FreeRDP
Loading...
Searching...
No Matches
license.c
1/*
2 * FreeRDP: A Remote Desktop Protocol Implementation
3 * RDP Licensing
4 *
5 * Copyright 2011-2013 Marc-Andre Moreau <marcandre.moreau@gmail.com>
6 * Copyright 2014 Norbert Federa <norbert.federa@thincast.com>
7 * Copyright 2018 David Fort <contact@hardening-consulting.com>
8 * Copyright 2022,2023 Armin Novak <armin.novak@thincast.com>
9 * Copyright 2022,2023 Thincast Technologies GmbH
10 *
11 * Licensed under the Apache License, Version 2.0 (the "License");
12 * you may not use this file except in compliance with the License.
13 * You may obtain a copy of the License at
14 *
15 * http://www.apache.org/licenses/LICENSE-2.0
16 *
17 * Unless required by applicable law or agreed to in writing, software
18 * distributed under the License is distributed on an "AS IS" BASIS,
19 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
20 * See the License for the specific language governing permissions and
21 * limitations under the License.
22 */
23
24#include <freerdp/config.h>
25
26#include "settings.h"
27
28#include <freerdp/license.h>
29
30#include <winpr/crt.h>
31#include <winpr/assert.h>
32#include <winpr/crypto.h>
33#include <winpr/shell.h>
34#include <winpr/path.h>
35#include <winpr/file.h>
36
37#include <freerdp/log.h>
38
39#include <freerdp/crypto/certificate.h>
40
41#include "license.h"
42
43#include "../crypto/crypto.h"
44#include "../crypto/certificate.h"
45
46#define LICENSE_TAG FREERDP_TAG("core.license")
47
48// #define LICENSE_NULL_CLIENT_RANDOM 1
49// #define LICENSE_NULL_PREMASTER_SECRET 1
50
51// #define WITH_LICENSE_DECRYPT_CHALLENGE_RESPONSE
52
53#define PLATFORM_CHALLENGE_RESPONSE_VERSION 0x0100
54
56enum LicenseRequestType
57{
58 LICENSE_REQUEST = 0x01,
59 PLATFORM_CHALLENGE = 0x02,
60 NEW_LICENSE = 0x03,
61 UPGRADE_LICENSE = 0x04,
62 LICENSE_INFO = 0x12,
63 NEW_LICENSE_REQUEST = 0x13,
64 PLATFORM_CHALLENGE_RESPONSE = 0x15,
65 ERROR_ALERT = 0xFF
66};
67
68/*
69#define LICENSE_PKT_CS_MASK \
70 (LICENSE_INFO | NEW_LICENSE_REQUEST | PLATFORM_CHALLENGE_RESPONSE | ERROR_ALERT)
71#define LICENSE_PKT_SC_MASK \
72 (LICENSE_REQUEST | PLATFORM_CHALLENGE | NEW_LICENSE | UPGRADE_LICENSE | ERROR_ALERT)
73#define LICENSE_PKT_MASK (LICENSE_PKT_CS_MASK | LICENSE_PKT_SC_MASK)
74*/
75#define LICENSE_PREAMBLE_LENGTH 4
76
77/* Cryptographic Lengths */
78
79#define SERVER_RANDOM_LENGTH 32
80#define MASTER_SECRET_LENGTH 48
81#define PREMASTER_SECRET_LENGTH 48
82#define SESSION_KEY_BLOB_LENGTH 48
83#define MAC_SALT_KEY_LENGTH 16
84#define LICENSING_ENCRYPTION_KEY_LENGTH 16
85#define HWID_PLATFORM_ID_LENGTH 4
86// #define HWID_UNIQUE_DATA_LENGTH 16
87#define HWID_LENGTH 20
88// #define LICENSING_PADDING_SIZE 8
89
90/* Preamble Flags */
91
92// #define PREAMBLE_VERSION_2_0 0x02
93#define PREAMBLE_VERSION_3_0 0x03
94// #define LicenseProtocolVersionMask 0x0F
95#define EXTENDED_ERROR_MSG_SUPPORTED 0x80
96
98enum
99{
100 BB_ANY_BLOB = 0x0000,
101 BB_DATA_BLOB = 0x0001,
102 BB_RANDOM_BLOB = 0x0002,
103 BB_CERTIFICATE_BLOB = 0x0003,
104 BB_ERROR_BLOB = 0x0004,
105 BB_ENCRYPTED_DATA_BLOB = 0x0009,
106 BB_KEY_EXCHG_ALG_BLOB = 0x000D,
107 BB_SCOPE_BLOB = 0x000E,
108 BB_CLIENT_USER_NAME_BLOB = 0x000F,
109 BB_CLIENT_MACHINE_NAME_BLOB = 0x0010
110};
111
112/* License Key Exchange Algorithms */
113
114#define KEY_EXCHANGE_ALG_RSA 0x00000001
115
118enum
119{
120 ERR_INVALID_SERVER_CERTIFICATE = 0x00000001,
121 ERR_NO_LICENSE = 0x00000002,
122 ERR_INVALID_MAC = 0x00000003,
123 ERR_INVALID_SCOPE = 0x00000004,
124 ERR_NO_LICENSE_SERVER = 0x00000006,
125 STATUS_VALID_CLIENT = 0x00000007,
126 ERR_INVALID_CLIENT = 0x00000008,
127 ERR_INVALID_PRODUCT_ID = 0x0000000B,
128 ERR_INVALID_MESSAGE_LENGTH = 0x0000000C
129};
130
133enum
134{
135 ST_TOTAL_ABORT = 0x00000001,
136 ST_NO_TRANSITION = 0x00000002,
137 ST_RESET_PHASE_TO_START = 0x00000003,
138 ST_RESEND_LAST_MESSAGE = 0x00000004
139};
140
143enum
144{
145 WIN32_PLATFORM_CHALLENGE_TYPE = 0x0100,
146 WIN16_PLATFORM_CHALLENGE_TYPE = 0x0200,
147 WINCE_PLATFORM_CHALLENGE_TYPE = 0x0300,
148 OTHER_PLATFORM_CHALLENGE_TYPE = 0xFF00
149};
150
153enum
154{
155 LICENSE_DETAIL_SIMPLE = 0x0001,
156 LICENSE_DETAIL_MODERATE = 0x0002,
157 LICENSE_DETAIL_DETAIL = 0x0003
158};
159
160/*
161 * PlatformId:
162 *
163 * The most significant byte of the PlatformId field contains the operating system version of the
164 * client. The second most significant byte of the PlatformId field identifies the ISV that provided
165 * the client image. The remaining two bytes in the PlatformId field are used by the ISV to identify
166 * the build number of the operating system.
167 *
168 * 0x04010000:
169 *
170 * CLIENT_OS_ID_WINNT_POST_52 (0x04000000)
171 * CLIENT_IMAGE_ID_MICROSOFT (0x00010000)
172 */
173enum
174{
175 CLIENT_OS_ID_WINNT_351 = 0x01000000,
176 CLIENT_OS_ID_WINNT_40 = 0x02000000,
177 CLIENT_OS_ID_WINNT_50 = 0x03000000,
178 CLIENT_OS_ID_WINNT_POST_52 = 0x04000000,
179
180 CLIENT_IMAGE_ID_MICROSOFT = 0x00010000,
181 CLIENT_IMAGE_ID_CITRIX = 0x00020000,
182};
183
184struct rdp_license
185{
186 LICENSE_STATE state;
187 LICENSE_TYPE type;
188 rdpRdp* rdp;
189 rdpCertificate* certificate;
190 BYTE HardwareId[HWID_LENGTH];
191 BYTE ClientRandom[CLIENT_RANDOM_LENGTH];
192 BYTE ServerRandom[SERVER_RANDOM_LENGTH];
193 BYTE MasterSecret[MASTER_SECRET_LENGTH];
194 BYTE PremasterSecret[PREMASTER_SECRET_LENGTH];
195 BYTE SessionKeyBlob[SESSION_KEY_BLOB_LENGTH];
196 BYTE MacSaltKey[MAC_SALT_KEY_LENGTH];
197 BYTE LicensingEncryptionKey[LICENSING_ENCRYPTION_KEY_LENGTH];
198 LICENSE_PRODUCT_INFO* ProductInfo;
199 LICENSE_BLOB* ErrorInfo;
200 LICENSE_BLOB* LicenseInfo; /* Client -> Server */
201 LICENSE_BLOB* KeyExchangeList;
202 LICENSE_BLOB* ServerCertificate;
203 LICENSE_BLOB* ClientUserName;
204 LICENSE_BLOB* ClientMachineName;
205 LICENSE_BLOB* PlatformChallenge;
206 LICENSE_BLOB* PlatformChallengeResponse;
207 LICENSE_BLOB* EncryptedPremasterSecret;
208 LICENSE_BLOB* EncryptedPlatformChallenge;
209 LICENSE_BLOB* EncryptedPlatformChallengeResponse;
210 LICENSE_BLOB* EncryptedHardwareId;
211 LICENSE_BLOB* EncryptedLicenseInfo;
212 BYTE MACData[LICENSING_ENCRYPTION_KEY_LENGTH];
213 SCOPE_LIST* ScopeList;
214 UINT32 PacketHeaderLength;
215 UINT32 PreferredKeyExchangeAlg;
216 UINT32 PlatformId;
217 UINT16 ClientType;
218 UINT16 LicenseDetailLevel;
219 BOOL update;
220 wLog* log;
221};
222
223WINPR_ATTR_NODISCARD
224static BOOL license_send_error_alert(rdpLicense* license, UINT32 dwErrorCode,
225 UINT32 dwStateTransition, const LICENSE_BLOB* info);
226
227static void license_set_state(rdpLicense* license, LICENSE_STATE state);
228
229WINPR_ATTR_NODISCARD
230static const char* license_get_state_string(LICENSE_STATE state);
231
232WINPR_ATTR_NODISCARD
233static const char* license_preferred_key_exchange_alg_string(UINT32 alg, char* buffer, size_t size)
234{
235 const char* name = nullptr;
236
237 switch (alg)
238 {
239 case KEY_EXCHANGE_ALG_RSA:
240 name = "KEY_EXCHANGE_ALG_RSA";
241 break;
242 default:
243 name = "KEY_EXCHANGE_ALG_UNKNOWN";
244 break;
245 }
246
247 (void)_snprintf(buffer, size, "%s [0x%08" PRIx32 "]", name, alg);
248 return buffer;
249}
250
251WINPR_ATTR_NODISCARD
252static const char* license_request_type_string(UINT32 type)
253{
254 switch (type)
255 {
256 case LICENSE_REQUEST:
257 return "LICENSE_REQUEST";
258 case PLATFORM_CHALLENGE:
259 return "PLATFORM_CHALLENGE";
260 case NEW_LICENSE:
261 return "NEW_LICENSE";
262 case UPGRADE_LICENSE:
263 return "UPGRADE_LICENSE";
264 case LICENSE_INFO:
265 return "LICENSE_INFO";
266 case NEW_LICENSE_REQUEST:
267 return "NEW_LICENSE_REQUEST";
268 case PLATFORM_CHALLENGE_RESPONSE:
269 return "PLATFORM_CHALLENGE_RESPONSE";
270 case ERROR_ALERT:
271 return "ERROR_ALERT";
272 default:
273 return "LICENSE_REQUEST_TYPE_UNKNOWN";
274 }
275}
276
277WINPR_ATTR_NODISCARD
278static const char* license_blob_type_string(UINT16 type)
279{
280 switch (type)
281 {
282 case BB_ANY_BLOB:
283 return "BB_ANY_BLOB";
284 case BB_DATA_BLOB:
285 return "BB_DATA_BLOB";
286 case BB_RANDOM_BLOB:
287 return "BB_RANDOM_BLOB";
288 case BB_CERTIFICATE_BLOB:
289 return "BB_CERTIFICATE_BLOB";
290 case BB_ERROR_BLOB:
291 return "BB_ERROR_BLOB";
292 case BB_ENCRYPTED_DATA_BLOB:
293 return "BB_ENCRYPTED_DATA_BLOB";
294 case BB_KEY_EXCHG_ALG_BLOB:
295 return "BB_KEY_EXCHG_ALG_BLOB";
296 case BB_SCOPE_BLOB:
297 return "BB_SCOPE_BLOB";
298 case BB_CLIENT_USER_NAME_BLOB:
299 return "BB_CLIENT_USER_NAME_BLOB";
300 case BB_CLIENT_MACHINE_NAME_BLOB:
301 return "BB_CLIENT_MACHINE_NAME_BLOB";
302 default:
303 return "BB_UNKNOWN";
304 }
305}
306
307WINPR_ATTR_NODISCARD
308static wStream* license_send_stream_init(rdpLicense* license, UINT16* sec_flags);
309
310WINPR_ATTR_NODISCARD
311static BOOL license_generate_randoms(rdpLicense* license);
312
313WINPR_ATTR_NODISCARD
314static BOOL license_generate_keys(rdpLicense* license);
315
316WINPR_ATTR_NODISCARD
317static BOOL license_generate_hwid(rdpLicense* license);
318
319WINPR_ATTR_NODISCARD
320static BOOL license_encrypt_premaster_secret(rdpLicense* license);
321
322static void license_free_product_info(LICENSE_PRODUCT_INFO* productInfo);
323
324WINPR_ATTR_MALLOC(license_free_product_info, 1)
325static LICENSE_PRODUCT_INFO* license_new_product_info(void);
326
327WINPR_ATTR_NODISCARD
328static BOOL license_read_product_info(wLog* log, wStream* s, LICENSE_PRODUCT_INFO* productInfo);
329
330static void license_free_binary_blob(LICENSE_BLOB* blob);
331
332WINPR_ATTR_MALLOC(license_free_binary_blob, 1)
333static LICENSE_BLOB* license_new_binary_blob(UINT16 type);
334
335WINPR_ATTR_NODISCARD
336static BOOL license_read_binary_blob_data(wLog* log, LICENSE_BLOB* blob, UINT16 type,
337 const void* data, size_t length);
338
339WINPR_ATTR_NODISCARD
340static BOOL license_read_binary_blob(wLog* log, wStream* s, LICENSE_BLOB* blob);
341
342WINPR_ATTR_NODISCARD
343static BOOL license_write_binary_blob(wStream* s, const LICENSE_BLOB* blob);
344
345static void license_free_scope_list(SCOPE_LIST* scopeList);
346
347WINPR_ATTR_MALLOC(license_free_scope_list, 1)
348static SCOPE_LIST* license_new_scope_list(void);
349
350WINPR_ATTR_NODISCARD
351static BOOL license_scope_list_resize(SCOPE_LIST* scopeList, UINT32 count);
352
353WINPR_ATTR_NODISCARD
354static BOOL license_read_scope_list(wLog* log, wStream* s, SCOPE_LIST* scopeList);
355
356WINPR_ATTR_NODISCARD
357static BOOL license_write_scope_list(wLog* log, wStream* s, const SCOPE_LIST* scopeList);
358
359WINPR_ATTR_NODISCARD
360static BOOL license_read_license_request_packet(rdpLicense* license, wStream* s);
361
362WINPR_ATTR_NODISCARD
363static BOOL license_write_license_request_packet(const rdpLicense* license, wStream* s);
364
365WINPR_ATTR_NODISCARD
366static BOOL license_read_platform_challenge_packet(rdpLicense* license, wStream* s);
367
368WINPR_ATTR_NODISCARD
369static BOOL license_send_platform_challenge_packet(rdpLicense* license);
370
371WINPR_ATTR_NODISCARD
372static BOOL license_read_new_or_upgrade_license_packet(rdpLicense* license, wStream* s);
373
374WINPR_ATTR_NODISCARD
375static BOOL license_read_error_alert_packet(rdpLicense* license, wStream* s);
376
377WINPR_ATTR_NODISCARD
378static BOOL license_write_new_license_request_packet(const rdpLicense* license, wStream* s);
379
380WINPR_ATTR_NODISCARD
381static BOOL license_read_new_license_request_packet(rdpLicense* license, wStream* s);
382
383WINPR_ATTR_NODISCARD
384static BOOL license_answer_license_request(rdpLicense* license);
385
386WINPR_ATTR_NODISCARD
387static BOOL license_send_platform_challenge_response(rdpLicense* license);
388
389WINPR_ATTR_NODISCARD
390static BOOL license_read_platform_challenge_response(rdpLicense* license);
391
392WINPR_ATTR_NODISCARD
393static BOOL license_read_client_platform_challenge_response(rdpLicense* license, wStream* s);
394
395WINPR_ATTR_NODISCARD
396static BOOL license_write_client_platform_challenge_response(rdpLicense* license, wStream* s);
397
398WINPR_ATTR_NODISCARD
399static BOOL license_write_server_upgrade_license(const rdpLicense* license, wStream* s);
