summaryrefslogtreecommitdiffstats
path: root/plugins/check_smtp.c
diff options
context:
space:
mode:
Diffstat (limited to 'plugins/check_smtp.c')
-rw-r--r--plugins/check_smtp.c1445
1 files changed, 792 insertions, 653 deletions
diff --git a/plugins/check_smtp.c b/plugins/check_smtp.c
index e6369e63..24883fd8 100644
--- a/plugins/check_smtp.c
+++ b/plugins/check_smtp.c
@@ -1,263 +1,313 @@
1/***************************************************************************** 1/*****************************************************************************
2* 2 *
3* Monitoring check_smtp plugin 3 * Monitoring check_smtp plugin
4* 4 *
5* License: GPL 5 * License: GPL
6* Copyright (c) 2000-2024 Monitoring Plugins Development Team 6 * Copyright (c) 2000-2024 Monitoring Plugins Development Team
7* 7 *
8* Description: 8 * Description:
9* 9 *
10* This file contains the check_smtp plugin 10 * This file contains the check_smtp plugin
11* 11 *
12* This plugin will attempt to open an SMTP connection with the host. 12 * This plugin will attempt to open an SMTP connection with the host.
13* 13 *
14* 14 *
15* This program is free software: you can redistribute it and/or modify 15 * This program is free software: you can redistribute it and/or modify
16* it under the terms of the GNU General Public License as published by 16 * it under the terms of the GNU General Public License as published by
17* the Free Software Foundation, either version 3 of the License, or 17 * the Free Software Foundation, either version 3 of the License, or
18* (at your option) any later version. 18 * (at your option) any later version.
19* 19 *
20* This program is distributed in the hope that it will be useful, 20 * This program is distributed in the hope that it will be useful,
21* but WITHOUT ANY WARRANTY; without even the implied warranty of 21 * but WITHOUT ANY WARRANTY; without even the implied warranty of
22* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 22 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
23* GNU General Public License for more details. 23 * GNU General Public License for more details.
24* 24 *
25* You should have received a copy of the GNU General Public License 25 * You should have received a copy of the GNU General Public License
26* along with this program. If not, see <http://www.gnu.org/licenses/>. 26 * along with this program. If not, see <http://www.gnu.org/licenses/>.
27* 27 *
28* 28 *
29*****************************************************************************/ 29 *****************************************************************************/
30
31const char *progname = "check_smtp";
32const char *copyright = "2000-2024";
33const char *email = "devel@monitoring-plugins.org";
34 30
35#include "common.h" 31#include "common.h"
36#include "netutils.h" 32#include "netutils.h"
33#include "output.h"
34#include "perfdata.h"
35#include "thresholds.h"
37#include "utils.h" 36#include "utils.h"
38#include "base64.h" 37#include "base64.h"
38#include "regex.h"
39 39
40#include <ctype.h> 40#include <ctype.h>
41#include <string.h>
42#include "check_smtp.d/config.h"
43#include "../lib/states.h"
44
45const char *progname = "check_smtp";
46const char *copyright = "2000-2024";
47const char *email = "devel@monitoring-plugins.org";
48
49#define PROXY_PREFIX "PROXY TCP4 0.0.0.0 0.0.0.0 25 25\r\n"
50#define SMTP_HELO "HELO "
51#define SMTP_EHLO "EHLO "
52#define SMTP_LHLO "LHLO "
53#define SMTP_QUIT "QUIT\r\n"
54#define SMTP_STARTTLS "STARTTLS\r\n"
55#define SMTP_AUTH_LOGIN "AUTH LOGIN\r\n"
56
57#define EHLO_SUPPORTS_STARTTLS 1
58
59typedef struct {
60 int errorcode;
61 check_smtp_config config;
62} check_smtp_config_wrapper;
63static check_smtp_config_wrapper process_arguments(int /*argc*/, char ** /*argv*/);
41 64
65int my_recv(check_smtp_config config, void *buf, int num, int socket_descriptor,
66 bool ssl_established) {
42#ifdef HAVE_SSL 67#ifdef HAVE_SSL
43static bool check_cert = false; 68 if ((config.use_starttls || config.use_ssl) && ssl_established) {
44static int days_till_exp_warn, days_till_exp_crit; 69 return np_net_ssl_read(buf, num);
45# define my_recv(buf, len) (((use_starttls || use_ssl) && ssl_established) ? np_net_ssl_read(buf, len) : read(sd, buf, len)) 70 }
