blob: 2efb89ab2b235b831d819f00cd75cf2bc7df2f67 [file]
#ifndef PRODUCTION_SUSHID_SAFEPOWER_AGENT_BMC_AUTH_LOAS3_H_
#define PRODUCTION_SUSHID_SAFEPOWER_AGENT_BMC_AUTH_LOAS3_H_
// THIS FILE IS NOT SUPPORTED BY THE UT ENVIRONMENT
#if LOAS3_AUTH
// this file is not supported by the gBMC unit test framework,
// but it is supported by the bitbake firmaware builds
#include <gpowerd_build_config.h>
#include <grpcpp/grpcpp.h>
#include <string>
#include <string_view>
#include "bmc/gmi_reader.h"
#include "grpcpp/security/server_credentials.h"
#include "grpcpp/security/tls_certificate_provider.h"
#include "grpcpp/security/tls_certificate_verifier.h"
#include "grpcpp/security/tls_credentials_options.h"
#include "grpcpp/ext/proto_server_reflection_plugin.h"
#include "absl/base/log_severity.h"
#include "absl/log/log.h"
// This header does not exist in the ut environment
#include "security/zatar/loas3_validation/validation/validation.h"
namespace auth {
using ::grpc::experimental::TlsCustomVerificationCheckRequest;
using ::grpc::experimental::ExternalCertificateVerifier;
void SetupLoas3(){
LOG(INFO) << "Setting up LOAS3";
security::SetCertificateAuthorityPolicyFilePath(
"/var/google/loas3/policy.pb");
}
std::vector<std::string_view>
ToStringViewVector(const std::vector<grpc::string_ref>& string_refs)
{
std::vector<std::string_view> strs(string_refs.size());
for (size_t i = 0; i < string_refs.size(); ++i)
{
strs[i] =
std::string_view(string_refs[i].data(), string_refs[i].size());
}
return strs;
}
class PeerVerifier : public ExternalCertificateVerifier
{
public:
PeerVerifier() = default;
~PeerVerifier() override = default;
bool Verify([[maybe_unused]] TlsCustomVerificationCheckRequest* request,
std::function<void(grpc::Status)>,
grpc::Status* sync_status) override
{
std::vector<std::string_view> peer_uri_names =
ToStringViewVector(request->uri_names());
std::vector<std::string_view> peer_dns_names =
ToStringViewVector(request->dns_names());
absl::Status status = security::ValidatePeer(
peer_uri_names, peer_dns_names,
request->verified_root_cert_subject().data());
if (!status.ok())
{
*sync_status =
grpc::Status(grpc::StatusCode::PERMISSION_DENIED,
// This is from Federation policy check
absl::StrCat("From Federation policy check: ",
status.message()));
LOG(ERROR) << status.message() << std::endl;
}
return true;
}
void Cancel(TlsCustomVerificationCheckRequest*) override {}
};
} // namespace auth
#endif // LOAS3_AUTH
#endif // PRODUCTION_SUSHID_SAFEPOWER_AGENT_BMC_AUTH_LOAS3_H_