400
401WINPR_ATTR_NODISCARD
402static BOOL license_send_license_info(rdpLicense* license, const LICENSE_BLOB* calBlob,
403 const BYTE* signature, size_t signature_length);
404
405WINPR_ATTR_NODISCARD
406static BOOL license_read_license_info(rdpLicense* license, wStream* s);
407
408WINPR_ATTR_NODISCARD
409static state_run_t license_client_recv(rdpLicense* license, wStream* s);
410
411WINPR_ATTR_NODISCARD
412static state_run_t license_server_recv(rdpLicense* license, wStream* s);
413
414#define PLATFORMID (CLIENT_OS_ID_WINNT_POST_52 | CLIENT_IMAGE_ID_MICROSOFT)
415
416#ifdef WITH_DEBUG_LICENSE
417
418WINPR_ATTR_NODISCARD
419static const char* error_codes(UINT32 idx)
420{
421#define EVCASE(x) \
422 case x: \
423 return #x
424 switch (idx)
425 {
426 EVCASE(ERR_INVALID_SERVER_CERTIFICATE);
427 EVCASE(ERR_NO_LICENSE);
428 EVCASE(ERR_INVALID_MAC);
429 EVCASE(ERR_INVALID_SCOPE);
430 EVCASE(ERR_NO_LICENSE_SERVER);
431 EVCASE(STATUS_VALID_CLIENT);
432 EVCASE(ERR_INVALID_CLIENT);
433 EVCASE(ERR_INVALID_PRODUCT_ID);
434 EVCASE(ERR_INVALID_MESSAGE_LENGTH);
435 default:
436 return "ERR_UNKNOWN";
437 }
438}
439
440WINPR_ATTR_NODISCARD
441static const char* state_transitions(UINT32 idx)
442{
443#define EVCASE(x) \
444 case x: \
445 return #x
446
447 switch (idx)
448 {
449 EVCASE(ST_TOTAL_ABORT);
450 EVCASE(ST_NO_TRANSITION);
451 EVCASE(ST_RESET_PHASE_TO_START);
452 EVCASE(ST_RESEND_LAST_MESSAGE);
453 default:
454 return "ST_UNKNOWN";
455 }
456}
457
458static void license_print_product_info(wLog* log, const LICENSE_PRODUCT_INFO* productInfo)
459{
460 char* CompanyName = nullptr;
461 char* ProductId = nullptr;
462
463 WINPR_ASSERT(productInfo);
464 WINPR_ASSERT(productInfo->pbCompanyName);
465 WINPR_ASSERT(productInfo->pbProductId);
466
467 CompanyName =
468 ConvertWCharNToUtf8Alloc(WINPR_PACKED_ALIGN_CAST(const WCHAR*, productInfo->pbCompanyName),
469 productInfo->cbCompanyName / sizeof(WCHAR), nullptr);
470 ProductId =
471 ConvertWCharNToUtf8Alloc(WINPR_PACKED_ALIGN_CAST(const WCHAR*, productInfo->pbProductId),
472 productInfo->cbProductId / sizeof(WCHAR), nullptr);
473 WLog_Print(log, WLOG_INFO, "ProductInfo:");
474 WLog_Print(log, WLOG_INFO, "\tdwVersion: 0x%08" PRIX32 "", productInfo->dwVersion);
475 WLog_Print(log, WLOG_INFO, "\tCompanyName: %s", CompanyName);
476 WLog_Print(log, WLOG_INFO, "\tProductId: %s", ProductId);
477 free(CompanyName);
478 free(ProductId);
479}
480
481static void license_print_scope_list(wLog* log, const SCOPE_LIST* scopeList)
482{
483 WINPR_ASSERT(scopeList);
484
485 WLog_Print(log, WLOG_INFO, "ScopeList (%" PRIu32 "):", scopeList->count);
486
487 for (UINT32 index = 0; index < scopeList->count; index++)
488 {
489 WINPR_ASSERT(scopeList->array);
490 const LICENSE_BLOB* scope = scopeList->array[index];
491 WINPR_ASSERT(scope);
492
493 WLog_Print(log, WLOG_INFO, "\t%.*s", (int)scope->length, (const char*)scope->data);
494 }
495}
496#endif
497
498static const char licenseStore[] = "licenses";
499
500WINPR_ATTR_NODISCARD
501static BOOL license_ensure_state(rdpLicense* license, LICENSE_STATE state, UINT32 msg)
502{
503 const LICENSE_STATE cstate = license_get_state(license);
504
505 WINPR_ASSERT(license);
506
507 if (cstate != state)
508 {
509 const char* scstate = license_get_state_string(cstate);
510 const char* sstate = license_get_state_string(state);
511 const char* where = license_request_type_string(msg);
512
513 WLog_Print(license->log, WLOG_WARN,
514 "Received [%s], but found invalid licensing state %s, expected %s", where,
515 scstate, sstate);
516 return FALSE;
517 }
518 return TRUE;
519}
520
521state_run_t license_recv(rdpLicense* license, wStream* s)
522{
523 WINPR_ASSERT(license);
524 WINPR_ASSERT(license->rdp);
525 WINPR_ASSERT(license->rdp->settings);
526
527 if (freerdp_settings_get_bool(license->rdp->settings, FreeRDP_ServerMode))
528 return license_server_recv(license, s);
529 else
530 return license_client_recv(license, s);
531}
532
533WINPR_ATTR_NODISCARD
534static BOOL license_check_stream_length(wLog* log, wStream* s, UINT64 expect, const char* where)
535{
536 const size_t remain = Stream_GetRemainingLength(s);
537
538 WINPR_ASSERT(where);
539
540 if (remain < expect)
541 {
542 WLog_Print(log, WLOG_WARN, "short %s, expected %" PRIu64 " bytes, got %" PRIuz, where,
543 expect, remain);
544 return FALSE;
545 }
546 return TRUE;
547}
548
549WINPR_ATTR_NODISCARD
550static BOOL license_check_stream_capacity(wLog* log, wStream* s, size_t expect, const char* where)
551{
552 WINPR_ASSERT(where);
553
554 return (Stream_CheckAndLogRequiredCapacityWLogEx(log, WLOG_WARN, s, expect, 1,
555 "%s(%s:%" PRIuz ") %s", __func__, __FILE__,
556 (size_t)__LINE__, where));
557}
558
559WINPR_ATTR_NODISCARD
560static BOOL computeCalHash(wLog* log, const char* hostname, char* hashStr, size_t len)
561{
562 WINPR_DIGEST_CTX* sha1 = nullptr;
563 BOOL ret = FALSE;
564 BYTE hash[20] = WINPR_C_ARRAY_INIT;
565
566 WINPR_ASSERT(hostname);
567 WINPR_ASSERT(hashStr);
568
569 if (len < 2 * sizeof(hash) + 1)
570 return FALSE;
571
572 if (!(sha1 = winpr_Digest_New()))
573 goto out;
574 if (!winpr_Digest_Init(sha1, WINPR_MD_SHA1))
575 goto out;
576 if (!winpr_Digest_Update(sha1, (const BYTE*)hostname, strlen(hostname)))
577 goto out;
578 if (!winpr_Digest_Final(sha1, hash, sizeof(hash)))
579 goto out;
580
581 for (size_t i = 0; i < sizeof(hash); i++, hashStr += 2)
582 (void)sprintf_s(hashStr, 3, "%.2x", hash[i]);
583
584 ret = TRUE;
585out:
586 if (!ret)
587 WLog_Print(log, WLOG_ERROR, "failed to generate SHA1 of hostname '%s'", hostname);
588 winpr_Digest_Free(sha1);
589 return ret;
590}
591
592WINPR_ATTR_NODISCARD
593static BOOL saveCal(wLog* log, const rdpSettings* settings, const BYTE* data, size_t length,
594 const char* hostname)
595{
596 char hash[41] = WINPR_C_ARRAY_INIT;
597 FILE* fp = nullptr;
598 char* licenseStorePath = nullptr;
599 char filename[MAX_PATH] = WINPR_C_ARRAY_INIT;
600 char filenameNew[MAX_PATH] = WINPR_C_ARRAY_INIT;
601 char* filepath = nullptr;
602 char* filepathNew = nullptr;
603
604 size_t written = 0;
605 BOOL ret = FALSE;
606 const char* path = freerdp_settings_get_string(settings, FreeRDP_ConfigPath);
607
608 WINPR_ASSERT(path);
609 WINPR_ASSERT(data || (length == 0));
610 WINPR_ASSERT(hostname);
611
612 if (!winpr_PathFileExists(path))
613 {
614 if (!winpr_PathMakePath(path, nullptr))
615 {
616 WLog_Print(log, WLOG_ERROR, "error creating directory '%s'", path);
617 goto out;
618 }
619 WLog_Print(log, WLOG_INFO, "creating directory %s", path);
620 }
621
622 if (!(licenseStorePath = GetCombinedPath(path, licenseStore)))
623 {
624 WLog_Print(log, WLOG_ERROR, "Failed to get license store path from '%s' + '%s'", path,
625 licenseStore);
626 goto out;
627 }
628
629 if (!winpr_PathFileExists(licenseStorePath))
630 {
631 if (!winpr_PathMakePath(licenseStorePath, nullptr))
632 {
633 WLog_Print(log, WLOG_ERROR, "error creating directory '%s'", licenseStorePath);
634 goto out;
635 }
636 WLog_Print(log, WLOG_INFO, "creating directory %s", licenseStorePath);
637 }
638
639 if (!computeCalHash(log, hostname, hash, sizeof(hash)))
640 goto out;
641 (void)sprintf_s(filename, sizeof(filename) - 1, "%s.cal", hash);
642 (void)sprintf_s(filenameNew, sizeof(filenameNew) - 1, "%s.cal.new", hash);
643
644 if (!(filepath = GetCombinedPath(licenseStorePath, filename)))
645 {
646 WLog_Print(log, WLOG_ERROR, "Failed to get license file path from '%s' + '%s'", path,
647 filename);
648 goto out;
649 }
650
651 if (!(filepathNew = GetCombinedPath(licenseStorePath, filenameNew)))
652 {
653 WLog_Print(log, WLOG_ERROR, "Failed to get license new file path from '%s' + '%s'", path,
654 filenameNew);
655 goto out;
656 }
657
658 fp = winpr_fopen(filepathNew, "wb");
659 if (!fp)
660 {
661 WLog_Print(log, WLOG_ERROR, "Failed to open license file '%s'", filepathNew);
662 goto out;
663 }
664
665 written = fwrite(data, length, 1, fp);
666 (void)fclose(fp);
667
668 if (written != 1)
669 {
670 WLog_Print(log, WLOG_ERROR, "Failed to write to license file '%s'", filepathNew);
671 winpr_DeleteFile(filepathNew);
672 goto out;
673 }
674
675 ret = winpr_MoveFileEx(filepathNew, filepath, MOVEFILE_REPLACE_EXISTING);
676 if (!ret)
677 WLog_Print(log, WLOG_ERROR, "Failed to move license file '%s' to '%s'", filepathNew,
678 filepath);
679
680out:
681 free(filepathNew);
682 free(filepath);
683 free(licenseStorePath);
684 return ret;
685}
686
687WINPR_ATTR_MALLOC(free, 1)
688static BYTE* loadCalFile(wLog* log, const rdpSettings* settings, const char* hostname,
689 size_t* dataLen)
690{
691 char* licenseStorePath = nullptr;
692 char* calPath = nullptr;
693 char calFilename[MAX_PATH] = WINPR_C_ARRAY_INIT;
694 char hash[41] = WINPR_C_ARRAY_INIT;
695 INT64 length = 0;
696 size_t status = 0;
697 FILE* fp = nullptr;
698 BYTE* ret = nullptr;
699
700 WINPR_ASSERT(settings);
701 WINPR_ASSERT(hostname);
702 WINPR_ASSERT(dataLen);
703
704 if (!computeCalHash(log, hostname, hash, sizeof(hash)))
705 {
706 WLog_Print(log, WLOG_ERROR, "loadCalFile: unable to compute hostname hash");
707 return nullptr;
708 }
709
710 (void)sprintf_s(calFilename, sizeof(calFilename) - 1, "%s.cal", hash);
711
712 if (!(licenseStorePath = GetCombinedPath(
713 freerdp_settings_get_string(settings, FreeRDP_ConfigPath), licenseStore)))
714 return nullptr;
715
716 if (!(calPath = GetCombinedPath(licenseStorePath, calFilename)))
717 goto error_path;
718
719 fp = winpr_fopen(calPath, "rb");
720 if (!fp)
721 goto error_open;
722
723 if (_fseeki64(fp, 0, SEEK_END) != 0)
724 goto error_malloc;
725 length = _ftelli64(fp);
726 if (_fseeki64(fp, 0, SEEK_SET) != 0)
727 goto error_malloc;
728 if (length < 0)
729 goto error_malloc;
730
731 ret = (BYTE*)malloc((size_t)length);
732 if (!ret)
733 goto error_malloc;
734
735 status = fread(ret, (size_t)length, 1, fp);
736 if (status == 0)
737 goto error_read;
738
739 *dataLen = (size_t)length;
740
741 (void)fclose(fp);
742 free(calPath);
743 free(licenseStorePath);
744 return ret;
745
746error_read:
747 free(ret);
748error_malloc:
749 fclose(fp);
750error_open:
751 free(calPath);
752error_path:
753 free(licenseStorePath);
754 return nullptr;
755}
756
766WINPR_ATTR_NODISCARD
767static BOOL license_read_preamble(wLog* log, wStream* s, BYTE* bMsgType, BYTE* flags,
768 UINT16* wMsgSize)
769{
770 WINPR_ASSERT(bMsgType);
771 WINPR_ASSERT(flags);
772 WINPR_ASSERT(wMsgSize);
773
774 /* preamble (4 bytes) */
775 if (!license_check_stream_length(log, s, 4, "license preamble"))
776 return FALSE;
777
778 Stream_Read_UINT8(s, *bMsgType); /* bMsgType (1 byte) */
779 Stream_Read_UINT8(s, *flags); /* flags (1 byte) */
780 Stream_Read_UINT16(s, *wMsgSize); /* wMsgSize (2 bytes) */
781 if (*wMsgSize < 4)
782 {
783 WLog_Print(log, WLOG_WARN,
784 "invalid license preamble::wMsgSize, expected value >= 4, got %" PRIu32,
785 *wMsgSize);
786 return FALSE;
787 }
788 return license_check_stream_length(log, s, *wMsgSize - 4ull, "license preamble::wMsgSize");
789}
790
800WINPR_ATTR_NODISCARD
801static BOOL license_write_preamble(wStream* s, BYTE bMsgType, BYTE flags, UINT16 wMsgSize)
802{
803 if (!Stream_EnsureRemainingCapacity(s, 4))
804 return FALSE;
805
806 /* preamble (4 bytes) */
807 Stream_Write_UINT8(s, bMsgType); /* bMsgType (1 byte) */
808 Stream_Write_UINT8(s, flags); /* flags (1 byte) */
809 Stream_Write_UINT16(s, wMsgSize); /* wMsgSize (2 bytes) */
810 return TRUE;
811}
812
821wStream* license_send_stream_init(rdpLicense* license, UINT16* sec_flags)
822{
823 WINPR_ASSERT(license);
824 WINPR_ASSERT(license->rdp);
825 WINPR_ASSERT(sec_flags);
826
827 const BOOL do_crypt = license->rdp->do_crypt;
828
829 *sec_flags = SEC_LICENSE_PKT;
830
831 /*
832 * Encryption of licensing packets is optional even if the rdp security
833 * layer is used. If the peer has not indicated that it is capable of
834 * processing encrypted licensing packets (rdp->do_crypt_license) we turn
835 * off encryption (via rdp->do_crypt) before initializing the rdp stream
836 * and re-enable it afterwards.
