1use serde_json::value::Value;
2use serde::{Deserialize, Serialize};
3use x509_parser::oid_registry::asn1_rs::oid;
4use x509_parser::prelude::*;
5use ldap3::SearchEntry;
6use log::{debug, error, trace};
7use std::collections::HashMap;
8use std::error::Error;
9
10use crate::objects::common::{LdapObject, AceTemplate, SPNTarget, Link, Member};
11use crate::enums::{decode_guid_le, parse_ntsecuritydescriptor};
12use crate::utils::date::string_to_epoch;
13use crate::utils::crypto::calculate_sha1;
14
15
16#[derive(Debug, Clone, Deserialize, Serialize, Default)]
18pub struct RootCA {
19 #[serde(rename = "Properties")]
20 properties: RootCAProperties,
21 #[serde(rename = "DomainSID")]
22 domain_sid: String,
23 #[serde(rename = "Aces")]
24 aces: Vec<AceTemplate>,
25 #[serde(rename = "ObjectIdentifier")]
26 object_identifier: String,
27 #[serde(rename = "IsDeleted")]
28 is_deleted: bool,
29 #[serde(rename = "IsACLProtected")]
30 is_acl_protected: bool,
31 #[serde(rename = "ContainedBy")]
32 contained_by: Option<Member>,
33}
34
35impl RootCA {
36 pub fn new() -> Self {
38 Self { ..Default::default() }
39 }
40
41 pub fn parse(
43 &mut self,
44 result: SearchEntry,
45 domain: &str,
46 dn_sid: &mut HashMap<String, String>,
47 sid_type: &mut HashMap<String, String>,
48 domain_sid: &str,
49 schema_guid_map: &HashMap<String, String>,
50 ) -> Result<(), Box<dyn Error>> {
51 let result_dn: String = result.dn.to_uppercase();
52 let result_attrs: HashMap<String, Vec<String>> = result.attrs;
53 let result_bin: HashMap<String, Vec<Vec<u8>>> = result.bin_attrs;
54
55 debug!("Parse RootCA: {result_dn}");
57
58 for (key, value) in &result_attrs {
60 trace!(" {key:?}:{value:?}");
61 }
62 for (key, value) in &result_bin {
64 trace!(" {key:?}:{value:?}");
65 }
66
67 self.properties.domain = domain.to_uppercase();
69 self.properties.distinguishedname = result_dn;
70 self.properties.domainsid = domain_sid.to_string();
71 self.domain_sid = domain_sid.to_string();
72
73 for (key, value) in &result_attrs {
75 match key.as_str() {
76 "name" => {
77 let name = format!("{}@{}", &value[0], domain);
78 self.properties.name = name.to_uppercase();
79 }
80 "description" => {
81 self.properties.description = value.first().cloned();
82 }
83 "whenCreated" => {
84 let epoch = string_to_epoch(&value[0])?;
85 if epoch.is_positive() {
86 self.properties.whencreated = epoch;
87 }
88 }
89 "isDeleted" => {
90 self.is_deleted = true;
91 }
92 _ => {}
93 }
94 }
95
96 for (key, value) in &result_bin {
98 match key.as_str() {
99 "objectGUID" => {
100 let guid = decode_guid_le(&value[0]);
102 self.object_identifier = guid.to_owned();
103 self.properties.objectguid = guid;
104 }
105 "nTSecurityDescriptor" => {
106 let relations_ace = parse_ntsecuritydescriptor(
108 self,
109 &value[0],
110 "RootCA",
111 &result_attrs,
112 &result_bin,
113 domain,
114 schema_guid_map,
115 );
116 self.aces = relations_ace;
117 }
118 "cACertificate" => {
119 let certsha1: String = calculate_sha1(&value[0]);
121 self.properties.certthumbprint = certsha1.to_string();
122 self.properties.certname = certsha1.to_string();
123 self.properties.certchain = vec![certsha1.to_string()];
124
125 let res = X509Certificate::from_der(&value[0]);
127 match res {
128 Ok((_rem, cert)) => {
129 for ext in cert.extensions() {
131 if &ext.oid == &oid!(2.5.29.19) {
133 if let ParsedExtension::BasicConstraints(basic_constraints) = &ext.parsed_extension() {
135 let _ca = &basic_constraints.ca;
136 let _path_len_constraint = &basic_constraints.path_len_constraint;
137 match _path_len_constraint {
140 Some(_path_len_constraint) => {
141 if _path_len_constraint > &0 {
142 self.properties.hasbasicconstraints = true;
143 self.properties.basicconstraintpathlength = _path_len_constraint.to_owned();
144
145 } else {
146 self.properties.hasbasicconstraints = false;