46# define my_send(buf, len) (((use_starttls || use_ssl) && ssl_established) ? np_net_ssl_write(buf, len) : send(sd, buf, len, 0)) 71 return (int)read(socket_descriptor, buf, (size_t)num);
47#else /* ifndef HAVE_SSL */ 72#else /* ifndef HAVE_SSL */
48# define my_recv(buf, len) read(sd, buf, len) 73 return read(socket_descriptor, buf, len)
49# define my_send(buf, len) send(sd, buf, len, 0)
50#endif 74#endif
75}
51 76
52enum { 77int my_send(check_smtp_config config, void *buf, int num, int socket_descriptor,
53 SMTP_PORT = 25, 78 bool ssl_established) {
54 SMTPS_PORT = 465 79#ifdef HAVE_SSL
55}; 80 if ((config.use_starttls || config.use_ssl) && ssl_established) {
56#define PROXY_PREFIX "PROXY TCP4 0.0.0.0 0.0.0.0 25 25\r\n"
57#define SMTP_EXPECT "220"
58#define SMTP_HELO "HELO "
59#define SMTP_EHLO "EHLO "
60#define SMTP_LHLO "LHLO "
61#define SMTP_QUIT "QUIT\r\n"
62#define SMTP_STARTTLS "STARTTLS\r\n"
63#define SMTP_AUTH_LOGIN "AUTH LOGIN\r\n"
64 81
65#define EHLO_SUPPORTS_STARTTLS 1 82 return np_net_ssl_write(buf, num);
83 }
84 return (int)send(socket_descriptor, buf, (size_t)num, 0);
85#else /* ifndef HAVE_SSL */
86 return send(socket_descriptor, buf, len, 0);
87#endif
88}
66 89
67static int process_arguments (int, char **); 90static void print_help(void);
68static int validate_arguments (void); 91void print_usage(void);
69static void print_help (void); 92static char *smtp_quit(check_smtp_config /*config*/, char /*buffer*/[MAX_INPUT_BUFFER],
70void print_usage (void); 93 int /*socket_descriptor*/, bool /*ssl_established*/);
71static void smtp_quit(void); 94static int recvline(char * /*buf*/, size_t /*bufsize*/, check_smtp_config /*config*/,
72static int recvline(char *, size_t); 95 int /*socket_descriptor*/, bool /*ssl_established*/);
73static int recvlines(char *, size_t); 96static int recvlines(check_smtp_config /*config*/, char * /*buf*/, size_t /*bufsize*/,
74static int my_close(void); 97 int /*socket_descriptor*/, bool /*ssl_established*/);
98static int my_close(int /*socket_descriptor*/);
75 99
76#include "regex.h"
77static regex_t preg;
78static regmatch_t pmatch[10];
79static char errbuf[MAX_INPUT_BUFFER];
80static int cflags = REG_EXTENDED | REG_NOSUB | REG_NEWLINE;
81static int eflags = 0;
82static int errcode, excode;
83
84static int server_port = SMTP_PORT;
85static int server_port_option = 0;
86static char *server_address = NULL;
87static char *server_expect = NULL;
88static char *mail_command = NULL;
89static char *from_arg = NULL;
90static int send_mail_from=0;
91static int ncommands=0;
92static int command_size=0;
93static int nresponses=0;
94static int response_size=0;
95static char **commands = NULL;
96static char **responses = NULL;
97static char *authtype = NULL;
98static char *authuser = NULL;
99static char *authpass = NULL;
100static double warning_time = 0;
101static bool check_warning_time = false;
102static double critical_time = 0;
103static bool check_critical_time = false;
104static int verbose = 0; 100static int verbose = 0;
105static bool use_ssl = false;
106static bool use_starttls = false;
107static bool use_sni = false;
108static bool use_proxy_prefix = false;
109static bool use_ehlo = false;
110static bool use_lhlo = false;
111static bool ssl_established = false;
112static char *localhostname = NULL;
113static int sd;
114static char buffer[MAX_INPUT_BUFFER];
115enum {
116 TCP_PROTOCOL = 1,
117 UDP_PROTOCOL = 2,
118};
119static bool ignore_send_quit_failure = false;
120
121
122int
123main (int argc, char **argv)
124{
125 bool supports_tls = false;
126 int n = 0;
127 double elapsed_time;
128 long microsec;
129 int result = STATE_UNKNOWN;
130 char *cmd_str = NULL;
131 char *helocmd = NULL;
132 char *error_msg = "";
133 char *server_response = NULL;
134 struct timeval tv;
135 101
136 /* Catch pipe errors in read/write - sometimes occurs when writing QUIT */ 102int main(int argc, char **argv) {
137 (void) signal (SIGPIPE, SIG_IGN); 103#ifdef __OpenBSD__
104 /* - rpath is required to read --extra-opts (given up later)
105 * - inet is required for sockets
106 * - unix is required for Unix domain sockets
107 * - dns is required for name lookups */
108 pledge("stdio rpath inet unix dns", NULL);
109#endif // __OpenBSD__
138 110
139 setlocale (LC_ALL, ""); 111 setlocale(LC_ALL, "");