837 */
838
839 if (do_crypt)
840 {
841 *sec_flags |= SEC_LICENSE_ENCRYPT_CS;
842 license->rdp->do_crypt = license->rdp->do_crypt_license;
843 }
844
845 wStream* s = rdp_send_stream_init(license->rdp, sec_flags);
846 if (!s)
847 return nullptr;
848
849 license->rdp->do_crypt = do_crypt;
850 license->PacketHeaderLength = (UINT16)Stream_GetPosition(s);
851 if (!Stream_SafeZero(s, LICENSE_PREAMBLE_LENGTH))
852 goto fail;
853 return s;
854
855fail:
856 Stream_Release(s);
857 return nullptr;
858}
859
866WINPR_ATTR_NODISCARD
867static BOOL license_send(rdpLicense* license, wStream* s, BYTE type, UINT16 sec_flags)
868{
869 WINPR_ASSERT(license);
870 WINPR_ASSERT(license->rdp);
871
872 rdpRdp* rdp = license->rdp;
873 WINPR_ASSERT(rdp->settings);
874
875 DEBUG_LICENSE("Sending %s Packet", license_request_type_string(type));
876 const size_t length = Stream_GetPosition(s);
877 WINPR_ASSERT(length >= license->PacketHeaderLength);
878 WINPR_ASSERT(length <= UINT16_MAX + license->PacketHeaderLength);
879
880 const UINT16 wMsgSize = (UINT16)(length - license->PacketHeaderLength);
881 if (!Stream_SetPosition(s, license->PacketHeaderLength))
882 return FALSE;
883 BYTE flags = PREAMBLE_VERSION_3_0;
884
890 if (!rdp->settings->ServerMode)
891 flags |= EXTENDED_ERROR_MSG_SUPPORTED;
892
893 if (!license_write_preamble(s, type, flags, wMsgSize))
894 {
895 Stream_Release(s);
896 return FALSE;
897 }
898
899#ifdef WITH_DEBUG_LICENSE
900 WLog_Print(license->log, WLOG_DEBUG, "Sending %s Packet, length %" PRIu16 "",
901 license_request_type_string(type), wMsgSize);
902 winpr_HexLogDump(license->log, WLOG_DEBUG, Stream_PointerAs(s, char) - LICENSE_PREAMBLE_LENGTH,
903 wMsgSize);
904#endif
905 if (!Stream_SetPosition(s, length))
906 return FALSE;
907 const BOOL ret = rdp_send(rdp, s, MCS_GLOBAL_CHANNEL_ID, sec_flags);
908 return ret;
909}
910
911BOOL license_write_server_upgrade_license(const rdpLicense* license, wStream* s)
912{
913 WINPR_ASSERT(license);
914
915 if (!license_write_binary_blob(s, license->EncryptedLicenseInfo))
916 return FALSE;
917 if (!license_check_stream_capacity(license->log, s, sizeof(license->MACData),
918 "SERVER_UPGRADE_LICENSE::MACData"))
919 return FALSE;
920 Stream_Write(s, license->MACData, sizeof(license->MACData));
921 return TRUE;
922}
923
924WINPR_ATTR_NODISCARD
925static BOOL license_server_send_new_or_upgrade_license(rdpLicense* license, BOOL upgrade)
926{
927 UINT16 sec_flags = 0;
928 wStream* s = license_send_stream_init(license, &sec_flags);
929 const BYTE type = upgrade ? UPGRADE_LICENSE : NEW_LICENSE;
930
931 if (!s)
932 return FALSE;
933
934 if (!license_write_server_upgrade_license(license, s))
935 goto fail;
936
937 return license_send(license, s, type, sec_flags);
938
939fail:
940 Stream_Release(s);
941 return FALSE;
942}
943
951WINPR_ATTR_NODISCARD
952static state_run_t license_client_recv_int(rdpLicense* license, wStream* s)
953{
954 BYTE flags = 0;
955 BYTE bMsgType = 0;
956 UINT16 wMsgSize = 0;
957 const size_t length = Stream_GetRemainingLength(s);
958
959 WINPR_ASSERT(license);
960
961 if (!license_read_preamble(license->log, s, &bMsgType, &flags,
962 &wMsgSize)) /* preamble (4 bytes) */
963 return STATE_RUN_FAILED;
964
965 DEBUG_LICENSE("Receiving %s Packet", license_request_type_string(bMsgType));
966
967 switch (bMsgType)
968 {
969 case LICENSE_REQUEST:
970 /* Client does not require configuration, so skip this state */
971 if (license_get_state(license) == LICENSE_STATE_INITIAL)
972 license_set_state(license, LICENSE_STATE_CONFIGURED);
973
974 if (!license_ensure_state(license, LICENSE_STATE_CONFIGURED, bMsgType))
975 return STATE_RUN_FAILED;
976
977 if (!license_read_license_request_packet(license, s))
978 return STATE_RUN_FAILED;
979
980 if (!license_answer_license_request(license))
981 return STATE_RUN_FAILED;
982
983 license_set_state(license, LICENSE_STATE_NEW_REQUEST);
984 break;
985
986 case PLATFORM_CHALLENGE:
987 if (!license_ensure_state(license, LICENSE_STATE_NEW_REQUEST, bMsgType))
988 return STATE_RUN_FAILED;
989
990 if (!license_read_platform_challenge_packet(license, s))
991 return STATE_RUN_FAILED;
992
993 if (!license_send_platform_challenge_response(license))
994 return STATE_RUN_FAILED;
995 license_set_state(license, LICENSE_STATE_PLATFORM_CHALLENGE_RESPONSE);
996 break;
997
998 case NEW_LICENSE:
999 case UPGRADE_LICENSE:
1000 if (!license_ensure_state(license, LICENSE_STATE_PLATFORM_CHALLENGE_RESPONSE, bMsgType))
1001 return STATE_RUN_FAILED;
1002 if (!license_read_new_or_upgrade_license_packet(license, s))
1003 return STATE_RUN_FAILED;
1004 break;
1005
1006 case ERROR_ALERT:
1007 if (!license_read_error_alert_packet(license, s))
1008 return STATE_RUN_FAILED;
1009 break;
1010
1011 default:
1012 WLog_Print(license->log, WLOG_ERROR, "invalid bMsgType:%" PRIu8 "", bMsgType);
1013 return STATE_RUN_FAILED;
1014 }
1015
1016 if (!tpkt_ensure_stream_consumed(license->log, s, length))
1017 return STATE_RUN_FAILED;
1018 return STATE_RUN_SUCCESS;
1019}
1020
1021state_run_t license_client_recv(rdpLicense* license, wStream* s)
1022{
1023 state_run_t rc = license_client_recv_int(license, s);
1024 if (state_run_failed(rc))
1025 {
1026 freerdp_set_last_error(license->rdp->context, ERROR_CTX_LICENSE_CLIENT_INVALID);
1027 }
1028 return rc;
1029}
1030
1031state_run_t license_server_recv(rdpLicense* license, wStream* s)
1032{
1033 state_run_t rc = STATE_RUN_FAILED;
1034 BYTE flags = 0;
1035 BYTE bMsgType = 0;
1036 UINT16 wMsgSize = 0;
1037 const size_t length = Stream_GetRemainingLength(s);
1038
1039 WINPR_ASSERT(license);
1040
1041 if (!license_read_preamble(license->log, s, &bMsgType, &flags,
1042 &wMsgSize)) /* preamble (4 bytes) */
1043 goto fail;
1044
1045 DEBUG_LICENSE("Receiving %s Packet", license_request_type_string(bMsgType));
1046
1047 switch (bMsgType)
1048 {
1049 case NEW_LICENSE_REQUEST:
1050 if (!license_ensure_state(license, LICENSE_STATE_REQUEST, bMsgType))
1051 goto fail;
1052 if (!license_read_new_license_request_packet(license, s))
1053 goto fail;
1054 // TODO: Validate if client is allowed
1055 if (!license_send_error_alert(license, ERR_INVALID_MAC, ST_TOTAL_ABORT,
1056 license->ErrorInfo))
1057 goto fail;
1058 if (!license_send_platform_challenge_packet(license))
1059 goto fail;
1060 license->update = FALSE;
1061 license_set_state(license, LICENSE_STATE_PLATFORM_CHALLENGE);
1062 break;
1063 case LICENSE_INFO:
1064 if (!license_ensure_state(license, LICENSE_STATE_REQUEST, bMsgType))
1065 goto fail;
1066 if (!license_read_license_info(license, s))
1067 goto fail;
1068 // TODO: Validate license info
1069 if (!license_send_platform_challenge_packet(license))
1070 goto fail;
1071 license_set_state(license, LICENSE_STATE_PLATFORM_CHALLENGE);
1072 license->update = TRUE;
1073 break;
1074
1075 case PLATFORM_CHALLENGE_RESPONSE:
1076 if (!license_ensure_state(license, LICENSE_STATE_PLATFORM_CHALLENGE, bMsgType))
1077 goto fail;
1078 if (!license_read_client_platform_challenge_response(license, s))
1079 goto fail;
1080
1081 // TODO: validate challenge response
1082 if (FALSE)
1083 {
1084 if (license_send_error_alert(license, ERR_INVALID_CLIENT, ST_TOTAL_ABORT,
1085 license->ErrorInfo))
1086 goto fail;
1087 }
1088 else
1089 {
1090 if (!license_server_send_new_or_upgrade_license(license, license->update))
1091 goto fail;
1092
1093 license->type = LICENSE_TYPE_ISSUED;
1094 license_set_state(license, LICENSE_STATE_COMPLETED);
1095
1096 rc = STATE_RUN_CONTINUE; /* License issued, switch state */
1097 }
1098 break;
1099
1100 case ERROR_ALERT:
1101 if (!license_read_error_alert_packet(license, s))
1102 goto fail;
1103 break;
1104
1105 default:
1106 WLog_Print(license->log, WLOG_ERROR, "invalid bMsgType:%" PRIu8 "", bMsgType);
1107 goto fail;
1108 }
1109
1110 if (!tpkt_ensure_stream_consumed(license->log, s, length))
1111 goto fail;
1112
1113 if (!state_run_success(rc))
1114 rc = STATE_RUN_SUCCESS;
1115
1116fail:
1117 if (state_run_failed(rc))
1118 {
1119 if (flags & EXTENDED_ERROR_MSG_SUPPORTED)
1120 {
1121 if (!license_send_error_alert(license, ERR_INVALID_CLIENT, ST_TOTAL_ABORT, nullptr))
1122 {
1123 WLog_Print(license->log, WLOG_ERROR, "license_send_error_alert failed");
1124 }
1125 }
1126 license_set_state(license, LICENSE_STATE_ABORTED);
1127 }
1128
1129 return rc;
1130}
1131
1132BOOL license_generate_randoms(rdpLicense* license)
1133{
1134 WINPR_ASSERT(license);
1135
1136#ifdef LICENSE_NULL_CLIENT_RANDOM
1137 ZeroMemory(license->ClientRandom, sizeof(license->ClientRandom)); /* ClientRandom */
1138#else
1139 if (winpr_RAND(license->ClientRandom, sizeof(license->ClientRandom)) < 0) /* ClientRandom */
1140 return FALSE;
1141#endif
1142
1143 if (winpr_RAND(license->ServerRandom, sizeof(license->ServerRandom)) < 0) /* ServerRandom */
1144 return FALSE;
1145
1146#ifdef LICENSE_NULL_PREMASTER_SECRET
1147 ZeroMemory(license->PremasterSecret, sizeof(license->PremasterSecret)); /* PremasterSecret */
1148#else
1149 if (winpr_RAND(license->PremasterSecret, sizeof(license->PremasterSecret)) <
1150 0) /* PremasterSecret */
1151 return FALSE;
1152#endif
1153 return TRUE;
1154}
1155
1160WINPR_ATTR_NODISCARD
1161static BOOL license_generate_keys(rdpLicense* license)
1162{
1163 WINPR_ASSERT(license);
1164
1165 if (
1166 /* MasterSecret */
1167 !security_master_secret(license->PremasterSecret, sizeof(license->PremasterSecret),
1168 license->ClientRandom, sizeof(license->ClientRandom),
1169 license->ServerRandom, sizeof(license->ServerRandom),
1170 license->MasterSecret, sizeof(license->MasterSecret)) ||
1171 /* SessionKeyBlob */
1172 !security_session_key_blob(license->MasterSecret, sizeof(license->MasterSecret),
1173 license->ClientRandom, sizeof(license->ClientRandom),
1174 license->ServerRandom, sizeof(license->ServerRandom),
1175 license->SessionKeyBlob, sizeof(license->SessionKeyBlob)))
1176 {
1177 return FALSE;
1178 }
1179 security_mac_salt_key(license->SessionKeyBlob, sizeof(license->SessionKeyBlob),
1180 license->ClientRandom, sizeof(license->ClientRandom),
1181 license->ServerRandom, sizeof(license->ServerRandom), license->MacSaltKey,
1182 sizeof(license->MacSaltKey)); /* MacSaltKey */
1183 const BOOL ret = security_licensing_encryption_key(
1184 license->SessionKeyBlob, sizeof(license->SessionKeyBlob), license->ClientRandom,
1185 sizeof(license->ClientRandom), license->ServerRandom, sizeof(license->ServerRandom),
1186 license->LicensingEncryptionKey,
1187 sizeof(license->LicensingEncryptionKey)); /* LicensingEncryptionKey */
1188
1189 WLog_Print(license->log, WLOG_TRACE, "license keys %s generated", ret ? "successfully" : "NOT");
1190
1191#ifdef WITH_DEBUG_LICENSE
1192 WLog_Print(license->log, WLOG_DEBUG, "ClientRandom:");
1193 winpr_HexLogDump(license->log, WLOG_DEBUG, license->ClientRandom,
1194 sizeof(license->ClientRandom));
1195 WLog_Print(license->log, WLOG_DEBUG, "ServerRandom:");
1196 winpr_HexLogDump(license->log, WLOG_DEBUG, license->ServerRandom,
1197 sizeof(license->ServerRandom));
1198 WLog_Print(license->log, WLOG_DEBUG, "PremasterSecret:");
1199 winpr_HexLogDump(license->log, WLOG_DEBUG, license->PremasterSecret,
1200 sizeof(license->PremasterSecret));
1201 WLog_Print(license->log, WLOG_DEBUG, "MasterSecret:");
1202 winpr_HexLogDump(license->log, WLOG_DEBUG, license->MasterSecret,
1203 sizeof(license->MasterSecret));
1204 WLog_Print(license->log, WLOG_DEBUG, "SessionKeyBlob:");
1205 winpr_HexLogDump(license->log, WLOG_DEBUG, license->SessionKeyBlob,
1206 sizeof(license->SessionKeyBlob));
1207 WLog_Print(license->log, WLOG_DEBUG, "MacSaltKey:");
1208 winpr_HexLogDump(license->log, WLOG_DEBUG, license->MacSaltKey, sizeof(license->MacSaltKey));
1209 WLog_Print(license->log, WLOG_DEBUG, "LicensingEncryptionKey:");
