FreeRDP
Loading...
Searching...
No Matches
license.c
1/*
2 * FreeRDP: A Remote Desktop Protocol Implementation
3 * RDP Licensing
4 *
5 * Copyright 2011-2013 Marc-Andre Moreau <marcandre.moreau@gmail.com>
6 * Copyright 2014 Norbert Federa <norbert.federa@thincast.com>
7 * Copyright 2018 David Fort <contact@hardening-consulting.com>
8 * Copyright 2022,2023 Armin Novak <armin.novak@thincast.com>
9 * Copyright 2022,2023 Thincast Technologies GmbH
10 *
11 * Licensed under the Apache License, Version 2.0 (the "License");
12 * you may not use this file except in compliance with the License.
13 * You may obtain a copy of the License at
14 *
15 * http://www.apache.org/licenses/LICENSE-2.0
16 *
17 * Unless required by applicable law or agreed to in writing, software
18 * distributed under the License is distributed on an "AS IS" BASIS,
19 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
20 * See the License for the specific language governing permissions and
21 * limitations under the License.
22 */
23
24#include <freerdp/config.h>
25
26#include "settings.h"
27
28#include <freerdp/license.h>
29
30#include <winpr/crt.h>
31#include <winpr/assert.h>
32#include <winpr/crypto.h>
33#include <winpr/shell.h>
34#include <winpr/path.h>
35#include <winpr/file.h>
36
37#include <freerdp/log.h>
38
39#include <freerdp/crypto/certificate.h>
40
41#include "license.h"
42
43#include "../crypto/crypto.h"
44#include "../crypto/certificate.h"
45
46#define LICENSE_TAG FREERDP_TAG("core.license")
47
48// #define LICENSE_NULL_CLIENT_RANDOM 1
49// #define LICENSE_NULL_PREMASTER_SECRET 1
50
51// #define WITH_LICENSE_DECRYPT_CHALLENGE_RESPONSE
52
53#define PLATFORM_CHALLENGE_RESPONSE_VERSION 0x0100
54
56enum LicenseRequestType
57{
58 LICENSE_REQUEST = 0x01,
59 PLATFORM_CHALLENGE = 0x02,
60 NEW_LICENSE = 0x03,
61 UPGRADE_LICENSE = 0x04,
62 LICENSE_INFO = 0x12,
63 NEW_LICENSE_REQUEST = 0x13,
64 PLATFORM_CHALLENGE_RESPONSE = 0x15,
65 ERROR_ALERT = 0xFF
66};
67
68/*
69#define LICENSE_PKT_CS_MASK \
70 (LICENSE_INFO | NEW_LICENSE_REQUEST | PLATFORM_CHALLENGE_RESPONSE | ERROR_ALERT)
71#define LICENSE_PKT_SC_MASK \
72 (LICENSE_REQUEST | PLATFORM_CHALLENGE | NEW_LICENSE | UPGRADE_LICENSE | ERROR_ALERT)
73#define LICENSE_PKT_MASK (LICENSE_PKT_CS_MASK | LICENSE_PKT_SC_MASK)
74*/
75#define LICENSE_PREAMBLE_LENGTH 4
76
77/* Cryptographic Lengths */
78
79#define SERVER_RANDOM_LENGTH 32
80#define MASTER_SECRET_LENGTH 48
81#define PREMASTER_SECRET_LENGTH 48
82#define SESSION_KEY_BLOB_LENGTH 48
83#define MAC_SALT_KEY_LENGTH 16
84#define LICENSING_ENCRYPTION_KEY_LENGTH 16
85#define HWID_PLATFORM_ID_LENGTH 4
86// #define HWID_UNIQUE_DATA_LENGTH 16
87#define HWID_LENGTH 20
88// #define LICENSING_PADDING_SIZE 8
89
90/* Preamble Flags */
91
92// #define PREAMBLE_VERSION_2_0 0x02
93#define PREAMBLE_VERSION_3_0 0x03
94// #define LicenseProtocolVersionMask 0x0F
95#define EXTENDED_ERROR_MSG_SUPPORTED 0x80
96
98enum
99{
100 BB_ANY_BLOB = 0x0000,
101 BB_DATA_BLOB = 0x0001,
102 BB_RANDOM_BLOB = 0x0002,
103 BB_CERTIFICATE_BLOB = 0x0003,
104 BB_ERROR_BLOB = 0x0004,
105 BB_ENCRYPTED_DATA_BLOB = 0x0009,
106 BB_KEY_EXCHG_ALG_BLOB = 0x000D,
107 BB_SCOPE_BLOB = 0x000E,
108 BB_CLIENT_USER_NAME_BLOB = 0x000F,
109 BB_CLIENT_MACHINE_NAME_BLOB = 0x0010
110};
111
112/* License Key Exchange Algorithms */
113
114#define KEY_EXCHANGE_ALG_RSA 0x00000001
115
118enum
119{
120 ERR_INVALID_SERVER_CERTIFICATE = 0x00000001,
121 ERR_NO_LICENSE = 0x00000002,
122 ERR_INVALID_MAC = 0x00000003,
123 ERR_INVALID_SCOPE = 0x00000004,
124 ERR_NO_LICENSE_SERVER = 0x00000006,
125 STATUS_VALID_CLIENT = 0x00000007,
126 ERR_INVALID_CLIENT = 0x00000008,
127 ERR_INVALID_PRODUCT_ID = 0x0000000B,
128 ERR_INVALID_MESSAGE_LENGTH = 0x0000000C
129};
130
133enum
134{
135 ST_TOTAL_ABORT = 0x00000001,
136 ST_NO_TRANSITION = 0x00000002,
137 ST_RESET_PHASE_TO_START = 0x00000003,
138 ST_RESEND_LAST_MESSAGE = 0x00000004
139};
140
143enum
144{
145 WIN32_PLATFORM_CHALLENGE_TYPE = 0x0100,
146 WIN16_PLATFORM_CHALLENGE_TYPE = 0x0200,
147 WINCE_PLATFORM_CHALLENGE_TYPE = 0x0300,
148 OTHER_PLATFORM_CHALLENGE_TYPE = 0xFF00
149};
150
153enum
154{
155 LICENSE_DETAIL_SIMPLE = 0x0001,
156 LICENSE_DETAIL_MODERATE = 0x0002,
157 LICENSE_DETAIL_DETAIL = 0x0003
158};
159
160/*
161 * PlatformId:
162 *
163 * The most significant byte of the PlatformId field contains the operating system version of the
164 * client. The second most significant byte of the PlatformId field identifies the ISV that provided
165 * the client image. The remaining two bytes in the PlatformId field are used by the ISV to identify
166 * the build number of the operating system.
167 *
168 * 0x04010000:
169 *
170 * CLIENT_OS_ID_WINNT_POST_52 (0x04000000)
171 * CLIENT_IMAGE_ID_MICROSOFT (0x00010000)
172 */
173enum
174{
175 CLIENT_OS_ID_WINNT_351 = 0x01000000,
176 CLIENT_OS_ID_WINNT_40 = 0x02000000,
177 CLIENT_OS_ID_WINNT_50 = 0x03000000,
178 CLIENT_OS_ID_WINNT_POST_52 = 0x04000000,
179
180 CLIENT_IMAGE_ID_MICROSOFT = 0x00010000,
181 CLIENT_IMAGE_ID_CITRIX = 0x00020000,
182};
183
184struct rdp_license
185{
186 LICENSE_STATE state;
187 LICENSE_TYPE type;
188 rdpRdp* rdp;
189 rdpCertificate* certificate;
190 BYTE HardwareId[HWID_LENGTH];
191 BYTE ClientRandom[CLIENT_RANDOM_LENGTH];
192 BYTE ServerRandom[SERVER_RANDOM_LENGTH];
193 BYTE MasterSecret[MASTER_SECRET_LENGTH];
194 BYTE PremasterSecret[PREMASTER_SECRET_LENGTH];
195 BYTE SessionKeyBlob[SESSION_KEY_BLOB_LENGTH];
196 BYTE MacSaltKey[MAC_SALT_KEY_LENGTH];
197 BYTE LicensingEncryptionKey[LICENSING_ENCRYPTION_KEY_LENGTH];
198 LICENSE_PRODUCT_INFO* ProductInfo;
199 LICENSE_BLOB* ErrorInfo;
200 LICENSE_BLOB* LicenseInfo; /* Client -> Server */
201 LICENSE_BLOB* KeyExchangeList;
202 LICENSE_BLOB* ServerCertificate;
203 LICENSE_BLOB* ClientUserName;
204 LICENSE_BLOB* ClientMachineName;
205 LICENSE_BLOB* PlatformChallenge;
206 LICENSE_BLOB* PlatformChallengeResponse;
207 LICENSE_BLOB* EncryptedPremasterSecret;
208 LICENSE_BLOB* EncryptedPlatformChallenge;
209 LICENSE_BLOB* EncryptedPlatformChallengeResponse;
210 LICENSE_BLOB* EncryptedHardwareId;
211 LICENSE_BLOB* EncryptedLicenseInfo;
212 BYTE MACData[LICENSING_ENCRYPTION_KEY_LENGTH];
213 SCOPE_LIST* ScopeList;
214 UINT32 PacketHeaderLength;
215 UINT32 PreferredKeyExchangeAlg;
216 UINT32 PlatformId;
217 UINT16 ClientType;
218 UINT16 LicenseDetailLevel;
219 BOOL update;
220 wLog* log;
221};
222
223WINPR_ATTR_NODISCARD
224static BOOL license_send_error_alert(rdpLicense* license, UINT32 dwErrorCode,
225 UINT32 dwStateTransition, const LICENSE_BLOB* info);
226
227static void license_set_state(rdpLicense* license, LICENSE_STATE state);
228
229WINPR_ATTR_NODISCARD
230static const char* license_get_state_string(LICENSE_STATE state);
231
232WINPR_ATTR_NODISCARD
233static const char* license_preferred_key_exchange_alg_string(UINT32 alg, char* buffer, size_t size)
234{
235 const char* name = nullptr;
236
237 switch (alg)
238 {
239 case KEY_EXCHANGE_ALG_RSA:
240 name = "KEY_EXCHANGE_ALG_RSA";
241 break;
242 default:
243 name = "KEY_EXCHANGE_ALG_UNKNOWN";
244 break;
245 }
246
247 (void)_snprintf(buffer, size, "%s [0x%08" PRIx32 "]", name, alg);
248 return buffer;
249}
250
251WINPR_ATTR_NODISCARD
252static const char* license_request_type_string(UINT32 type)
253{
254 switch (type)
255 {
256 case LICENSE_REQUEST:
257 return "LICENSE_REQUEST";
258 case PLATFORM_CHALLENGE:
259 return "PLATFORM_CHALLENGE";
260 case NEW_LICENSE:
261 return "NEW_LICENSE";
262 case UPGRADE_LICENSE:
263 return "UPGRADE_LICENSE";
264 case LICENSE_INFO:
265 return "LICENSE_INFO";
266 case NEW_LICENSE_REQUEST:
267 return "NEW_LICENSE_REQUEST";
268 case PLATFORM_CHALLENGE_RESPONSE:
269 return "PLATFORM_CHALLENGE_RESPONSE";
270 case ERROR_ALERT:
271 return "ERROR_ALERT";
272 default:
273 return "LICENSE_REQUEST_TYPE_UNKNOWN";
274 }
275}
276
277WINPR_ATTR_NODISCARD
278static const char* license_blob_type_string(UINT16 type)
279{
280 switch (type)
281 {
282 case BB_ANY_BLOB:
283 return "BB_ANY_BLOB";
284 case BB_DATA_BLOB:
285 return "BB_DATA_BLOB";
286 case BB_RANDOM_BLOB:
287 return "BB_RANDOM_BLOB";
288 case BB_CERTIFICATE_BLOB:
289 return "BB_CERTIFICATE_BLOB";
290 case BB_ERROR_BLOB:
291 return "BB_ERROR_BLOB";
292 case BB_ENCRYPTED_DATA_BLOB:
293 return "BB_ENCRYPTED_DATA_BLOB";
294 case BB_KEY_EXCHG_ALG_BLOB:
295 return "BB_KEY_EXCHG_ALG_BLOB";
296 case BB_SCOPE_BLOB:
297 return "BB_SCOPE_BLOB";
298 case BB_CLIENT_USER_NAME_BLOB:
299 return "BB_CLIENT_USER_NAME_BLOB";
300 case BB_CLIENT_MACHINE_NAME_BLOB:
301 return "BB_CLIENT_MACHINE_NAME_BLOB";
302 default:
303 return "BB_UNKNOWN";
304 }
305}
306
307WINPR_ATTR_NODISCARD
308static wStream* license_send_stream_init(rdpLicense* license, UINT16* sec_flags);
309
310WINPR_ATTR_NODISCARD
311static BOOL license_generate_randoms(rdpLicense* license);
312
313WINPR_ATTR_NODISCARD
314static BOOL license_generate_keys(rdpLicense* license);
315
316WINPR_ATTR_NODISCARD
317static BOOL license_generate_hwid(rdpLicense* license);
318
319WINPR_ATTR_NODISCARD
320static BOOL license_encrypt_premaster_secret(rdpLicense* license);
321
322static void license_free_product_info(LICENSE_PRODUCT_INFO* productInfo);
323
324WINPR_ATTR_MALLOC(license_free_product_info, 1)
325static LICENSE_PRODUCT_INFO* license_new_product_info(void);
326
327WINPR_ATTR_NODISCARD
328static BOOL license_read_product_info(wLog* log, wStream* s, LICENSE_PRODUCT_INFO* productInfo);
329
330static void license_free_binary_blob(LICENSE_BLOB* blob);
331
332WINPR_ATTR_MALLOC(license_free_binary_blob, 1)
333static LICENSE_BLOB* license_new_binary_blob(UINT16 type);
334
335WINPR_ATTR_NODISCARD
336static BOOL license_read_binary_blob_data(wLog* log, LICENSE_BLOB* blob, UINT16 type,
337 const void* data, size_t length);
338
339WINPR_ATTR_NODISCARD
340static BOOL license_read_binary_blob(wLog* log, wStream* s, LICENSE_BLOB* blob);
341
342WINPR_ATTR_NODISCARD
343static BOOL license_write_binary_blob(wStream* s, const LICENSE_BLOB* blob);
344
345static void license_free_scope_list(SCOPE_LIST* scopeList);
346
347WINPR_ATTR_MALLOC(license_free_scope_list, 1)
348static SCOPE_LIST* license_new_scope_list(void);
349
350WINPR_ATTR_NODISCARD
351static BOOL license_scope_list_resize(SCOPE_LIST* scopeList, UINT32 count);
352
353WINPR_ATTR_NODISCARD
354static BOOL license_read_scope_list(wLog* log, wStream* s, SCOPE_LIST* scopeList);
355
356WINPR_ATTR_NODISCARD
357static BOOL license_write_scope_list(wLog* log, wStream* s, const SCOPE_LIST* scopeList);
358
359WINPR_ATTR_NODISCARD
360static BOOL license_read_license_request_packet(rdpLicense* license, wStream* s);
361
362WINPR_ATTR_NODISCARD
363static BOOL license_write_license_request_packet(const rdpLicense* license, wStream* s);
364
365WINPR_ATTR_NODISCARD
366static BOOL license_read_platform_challenge_packet(rdpLicense* license, wStream* s);
367
368WINPR_ATTR_NODISCARD
369static BOOL license_send_platform_challenge_packet(rdpLicense* license);
370
371WINPR_ATTR_NODISCARD
372static BOOL license_read_new_or_upgrade_license_packet(rdpLicense* license, wStream* s);
373
374WINPR_ATTR_NODISCARD
375static BOOL license_read_error_alert_packet(rdpLicense* license, wStream* s);
376
377WINPR_ATTR_NODISCARD
378static BOOL license_write_new_license_request_packet(const rdpLicense* license, wStream* s);
379
380WINPR_ATTR_NODISCARD
381static BOOL license_read_new_license_request_packet(rdpLicense* license, wStream* s);
382
383WINPR_ATTR_NODISCARD
384static BOOL license_answer_license_request(rdpLicense* license);
385
386WINPR_ATTR_NODISCARD
387static BOOL license_send_platform_challenge_response(rdpLicense* license);
388
389WINPR_ATTR_NODISCARD
390static BOOL license_read_platform_challenge_response(rdpLicense* license);
391
392WINPR_ATTR_NODISCARD
393static BOOL license_read_client_platform_challenge_response(rdpLicense* license, wStream* s);
394
395WINPR_ATTR_NODISCARD