140 bindtextdomain (PACKAGE, LOCALEDIR); 112 bindtextdomain(PACKAGE, LOCALEDIR);
141 textdomain (PACKAGE); 113 textdomain(PACKAGE);
142 114
143 /* Parse extra opts if any */ 115 /* Parse extra opts if any */
144 argv=np_extra_opts (&argc, argv, progname); 116 argv = np_extra_opts(&argc, argv, progname);
117
118 check_smtp_config_wrapper tmp_config = process_arguments(argc, argv);
145 119
146 if (process_arguments (argc, argv) == ERROR) 120 if (tmp_config.errorcode == ERROR) {
147 usage4 (_("Could not parse arguments")); 121 usage4(_("Could not parse arguments"));
122 }
123
124#ifdef __OpenBSD__
125 pledge("stdio inet unix dns", NULL);
126#endif // __OpenBSD__
127
128 const check_smtp_config config = tmp_config.config;
129
130 if (config.output_format_is_set) {
131 mp_set_format(config.output_format);
132 }
148 133
149 /* If localhostname not set on command line, use gethostname to set */ 134 /* If localhostname not set on command line, use gethostname to set */
150 if(! localhostname){ 135 char *localhostname = config.localhostname;
151 localhostname = malloc (HOST_MAX_BYTES); 136 if (!localhostname) {
152 if(!localhostname){ 137 localhostname = malloc(HOST_MAX_BYTES);
138 if (!localhostname) {
153 printf(_("malloc() failed!\n")); 139 printf(_("malloc() failed!\n"));
154 return STATE_CRITICAL; 140 exit(STATE_CRITICAL);
155 } 141 }
156 if(gethostname(localhostname, HOST_MAX_BYTES)){ 142 if (gethostname(localhostname, HOST_MAX_BYTES)) {
157 printf(_("gethostname() failed!\n")); 143 printf(_("gethostname() failed!\n"));
158 return STATE_CRITICAL; 144 exit(STATE_CRITICAL);
159 } 145 }
160 } 146 }
161 if(use_lhlo)
162 xasprintf (&helocmd, "%s%s%s", SMTP_LHLO, localhostname, "\r\n");
163 else if(use_ehlo)
164 xasprintf (&helocmd, "%s%s%s", SMTP_EHLO, localhostname, "\r\n");
165 else
166 xasprintf (&helocmd, "%s%s%s", SMTP_HELO, localhostname, "\r\n");
167 147
168 if (verbose) 148 char *helocmd = NULL;
149 if (config.use_lhlo) {
150 xasprintf(&helocmd, "%s%s%s", SMTP_LHLO, localhostname, "\r\n");
151 } else if (config.use_ehlo) {
152 xasprintf(&helocmd, "%s%s%s", SMTP_EHLO, localhostname, "\r\n");
153 } else {
154 xasprintf(&helocmd, "%s%s%s", SMTP_HELO, localhostname, "\r\n");
155 }
156
157 if (verbose) {
169 printf("HELOCMD: %s", helocmd); 158 printf("HELOCMD: %s", helocmd);
159 }
170 160
161 char *mail_command = strdup("MAIL ");
162 char *cmd_str = NULL;
171 /* initialize the MAIL command with optional FROM command */ 163 /* initialize the MAIL command with optional FROM command */
172 xasprintf (&cmd_str, "%sFROM:<%s>%s", mail_command, from_arg, "\r\n"); 164 xasprintf(&cmd_str, "%sFROM:<%s>%s", mail_command, config.from_arg, "\r\n");
173 165
174 if (verbose && send_mail_from) 166 if (verbose && config.send_mail_from) {
175 printf ("FROM CMD: %s", cmd_str); 167 printf("FROM CMD: %s", cmd_str);
168 }
169
170 /* Catch pipe errors in read/write - sometimes occurs when writing QUIT */
171 (void)signal(SIGPIPE, SIG_IGN);
176 172
177 /* initialize alarm signal handling */ 173 /* initialize alarm signal handling */
178 (void) signal (SIGALRM, socket_timeout_alarm_handler); 174 (void)signal(SIGALRM, socket_timeout_alarm_handler);
179 175
180 /* set socket timeout */ 176 /* set socket timeout */
181 (void) alarm (socket_timeout); 177 (void)alarm(socket_timeout);
182 178
179 struct timeval start_time;
183 /* start timer */ 180 /* start timer */
184 gettimeofday (&tv, NULL); 181 gettimeofday(&start_time, NULL);
182
183 int socket_descriptor = 0;
185 184
186 /* try to connect to the host at the given port number */ 185 /* try to connect to the host at the given port number */
187 result = my_tcp_connect (server_address, server_port, &sd); 186 mp_state_enum tcp_result =
188 187 my_tcp_connect(config.server_address, config.server_port, &socket_descriptor);
189 if (result == STATE_OK) { /* we connected */ 188
190 /* If requested, send PROXY header */ 189 mp_check overall = mp_check_init();
191 if (use_proxy_prefix) { 190 mp_subcheck sc_tcp_connect = mp_subcheck_init();
192 if (verbose) 191 char buffer[MAX_INPUT_BUFFER];
193 printf ("Sending header %s\n", PROXY_PREFIX); 192 bool ssl_established = false;
194 my_send(PROXY_PREFIX, strlen(PROXY_PREFIX)); 193
194 if (tcp_result != STATE_OK) {
