| | | 1 | | // Licensed to the .NET Foundation under one or more agreements. |
| | | 2 | | // The .NET Foundation licenses this file to you under the MIT license. |
| | | 3 | | |
| | | 4 | | using System.Collections; |
| | | 5 | | using System.ComponentModel; |
| | | 6 | | using System.Runtime.InteropServices; |
| | | 7 | | using System.Runtime.Serialization; |
| | | 8 | | using System.Text; |
| | | 9 | | |
| | | 10 | | namespace System.Security.Authentication.ExtendedProtection |
| | | 11 | | { |
| | | 12 | | /// <summary> |
| | | 13 | | /// This class contains the necessary settings for specifying how Extended Protection |
| | | 14 | | /// should behave. Use one of the Build* methods to create an instance of this type. |
| | | 15 | | /// </summary> |
| | | 16 | | public class ExtendedProtectionPolicy : ISerializable |
| | | 17 | | { |
| | | 18 | | private readonly ServiceNameCollection? _customServiceNames; |
| | | 19 | | private readonly PolicyEnforcement _policyEnforcement; |
| | | 20 | | private readonly ProtectionScenario _protectionScenario; |
| | | 21 | | private readonly ChannelBinding? _customChannelBinding; |
| | | 22 | | |
| | 0 | 23 | | public ExtendedProtectionPolicy(PolicyEnforcement policyEnforcement, |
| | 0 | 24 | | ProtectionScenario protectionScenario, |
| | 0 | 25 | | ServiceNameCollection? customServiceNames) |
| | 0 | 26 | | { |
| | 0 | 27 | | if (policyEnforcement == PolicyEnforcement.Never) |
| | 0 | 28 | | { |
| | 0 | 29 | | throw new ArgumentException(SR.security_ExtendedProtectionPolicy_UseDifferentConstructorForNever, nameof |
| | | 30 | | } |
| | | 31 | | |
| | 0 | 32 | | if (customServiceNames != null && customServiceNames.Count == 0) |
| | 0 | 33 | | { |
| | 0 | 34 | | throw new ArgumentException(SR.security_ExtendedProtectionPolicy_NoEmptyServiceNameCollection, nameof(cu |
| | | 35 | | } |
| | | 36 | | |
| | 0 | 37 | | _policyEnforcement = policyEnforcement; |
| | 0 | 38 | | _protectionScenario = protectionScenario; |
| | 0 | 39 | | _customServiceNames = customServiceNames; |
| | 0 | 40 | | } |
| | | 41 | | |
| | | 42 | | public ExtendedProtectionPolicy(PolicyEnforcement policyEnforcement, |
| | | 43 | | ProtectionScenario protectionScenario, |
| | | 44 | | ICollection? customServiceNames) |
| | 0 | 45 | | : this(policyEnforcement, protectionScenario, |
| | 0 | 46 | | customServiceNames == null ? (ServiceNameCollection?)null : new ServiceNameCollection(customServiceNa |
| | 0 | 47 | | { |
| | 0 | 48 | | } |
| | | 49 | | |
| | 0 | 50 | | public ExtendedProtectionPolicy(PolicyEnforcement policyEnforcement, |
| | 0 | 51 | | ChannelBinding customChannelBinding) |
| | 0 | 52 | | { |
| | 0 | 53 | | if (policyEnforcement == PolicyEnforcement.Never) |
| | 0 | 54 | | { |
| | 0 | 55 | | throw new ArgumentException(SR.security_ExtendedProtectionPolicy_UseDifferentConstructorForNever, nameof |
| | | 56 | | } |
| | 0 | 57 | | ArgumentNullException.ThrowIfNull(customChannelBinding); |
| | | 58 | | |
| | 0 | 59 | | _policyEnforcement = policyEnforcement; |
| | 0 | 60 | | _protectionScenario = ProtectionScenario.TransportSelected; |
| | 0 | 61 | | _customChannelBinding = customChannelBinding; |
| | 0 | 62 | | } |
| | | 63 | | |
| | 0 | 64 | | public ExtendedProtectionPolicy(PolicyEnforcement policyEnforcement) |
| | 0 | 65 | | { |
| | | 66 | | // This is the only constructor which allows PolicyEnforcement.Never. |
| | 0 | 67 | | _policyEnforcement = policyEnforcement; |