396static BOOL license_write_client_platform_challenge_response(rdpLicense* license, wStream* s);
397
398WINPR_ATTR_NODISCARD
399static BOOL license_write_server_upgrade_license(const rdpLicense* license, wStream* s);
400
401WINPR_ATTR_NODISCARD
402static BOOL license_send_license_info(rdpLicense* license, const LICENSE_BLOB* calBlob,
403 const BYTE* signature, size_t signature_length);
404
405WINPR_ATTR_NODISCARD
406static BOOL license_read_license_info(rdpLicense* license, wStream* s);
407
408WINPR_ATTR_NODISCARD
409static state_run_t license_client_recv(rdpLicense* license, wStream* s);
410
411WINPR_ATTR_NODISCARD
412static state_run_t license_server_recv(rdpLicense* license, wStream* s);
413
414#define PLATFORMID (CLIENT_OS_ID_WINNT_POST_52 | CLIENT_IMAGE_ID_MICROSOFT)
415
416#ifdef WITH_DEBUG_LICENSE
417
418static const char* error_codes[] = { "ERR_UNKNOWN",
419 "ERR_INVALID_SERVER_CERTIFICATE",
420 "ERR_NO_LICENSE",
421 "ERR_INVALID_MAC",
422 "ERR_INVALID_SCOPE",
423 "ERR_UNKNOWN",
424 "ERR_NO_LICENSE_SERVER",
425 "STATUS_VALID_CLIENT",
426 "ERR_INVALID_CLIENT",
427 "ERR_UNKNOWN",
428 "ERR_UNKNOWN",
429 "ERR_INVALID_PRODUCT_ID",
430 "ERR_INVALID_MESSAGE_LENGTH" };
431
432static const char* state_transitions[] = { "ST_UNKNOWN", "ST_TOTAL_ABORT", "ST_NO_TRANSITION",
433 "ST_RESET_PHASE_TO_START", "ST_RESEND_LAST_MESSAGE" };
434
435static void license_print_product_info(wLog* log, const LICENSE_PRODUCT_INFO* productInfo)
436{
437 char* CompanyName = nullptr;
438 char* ProductId = nullptr;
439
440 WINPR_ASSERT(productInfo);
441 WINPR_ASSERT(productInfo->pbCompanyName);
442 WINPR_ASSERT(productInfo->pbProductId);
443
444 CompanyName =
445 ConvertWCharNToUtf8Alloc(WINPR_PACKED_ALIGN_CAST(const WCHAR*, productInfo->pbCompanyName),
446 productInfo->cbCompanyName / sizeof(WCHAR), nullptr);
447 ProductId =
448 ConvertWCharNToUtf8Alloc(WINPR_PACKED_ALIGN_CAST(const WCHAR*, productInfo->pbProductId),
449 productInfo->cbProductId / sizeof(WCHAR), nullptr);
450 WLog_Print(log, WLOG_INFO, "ProductInfo:");
451 WLog_Print(log, WLOG_INFO, "\tdwVersion: 0x%08" PRIX32 "", productInfo->dwVersion);
452 WLog_Print(log, WLOG_INFO, "\tCompanyName: %s", CompanyName);
453 WLog_Print(log, WLOG_INFO, "\tProductId: %s", ProductId);
454 free(CompanyName);
455 free(ProductId);
456}
457
458static void license_print_scope_list(wLog* log, const SCOPE_LIST* scopeList)
459{
460 WINPR_ASSERT(scopeList);
461
462 WLog_Print(log, WLOG_INFO, "ScopeList (%" PRIu32 "):", scopeList->count);
463
464 for (UINT32 index = 0; index < scopeList->count; index++)
465 {
466 const LICENSE_BLOB* scope = nullptr;
467
468 WINPR_ASSERT(scopeList->array);
469 scope = scopeList->array[index];
470 WINPR_ASSERT(scope);
471
472 WLog_Print(log, WLOG_INFO, "\t%s", (const char*)scope->data);
473 }
474}
475#endif
476
477static const char licenseStore[] = "licenses";
478
479WINPR_ATTR_NODISCARD
480static BOOL license_ensure_state(rdpLicense* license, LICENSE_STATE state, UINT32 msg)
481{
482 const LICENSE_STATE cstate = license_get_state(license);
483
484 WINPR_ASSERT(license);
485
486 if (cstate != state)
487 {
488 const char* scstate = license_get_state_string(cstate);
489 const char* sstate = license_get_state_string(state);
490 const char* where = license_request_type_string(msg);
491
492 WLog_Print(license->log, WLOG_WARN,
493 "Received [%s], but found invalid licensing state %s, expected %s", where,
494 scstate, sstate);
495 return FALSE;
496 }
497 return TRUE;
498}
499
500state_run_t license_recv(rdpLicense* license, wStream* s)
501{
502 WINPR_ASSERT(license);
503 WINPR_ASSERT(license->rdp);
504 WINPR_ASSERT(license->rdp->settings);
505
506 if (freerdp_settings_get_bool(license->rdp->settings, FreeRDP_ServerMode))
507 return license_server_recv(license, s);
508 else
509 return license_client_recv(license, s);
510}
511
512WINPR_ATTR_NODISCARD
513static BOOL license_check_stream_length(wLog* log, wStream* s, UINT64 expect, const char* where)
514{
515 const size_t remain = Stream_GetRemainingLength(s);
516
517 WINPR_ASSERT(where);
518
519 if (remain < expect)
520 {
521 WLog_Print(log, WLOG_WARN, "short %s, expected %" PRIu64 " bytes, got %" PRIuz, where,
522 expect, remain);
523 return FALSE;
524 }
525 return TRUE;
526}
527
528WINPR_ATTR_NODISCARD
529static BOOL license_check_stream_capacity(wLog* log, wStream* s, size_t expect, const char* where)
530{
531 WINPR_ASSERT(where);
532
533 return (Stream_CheckAndLogRequiredCapacityWLogEx(log, WLOG_WARN, s, expect, 1,
534 "%s(%s:%" PRIuz ") %s", __func__, __FILE__,
535 (size_t)__LINE__, where));
536}
537
538WINPR_ATTR_NODISCARD
539static BOOL computeCalHash(wLog* log, const char* hostname, char* hashStr, size_t len)
540{
541 WINPR_DIGEST_CTX* sha1 = nullptr;
542 BOOL ret = FALSE;
543 BYTE hash[20] = WINPR_C_ARRAY_INIT;
544
545 WINPR_ASSERT(hostname);
546 WINPR_ASSERT(hashStr);
547
548 if (len < 2 * sizeof(hash) + 1)
549 return FALSE;
550
551 if (!(sha1 = winpr_Digest_New()))
552 goto out;
553 if (!winpr_Digest_Init(sha1, WINPR_MD_SHA1))
554 goto out;
555 if (!winpr_Digest_Update(sha1, (const BYTE*)hostname, strlen(hostname)))
556 goto out;
557 if (!winpr_Digest_Final(sha1, hash, sizeof(hash)))
558 goto out;
559
560 for (size_t i = 0; i < sizeof(hash); i++, hashStr += 2)
561 (void)sprintf_s(hashStr, 3, "%.2x", hash[i]);
562
563 ret = TRUE;
564out:
565 if (!ret)
566 WLog_Print(log, WLOG_ERROR, "failed to generate SHA1 of hostname '%s'", hostname);
567 winpr_Digest_Free(sha1);
568 return ret;
569}
570
571WINPR_ATTR_NODISCARD
572static BOOL saveCal(wLog* log, const rdpSettings* settings, const BYTE* data, size_t length,
573 const char* hostname)
574{
575 char hash[41] = WINPR_C_ARRAY_INIT;
576 FILE* fp = nullptr;
577 char* licenseStorePath = nullptr;
578 char filename[MAX_PATH] = WINPR_C_ARRAY_INIT;
579 char filenameNew[MAX_PATH] = WINPR_C_ARRAY_INIT;
580 char* filepath = nullptr;
581 char* filepathNew = nullptr;
582
583 size_t written = 0;
584 BOOL ret = FALSE;
585 const char* path = freerdp_settings_get_string(settings, FreeRDP_ConfigPath);
586
587 WINPR_ASSERT(path);
588 WINPR_ASSERT(data || (length == 0));
589 WINPR_ASSERT(hostname);
590
591 if (!winpr_PathFileExists(path))
592 {
593 if (!winpr_PathMakePath(path, nullptr))
594 {
595 WLog_Print(log, WLOG_ERROR, "error creating directory '%s'", path);
596 goto out;
597 }
598 WLog_Print(log, WLOG_INFO, "creating directory %s", path);
599 }
600
601 if (!(licenseStorePath = GetCombinedPath(path, licenseStore)))
602 {
603 WLog_Print(log, WLOG_ERROR, "Failed to get license store path from '%s' + '%s'", path,
604 licenseStore);
605 goto out;
606 }
607
608 if (!winpr_PathFileExists(licenseStorePath))
609 {
610 if (!winpr_PathMakePath(licenseStorePath, nullptr))
611 {
612 WLog_Print(log, WLOG_ERROR, "error creating directory '%s'", licenseStorePath);
613 goto out;
614 }
615 WLog_Print(log, WLOG_INFO, "creating directory %s", licenseStorePath);
616 }
617
618 if (!computeCalHash(log, hostname, hash, sizeof(hash)))
619 goto out;
620 (void)sprintf_s(filename, sizeof(filename) - 1, "%s.cal", hash);
621 (void)sprintf_s(filenameNew, sizeof(filenameNew) - 1, "%s.cal.new", hash);
622
623 if (!(filepath = GetCombinedPath(licenseStorePath, filename)))
624 {
625 WLog_Print(log, WLOG_ERROR, "Failed to get license file path from '%s' + '%s'", path,
626 filename);
627 goto out;
628 }
629
630 if (!(filepathNew = GetCombinedPath(licenseStorePath, filenameNew)))
631 {
632 WLog_Print(log, WLOG_ERROR, "Failed to get license new file path from '%s' + '%s'", path,
633 filenameNew);
634 goto out;
635 }
636
637 fp = winpr_fopen(filepathNew, "wb");
638 if (!fp)
639 {
640 WLog_Print(log, WLOG_ERROR, "Failed to open license file '%s'", filepathNew);
641 goto out;
642 }
643
644 written = fwrite(data, length, 1, fp);
645 (void)fclose(fp);
646
647 if (written != 1)
648 {
649 WLog_Print(log, WLOG_ERROR, "Failed to write to license file '%s'", filepathNew);
650 winpr_DeleteFile(filepathNew);
651 goto out;
652 }
653
654 ret = winpr_MoveFileEx(filepathNew, filepath, MOVEFILE_REPLACE_EXISTING);
655 if (!ret)
656 WLog_Print(log, WLOG_ERROR, "Failed to move license file '%s' to '%s'", filepathNew,
657 filepath);
658
659out:
660 free(filepathNew);
661 free(filepath);
662 free(licenseStorePath);
663 return ret;
664}
665
666WINPR_ATTR_MALLOC(free, 1)
667static BYTE* loadCalFile(wLog* log, const rdpSettings* settings, const char* hostname,
668 size_t* dataLen)
669{
670 char* licenseStorePath = nullptr;
671 char* calPath = nullptr;
672 char calFilename[MAX_PATH] = WINPR_C_ARRAY_INIT;
673 char hash[41] = WINPR_C_ARRAY_INIT;
674 INT64 length = 0;
675 size_t status = 0;
676 FILE* fp = nullptr;
677 BYTE* ret = nullptr;
678
679 WINPR_ASSERT(settings);
680 WINPR_ASSERT(hostname);
681 WINPR_ASSERT(dataLen);
682
683 if (!computeCalHash(log, hostname, hash, sizeof(hash)))
684 {
685 WLog_Print(log, WLOG_ERROR, "loadCalFile: unable to compute hostname hash");
686 return nullptr;
687 }
688
689 (void)sprintf_s(calFilename, sizeof(calFilename) - 1, "%s.cal", hash);
690
691 if (!(licenseStorePath = GetCombinedPath(
692 freerdp_settings_get_string(settings, FreeRDP_ConfigPath), licenseStore)))
693 return nullptr;
694
695 if (!(calPath = GetCombinedPath(licenseStorePath, calFilename)))
696 goto error_path;
697
698 fp = winpr_fopen(calPath, "rb");
699 if (!fp)
700 goto error_open;
701
702 if (_fseeki64(fp, 0, SEEK_END) != 0)
703 goto error_malloc;
704 length = _ftelli64(fp);
705 if (_fseeki64(fp, 0, SEEK_SET) != 0)
706 goto error_malloc;
707 if (length < 0)
708 goto error_malloc;
709
710 ret = (BYTE*)malloc((size_t)length);
711 if (!ret)
712 goto error_malloc;
713
714 status = fread(ret, (size_t)length, 1, fp);
715 if (status == 0)
716 goto error_read;
717
718 *dataLen = (size_t)length;
719
720 (void)fclose(fp);
721 free(calPath);
722 free(licenseStorePath);
723 return ret;
724
725error_read:
726 free(ret);
727error_malloc:
728 fclose(fp);
729error_open:
730 free(calPath);
731error_path:
732 free(licenseStorePath);
733 return nullptr;
734}
735
745WINPR_ATTR_NODISCARD
746static BOOL license_read_preamble(wLog* log, wStream* s, BYTE* bMsgType, BYTE* flags,
747 UINT16* wMsgSize)
748{
749 WINPR_ASSERT(bMsgType);
750 WINPR_ASSERT(flags);
751 WINPR_ASSERT(wMsgSize);
752
753 /* preamble (4 bytes) */
754 if (!license_check_stream_length(log, s, 4, "license preamble"))
755 return FALSE;
756
757 Stream_Read_UINT8(s, *bMsgType); /* bMsgType (1 byte) */
758 Stream_Read_UINT8(s, *flags); /* flags (1 byte) */
759 Stream_Read_UINT16(s, *wMsgSize); /* wMsgSize (2 bytes) */
760 if (*wMsgSize < 4)
761 {
762 WLog_Print(log, WLOG_WARN,
763 "invalid license preamble::wMsgSize, expected value >= 4, got %" PRIu32,
764 *wMsgSize);
765 return FALSE;
766 }
767 return license_check_stream_length(log, s, *wMsgSize - 4ull, "license preamble::wMsgSize");
768}
769
779WINPR_ATTR_NODISCARD
780static BOOL license_write_preamble(wStream* s, BYTE bMsgType, BYTE flags, UINT16 wMsgSize)
781{
782 if (!Stream_EnsureRemainingCapacity(s, 4))
783 return FALSE;
784
785 /* preamble (4 bytes) */
786 Stream_Write_UINT8(s, bMsgType); /* bMsgType (1 byte) */
787 Stream_Write_UINT8(s, flags); /* flags (1 byte) */
788 Stream_Write_UINT16(s, wMsgSize); /* wMsgSize (2 bytes) */
789 return TRUE;
790}
791
800wStream* license_send_stream_init(rdpLicense* license, UINT16* sec_flags)
801{
802 WINPR_ASSERT(license);
803 WINPR_ASSERT(license->rdp);
804 WINPR_ASSERT(sec_flags);
805
806 const BOOL do_crypt = license->rdp->do_crypt;
807
808 *sec_flags = SEC_LICENSE_PKT;
809
810 /*
811 * Encryption of licensing packets is optional even if the rdp security
812 * layer is used. If the peer has not indicated that it is capable of
813 * processing encrypted licensing packets (rdp->do_crypt_license) we turn
814 * off encryption (via rdp->do_crypt) before initializing the rdp stream
815 * and re-enable it afterwards.