1210 winpr_HexLogDump(license->log, WLOG_DEBUG, license->LicensingEncryptionKey,
1211 sizeof(license->LicensingEncryptionKey));
1212#endif
1213 return ret;
1214}
1215
1221BOOL license_generate_hwid(rdpLicense* license)
1222{
1223 const BYTE* hashTarget = nullptr;
1224 size_t targetLen = 0;
1225 BYTE macAddress[6] = WINPR_C_ARRAY_INIT;
1226
1227 WINPR_ASSERT(license);
1228 WINPR_ASSERT(license->rdp);
1229 WINPR_ASSERT(license->rdp->settings);
1230
1231 ZeroMemory(license->HardwareId, sizeof(license->HardwareId));
1232
1233 if (license->rdp->settings->OldLicenseBehaviour)
1234 {
1235 hashTarget = macAddress;
1236 targetLen = sizeof(macAddress);
1237 }
1238 else
1239 {
1240 wStream buffer = WINPR_C_ARRAY_INIT;
1241 const char* hostname = license->rdp->settings->ClientHostname;
1242 wStream* s = Stream_StaticInit(&buffer, license->HardwareId, 4);
1243 Stream_Write_UINT32(s, license->PlatformId);
1244
1245 hashTarget = (const BYTE*)hostname;
1246 targetLen = hostname ? strlen(hostname) : 0;
1247 }
1248
1249 /* Allow FIPS override for use of MD5 here, really this does not have to be MD5 as we are just
1250 * taking a MD5 hash of the 6 bytes of 0's(macAddress) */
1251 /* and filling in the Data1-Data4 fields of the CLIENT_HARDWARE_ID structure(from MS-RDPELE
1252 * section 2.2.2.3.1). This is for RDP licensing packets */
1253 /* which will already be encrypted under FIPS, so the use of MD5 here is not for sensitive data
1254 * protection. */
1255 return winpr_Digest_Allow_FIPS(WINPR_MD_MD5, hashTarget, targetLen,
1256 &license->HardwareId[HWID_PLATFORM_ID_LENGTH],
1257 WINPR_MD5_DIGEST_LENGTH);
1258}
1259
1260WINPR_ATTR_NODISCARD
1261static BOOL license_get_server_rsa_public_key(rdpLicense* license)
1262{
1263 rdpSettings* settings = nullptr;
1264
1265 WINPR_ASSERT(license);
1266 WINPR_ASSERT(license->certificate);
1267 WINPR_ASSERT(license->rdp);
1268
1269 settings = license->rdp->settings;
1270 WINPR_ASSERT(settings);
1271
1272 if (license->ServerCertificate->length < 1)
1273 {
1274 if (!freerdp_certificate_read_server_cert(license->certificate, settings->ServerCertificate,
1275 settings->ServerCertificateLength))
1276 return FALSE;
1277 }
1278
1279 return TRUE;
1280}
1281
1282BOOL license_encrypt_premaster_secret(rdpLicense* license)
1283{
1284 WINPR_ASSERT(license);
1285 WINPR_ASSERT(license->certificate);
1286
1287 if (!license_get_server_rsa_public_key(license))
1288 return FALSE;
1289
1290 WINPR_ASSERT(license->EncryptedPremasterSecret);
1291
1292 const rdpCertInfo* info = freerdp_certificate_get_info(license->certificate);
1293 if (!info)
1294 {
1295 WLog_Print(license->log, WLOG_ERROR, "info=%p, license->certificate=%p", (const void*)info,
1296 (void*)license->certificate);
1297 return FALSE;
1298 }
1299
1300#ifdef WITH_DEBUG_LICENSE
1301 WLog_Print(license->log, WLOG_DEBUG, "Modulus (%" PRIu32 " bits):", info->ModulusLength * 8);
1302 winpr_HexLogDump(license->log, WLOG_DEBUG, info->Modulus, info->ModulusLength);
1303 WLog_Print(license->log, WLOG_DEBUG, "Exponent:");
1304 winpr_HexLogDump(license->log, WLOG_DEBUG, info->exponent, sizeof(info->exponent));
1305#endif
1306
1307 BYTE* EncryptedPremasterSecret = (BYTE*)calloc(1, info->ModulusLength);
1308 if (!EncryptedPremasterSecret)
1309 {
1310 WLog_Print(license->log, WLOG_ERROR,
1311 "EncryptedPremasterSecret=%p, info->ModulusLength=%" PRIu32,
1312 (const void*)EncryptedPremasterSecret, info->ModulusLength);
1313 return FALSE;
1314 }
1315
1316 license->EncryptedPremasterSecret->type = BB_RANDOM_BLOB;
1317 license->EncryptedPremasterSecret->length = sizeof(license->PremasterSecret);
1318#ifndef LICENSE_NULL_PREMASTER_SECRET
1319 {
1320 const SSIZE_T length =
1321 crypto_rsa_public_encrypt(license->PremasterSecret, sizeof(license->PremasterSecret),
1322 info, EncryptedPremasterSecret, info->ModulusLength);
1323 if ((length < 0) || (length > UINT16_MAX))
1324 {
1325 WLog_Print(license->log, WLOG_ERROR, "RSA public encrypt length=%" PRIdz " < 0 || > %d",
1326 length, UINT16_MAX);
1327 return FALSE;
1328 }
1329 license->EncryptedPremasterSecret->length = (UINT16)length;
1330 }
1331#endif
1332 license->EncryptedPremasterSecret->data = EncryptedPremasterSecret;
1333 return TRUE;
1334}
1335
1336WINPR_ATTR_NODISCARD
1337static BOOL license_rc4_with_licenseKey(const rdpLicense* license, const BYTE* input, size_t len,
1338 LICENSE_BLOB* target)
1339{
1340 WINPR_ASSERT(license);
1341 WINPR_ASSERT(input || (len == 0));
1342 WINPR_ASSERT(target);
1343 WINPR_ASSERT(len <= UINT16_MAX);
1344
1345 WINPR_RC4_CTX* rc4 = winpr_RC4_New_Allow_FIPS(license->LicensingEncryptionKey,
1346 sizeof(license->LicensingEncryptionKey));
1347 if (!rc4)
1348 {
1349 WLog_Print(license->log, WLOG_ERROR, "Failed to allocate RC4");
1350 return FALSE;
1351 }
1352
1353 BYTE* buffer = nullptr;
1354 if (len > 0)
1355 buffer = realloc(target->data, len);
1356 if (!buffer)
1357 goto error_buffer;
1358
1359 target->data = buffer;
1360 target->length = (UINT16)len;
1361
1362 if (!winpr_RC4_Update(rc4, len, input, buffer))
1363 goto error_buffer;
1364
1365 winpr_RC4_Free(rc4);
1366 return TRUE;
1367
1368error_buffer:
1369 WLog_Print(license->log, WLOG_ERROR, "Failed to create/update RC4: len=%" PRIuz ", buffer=%p",
1370 len, (const void*)buffer);
1371 winpr_RC4_Free(rc4);
1372 return FALSE;
1373}
1374
1386WINPR_ATTR_NODISCARD
1387static BOOL license_encrypt_and_MAC(rdpLicense* license, const BYTE* input, size_t len,
1388 LICENSE_BLOB* target, BYTE* mac, size_t mac_length)
1389{
1390 WINPR_ASSERT(license);
1391 return license_rc4_with_licenseKey(license, input, len, target) &&
1392 security_mac_data(license->MacSaltKey, sizeof(license->MacSaltKey), input, len, mac,
1393 mac_length);
1394}
1395
1407WINPR_ATTR_NODISCARD
1408static BOOL license_decrypt_and_check_MAC(rdpLicense* license, const BYTE* input, size_t len,
1409 LICENSE_BLOB* target, const BYTE* packetMac)
1410{
1411 BYTE macData[sizeof(license->MACData)] = WINPR_C_ARRAY_INIT;
1412
1413 WINPR_ASSERT(license);
1414 WINPR_ASSERT(target);
1415
1416 if (freerdp_settings_get_bool(license->rdp->settings, FreeRDP_TransportDumpReplay))
1417 {
1418 WLog_Print(license->log, WLOG_DEBUG, "TransportDumpReplay active, skipping...");
1419 return TRUE;
1420 }
1421
1422 if (!license_rc4_with_licenseKey(license, input, len, target))
1423 return FALSE;
1424
1425 if (!security_mac_data(license->MacSaltKey, sizeof(license->MacSaltKey), target->data, len,
1426 macData, sizeof(macData)))
1427 return FALSE;
1428
1429 if (memcmp(packetMac, macData, sizeof(macData)) != 0)
1430 {
1431 WLog_Print(license->log, WLOG_ERROR, "packetMac != expectedMac");
1432 return FALSE;
1433 }
1434 return TRUE;
1435}
1436
1444BOOL license_read_product_info(wLog* log, wStream* s, LICENSE_PRODUCT_INFO* productInfo)
1445{
1446 WINPR_ASSERT(productInfo);
1447
1448 if (!license_check_stream_length(log, s, 8, "license product info::cbCompanyName"))
1449 return FALSE;
1450
1451 Stream_Read_UINT32(s, productInfo->dwVersion); /* dwVersion (4 bytes) */
1452 Stream_Read_UINT32(s, productInfo->cbCompanyName); /* cbCompanyName (4 bytes) */
1453
1454 /* Name must be >0, but there is no upper limit defined, use UINT32_MAX */
1455 if ((productInfo->cbCompanyName < 2) || (productInfo->cbCompanyName % 2 != 0))
1456 {
1457 WLog_Print(log, WLOG_WARN, "license product info invalid cbCompanyName %" PRIu32,
1458 productInfo->cbCompanyName);
1459 return FALSE;
1460 }
1461
1462 if (!license_check_stream_length(log, s, productInfo->cbCompanyName,
1463 "license product info::CompanyName"))
1464 return FALSE;
1465
1466 productInfo->pbProductId = nullptr;
1467 productInfo->pbCompanyName = (BYTE*)malloc(productInfo->cbCompanyName);
1468 if (!productInfo->pbCompanyName)
1469 goto out_fail;
1470 Stream_Read(s, productInfo->pbCompanyName, productInfo->cbCompanyName);
1471
1472 if (!license_check_stream_length(log, s, 4, "license product info::cbProductId"))
1473 goto out_fail;
1474
1475 Stream_Read_UINT32(s, productInfo->cbProductId); /* cbProductId (4 bytes) */
1476
1477 if ((productInfo->cbProductId < 2) || (productInfo->cbProductId % 2 != 0))
1478 {
1479 WLog_Print(log, WLOG_WARN, "license product info invalid cbProductId %" PRIu32,
1480 productInfo->cbProductId);
1481 goto out_fail;
1482 }
1483
1484 if (!license_check_stream_length(log, s, productInfo->cbProductId,
1485 "license product info::ProductId"))
1486 goto out_fail;
1487
1488 productInfo->pbProductId = (BYTE*)malloc(productInfo->cbProductId);
1489 if (!productInfo->pbProductId)
1490 goto out_fail;
1491 Stream_Read(s, productInfo->pbProductId, productInfo->cbProductId);
1492 return TRUE;
1493
1494out_fail:
1495 free(productInfo->pbCompanyName);
1496 free(productInfo->pbProductId);
1497 productInfo->pbCompanyName = nullptr;
1498 productInfo->pbProductId = nullptr;
1499 return FALSE;
1500}
1501
1502WINPR_ATTR_NODISCARD
1503static BOOL license_write_product_info(wLog* log, wStream* s,
1504 const LICENSE_PRODUCT_INFO* productInfo)
1505{
1506 WINPR_ASSERT(productInfo);
1507
1508 if (!license_check_stream_capacity(log, s, 8, "license product info::cbCompanyName"))
1509 return FALSE;
1510
1511 Stream_Write_UINT32(s, productInfo->dwVersion); /* dwVersion (4 bytes) */
1512 Stream_Write_UINT32(s, productInfo->cbCompanyName); /* cbCompanyName (4 bytes) */
1513
1514 /* Name must be >0, but there is no upper limit defined, use UINT32_MAX */
1515 if ((productInfo->cbCompanyName < 2) || (productInfo->cbCompanyName % 2 != 0) ||
1516 !productInfo->pbCompanyName)
1517 {
1518 WLog_Print(log, WLOG_WARN, "license product info invalid cbCompanyName %" PRIu32,
1519 productInfo->cbCompanyName);
1520 return FALSE;
1521 }
1522
1523 if (!license_check_stream_capacity(log, s, productInfo->cbCompanyName,
1524 "license product info::CompanyName"))
1525 return FALSE;
1526
1527 Stream_Write(s, productInfo->pbCompanyName, productInfo->cbCompanyName);
1528
1529 if (!license_check_stream_capacity(log, s, 4, "license product info::cbProductId"))
1530 return FALSE;
1531
1532 Stream_Write_UINT32(s, productInfo->cbProductId); /* cbProductId (4 bytes) */
1533
1534 if ((productInfo->cbProductId < 2) || (productInfo->cbProductId % 2 != 0) ||
1535 !productInfo->pbProductId)
1536 {
1537 WLog_Print(log, WLOG_WARN, "license product info invalid cbProductId %" PRIu32,
1538 productInfo->cbProductId);
1539 return FALSE;
1540 }
1541
1542 if (!license_check_stream_capacity(log, s, productInfo->cbProductId,
1543 "license product info::ProductId"))
1544 return FALSE;
1545
1546 Stream_Write(s, productInfo->pbProductId, productInfo->cbProductId);
1547 return TRUE;
1548}
1549
1556LICENSE_PRODUCT_INFO* license_new_product_info(void)
1557{
1558 LICENSE_PRODUCT_INFO* productInfo =
1559 (LICENSE_PRODUCT_INFO*)calloc(1, sizeof(LICENSE_PRODUCT_INFO));
1560 if (!productInfo)
1561 return nullptr;
1562 return productInfo;
1563}
1564
1571void license_free_product_info(LICENSE_PRODUCT_INFO* productInfo)
1572{
1573 if (productInfo)
1574 {
1575 free(productInfo->pbCompanyName);
1576 free(productInfo->pbProductId);
1577 free(productInfo);
1578 }
1579}
1580
1581BOOL license_read_binary_blob_data(wLog* log, LICENSE_BLOB* blob, UINT16 wBlobType,
1582 const void* data, size_t length)
1583{
1584 WINPR_ASSERT(blob);
1585 WINPR_ASSERT(length <= UINT16_MAX);
1586 WINPR_ASSERT(data || (length == 0));
1587
1588 blob->length = (UINT16)length;
1589 free(blob->data);
1590 blob->data = nullptr;
1591
1592 if ((blob->type != wBlobType) && (blob->type != BB_ANY_BLOB))
1593 {
1594 WLog_Print(log, WLOG_ERROR, "license binary blob::type expected %s, got %s",
1595 license_blob_type_string(wBlobType), license_blob_type_string(blob->type));
1596 }
1597
1598 /*
1599 * Server can choose to not send data by setting length to 0.
