+/* set_signature() */
+/* */
+/* If found in conf file, use it. */
+/* If not found in conf file, genarate and append in conf file. */
+/* If conf file don't exist, create and genarate. */
+/* If cannot open conf file, use one-time signature. */
+/* If -signature user:xxxxx, use it. */
+
+void set_signature(struct afp_options *options) {
+ char *usersign;
+ int fd, i;
+ struct stat tmpstat;
+ char *servername_conf;
+ int header = 0;
+ char buf[1024], *p;
+ FILE *fp = NULL, *randomp;
+ size_t len;
+ char *server_tmp;
+
+ server_tmp = (options->server ? options->server : options->hostname);
+ if (strcmp(options->signatureopt, "auto") == 0) {
+ goto server_signature_auto; /* default */
+ } else if (strcmp(options->signatureopt, "host") == 0) {
+ LOG(log_warning, logtype_afpd, "WARNING: option \"-signature host\" is obsoleted. Switching back to auto.", options->signatureopt);
+ goto server_signature_auto; /* same as auto */
+ } else if (strncmp(options->signatureopt, "user", 4) == 0) {
+ goto server_signature_user; /* user string */
+ } else {
+ LOG(log_error, logtype_afpd, "ERROR: option \"-signature %s\" is not valid. Switching back to auto.", options->signatureopt);
+ goto server_signature_auto; /* switch back to auto*/
+ }
+
+server_signature_user:
+
+ /* Signature type is user string */
+ len = strlen(options->signatureopt);
+ if (len <= 5) {
+ LOG(log_warning, logtype_afpd, "WARNING: option \"-signature %s\" is not valid. Switching back to auto.", options->signatureopt);
+ goto server_signature_auto;
+ }
+ usersign = options->signatureopt + 5;
+ len = len - 5;
+ if (len > 16) {
+ LOG(log_warning, logtype_afpd, "WARNING: signature user string %s is very long !", usersign);
+ len = 16;
+ } else if (len >= 3) {
+ LOG(log_info, logtype_afpd, "signature user string is %s.", usersign);
+ } else {
+ LOG(log_warning, logtype_afpd, "WARNING: signature user string %s is very short !", usersign);
+ }
+ memset(options->signature, 0, 16);
+ memcpy(options->signature, usersign, len);
+ goto server_signature_done;
+
+server_signature_auto:
+
+ /* Signature type is auto, using afp_signature.conf */
+ if (!stat(options->sigconffile, &tmpstat)) { /* conf file exists? */
+ if ((fp = fopen(options->sigconffile, "r")) != NULL) { /* read open? */
+ /* scan in the conf file */
+ while (fgets(buf, sizeof(buf), fp) != NULL) {
+ p = buf;
+ while (p && isblank(*p))
+ p++;
+ if (!p || (*p == '#') || (*p == '\n'))
+ continue; /* invalid line */
+ if (*p == '"') {
+ p++;
+ if ((servername_conf = strtok( p, "\"" )) == NULL)
+ continue; /* syntax error: invalid quoted servername */
+ } else {
+ if ((servername_conf = strtok( p, " \t" )) == NULL)
+ continue; /* syntax error: invalid servername */
+ }
+ p = strchr(p, '\0');
+ p++;
+ if (*p == '\0')
+ continue; /* syntax error: missing signature */
+
+ if (strcmp(server_tmp, servername_conf))
+ continue; /* another servername */
+
+ while (p && isblank(*p))
+ p++;
+ if ( 16 == sscanf(p, "%2hhX%2hhX%2hhX%2hhX%2hhX%2hhX%2hhX%2hhX%2hhX%2hhX%2hhX%2hhX%2hhX%2hhX%2hhX%2hhX",
+ &options->signature[ 0], &options->signature[ 1],
+ &options->signature[ 2], &options->signature[ 3],
+ &options->signature[ 4], &options->signature[ 5],
+ &options->signature[ 6], &options->signature[ 7],
+ &options->signature[ 8], &options->signature[ 9],
+ &options->signature[10], &options->signature[11],
+ &options->signature[12], &options->signature[13],
+ &options->signature[14], &options->signature[15]
+ )) {
+ fclose(fp);
+ goto server_signature_done; /* found in conf file */
+ }
+ }
+ if ((fp = freopen(options->sigconffile, "a+", fp)) != NULL) { /* append because not found */
+ fseek(fp, 0L, SEEK_END);
+ if(ftell(fp) == 0) { /* size = 0 */
+ header = 1;
+ goto server_signature_random;
+ } else {
+ fseek(fp, -1L, SEEK_END);
+ if(fgetc(fp) != '\n') fputc('\n', fp); /* last char is \n? */
+ goto server_signature_random;
+ }
+ } else {
+ LOG(log_error, logtype_afpd, "ERROR: Cannot write in %s (%s). Using one-time signature.",
+ options->sigconffile, strerror(errno));
+ goto server_signature_random;
+ }
+ } else {
+ LOG(log_error, logtype_afpd, "ERROR: Cannot read %s (%s). Using one-time signature.",
+ options->sigconffile, strerror(errno));
+ goto server_signature_random;
+ }
+ } else { /* conf file don't exist */
+ if (( fd = creat(options->sigconffile, 0644 )) < 0 ) {
+ LOG(log_error, logtype_afpd, "ERROR: Cannot create %s (%s). Using one-time signature.",
+ options->sigconffile, strerror(errno));
+ goto server_signature_random;
+ }
+ if (( fp = fdopen( fd, "w" )) == NULL ) {
+ LOG(log_error, logtype_afpd, "ERROR: Cannot fdopen %s (%s). Using one-time signature.",
+ options->sigconffile, strerror(errno));
+ close(fd);
+ goto server_signature_random;
+ }
+ header = 1;
+ goto server_signature_random;
+ }
+
+server_signature_random:
+
+ /* generate signature from random number */
+ randombytes(options->signature, 16);
+
+ if (fp && header) { /* conf file is created or size=0 */
+ fprintf(fp, "# DON'T TOUCH NOR COPY THOUGHTLESSLY!\n");
+ fprintf(fp, "# This file is auto-generated by afpd.\n");
+ fprintf(fp, "# \n");
+ fprintf(fp, "# ServerSignature is unique identifier used to prevent logging on to\n");
+ fprintf(fp, "# the same server twice.\n");
+ fprintf(fp, "# \n");
+ fprintf(fp, "# If setting \"-signature user:xxxxx\" in afpd.conf, this file is not used.\n\n");
+ }
+
+ if (fp) {
+ fprintf(fp, "\"%s\"\t", server_tmp);
+ for (i=0 ; i<16 ; i++) {
+ fprintf(fp, "%02X", (options->signature)[i]);
+ }
+ fprintf(fp, "%s", "\n");
+ fclose(fp);
+ }
+
+server_signature_done:
+
+ /* retrun */
+ LOG(log_info, logtype_afpd,
+ " \"%s\"'s signature is %02X%02X%02X%02X%02X%02X%02X%02X%02X%02X%02X%02X%02X%02X%02X%02X",
+ server_tmp,
+ (options->signature)[ 0], (options->signature)[ 1],
+ (options->signature)[ 2], (options->signature)[ 3],
+ (options->signature)[ 4], (options->signature)[ 5],
+ (options->signature)[ 6], (options->signature)[ 7],
+ (options->signature)[ 8], (options->signature)[ 9],
+ (options->signature)[10], (options->signature)[11],
+ (options->signature)[12], (options->signature)[13],
+ (options->signature)[14], (options->signature)[15]);
+
+ return;
+}
+