816 */
817
818 if (do_crypt)
819 {
820 *sec_flags |= SEC_LICENSE_ENCRYPT_CS;
821 license->rdp->do_crypt = license->rdp->do_crypt_license;
822 }
823
824 wStream* s = rdp_send_stream_init(license->rdp, sec_flags);
825 if (!s)
826 return nullptr;
827
828 license->rdp->do_crypt = do_crypt;
829 license->PacketHeaderLength = (UINT16)Stream_GetPosition(s);
830 if (!Stream_SafeZero(s, LICENSE_PREAMBLE_LENGTH))
831 goto fail;
832 return s;
833
834fail:
835 Stream_Release(s);
836 return nullptr;
837}
838
845WINPR_ATTR_NODISCARD
846static BOOL license_send(rdpLicense* license, wStream* s, BYTE type, UINT16 sec_flags)
847{
848 WINPR_ASSERT(license);
849 WINPR_ASSERT(license->rdp);
850
851 rdpRdp* rdp = license->rdp;
852 WINPR_ASSERT(rdp->settings);
853
854 DEBUG_LICENSE("Sending %s Packet", license_request_type_string(type));
855 const size_t length = Stream_GetPosition(s);
856 WINPR_ASSERT(length >= license->PacketHeaderLength);
857 WINPR_ASSERT(length <= UINT16_MAX + license->PacketHeaderLength);
858
859 const UINT16 wMsgSize = (UINT16)(length - license->PacketHeaderLength);
860 if (!Stream_SetPosition(s, license->PacketHeaderLength))
861 return FALSE;
862 BYTE flags = PREAMBLE_VERSION_3_0;
863
869 if (!rdp->settings->ServerMode)
870 flags |= EXTENDED_ERROR_MSG_SUPPORTED;
871
872 if (!license_write_preamble(s, type, flags, wMsgSize))
873 {
874 Stream_Release(s);
875 return FALSE;
876 }
877
878#ifdef WITH_DEBUG_LICENSE
879 WLog_Print(license->log, WLOG_DEBUG, "Sending %s Packet, length %" PRIu16 "",
880 license_request_type_string(type), wMsgSize);
881 winpr_HexLogDump(license->log, WLOG_DEBUG, Stream_PointerAs(s, char) - LICENSE_PREAMBLE_LENGTH,
882 wMsgSize);
883#endif
884 if (!Stream_SetPosition(s, length))
885 return FALSE;
886 const BOOL ret = rdp_send(rdp, s, MCS_GLOBAL_CHANNEL_ID, sec_flags);
887 return ret;
888}
889
890BOOL license_write_server_upgrade_license(const rdpLicense* license, wStream* s)
891{
892 WINPR_ASSERT(license);
893
894 if (!license_write_binary_blob(s, license->EncryptedLicenseInfo))
895 return FALSE;
896 if (!license_check_stream_capacity(license->log, s, sizeof(license->MACData),
897 "SERVER_UPGRADE_LICENSE::MACData"))
898 return FALSE;
899 Stream_Write(s, license->MACData, sizeof(license->MACData));
900 return TRUE;
901}
902
903WINPR_ATTR_NODISCARD
904static BOOL license_server_send_new_or_upgrade_license(rdpLicense* license, BOOL upgrade)
905{
906 UINT16 sec_flags = 0;
907 wStream* s = license_send_stream_init(license, &sec_flags);
908 const BYTE type = upgrade ? UPGRADE_LICENSE : NEW_LICENSE;
909
910 if (!s)
911 return FALSE;
912
913 if (!license_write_server_upgrade_license(license, s))
914 goto fail;
915
916 return license_send(license, s, type, sec_flags);
917
918fail:
919 Stream_Release(s);
920 return FALSE;
921}
922
930WINPR_ATTR_NODISCARD
931static state_run_t license_client_recv_int(rdpLicense* license, wStream* s)
932{
933 BYTE flags = 0;
934 BYTE bMsgType = 0;
935 UINT16 wMsgSize = 0;
936 const size_t length = Stream_GetRemainingLength(s);
937
938 WINPR_ASSERT(license);
939
940 if (!license_read_preamble(license->log, s, &bMsgType, &flags,
941 &wMsgSize)) /* preamble (4 bytes) */
942 return STATE_RUN_FAILED;
943
944 DEBUG_LICENSE("Receiving %s Packet", license_request_type_string(bMsgType));
945
946 switch (bMsgType)
947 {
948 case LICENSE_REQUEST:
949 /* Client does not require configuration, so skip this state */
950 if (license_get_state(license) == LICENSE_STATE_INITIAL)
951 license_set_state(license, LICENSE_STATE_CONFIGURED);
952
953 if (!license_ensure_state(license, LICENSE_STATE_CONFIGURED, bMsgType))
954 return STATE_RUN_FAILED;
955
956 if (!license_read_license_request_packet(license, s))
957 return STATE_RUN_FAILED;
958
959 if (!license_answer_license_request(license))
960 return STATE_RUN_FAILED;
961
962 license_set_state(license, LICENSE_STATE_NEW_REQUEST);
963 break;
964
965 case PLATFORM_CHALLENGE:
966 if (!license_ensure_state(license, LICENSE_STATE_NEW_REQUEST, bMsgType))
967 return STATE_RUN_FAILED;
968
969 if (!license_read_platform_challenge_packet(license, s))
970 return STATE_RUN_FAILED;
971
972 if (!license_send_platform_challenge_response(license))
973 return STATE_RUN_FAILED;
974 license_set_state(license, LICENSE_STATE_PLATFORM_CHALLENGE_RESPONSE);
975 break;
976
977 case NEW_LICENSE:
978 case UPGRADE_LICENSE:
979 if (!license_ensure_state(license, LICENSE_STATE_PLATFORM_CHALLENGE_RESPONSE, bMsgType))
980 return STATE_RUN_FAILED;
981 if (!license_read_new_or_upgrade_license_packet(license, s))
982 return STATE_RUN_FAILED;
983 break;
984
985 case ERROR_ALERT:
986 if (!license_read_error_alert_packet(license, s))
987 return STATE_RUN_FAILED;
988 break;
989
990 default:
991 WLog_Print(license->log, WLOG_ERROR, "invalid bMsgType:%" PRIu8 "", bMsgType);
992 return STATE_RUN_FAILED;
993 }
994
995 if (!tpkt_ensure_stream_consumed(license->log, s, length))
996 return STATE_RUN_FAILED;
997 return STATE_RUN_SUCCESS;
998}
999
1000state_run_t license_client_recv(rdpLicense* license, wStream* s)
1001{
1002 state_run_t rc = license_client_recv_int(license, s);
1003 if (state_run_failed(rc))
1004 {
1005 freerdp_set_last_error(license->rdp->context, ERROR_CTX_LICENSE_CLIENT_INVALID);
1006 }
1007 return rc;
1008}
1009
1010state_run_t license_server_recv(rdpLicense* license, wStream* s)
1011{
1012 state_run_t rc = STATE_RUN_FAILED;
1013 BYTE flags = 0;
1014 BYTE bMsgType = 0;
1015 UINT16 wMsgSize = 0;
1016 const size_t length = Stream_GetRemainingLength(s);
1017
1018 WINPR_ASSERT(license);
1019
1020 if (!license_read_preamble(license->log, s, &bMsgType, &flags,
1021 &wMsgSize)) /* preamble (4 bytes) */
1022 goto fail;
1023
1024 DEBUG_LICENSE("Receiving %s Packet", license_request_type_string(bMsgType));
1025
1026 switch (bMsgType)
1027 {
1028 case NEW_LICENSE_REQUEST:
1029 if (!license_ensure_state(license, LICENSE_STATE_REQUEST, bMsgType))
1030 goto fail;
1031 if (!license_read_new_license_request_packet(license, s))
1032 goto fail;
1033 // TODO: Validate if client is allowed
1034 if (!license_send_error_alert(license, ERR_INVALID_MAC, ST_TOTAL_ABORT,
1035 license->ErrorInfo))
1036 goto fail;
1037 if (!license_send_platform_challenge_packet(license))
1038 goto fail;
1039 license->update = FALSE;
1040 license_set_state(license, LICENSE_STATE_PLATFORM_CHALLENGE);
1041 break;
1042 case LICENSE_INFO:
1043 if (!license_ensure_state(license, LICENSE_STATE_REQUEST, bMsgType))
1044 goto fail;
1045 if (!license_read_license_info(license, s))
1046 goto fail;
1047 // TODO: Validate license info
1048 if (!license_send_platform_challenge_packet(license))
1049 goto fail;
1050 license_set_state(license, LICENSE_STATE_PLATFORM_CHALLENGE);
1051 license->update = TRUE;
1052 break;
1053
1054 case PLATFORM_CHALLENGE_RESPONSE:
1055 if (!license_ensure_state(license, LICENSE_STATE_PLATFORM_CHALLENGE, bMsgType))
1056 goto fail;
1057 if (!license_read_client_platform_challenge_response(license, s))
1058 goto fail;
1059
1060 // TODO: validate challenge response
1061 if (FALSE)
1062 {
1063 if (license_send_error_alert(license, ERR_INVALID_CLIENT, ST_TOTAL_ABORT,
1064 license->ErrorInfo))
1065 goto fail;
1066 }
1067 else
1068 {
1069 if (!license_server_send_new_or_upgrade_license(license, license->update))
1070 goto fail;
1071
1072 license->type = LICENSE_TYPE_ISSUED;
1073 license_set_state(license, LICENSE_STATE_COMPLETED);
1074
1075 rc = STATE_RUN_CONTINUE; /* License issued, switch state */
1076 }
1077 break;
1078
1079 case ERROR_ALERT:
1080 if (!license_read_error_alert_packet(license, s))
1081 goto fail;
1082 break;
1083
1084 default:
1085 WLog_Print(license->log, WLOG_ERROR, "invalid bMsgType:%" PRIu8 "", bMsgType);
1086 goto fail;
1087 }
1088
1089 if (!tpkt_ensure_stream_consumed(license->log, s, length))
1090 goto fail;
1091
1092 if (!state_run_success(rc))
1093 rc = STATE_RUN_SUCCESS;
1094
1095fail:
1096 if (state_run_failed(rc))
1097 {
1098 if (flags & EXTENDED_ERROR_MSG_SUPPORTED)
1099 {
1100 if (!license_send_error_alert(license, ERR_INVALID_CLIENT, ST_TOTAL_ABORT, nullptr))
1101 {
1102 WLog_Print(license->log, WLOG_ERROR, "license_send_error_alert failed");
1103 }
1104 }
1105 license_set_state(license, LICENSE_STATE_ABORTED);
1106 }
1107
1108 return rc;
1109}
1110
1111BOOL license_generate_randoms(rdpLicense* license)
1112{
1113 WINPR_ASSERT(license);
1114
1115#ifdef LICENSE_NULL_CLIENT_RANDOM
1116 ZeroMemory(license->ClientRandom, sizeof(license->ClientRandom)); /* ClientRandom */
1117#else
1118 if (winpr_RAND(license->ClientRandom, sizeof(license->ClientRandom)) < 0) /* ClientRandom */
1119 return FALSE;
1120#endif
1121
1122 if (winpr_RAND(license->ServerRandom, sizeof(license->ServerRandom)) < 0) /* ServerRandom */
1123 return FALSE;
1124
1125#ifdef LICENSE_NULL_PREMASTER_SECRET
1126 ZeroMemory(license->PremasterSecret, sizeof(license->PremasterSecret)); /* PremasterSecret */
1127#else
1128 if (winpr_RAND(license->PremasterSecret, sizeof(license->PremasterSecret)) <
1129 0) /* PremasterSecret */
1130 return FALSE;
1131#endif
1132 return TRUE;
1133}
1134
1139WINPR_ATTR_NODISCARD
1140static BOOL license_generate_keys(rdpLicense* license)
1141{
1142 WINPR_ASSERT(license);
1143
1144 if (
1145 /* MasterSecret */
1146 !security_master_secret(license->PremasterSecret, sizeof(license->PremasterSecret),
1147 license->ClientRandom, sizeof(license->ClientRandom),
1148 license->ServerRandom, sizeof(license->ServerRandom),
1149 license->MasterSecret, sizeof(license->MasterSecret)) ||
1150 /* SessionKeyBlob */
1151 !security_session_key_blob(license->MasterSecret, sizeof(license->MasterSecret),
1152 license->ClientRandom, sizeof(license->ClientRandom),
1153 license->ServerRandom, sizeof(license->ServerRandom),
1154 license->SessionKeyBlob, sizeof(license->SessionKeyBlob)))
1155 {
1156 return FALSE;
1157 }
1158 security_mac_salt_key(license->SessionKeyBlob, sizeof(license->SessionKeyBlob),
1159 license->ClientRandom, sizeof(license->ClientRandom),
1160 license->ServerRandom, sizeof(license->ServerRandom), license->MacSaltKey,
1161 sizeof(license->MacSaltKey)); /* MacSaltKey */
1162 const BOOL ret = security_licensing_encryption_key(
1163 license->SessionKeyBlob, sizeof(license->SessionKeyBlob), license->ClientRandom,
1164 sizeof(license->ClientRandom), license->ServerRandom, sizeof(license->ServerRandom),
1165 license->LicensingEncryptionKey,
1166 sizeof(license->LicensingEncryptionKey)); /* LicensingEncryptionKey */
1167
1168 WLog_Print(license->log, WLOG_TRACE, "license keys %s generated", ret ? "successfully" : "NOT");
1169
1170#ifdef WITH_DEBUG_LICENSE
1171 WLog_Print(license->log, WLOG_DEBUG, "ClientRandom:");
1172 winpr_HexLogDump(license->log, WLOG_DEBUG, license->ClientRandom,
1173 sizeof(license->ClientRandom));
1174 WLog_Print(license->log, WLOG_DEBUG, "ServerRandom:");
1175 winpr_HexLogDump(license->log, WLOG_DEBUG, license->ServerRandom,
1176 sizeof(license->ServerRandom));
1177 WLog_Print(license->log, WLOG_DEBUG, "PremasterSecret:");
1178 winpr_HexLogDump(license->log, WLOG_DEBUG, license->PremasterSecret,
1179 sizeof(license->PremasterSecret));
1180 WLog_Print(license->log, WLOG_DEBUG, "MasterSecret:");
1181 winpr_HexLogDump(license->log, WLOG_DEBUG, license->MasterSecret,
1182 sizeof(license->MasterSecret));
1183 WLog_Print(license->log, WLOG_DEBUG, "SessionKeyBlob:");
1184 winpr_HexLogDump(license->log, WLOG_DEBUG, license->SessionKeyBlob,
1185 sizeof(license->SessionKeyBlob));
1186 WLog_Print(license->log, WLOG_DEBUG, "MacSaltKey:");
1187 winpr_HexLogDump(license->log, WLOG_DEBUG, license->MacSaltKey, sizeof(license->MacSaltKey));
1188 WLog_Print(license->log, WLOG_DEBUG, "LicensingEncryptionKey:");