1600 * If so, it may not bother to set the type, so shortcut the warning
1601 */
1602 if ((blob->type != BB_ANY_BLOB) && (blob->length == 0))
1603 {
1604 WLog_Print(log, WLOG_DEBUG, "license binary blob::type %s, length=0, skipping.",
1605 license_blob_type_string(blob->type));
1606 return TRUE;
1607 }
1608
1609 blob->type = wBlobType;
1610 blob->data = nullptr;
1611 if (blob->length > 0)
1612 blob->data = malloc(blob->length);
1613 if (!blob->data)
1614 {
1615 WLog_Print(log, WLOG_ERROR, "license binary blob::length=%" PRIu16 ", blob::data=%p",
1616 blob->length, (const void*)blob->data);
1617 return FALSE;
1618 }
1619 memcpy(blob->data, data, blob->length); /* blobData */
1620 return TRUE;
1621}
1622
1630BOOL license_read_binary_blob(wLog* log, wStream* s, LICENSE_BLOB* blob)
1631{
1632 UINT16 wBlobType = 0;
1633 UINT16 length = 0;
1634
1635 WINPR_ASSERT(blob);
1636
1637 if (!license_check_stream_length(log, s, 4, "license binary blob::type"))
1638 return FALSE;
1639
1640 Stream_Read_UINT16(s, wBlobType); /* wBlobType (2 bytes) */
1641 Stream_Read_UINT16(s, length); /* wBlobLen (2 bytes) */
1642
1643 if (!license_check_stream_length(log, s, length, "license binary blob::length"))
1644 return FALSE;
1645
1646 if (!license_read_binary_blob_data(log, blob, wBlobType, Stream_Pointer(s), length))
1647 return FALSE;
1648
1649 return Stream_SafeSeek(s, length);
1650}
1651
1659BOOL license_write_binary_blob(wStream* s, const LICENSE_BLOB* blob)
1660{
1661 WINPR_ASSERT(blob);
1662
1663 if (!Stream_EnsureRemainingCapacity(s, blob->length + 4ull))
1664 return FALSE;
1665
1666 Stream_Write_UINT16(s, blob->type); /* wBlobType (2 bytes) */
1667 Stream_Write_UINT16(s, blob->length); /* wBlobLen (2 bytes) */
1668
1669 if (blob->length > 0)
1670 Stream_Write(s, blob->data, blob->length); /* blobData */
1671 return TRUE;
1672}
1673
1674WINPR_ATTR_NODISCARD
1675static BOOL license_write_encrypted_premaster_secret_blob(wLog* log, wStream* s,
1676 const LICENSE_BLOB* blob,
1677 UINT32 ModulusLength)
1678{
1679 const UINT32 length = ModulusLength + 8;
1680
1681 WINPR_ASSERT(blob);
1682 WINPR_ASSERT(length <= UINT16_MAX);
1683
1684 if (blob->length > ModulusLength)
1685 {
1686 WLog_Print(log, WLOG_ERROR, "invalid blob");
1687 return FALSE;
1688 }
1689
1690 if (!Stream_EnsureRemainingCapacity(s, length + 4ull))
1691 return FALSE;
1692 Stream_Write_UINT16(s, blob->type); /* wBlobType (2 bytes) */
1693 Stream_Write_UINT16(s, (UINT16)length); /* wBlobLen (2 bytes) */
1694
1695 if (blob->length > 0)
1696 Stream_Write(s, blob->data, blob->length); /* blobData */
1697
1698 Stream_Zero(s, length - blob->length);
1699 return TRUE;
1700}
1701
1702WINPR_ATTR_NODISCARD
1703static BOOL license_read_encrypted_premaster_secret_blob(wLog* log, wStream* s, LICENSE_BLOB* blob,
1704 UINT32* ModulusLength)
1705{
1706 if (!license_read_binary_blob(log, s, blob))
1707 return FALSE;
1708 WINPR_ASSERT(ModulusLength);
1709 *ModulusLength = blob->length;
1710 return TRUE;
1711}
1712
1719LICENSE_BLOB* license_new_binary_blob(UINT16 type)
1720{
1721 LICENSE_BLOB* blob = (LICENSE_BLOB*)calloc(1, sizeof(LICENSE_BLOB));
1722 if (blob)
1723 blob->type = type;
1724 return blob;
1725}
1726
1733void license_free_binary_blob(LICENSE_BLOB* blob)
1734{
1735 if (blob)
1736 {
1737 free(blob->data);
1738 free(blob);
1739 }
1740}
1741
1749BOOL license_read_scope_list(wLog* log, wStream* s, SCOPE_LIST* scopeList)
1750{
1751 UINT32 scopeCount = 0;
1752
1753 WINPR_ASSERT(scopeList);
1754
1755 if (!license_check_stream_length(log, s, 4, "license scope list"))
1756 return FALSE;
1757
1758 Stream_Read_UINT32(s, scopeCount); /* ScopeCount (4 bytes) */
1759
1760 if (!license_check_stream_length(log, s, 4ull * scopeCount, "license scope list::count"))
1761 return FALSE;
1762
1763 if (!license_scope_list_resize(scopeList, scopeCount))
1764 return FALSE;
1765 /* ScopeArray */
1766 for (UINT32 i = 0; i < scopeCount; i++)
1767 {
1768 if (!license_read_binary_blob(log, s, scopeList->array[i]))
1769 return FALSE;
1770 }
1771
1772 return TRUE;
1773}
1774
1775BOOL license_write_scope_list(wLog* log, wStream* s, const SCOPE_LIST* scopeList)
1776{
1777 WINPR_ASSERT(scopeList);
1778
1779 if (!license_check_stream_capacity(log, s, 4, "license scope list"))
1780 return FALSE;
1781
1782 Stream_Write_UINT32(s, scopeList->count); /* ScopeCount (4 bytes) */
1783
1784 if (!license_check_stream_capacity(log, s, scopeList->count * 4ull,
1785 "license scope list::count"))
1786 return FALSE;
1787
1788 /* ScopeArray */
1789 WINPR_ASSERT(scopeList->array || (scopeList->count == 0));
1790 for (UINT32 i = 0; i < scopeList->count; i++)
1791 {
1792 const LICENSE_BLOB* element = scopeList->array[i];
1793
1794 if (!license_write_binary_blob(s, element))
1795 return FALSE;
1796 }
1797
1798 return TRUE;
1799}
1800
1807SCOPE_LIST* license_new_scope_list(void)
1808{
1809 SCOPE_LIST* list = calloc(1, sizeof(SCOPE_LIST));
1810 return list;
1811}
1812
1813static void license_scope_list_free(SCOPE_LIST* scopeList, UINT32 count)
1814{
1815 WINPR_ASSERT(scopeList);
1816 WINPR_ASSERT(scopeList->array || (scopeList->count == 0));
1817
1818 for (UINT32 x = count; x < scopeList->count; x++)
1819 {
1820 license_free_binary_blob(scopeList->array[x]);
1821 scopeList->array[x] = nullptr;
1822 }
1823
1824 if (count == 0)
1825 {
1826 free((void*)scopeList->array);
1827 scopeList->array = nullptr;
1828 }
1829}
1830
1831BOOL license_scope_list_resize(SCOPE_LIST* scopeList, UINT32 count)
1832{
1833 license_scope_list_free(scopeList, count);
1834 if (count > 0)
1835 {
1836 LICENSE_BLOB** tmp =
1837 (LICENSE_BLOB**)realloc((void*)scopeList->array, count * sizeof(LICENSE_BLOB*));
1838 if (!tmp)
1839 return FALSE;
1840 scopeList->array = tmp;
1841 }
1842
1843 for (UINT32 x = scopeList->count; x < count; x++)
1844 {
1845 LICENSE_BLOB* blob = license_new_binary_blob(BB_SCOPE_BLOB);
1846 if (!blob)
1847 {
1848 scopeList->count = x;
1849 return FALSE;
1850 }
1851 scopeList->array[x] = blob;
1852 }
1853
1854 scopeList->count = count;
1855 return TRUE;
1856}
1857
1864void license_free_scope_list(SCOPE_LIST* scopeList)
1865{
1866 if (!scopeList)
1867 return;
1868
1869 license_scope_list_free(scopeList, 0);
1870 free(scopeList);
1871}
1872
1873BOOL license_send_license_info(rdpLicense* license, const LICENSE_BLOB* calBlob,
1874 const BYTE* signature, size_t signature_length)
1875{
1876 WINPR_ASSERT(calBlob);
1877 WINPR_ASSERT(signature);
1878 WINPR_ASSERT(license->certificate);
1879
1880 const rdpCertInfo* info = freerdp_certificate_get_info(license->certificate);
1881 if (!info)
1882 return FALSE;
1883
1884 UINT16 sec_flags = 0;
1885 wStream* s = license_send_stream_init(license, &sec_flags);
1886 if (!s)
1887 return FALSE;
1888
1889 if (!license_check_stream_capacity(license->log, s, 8 + sizeof(license->ClientRandom),
1890 "license info::ClientRandom"))
1891 goto error;
1892
1893 Stream_Write_UINT32(s,
1894 license->PreferredKeyExchangeAlg); /* PreferredKeyExchangeAlg (4 bytes) */
1895 Stream_Write_UINT32(s, license->PlatformId); /* PlatformId (4 bytes) */
1896
1897 /* ClientRandom (32 bytes) */
1898 Stream_Write(s, license->ClientRandom, sizeof(license->ClientRandom));
1899
1900 /* Licensing Binary Blob with EncryptedPreMasterSecret: */
1901 if (!license_write_encrypted_premaster_secret_blob(
1902 license->log, s, license->EncryptedPremasterSecret, info->ModulusLength))
1903 goto error;
1904
1905 /* Licensing Binary Blob with LicenseInfo: */
1906 if (!license_write_binary_blob(s, calBlob))
1907 goto error;
1908
1909 /* Licensing Binary Blob with EncryptedHWID */
1910 if (!license_write_binary_blob(s, license->EncryptedHardwareId))
1911 goto error;
1912
1913 /* MACData */
1914 if (!license_check_stream_capacity(license->log, s, signature_length, "license info::MACData"))
1915 goto error;
1916 Stream_Write(s, signature, signature_length);
1917
1918 return license_send(license, s, LICENSE_INFO, sec_flags);
1919
1920error:
1921 Stream_Release(s);
1922 return FALSE;
1923}
1924
1925WINPR_ATTR_NODISCARD
1926static BOOL license_check_preferred_alg(rdpLicense* license, UINT32 PreferredKeyExchangeAlg,
1927 const char* where)
1928{
1929 WINPR_ASSERT(license);
1930 WINPR_ASSERT(where);
1931
1932 if (license->PreferredKeyExchangeAlg != PreferredKeyExchangeAlg)
1933 {
1934 char buffer1[64] = WINPR_C_ARRAY_INIT;
1935 char buffer2[64] = WINPR_C_ARRAY_INIT;
1936 WLog_Print(license->log, WLOG_WARN, "%s::PreferredKeyExchangeAlg, expected %s, got %s",
1937 where,
1938 license_preferred_key_exchange_alg_string(license->PreferredKeyExchangeAlg,
1939 buffer1, sizeof(buffer1)),
1940 license_preferred_key_exchange_alg_string(PreferredKeyExchangeAlg, buffer2,
1941 sizeof(buffer2)));
1942 return FALSE;
1943 }
1944 return TRUE;
1945}
1946
1947BOOL license_read_license_info(rdpLicense* license, wStream* s)
1948{
1949 BOOL rc = FALSE;
1950 UINT32 PreferredKeyExchangeAlg = 0;
1951
1952 WINPR_ASSERT(license);
1953 WINPR_ASSERT(license->certificate);
1954
1955 const rdpCertInfo* info = freerdp_certificate_get_info(license->certificate);
1956 if (!info)
1957 goto error;
1958
1959 /* ClientRandom (32 bytes) */
1960 if (!license_check_stream_length(license->log, s, 8 + sizeof(license->ClientRandom),
1961 "license info"))
1962 goto error;
1963
1964 Stream_Read_UINT32(s, PreferredKeyExchangeAlg); /* PreferredKeyExchangeAlg (4 bytes) */
1965 if (!license_check_preferred_alg(license, PreferredKeyExchangeAlg, "license info"))
1966 goto error;
1967 Stream_Read_UINT32(s, license->PlatformId); /* PlatformId (4 bytes) */
1968
1969 /* ClientRandom (32 bytes) */
1970 Stream_Read(s, license->ClientRandom, sizeof(license->ClientRandom));
1971
1972 /* Licensing Binary Blob with EncryptedPreMasterSecret: */
1973 {
1974 UINT32 ModulusLength = 0;
1975 if (!license_read_encrypted_premaster_secret_blob(
1976 license->log, s, license->EncryptedPremasterSecret, &ModulusLength))
1977 goto error;
1978
1979 if (ModulusLength != info->ModulusLength)
1980 {
1981 WLog_Print(license->log, WLOG_WARN,
1982 "EncryptedPremasterSecret,::ModulusLength[%" PRIu32
1983 "] != rdpCertInfo::ModulusLength[%" PRIu32 "]",
1984 ModulusLength, info->ModulusLength);
1985 goto error;
1986 }
1987 }
1988
1989 /* Licensing Binary Blob with LicenseInfo: */
1990 if (!license_read_binary_blob(license->log, s, license->LicenseInfo))
1991 goto error;
1992
1993 /* Licensing Binary Blob with EncryptedHWID */
1994 if (!license_read_binary_blob(license->log, s, license->EncryptedHardwareId))
1995 goto error;
1996
1997 /* MACData */
1998 if (!license_check_stream_length(license->log, s, sizeof(license->MACData),
1999 "license info::MACData"))
2000 goto error;
2001 Stream_Read(s, license->MACData, sizeof(license->MACData));
2002
2003 rc = TRUE;
2004
2005error:
2006 return rc;
2007}
2008
2016BOOL license_read_license_request_packet(rdpLicense* license, wStream* s)
2017{
2018 WINPR_ASSERT(license);
2019
2020 /* ServerRandom (32 bytes) */
2021 if (!license_check_stream_length(license->log, s, sizeof(license->ServerRandom),
2022 "license request"))
2023 return FALSE;
2024
2025 Stream_Read(s, license->ServerRandom, sizeof(license->ServerRandom));
2026
2027 /* ProductInfo */
2028 if (!license_read_product_info(license->log, s, license->ProductInfo))
2029 return FALSE;
2030
2031 /* KeyExchangeList */
2032 if (!license_read_binary_blob(license->log, s, license->KeyExchangeList))
2033 return FALSE;
2034
2035 /* ServerCertificate */
2036 if (!license_read_binary_blob(license->log, s, license->ServerCertificate))
2037 return FALSE;
2038
2039 /* ScopeList */
2040 if (!license_read_scope_list(license->log, s, license->ScopeList))
2041 return FALSE;
2042
2043 /* Parse Server Certificate */
2044 if (!freerdp_certificate_read_server_cert(license->certificate,
2045 license->ServerCertificate->data,
2046 license->ServerCertificate->length))
2047 return FALSE;
2048
2049 if (!license_generate_keys(license) || !license_generate_hwid(license) ||
2050 !license_encrypt_premaster_secret(license))
2051 return FALSE;
2052
2053#ifdef WITH_DEBUG_LICENSE
2054 WLog_Print(license->log, WLOG_DEBUG, "ServerRandom:");
2055 winpr_HexLogDump(license->log, WLOG_DEBUG, license->ServerRandom,
2056 sizeof(license->ServerRandom));
2057 license_print_product_info(license->log, license->ProductInfo);
2058 license_print_scope_list(license->log, license->ScopeList);
2059#endif
2060 return TRUE;
2061}
2062
2063BOOL license_write_license_request_packet(const rdpLicense* license, wStream* s)
2064{
2065 WINPR_ASSERT(license);
2066
2067 /* ServerRandom (32 bytes) */
2068 if (!license_check_stream_capacity(license->log, s, sizeof(license->ServerRandom),
2069 "license request"))
2070 return FALSE;
2071 Stream_Write(s, license->ServerRandom, sizeof(license->ServerRandom));
2072
2073 /* ProductInfo */
2074 if (!license_write_product_info(license->log, s, license->ProductInfo))
2075 return FALSE;
2076
2077 /* KeyExchangeList */
2078 if (!license_write_binary_blob(s, license->KeyExchangeList))
2079 return FALSE;
2080
2081 /* ServerCertificate */
2082 if (!license_write_binary_blob(s, license->ServerCertificate))
2083 return FALSE;
2084
2085 /* ScopeList */
2086 if (!license_write_scope_list(license->log, s, license->ScopeList))
2087 return FALSE;
2088
2089 return TRUE;
2090}
2091
2092WINPR_ATTR_NODISCARD
2093static BOOL license_send_license_request_packet(rdpLicense* license)
2094{
2095 UINT16 sec_flags = 0;
2096 wStream* s = license_send_stream_init(license, &sec_flags);
2097 if (!s)
2098 return FALSE;
2099
2100 if (!license_write_license_request_packet(license, s))
2101 goto fail;
2102
2103 return license_send(license, s, LICENSE_REQUEST, sec_flags);
2104
2105fail:
2106 Stream_Release(s);
2107 return FALSE;
2108}
2109
2110/*
2111 * Read a PLATFORM_CHALLENGE packet.
