIMEOUT_FINDER);
    }
}

void YubiKeyFinder::stop() {
    //Stop timer
    if(m_timer && m_timer->isActive()) {
        m_timer->stop();
172 173 174 175
        // doing closeKey() here might look out of place and may cause findKey()
        // to fail unexpectedly, but it's needed to not leak file descriptors
        // when writing the key.
        closeKey();
176 177 178 179 180
    }
}

bool YubiKeyFinder::openKey() {
    bool flag = true;
181
    if (!(m_yk = yk_open_first_key())) {
182 183 184 185 186 187 188 189 190 191 192 193
        flag = false;
    }

    return flag;
}

bool YubiKeyFinder::closeKey() {
    bool flag = true;
    if(m_yk != 0) {
        if (!yk_close_key(m_yk)) {
            flag = false;
        }
194
        m_yk = 0;
195 196 197 198 199 200
    }

    return flag;
}

void YubiKeyFinder::findKey() {
201 202
    if(QApplication::activeWindow() == 0) {
        //No focus, avoid locking the YubiKey.
203
        m_state = State_NoFocus;
204 205 206
        return;
    }

207 208 209 210 211 212 213 214 215 216 217
    bool error = false;

    //qDebug() << "-------------------------";
    //qDebug() << "Starting key search";
    //qDebug() << "-------------------------";

    try {
        if(m_yk == 0 && !openKey()) {
            throw 0;
        }

218
        if (!yk_get_status(m_yk, m_ykds)) {
219 220 221 222 223 224
            throw 0;
        }

        //qDebug() << "Key found";

        //Check pervious state
225
        if(m_state == State_Absent || m_state == State_NoFocus) {
226

227
            m_state = State_Present;
228 229

            //Get version
230 231 232
            m_versionMajor = ykds_version_major(m_ykds);
            m_versionMinor = ykds_version_minor(m_ykds);
            m_versionBuild = ykds_version_build(m_ykds);
233 234 235 236
            m_version = YK_VERSION(m_versionMajor,
                                   m_versionMinor,
                                   m_versionBuild);

237
            m_touchLevel = ykds_touch_level(m_ykds);
238

239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254
            //Get serial number
            if(checkFeatureSupport(Feature_SerialNumber)) {
                if (!yk_get_serial(m_yk, 0, 0, &m_serial)) {
                    qDebug() << "Failed to read serial number (serial-api-visible disabled?).";
                } else {
                    qDebug() << "Serial number: " << m_serial;
                }
            }

            //Get supported features
            size_t featuresCount = sizeof(FEATURE_MATRIX)/sizeof(FEATURE_MATRIX[0]);
            bool featuresMatrix[featuresCount];
            for(size_t i = 0; i < featuresCount; i++) {
                featuresMatrix[i] = checkFeatureSupport((Feature)i);
            }

255 256 257 258 259 260
            int error = ERR_NOERROR;
            if(!yk_check_firmware_version2(m_ykds)) {
                error = ERR_UNKNOWN_FIRMWARE;
            }

            emit keyFound(true, featuresMatrix, error);
261 262
            emit diagnostics(QString("Found key with version %1, serial %2 and touch %3.")
                .arg(versionStr(), QString::number(m_serial), QString::number(m_touchLevel)));
263 264 265 266 267 268
        }
    }
    catch(...) {
        error = true;
    }

269 270
    closeKey();

271
    if(error) {
272
        init();
273
        m_state = State_Absent;
274 275 276 277 278
        int error = ERR_OTHER;
        if(yk_errno == YK_EMORETHANONE) {
            error = ERR_MORETHANONE;
        } else if(yk_errno == YK_ENOKEY) {
            error = ERR_NOKEY;
279 280 281 282
        } else if(yk_errno == YK_EUSBERR) {
            emit diagnostics(QString("USB Error: %1").arg(yk_usb_strerror()));
        } else if(yk_errno) {
            emit diagnostics(yk_strerror(yk_errno));
283 284 285 286
        }
        yk_errno = 0;
        ykp_errno = 0;
        emit keyFound(false, NULL, error);
287 288 289 290 291 292
    }

    //qDebug() << "-------------------------";
    //qDebug() << "Stopping key search";
    //qDebug() << "-------------------------";
}