1189 winpr_HexLogDump(license->log, WLOG_DEBUG, license->LicensingEncryptionKey,
1190 sizeof(license->LicensingEncryptionKey));
1191#endif
1192 return ret;
1193}
1194
1200BOOL license_generate_hwid(rdpLicense* license)
1201{
1202 const BYTE* hashTarget = nullptr;
1203 size_t targetLen = 0;
1204 BYTE macAddress[6] = WINPR_C_ARRAY_INIT;
1205
1206 WINPR_ASSERT(license);
1207 WINPR_ASSERT(license->rdp);
1208 WINPR_ASSERT(license->rdp->settings);
1209
1210 ZeroMemory(license->HardwareId, sizeof(license->HardwareId));
1211
1212 if (license->rdp->settings->OldLicenseBehaviour)
1213 {
1214 hashTarget = macAddress;
1215 targetLen = sizeof(macAddress);
1216 }
1217 else
1218 {
1219 wStream buffer = WINPR_C_ARRAY_INIT;
1220 const char* hostname = license->rdp->settings->ClientHostname;
1221 wStream* s = Stream_StaticInit(&buffer, license->HardwareId, 4);
1222 Stream_Write_UINT32(s, license->PlatformId);
1223
1224 hashTarget = (const BYTE*)hostname;
1225 targetLen = hostname ? strlen(hostname) : 0;
1226 }
1227
1228 /* Allow FIPS override for use of MD5 here, really this does not have to be MD5 as we are just
1229 * taking a MD5 hash of the 6 bytes of 0's(macAddress) */
1230 /* and filling in the Data1-Data4 fields of the CLIENT_HARDWARE_ID structure(from MS-RDPELE
1231 * section 2.2.2.3.1). This is for RDP licensing packets */
1232 /* which will already be encrypted under FIPS, so the use of MD5 here is not for sensitive data
1233 * protection. */
1234 return winpr_Digest_Allow_FIPS(WINPR_MD_MD5, hashTarget, targetLen,
1235 &license->HardwareId[HWID_PLATFORM_ID_LENGTH],
1236 WINPR_MD5_DIGEST_LENGTH);
1237}
1238
1239WINPR_ATTR_NODISCARD
1240static BOOL license_get_server_rsa_public_key(rdpLicense* license)
1241{
1242 rdpSettings* settings = nullptr;
1243
1244 WINPR_ASSERT(license);
1245 WINPR_ASSERT(license->certificate);
1246 WINPR_ASSERT(license->rdp);
1247
1248 settings = license->rdp->settings;
1249 WINPR_ASSERT(settings);
1250
1251 if (license->ServerCertificate->length < 1)
1252 {
1253 if (!freerdp_certificate_read_server_cert(license->certificate, settings->ServerCertificate,
1254 settings->ServerCertificateLength))
1255 return FALSE;
1256 }
1257
1258 return TRUE;
1259}
1260
1261BOOL license_encrypt_premaster_secret(rdpLicense* license)
1262{
1263 WINPR_ASSERT(license);
1264 WINPR_ASSERT(license->certificate);
1265
1266 if (!license_get_server_rsa_public_key(license))
1267 return FALSE;
1268
1269 WINPR_ASSERT(license->EncryptedPremasterSecret);
1270
1271 const rdpCertInfo* info = freerdp_certificate_get_info(license->certificate);
1272 if (!info)
1273 {
1274 WLog_Print(license->log, WLOG_ERROR, "info=%p, license->certificate=%p", (const void*)info,
1275 (void*)license->certificate);
1276 return FALSE;
1277 }
1278
1279#ifdef WITH_DEBUG_LICENSE
1280 WLog_Print(license->log, WLOG_DEBUG, "Modulus (%" PRIu32 " bits):", info->ModulusLength * 8);
1281 winpr_HexLogDump(license->log, WLOG_DEBUG, info->Modulus, info->ModulusLength);
1282 WLog_Print(license->log, WLOG_DEBUG, "Exponent:");
1283 winpr_HexLogDump(license->log, WLOG_DEBUG, info->exponent, sizeof(info->exponent));
1284#endif
1285
1286 BYTE* EncryptedPremasterSecret = (BYTE*)calloc(1, info->ModulusLength);
1287 if (!EncryptedPremasterSecret)
1288 {
1289 WLog_Print(license->log, WLOG_ERROR,
1290 "EncryptedPremasterSecret=%p, info->ModulusLength=%" PRIu32,
1291 (const void*)EncryptedPremasterSecret, info->ModulusLength);
1292 return FALSE;
1293 }
1294
1295 license->EncryptedPremasterSecret->type = BB_RANDOM_BLOB;
1296 license->EncryptedPremasterSecret->length = sizeof(license->PremasterSecret);
1297#ifndef LICENSE_NULL_PREMASTER_SECRET
1298 {
1299 const SSIZE_T length =
1300 crypto_rsa_public_encrypt(license->PremasterSecret, sizeof(license->PremasterSecret),
1301 info, EncryptedPremasterSecret, info->ModulusLength);
1302 if ((length < 0) || (length > UINT16_MAX))
1303 {
1304 WLog_Print(license->log, WLOG_ERROR, "RSA public encrypt length=%" PRIdz " < 0 || > %d",
1305 length, UINT16_MAX);
1306 return FALSE;
1307 }
1308 license->EncryptedPremasterSecret->length = (UINT16)length;
1309 }
1310#endif
1311 license->EncryptedPremasterSecret->data = EncryptedPremasterSecret;
1312 return TRUE;
1313}
1314
1315WINPR_ATTR_NODISCARD
1316static BOOL license_rc4_with_licenseKey(const rdpLicense* license, const BYTE* input, size_t len,
1317 LICENSE_BLOB* target)
1318{
1319 WINPR_ASSERT(license);
1320 WINPR_ASSERT(input || (len == 0));
1321 WINPR_ASSERT(target);
1322 WINPR_ASSERT(len <= UINT16_MAX);
1323
1324 WINPR_RC4_CTX* rc4 = winpr_RC4_New_Allow_FIPS(license->LicensingEncryptionKey,
1325 sizeof(license->LicensingEncryptionKey));
1326 if (!rc4)
1327 {
1328 WLog_Print(license->log, WLOG_ERROR, "Failed to allocate RC4");
1329 return FALSE;
1330 }
1331
1332 BYTE* buffer = nullptr;
1333 if (len > 0)
1334 buffer = realloc(target->data, len);
1335 if (!buffer)
1336 goto error_buffer;
1337
1338 target->data = buffer;
1339 target->length = (UINT16)len;
1340
1341 if (!winpr_RC4_Update(rc4, len, input, buffer))
1342 goto error_buffer;
1343
1344 winpr_RC4_Free(rc4);
1345 return TRUE;
1346
1347error_buffer:
1348 WLog_Print(license->log, WLOG_ERROR, "Failed to create/update RC4: len=%" PRIuz ", buffer=%p",
1349 len, (const void*)buffer);
1350 winpr_RC4_Free(rc4);
1351 return FALSE;
1352}
1353
1365WINPR_ATTR_NODISCARD
1366static BOOL license_encrypt_and_MAC(rdpLicense* license, const BYTE* input, size_t len,
1367 LICENSE_BLOB* target, BYTE* mac, size_t mac_length)
1368{
1369 WINPR_ASSERT(license);
1370 return license_rc4_with_licenseKey(license, input, len, target) &&
1371 security_mac_data(license->MacSaltKey, sizeof(license->MacSaltKey), input, len, mac,
1372 mac_length);
1373}
1374
1386WINPR_ATTR_NODISCARD
1387static BOOL license_decrypt_and_check_MAC(rdpLicense* license, const BYTE* input, size_t len,
1388 LICENSE_BLOB* target, const BYTE* packetMac)
1389{
1390 BYTE macData[sizeof(license->MACData)] = WINPR_C_ARRAY_INIT;
1391
1392 WINPR_ASSERT(license);
1393 WINPR_ASSERT(target);
1394
1395 if (freerdp_settings_get_bool(license->rdp->settings, FreeRDP_TransportDumpReplay))
1396 {
1397 WLog_Print(license->log, WLOG_DEBUG, "TransportDumpReplay active, skipping...");
1398 return TRUE;
1399 }
1400
1401 if (!license_rc4_with_licenseKey(license, input, len, target))
1402 return FALSE;
1403
1404 if (!security_mac_data(license->MacSaltKey, sizeof(license->MacSaltKey), target->data, len,
1405 macData, sizeof(macData)))
1406 return FALSE;
1407
1408 if (memcmp(packetMac, macData, sizeof(macData)) != 0)
1409 {
1410 WLog_Print(license->log, WLOG_ERROR, "packetMac != expectedMac");
1411 return FALSE;
1412 }
1413 return TRUE;
1414}
1415
1423BOOL license_read_product_info(wLog* log, wStream* s, LICENSE_PRODUCT_INFO* productInfo)
1424{
1425 WINPR_ASSERT(productInfo);
1426
1427 if (!license_check_stream_length(log, s, 8, "license product info::cbCompanyName"))
1428 return FALSE;
1429
1430 Stream_Read_UINT32(s, productInfo->dwVersion); /* dwVersion (4 bytes) */
1431 Stream_Read_UINT32(s, productInfo->cbCompanyName); /* cbCompanyName (4 bytes) */
1432
1433 /* Name must be >0, but there is no upper limit defined, use UINT32_MAX */
1434 if ((productInfo->cbCompanyName < 2) || (productInfo->cbCompanyName % 2 != 0))
1435 {
1436 WLog_Print(log, WLOG_WARN, "license product info invalid cbCompanyName %" PRIu32,
1437 productInfo->cbCompanyName);
1438 return FALSE;
1439 }
1440
1441 if (!license_check_stream_length(log, s, productInfo->cbCompanyName,
1442 "license product info::CompanyName"))
1443 return FALSE;
1444
1445 productInfo->pbProductId = nullptr;
1446 productInfo->pbCompanyName = (BYTE*)malloc(productInfo->cbCompanyName);
1447 if (!productInfo->pbCompanyName)
1448 goto out_fail;
1449 Stream_Read(s, productInfo->pbCompanyName, productInfo->cbCompanyName);
1450
1451 if (!license_check_stream_length(log, s, 4, "license product info::cbProductId"))
1452 goto out_fail;
1453
1454 Stream_Read_UINT32(s, productInfo->cbProductId); /* cbProductId (4 bytes) */
1455
1456 if ((productInfo->cbProductId < 2) || (productInfo->cbProductId % 2 != 0))
1457 {
1458 WLog_Print(log, WLOG_WARN, "license product info invalid cbProductId %" PRIu32,
1459 productInfo->cbProductId);
1460 goto out_fail;
1461 }
1462
1463 if (!license_check_stream_length(log, s, productInfo->cbProductId,
1464 "license product info::ProductId"))
1465 goto out_fail;
1466
1467 productInfo->pbProductId = (BYTE*)malloc(productInfo->cbProductId);
1468 if (!productInfo->pbProductId)
1469 goto out_fail;
1470 Stream_Read(s, productInfo->pbProductId, productInfo->cbProductId);
1471 return TRUE;
1472
1473out_fail:
1474 free(productInfo->pbCompanyName);
1475 free(productInfo->pbProductId);
1476 productInfo->pbCompanyName = nullptr;
1477 productInfo->pbProductId = nullptr;
1478 return FALSE;
1479}
1480
1481WINPR_ATTR_NODISCARD
1482static BOOL license_write_product_info(wLog* log, wStream* s,
1483 const LICENSE_PRODUCT_INFO* productInfo)
1484{
1485 WINPR_ASSERT(productInfo);
1486
1487 if (!license_check_stream_capacity(log, s, 8, "license product info::cbCompanyName"))
1488 return FALSE;
1489
1490 Stream_Write_UINT32(s, productInfo->dwVersion); /* dwVersion (4 bytes) */
1491 Stream_Write_UINT32(s, productInfo->cbCompanyName); /* cbCompanyName (4 bytes) */
1492
1493 /* Name must be >0, but there is no upper limit defined, use UINT32_MAX */
1494 if ((productInfo->cbCompanyName < 2) || (productInfo->cbCompanyName % 2 != 0) ||
1495 !productInfo->pbCompanyName)
1496 {
1497 WLog_Print(log, WLOG_WARN, "license product info invalid cbCompanyName %" PRIu32,
1498 productInfo->cbCompanyName);
1499 return FALSE;
1500 }
1501
1502 if (!license_check_stream_capacity(log, s, productInfo->cbCompanyName,
1503 "license product info::CompanyName"))
1504 return FALSE;
1505
1506 Stream_Write(s, productInfo->pbCompanyName, productInfo->cbCompanyName);
1507
1508 if (!license_check_stream_capacity(log, s, 4, "license product info::cbProductId"))
1509 return FALSE;
1510
1511 Stream_Write_UINT32(s, productInfo->cbProductId); /* cbProductId (4 bytes) */
1512
1513 if ((productInfo->cbProductId < 2) || (productInfo->cbProductId % 2 != 0) ||
1514 !productInfo->pbProductId)
1515 {
1516 WLog_Print(log, WLOG_WARN, "license product info invalid cbProductId %" PRIu32,
1517 productInfo->cbProductId);
1518 return FALSE;
1519 }
1520
1521 if (!license_check_stream_capacity(log, s, productInfo->cbProductId,
1522 "license product info::ProductId"))
1523 return FALSE;
1524
1525 Stream_Write(s, productInfo->pbProductId, productInfo->cbProductId);
1526 return TRUE;
1527}
1528
1535LICENSE_PRODUCT_INFO* license_new_product_info(void)
1536{
1537 LICENSE_PRODUCT_INFO* productInfo =
1538 (LICENSE_PRODUCT_INFO*)calloc(1, sizeof(LICENSE_PRODUCT_INFO));
1539 if (!productInfo)
1540 return nullptr;
1541 return productInfo;
1542}
1543
1550void license_free_product_info(LICENSE_PRODUCT_INFO* productInfo)
1551{
1552 if (productInfo)
1553 {
1554 free(productInfo->pbCompanyName);
1555 free(productInfo->pbProductId);
1556 free(productInfo);
1557 }
1558}
1559
1560BOOL license_read_binary_blob_data(wLog* log, LICENSE_BLOB* blob, UINT16 wBlobType,
1561 const void* data, size_t length)
1562{
1563 WINPR_ASSERT(blob);
1564 WINPR_ASSERT(length <= UINT16_MAX);
1565 WINPR_ASSERT(data || (length == 0));
1566
1567 blob->length = (UINT16)length;
1568 free(blob->data);
1569 blob->data = nullptr;
1570
1571 if ((blob->type != wBlobType) && (blob->type != BB_ANY_BLOB))
1572 {
1573 WLog_Print(log, WLOG_ERROR, "license binary blob::type expected %s, got %s",
1574 license_blob_type_string(wBlobType), license_blob_type_string(blob->type));
1575 }
1576
1577 /*
1578 * Server can choose to not send data by setting length to 0.