2112 * msdn{cc241921}
2113 * @param license license module
2114 * @param s stream
2115 */
2116
2117BOOL license_read_platform_challenge_packet(rdpLicense* license, wStream* s)
2118{
2119 BYTE macData[LICENSING_ENCRYPTION_KEY_LENGTH] = WINPR_C_ARRAY_INIT;
2120
2121 WINPR_ASSERT(license);
2122
2123 DEBUG_LICENSE("Receiving Platform Challenge Packet");
2124
2125 if (!license_check_stream_length(license->log, s, 4, "license platform challenge"))
2126 return FALSE;
2127
2128 /* [MS-RDPELE] 2.2.2.4 Server Platform Challenge (SERVER_PLATFORM_CHALLENGE)
2129 * reserved field */
2130 Stream_Seek_UINT32(s); /* ConnectFlags, Reserved (4 bytes) */
2131
2132 /* EncryptedPlatformChallenge */
2133 license->EncryptedPlatformChallenge->type = BB_ANY_BLOB;
2134 if (!license_read_binary_blob(license->log, s, license->EncryptedPlatformChallenge))
2135 return FALSE;
2136 license->EncryptedPlatformChallenge->type = BB_ENCRYPTED_DATA_BLOB;
2137
2138 /* MACData (16 bytes) */
2139 if (!license_check_stream_length(license->log, s, sizeof(macData),
2140 "license platform challenge::MAC"))
2141 return FALSE;
2142
2143 Stream_Read(s, macData, sizeof(macData));
2144 if (!license_decrypt_and_check_MAC(license, license->EncryptedPlatformChallenge->data,
2145 license->EncryptedPlatformChallenge->length,
2146 license->PlatformChallenge, macData))
2147 return FALSE;
2148
2149 WLog_Print(license->log, WLOG_TRACE, "platform challenge read");
2150
2151#ifdef WITH_DEBUG_LICENSE
2152 WLog_Print(license->log, WLOG_DEBUG, "EncryptedPlatformChallenge:");
2153 winpr_HexLogDump(license->log, WLOG_DEBUG, license->EncryptedPlatformChallenge->data,
2154 license->EncryptedPlatformChallenge->length);
2155 WLog_Print(license->log, WLOG_DEBUG, "PlatformChallenge:");
2156 winpr_HexLogDump(license->log, WLOG_DEBUG, license->PlatformChallenge->data,
2157 license->PlatformChallenge->length);
2158 WLog_Print(license->log, WLOG_DEBUG, "MacData:");
2159 winpr_HexLogDump(license->log, WLOG_DEBUG, macData, sizeof(macData));
2160#endif
2161 return TRUE;
2162}
2163
2164BOOL license_send_error_alert(rdpLicense* license, UINT32 dwErrorCode, UINT32 dwStateTransition,
2165 const LICENSE_BLOB* info)
2166{
2167 UINT16 sec_flags = 0;
2168 wStream* s = license_send_stream_init(license, &sec_flags);
2169
2170 if (!s)
2171 goto fail;
2172
2173 if (!license_check_stream_capacity(license->log, s, 8, "license error alert"))
2174 goto fail;
2175 Stream_Write_UINT32(s, dwErrorCode);
2176 Stream_Write_UINT32(s, dwStateTransition);
2177
2178 if (info)
2179 {
2180 if (!license_write_binary_blob(s, info))
2181 goto fail;
2182 }
2183
2184 return license_send(license, s, ERROR_ALERT, sec_flags);
2185fail:
2186 Stream_Release(s);
2187 return FALSE;
2188}
2189
2190BOOL license_send_platform_challenge_packet(rdpLicense* license)
2191{
2192 UINT16 sec_flags = 0;
2193 wStream* s = license_send_stream_init(license, &sec_flags);
2194
2195 if (!s)
2196 goto fail;
2197
2198 DEBUG_LICENSE("Receiving Platform Challenge Packet");
2199
2200 if (!license_check_stream_capacity(license->log, s, 4, "license platform challenge"))
2201 goto fail;
2202
2203 Stream_Zero(s, 4); /* ConnectFlags, Reserved (4 bytes) */
2204
2205 /* EncryptedPlatformChallenge */
2206 if (!license_write_binary_blob(s, license->EncryptedPlatformChallenge))
2207 goto fail;
2208
2209 /* MACData (16 bytes) */
2210 if (!license_check_stream_length(license->log, s, sizeof(license->MACData),
2211 "license platform challenge::MAC"))
2212 goto fail;
2213
2214 Stream_Write(s, license->MACData, sizeof(license->MACData));
2215
2216 return license_send(license, s, PLATFORM_CHALLENGE, sec_flags);
2217fail:
2218 Stream_Release(s);
2219 return FALSE;
2220}
2221
2222WINPR_ATTR_NODISCARD
2223static BOOL license_read_encrypted_blob(const rdpLicense* license, wStream* s, LICENSE_BLOB* target)
2224{
2225 UINT16 wBlobType = 0;
2226 UINT16 wBlobLen = 0;
2227
2228 WINPR_ASSERT(license);
2229 WINPR_ASSERT(target);
2230
2231 if (!license_check_stream_length(license->log, s, 4, "license encrypted blob"))
2232 return FALSE;
2233
2234 Stream_Read_UINT16(s, wBlobType);
2235 if (wBlobType != BB_ENCRYPTED_DATA_BLOB)
2236 {
2237 WLog_Print(
2238 license->log, WLOG_WARN,
2239 "expecting BB_ENCRYPTED_DATA_BLOB blob, probably a windows 2003 server, continuing...");
2240 }
2241
2242 Stream_Read_UINT16(s, wBlobLen);
2243
2244 BYTE* encryptedData = Stream_Pointer(s);
2245 if (!Stream_SafeSeek(s, wBlobLen))
2246 {
2247 WLog_Print(license->log, WLOG_WARN,
2248 "short license encrypted blob::length, expected %" PRIu16 " bytes, got %" PRIuz,
2249 wBlobLen, Stream_GetRemainingLength(s));
2250 return FALSE;
2251 }
2252
2253 return license_rc4_with_licenseKey(license, encryptedData, wBlobLen, target);
2254}
2255
2263BOOL license_read_new_or_upgrade_license_packet(rdpLicense* license, wStream* s)
2264{
2265 UINT32 os_major = 0;
2266 UINT32 os_minor = 0;
2267 UINT32 cbScope = 0;
2268 UINT32 cbCompanyName = 0;
2269 UINT32 cbProductId = 0;
2270 UINT32 cbLicenseInfo = 0;
2271 wStream sbuffer = WINPR_C_ARRAY_INIT;
2272 wStream* licenseStream = nullptr;
2273 BOOL ret = FALSE;
2274 BYTE computedMac[16] = WINPR_C_ARRAY_INIT;
2275 const BYTE* readMac = nullptr;
2276
2277 WINPR_ASSERT(license);
2278
2279 DEBUG_LICENSE("Receiving Server New/Upgrade License Packet");
2280
2281 LICENSE_BLOB* calBlob = license_new_binary_blob(BB_DATA_BLOB);
2282 if (!calBlob)
2283 return FALSE;
2284
2285 /* EncryptedLicenseInfo */
2286 if (!license_read_encrypted_blob(license, s, calBlob))
2287 goto fail;
2288
2289 /* compute MAC and check it */
2290 readMac = Stream_Pointer(s);
2291 if (!Stream_SafeSeek(s, sizeof(computedMac)))
2292 {
2293 WLog_Print(license->log, WLOG_WARN,
2294 "short license new/upgrade, expected 16 bytes, got %" PRIuz,
2295 Stream_GetRemainingLength(s));
2296 goto fail;
2297 }
2298
2299 if (!security_mac_data(license->MacSaltKey, sizeof(license->MacSaltKey), calBlob->data,
2300 calBlob->length, computedMac, sizeof(computedMac)))
2301 goto fail;
2302
2303 if (memcmp(computedMac, readMac, sizeof(computedMac)) != 0)
2304 {
2305 WLog_Print(license->log, WLOG_ERROR, "new or upgrade license MAC mismatch");
2306 goto fail;
2307 }
2308
2309 licenseStream = Stream_StaticConstInit(&sbuffer, calBlob->data, calBlob->length);
2310 if (!licenseStream)
2311 {
2312 WLog_Print(license->log, WLOG_ERROR,
2313 "license::blob::data=%p, license::blob::length=%" PRIu16,
2314 (const void*)calBlob->data, calBlob->length);
2315 goto fail;
2316 }
2317
2318 if (!license_check_stream_length(license->log, licenseStream, 8,
2319 "license new/upgrade::blob::version"))
2320 goto fail;
2321
2322 Stream_Read_UINT16(licenseStream, os_minor);
2323 Stream_Read_UINT16(licenseStream, os_major);
2324
2325 WLog_Print(license->log, WLOG_DEBUG, "Version: %" PRIu16 ".%" PRIu16, os_major, os_minor);
2326
2327 /* Scope */
2328 Stream_Read_UINT32(licenseStream, cbScope);
2329 if (!license_check_stream_length(license->log, licenseStream, cbScope,
2330 "license new/upgrade::blob::scope"))
2331 goto fail;
2332
2333#ifdef WITH_DEBUG_LICENSE
2334 WLog_Print(license->log, WLOG_DEBUG, "Scope:");
2335 winpr_HexLogDump(license->log, WLOG_DEBUG, Stream_Pointer(licenseStream), cbScope);
2336#endif
2337 Stream_Seek(licenseStream, cbScope);
2338
2339 /* CompanyName */
2340 if (!license_check_stream_length(license->log, licenseStream, 4,
2341 "license new/upgrade::blob::cbCompanyName"))
2342 goto fail;
2343
2344 Stream_Read_UINT32(licenseStream, cbCompanyName);
2345 if (!license_check_stream_length(license->log, licenseStream, cbCompanyName,
2346 "license new/upgrade::blob::CompanyName"))
2347 goto fail;
2348
2349#ifdef WITH_DEBUG_LICENSE
2350 WLog_Print(license->log, WLOG_DEBUG, "Company name:");
2351 winpr_HexLogDump(license->log, WLOG_DEBUG, Stream_Pointer(licenseStream), cbCompanyName);
2352#endif
2353 Stream_Seek(licenseStream, cbCompanyName);
2354
2355 /* productId */
2356 if (!license_check_stream_length(license->log, licenseStream, 4,
2357 "license new/upgrade::blob::cbProductId"))
2358 goto fail;
2359
2360 Stream_Read_UINT32(licenseStream, cbProductId);
2361
2362 if (!license_check_stream_length(license->log, licenseStream, cbProductId,
2363 "license new/upgrade::blob::ProductId"))
2364 goto fail;
2365
2366#ifdef WITH_DEBUG_LICENSE
2367 WLog_Print(license->log, WLOG_DEBUG, "Product id:");
2368 winpr_HexLogDump(license->log, WLOG_DEBUG, Stream_Pointer(licenseStream), cbProductId);
2369#endif
2370 Stream_Seek(licenseStream, cbProductId);
2371
2372 /* licenseInfo */
2373 if (!license_check_stream_length(license->log, licenseStream, 4,
2374 "license new/upgrade::blob::cbLicenseInfo"))
2375 goto fail;
2376
2377 Stream_Read_UINT32(licenseStream, cbLicenseInfo);
2378 if (!license_check_stream_length(license->log, licenseStream, cbLicenseInfo,
2379 "license new/upgrade::blob::LicenseInfo"))
2380 goto fail;
2381
2382 license->type = LICENSE_TYPE_ISSUED;
2383 license_set_state(license, LICENSE_STATE_COMPLETED);
2384 ret = TRUE;
2385
2386 if (!license->rdp->settings->OldLicenseBehaviour)
2387 ret = saveCal(license->log, license->rdp->settings, Stream_Pointer(licenseStream),
2388 cbLicenseInfo, license->rdp->settings->ClientHostname);
2389
2390fail:
2391 license_free_binary_blob(calBlob);
2392 return ret;
2393}
2394
2402BOOL license_read_error_alert_packet(rdpLicense* license, wStream* s)
2403{
2404 UINT32 dwErrorCode = 0;
2405 UINT32 dwStateTransition = 0;
2406
2407 WINPR_ASSERT(license);
2408 WINPR_ASSERT(license->rdp);
2409
2410 if (!license_check_stream_length(license->log, s, 8ul, "error alert"))
2411 return FALSE;
2412
2413 Stream_Read_UINT32(s, dwErrorCode); /* dwErrorCode (4 bytes) */
2414 Stream_Read_UINT32(s, dwStateTransition); /* dwStateTransition (4 bytes) */
2415
2416 if (!license_read_binary_blob(license->log, s, license->ErrorInfo)) /* bbErrorInfo */
2417 return FALSE;
2418
2419#ifdef WITH_DEBUG_LICENSE
2420 WLog_Print(license->log, WLOG_DEBUG, "dwErrorCode: %s, dwStateTransition: %s",
2421 error_codes(dwErrorCode), state_transitions(dwStateTransition));
2422#endif
2423
2424 if (dwErrorCode == STATUS_VALID_CLIENT)
2425 {
2426 license->type = LICENSE_TYPE_NONE;
2427 license_set_state(license, LICENSE_STATE_COMPLETED);
2428 return TRUE;
2429 }
2430
2431 switch (dwStateTransition)
2432 {
2433 case ST_TOTAL_ABORT:
2434 license_set_state(license, LICENSE_STATE_ABORTED);
2435 break;
2436 case ST_NO_TRANSITION:
2437 license_set_state(license, LICENSE_STATE_COMPLETED);
2438 break;
2439 case ST_RESET_PHASE_TO_START:
2440 license_set_state(license, LICENSE_STATE_CONFIGURED);
2441 break;
2442 case ST_RESEND_LAST_MESSAGE:
2443 break;
2444 default:
2445 break;
2446 }
2447
2448 return TRUE;
2449}
2450
2458BOOL license_write_new_license_request_packet(const rdpLicense* license, wStream* s)
2459{
2460 WINPR_ASSERT(license);
2461
2462 const rdpCertInfo* info = freerdp_certificate_get_info(license->certificate);
2463 if (!info)
2464 return FALSE;
2465
2466 if (!license_check_stream_capacity(license->log, s, 8 + sizeof(license->ClientRandom),
2467 "License Request"))
2468 return FALSE;
2469
2470 Stream_Write_UINT32(s,
2471 license->PreferredKeyExchangeAlg); /* PreferredKeyExchangeAlg (4 bytes) */
2472 Stream_Write_UINT32(s, license->PlatformId); /* PlatformId (4 bytes) */
2473 Stream_Write(s, license->ClientRandom,
2474 sizeof(license->ClientRandom)); /* ClientRandom (32 bytes) */
2475
2476 if (/* EncryptedPremasterSecret */
2477 !license_write_encrypted_premaster_secret_blob(