195 // Connect failed
196 sc_tcp_connect = mp_set_subcheck_state(sc_tcp_connect, STATE_CRITICAL);
197 xasprintf(&sc_tcp_connect.output, "TCP connect to '%s' failed", config.server_address);
198 mp_add_subcheck_to_check(&overall, sc_tcp_connect);
199 mp_exit(overall);
200 }
201
202 /* we connected */
203 /* If requested, send PROXY header */
204 if (config.use_proxy_prefix) {
205 if (verbose) {
206 printf("Sending header %s\n", PROXY_PREFIX);
195 } 207 }
208 my_send(config, PROXY_PREFIX, strlen(PROXY_PREFIX), socket_descriptor, ssl_established);
209 }
196 210
197#ifdef HAVE_SSL 211#ifdef HAVE_SSL
198 if (use_ssl) { 212 if (config.use_ssl) {
199 result = np_net_ssl_init_with_hostname(sd, (use_sni ? server_address : NULL)); 213 int tls_result = np_net_ssl_init_with_hostname(
200 if (result != STATE_OK) { 214 socket_descriptor, (config.use_sni ? config.server_address : NULL));
201 printf (_("CRITICAL - Cannot create SSL context.\n")); 215
202 close(sd); 216 mp_subcheck sc_tls_connection = mp_subcheck_init();
203 np_net_ssl_cleanup(); 217
204 return STATE_CRITICAL; 218 if (tls_result != STATE_OK) {
205 } else { 219 close(socket_descriptor);
206 ssl_established = 1; 220 np_net_ssl_cleanup();
207 } 221
222 sc_tls_connection = mp_set_subcheck_state(sc_tls_connection, STATE_CRITICAL);
223 xasprintf(&sc_tls_connection.output, "cannot create TLS context");
224 mp_add_subcheck_to_check(&overall, sc_tls_connection);
225 mp_exit(overall);
208 } 226 }
227
228 sc_tls_connection = mp_set_subcheck_state(sc_tls_connection, STATE_OK);
229 xasprintf(&sc_tls_connection.output, "TLS context established");
230 mp_add_subcheck_to_check(&overall, sc_tls_connection);
231 ssl_established = true;
232 }
209#endif 233#endif
210 234
211 /* watch for the SMTP connection string and */ 235 /* watch for the SMTP connection string and */
212 /* return a WARNING status if we couldn't read any data */ 236 /* return a WARNING status if we couldn't read any data */
213 if (recvlines(buffer, MAX_INPUT_BUFFER) <= 0) { 237 if (recvlines(config, buffer, MAX_INPUT_BUFFER, socket_descriptor, ssl_established) <= 0) {
214 printf (_("recv() failed\n")); 238 mp_subcheck sc_read_data = mp_subcheck_init();
215 return STATE_WARNING; 239 sc_read_data = mp_set_subcheck_state(sc_read_data, STATE_WARNING);
240 xasprintf(&sc_read_data.output, "recv() failed");
241 mp_add_subcheck_to_check(&overall, sc_read_data);
242 mp_exit(overall);
243 }
244
245 char *server_response = NULL;
246 /* save connect return (220 hostname ..) for later use */
247 xasprintf(&server_response, "%s", buffer);
248
249 /* send the HELO/EHLO command */
250 my_send(config, helocmd, (int)strlen(helocmd), socket_descriptor, ssl_established);
251
252 /* allow for response to helo command to reach us */
253 if (recvlines(config, buffer, MAX_INPUT_BUFFER, socket_descriptor, ssl_established) <= 0) {
254 mp_subcheck sc_read_data = mp_subcheck_init();
255 sc_read_data = mp_set_subcheck_state(sc_read_data, STATE_WARNING);
256 xasprintf(&sc_read_data.output, "recv() failed");
257 mp_add_subcheck_to_check(&overall, sc_read_data);
258 mp_exit(overall);
259 }
260
261 bool supports_tls = false;
262 if (config.use_ehlo || config.use_lhlo) {
263 if (strstr(buffer, "250 STARTTLS") != NULL || strstr(buffer, "250-STARTTLS") != NULL) {
264 supports_tls = true;
216 } 265 }
266 }
217 267
218 /* save connect return (220 hostname ..) for later use */ 268 if (config.use_starttls && !supports_tls) {
219 xasprintf(&server_response, "%s", buffer); 269 smtp_quit(config, buffer, socket_descriptor, ssl_established);
220 270
221 /* send the HELO/EHLO command */ 271 mp_subcheck sc_read_data = mp_subcheck_init();
222 my_send(helocmd, strlen(helocmd)); 272 sc_read_data = mp_set_subcheck_state(sc_read_data, STATE_WARNING);
273 xasprintf(&sc_read_data.output, "StartTLS not supported by server");
274 mp_add_subcheck_to_check(&overall, sc_read_data);
275 mp_exit(overall);
276 }
223 277
224 /* allow for response to helo command to reach us */ 278#ifdef HAVE_SSL
225 if (recvlines(buffer, MAX_INPUT_BUFFER) <= 0) { 279 if (config.use_starttls) {
226 printf (_("recv() failed\n")); 280 /* send the STARTTLS command */
227 return STATE_WARNING; 281 send(socket_descriptor, SMTP_STARTTLS, strlen(SMTP_STARTTLS), 0);
