Skip to main content

rusthound_ce/objects/
rootca.rs

1use serde_json::value::Value;
2use serde::{Deserialize, Serialize};
3use x509_parser::oid_registry::asn1_rs::oid;
4use x509_parser::prelude::*;
5use ldap3::SearchEntry;
6use log::{debug, error, trace};
7use std::collections::HashMap;
8use std::error::Error;
9
10use crate::objects::common::{LdapObject, AceTemplate, SPNTarget, Link, Member};
11use crate::enums::{decode_guid_le, parse_ntsecuritydescriptor};
12use crate::utils::date::string_to_epoch;
13use crate::utils::crypto::calculate_sha1;
14
15
16/// RootCA structure
17#[derive(Debug, Clone, Deserialize, Serialize, Default)]
18pub struct RootCA {
19    #[serde(rename = "Properties")]
20    properties: RootCAProperties,
21    #[serde(rename = "DomainSID")]
22    domain_sid: String,
23    #[serde(rename = "Aces")]
24    aces: Vec<AceTemplate>,
25    #[serde(rename = "ObjectIdentifier")]
26    object_identifier: String,
27    #[serde(rename = "IsDeleted")]
28    is_deleted: bool,
29    #[serde(rename = "IsACLProtected")]
30    is_acl_protected: bool,
31    #[serde(rename = "ContainedBy")]
32    contained_by: Option<Member>,
33}
34
35impl RootCA {
36    // New RootCA
37    pub fn new() -> Self { 
38        Self { ..Default::default() } 
39    }
40
41    /// Function to parse and replace value in json template for ROOT CA object.
42    pub fn parse(
43        &mut self,
44        result: SearchEntry,
45        domain: &str,
46        dn_sid: &mut HashMap<String, String>,
47        sid_type: &mut HashMap<String, String>,
48        domain_sid: &str,
49        schema_guid_map: &HashMap<String, String>,
50    ) -> Result<(), Box<dyn Error>> {
51        let result_dn: String = result.dn.to_uppercase();
52        let result_attrs: HashMap<String, Vec<String>> = result.attrs;
53        let result_bin: HashMap<String, Vec<Vec<u8>>> = result.bin_attrs;
54
55        // Debug for current object
56        debug!("Parse RootCA: {result_dn}");
57
58        // Trace all result attributes
59        for (key, value) in &result_attrs {
60            trace!("  {key:?}:{value:?}");
61        }
62        // Trace all bin result attributes
63        for (key, value) in &result_bin {
64            trace!("  {key:?}:{value:?}");
65        }
66
67        // Change all values...
68        self.properties.domain = domain.to_uppercase();
69        self.properties.distinguishedname = result_dn;    
70        self.properties.domainsid = domain_sid.to_string();
71        self.domain_sid = domain_sid.to_string();
72
73        // With a check
74        for (key, value) in &result_attrs {
75            match key.as_str() {
76                "name" => {
77                    let name = format!("{}@{}", &value[0], domain);
78                    self.properties.name = name.to_uppercase();
79                }
80                "description" => {
81                    self.properties.description = value.first().cloned();
82                }
83                "whenCreated" => {
84                    let epoch = string_to_epoch(&value[0])?;
85                    if epoch.is_positive() {
86                        self.properties.whencreated = epoch;
87                    }
88                }
89                "isDeleted" => {
90                    self.is_deleted = true;
91                }
92                _ => {}
93            }
94        }
95
96        // For all, bins attributs
97        for (key, value) in &result_bin {
98            match key.as_str() {
99                "objectGUID" => {
100                    // objectGUID raw to string
101                    let guid = decode_guid_le(&value[0]);
102                    self.object_identifier = guid.to_owned();
103                    self.properties.objectguid = guid;
104                }
105                "nTSecurityDescriptor" => {
106                    // nTSecurityDescriptor raw to string
107                    let relations_ace = parse_ntsecuritydescriptor(
108                        self,
109                        &value[0],
110                        "RootCA",
111                        &result_attrs,
112                        &result_bin,
113                        domain,
114                        schema_guid_map,
115                    );
116                    self.aces = relations_ace;
117                }
118                "cACertificate" => {
119                    //info!("{:?}:{:?}", key,value[0].to_owned());
120                    let certsha1: String = calculate_sha1(&value[0]);
121                    self.properties.certthumbprint = certsha1.to_string();
122                    self.properties.certname = certsha1.to_string();
123                    self.properties.certchain = vec![certsha1.to_string()];
124
125                    // Parsing certificate.