2478 license->log, s, license->EncryptedPremasterSecret, info->ModulusLength) ||
2479 /* ClientUserName */
2480 !license_write_binary_blob(s, license->ClientUserName) ||
2481 /* ClientMachineName */
2482 !license_write_binary_blob(s, license->ClientMachineName))
2483 {
2484 return FALSE;
2485 }
2486
2487 WLog_Print(license->log, WLOG_TRACE, "new license written");
2488
2489#ifdef WITH_DEBUG_LICENSE
2490 WLog_Print(license->log, WLOG_DEBUG, "PreferredKeyExchangeAlg: 0x%08" PRIX32 "",
2491 license->PreferredKeyExchangeAlg);
2492 WLog_Print(license->log, WLOG_DEBUG, "ClientRandom:");
2493 winpr_HexLogDump(license->log, WLOG_DEBUG, license->ClientRandom,
2494 sizeof(license->ClientRandom));
2495 WLog_Print(license->log, WLOG_DEBUG, "EncryptedPremasterSecret");
2496 winpr_HexLogDump(license->log, WLOG_DEBUG, license->EncryptedPremasterSecret->data,
2497 license->EncryptedPremasterSecret->length);
2498 WLog_Print(license->log, WLOG_DEBUG, "ClientUserName (%" PRIu16 "): %s",
2499 license->ClientUserName->length, (char*)license->ClientUserName->data);
2500 WLog_Print(license->log, WLOG_DEBUG, "ClientMachineName (%" PRIu16 "): %s",
2501 license->ClientMachineName->length, (char*)license->ClientMachineName->data);
2502#endif
2503 return TRUE;
2504}
2505
2506BOOL license_read_new_license_request_packet(rdpLicense* license, wStream* s)
2507{
2508 UINT32 PreferredKeyExchangeAlg = 0;
2509
2510 WINPR_ASSERT(license);
2511
2512 if (!license_check_stream_length(license->log, s, 8ull + sizeof(license->ClientRandom),
2513 "new license request"))
2514 return FALSE;
2515
2516 Stream_Read_UINT32(s, PreferredKeyExchangeAlg); /* PreferredKeyExchangeAlg (4 bytes) */
2517 if (!license_check_preferred_alg(license, PreferredKeyExchangeAlg, "new license request"))
2518 return FALSE;
2519
2520 Stream_Read_UINT32(s, license->PlatformId); /* PlatformId (4 bytes) */
2521 Stream_Read(s, license->ClientRandom,
2522 sizeof(license->ClientRandom)); /* ClientRandom (32 bytes) */
2523
2524 /* EncryptedPremasterSecret */
2525 UINT32 ModulusLength = 0;
2526 if (!license_read_encrypted_premaster_secret_blob(
2527 license->log, s, license->EncryptedPremasterSecret, &ModulusLength))
2528 return FALSE;
2529
2530 const rdpCertInfo* info = freerdp_certificate_get_info(license->certificate);
2531 if (!info)
2532 WLog_Print(license->log, WLOG_WARN,
2533 "Missing license certificate, skipping ModulusLength checks");
2534 else if (ModulusLength != info->ModulusLength)
2535 {
2536 WLog_Print(license->log, WLOG_WARN,
2537 "EncryptedPremasterSecret expected to be %" PRIu32 " bytes, but read %" PRIu32
2538 " bytes",
2539 info->ModulusLength, ModulusLength);
2540 return FALSE;
2541 }
2542
2543 /* ClientUserName */
2544 if (!license_read_binary_blob(license->log, s, license->ClientUserName))
2545 return FALSE;
2546 /* ClientMachineName */
2547 if (!license_read_binary_blob(license->log, s, license->ClientMachineName))
2548 return FALSE;
2549
2550 return TRUE;
2551}
2552
2559BOOL license_answer_license_request(rdpLicense* license)
2560{
2561 UINT16 sec_flags = 0;
2562 wStream* s = nullptr;
2563 BYTE* license_data = nullptr;
2564 size_t license_size = 0;
2565 BOOL status = 0;
2566 char* username = nullptr;
2567
2568 WINPR_ASSERT(license);
2569 WINPR_ASSERT(license->rdp);
2570 WINPR_ASSERT(license->rdp->settings);
2571
2572 if (!license->rdp->settings->OldLicenseBehaviour)
2573 license_data = loadCalFile(license->log, license->rdp->settings,
2574 license->rdp->settings->ClientHostname, &license_size);
2575
2576 if (license_data)
2577 {
2578 LICENSE_BLOB* calBlob = nullptr;
2579 BYTE signature[LICENSING_ENCRYPTION_KEY_LENGTH] = WINPR_C_ARRAY_INIT;
2580
2581 DEBUG_LICENSE("Sending Saved License Packet");
2582
2583 WINPR_ASSERT(license->EncryptedHardwareId);
2584 license->EncryptedHardwareId->type = BB_ENCRYPTED_DATA_BLOB;
2585 if (!license_encrypt_and_MAC(license, license->HardwareId, sizeof(license->HardwareId),
2586 license->EncryptedHardwareId, signature, sizeof(signature)))
2587 {
2588 free(license_data);
2589 return FALSE;
2590 }
2591
2592 calBlob = license_new_binary_blob(BB_DATA_BLOB);
2593 if (!calBlob)
2594 {
2595 free(license_data);
2596 return FALSE;
2597 }
2598 calBlob->data = license_data;
2599 WINPR_ASSERT(license_size <= UINT16_MAX);
2600 calBlob->length = (UINT16)license_size;
2601
2602 status = license_send_license_info(license, calBlob, signature, sizeof(signature));
2603 license_free_binary_blob(calBlob);
2604
2605 return status;
2606 }
2607
2608 DEBUG_LICENSE("Sending New License Packet");
2609
2610 s = license_send_stream_init(license, &sec_flags);
2611 if (!s)
2612 return FALSE;
2613 if (license->rdp->settings->Username != nullptr)
2614 username = license->rdp->settings->Username;
2615 else
2616 username = "username";
2617
2618 {
2619 WINPR_ASSERT(license->ClientUserName);
2620 const size_t len = strlen(username) + 1;
2621 WINPR_ASSERT(len <= UINT16_MAX);
2622
2623 license->ClientUserName->data = (BYTE*)username;
2624 license->ClientUserName->length = (UINT16)len;
2625 }
2626
2627 {
2628 WINPR_ASSERT(license->ClientMachineName);
2629 const size_t len = strlen(license->rdp->settings->ClientHostname) + 1;
2630 WINPR_ASSERT(len <= UINT16_MAX);
2631
2632 license->ClientMachineName->data = (BYTE*)license->rdp->settings->ClientHostname;
2633 license->ClientMachineName->length = (UINT16)len;
2634 }
2635 status = license_write_new_license_request_packet(license, s);
2636
2637 WINPR_ASSERT(license->ClientUserName);
2638 license->ClientUserName->data = nullptr;
2639 license->ClientUserName->length = 0;
2640
2641 WINPR_ASSERT(license->ClientMachineName);
2642 license->ClientMachineName->data = nullptr;
2643 license->ClientMachineName->length = 0;
2644
2645 if (!status)
2646 {
2647 Stream_Release(s);
2648 return FALSE;
2649 }
2650
2651 return license_send(license, s, NEW_LICENSE_REQUEST, sec_flags);
2652}
2653
2660BOOL license_send_platform_challenge_response(rdpLicense* license)
2661{
2662 wStream* challengeRespData = nullptr;
2663 BYTE* buffer = nullptr;
2664 BOOL status = 0;
2665
2666 WINPR_ASSERT(license);
2667 WINPR_ASSERT(license->PlatformChallenge);
2668 WINPR_ASSERT(license->MacSaltKey);
2669 WINPR_ASSERT(license->EncryptedPlatformChallenge);
2670 WINPR_ASSERT(license->EncryptedHardwareId);
2671
2672 DEBUG_LICENSE("Sending Platform Challenge Response Packet");
2673
2674 license->EncryptedPlatformChallenge->type = BB_DATA_BLOB;
2675
2676 /* prepare the PLATFORM_CHALLENGE_RESPONSE_DATA */
2677 challengeRespData = Stream_New(nullptr, 8 + license->PlatformChallenge->length);
2678 if (!challengeRespData)
2679 return FALSE;
2680 Stream_Write_UINT16(challengeRespData, PLATFORM_CHALLENGE_RESPONSE_VERSION); /* wVersion */
2681 Stream_Write_UINT16(challengeRespData, license->ClientType); /* wClientType */
2682 Stream_Write_UINT16(challengeRespData, license->LicenseDetailLevel); /* wLicenseDetailLevel */
2683 Stream_Write_UINT16(challengeRespData, license->PlatformChallenge->length); /* cbChallenge */
2684 Stream_Write(challengeRespData, license->PlatformChallenge->data,
2685 license->PlatformChallenge->length); /* pbChallenge */
2686 Stream_SealLength(challengeRespData);
2687
2688 /* compute MAC of PLATFORM_CHALLENGE_RESPONSE_DATA + HWID */
2689 const size_t length = Stream_Length(challengeRespData) + sizeof(license->HardwareId);
2690 buffer = (BYTE*)malloc(length);
2691 if (!buffer)
2692 {
2693 Stream_Free(challengeRespData, TRUE);
2694 return FALSE;
2695 }
2696
2697 CopyMemory(buffer, Stream_Buffer(challengeRespData), Stream_Length(challengeRespData));
2698 CopyMemory(&buffer[Stream_Length(challengeRespData)], license->HardwareId,
2699 sizeof(license->HardwareId));
2700 status = security_mac_data(license->MacSaltKey, sizeof(license->MacSaltKey), buffer, length,
2701 license->MACData, sizeof(license->MACData));
2702 free(buffer);
2703
2704 if (!status)
2705 {
2706 Stream_Free(challengeRespData, TRUE);
2707 return FALSE;
2708 }
2709
2710 license->EncryptedHardwareId->type = BB_ENCRYPTED_DATA_BLOB;
2711 if (!license_rc4_with_licenseKey(license, license->HardwareId, sizeof(license->HardwareId),
2712 license->EncryptedHardwareId))
2713 {
2714 Stream_Free(challengeRespData, TRUE);
2715 return FALSE;
2716 }
2717
2718 status = license_rc4_with_licenseKey(license, Stream_Buffer(challengeRespData),
2719 Stream_Length(challengeRespData),
2720 license->EncryptedPlatformChallengeResponse);
2721 Stream_Free(challengeRespData, TRUE);
2722 if (!status)
2723 return FALSE;
2724
2725#ifdef WITH_DEBUG_LICENSE
2726 WLog_Print(license->log, WLOG_DEBUG, "LicensingEncryptionKey:");
2727 winpr_HexLogDump(license->log, WLOG_DEBUG, license->LicensingEncryptionKey, 16);
2728 WLog_Print(license->log, WLOG_DEBUG, "HardwareId:");
2729 winpr_HexLogDump(license->log, WLOG_DEBUG, license->HardwareId, sizeof(license->HardwareId));
2730 WLog_Print(license->log, WLOG_DEBUG, "EncryptedHardwareId:");
2731 winpr_HexLogDump(license->log, WLOG_DEBUG, license->EncryptedHardwareId->data,
2732 license->EncryptedHardwareId->length);
2733#endif
2734 UINT16 sec_flags = 0;
2735 wStream* s = license_send_stream_init(license, &sec_flags);
2736 if (!s)
2737 return FALSE;
2738
2739 if (license_write_client_platform_challenge_response(license, s))
2740 return license_send(license, s, PLATFORM_CHALLENGE_RESPONSE, sec_flags);
2741
2742 Stream_Release(s);
2743 return FALSE;
2744}
2745
2746BOOL license_read_platform_challenge_response(WINPR_ATTR_UNUSED rdpLicense* license)
2747{
2748 WINPR_ASSERT(license);
2749 WINPR_ASSERT(license->PlatformChallenge);
2750 WINPR_ASSERT(license->MacSaltKey);
2751 WINPR_ASSERT(license->EncryptedPlatformChallenge);
2752 WINPR_ASSERT(license->EncryptedHardwareId);
2753
2754 DEBUG_LICENSE("Receiving Platform Challenge Response Packet");
2755
2756#if defined(WITH_LICENSE_DECRYPT_CHALLENGE_RESPONSE)
2757 BOOL rc = FALSE;
2758 LICENSE_BLOB* dblob = license_new_binary_blob(BB_ANY_BLOB);
2759 if (!dblob)
2760 return FALSE;
2761
2762 wStream sbuffer = WINPR_C_ARRAY_INIT;
2763 UINT16 wVersion = 0;
2764 UINT16 cbChallenge = 0;
2765 const BYTE* pbChallenge = nullptr;
2766 LICENSE_BLOB* blob = license->EncryptedPlatformChallengeResponse;
2767
2768 if (!license_rc4_with_licenseKey(license, blob->data, blob->length, dblob))
2769 goto fail;
2770
2771 wStream* s = Stream_StaticConstInit(&sbuffer, dblob->data, dblob->length);
2772 if (!license_check_stream_length(s, 8, "PLATFORM_CHALLENGE_RESPONSE_DATA"))
2773 goto fail;
2774
2775 Stream_Read_UINT16(s, wVersion);
2776 if (wVersion != PLATFORM_CHALLENGE_RESPONSE_VERSION)
2777 {
2778 WLog_Print(license->log, WLOG_WARN,
2779 "Invalid PLATFORM_CHALLENGE_RESPONSE_DATA::wVersion 0x%04" PRIx16
2780 ", expected 0x04" PRIx16,
2781 wVersion, PLATFORM_CHALLENGE_RESPONSE_VERSION);
2782 goto fail;
2783 }
2784 Stream_Read_UINT16(s, license->ClientType);
2785 Stream_Read_UINT16(s, license->LicenseDetailLevel);
2786 Stream_Read_UINT16(s, cbChallenge);
2787
2788 if (!license_check_stream_length(s, cbChallenge,
2789 "PLATFORM_CHALLENGE_RESPONSE_DATA::pbChallenge"))
2790 goto fail;
2791
2792 pbChallenge = Stream_Pointer(s);
2793 if (!license_read_binary_blob_data(license->PlatformChallengeResponse, BB_DATA_BLOB,
2794 pbChallenge, cbChallenge))
2795 goto fail;
2796 if (!Stream_SafeSeek(s, cbChallenge))
2797 goto fail;
2798
2799 rc = TRUE;
2800fail:
2801 license_free_binary_blob(dblob);
2802 return rc;
2803#else
2804 return TRUE;
2805#endif
2806}
2807
2808BOOL license_write_client_platform_challenge_response(rdpLicense* license, wStream* s)