1579 * If so, it may not bother to set the type, so shortcut the warning
1580 */
1581 if ((blob->type != BB_ANY_BLOB) && (blob->length == 0))
1582 {
1583 WLog_Print(log, WLOG_DEBUG, "license binary blob::type %s, length=0, skipping.",
1584 license_blob_type_string(blob->type));
1585 return TRUE;
1586 }
1587
1588 blob->type = wBlobType;
1589 blob->data = nullptr;
1590 if (blob->length > 0)
1591 blob->data = malloc(blob->length);
1592 if (!blob->data)
1593 {
1594 WLog_Print(log, WLOG_ERROR, "license binary blob::length=%" PRIu16 ", blob::data=%p",
1595 blob->length, (const void*)blob->data);
1596 return FALSE;
1597 }
1598 memcpy(blob->data, data, blob->length); /* blobData */
1599 return TRUE;
1600}
1601
1609BOOL license_read_binary_blob(wLog* log, wStream* s, LICENSE_BLOB* blob)
1610{
1611 UINT16 wBlobType = 0;
1612 UINT16 length = 0;
1613
1614 WINPR_ASSERT(blob);
1615
1616 if (!license_check_stream_length(log, s, 4, "license binary blob::type"))
1617 return FALSE;
1618
1619 Stream_Read_UINT16(s, wBlobType); /* wBlobType (2 bytes) */
1620 Stream_Read_UINT16(s, length); /* wBlobLen (2 bytes) */
1621
1622 if (!license_check_stream_length(log, s, length, "license binary blob::length"))
1623 return FALSE;
1624
1625 if (!license_read_binary_blob_data(log, blob, wBlobType, Stream_Pointer(s), length))
1626 return FALSE;
1627
1628 return Stream_SafeSeek(s, length);
1629}
1630
1638BOOL license_write_binary_blob(wStream* s, const LICENSE_BLOB* blob)
1639{
1640 WINPR_ASSERT(blob);
1641
1642 if (!Stream_EnsureRemainingCapacity(s, blob->length + 4))
1643 return FALSE;
1644
1645 Stream_Write_UINT16(s, blob->type); /* wBlobType (2 bytes) */
1646 Stream_Write_UINT16(s, blob->length); /* wBlobLen (2 bytes) */
1647
1648 if (blob->length > 0)
1649 Stream_Write(s, blob->data, blob->length); /* blobData */
1650 return TRUE;
1651}
1652
1653WINPR_ATTR_NODISCARD
1654static BOOL license_write_encrypted_premaster_secret_blob(wLog* log, wStream* s,
1655 const LICENSE_BLOB* blob,
1656 UINT32 ModulusLength)
1657{
1658 const UINT32 length = ModulusLength + 8;
1659
1660 WINPR_ASSERT(blob);
1661 WINPR_ASSERT(length <= UINT16_MAX);
1662
1663 if (blob->length > ModulusLength)
1664 {
1665 WLog_Print(log, WLOG_ERROR, "invalid blob");
1666 return FALSE;
1667 }
1668
1669 if (!Stream_EnsureRemainingCapacity(s, length + 4))
1670 return FALSE;
1671 Stream_Write_UINT16(s, blob->type); /* wBlobType (2 bytes) */
1672 Stream_Write_UINT16(s, (UINT16)length); /* wBlobLen (2 bytes) */
1673
1674 if (blob->length > 0)
1675 Stream_Write(s, blob->data, blob->length); /* blobData */
1676
1677 Stream_Zero(s, length - blob->length);
1678 return TRUE;
1679}
1680
1681WINPR_ATTR_NODISCARD
1682static BOOL license_read_encrypted_premaster_secret_blob(wLog* log, wStream* s, LICENSE_BLOB* blob,
1683 UINT32* ModulusLength)
1684{
1685 if (!license_read_binary_blob(log, s, blob))
1686 return FALSE;
1687 WINPR_ASSERT(ModulusLength);
1688 *ModulusLength = blob->length;
1689 return TRUE;
1690}
1691
1698LICENSE_BLOB* license_new_binary_blob(UINT16 type)
1699{
1700 LICENSE_BLOB* blob = (LICENSE_BLOB*)calloc(1, sizeof(LICENSE_BLOB));
1701 if (blob)
1702 blob->type = type;
1703 return blob;
1704}
1705
1712void license_free_binary_blob(LICENSE_BLOB* blob)
1713{
1714 if (blob)
1715 {
1716 free(blob->data);
1717 free(blob);
1718 }
1719}
1720
1728BOOL license_read_scope_list(wLog* log, wStream* s, SCOPE_LIST* scopeList)
1729{
1730 UINT32 scopeCount = 0;
1731
1732 WINPR_ASSERT(scopeList);
1733
1734 if (!license_check_stream_length(log, s, 4, "license scope list"))
1735 return FALSE;
1736
1737 Stream_Read_UINT32(s, scopeCount); /* ScopeCount (4 bytes) */
1738
1739 if (!license_check_stream_length(log, s, 4ull * scopeCount, "license scope list::count"))
1740 return FALSE;
1741
1742 if (!license_scope_list_resize(scopeList, scopeCount))
1743 return FALSE;
1744 /* ScopeArray */
1745 for (UINT32 i = 0; i < scopeCount; i++)
1746 {
1747 if (!license_read_binary_blob(log, s, scopeList->array[i]))
1748 return FALSE;
1749 }
1750
1751 return TRUE;
1752}
1753
1754BOOL license_write_scope_list(wLog* log, wStream* s, const SCOPE_LIST* scopeList)
1755{
1756 WINPR_ASSERT(scopeList);
1757
1758 if (!license_check_stream_capacity(log, s, 4, "license scope list"))
1759 return FALSE;
1760
1761 Stream_Write_UINT32(s, scopeList->count); /* ScopeCount (4 bytes) */
1762
1763 if (!license_check_stream_capacity(log, s, scopeList->count * 4ull,
1764 "license scope list::count"))
1765 return FALSE;
1766
1767 /* ScopeArray */
1768 WINPR_ASSERT(scopeList->array || (scopeList->count == 0));
1769 for (UINT32 i = 0; i < scopeList->count; i++)
1770 {
1771 const LICENSE_BLOB* element = scopeList->array[i];
1772
1773 if (!license_write_binary_blob(s, element))
1774 return FALSE;
1775 }
1776
1777 return TRUE;
1778}
1779
1786SCOPE_LIST* license_new_scope_list(void)
1787{
1788 SCOPE_LIST* list = calloc(1, sizeof(SCOPE_LIST));
1789 return list;
1790}
1791
1792static void license_scope_list_free(SCOPE_LIST* scopeList, UINT32 count)
1793{
1794 WINPR_ASSERT(scopeList);
1795 WINPR_ASSERT(scopeList->array || (scopeList->count == 0));
1796
1797 for (UINT32 x = count; x < scopeList->count; x++)
1798 {
1799 license_free_binary_blob(scopeList->array[x]);
1800 scopeList->array[x] = nullptr;
1801 }
1802
1803 if (count == 0)
1804 {
1805 free((void*)scopeList->array);
1806 scopeList->array = nullptr;
1807 }
1808}
1809
1810BOOL license_scope_list_resize(SCOPE_LIST* scopeList, UINT32 count)
1811{
1812 license_scope_list_free(scopeList, count);
1813 if (count > 0)
1814 {
1815 LICENSE_BLOB** tmp =
1816 (LICENSE_BLOB**)realloc((void*)scopeList->array, count * sizeof(LICENSE_BLOB*));
1817 if (!tmp)
1818 return FALSE;
1819 scopeList->array = tmp;
1820 }
1821
1822 for (UINT32 x = scopeList->count; x < count; x++)
1823 {
1824 LICENSE_BLOB* blob = license_new_binary_blob(BB_SCOPE_BLOB);
1825 if (!blob)
1826 {
1827 scopeList->count = x;
1828 return FALSE;
1829 }
1830 scopeList->array[x] = blob;
1831 }
1832
1833 scopeList->count = count;
1834 return TRUE;
1835}
1836
1843void license_free_scope_list(SCOPE_LIST* scopeList)
1844{
1845 if (!scopeList)
1846 return;
1847
1848 license_scope_list_free(scopeList, 0);
1849 free(scopeList);
1850}
1851
1852BOOL license_send_license_info(rdpLicense* license, const LICENSE_BLOB* calBlob,
1853 const BYTE* signature, size_t signature_length)
1854{
1855 WINPR_ASSERT(calBlob);
1856 WINPR_ASSERT(signature);
1857 WINPR_ASSERT(license->certificate);
1858
1859 const rdpCertInfo* info = freerdp_certificate_get_info(license->certificate);
1860 if (!info)
1861 return FALSE;
1862
1863 UINT16 sec_flags = 0;
1864 wStream* s = license_send_stream_init(license, &sec_flags);
1865 if (!s)
1866 return FALSE;
1867
1868 if (!license_check_stream_capacity(license->log, s, 8 + sizeof(license->ClientRandom),
1869 "license info::ClientRandom"))
1870 goto error;
1871
1872 Stream_Write_UINT32(s,
1873 license->PreferredKeyExchangeAlg); /* PreferredKeyExchangeAlg (4 bytes) */
1874 Stream_Write_UINT32(s, license->PlatformId); /* PlatformId (4 bytes) */
1875
1876 /* ClientRandom (32 bytes) */
1877 Stream_Write(s, license->ClientRandom, sizeof(license->ClientRandom));
1878
1879 /* Licensing Binary Blob with EncryptedPreMasterSecret: */
1880 if (!license_write_encrypted_premaster_secret_blob(
1881 license->log, s, license->EncryptedPremasterSecret, info->ModulusLength))
1882 goto error;
1883
1884 /* Licensing Binary Blob with LicenseInfo: */
1885 if (!license_write_binary_blob(s, calBlob))
1886 goto error;
1887
1888 /* Licensing Binary Blob with EncryptedHWID */
1889 if (!license_write_binary_blob(s, license->EncryptedHardwareId))
1890 goto error;
1891
1892 /* MACData */
1893 if (!license_check_stream_capacity(license->log, s, signature_length, "license info::MACData"))
1894 goto error;
1895 Stream_Write(s, signature, signature_length);
1896
1897 return license_send(license, s, LICENSE_INFO, sec_flags);
1898
1899error:
1900 Stream_Release(s);
1901 return FALSE;
1902}
1903
1904WINPR_ATTR_NODISCARD
1905static BOOL license_check_preferred_alg(rdpLicense* license, UINT32 PreferredKeyExchangeAlg,
1906 const char* where)
1907{
1908 WINPR_ASSERT(license);
1909 WINPR_ASSERT(where);
1910
1911 if (license->PreferredKeyExchangeAlg != PreferredKeyExchangeAlg)
1912 {
1913 char buffer1[64] = WINPR_C_ARRAY_INIT;
1914 char buffer2[64] = WINPR_C_ARRAY_INIT;
1915 WLog_Print(license->log, WLOG_WARN, "%s::PreferredKeyExchangeAlg, expected %s, got %s",
1916 where,
1917 license_preferred_key_exchange_alg_string(license->PreferredKeyExchangeAlg,
1918 buffer1, sizeof(buffer1)),
1919 license_preferred_key_exchange_alg_string(PreferredKeyExchangeAlg, buffer2,
1920 sizeof(buffer2)));
1921 return FALSE;
1922 }
1923 return TRUE;
1924}
1925
1926BOOL license_read_license_info(rdpLicense* license, wStream* s)
1927{
1928 BOOL rc = FALSE;
1929 UINT32 PreferredKeyExchangeAlg = 0;
1930
1931 WINPR_ASSERT(license);
1932 WINPR_ASSERT(license->certificate);
1933
1934 const rdpCertInfo* info = freerdp_certificate_get_info(license->certificate);
1935 if (!info)
1936 goto error;
1937
1938 /* ClientRandom (32 bytes) */
1939 if (!license_check_stream_length(license->log, s, 8 + sizeof(license->ClientRandom),
1940 "license info"))
1941 goto error;
1942
1943 Stream_Read_UINT32(s, PreferredKeyExchangeAlg); /* PreferredKeyExchangeAlg (4 bytes) */
1944 if (!license_check_preferred_alg(license, PreferredKeyExchangeAlg, "license info"))
1945 goto error;
1946 Stream_Read_UINT32(s, license->PlatformId); /* PlatformId (4 bytes) */
1947
1948 /* ClientRandom (32 bytes) */
1949 Stream_Read(s, license->ClientRandom, sizeof(license->ClientRandom));
1950
1951 /* Licensing Binary Blob with EncryptedPreMasterSecret: */
1952 {
1953 UINT32 ModulusLength = 0;
1954 if (!license_read_encrypted_premaster_secret_blob(
1955 license->log, s, license->EncryptedPremasterSecret, &ModulusLength))
1956 goto error;
1957
1958 if (ModulusLength != info->ModulusLength)
1959 {
1960 WLog_Print(license->log, WLOG_WARN,
1961 "EncryptedPremasterSecret,::ModulusLength[%" PRIu32
1962 "] != rdpCertInfo::ModulusLength[%" PRIu32 "]",
1963 ModulusLength, info->ModulusLength);
1964 goto error;
1965 }
1966 }
1967
1968 /* Licensing Binary Blob with LicenseInfo: */
1969 if (!license_read_binary_blob(license->log, s, license->LicenseInfo))
1970 goto error;
1971
1972 /* Licensing Binary Blob with EncryptedHWID */
1973 if (!license_read_binary_blob(license->log, s, license->EncryptedHardwareId))
1974 goto error;
1975
1976 /* MACData */
1977 if (!license_check_stream_length(license->log, s, sizeof(license->MACData),
1978 "license info::MACData"))
1979 goto error;
1980 Stream_Read(s, license->MACData, sizeof(license->MACData));
1981
1982 rc = TRUE;
1983
1984error:
1985 return rc;
1986}
1987
1995BOOL license_read_license_request_packet(rdpLicense* license, wStream* s)
1996{
1997 WINPR_ASSERT(license);
1998
1999 /* ServerRandom (32 bytes) */
2000 if (!license_check_stream_length(license->log, s, sizeof(license->ServerRandom),
2001 "license request"))
2002 return FALSE;
2003
2004 Stream_Read(s, license->ServerRandom, sizeof(license->ServerRandom));
2005
2006 /* ProductInfo */
2007 if (!license_read_product_info(license->log, s, license->ProductInfo))
2008 return FALSE;
2009
2010 /* KeyExchangeList */
2011 if (!license_read_binary_blob(license->log, s, license->KeyExchangeList))
2012 return FALSE;
2013
2014 /* ServerCertificate */
2015 if (!license_read_binary_blob(license->log, s, license->ServerCertificate))
2016 return FALSE;
2017
2018 /* ScopeList */
2019 if (!license_read_scope_list(license->log, s, license->ScopeList))
2020 return FALSE;
2021
2022 /* Parse Server Certificate */
2023 if (!freerdp_certificate_read_server_cert(license->certificate,
2024 license->ServerCertificate->data,
2025 license->ServerCertificate->length))
2026 return FALSE;
2027
2028 if (!license_generate_keys(license) || !license_generate_hwid(license) ||
2029 !license_encrypt_premaster_secret(license))
2030 return FALSE;
2031
2032#ifdef WITH_DEBUG_LICENSE
2033 WLog_Print(license->log, WLOG_DEBUG, "ServerRandom:");
2034 winpr_HexLogDump(license->log, WLOG_DEBUG, license->ServerRandom,
2035 sizeof(license->ServerRandom));
2036 license_print_product_info(license->log, license->ProductInfo);
2037 license_print_scope_list(license->log, license->ScopeList);
2038#endif
2039 return TRUE;
2040}
2041
2042BOOL license_write_license_request_packet(const rdpLicense* license, wStream* s)
2043{
2044 WINPR_ASSERT(license);
2045
2046 /* ServerRandom (32 bytes) */
2047 if (!license_check_stream_capacity(license->log, s, sizeof(license->ServerRandom),
2048 "license request"))
2049 return FALSE;
2050 Stream_Write(s, license->ServerRandom, sizeof(license->ServerRandom));
2051
2052 /* ProductInfo */
2053 if (!license_write_product_info(license->log, s, license->ProductInfo))
2054 return FALSE;
2055
2056 /* KeyExchangeList */
2057 if (!license_write_binary_blob(s, license->KeyExchangeList))
2058 return FALSE;
2059
2060 /* ServerCertificate */
2061 if (!license_write_binary_blob(s, license->ServerCertificate))
2062 return FALSE;
2063
2064 /* ScopeList */
2065 if (!license_write_scope_list(license->log, s, license->ScopeList))
2066 return FALSE;
2067
2068 return TRUE;
2069}
2070
2071WINPR_ATTR_NODISCARD
2072static BOOL license_send_license_request_packet(rdpLicense* license)
2073{
2074 UINT16 sec_flags = 0;
2075 wStream* s = license_send_stream_init(license, &sec_flags);
2076 if (!s)
2077 return FALSE;
2078
2079 if (!license_write_license_request_packet(license, s))
2080 goto fail;
2081
2082 return license_send(license, s, LICENSE_REQUEST, sec_flags);
2083
2084fail:
2085 Stream_Release(s);
2086 return FALSE;
2087}
2088
2089/*
2090 * Read a PLATFORM_CHALLENGE packet.