126                    let res = X509Certificate::from_der(&value[0]);
127                    match res {
128                        Ok((_rem, cert)) => {
129                            // println!("Basic Constraints Extensions:");
130                            for ext in cert.extensions() {
131                                // println!("{:?} : {:?}",&ext.oid, ext);
132                                if &ext.oid == &oid!(2.5.29.19) {
133                                    // <https://docs.rs/x509-parser/latest/x509_parser/extensions/struct.BasicConstraints.html>
134                                    if let ParsedExtension::BasicConstraints(basic_constraints) = &ext.parsed_extension() {
135                                        let _ca = &basic_constraints.ca;
136                                        let _path_len_constraint = &basic_constraints.path_len_constraint;
137                                        // println!("ca: {:?}", _ca);
138                                        // println!("path_len_constraint: {:?}", _path_len_constraint);
139                                        match _path_len_constraint {
140                                            Some(_path_len_constraint) => {
141                                                if _path_len_constraint > &0 {
142                                                    self.properties.hasbasicconstraints = true;
143                                                    self.properties.basicconstraintpathlength = _path_len_constraint.to_owned();
144
145                                                } else {
146                                                    self.properties.hasbasicconstraints = false;
147                                                    self.properties.basicconstraintpathlength = 0_u32;
148                                                }
149                                            },
150                                            None => {
151                                                self.properties.hasbasicconstraints = false;
152                                                self.properties.basicconstraintpathlength = 0_u32;
153                                            }
154                                        }
155                                    }
156                                }
157                            }
158                        },
159                        _ => error!("CA x509 certificate parsing failed: {:?}", res),
160                    }
161                }
162                _ => {}
163            }
164        }
165
166        // Push DN and SID in HashMap
167        if self.object_identifier != "SID" {
168            dn_sid.insert(
169                self.properties.distinguishedname.to_string(),
170                self.object_identifier.to_string()
171            );
172            // Push DN and Type
173            sid_type.insert(
174                self.object_identifier.to_string(),
175                "RootCA".to_string()
176            );
177        }
178
179        // Trace and return RootCA struct
180        // trace!("JSON OUTPUT: {:?}",serde_json::to_string(&self).unwrap());
181        Ok(())
182    }
183}
184
185impl LdapObject for RootCA {
186    // To JSON
187    fn to_json(&self) -> Value {
188        serde_json::to_value(self).unwrap()
189    }
190
191    // Get values
192    fn get_object_identifier(&self) -> &String {
193        &self.object_identifier
194    }
195    fn get_is_acl_protected(&self) -> &bool {
196        &self.is_acl_protected
197    }
198    fn get_aces(&self) -> &Vec<AceTemplate> {
199        &self.aces
200    }
201    fn get_spntargets(&self) -> &Vec<SPNTarget> {
202        panic!("Not used by current object.");
203    }
204    fn get_allowed_to_delegate(&self) -> &Vec<Member> {
205        panic!("Not used by current object.");
206    }
207    fn get_links(&self) -> &Vec<Link> {
208        panic!("Not used by current object.");
209    }
210    fn get_contained_by(&self) -> &Option<Member> {
211        &self.contained_by
212    }
213    fn get_child_objects(&self) -> &Vec<Member> {
214        panic!("Not used by current object.");
215    }
216    fn get_haslaps(&self) -> &bool {
217        &false
218    }
219    
220    // Get mutable values
221    fn get_aces_mut(&mut self) -> &mut Vec<AceTemplate> {
222        &mut self.aces
223    }
224    fn get_spntargets_mut(&mut self) -> &mut Vec<SPNTarget> {
225        panic!("Not used by current object.");
226    }
227    fn get_allowed_to_delegate_mut(&mut self) -> &mut Vec<Member> {
228        panic!("Not used by current object.");
229    }
230    
231    // Edit values
232    fn set_is_acl_protected(&mut self, is_acl_protected: bool) {
233        self.is_acl_protected = is_acl_protected;
234        self.properties.isaclprotected = is_acl_protected;
235    }
236    fn set_aces(&mut self, aces: Vec<AceTemplate>) {
237        self.aces = aces;
238    }
239    fn set_spntargets(&mut self, _spn_targets: Vec<SPNTarget>) {
240        // Not used by current object.
241    }
242    fn set_allowed_to_delegate(&mut self, _allowed_to_delegate: Vec<Member>) {
243        // Not used by current object.
244    }
245    fn set_links(&mut self, _links: Vec<Link>) {
246        // Not used by current object.
247    }
248    fn set_contained_by(&mut self, contained_by: Option<Member>) {
249        self.contained_by = contained_by;
250    }
251    fn set_child_objects(&mut self, _child_objects: Vec<Member>) {
252        // Not used by current object.
253    }
254    fn set_owner_rights_flags(&mut self, any: bool, any_inherited: bool) {
255        self.properties.doesanyacegrantownerrights = any;
256        self.properties.doesanyinheritedacegrantownerrights = any_inherited;
257    }
258}
259
260
261// RootCA properties structure
262#[derive(Debug, Clone, Deserialize, Serialize)]
263pub struct RootCAProperties {
264    domain: String,
265    name: String,
266    distinguishedname: String,
267    domainsid: String,
268    objectguid: String,
269    doesanyacegrantownerrights: bool,
270    doesanyinheritedacegrantownerrights: bool,
271    isaclprotected: bool,
272    description: Option<String>,
273    whencreated: i64,
274    certthumbprint: String,
275    certname: String,
276    certchain: Vec<String>,
277    hasbasicconstraints: bool,
278    basicconstraintpathlength: u32,
279}
280
281impl Default for RootCAProperties {
282    fn default() -> RootCAProperties {
283        RootCAProperties {
284            domain: String::from(""),
285            name: String::from(""),
286            distinguishedname: String::from(""),
287            domainsid: String::from(""),
288            objectguid: String::from(""),
289            doesanyacegrantownerrights: false,
290            doesanyinheritedacegrantownerrights: false,
291            isaclprotected: false,
292            description: None,
293            whencreated: -1,
294            certthumbprint: String::from(""),
295            certname: String::from(""),
296            certchain: Vec::new(),
297            hasbasicconstraints: false,
298            basicconstraintpathlength: 0,
299       }
300    }
301}