CLOUDSTACK-6030: Encrypt the primary and secondary smb storage password when it is stored in the db.

This commit is contained in:
Devdeep Singh 2014-02-05 14:58:12 +05:30
parent 0ce488849d
commit a24263fe81
8 changed files with 100 additions and 16 deletions

View File

@ -86,7 +86,7 @@ public class Storage {
public static enum StoragePoolType {
Filesystem(false), // local directory
NetworkFilesystem(true), // NFS or CIFS
NetworkFilesystem(true), // NFS
IscsiLUN(true), // shared LUN, with a clusterfs overlay
Iscsi(true), // for e.g., ZFS Comstar
ISO(false), // for iso image
@ -97,7 +97,8 @@ public class Storage {
VMFS(true), // VMware VMFS storage
PreSetup(true), // for XenServer, Storage Pool is set up by customers.
EXT(false), // XenServer local EXT SR
OCFS2(true);
OCFS2(true),
SMB(true);
boolean shared;

View File

@ -31,6 +31,7 @@ import javax.persistence.TableGenerator;
import com.cloud.storage.DataStoreRole;
import com.cloud.storage.ImageStore;
import com.cloud.storage.ScopeType;
import com.cloud.utils.UriUtils;
import com.cloud.utils.db.GenericDao;
@Entity
@ -149,11 +150,18 @@ public class ImageStoreVO implements ImageStore {
}
public String getUrl() {
return url;
String updatedUrl = url;
if ("cifs".equalsIgnoreCase(this.protocol)) {
updatedUrl = UriUtils.getUpdateUri(updatedUrl, false);
}
return updatedUrl;
}
public void setUrl(String url) {
this.url = url;
if ("cifs".equalsIgnoreCase(this.protocol)) {
this.url = UriUtils.getUpdateUri(url, true);
}
}
public Date getCreated() {

View File

@ -34,6 +34,7 @@ import com.cloud.storage.ScopeType;
import com.cloud.storage.Storage.StoragePoolType;
import com.cloud.storage.StoragePool;
import com.cloud.storage.StoragePoolStatus;
import com.cloud.utils.UriUtils;
import com.cloud.utils.db.GenericDao;
@Entity
@ -141,10 +142,10 @@ public class StoragePoolVO implements StoragePool {
this.usedBytes = availableBytes;
this.capacityBytes = capacityBytes;
this.hostAddress = hostAddress;
this.path = hostPath;
this.port = port;
this.podId = podId;
this.setStatus(StoragePoolStatus.Initial);
this.setPath(hostPath);
}
public StoragePoolVO(StoragePoolVO that) {
@ -155,9 +156,9 @@ public class StoragePoolVO implements StoragePool {
this.poolType = type;
this.hostAddress = hostAddress;
this.port = port;
this.path = path;
this.setStatus(StoragePoolStatus.Initial);
this.uuid = UUID.randomUUID().toString();
this.setPath(path);
}
@Override
@ -262,7 +263,12 @@ public class StoragePoolVO implements StoragePool {
@Override
public String getPath() {
return path;
String updatedPath = path;
if (this.poolType == StoragePoolType.SMB) {
updatedPath = UriUtils.getUpdateUri(updatedPath, false);
}
return updatedPath;
}
@Override
@ -292,6 +298,9 @@ public class StoragePoolVO implements StoragePool {
public void setPath(String path) {
this.path = path;
if (this.poolType == StoragePoolType.SMB) {
this.path = UriUtils.getUpdateUri(this.path, true);
}
}
public void setUserInfo(String userInfo) {

View File

@ -70,8 +70,8 @@ public class PrimaryDataStoreHelper {
dataStoreVO = new StoragePoolVO();
dataStoreVO.setStorageProviderName(params.getProviderName());
dataStoreVO.setHostAddress(params.getHost());
dataStoreVO.setPath(params.getPath());
dataStoreVO.setPoolType(params.getType());
dataStoreVO.setPath(params.getPath());
dataStoreVO.setPort(params.getPort());
dataStoreVO.setName(params.getName());
dataStoreVO.setUuid(params.getUuid());

View File

@ -61,7 +61,7 @@ namespace HypervResource
get
{
string uncPath = null;
if (uri != null && (uri.Scheme.Equals("cifs") || uri.Scheme.Equals("networkfilesystem")))
if (uri != null && (uri.Scheme.Equals("cifs") || uri.Scheme.Equals("networkfilesystem") || uri.Scheme.Equals("smb")))
{
uncPath = @"\\" + uri.Host + uri.LocalPath;
}
@ -584,7 +584,11 @@ namespace HypervResource
/// <summary>
///
/// </summary>
OCFS2
OCFS2,
/// <summary>
/// for hyper-v
/// </summary>
SMB
}
public enum StorageResourceType

View File

@ -916,7 +916,8 @@ namespace HypervResource
GetCapacityForLocalPath(localPath, out capacityBytes, out availableBytes);
hostPath = localPath;
}
else if (poolType == StoragePoolType.NetworkFilesystem)
else if (poolType == StoragePoolType.NetworkFilesystem ||
poolType == StoragePoolType.SMB)
{
NFSTO share = new NFSTO();
String uriStr = "cifs://" + (string)cmd.pool.host + (string)cmd.pool.path;
@ -972,7 +973,8 @@ namespace HypervResource
}
if (poolType != StoragePoolType.Filesystem &&
poolType != StoragePoolType.NetworkFilesystem)
poolType != StoragePoolType.NetworkFilesystem &&
poolType != StoragePoolType.SMB)
{
details = "Request to create / modify unsupported pool type: " + (poolTypeStr == null ? "NULL" : poolTypeStr) + "in cmd " + JsonConvert.SerializeObject(cmd);
logger.Error(details);
@ -1815,7 +1817,7 @@ namespace HypervResource
used = capacity - available;
result = true;
}
else if (poolType == StoragePoolType.NetworkFilesystem)
else if (poolType == StoragePoolType.NetworkFilesystem || poolType == StoragePoolType.SMB)
{
string sharePath = config.getPrimaryStorage((string)cmd.id);
if (sharePath != null)