2091 * msdn{cc241921}
2092 * @param license license module
2093 * @param s stream
2094 */
2095
2096BOOL license_read_platform_challenge_packet(rdpLicense* license, wStream* s)
2097{
2098 BYTE macData[LICENSING_ENCRYPTION_KEY_LENGTH] = WINPR_C_ARRAY_INIT;
2099
2100 WINPR_ASSERT(license);
2101
2102 DEBUG_LICENSE("Receiving Platform Challenge Packet");
2103
2104 if (!license_check_stream_length(license->log, s, 4, "license platform challenge"))
2105 return FALSE;
2106
2107 /* [MS-RDPELE] 2.2.2.4 Server Platform Challenge (SERVER_PLATFORM_CHALLENGE)
2108 * reserved field */
2109 Stream_Seek_UINT32(s); /* ConnectFlags, Reserved (4 bytes) */
2110
2111 /* EncryptedPlatformChallenge */
2112 license->EncryptedPlatformChallenge->type = BB_ANY_BLOB;
2113 if (!license_read_binary_blob(license->log, s, license->EncryptedPlatformChallenge))
2114 return FALSE;
2115 license->EncryptedPlatformChallenge->type = BB_ENCRYPTED_DATA_BLOB;
2116
2117 /* MACData (16 bytes) */
2118 if (!license_check_stream_length(license->log, s, sizeof(macData),
2119 "license platform challenge::MAC"))
2120 return FALSE;
2121
2122 Stream_Read(s, macData, sizeof(macData));
2123 if (!license_decrypt_and_check_MAC(license, license->EncryptedPlatformChallenge->data,
2124 license->EncryptedPlatformChallenge->length,
2125 license->PlatformChallenge, macData))
2126 return FALSE;
2127
2128 WLog_Print(license->log, WLOG_TRACE, "platform challenge read");
2129
2130#ifdef WITH_DEBUG_LICENSE
2131 WLog_Print(license->log, WLOG_DEBUG, "EncryptedPlatformChallenge:");
2132 winpr_HexLogDump(license->log, WLOG_DEBUG, license->EncryptedPlatformChallenge->data,
2133 license->EncryptedPlatformChallenge->length);
2134 WLog_Print(license->log, WLOG_DEBUG, "PlatformChallenge:");
2135 winpr_HexLogDump(license->log, WLOG_DEBUG, license->PlatformChallenge->data,
2136 license->PlatformChallenge->length);
2137 WLog_Print(license->log, WLOG_DEBUG, "MacData:");
2138 winpr_HexLogDump(license->log, WLOG_DEBUG, macData, sizeof(macData));
2139#endif
2140 return TRUE;
2141}
2142
2143BOOL license_send_error_alert(rdpLicense* license, UINT32 dwErrorCode, UINT32 dwStateTransition,
2144 const LICENSE_BLOB* info)
2145{
2146 UINT16 sec_flags = 0;
2147 wStream* s = license_send_stream_init(license, &sec_flags);
2148
2149 if (!s)
2150 goto fail;
2151
2152 if (!license_check_stream_capacity(license->log, s, 8, "license error alert"))
2153 goto fail;
2154 Stream_Write_UINT32(s, dwErrorCode);
2155 Stream_Write_UINT32(s, dwStateTransition);
2156
2157 if (info)
2158 {
2159 if (!license_write_binary_blob(s, info))
2160 goto fail;
2161 }
2162
2163 return license_send(license, s, ERROR_ALERT, sec_flags);
2164fail:
2165 Stream_Release(s);
2166 return FALSE;
2167}
2168
2169BOOL license_send_platform_challenge_packet(rdpLicense* license)
2170{
2171 UINT16 sec_flags = 0;
2172 wStream* s = license_send_stream_init(license, &sec_flags);
2173
2174 if (!s)
2175 goto fail;
2176
2177 DEBUG_LICENSE("Receiving Platform Challenge Packet");
2178
2179 if (!license_check_stream_capacity(license->log, s, 4, "license platform challenge"))
2180 goto fail;
2181
2182 Stream_Zero(s, 4); /* ConnectFlags, Reserved (4 bytes) */
2183
2184 /* EncryptedPlatformChallenge */
2185 if (!license_write_binary_blob(s, license->EncryptedPlatformChallenge))
2186 goto fail;
2187
2188 /* MACData (16 bytes) */
2189 if (!license_check_stream_length(license->log, s, sizeof(license->MACData),
2190 "license platform challenge::MAC"))
2191 goto fail;
2192
2193 Stream_Write(s, license->MACData, sizeof(license->MACData));
2194
2195 return license_send(license, s, PLATFORM_CHALLENGE, sec_flags);
2196fail:
2197 Stream_Release(s);
2198 return FALSE;
2199}
2200
2201WINPR_ATTR_NODISCARD
2202static BOOL license_read_encrypted_blob(const rdpLicense* license, wStream* s, LICENSE_BLOB* target)
2203{
2204 UINT16 wBlobType = 0;
2205 UINT16 wBlobLen = 0;
2206
2207 WINPR_ASSERT(license);
2208 WINPR_ASSERT(target);
2209
2210 if (!license_check_stream_length(license->log, s, 4, "license encrypted blob"))
2211 return FALSE;
2212
2213 Stream_Read_UINT16(s, wBlobType);
2214 if (wBlobType != BB_ENCRYPTED_DATA_BLOB)
2215 {
2216 WLog_Print(
2217 license->log, WLOG_WARN,
2218 "expecting BB_ENCRYPTED_DATA_BLOB blob, probably a windows 2003 server, continuing...");
2219 }
2220
2221 Stream_Read_UINT16(s, wBlobLen);
2222
2223 BYTE* encryptedData = Stream_Pointer(s);
2224 if (!Stream_SafeSeek(s, wBlobLen))
2225 {
2226 WLog_Print(license->log, WLOG_WARN,
2227 "short license encrypted blob::length, expected %" PRIu16 " bytes, got %" PRIuz,
2228 wBlobLen, Stream_GetRemainingLength(s));
2229 return FALSE;
2230 }
2231
2232 return license_rc4_with_licenseKey(license, encryptedData, wBlobLen, target);
2233}
2234
2242BOOL license_read_new_or_upgrade_license_packet(rdpLicense* license, wStream* s)
2243{
2244 UINT32 os_major = 0;
2245 UINT32 os_minor = 0;
2246 UINT32 cbScope = 0;
2247 UINT32 cbCompanyName = 0;
2248 UINT32 cbProductId = 0;
2249 UINT32 cbLicenseInfo = 0;
2250 wStream sbuffer = WINPR_C_ARRAY_INIT;
2251 wStream* licenseStream = nullptr;
2252 BOOL ret = FALSE;
2253 BYTE computedMac[16] = WINPR_C_ARRAY_INIT;
2254 const BYTE* readMac = nullptr;
2255
2256 WINPR_ASSERT(license);
2257
2258 DEBUG_LICENSE("Receiving Server New/Upgrade License Packet");
2259
2260 LICENSE_BLOB* calBlob = license_new_binary_blob(BB_DATA_BLOB);
2261 if (!calBlob)
2262 return FALSE;
2263
2264 /* EncryptedLicenseInfo */
2265 if (!license_read_encrypted_blob(license, s, calBlob))
2266 goto fail;
2267
2268 /* compute MAC and check it */
2269 readMac = Stream_Pointer(s);
2270 if (!Stream_SafeSeek(s, sizeof(computedMac)))
2271 {
2272 WLog_Print(license->log, WLOG_WARN,
2273 "short license new/upgrade, expected 16 bytes, got %" PRIuz,
2274 Stream_GetRemainingLength(s));
2275 goto fail;
2276 }
2277
2278 if (!security_mac_data(license->MacSaltKey, sizeof(license->MacSaltKey), calBlob->data,
2279 calBlob->length, computedMac, sizeof(computedMac)))
2280 goto fail;
2281
2282 if (memcmp(computedMac, readMac, sizeof(computedMac)) != 0)
2283 {
2284 WLog_Print(license->log, WLOG_ERROR, "new or upgrade license MAC mismatch");
2285 goto fail;
2286 }
2287
2288 licenseStream = Stream_StaticConstInit(&sbuffer, calBlob->data, calBlob->length);
2289 if (!licenseStream)
2290 {
2291 WLog_Print(license->log, WLOG_ERROR,
2292 "license::blob::data=%p, license::blob::length=%" PRIu16,
2293 (const void*)calBlob->data, calBlob->length);
2294 goto fail;
2295 }
2296
2297 if (!license_check_stream_length(license->log, licenseStream, 8,
2298 "license new/upgrade::blob::version"))
2299 goto fail;
2300
2301 Stream_Read_UINT16(licenseStream, os_minor);
2302 Stream_Read_UINT16(licenseStream, os_major);
2303
2304 WLog_Print(license->log, WLOG_DEBUG, "Version: %" PRIu16 ".%" PRIu16, os_major, os_minor);
2305
2306 /* Scope */
2307 Stream_Read_UINT32(licenseStream, cbScope);
2308 if (!license_check_stream_length(license->log, licenseStream, cbScope,
2309 "license new/upgrade::blob::scope"))
2310 goto fail;
2311
2312#ifdef WITH_DEBUG_LICENSE
2313 WLog_Print(license->log, WLOG_DEBUG, "Scope:");
2314 winpr_HexLogDump(license->log, WLOG_DEBUG, Stream_Pointer(licenseStream), cbScope);
2315#endif
2316 Stream_Seek(licenseStream, cbScope);
2317
2318 /* CompanyName */
2319 if (!license_check_stream_length(license->log, licenseStream, 4,
2320 "license new/upgrade::blob::cbCompanyName"))
2321 goto fail;
2322
2323 Stream_Read_UINT32(licenseStream, cbCompanyName);
2324 if (!license_check_stream_length(license->log, licenseStream, cbCompanyName,
2325 "license new/upgrade::blob::CompanyName"))
2326 goto fail;
2327
2328#ifdef WITH_DEBUG_LICENSE
2329 WLog_Print(license->log, WLOG_DEBUG, "Company name:");
2330 winpr_HexLogDump(license->log, WLOG_DEBUG, Stream_Pointer(licenseStream), cbCompanyName);
2331#endif
2332 Stream_Seek(licenseStream, cbCompanyName);
2333
2334 /* productId */
2335 if (!license_check_stream_length(license->log, licenseStream, 4,
2336 "license new/upgrade::blob::cbProductId"))
2337 goto fail;
2338
2339 Stream_Read_UINT32(licenseStream, cbProductId);
2340
2341 if (!license_check_stream_length(license->log, licenseStream, cbProductId,
2342 "license new/upgrade::blob::ProductId"))
2343 goto fail;
2344
2345#ifdef WITH_DEBUG_LICENSE
2346 WLog_Print(license->log, WLOG_DEBUG, "Product id:");
2347 winpr_HexLogDump(license->log, WLOG_DEBUG, Stream_Pointer(licenseStream), cbProductId);
2348#endif
2349 Stream_Seek(licenseStream, cbProductId);
2350
2351 /* licenseInfo */
2352 if (!license_check_stream_length(license->log, licenseStream, 4,
2353 "license new/upgrade::blob::cbLicenseInfo"))
2354 goto fail;
2355
2356 Stream_Read_UINT32(licenseStream, cbLicenseInfo);
2357 if (!license_check_stream_length(license->log, licenseStream, cbLicenseInfo,
2358 "license new/upgrade::blob::LicenseInfo"))
2359 goto fail;
2360
2361 license->type = LICENSE_TYPE_ISSUED;
2362 license_set_state(license, LICENSE_STATE_COMPLETED);
2363 ret = TRUE;
2364
2365 if (!license->rdp->settings->OldLicenseBehaviour)
2366 ret = saveCal(license->log, license->rdp->settings, Stream_Pointer(licenseStream),
2367 cbLicenseInfo, license->rdp->settings->ClientHostname);
2368
2369fail:
2370 license_free_binary_blob(calBlob);
2371 return ret;
2372}
2373
2381BOOL license_read_error_alert_packet(rdpLicense* license, wStream* s)
2382{
2383 UINT32 dwErrorCode = 0;
2384 UINT32 dwStateTransition = 0;
2385
2386 WINPR_ASSERT(license);
2387 WINPR_ASSERT(license->rdp);
2388
2389 if (!license_check_stream_length(license->log, s, 8ul, "error alert"))
2390 return FALSE;
2391
2392 Stream_Read_UINT32(s, dwErrorCode); /* dwErrorCode (4 bytes) */
2393 Stream_Read_UINT32(s, dwStateTransition); /* dwStateTransition (4 bytes) */
2394
2395 if (!license_read_binary_blob(license->log, s, license->ErrorInfo)) /* bbErrorInfo */
2396 return FALSE;
2397
2398#ifdef WITH_DEBUG_LICENSE
2399 WLog_Print(license->log, WLOG_DEBUG, "dwErrorCode: %s, dwStateTransition: %s",
2400 error_codes[dwErrorCode], state_transitions[dwStateTransition]);
2401#endif
2402
2403 if (dwErrorCode == STATUS_VALID_CLIENT)
2404 {
2405 license->type = LICENSE_TYPE_NONE;
2406 license_set_state(license, LICENSE_STATE_COMPLETED);
2407 return TRUE;
2408 }
2409
2410 switch (dwStateTransition)
2411 {
2412 case ST_TOTAL_ABORT:
2413 license_set_state(license, LICENSE_STATE_ABORTED);
2414 break;
2415 case ST_NO_TRANSITION:
2416 license_set_state(license, LICENSE_STATE_COMPLETED);
2417 break;
2418 case ST_RESET_PHASE_TO_START:
2419 license_set_state(license, LICENSE_STATE_CONFIGURED);
2420 break;
2421 case ST_RESEND_LAST_MESSAGE:
2422 break;
2423 default:
2424 break;
2425 }
2426
2427 return TRUE;
2428}
2429
2437BOOL license_write_new_license_request_packet(const rdpLicense* license, wStream* s)
2438{
2439 WINPR_ASSERT(license);
2440
2441 const rdpCertInfo* info = freerdp_certificate_get_info(license->certificate);
2442 if (!info)
2443 return FALSE;
2444
2445 if (!license_check_stream_capacity(license->log, s, 8 + sizeof(license->ClientRandom),
2446 "License Request"))
2447 return FALSE;
2448
2449 Stream_Write_UINT32(s,
2450 license->PreferredKeyExchangeAlg); /* PreferredKeyExchangeAlg (4 bytes) */
2451 Stream_Write_UINT32(s, license->PlatformId); /* PlatformId (4 bytes) */
2452 Stream_Write(s, license->ClientRandom,
2453 sizeof(license->ClientRandom)); /* ClientRandom (32 bytes) */
2454
2455 if (/* EncryptedPremasterSecret */
2456 !license_write_encrypted_premaster_secret_blob(