2809{
2810 WINPR_ASSERT(license);
2811
2812 if (!license_write_binary_blob(s, license->EncryptedPlatformChallengeResponse))
2813 return FALSE;
2814 if (!license_write_binary_blob(s, license->EncryptedHardwareId))
2815 return FALSE;
2816 if (!license_check_stream_capacity(license->log, s, sizeof(license->MACData),
2817 "CLIENT_PLATFORM_CHALLENGE_RESPONSE::MACData"))
2818 return FALSE;
2819 Stream_Write(s, license->MACData, sizeof(license->MACData));
2820 return TRUE;
2821}
2822
2823BOOL license_read_client_platform_challenge_response(rdpLicense* license, wStream* s)
2824{
2825 WINPR_ASSERT(license);
2826
2827 if (!license_read_binary_blob(license->log, s, license->EncryptedPlatformChallengeResponse))
2828 return FALSE;
2829 if (!license_read_binary_blob(license->log, s, license->EncryptedHardwareId))
2830 return FALSE;
2831 if (!license_check_stream_length(license->log, s, sizeof(license->MACData),
2832 "CLIENT_PLATFORM_CHALLENGE_RESPONSE::MACData"))
2833 return FALSE;
2834 Stream_Read(s, license->MACData, sizeof(license->MACData));
2835 return license_read_platform_challenge_response(license);
2836}
2837
2847BOOL license_send_valid_client_error_packet(rdpRdp* rdp)
2848{
2849 WINPR_ASSERT(rdp);
2850 rdpLicense* license = rdp->license;
2851 WINPR_ASSERT(license);
2852
2853 license->state = LICENSE_STATE_COMPLETED;
2854 license->type = LICENSE_TYPE_NONE;
2855 return license_send_error_alert(license, STATUS_VALID_CLIENT, ST_NO_TRANSITION,
2856 license->ErrorInfo);
2857}
2858
2865rdpLicense* license_new(rdpRdp* rdp)
2866{
2867 WINPR_ASSERT(rdp);
2868
2869 rdpLicense* license = (rdpLicense*)calloc(1, sizeof(rdpLicense));
2870 if (!license)
2871 return nullptr;
2872 license->log = WLog_Get(LICENSE_TAG);
2873 WINPR_ASSERT(license->log);
2874
2875 license->PlatformId = PLATFORMID;
2876 license->ClientType = OTHER_PLATFORM_CHALLENGE_TYPE;
2877 license->LicenseDetailLevel = LICENSE_DETAIL_DETAIL;
2878 license->PreferredKeyExchangeAlg = KEY_EXCHANGE_ALG_RSA;
2879 license->rdp = rdp;
2880
2881 license_set_state(license, LICENSE_STATE_INITIAL);
2882 if (!(license->certificate = freerdp_certificate_new()))
2883 goto out_error;
2884 if (!(license->ProductInfo = license_new_product_info()))
2885 goto out_error;
2886 if (!(license->ErrorInfo = license_new_binary_blob(BB_ERROR_BLOB)))
2887 goto out_error;
2888 if (!(license->LicenseInfo = license_new_binary_blob(BB_DATA_BLOB)))
2889 goto out_error;
2890 if (!(license->KeyExchangeList = license_new_binary_blob(BB_KEY_EXCHG_ALG_BLOB)))
2891 goto out_error;
2892 if (!(license->ServerCertificate = license_new_binary_blob(BB_CERTIFICATE_BLOB)))
2893 goto out_error;
2894 if (!(license->ClientUserName = license_new_binary_blob(BB_CLIENT_USER_NAME_BLOB)))
2895 goto out_error;
2896 if (!(license->ClientMachineName = license_new_binary_blob(BB_CLIENT_MACHINE_NAME_BLOB)))
2897 goto out_error;
2898 if (!(license->PlatformChallenge = license_new_binary_blob(BB_ANY_BLOB)))
2899 goto out_error;
2900 if (!(license->PlatformChallengeResponse = license_new_binary_blob(BB_ANY_BLOB)))
2901 goto out_error;
2902 if (!(license->EncryptedPlatformChallenge = license_new_binary_blob(BB_ANY_BLOB)))
2903 goto out_error;
2904 if (!(license->EncryptedPlatformChallengeResponse =
2905 license_new_binary_blob(BB_ENCRYPTED_DATA_BLOB)))
2906 goto out_error;
2907 if (!(license->EncryptedPremasterSecret = license_new_binary_blob(BB_ANY_BLOB)))
2908 goto out_error;
2909 if (!(license->EncryptedHardwareId = license_new_binary_blob(BB_ENCRYPTED_DATA_BLOB)))
2910 goto out_error;
2911 if (!(license->EncryptedLicenseInfo = license_new_binary_blob(BB_ENCRYPTED_DATA_BLOB)))
2912 goto out_error;
2913 if (!(license->ScopeList = license_new_scope_list()))
2914 goto out_error;
2915
2916 if (!license_generate_randoms(license))
2917 goto out_error;
2918
2919 return license;
2920
2921out_error:
2922 WINPR_PRAGMA_DIAG_PUSH
2923 WINPR_PRAGMA_DIAG_IGNORED_MISMATCHED_DEALLOC
2924 license_free(license);
2925 WINPR_PRAGMA_DIAG_POP
2926 return nullptr;
2927}
2928
2934void license_free(rdpLicense* license)
2935{
2936 if (license)
2937 {
2938 freerdp_certificate_free(license->certificate);
2939 license_free_product_info(license->ProductInfo);
2940 license_free_binary_blob(license->ErrorInfo);
2941 license_free_binary_blob(license->LicenseInfo);
2942 license_free_binary_blob(license->KeyExchangeList);
2943 license_free_binary_blob(license->ServerCertificate);
2944 license_free_binary_blob(license->ClientUserName);
2945 license_free_binary_blob(license->ClientMachineName);
2946 license_free_binary_blob(license->PlatformChallenge);
2947 license_free_binary_blob(license->PlatformChallengeResponse);
2948 license_free_binary_blob(license->EncryptedPlatformChallenge);
2949 license_free_binary_blob(license->EncryptedPlatformChallengeResponse);
2950 license_free_binary_blob(license->EncryptedPremasterSecret);
2951 license_free_binary_blob(license->EncryptedHardwareId);
2952 license_free_binary_blob(license->EncryptedLicenseInfo);
2953 license_free_scope_list(license->ScopeList);
2954 free(license);
2955 }
2956}
2957
2958LICENSE_STATE license_get_state(const rdpLicense* license)
2959{
2960 WINPR_ASSERT(license);
2961 return license->state;
2962}
2963
2964LICENSE_TYPE license_get_type(const rdpLicense* license)
2965{
2966 WINPR_ASSERT(license);
2967 return license->type;
2968}
2969
2970void license_set_state(rdpLicense* license, LICENSE_STATE state)
2971{
2972 WINPR_ASSERT(license);
2973 license->state = state;
2974 switch (state)
2975 {
2976 case LICENSE_STATE_COMPLETED:
2977 break;
2978 case LICENSE_STATE_ABORTED:
2979 default:
2980 license->type = LICENSE_TYPE_INVALID;
2981 break;
2982 }
2983}
2984
2985const char* license_get_state_string(LICENSE_STATE state)
2986{
2987 switch (state)
2988 {
2989 case LICENSE_STATE_INITIAL:
2990 return "LICENSE_STATE_INITIAL";
2991 case LICENSE_STATE_CONFIGURED:
2992 return "LICENSE_STATE_CONFIGURED";
2993 case LICENSE_STATE_REQUEST:
2994 return "LICENSE_STATE_REQUEST";
2995 case LICENSE_STATE_NEW_REQUEST:
2996 return "LICENSE_STATE_NEW_REQUEST";
2997 case LICENSE_STATE_PLATFORM_CHALLENGE:
2998 return "LICENSE_STATE_PLATFORM_CHALLENGE";
2999 case LICENSE_STATE_PLATFORM_CHALLENGE_RESPONSE:
3000 return "LICENSE_STATE_PLATFORM_CHALLENGE_RESPONSE";
3001 case LICENSE_STATE_COMPLETED:
3002 return "LICENSE_STATE_COMPLETED";
3003 case LICENSE_STATE_ABORTED:
3004 return "LICENSE_STATE_ABORTED";
3005 default:
3006 return "LICENSE_STATE_UNKNOWN";
3007 }
3008}
3009
3010BOOL license_server_send_request(rdpLicense* license)
3011{
3012 if (!license_ensure_state(license, LICENSE_STATE_CONFIGURED, LICENSE_REQUEST))
3013 return FALSE;
3014 if (!license_send_license_request_packet(license))
3015 return FALSE;
3016 license_set_state(license, LICENSE_STATE_REQUEST);
3017 return TRUE;
3018}
3019
3020WINPR_ATTR_NODISCARD
3021static BOOL license_set_string(wLog* log, const char* what, const char* value, BYTE** bdst,
3022 UINT32* dstLen)
3023{
3024 WINPR_ASSERT(what);
3025 WINPR_ASSERT(value);
3026 WINPR_ASSERT(bdst);
3027 WINPR_ASSERT(dstLen);
3028
3029 union
3030 {
3031 WCHAR** w;
3032 BYTE** b;
3033 } cnv;
3034 cnv.b = bdst;
3035
3036 size_t len = 0;
3037 *cnv.w = ConvertUtf8ToWCharAlloc(value, &len);
3038 if (!*cnv.w || (len > UINT32_MAX / sizeof(WCHAR)))
3039 {
3040 WLog_Print(log, WLOG_ERROR, "license->ProductInfo: %s == %p || %" PRIuz " > UINT32_MAX",
3041 what, (void*)(*cnv.w), len);
3042 return FALSE;
3043 }
3044 *dstLen = (UINT32)(len * sizeof(WCHAR));
3045 return TRUE;
3046}
3047
3048BOOL license_server_configure(rdpLicense* license)
3049{
3050 wStream* s = nullptr;
3051 UINT32 algs[] = { KEY_EXCHANGE_ALG_RSA };
3052
3053 WINPR_ASSERT(license);
3054 WINPR_ASSERT(license->rdp);
3055
3056 const rdpSettings* settings = license->rdp->settings;
3057
3058 const char* CompanyName =
3059 freerdp_settings_get_string(settings, FreeRDP_ServerLicenseCompanyName);
3060
3061 const char* ProductName =
3062 freerdp_settings_get_string(settings, FreeRDP_ServerLicenseProductName);
3063 const UINT32 ProductVersion =
3064 freerdp_settings_get_uint32(settings, FreeRDP_ServerLicenseProductVersion);
3065 const UINT32 issuerCount =
3066 freerdp_settings_get_uint32(settings, FreeRDP_ServerLicenseProductIssuersCount);
3067
3068 const void* ptr = freerdp_settings_get_pointer(settings, FreeRDP_ServerLicenseProductIssuers);
3069 const char** issuers = WINPR_REINTERPRET_CAST(ptr, const void*, const char**);
3070
3071 WINPR_ASSERT(CompanyName);
3072 WINPR_ASSERT(ProductName);
3073 WINPR_ASSERT(ProductVersion > 0);
3074 WINPR_ASSERT(issuers || (issuerCount == 0));
3075
3076 if (!license_ensure_state(license, LICENSE_STATE_INITIAL, LICENSE_REQUEST))
3077 return FALSE;
3078
3079 license->ProductInfo->dwVersion = ProductVersion;
3080 if (!license_set_string(license->log, "pbCompanyName", CompanyName,
3081 &license->ProductInfo->pbCompanyName,
3082 &license->ProductInfo->cbCompanyName))
3083 return FALSE;
3084
3085 if (!license_set_string(license->log, "pbProductId", ProductName,
3086 &license->ProductInfo->pbProductId, &license->ProductInfo->cbProductId))
3087 return FALSE;
3088
3089 if (!license_read_binary_blob_data(license->log, license->KeyExchangeList,
3090 BB_KEY_EXCHG_ALG_BLOB, algs, sizeof(algs)))
3091 return FALSE;
3092
3093 if (!freerdp_certificate_read_server_cert(license->certificate, settings->ServerCertificate,
3094 settings->ServerCertificateLength))
3095 return FALSE;
3096
3097 s = Stream_New(nullptr, 1024);
3098 if (!s)
3099 return FALSE;
3100 else
3101 {
3102 BOOL r = FALSE;
3103 SSIZE_T res =
3104 freerdp_certificate_write_server_cert(license->certificate, CERT_CHAIN_VERSION_2, s);
3105 if (res >= 0)
3106 r = license_read_binary_blob_data(license->log, license->ServerCertificate,
3107 BB_CERTIFICATE_BLOB, Stream_Buffer(s),
3108 Stream_GetPosition(s));
3109
3110 Stream_Free(s, TRUE);
3111 if (!r)
3112 return FALSE;
3113 }
3114
3115 if (!license_scope_list_resize(license->ScopeList, issuerCount))
3116 return FALSE;
3117 for (size_t x = 0; x < issuerCount; x++)
3118 {
3119 LICENSE_BLOB* blob = license->ScopeList->array[x];
3120 const char* name = issuers[x];
3121 const size_t length = strnlen(name, UINT16_MAX) + 1;
3122 if ((length == 0) || (length > UINT16_MAX))
3123 {
3124 WLog_Print(license->log, WLOG_WARN,
3125 "Invalid issuer at position %" PRIuz ": length 0 < %" PRIuz " <= %d"
3126 " ['%s']",
3127 x, length, UINT16_MAX, name);
3128 return FALSE;
3129 }
3130 if (!license_read_binary_blob_data(license->log, blob, BB_SCOPE_BLOB, name, length))
3131 return FALSE;
3132 }
3133
3134 license_set_state(license, LICENSE_STATE_CONFIGURED);
3135 return TRUE;
3136}
3137
3138rdpLicense* license_get(rdpContext* context)
3139{
3140 WINPR_ASSERT(context);
3141 WINPR_ASSERT(context->rdp);
3142 return context->rdp->license;
3143}
WINPR_ATTR_NODISCARD FREERDP_API const void * freerdp_settings_get_pointer(const rdpSettings *settings, FreeRDP_Settings_Keys_Pointer id)
Returns a immutable pointer settings value.
WINPR_ATTR_NODISCARD FREERDP_API const char * freerdp_settings_get_string(const rdpSettings *settings, FreeRDP_Settings_Keys_String id)
Returns a immutable string settings value.
WINPR_ATTR_NODISCARD FREERDP_API UINT32 freerdp_settings_get_uint32(const rdpSettings *settings, FreeRDP_Settings_Keys_UInt32 id)
Returns a UINT32 settings value.
WINPR_ATTR_NODISCARD FREERDP_API BOOL freerdp_settings_get_bool(const rdpSettings *settings, FreeRDP_Settings_Keys_Bool id)
Returns a boolean settings value.