2016-07-20 12:02:01 +02:00
|
|
|
// (c) Copyright 2016 Hewlett Packard Enterprise Development LP
|
|
|
|
//
|
|
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
// you may not use this file except in compliance with the License.
|
|
|
|
// You may obtain a copy of the License at
|
|
|
|
//
|
|
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
//
|
|
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
// See the License for the specific language governing permissions and
|
|
|
|
// limitations under the License.
|
|
|
|
|
2018-02-21 07:59:18 +02:00
|
|
|
//go:generate tlsconfig
|
|
|
|
|
2016-07-20 12:02:01 +02:00
|
|
|
package rules
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
|
|
|
"go/ast"
|
|
|
|
|
2018-07-19 18:42:25 +02:00
|
|
|
"github.com/securego/gosec"
|
2016-07-20 12:02:01 +02:00
|
|
|
)
|
|
|
|
|
2017-12-13 09:39:00 +02:00
|
|
|
type insecureConfigTLS struct {
|
2018-07-19 18:42:25 +02:00
|
|
|
gosec.MetaData
|
2017-07-19 23:17:00 +02:00
|
|
|
MinVersion int16
|
|
|
|
MaxVersion int16
|
|
|
|
requiredType string
|
|
|
|
goodCiphers []string
|
2016-07-20 12:02:01 +02:00
|
|
|
}
|
|
|
|
|
2017-10-05 23:32:03 +02:00
|
|
|
func (t *insecureConfigTLS) ID() string {
|
|
|
|
return t.MetaData.ID
|
|
|
|
}
|
|
|
|
|
2016-07-20 12:02:01 +02:00
|
|
|
func stringInSlice(a string, list []string) bool {
|
|
|
|
for _, b := range list {
|
|
|
|
if b == a {
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
2018-07-19 18:42:25 +02:00
|
|
|
func (t *insecureConfigTLS) processTLSCipherSuites(n ast.Node, c *gosec.Context) *gosec.Issue {
|
2017-07-19 23:17:00 +02:00
|
|
|
|
2017-12-28 08:54:10 +02:00
|
|
|
if ciphers, ok := n.(*ast.CompositeLit); ok {
|
|
|
|
for _, cipher := range ciphers.Elts {
|
|
|
|
if ident, ok := cipher.(*ast.SelectorExpr); ok {
|
2016-07-20 12:02:01 +02:00
|
|
|
if !stringInSlice(ident.Sel.Name, t.goodCiphers) {
|
2017-12-28 08:54:10 +02:00
|
|
|
err := fmt.Sprintf("TLS Bad Cipher Suite: %s", ident.Sel.Name)
|
2018-07-19 18:42:25 +02:00
|
|
|
return gosec.NewIssue(c, ident, t.ID(), err, gosec.High, gosec.High)
|
2016-07-20 12:02:01 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2018-07-19 18:42:25 +02:00
|
|
|
func (t *insecureConfigTLS) processTLSConfVal(n *ast.KeyValueExpr, c *gosec.Context) *gosec.Issue {
|
2016-07-20 12:02:01 +02:00
|
|
|
if ident, ok := n.Key.(*ast.Ident); ok {
|
|
|
|
switch ident.Name {
|
2017-12-28 08:54:10 +02:00
|
|
|
|
2016-07-20 12:02:01 +02:00
|
|
|
case "InsecureSkipVerify":
|
|
|
|
if node, ok := n.Value.(*ast.Ident); ok {
|
|
|
|
if node.Name != "false" {
|
2018-07-19 18:42:25 +02:00
|
|
|
return gosec.NewIssue(c, n, t.ID(), "TLS InsecureSkipVerify set true.", gosec.High, gosec.High)
|
2016-07-20 12:02:01 +02:00
|
|
|
}
|
|
|
|
} else {
|
|
|
|
// TODO(tk): symbol tab look up to get the actual value
|
2018-07-19 18:42:25 +02:00
|
|
|
return gosec.NewIssue(c, n, t.ID(), "TLS InsecureSkipVerify may be true.", gosec.High, gosec.Low)