View File

@ -203,12 +203,11 @@ public class CloudStackPrimaryDataStoreLifeCycleImpl implements PrimaryDataStore
if (port == -1) {
port = 445;
}
parameters.setType(StoragePoolType.NetworkFilesystem);
parameters.setType(StoragePoolType.SMB);
parameters.setHost(storageHost);
parameters.setPort(port);
parameters.setPath(hostPath);
parameters.setUserInfo(uri.getQuery());
} else if (scheme.equalsIgnoreCase("file")) {
if (port == -1) {
port = 0;
@ -347,10 +346,11 @@ public class CloudStackPrimaryDataStoreLifeCycleImpl implements PrimaryDataStore
protected boolean createStoragePool(long hostId, StoragePool pool) {
s_logger.debug("creating pool " + pool.getName() + " on host " + hostId);
if (pool.getPoolType() != StoragePoolType.NetworkFilesystem && pool.getPoolType() != StoragePoolType.Filesystem &&
pool.getPoolType() != StoragePoolType.IscsiLUN && pool.getPoolType() != StoragePoolType.Iscsi && pool.getPoolType() != StoragePoolType.VMFS &&
pool.getPoolType() != StoragePoolType.SharedMountPoint && pool.getPoolType() != StoragePoolType.PreSetup && pool.getPoolType() != StoragePoolType.OCFS2 &&
pool.getPoolType() != StoragePoolType.RBD && pool.getPoolType() != StoragePoolType.CLVM) {
pool.getPoolType() != StoragePoolType.RBD && pool.getPoolType() != StoragePoolType.CLVM && pool.getPoolType() != StoragePoolType.SMB) {
s_logger.warn(" Doesn't support storage pool type " + pool.getPoolType());
return false;
}

View File

@ -26,7 +26,10 @@ import java.net.URI;
import java.net.URISyntaxException;
import java.net.URLEncoder;
import java.net.UnknownHostException;
import java.util.ArrayList;
import java.util.List;
import java.util.ListIterator;
import java.util.StringTokenizer;
import javax.net.ssl.HttpsURLConnection;
@ -37,10 +40,14 @@ import org.apache.commons.httpclient.MultiThreadedHttpConnectionManager;
import org.apache.commons.httpclient.UsernamePasswordCredentials;
import org.apache.commons.httpclient.auth.AuthScope;
import org.apache.commons.httpclient.methods.GetMethod;
import org.apache.commons.httpclient.util.URIUtil;
import org.apache.http.NameValuePair;
import org.apache.http.message.BasicNameValuePair;
import org.apache.http.client.utils.URIBuilder;
import org.apache.http.client.utils.URLEncodedUtils;
import org.apache.log4j.Logger;
import com.cloud.utils.crypt.DBEncryptionUtil;
import com.cloud.utils.exception.CloudRuntimeException;
public class UriUtils {
@ -138,6 +145,59 @@ public class UriUtils {
return (foundUser && foundPswd);
}
public static String getUpdateUri(String url, boolean encrypt) {
String updatedPath = null;
try {
String query = URIUtil.getQuery(url);
URIBuilder builder = new URIBuilder(url);
builder.removeQuery();
String updatedQuery = new String();
List<NameValuePair> queryParams = getUserDetails(query);
ListIterator<NameValuePair> iterator = queryParams.listIterator();
while (iterator.hasNext()) {
NameValuePair param = iterator.next();
String value = null;
if ("password".equalsIgnoreCase(param.getName()) &&
param.getValue() != null) {
value = encrypt ? DBEncryptionUtil.encrypt(param.getValue()) : DBEncryptionUtil.decrypt(param.getValue());
} else {
value = param.getValue();
}
if (updatedQuery.isEmpty()) {
updatedQuery += (param.getName() + "=" + value);
} else {
updatedQuery += ("&" + param.getName() + "=" + value);
}
}
String schemeAndHost = new String();
URI newUri = builder.build();
if (newUri.getScheme() != null) {
schemeAndHost = newUri.getScheme() + "://" + newUri.getHost();
}
updatedPath = schemeAndHost + newUri.getPath() + "?" + updatedQuery;
} catch (URISyntaxException e) {
throw new CloudRuntimeException("Couldn't generate an updated uri. " + e.getMessage());
}
return updatedPath;
}
private static List<NameValuePair> getUserDetails(String query) {
List<NameValuePair> details = new ArrayList<NameValuePair>();
StringTokenizer allParams = new StringTokenizer(query, "&");
while (allParams.hasMoreTokens()) {
String param = allParams.nextToken();
details.add(new BasicNameValuePair(param.substring(0, param.indexOf("=")),
param.substring(param.indexOf("=") + 1)));
}
return details;
}
// Get the size of a file from URL response header.
public static Long getRemoteSize(String url) {
Long remoteSize = (long)0;