1f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)// Copyright 2013 The Chromium Authors. All rights reserved. 2f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)// Use of this source code is governed by a BSD-style license that can be 3f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)// found in the LICENSE file. 4f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) 5f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)#include "chrome/browser/chromeos/policy/policy_cert_service.h" 6f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) 7f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)#include "base/bind.h" 8f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)#include "base/bind_helpers.h" 9f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)#include "base/logging.h" 105d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)#include "chrome/browser/chromeos/policy/policy_cert_service_factory.h" 11f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)#include "chrome/browser/chromeos/policy/policy_cert_verifier.h" 126e8cce623b6e4fe0c9e4af605d675dd9d0338c38Torne (Richard Coles)#include "components/user_manager/user_manager.h" 13f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)#include "content/public/browser/browser_thread.h" 14f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)#include "net/cert/x509_certificate.h" 15f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) 16f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)namespace policy { 17f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) 18f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)PolicyCertService::~PolicyCertService() { 19f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) DCHECK(cert_verifier_) 20f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) << "CreatePolicyCertVerifier() must be called after construction."; 21f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)} 22f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) 23f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)PolicyCertService::PolicyCertService( 245d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) const std::string& user_id, 25f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) UserNetworkConfigurationUpdater* net_conf_updater, 266e8cce623b6e4fe0c9e4af605d675dd9d0338c38Torne (Richard Coles) user_manager::UserManager* user_manager) 27f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) : cert_verifier_(NULL), 285d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) user_id_(user_id), 29f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) net_conf_updater_(net_conf_updater), 305d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) user_manager_(user_manager), 315d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) has_trust_anchors_(false), 32f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) weak_ptr_factory_(this) { 33f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) DCHECK(net_conf_updater_); 345d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) DCHECK(user_manager_); 35f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)} 36f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) 375d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)PolicyCertService::PolicyCertService(const std::string& user_id, 385d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) PolicyCertVerifier* verifier, 396e8cce623b6e4fe0c9e4af605d675dd9d0338c38Torne (Richard Coles) user_manager::UserManager* user_manager) 405d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) : cert_verifier_(verifier), 415d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) user_id_(user_id), 425d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) net_conf_updater_(NULL), 435d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) user_manager_(user_manager), 445d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) has_trust_anchors_(false), 456e8cce623b6e4fe0c9e4af605d675dd9d0338c38Torne (Richard Coles) weak_ptr_factory_(this) { 466e8cce623b6e4fe0c9e4af605d675dd9d0338c38Torne (Richard Coles)} 475d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) 48f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)scoped_ptr<PolicyCertVerifier> PolicyCertService::CreatePolicyCertVerifier() { 495d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) base::Closure callback = base::Bind( 505d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) &PolicyCertServiceFactory::SetUsedPolicyCertificates, user_id_); 51f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) cert_verifier_ = new PolicyCertVerifier( 52f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) base::Bind(base::IgnoreResult(&content::BrowserThread::PostTask), 53f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) content::BrowserThread::UI, 54f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) FROM_HERE, 55f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) callback)); 56f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) // Certs are forwarded to |cert_verifier_|, thus register here after 57f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) // |cert_verifier_| is created. 58f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) net_conf_updater_->AddTrustedCertsObserver(this); 59f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) 60f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) // Set the current list of trust anchors. 61f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) net::CertificateList trust_anchors; 62f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) net_conf_updater_->GetWebTrustedCertificates(&trust_anchors); 63f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) OnTrustAnchorsChanged(trust_anchors); 64f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) 65f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) return make_scoped_ptr(cert_verifier_); 66f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)} 67f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) 68f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)void PolicyCertService::OnTrustAnchorsChanged( 69f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) const net::CertificateList& trust_anchors) { 70f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) DCHECK(cert_verifier_); 715d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) 725d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) // Do not use certificates installed via ONC policy if the current session has 735d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) // multiple profiles. This is important to make sure that any possibly tainted 745d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) // data is absolutely confined to the managed profile and never, ever leaks to 755d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) // any other profile. 765d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) if (!trust_anchors.empty() && user_manager_->GetLoggedInUsers().size() > 1u) { 775d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) LOG(ERROR) << "Ignoring ONC-pushed certificates update because multiple " 785d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) << "users are logged in."; 795d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) return; 805d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) } 815d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) 825d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) has_trust_anchors_ = !trust_anchors.empty(); 835d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) 84f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) // It's safe to use base::Unretained here, because it's guaranteed that 85f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) // |cert_verifier_| outlives this object (see description of 86f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) // CreatePolicyCertVerifier). 87f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) // Note: ProfileIOData, which owns the CertVerifier is deleted by a 88f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) // DeleteSoon on IO, i.e. after all pending tasks on IO are finished. 89f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) content::BrowserThread::PostTask( 90f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) content::BrowserThread::IO, 91f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) FROM_HERE, 92f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) base::Bind(&PolicyCertVerifier::SetTrustAnchors, 93f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) base::Unretained(cert_verifier_), 94f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) trust_anchors)); 95f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)} 96f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) 97f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)bool PolicyCertService::UsedPolicyCertificates() const { 985d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) return PolicyCertServiceFactory::UsedPolicyCertificates(user_id_); 99f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)} 100f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) 101f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)void PolicyCertService::Shutdown() { 102f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) weak_ptr_factory_.InvalidateWeakPtrs(); 1035d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) if (net_conf_updater_) 1045d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) net_conf_updater_->RemoveTrustedCertsObserver(this); 105f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) OnTrustAnchorsChanged(net::CertificateList()); 106f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) net_conf_updater_ = NULL; 107f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)} 108f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) 1095d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)// static 1105d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles)scoped_ptr<PolicyCertService> PolicyCertService::CreateForTesting( 1115d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) const std::string& user_id, 1125d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) PolicyCertVerifier* verifier, 1136e8cce623b6e4fe0c9e4af605d675dd9d0338c38Torne (Richard Coles) user_manager::UserManager* user_manager) { 1145d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) return make_scoped_ptr( 1155d1f7b1de12d16ceb2c938c56701a3e8bfa558f7Torne (Richard Coles) new PolicyCertService(user_id, verifier, user_manager)); 116f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)} 117f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles) 118f2477e01787aa58f445919b809d89e252beef54fTorne (Richard Coles)} // namespace policy 119