2457 license->log, s, license->EncryptedPremasterSecret, info->ModulusLength) ||
2458 /* ClientUserName */
2459 !license_write_binary_blob(s, license->ClientUserName) ||
2460 /* ClientMachineName */
2461 !license_write_binary_blob(s, license->ClientMachineName))
2462 {
2463 return FALSE;
2464 }
2465
2466 WLog_Print(license->log, WLOG_TRACE, "new license written");
2467
2468#ifdef WITH_DEBUG_LICENSE
2469 WLog_Print(license->log, WLOG_DEBUG, "PreferredKeyExchangeAlg: 0x%08" PRIX32 "",
2470 license->PreferredKeyExchangeAlg);
2471 WLog_Print(license->log, WLOG_DEBUG, "ClientRandom:");
2472 winpr_HexLogDump(license->log, WLOG_DEBUG, license->ClientRandom,
2473 sizeof(license->ClientRandom));
2474 WLog_Print(license->log, WLOG_DEBUG, "EncryptedPremasterSecret");
2475 winpr_HexLogDump(license->log, WLOG_DEBUG, license->EncryptedPremasterSecret->data,
2476 license->EncryptedPremasterSecret->length);
2477 WLog_Print(license->log, WLOG_DEBUG, "ClientUserName (%" PRIu16 "): %s",
2478 license->ClientUserName->length, (char*)license->ClientUserName->data);
2479 WLog_Print(license->log, WLOG_DEBUG, "ClientMachineName (%" PRIu16 "): %s",
2480 license->ClientMachineName->length, (char*)license->ClientMachineName->data);
2481#endif
2482 return TRUE;
2483}
2484
2485BOOL license_read_new_license_request_packet(rdpLicense* license, wStream* s)
2486{
2487 UINT32 PreferredKeyExchangeAlg = 0;
2488
2489 WINPR_ASSERT(license);
2490
2491 if (!license_check_stream_length(license->log, s, 8ull + sizeof(license->ClientRandom),
2492 "new license request"))
2493 return FALSE;
2494
2495 Stream_Read_UINT32(s, PreferredKeyExchangeAlg); /* PreferredKeyExchangeAlg (4 bytes) */
2496 if (!license_check_preferred_alg(license, PreferredKeyExchangeAlg, "new license request"))
2497 return FALSE;
2498
2499 Stream_Read_UINT32(s, license->PlatformId); /* PlatformId (4 bytes) */
2500 Stream_Read(s, license->ClientRandom,
2501 sizeof(license->ClientRandom)); /* ClientRandom (32 bytes) */
2502
2503 /* EncryptedPremasterSecret */
2504 UINT32 ModulusLength = 0;
2505 if (!license_read_encrypted_premaster_secret_blob(
2506 license->log, s, license->EncryptedPremasterSecret, &ModulusLength))
2507 return FALSE;
2508
2509 const rdpCertInfo* info = freerdp_certificate_get_info(license->certificate);
2510 if (!info)
2511 WLog_Print(license->log, WLOG_WARN,
2512 "Missing license certificate, skipping ModulusLength checks");
2513 else if (ModulusLength != info->ModulusLength)
2514 {
2515 WLog_Print(license->log, WLOG_WARN,
2516 "EncryptedPremasterSecret expected to be %" PRIu32 " bytes, but read %" PRIu32
2517 " bytes",
2518 info->ModulusLength, ModulusLength);
2519 return FALSE;
2520 }
2521
2522 /* ClientUserName */
2523 if (!license_read_binary_blob(license->log, s, license->ClientUserName))
2524 return FALSE;
2525 /* ClientMachineName */
2526 if (!license_read_binary_blob(license->log, s, license->ClientMachineName))
2527 return FALSE;
2528
2529 return TRUE;
2530}
2531
2538BOOL license_answer_license_request(rdpLicense* license)
2539{
2540 UINT16 sec_flags = 0;
2541 wStream* s = nullptr;
2542 BYTE* license_data = nullptr;
2543 size_t license_size = 0;
2544 BOOL status = 0;
2545 char* username = nullptr;
2546
2547 WINPR_ASSERT(license);
2548 WINPR_ASSERT(license->rdp);
2549 WINPR_ASSERT(license->rdp->settings);
2550
2551 if (!license->rdp->settings->OldLicenseBehaviour)
2552 license_data = loadCalFile(license->log, license->rdp->settings,
2553 license->rdp->settings->ClientHostname, &license_size);
2554
2555 if (license_data)
2556 {
2557 LICENSE_BLOB* calBlob = nullptr;
2558 BYTE signature[LICENSING_ENCRYPTION_KEY_LENGTH] = WINPR_C_ARRAY_INIT;
2559
2560 DEBUG_LICENSE("Sending Saved License Packet");
2561
2562 WINPR_ASSERT(license->EncryptedHardwareId);
2563 license->EncryptedHardwareId->type = BB_ENCRYPTED_DATA_BLOB;
2564 if (!license_encrypt_and_MAC(license, license->HardwareId, sizeof(license->HardwareId),
2565 license->EncryptedHardwareId, signature, sizeof(signature)))
2566 {
2567 free(license_data);
2568 return FALSE;
2569 }
2570
2571 calBlob = license_new_binary_blob(BB_DATA_BLOB);
2572 if (!calBlob)
2573 {
2574 free(license_data);
2575 return FALSE;
2576 }
2577 calBlob->data = license_data;
2578 WINPR_ASSERT(license_size <= UINT16_MAX);
2579 calBlob->length = (UINT16)license_size;
2580
2581 status = license_send_license_info(license, calBlob, signature, sizeof(signature));
2582 license_free_binary_blob(calBlob);
2583
2584 return status;
2585 }
2586
2587 DEBUG_LICENSE("Sending New License Packet");
2588
2589 s = license_send_stream_init(license, &sec_flags);
2590 if (!s)
2591 return FALSE;
2592 if (license->rdp->settings->Username != nullptr)
2593 username = license->rdp->settings->Username;
2594 else
2595 username = "username";
2596
2597 {
2598 WINPR_ASSERT(license->ClientUserName);
2599 const size_t len = strlen(username) + 1;
2600 WINPR_ASSERT(len <= UINT16_MAX);
2601
2602 license->ClientUserName->data = (BYTE*)username;
2603 license->ClientUserName->length = (UINT16)len;
2604 }
2605
2606 {
2607 WINPR_ASSERT(license->ClientMachineName);
2608 const size_t len = strlen(license->rdp->settings->ClientHostname) + 1;
2609 WINPR_ASSERT(len <= UINT16_MAX);
2610
2611 license->ClientMachineName->data = (BYTE*)license->rdp->settings->ClientHostname;
2612 license->ClientMachineName->length = (UINT16)len;
2613 }
2614 status = license_write_new_license_request_packet(license, s);
2615
2616 WINPR_ASSERT(license->ClientUserName);
2617 license->ClientUserName->data = nullptr;
2618 license->ClientUserName->length = 0;
2619
2620 WINPR_ASSERT(license->ClientMachineName);
2621 license->ClientMachineName->data = nullptr;
2622 license->ClientMachineName->length = 0;
2623
2624 if (!status)
2625 {
2626 Stream_Release(s);
2627 return FALSE;
2628 }
2629
2630 return license_send(license, s, NEW_LICENSE_REQUEST, sec_flags);
2631}
2632
2639BOOL license_send_platform_challenge_response(rdpLicense* license)
2640{
2641 wStream* challengeRespData = nullptr;
2642 BYTE* buffer = nullptr;
2643 BOOL status = 0;
2644
2645 WINPR_ASSERT(license);
2646 WINPR_ASSERT(license->PlatformChallenge);
2647 WINPR_ASSERT(license->MacSaltKey);
2648 WINPR_ASSERT(license->EncryptedPlatformChallenge);
2649 WINPR_ASSERT(license->EncryptedHardwareId);
2650
2651 DEBUG_LICENSE("Sending Platform Challenge Response Packet");
2652
2653 license->EncryptedPlatformChallenge->type = BB_DATA_BLOB;
2654
2655 /* prepare the PLATFORM_CHALLENGE_RESPONSE_DATA */
2656 challengeRespData = Stream_New(nullptr, 8 + license->PlatformChallenge->length);
2657 if (!challengeRespData)
2658 return FALSE;
2659 Stream_Write_UINT16(challengeRespData, PLATFORM_CHALLENGE_RESPONSE_VERSION); /* wVersion */
2660 Stream_Write_UINT16(challengeRespData, license->ClientType); /* wClientType */
2661 Stream_Write_UINT16(challengeRespData, license->LicenseDetailLevel); /* wLicenseDetailLevel */
2662 Stream_Write_UINT16(challengeRespData, license->PlatformChallenge->length); /* cbChallenge */
2663 Stream_Write(challengeRespData, license->PlatformChallenge->data,
2664 license->PlatformChallenge->length); /* pbChallenge */
2665 Stream_SealLength(challengeRespData);
2666
2667 /* compute MAC of PLATFORM_CHALLENGE_RESPONSE_DATA + HWID */
2668 const size_t length = Stream_Length(challengeRespData) + sizeof(license->HardwareId);
2669 buffer = (BYTE*)malloc(length);
2670 if (!buffer)
2671 {
2672 Stream_Free(challengeRespData, TRUE);
2673 return FALSE;
2674 }
2675
2676 CopyMemory(buffer, Stream_Buffer(challengeRespData), Stream_Length(challengeRespData));
2677 CopyMemory(&buffer[Stream_Length(challengeRespData)], license->HardwareId,
2678 sizeof(license->HardwareId));
2679 status = security_mac_data(license->MacSaltKey, sizeof(license->MacSaltKey), buffer, length,
2680 license->MACData, sizeof(license->MACData));
2681 free(buffer);
2682
2683 if (!status)
2684 {
2685 Stream_Free(challengeRespData, TRUE);
2686 return FALSE;
2687 }
2688
2689 license->EncryptedHardwareId->type = BB_ENCRYPTED_DATA_BLOB;
2690 if (!license_rc4_with_licenseKey(license, license->HardwareId, sizeof(license->HardwareId),
2691 license->EncryptedHardwareId))
2692 {
2693 Stream_Free(challengeRespData, TRUE);
2694 return FALSE;
2695 }
2696
2697 status = license_rc4_with_licenseKey(license, Stream_Buffer(challengeRespData),
2698 Stream_Length(challengeRespData),
2699 license->EncryptedPlatformChallengeResponse);
2700 Stream_Free(challengeRespData, TRUE);
2701 if (!status)
2702 return FALSE;
2703
2704#ifdef WITH_DEBUG_LICENSE
2705 WLog_Print(license->log, WLOG_DEBUG, "LicensingEncryptionKey:");
2706 winpr_HexLogDump(license->log, WLOG_DEBUG, license->LicensingEncryptionKey, 16);
2707 WLog_Print(license->log, WLOG_DEBUG, "HardwareId:");
2708 winpr_HexLogDump(license->log, WLOG_DEBUG, license->HardwareId, sizeof(license->HardwareId));
2709 WLog_Print(license->log, WLOG_DEBUG, "EncryptedHardwareId:");
2710 winpr_HexLogDump(license->log, WLOG_DEBUG, license->EncryptedHardwareId->data,
2711 license->EncryptedHardwareId->length);
2712#endif
2713 UINT16 sec_flags = 0;
2714 wStream* s = license_send_stream_init(license, &sec_flags);
2715 if (!s)
2716 return FALSE;
2717
2718 if (license_write_client_platform_challenge_response(license, s))
2719 return license_send(license, s, PLATFORM_CHALLENGE_RESPONSE, sec_flags);
2720
2721 Stream_Release(s);
2722 return FALSE;
2723}
2724
2725BOOL license_read_platform_challenge_response(WINPR_ATTR_UNUSED rdpLicense* license)
2726{
2727 WINPR_ASSERT(license);
2728 WINPR_ASSERT(license->PlatformChallenge);
2729 WINPR_ASSERT(license->MacSaltKey);
2730 WINPR_ASSERT(license->EncryptedPlatformChallenge);
2731 WINPR_ASSERT(license->EncryptedHardwareId);
2732
2733 DEBUG_LICENSE("Receiving Platform Challenge Response Packet");
2734
2735#if defined(WITH_LICENSE_DECRYPT_CHALLENGE_RESPONSE)
2736 BOOL rc = FALSE;
2737 LICENSE_BLOB* dblob = license_new_binary_blob(BB_ANY_BLOB);
2738 if (!dblob)
2739 return FALSE;
2740
2741 wStream sbuffer = WINPR_C_ARRAY_INIT;
2742 UINT16 wVersion = 0;
2743 UINT16 cbChallenge = 0;
2744 const BYTE* pbChallenge = nullptr;
2745 LICENSE_BLOB* blob = license->EncryptedPlatformChallengeResponse;
2746
2747 if (!license_rc4_with_licenseKey(license, blob->data, blob->length, dblob))
2748 goto fail;
2749
2750 wStream* s = Stream_StaticConstInit(&sbuffer, dblob->data, dblob->length);
2751 if (!license_check_stream_length(s, 8, "PLATFORM_CHALLENGE_RESPONSE_DATA"))
2752 goto fail;
2753
2754 Stream_Read_UINT16(s, wVersion);
2755 if (wVersion != PLATFORM_CHALLENGE_RESPONSE_VERSION)
2756 {
2757 WLog_Print(license->log, WLOG_WARN,
2758 "Invalid PLATFORM_CHALLENGE_RESPONSE_DATA::wVersion 0x%04" PRIx16
2759 ", expected 0x04" PRIx16,
2760 wVersion, PLATFORM_CHALLENGE_RESPONSE_VERSION);
2761 goto fail;
2762 }
2763 Stream_Read_UINT16(s, license->ClientType);
2764 Stream_Read_UINT16(s, license->LicenseDetailLevel);
2765 Stream_Read_UINT16(s, cbChallenge);
2766
2767 if (!license_check_stream_length(s, cbChallenge,
2768 "PLATFORM_CHALLENGE_RESPONSE_DATA::pbChallenge"))
2769 goto fail;
2770
2771 pbChallenge = Stream_Pointer(s);
2772 if (!license_read_binary_blob_data(license->PlatformChallengeResponse, BB_DATA_BLOB,
2773 pbChallenge, cbChallenge))
2774 goto fail;
2775 if (!Stream_SafeSeek(s, cbChallenge))
2776 goto fail;
2777
2778 rc = TRUE;
2779fail:
2780 license_free_binary_blob(dblob);
2781 return rc;
2782#else
2783 return TRUE;
2784#endif
2785}
2786
2787BOOL license_write_client_platform_challenge_response(rdpLicense* license, wStream* s)