228 } else if(use_ehlo || use_lhlo){ 282
229 if(strstr(buffer, "250 STARTTLS") != NULL || 283 mp_subcheck sc_starttls_init = mp_subcheck_init();
230 strstr(buffer, "250-STARTTLS") != NULL){ 284 recvlines(config, buffer, MAX_INPUT_BUFFER, socket_descriptor,
231 supports_tls=true; 285 ssl_established); /* wait for it */
232 } 286 if (!strstr(buffer, SMTP_EXPECT)) {
287 smtp_quit(config, buffer, socket_descriptor, ssl_established);
288
289 xasprintf(&sc_starttls_init.output, "StartTLS not supported by server");
290 sc_starttls_init = mp_set_subcheck_state(sc_starttls_init, STATE_UNKNOWN);
291 mp_add_subcheck_to_check(&overall, sc_starttls_init);
292 mp_exit(overall);
233 } 293 }
234 294
235 if(use_starttls && ! supports_tls){ 295 mp_state_enum starttls_result = np_net_ssl_init_with_hostname(
236 printf(_("WARNING - TLS not supported by server\n")); 296 socket_descriptor, (config.use_sni ? config.server_address : NULL));
237 smtp_quit(); 297 if (starttls_result != STATE_OK) {
238 return STATE_WARNING; 298 close(socket_descriptor);
299 np_net_ssl_cleanup();
300
301 sc_starttls_init = mp_set_subcheck_state(sc_starttls_init, STATE_CRITICAL);
302 xasprintf(&sc_starttls_init.output, "failed to create StartTLS context");
303 mp_add_subcheck_to_check(&overall, sc_starttls_init);
304 mp_exit(overall);
239 } 305 }
306 sc_starttls_init = mp_set_subcheck_state(sc_starttls_init, STATE_OK);
307 xasprintf(&sc_starttls_init.output, "created StartTLS context");
308 mp_add_subcheck_to_check(&overall, sc_starttls_init);
240 309
241#ifdef HAVE_SSL 310 ssl_established = true;
242 if(use_starttls) {
243 /* send the STARTTLS command */
244 send(sd, SMTP_STARTTLS, strlen(SMTP_STARTTLS), 0);
245
246 recvlines(buffer, MAX_INPUT_BUFFER); /* wait for it */
247 if (!strstr (buffer, SMTP_EXPECT)) {
248 printf (_("Server does not support STARTTLS\n"));
249 smtp_quit();
250 return STATE_UNKNOWN;
251 }
252 result = np_net_ssl_init_with_hostname(sd, (use_sni ? server_address : NULL));
253 if(result != STATE_OK) {
254 printf (_("CRITICAL - Cannot create SSL context.\n"));
255 close(sd);
256 np_net_ssl_cleanup();
257 return STATE_CRITICAL;
258 } else {
259 ssl_established = 1;
260 }
261 311
262 /* 312 /*
263 * Resend the EHLO command. 313 * Resend the EHLO command.
@@ -270,218 +320,287 @@ main (int argc, char **argv)
270 * reason, some MTAs will not allow an AUTH LOGIN command before 320 * reason, some MTAs will not allow an AUTH LOGIN command before
271 * we resent EHLO via TLS. 321 * we resent EHLO via TLS.
272 */ 322 */
273 if (my_send(helocmd, strlen(helocmd)) <= 0) { 323 if (my_send(config, helocmd, (int)strlen(helocmd), socket_descriptor, ssl_established) <=
274 printf("%s\n", _("SMTP UNKNOWN - Cannot send EHLO command via TLS.")); 324 0) {
275 my_close(); 325 my_close(socket_descriptor);
276 return STATE_UNKNOWN; 326
327 mp_subcheck sc_ehlo = mp_subcheck_init();
328 sc_ehlo = mp_set_subcheck_state(sc_ehlo, STATE_UNKNOWN);
329 xasprintf(&sc_ehlo.output, "cannot send EHLO command via StartTLS");
330 mp_add_subcheck_to_check(&overall, sc_ehlo);
331 mp_exit(overall);
277 } 332 }
278 if (verbose) 333
334 if (verbose) {
279 printf(_("sent %s"), helocmd); 335 printf(_("sent %s"), helocmd);
280 if ((n = recvlines(buffer, MAX_INPUT_BUFFER)) <= 0) {
281 printf("%s\n", _("SMTP UNKNOWN - Cannot read EHLO response via TLS."));
282 my_close();
283 return STATE_UNKNOWN;
284 } 336 }
337
338 if (recvlines(config, buffer, MAX_INPUT_BUFFER, socket_descriptor, ssl_established) <= 0) {
339 my_close(socket_descriptor);
340
341 mp_subcheck sc_ehlo = mp_subcheck_init();
342 sc_ehlo = mp_set_subcheck_state(sc_ehlo, STATE_UNKNOWN);
343 xasprintf(&sc_ehlo.output, "cannot read EHLO response via StartTLS");
344 mp_add_subcheck_to_check(&overall, sc_ehlo);
345 mp_exit(overall);
346 }
347
285 if (verbose) { 348 if (verbose) {
286 printf("%s", buffer); 349 printf("%s", buffer);
287 } 350 }
351 }
352
353# ifdef USE_OPENSSL
354 if (ssl_established) {
355 net_ssl_check_cert_result cert_check_result =
356 np_net_ssl_check_cert2(config.days_till_exp_warn, config.days_till_exp_crit);
357
358 mp_subcheck sc_cert_check = mp_subcheck_init();
359
360 switch (cert_check_result.errors) {
361 case ALL_OK: {
362
363 if (cert_check_result.result_state != STATE_OK &&