|
2016-07-20 12:02:01 +02:00
|
|
|
}
|
|
|
|
|
2017-03-15 16:05:44 +02:00
|
|
|
case "PreferServerCipherSuites":
|
|
|
|
if node, ok := n.Value.(*ast.Ident); ok {
|
|
|
|
if node.Name == "false" {
|
2018-07-19 18:42:25 +02:00
|
|
|
return gosec.NewIssue(c, n, t.ID(), "TLS PreferServerCipherSuites set false.", gosec.Medium, gosec.High)
|
2017-03-15 16:05:44 +02:00
|
|
|
}
|
|
|
|
} else {
|
|
|
|
// TODO(tk): symbol tab look up to get the actual value
|
2018-07-19 18:42:25 +02:00
|
|
|
return gosec.NewIssue(c, n, t.ID(), "TLS PreferServerCipherSuites may be false.", gosec.Medium, gosec.Low)
|
2017-03-15 16:05:44 +02:00
|
|
|
}
|
|
|
|
|
2016-07-20 12:02:01 +02:00
|
|
|
case "MinVersion":
|
2018-07-19 18:42:25 +02:00
|
|
|
if ival, ierr := gosec.GetInt(n.Value); ierr == nil {
|
2016-07-20 12:02:01 +02:00
|
|
|
if (int16)(ival) < t.MinVersion {
|
2018-07-19 18:42:25 +02:00
|
|
|
return gosec.NewIssue(c, n, t.ID(), "TLS MinVersion too low.", gosec.High, gosec.High)
|
2016-07-20 12:02:01 +02:00
|
|
|
}
|
|
|
|
// TODO(tk): symbol tab look up to get the actual value
|
2018-07-19 18:42:25 +02:00
|
|
|
return gosec.NewIssue(c, n, t.ID(), "TLS MinVersion may be too low.", gosec.High, gosec.Low)
|
2016-07-20 12:02:01 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
case "MaxVersion":
|
2018-07-19 18:42:25 +02:00
|
|
|
if ival, ierr := gosec.GetInt(n.Value); ierr == nil {
|
2016-07-20 12:02:01 +02:00
|
|
|
if (int16)(ival) < t.MaxVersion {
|
2018-07-19 18:42:25 +02:00
|
|
|
return gosec.NewIssue(c, n, t.ID(), "TLS MaxVersion too low.", gosec.High, gosec.High)
|
2016-07-20 12:02:01 +02:00
|
|
|
}
|
|
|
|
// TODO(tk): symbol tab look up to get the actual value
|
2018-07-19 18:42:25 +02:00
|
|
|
return gosec.NewIssue(c, n, t.ID(), "TLS MaxVersion may be too low.", gosec.High, gosec.Low)
|
2016-07-20 12:02:01 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
case "CipherSuites":
|
2017-12-28 08:54:10 +02:00
|
|
|
if ret := t.processTLSCipherSuites(n.Value, c); ret != nil {
|
2016-07-20 12:02:01 +02:00
|
|
|
return ret
|
|
|
|
}
|
2017-03-15 16:05:44 +02:00
|
|
|
|
2016-07-20 12:02:01 +02:00
|
|
|
}
|
2017-03-15 16:05:44 +02:00
|
|
|
|
2016-07-20 12:02:01 +02:00
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2018-07-19 18:42:25 +02:00
|
|
|
func (t *insecureConfigTLS) Match(n ast.Node, c *gosec.Context) (*gosec.Issue, error) {
|
2018-02-27 20:29:25 +02:00
|
|
|
if complit, ok := n.(*ast.CompositeLit); ok && complit.Type != nil {
|
|
|
|
actualType := c.Info.TypeOf(complit.Type)
|
|
|
|
if actualType != nil && actualType.String() == t.requiredType {
|
|
|
|
for _, elt := range complit.Elts {
|
|
|
|
if kve, ok := elt.(*ast.KeyValueExpr); ok {
|
|
|
|
issue := t.processTLSConfVal(kve, c)
|
|
|
|
if issue != nil {
|
|
|
|
return issue, nil
|
|
|
|
}
|
2016-07-20 12:02:01 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2017-12-28 08:54:10 +02:00
|
|
|
return nil, nil
|
2016-07-20 12:02:01 +02:00
|
|
|
}
|