| | 0 | 68 | | _protectionScenario = ProtectionScenario.TransportSelected; |
| | 0 | 69 | | } |
| | | 70 | | |
| | | 71 | | [Obsolete(Obsoletions.LegacyFormatterImplMessage, DiagnosticId = Obsoletions.LegacyFormatterImplDiagId, UrlForma |
| | | 72 | | [EditorBrowsable(EditorBrowsableState.Never)] |
| | 0 | 73 | | protected ExtendedProtectionPolicy(SerializationInfo info, StreamingContext context) |
| | 0 | 74 | | { |
| | 0 | 75 | | throw new PlatformNotSupportedException(); |
| | | 76 | | } |
| | | 77 | | |
| | | 78 | | void ISerializable.GetObjectData(SerializationInfo info, StreamingContext context) |
| | 0 | 79 | | { |
| | 0 | 80 | | throw new PlatformNotSupportedException(); |
| | | 81 | | } |
| | | 82 | | |
| | | 83 | | public ServiceNameCollection? CustomServiceNames |
| | | 84 | | { |
| | 0 | 85 | | get { return _customServiceNames; } |
| | | 86 | | } |
| | | 87 | | |
| | | 88 | | public PolicyEnforcement PolicyEnforcement |
| | | 89 | | { |
| | 0 | 90 | | get { return _policyEnforcement; } |
| | | 91 | | } |
| | | 92 | | |
| | | 93 | | public ProtectionScenario ProtectionScenario |
| | | 94 | | { |
| | 0 | 95 | | get { return _protectionScenario; } |
| | | 96 | | } |
| | | 97 | | |
| | | 98 | | public ChannelBinding? CustomChannelBinding |
| | | 99 | | { |
| | 0 | 100 | | get { return _customChannelBinding; } |
| | | 101 | | } |
| | | 102 | | |
| | | 103 | | public override string ToString() |
| | 0 | 104 | | { |
| | 0 | 105 | | StringBuilder sb = new StringBuilder(); |
| | 0 | 106 | | sb.Append("ProtectionScenario="); |
| | 0 | 107 | | sb.Append($"{_protectionScenario}"); |
| | 0 | 108 | | sb.Append("; PolicyEnforcement="); |
| | 0 | 109 | | sb.Append($"{_policyEnforcement}"); |
| | | 110 | | |
| | 0 | 111 | | sb.Append("; CustomChannelBinding="); |
| | 0 | 112 | | if (_customChannelBinding == null) |
| | 0 | 113 | | { |
| | 0 | 114 | | sb.Append("<null>"); |
| | 0 | 115 | | } |
| | | 116 | | else |
| | 0 | 117 | | { |
| | 0 | 118 | | sb.Append(_customChannelBinding.ToString()); |
| | 0 | 119 | | } |
| | | 120 | | |
| | 0 | 121 | | sb.Append("; ServiceNames="); |
| | 0 | 122 | | if (_customServiceNames == null) |
| | 0 | 123 | | { |
| | 0 | 124 | | sb.Append("<null>"); |
| | 0 | 125 | | } |
| | | 126 | | else |
| | 0 | 127 | | { |
| | 0 | 128 | | bool first = true; |
| | 0 | 129 | | foreach (string serviceName in _customServiceNames) |
| | 0 | 130 | | { |
| | 0 | 131 | | if (first) |
| | 0 | 132 | | { |
| | 0 | 133 | | first = false; |
| | 0 | 134 | | } |
| | | 135 | | else |
| | 0 | 136 | | { |
| | 0 | 137 | | sb.Append(", "); |
| | 0 | 138 | | } |
| | | 139 | | |
| | 0 | 140 | | sb.Append(serviceName); |
| | 0 | 141 | | } |
| | 0 | 142 | | } |
| | | 143 | | |
| | 0 | 144 | | return sb.ToString(); |
| | 0 | 145 | | } |
| | | 146 | | |
| | | 147 | | public static bool OSSupportsExtendedProtection |
| | | 148 | | { |
| | | 149 | | get |
| | 0 | 150 | | { |
| | | 151 | | // ExtendedProtection is supported on all Windows versions supported by current .NET version. |
| | | 152 | | // Linux is supported via GSSAPI (Managed implements only client-side). |
| | | 153 | | // MacOS's Heimdal-derived GSS.framework does not reject a channel binding mismatch (the exchange comple |
| | 0 | 154 | | return OperatingSystem.IsWindows() || OperatingSystem.IsLinux(); |
| | 0 | 155 | | } |
| | | 156 | | } |
| | | 157 | | } |
| | | 158 | | } |
| | | 159 | | |