on-demand release 4.0dev+
[moodle.git] / mnet / environment.php
CommitLineData
1d422980 1<?php
71558f85 2/**
3 * Info about the local environment, wrt RPC
4 *
5 * This should really be a singleton. A PHP5 Todo I guess.
6 */
7
8class mnet_environment {
9
10 var $id = 0;
11 var $wwwroot = '';
12 var $ip_address = '';
13 var $public_key = '';
14 var $public_key_expires = 0;
15 var $last_connect_time = 0;
16 var $last_log_id = 0;
17 var $keypair = array();
f32689ad 18 var $deleted = 0;
71558f85 19
71558f85 20 function init() {
cc38ff5d 21 global $CFG, $DB;
71558f85 22
23 // Bootstrap the object data on first load.
1caea91e 24 if (!$hostobject = $DB->get_record('mnet_host', array('id'=>$CFG->mnet_localhost_id))) {
25 return false;
26 }
27 $temparr = get_object_vars($hostobject);
28 foreach($temparr as $key => $value) {
29 $this->$key = $value;
30 }
31 unset($hostobject, $temparr);
71558f85 32
1caea91e 33 // Unless this is an install/upgrade, generate the SSL keys.
34 if (empty($this->public_key)) {
35 $this->get_keypair();
71558f85 36 }
37
38 // We need to set up a record that represents 'all hosts'. Any rights
39 // granted to this host will be conferred on all hosts.
40 if (empty($CFG->mnet_all_hosts_id) ) {
41 $hostobject = new stdClass();
42 $hostobject->wwwroot = '';
43 $hostobject->ip_address = '';
44 $hostobject->public_key = '';
4ab65b56 45 $hostobject->public_key_expires = 0;
46 $hostobject->last_connect_time = 0;
47 $hostobject->last_log_id = 0;
71558f85 48 $hostobject->deleted = 0;
49 $hostobject->name = 'All Hosts';
50
cc38ff5d 51 $hostobject->id = $DB->insert_record('mnet_host',$hostobject);
71558f85 52 set_config('mnet_all_hosts_id', $hostobject->id);
53 $CFG->mnet_all_hosts_id = $hostobject->id;
54 unset($hostobject);
55 }
56 }
57
58 function get_keypair() {
1caea91e 59 global $DB, $CFG;
a5d424df 60
735c7beb 61 // We don't generate keys on install/upgrade because we want the USER
62 // record to have an email address, city and country already.
31a99877 63 if (during_initial_install()) return true;
1caea91e 64 if ($CFG->mnet_dispatcher_mode == 'off') return true;
722f3f05 65 if (!extension_loaded("openssl")) return true;
71558f85 66 if (!empty($this->keypair)) return true;
735c7beb 67
68 $this->keypair = array();
bac44e6d 69 $keypair = get_config('mnet', 'openssl');
735c7beb 70
71 if (!empty($keypair)) {
72 // Explode/Implode is faster than Unserialize/Serialize
8c99567e 73 list($this->keypair['certificate'], $this->keypair['keypair_PEM']) = explode('@@@@@@@@', $keypair);
735c7beb 74 }
75
76 if ($this->public_key_expires > time()) {
08cb427a 77 $this->keypair['privatekey'] = openssl_pkey_get_private($this->keypair['keypair_PEM']);
78 $this->keypair['publickey'] = openssl_pkey_get_public($this->keypair['certificate']);
71558f85 79 } else {
735c7beb 80 // Key generation/rotation
81
82 // 1. Archive the current key (if there is one).
bac44e6d 83 $result = get_config('mnet', 'openssl_history');
735c7beb 84 if(empty($result)) {
85 set_config('openssl_history', serialize(array()), 'mnet');
86 $openssl_history = array();
87 } else {
88 $openssl_history = unserialize($result);
89 }
90
91 if(count($this->keypair)) {
92 $this->keypair['expires'] = $this->public_key_expires;
93 array_unshift($openssl_history, $this->keypair);
94 }
95
1d422980 96 // 2. How many old keys do we want to keep? Use array_slice to get
735c7beb 97 // rid of any we don't want
bac44e6d 98 $openssl_generations = get_config('mnet', 'openssl_generations');
735c7beb 99 if(empty($openssl_generations)) {
100 set_config('openssl_generations', 3, 'mnet');
101 $openssl_generations = 3;
102 }
103
104 if(count($openssl_history) > $openssl_generations) {
105 $openssl_history = array_slice($openssl_history, 0, $openssl_generations);
106 }
107
108 set_config('openssl_history', serialize($openssl_history), 'mnet');
109
110 // 3. Generate fresh keys
e2d4f75c 111 $this->replace_keys();
71558f85 112 }
113 return true;
114 }
115
e2d4f75c 116 function replace_keys() {
e47ac681 117 global $DB, $CFG;
cc38ff5d 118
eb7f89bc 119 $keypair = mnet_generate_keypair();
120 if (empty($keypair)) {
121 error_log('Can not generate keypair, sorry');
122 return;
123 }
124
e2d4f75c 125 $this->keypair = array();
eb7f89bc 126 $this->keypair = $keypair;
e2d4f75c 127 $this->public_key = $this->keypair['certificate'];
08cb427a 128 $details = openssl_x509_parse($this->public_key);
e2d4f75c 129 $this->public_key_expires = $details['validTo_time_t'];
130
e47ac681 131 $this->wwwroot = $CFG->wwwroot;
132 if (empty($_SERVER['SERVER_ADDR'])) {
133 // SERVER_ADDR is only returned by Apache-like webservers
134 $my_hostname = mnet_get_hostname_from_uri($CFG->wwwroot);
135 $my_ip = gethostbyname($my_hostname); // Returns unmodified hostname on failure. DOH!
136 if ($my_ip == $my_hostname) {
137 $this->ip_address = 'UNKNOWN';
138 } else {
139 $this->ip_address = $my_ip;
140 }
141 } else {
142 $this->ip_address = $_SERVER['SERVER_ADDR'];
143 }
144
e2d4f75c 145 set_config('openssl', implode('@@@@@@@@', $this->keypair), 'mnet');
146
cc38ff5d 147 $DB->update_record('mnet_host', $this);
309eb040 148 error_log('New public key has been generated. It expires ' . date('Y/m/d h:i:s', $this->public_key_expires));
e2d4f75c 149 }
150
71558f85 151 function get_private_key() {
152 if (empty($this->keypair)) $this->get_keypair();
153 if (isset($this->keypair['privatekey'])) return $this->keypair['privatekey'];
08cb427a 154 $this->keypair['privatekey'] = openssl_pkey_get_private($this->keypair['keypair_PEM']);
71558f85 155 return $this->keypair['privatekey'];
156 }
157
158 function get_public_key() {
159 if (!isset($this->keypair)) $this->get_keypair();
160 if (isset($this->keypair['publickey'])) return $this->keypair['publickey'];
08cb427a 161 $this->keypair['publickey'] = openssl_pkey_get_public($this->keypair['certificate']);
71558f85 162 return $this->keypair['publickey'];
163 }
71558f85 164}