364 config.ignore_certificate_expiration) {
365 xasprintf(&sc_cert_check.output,
366 "Remaining certificate lifetime: %d days. Expiration will be ignored",
367 (int)(cert_check_result.remaining_seconds / 86400));
368 sc_cert_check = mp_set_subcheck_state(sc_cert_check, STATE_OK);
369 } else {
370 xasprintf(&sc_cert_check.output, "Remaining certificate lifetime: %d days",
371 (int)(cert_check_result.remaining_seconds / 86400));
372 sc_cert_check =
373 mp_set_subcheck_state(sc_cert_check, cert_check_result.result_state);
374 }
375 } break;
376 case NO_SERVER_CERTIFICATE_PRESENT: {
377 xasprintf(&sc_cert_check.output, "no server certificate present");
378 sc_cert_check = mp_set_subcheck_state(sc_cert_check, cert_check_result.result_state);
379 } break;
380 case UNABLE_TO_RETRIEVE_CERTIFICATE_SUBJECT: {
381 xasprintf(&sc_cert_check.output, "can not retrieve certificate subject");
382 sc_cert_check = mp_set_subcheck_state(sc_cert_check, cert_check_result.result_state);
383 } break;
384 case WRONG_TIME_FORMAT_IN_CERTIFICATE: {
385 xasprintf(&sc_cert_check.output, "wrong time format in certificate");
386 sc_cert_check = mp_set_subcheck_state(sc_cert_check, cert_check_result.result_state);
387 } break;
388 };
389
390 mp_add_subcheck_to_check(&overall, sc_cert_check);
391 }
392# endif /* USE_OPENSSL */
288 393
289# ifdef USE_OPENSSL
290 if ( check_cert ) {
291 result = np_net_ssl_check_cert(days_till_exp_warn, days_till_exp_crit);
292 smtp_quit();
293 my_close();
294 return result;
295 }
296# endif /* USE_OPENSSL */
297 }
298#endif 394#endif
299 395
300 if (verbose) 396 if (verbose) {
301 printf ("%s", buffer); 397 printf("%s", buffer);
302 398 }
303 /* save buffer for later use */ 399
304 xasprintf(&server_response, "%s%s", server_response, buffer); 400 /* save buffer for later use */
305 /* strip the buffer of carriage returns */ 401 xasprintf(&server_response, "%s%s", server_response, buffer);
306 strip (server_response); 402 /* strip the buffer of carriage returns */
307 403 strip(server_response);
308 /* make sure we find the droids we are looking for */ 404
309 if (!strstr (server_response, server_expect)) { 405 /* make sure we find the droids we are looking for */
310 if (server_port == SMTP_PORT) 406 mp_subcheck sc_expect_response = mp_subcheck_init();
311 printf (_("Invalid SMTP response received from host: %s\n"), server_response); 407
312 else 408 if (!strstr(server_response, config.server_expect)) {
313 printf (_("Invalid SMTP response received from host on port %d: %s\n"), 409 sc_expect_response = mp_set_subcheck_state(sc_expect_response, STATE_WARNING);
314 server_port, server_response); 410 if (config.server_port == SMTP_PORT) {
315 return STATE_WARNING; 411 xasprintf(&sc_expect_response.output, _("invalid SMTP response received from host: %s"),
412 server_response);
413 } else {
414 xasprintf(&sc_expect_response.output,
415 _("invalid SMTP response received from host on port %d: %s"),
416 config.server_port, server_response);
316 } 417 }
418 exit(STATE_WARNING);
419 } else {
420 xasprintf(&sc_expect_response.output, "received valid SMTP response '%s' from host: '%s'",
421 config.server_expect, server_response);
422 sc_expect_response = mp_set_subcheck_state(sc_expect_response, STATE_OK);
423 }
424
425 mp_add_subcheck_to_check(&overall, sc_expect_response);
317 426
318 if (send_mail_from) { 427 if (config.send_mail_from) {
319 my_send(cmd_str, strlen(cmd_str)); 428 my_send(config, cmd_str, (int)strlen(cmd_str), socket_descriptor, ssl_established);
320 if (recvlines(buffer, MAX_INPUT_BUFFER) >= 1 && verbose) 429 if (recvlines(config, buffer, MAX_INPUT_BUFFER, socket_descriptor, ssl_established) >= 1 &&
321 printf("%s", buffer); 430 verbose) {
431 printf("%s", buffer);
322 } 432 }
433 }
434
435 size_t counter = 0;
436 while (counter < config.ncommands) {
437 xasprintf(&cmd_str, "%s%s", config.commands[counter], "\r\n");
438 my_send(config, cmd_str, (int)strlen(cmd_str), socket_descriptor, ssl_established);
439 if (recvlines(config, buffer, MAX_INPUT_BUFFER, socket_descriptor, ssl_established) >= 1 &&
440 verbose) {
441 printf("%s", buffer);
442 }
443
444 strip(buffer);
445
446 if (counter < config.nresponses) {
447 int cflags = REG_EXTENDED | REG_NOSUB | REG_NEWLINE;
