File

mod_client_certs/README.md @ 6110:1a6cd0bbb7ab

mod_compliance_2023: Add 2023 Version of the compliance module, basis is the 2021 Version. diff --git a/mod_compliance_2023/README.md b/mod_compliance_2023/README.md new file mode 100644 --- /dev/null +++ b/mod_compliance_2023/README.md @@ -0,0 +1,22 @@ +--- +summary: XMPP Compliance Suites 2023 self-test +labels: +- Stage-Beta +rockspec: + dependencies: + - mod_cloud_notify + +... + +Compare the list of enabled modules with +[XEP-0479: XMPP Compliance Suites 2023] and produce basic report to the +Prosody log file. + +If installed with the Prosody plugin installer then all modules needed for a green checkmark should be included. (With prosody 0.12 only [mod_cloud_notify] is not included with prosody and we need the community module) + +# Compatibility + + Prosody-Version Status + --------------- ---------------------- + trunk Works as of 2024-12-21 + 0.12 Works diff --git a/mod_compliance_2023/mod_compliance_2023.lua b/mod_compliance_2023/mod_compliance_2023.lua new file mode 100644 --- /dev/null +++ b/mod_compliance_2023/mod_compliance_2023.lua @@ -0,0 +1,79 @@ +-- Copyright (c) 2021 Kim Alvefur +-- +-- This module is MIT licensed. + +local hostmanager = require "core.hostmanager"; + +local array = require "util.array"; +local set = require "util.set"; + +local modules_enabled = module:get_option_inherited_set("modules_enabled"); + +for host in pairs(hostmanager.get_children(module.host)) do + local component = module:context(host):get_option_string("component_module"); + if component then + modules_enabled:add(component); + modules_enabled:include(module:context(host):get_option_set("modules_enabled", {})); + end +end + +local function check(suggested, alternate, ...) + if set.intersection(modules_enabled, set.new({suggested; alternate; ...})):empty() then return suggested; end + return false; +end + +local compliance = { + array {"Server"; check("tls"); check("disco")}; + + array {"Advanced Server"; check("pep", "pep_simple")}; + + array {"Web"; check("bosh"); check("websocket")}; + + -- No Server requirements for Advanced Web + + array {"IM"; check("vcard_legacy", "vcard"); check("carbons"); check("http_file_share", "http_upload")}; + + array { + "Advanced IM"; + check("vcard_legacy", "vcard"); + check("blocklist"); + check("muc"); + check("private"); + check("smacks"); + check("mam"); + check("bookmarks"); + }; + + array {"Mobile"; check("smacks"); check("csi_simple", "csi_battery_saver")}; + + array {"Advanced Mobile"; check("cloud_notify")}; + + array {"A/V Calling"; check("turn_external", "external_services", "turncredentials", "extdisco")}; + +}; + +function check_compliance() + local compliant = true; + for _, suite in ipairs(compliance) do + local section = suite:pop(1); + if module:get_option_boolean("compliance_" .. section:lower():gsub("%A", "_"), true) then + local missing = set.new(suite:filter(function(m) return type(m) == "string" end):map(function(m) return "mod_" .. m end)); + if suite[1] then + if compliant then + compliant = false; + module:log("warn", "Missing some modules for XMPP Compliance 2023"); + end + module:log("info", "%s Compliance: %s", section, missing); + end + end + end + + if compliant then module:log("info", "XMPP Compliance 2023: Compliant ✔️"); end +end + +if prosody.start_time then + check_compliance() +else + module:hook_global("server-started", check_compliance); +end +
author Menel <menel@snikket.de>
date Sun, 22 Dec 2024 16:06:28 +0100
parent 6003:fe081789f7b5
line wrap: on
line source

---
labels:
- 'Stage-Alpha'
summary: 'Client-side certificate management for Prosody'
...

Introduction
============

[XEP-0257](http://xmpp.org/extensions/xep-0257.html) specifies a
protocol for clients to store and manage client side certificates. When
a client presents a stored client side certificate during the TLS
handshake, it can log in without supplying a password (using SASL
EXTERNAL). This makes it possible to have multiple devices accessing an
account, without any of them needing to know the password, and makes it
easier to revoke access for a single device.

Details
=======

Each user can add their own certificates. These do not need to be signed
by a trusted CA, yet they do need to be valid at the time of logging in
and they should include an subjectAltName with otherName
"id-on-xmppAddr" with the JID of the user.

Generating your certificate
---------------------------

1.  To generate your own certificate with a "id-on-xmppAddr" attribute
    using the command line `openssl` tool, first create a file called
    `client.cnf` with contents:

        [req] prompt = no
        x509_extensions = v3_extensions
        req_extensions = v3_extensions
        distinguished_name = distinguished_name

        [v3_extensions]
        extendedKeyUsage = clientAuth
        keyUsage = digitalSignature,keyEncipherment
        basicConstraints = CA:FALSE
        subjectAltName = @subject_alternative_name

        [subject_alternative_name]
        otherName.0 =
        1.3.6.1.5.5.7.8.5;FORMAT:UTF8,UTF8:hamlet@shakespeare.lit

        [distinguished_name]
        commonName = Your Name
        emailAddress = hamlet@shakespeare.lit

2.  Replace the values for `otherName.0` and `commonName` and
    `emailAddress` with your own values. The JID in `otherName.0` can
    either be a full JID or a bare JID, in the former case, the client
    can only use the resource specified in the resource. There are many
    other fields you can add, however, for SASL EXTERNAL, they will have
    no meaning. You can add more JIDs as `otherName.1`, `otherName.2`,
    etc.
3.  Create a private key (as an example, a 4096 bits RSA key):

        openssl genrsa -out client.key 4096

4.  Create the certificate request:

        openssl req -key client.key -new -out client.req -config client.cnf -extensions v3_extensions

5.  Sign it yourself:

        openssl x509 -req -days 365 -in client.req -signkey client.key -out client.crt -extfile client.cnf -extensions v3_extensions

The 365 means the certificate will be valid for a year starting now.

The `client.key` **must** be kept secret, and is only needed by clients
connecting using this certificate. The `client.crt` file contains the
certificate that should be sent to the server using XEP-0257, and is
also needed by clients connecting to the server. The `client.req` file
is not needed anymore.

Configuration
=============

(None yet)

Compatibility
=============

  ----- -----------------------------
  0.9   Works
  0.8   Untested. Probably doesn't.
  ----- -----------------------------

Clients
=======

(None?)

TODO
====

Possible options to add to the configuration:

-   Require certificates to be signed by a trusted CA.
-   Do not require a id-on-xmppAddr
-   Remove expired certs after a certain time
-   Limit the number of certificates per user