147 self.properties.basicconstraintpathlength = 0_u32;
148 }
149 },
150 None => {
151 self.properties.hasbasicconstraints = false;
152 self.properties.basicconstraintpathlength = 0_u32;
153 }
154 }
155 }
156 }
157 }
158 },
159 _ => error!("CA x509 certificate parsing failed: {:?}", res),
160 }
161 }
162 _ => {}
163 }
164 }
165
166 if self.object_identifier != "SID" {
168 dn_sid.insert(
169 self.properties.distinguishedname.to_string(),
170 self.object_identifier.to_string()
171 );
172 sid_type.insert(
174 self.object_identifier.to_string(),
175 "RootCA".to_string()
176 );
177 }
178
179 Ok(())
182 }
183}
184
185impl LdapObject for RootCA {
186 fn to_json(&self) -> Value {
188 serde_json::to_value(self).unwrap()
189 }
190
191 fn get_object_identifier(&self) -> &String {
193 &self.object_identifier
194 }
195 fn get_is_acl_protected(&self) -> &bool {
196 &self.is_acl_protected
197 }
198 fn get_aces(&self) -> &Vec<AceTemplate> {
199 &self.aces
200 }
201 fn get_spntargets(&self) -> &Vec<SPNTarget> {
202 panic!("Not used by current object.");
203 }
204 fn get_allowed_to_delegate(&self) -> &Vec<Member> {
205 panic!("Not used by current object.");
206 }
207 fn get_links(&self) -> &Vec<Link> {
208 panic!("Not used by current object.");
209 }
210 fn get_contained_by(&self) -> &Option<Member> {
211 &self.contained_by
212 }
213 fn get_child_objects(&self) -> &Vec<Member> {
214 panic!("Not used by current object.");
215 }
216 fn get_haslaps(&self) -> &bool {
217 &false
218 }
219
220 fn get_aces_mut(&mut self) -> &mut Vec<AceTemplate> {
222 &mut self.aces
223 }
224 fn get_spntargets_mut(&mut self) -> &mut Vec<SPNTarget> {
225 panic!("Not used by current object.");
226 }
227 fn get_allowed_to_delegate_mut(&mut self) -> &mut Vec<Member> {
228 panic!("Not used by current object.");
229 }
230
231 fn set_is_acl_protected(&mut self, is_acl_protected: bool) {
233 self.is_acl_protected = is_acl_protected;
234 self.properties.isaclprotected = is_acl_protected;
235 }
236 fn set_aces(&mut self, aces: Vec<AceTemplate>) {
237 self.aces = aces;
238 }
239 fn set_spntargets(&mut self, _spn_targets: Vec<SPNTarget>) {
240 }
242 fn set_allowed_to_delegate(&mut self, _allowed_to_delegate: Vec<Member>) {
243 }
245 fn set_links(&mut self, _links: Vec<Link>) {
246 }
248 fn set_contained_by(&mut self, contained_by: Option<Member>) {
249 self.contained_by = contained_by;
250 }
251 fn set_child_objects(&mut self, _child_objects: Vec<Member>) {
252 }
254 fn set_owner_rights_flags(&mut self, any: bool, any_inherited: bool) {
255 self.properties.doesanyacegrantownerrights = any;
256 self.properties.doesanyinheritedacegrantownerrights = any_inherited;
257 }
258}
259
260
261#[derive(Debug, Clone, Deserialize, Serialize)]
263pub struct RootCAProperties {
264 domain: String,
265 name: String,
266 distinguishedname: String,
267 domainsid: String,
268 objectguid: String,
269 doesanyacegrantownerrights: bool,
270 doesanyinheritedacegrantownerrights: bool,
271 isaclprotected: bool,
272 description: Option<String>,
273 whencreated: i64,
274 certthumbprint: String,
275 certname: String,
276 certchain: Vec<String>,
277 hasbasicconstraints: bool,
278 basicconstraintpathlength: u32,
279}
280
281impl Default for RootCAProperties {
282 fn default() -> RootCAProperties {
283 RootCAProperties {
284 domain: String::from(""),
285 name: String::from(""),
286 distinguishedname: String::from(""),
287 domainsid: String::from(""),
288 objectguid: String::from(""),
289 doesanyacegrantownerrights: false,
290 doesanyinheritedacegrantownerrights: false,
291 isaclprotected: false,
292 description: None,
293 whencreated: -1,
294 certthumbprint: String::from(""),
295 certname: String::from(""),
296 certchain: Vec::new(),
297 hasbasicconstraints: false,
298 basicconstraintpathlength: 0,
299 }
300 }
301}