448 regex_t preg;
449 int errcode = regcomp(&preg, config.responses[counter], cflags);
450 char errbuf[MAX_INPUT_BUFFER];
451 if (errcode != 0) {
452 regerror(errcode, &preg, errbuf, MAX_INPUT_BUFFER);
453 printf(_("Could Not Compile Regular Expression"));
454 exit(STATE_UNKNOWN);
455 }
323 456
324 n = 0; 457 regmatch_t pmatch[10];
325 while (n < ncommands) { 458 int eflags = 0;
326 xasprintf (&cmd_str, "%s%s", commands[n], "\r\n"); 459 int excode = regexec(&preg, buffer, 10, pmatch, eflags);
327 my_send(cmd_str, strlen(cmd_str)); 460 mp_subcheck sc_expected_responses = mp_subcheck_init();
328 if (recvlines(buffer, MAX_INPUT_BUFFER) >= 1 && verbose) 461 if (excode == 0) {
329 printf("%s", buffer); 462 xasprintf(&sc_expected_responses.output, "valid response '%s' to command '%s'",
330 strip (buffer); 463 buffer, config.commands[counter]);
331 if (n < nresponses) { 464 sc_expected_responses = mp_set_subcheck_state(sc_expected_responses, STATE_OK);
332 cflags |= REG_EXTENDED | REG_NOSUB | REG_NEWLINE; 465 } else if (excode == REG_NOMATCH) {
333 errcode = regcomp (&preg, responses[n], cflags); 466 sc_expected_responses = mp_set_subcheck_state(sc_expected_responses, STATE_WARNING);
334 if (errcode != 0) { 467 xasprintf(&sc_expected_responses.output, "invalid response '%s' to command '%s'",
335 regerror (errcode, &preg, errbuf, MAX_INPUT_BUFFER); 468 buffer, config.commands[counter]);
336 printf (_("Could Not Compile Regular Expression")); 469 } else {
337 return ERROR; 470 regerror(excode, &preg, errbuf, MAX_INPUT_BUFFER);
471 xasprintf(&sc_expected_responses.output, "regexec execute error: %s", errbuf);
472 sc_expected_responses = mp_set_subcheck_state(sc_expected_responses, STATE_UNKNOWN);
473 }
474 }
475 counter++;
476 }
477
478 if (config.authtype != NULL) {
479 mp_subcheck sc_auth = mp_subcheck_init();
480
481 if (strcmp(config.authtype, "LOGIN") == 0) {
482 char *abuf;
483 int ret;
484 do {
485 /* send AUTH LOGIN */
486 my_send(config, SMTP_AUTH_LOGIN, strlen(SMTP_AUTH_LOGIN), socket_descriptor,
487 ssl_established);
488
489 if (verbose) {
490 printf(_("sent %s\n"), "AUTH LOGIN");
338 } 491 }
339 excode = regexec (&preg, buffer, 10, pmatch, eflags); 492
340 if (excode == 0) { 493 if ((ret = recvlines(config, buffer, MAX_INPUT_BUFFER, socket_descriptor,
341 result = STATE_OK; 494 ssl_established)) <= 0) {
495 xasprintf(&sc_auth.output, _("recv() failed after AUTH LOGIN"));
496 sc_auth = mp_set_subcheck_state(sc_auth, STATE_WARNING);
497 break;
342 } 498 }
343 else if (excode == REG_NOMATCH) { 499
344 result = STATE_WARNING; 500 if (verbose) {
345 printf (_("SMTP %s - Invalid response '%s' to command '%s'\n"), state_text (result), buffer, commands[n]); 501 printf(_("received %s\n"), buffer);
346 } 502 }
347 else { 503
348 regerror (excode, &preg, errbuf, MAX_INPUT_BUFFER); 504 if (strncmp(buffer, "334", 3) != 0) {
349 printf (_("Execute Error: %s\n"), errbuf); 505 xasprintf(&sc_auth.output, "invalid response received after AUTH LOGIN");
350 result = STATE_UNKNOWN; 506 sc_auth = mp_set_subcheck_state(sc_auth, STATE_CRITICAL);
507 break;
351 } 508 }
352 }
353 n++;
354 }
355 509
356 if (authtype != NULL) { 510 /* encode authuser with base64 */
357 if (strcmp (authtype, "LOGIN") == 0) { 511 base64_encode_alloc(config.authuser, strlen(config.authuser), &abuf);
358 char *abuf; 512 xasprintf(&abuf, "%s\r\n", abuf);
359 int ret; 513 my_send(config, abuf, (int)strlen(abuf), socket_descriptor, ssl_established);
360 do { 514 if (verbose) {
361 if (authuser == NULL) { 515 printf(_("sent %s\n"), abuf);
362 result = STATE_CRITICAL; 516 }
363 xasprintf(&error_msg, _("no authuser specified, ")); 517
364 break; 518 if ((ret = recvlines(config, buffer, MAX_INPUT_BUFFER, socket_descriptor,
365 } 519 ssl_established)) <= 0) {
366 if (authpass == NULL) { 520 xasprintf(&sc_auth.output, "recv() failed after sending authuser");
367 result = STATE_CRITICAL; 521 sc_auth = mp_set_subcheck_state(sc_auth, STATE_CRITICAL);
368 xasprintf(&error_msg, _("no authpass specified, "));
369 break;
370 }
371
372 /* send AUTH LOGIN */
373 my_send(SMTP_AUTH_LOGIN, strlen(SMTP_AUTH_LOGIN));
374 if (verbose)
375 printf (_("sent %s\n"), "AUTH LOGIN");
376
377 if ((ret = recvlines(buffer, MAX_INPUT_BUFFER)) <= 0) {
