From 39cd897ff662c066e05341fd8a070481e87a3697 Mon Sep 17 00:00:00 2001 From: "relyea%netscape.com" Date: Sat, 15 Feb 2003 01:21:25 +0000 Subject: [PATCH] Bug 167756. Address Nelson's review comments. remove socket specific latency in favor of a slot specific latency test (already done by pk11wrap code). git-svn-id: svn://10.0.0.236/trunk@137837 18797224-902f-48f8-a5cc-f745e15eee43 --- mozilla/security/nss/lib/ssl/ssl3con.c | 56 ++++++------------------- mozilla/security/nss/lib/ssl/sslimpl.h | 6 +-- mozilla/security/nss/lib/ssl/sslsecur.c | 7 +--- 3 files changed, 15 insertions(+), 54 deletions(-) diff --git a/mozilla/security/nss/lib/ssl/ssl3con.c b/mozilla/security/nss/lib/ssl/ssl3con.c index 0fe6c8bbcc5..9ef48be0749 100644 --- a/mozilla/security/nss/lib/ssl/ssl3con.c +++ b/mozilla/security/nss/lib/ssl/ssl3con.c @@ -33,7 +33,7 @@ * may use your version of this file under either the MPL or the * GPL. * - * $Id: ssl3con.c,v 1.46 2003-01-23 22:02:36 relyea%netscape.com Exp $ + * $Id: ssl3con.c,v 1.47 2003-02-15 01:21:23 relyea%netscape.com Exp $ */ #include "nssrenam.h" @@ -1323,48 +1323,31 @@ ssl3_ComputeRecordMAC( return rv; } -PRBool -ssl_ClientAuthTokenPresent(sslSocket *ss) { - sslSessionID *sid; - PRIntervalTime thisTime; - static PRIntervalTime timeout = 0; +static PRBool +ssl3_ClientAuthTokenPresent(sslSessionID *sid) { PK11SlotInfo *slot = NULL; - - - if (timeout == 0) { - timeout = PR_SecondsToInterval(10); - } - sid = ss->sec.ci.sid; + PRBool isPresent = PR_TRUE; /* we only care if we are doing client auth */ if (!sid || !sid->u.ssl3.clAuthValid) { return PR_TRUE; } - /* Limit how often we really check the token */ - thisTime = PR_IntervalNow(); - if (thisTime - ss->sec.lastTime < timeout) { - return ss->sec.lastState; - } - /* get the slot */ slot = SECMOD_LookupSlot(sid->u.ssl3.clAuthModuleID, - sid->u.ssl3.clAuthSlotID); - ss->sec.lastTime = thisTime; + sid->u.ssl3.clAuthSlotID); if (slot == NULL || - !PK11_IsPresent(slot) || + !PK11_IsPresent(slot) || sid->u.ssl3.clAuthSeries != PK11_GetSlotSeries(slot) || sid->u.ssl3.clAuthSlotID != PK11_GetSlotID(slot) || sid->u.ssl3.clAuthModuleID != PK11_GetModuleID(slot) || !PK11_IsLoggedIn(slot, NULL)) { - ss->sec.lastState = PR_FALSE; - } else { - ss->sec.lastState = PR_TRUE; - } + isPresent = PR_FALSE; + } if (slot) { PK11_FreeSlot(slot); } - return ss->sec.lastState; + return isPresent; } /* Process the plain text before sending it. @@ -1412,7 +1395,7 @@ ssl3_SendRecord( sslSocket * ss, } /* check for Token Presence */ - if (!ssl_ClientAuthTokenPresent(ss)) { + if (!ssl3_ClientAuthTokenPresent(ss->sec.ci.sid)) { PORT_SetError(SSL_ERROR_TOKEN_INSERTION_REMOVAL); return SECFailure; } @@ -2741,21 +2724,8 @@ ssl3_SendClientHello(sslSocket *ss) ** holds the private key still exists, is logged in, hasn't been ** removed, etc. */ - if (sidOK && sid->u.ssl3.clAuthValid) { - slot = SECMOD_LookupSlot(sid->u.ssl3.clAuthModuleID, - sid->u.ssl3.clAuthSlotID); - if (slot == NULL || - !PK11_IsPresent(slot) || - sid->u.ssl3.clAuthSeries != PK11_GetSlotSeries(slot) || - sid->u.ssl3.clAuthSlotID != PK11_GetSlotID(slot) || - sid->u.ssl3.clAuthModuleID != PK11_GetModuleID(slot) || - !PK11_IsLoggedIn(slot, NULL)) { - sidOK = PR_FALSE; - } - if (slot) { - PK11_FreeSlot(slot); - slot = NULL; - } + if (sidOK && !ssl3_ClientAuthTokenPresent(sid)) { + sidOK = PR_FALSE; } if (!sidOK) { @@ -7463,7 +7433,7 @@ const ssl3BulkCipherDef *cipher_def; ssl3 = ss->ssl3; /* check for Token Presence */ - if (!ssl_ClientAuthTokenPresent(ss)) { + if (!ssl3_ClientAuthTokenPresent(ss->sec.ci.sid)) { PORT_SetError(SSL_ERROR_TOKEN_INSERTION_REMOVAL); return SECFailure; } diff --git a/mozilla/security/nss/lib/ssl/sslimpl.h b/mozilla/security/nss/lib/ssl/sslimpl.h index 88979bd9211..4099d93534e 100644 --- a/mozilla/security/nss/lib/ssl/sslimpl.h +++ b/mozilla/security/nss/lib/ssl/sslimpl.h @@ -34,7 +34,7 @@ * may use your version of this file under either the MPL or the * GPL. * - * $Id: sslimpl.h,v 1.28 2003-01-23 22:02:37 relyea%netscape.com Exp $ + * $Id: sslimpl.h,v 1.29 2003-02-15 01:21:24 relyea%netscape.com Exp $ */ #ifndef __sslimpl_h_ @@ -847,10 +847,6 @@ struct sslSecurityInfoStr { /* These are used during a connection handshake */ sslConnectInfo ci; /* ssl 2 & 3 */ - PRIntervalTime lastTime; /* last time smart card - * checked */ /* ssl3 only */ - PRBool lastState; /* last state of client auth - * smart card present (ssl 3) */ }; diff --git a/mozilla/security/nss/lib/ssl/sslsecur.c b/mozilla/security/nss/lib/ssl/sslsecur.c index 50391b9afbb..aa8e13859a8 100644 --- a/mozilla/security/nss/lib/ssl/sslsecur.c +++ b/mozilla/security/nss/lib/ssl/sslsecur.c @@ -32,7 +32,7 @@ * may use your version of this file under either the MPL or the * GPL. * - * $Id: sslsecur.c,v 1.20 2003-01-23 22:02:37 relyea%netscape.com Exp $ + * $Id: sslsecur.c,v 1.21 2003-02-15 01:21:25 relyea%netscape.com Exp $ */ #include "cert.h" #include "secitem.h" @@ -714,9 +714,6 @@ ssl_CreateSecurityInfo(sslSocket *ss) status = sslBuffer_Grow(&ss->sec.writeBuf, 4096); ssl_ReleaseXmitBufLock(ss); - ss->sec.lastTime = 0; - ss->sec.lastState = PR_TRUE; - return status; } @@ -823,8 +820,6 @@ ssl_ResetSecurityInfo(sslSecurityInfo *sec) } PORT_ZFree(sec->ci.sendBuf.buf, sec->ci.sendBuf.space); memset(&sec->ci, 0, sizeof sec->ci); - sec->lastTime = 0; - sec->lastState = PR_TRUE; } /*