2788{
2789 WINPR_ASSERT(license);
2790
2791 if (!license_write_binary_blob(s, license->EncryptedPlatformChallengeResponse))
2792 return FALSE;
2793 if (!license_write_binary_blob(s, license->EncryptedHardwareId))
2794 return FALSE;
2795 if (!license_check_stream_capacity(license->log, s, sizeof(license->MACData),
2796 "CLIENT_PLATFORM_CHALLENGE_RESPONSE::MACData"))
2797 return FALSE;
2798 Stream_Write(s, license->MACData, sizeof(license->MACData));
2799 return TRUE;
2800}
2801
2802BOOL license_read_client_platform_challenge_response(rdpLicense* license, wStream* s)
2803{
2804 WINPR_ASSERT(license);
2805
2806 if (!license_read_binary_blob(license->log, s, license->EncryptedPlatformChallengeResponse))
2807 return FALSE;
2808 if (!license_read_binary_blob(license->log, s, license->EncryptedHardwareId))
2809 return FALSE;
2810 if (!license_check_stream_length(license->log, s, sizeof(license->MACData),
2811 "CLIENT_PLATFORM_CHALLENGE_RESPONSE::MACData"))
2812 return FALSE;
2813 Stream_Read(s, license->MACData, sizeof(license->MACData));
2814 return license_read_platform_challenge_response(license);
2815}
2816
2826BOOL license_send_valid_client_error_packet(rdpRdp* rdp)
2827{
2828 WINPR_ASSERT(rdp);
2829 rdpLicense* license = rdp->license;
2830 WINPR_ASSERT(license);
2831
2832 license->state = LICENSE_STATE_COMPLETED;
2833 license->type = LICENSE_TYPE_NONE;
2834 return license_send_error_alert(license, STATUS_VALID_CLIENT, ST_NO_TRANSITION,
2835 license->ErrorInfo);
2836}
2837
2844rdpLicense* license_new(rdpRdp* rdp)
2845{
2846 WINPR_ASSERT(rdp);
2847
2848 rdpLicense* license = (rdpLicense*)calloc(1, sizeof(rdpLicense));
2849 if (!license)
2850 return nullptr;
2851 license->log = WLog_Get(LICENSE_TAG);
2852 WINPR_ASSERT(license->log);
2853
2854 license->PlatformId = PLATFORMID;
2855 license->ClientType = OTHER_PLATFORM_CHALLENGE_TYPE;
2856 license->LicenseDetailLevel = LICENSE_DETAIL_DETAIL;
2857 license->PreferredKeyExchangeAlg = KEY_EXCHANGE_ALG_RSA;
2858 license->rdp = rdp;
2859
2860 license_set_state(license, LICENSE_STATE_INITIAL);
2861 if (!(license->certificate = freerdp_certificate_new()))
2862 goto out_error;
2863 if (!(license->ProductInfo = license_new_product_info()))
2864 goto out_error;
2865 if (!(license->ErrorInfo = license_new_binary_blob(BB_ERROR_BLOB)))
2866 goto out_error;
2867 if (!(license->LicenseInfo = license_new_binary_blob(BB_DATA_BLOB)))
2868 goto out_error;
2869 if (!(license->KeyExchangeList = license_new_binary_blob(BB_KEY_EXCHG_ALG_BLOB)))
2870 goto out_error;
2871 if (!(license->ServerCertificate = license_new_binary_blob(BB_CERTIFICATE_BLOB)))
2872 goto out_error;
2873 if (!(license->ClientUserName = license_new_binary_blob(BB_CLIENT_USER_NAME_BLOB)))
2874 goto out_error;
2875 if (!(license->ClientMachineName = license_new_binary_blob(BB_CLIENT_MACHINE_NAME_BLOB)))
2876 goto out_error;
2877 if (!(license->PlatformChallenge = license_new_binary_blob(BB_ANY_BLOB)))
2878 goto out_error;
2879 if (!(license->PlatformChallengeResponse = license_new_binary_blob(BB_ANY_BLOB)))
2880 goto out_error;
2881 if (!(license->EncryptedPlatformChallenge = license_new_binary_blob(BB_ANY_BLOB)))
2882 goto out_error;
2883 if (!(license->EncryptedPlatformChallengeResponse =
2884 license_new_binary_blob(BB_ENCRYPTED_DATA_BLOB)))
2885 goto out_error;
2886 if (!(license->EncryptedPremasterSecret = license_new_binary_blob(BB_ANY_BLOB)))
2887 goto out_error;
2888 if (!(license->EncryptedHardwareId = license_new_binary_blob(BB_ENCRYPTED_DATA_BLOB)))
2889 goto out_error;
2890 if (!(license->EncryptedLicenseInfo = license_new_binary_blob(BB_ENCRYPTED_DATA_BLOB)))
2891 goto out_error;
2892 if (!(license->ScopeList = license_new_scope_list()))
2893 goto out_error;
2894
2895 if (!license_generate_randoms(license))
2896 goto out_error;
2897
2898 return license;
2899
2900out_error:
2901 WINPR_PRAGMA_DIAG_PUSH
2902 WINPR_PRAGMA_DIAG_IGNORED_MISMATCHED_DEALLOC
2903 license_free(license);
2904 WINPR_PRAGMA_DIAG_POP
2905 return nullptr;
2906}
2907
2913void license_free(rdpLicense* license)
2914{
2915 if (license)
2916 {
2917 freerdp_certificate_free(license->certificate);
2918 license_free_product_info(license->ProductInfo);
2919 license_free_binary_blob(license->ErrorInfo);
2920 license_free_binary_blob(license->LicenseInfo);
2921 license_free_binary_blob(license->KeyExchangeList);
2922 license_free_binary_blob(license->ServerCertificate);
2923 license_free_binary_blob(license->ClientUserName);
2924 license_free_binary_blob(license->ClientMachineName);
2925 license_free_binary_blob(license->PlatformChallenge);
2926 license_free_binary_blob(license->PlatformChallengeResponse);
2927 license_free_binary_blob(license->EncryptedPlatformChallenge);
2928 license_free_binary_blob(license->EncryptedPlatformChallengeResponse);
2929 license_free_binary_blob(license->EncryptedPremasterSecret);
2930 license_free_binary_blob(license->EncryptedHardwareId);
2931 license_free_binary_blob(license->EncryptedLicenseInfo);
2932 license_free_scope_list(license->ScopeList);
2933 free(license);
2934 }
2935}
2936
2937LICENSE_STATE license_get_state(const rdpLicense* license)
2938{
2939 WINPR_ASSERT(license);
2940 return license->state;
2941}
2942
2943LICENSE_TYPE license_get_type(const rdpLicense* license)
2944{
2945 WINPR_ASSERT(license);
2946 return license->type;
2947}
2948
2949void license_set_state(rdpLicense* license, LICENSE_STATE state)
2950{
2951 WINPR_ASSERT(license);
2952 license->state = state;
2953 switch (state)
2954 {
2955 case LICENSE_STATE_COMPLETED:
2956 break;
2957 case LICENSE_STATE_ABORTED:
2958 default:
2959 license->type = LICENSE_TYPE_INVALID;
2960 break;
2961 }
2962}
2963
2964const char* license_get_state_string(LICENSE_STATE state)
2965{
2966 switch (state)
2967 {
2968 case LICENSE_STATE_INITIAL:
2969 return "LICENSE_STATE_INITIAL";
2970 case LICENSE_STATE_CONFIGURED:
2971 return "LICENSE_STATE_CONFIGURED";
2972 case LICENSE_STATE_REQUEST:
2973 return "LICENSE_STATE_REQUEST";
2974 case LICENSE_STATE_NEW_REQUEST:
2975 return "LICENSE_STATE_NEW_REQUEST";
2976 case LICENSE_STATE_PLATFORM_CHALLENGE:
2977 return "LICENSE_STATE_PLATFORM_CHALLENGE";
2978 case LICENSE_STATE_PLATFORM_CHALLENGE_RESPONSE:
2979 return "LICENSE_STATE_PLATFORM_CHALLENGE_RESPONSE";
2980 case LICENSE_STATE_COMPLETED:
2981 return "LICENSE_STATE_COMPLETED";
2982 case LICENSE_STATE_ABORTED:
2983 return "LICENSE_STATE_ABORTED";
2984 default:
2985 return "LICENSE_STATE_UNKNOWN";
2986 }
2987}
2988
2989BOOL license_server_send_request(rdpLicense* license)
2990{
2991 if (!license_ensure_state(license, LICENSE_STATE_CONFIGURED, LICENSE_REQUEST))
2992 return FALSE;
2993 if (!license_send_license_request_packet(license))
2994 return FALSE;
2995 license_set_state(license, LICENSE_STATE_REQUEST);
2996 return TRUE;
2997}
2998
2999WINPR_ATTR_NODISCARD
3000static BOOL license_set_string(wLog* log, const char* what, const char* value, BYTE** bdst,
3001 UINT32* dstLen)
3002{
3003 WINPR_ASSERT(what);
3004 WINPR_ASSERT(value);
3005 WINPR_ASSERT(bdst);
3006 WINPR_ASSERT(dstLen);
3007
3008 union
3009 {
3010 WCHAR** w;
3011 BYTE** b;
3012 } cnv;
3013 cnv.b = bdst;
3014
3015 size_t len = 0;
3016 *cnv.w = ConvertUtf8ToWCharAlloc(value, &len);
3017 if (!*cnv.w || (len > UINT32_MAX / sizeof(WCHAR)))
3018 {
3019 WLog_Print(log, WLOG_ERROR, "license->ProductInfo: %s == %p || %" PRIuz " > UINT32_MAX",
3020 what, (void*)(*cnv.w), len);
3021 return FALSE;
3022 }
3023 *dstLen = (UINT32)(len * sizeof(WCHAR));
3024 return TRUE;
3025}
3026
3027BOOL license_server_configure(rdpLicense* license)
3028{
3029 wStream* s = nullptr;
3030 UINT32 algs[] = { KEY_EXCHANGE_ALG_RSA };
3031
3032 WINPR_ASSERT(license);
3033 WINPR_ASSERT(license->rdp);
3034
3035 const rdpSettings* settings = license->rdp->settings;
3036
3037 const char* CompanyName =
3038 freerdp_settings_get_string(settings, FreeRDP_ServerLicenseCompanyName);
3039
3040 const char* ProductName =
3041 freerdp_settings_get_string(settings, FreeRDP_ServerLicenseProductName);
3042 const UINT32 ProductVersion =
3043 freerdp_settings_get_uint32(settings, FreeRDP_ServerLicenseProductVersion);
3044 const UINT32 issuerCount =
3045 freerdp_settings_get_uint32(settings, FreeRDP_ServerLicenseProductIssuersCount);
3046
3047 const void* ptr = freerdp_settings_get_pointer(settings, FreeRDP_ServerLicenseProductIssuers);
3048 const char** issuers = WINPR_REINTERPRET_CAST(ptr, const void*, const char**);
3049
3050 WINPR_ASSERT(CompanyName);
3051 WINPR_ASSERT(ProductName);
3052 WINPR_ASSERT(ProductVersion > 0);
3053 WINPR_ASSERT(issuers || (issuerCount == 0));
3054
3055 if (!license_ensure_state(license, LICENSE_STATE_INITIAL, LICENSE_REQUEST))
3056 return FALSE;
3057
3058 license->ProductInfo->dwVersion = ProductVersion;
3059 if (!license_set_string(license->log, "pbCompanyName", CompanyName,
3060 &license->ProductInfo->pbCompanyName,
3061 &license->ProductInfo->cbCompanyName))
3062 return FALSE;
3063
3064 if (!license_set_string(license->log, "pbProductId", ProductName,
3065 &license->ProductInfo->pbProductId, &license->ProductInfo->cbProductId))
3066 return FALSE;
3067
3068 if (!license_read_binary_blob_data(license->log, license->KeyExchangeList,
3069 BB_KEY_EXCHG_ALG_BLOB, algs, sizeof(algs)))
3070 return FALSE;
3071
3072 if (!freerdp_certificate_read_server_cert(license->certificate, settings->ServerCertificate,
3073 settings->ServerCertificateLength))
3074 return FALSE;
3075
3076 s = Stream_New(nullptr, 1024);
3077 if (!s)
3078 return FALSE;
3079 else
3080 {
3081 BOOL r = FALSE;
3082 SSIZE_T res =
3083 freerdp_certificate_write_server_cert(license->certificate, CERT_CHAIN_VERSION_2, s);
3084 if (res >= 0)
3085 r = license_read_binary_blob_data(license->log, license->ServerCertificate,
3086 BB_CERTIFICATE_BLOB, Stream_Buffer(s),
3087 Stream_GetPosition(s));
3088
3089 Stream_Free(s, TRUE);
3090 if (!r)
3091 return FALSE;
3092 }
3093
3094 if (!license_scope_list_resize(license->ScopeList, issuerCount))
3095 return FALSE;
3096 for (size_t x = 0; x < issuerCount; x++)
3097 {
3098 LICENSE_BLOB* blob = license->ScopeList->array[x];
3099 const char* name = issuers[x];
3100 const size_t length = strnlen(name, UINT16_MAX) + 1;
3101 if ((length == 0) || (length > UINT16_MAX))
3102 {
3103 WLog_Print(license->log, WLOG_WARN,
3104 "Invalid issuer at position %" PRIuz ": length 0 < %" PRIuz " <= %d"
3105 " ['%s']",
3106 x, length, UINT16_MAX, name);
3107 return FALSE;
3108 }
3109 if (!license_read_binary_blob_data(license->log, blob, BB_SCOPE_BLOB, name, length))
3110 return FALSE;
3111 }
3112
3113 license_set_state(license, LICENSE_STATE_CONFIGURED);
3114 return TRUE;
3115}
3116
3117rdpLicense* license_get(rdpContext* context)
3118{
3119 WINPR_ASSERT(context);
3120 WINPR_ASSERT(context->rdp);
3121 return context->rdp->license;
3122}
WINPR_ATTR_NODISCARD FREERDP_API const void * freerdp_settings_get_pointer(const rdpSettings *settings, FreeRDP_Settings_Keys_Pointer id)
Returns a immutable pointer settings value.
WINPR_ATTR_NODISCARD FREERDP_API const char * freerdp_settings_get_string(const rdpSettings *settings, FreeRDP_Settings_Keys_String id)
Returns a immutable string settings value.
WINPR_ATTR_NODISCARD FREERDP_API UINT32 freerdp_settings_get_uint32(const rdpSettings *settings, FreeRDP_Settings_Keys_UInt32 id)
Returns a UINT32 settings value.
WINPR_ATTR_NODISCARD FREERDP_API BOOL freerdp_settings_get_bool(const rdpSettings *settings, FreeRDP_Settings_Keys_Bool id)
Returns a boolean settings value.