378 xasprintf(&error_msg, _("recv() failed after AUTH LOGIN, "));
379 result = STATE_WARNING;
380 break;
381 }
382 if (verbose)
383 printf (_("received %s\n"), buffer);
384
385 if (strncmp (buffer, "334", 3) != 0) {
386 result = STATE_CRITICAL;
387 xasprintf(&error_msg, _("invalid response received after AUTH LOGIN, "));
388 break;
389 }
390
391 /* encode authuser with base64 */
392 base64_encode_alloc (authuser, strlen(authuser), &abuf);
393 xasprintf(&abuf, "%s\r\n", abuf);
394 my_send(abuf, strlen(abuf));
395 if (verbose)
396 printf (_("sent %s\n"), abuf);
397
398 if ((ret = recvlines(buffer, MAX_INPUT_BUFFER)) <= 0) {
399 result = STATE_CRITICAL;
400 xasprintf(&error_msg, _("recv() failed after sending authuser, "));
401 break;
402 }
403 if (verbose) {
404 printf (_("received %s\n"), buffer);
405 }
406 if (strncmp (buffer, "334", 3) != 0) {
407 result = STATE_CRITICAL;
408 xasprintf(&error_msg, _("invalid response received after authuser, "));
409 break;
410 }
411 /* encode authpass with base64 */
412 base64_encode_alloc (authpass, strlen(authpass), &abuf);
413 xasprintf(&abuf, "%s\r\n", abuf);
414 my_send(abuf, strlen(abuf));
415 if (verbose) {
416 printf (_("sent %s\n"), abuf);
417 }
418 if ((ret = recvlines(buffer, MAX_INPUT_BUFFER)) <= 0) {
419 result = STATE_CRITICAL;
420 xasprintf(&error_msg, _("recv() failed after sending authpass, "));
421 break;
422 }
423 if (verbose) {
424 printf (_("received %s\n"), buffer);
425 }
426 if (strncmp (buffer, "235", 3) != 0) {
427 result = STATE_CRITICAL;
428 xasprintf(&error_msg, _("invalid response received after authpass, "));
429 break;
430 }
431 break; 522 break;
432 } while (0); 523 }
433 } else {
434 result = STATE_CRITICAL;
435 xasprintf(&error_msg, _("only authtype LOGIN is supported, "));
436 }
437 }
438 524
439 /* tell the server we're done */ 525 if (verbose) {
440 smtp_quit(); 526 printf(_("received %s\n"), buffer);
527 }
441 528
442 /* finally close the connection */ 529 if (strncmp(buffer, "334", 3) != 0) {
443 close (sd); 530 xasprintf(&sc_auth.output, "invalid response received after authuser");
444 } 531 sc_auth = mp_set_subcheck_state(sc_auth, STATE_CRITICAL);
532 break;
533 }
445 534
446 /* reset the alarm */ 535 /* encode authpass with base64 */
447 alarm (0); 536 base64_encode_alloc(config.authpass, strlen(config.authpass), &abuf);
537 xasprintf(&abuf, "%s\r\n", abuf);
538 my_send(config, abuf, (int)strlen(abuf), socket_descriptor, ssl_established);
539
540 if (verbose) {
541 printf(_("sent %s\n"), abuf);
542 }
448 543
449 microsec = deltime (tv); 544 if ((ret = recvlines(config, buffer, MAX_INPUT_BUFFER, socket_descriptor,
450 elapsed_time = (double)microsec / 1.0e6; 545 ssl_established)) <= 0) {
546 xasprintf(&sc_auth.output, "recv() failed after sending authpass");
547 sc_auth = mp_set_subcheck_state(sc_auth, STATE_CRITICAL);
548 break;
549 }
550
551 if (verbose) {
552 printf(_("received %s\n"), buffer);
553 }
554
555 if (strncmp(buffer, "235", 3) != 0) {
556 xasprintf(&sc_auth.output, "invalid response received after authpass");
557 sc_auth = mp_set_subcheck_state(sc_auth, STATE_CRITICAL);
558 break;
559 }
560 break;
561 } while (false);
562 } else {
563 sc_auth = mp_set_subcheck_state(sc_auth, STATE_CRITICAL);
564 xasprintf(&sc_auth.output, "only authtype LOGIN is supported");
565 }
451 566
452 if (result == STATE_OK) { 567 mp_add_subcheck_to_check(&overall, sc_auth);
453 if (check_critical_time && elapsed_time > critical_time)
454 result = STATE_CRITICAL;
455 else if (check_warning_time && elapsed_time > warning_time)
456 result = STATE_WARNING;
457 } 568 }
458 569
459 printf (_("SMTP %s - %s%.3f sec. response time%s%s|%s\n"), 570 /* tell the server we're done */
460 state_text (result), 571 smtp_quit(config, buffer, socket_descriptor, ssl_established);
461 error_msg,
462 elapsed_time,
463 verbose?", ":"", verbose?buffer:"",
464 fperfdata ("time", elapsed_time, "s",
465 (int)check_warning_time, warning_time,
466 (int)check_critical_time, critical_time,
467 true, 0, false, 0));
468 572
469 return result; 573 /* finally close the connection */
470} 574 close(socket_descriptor);
471 575
576 /* reset the alarm */
577 alarm(0);
472 578
579 long microsec = deltime(start_time);
580 double elapsed_time = (double)microsec / 1.0e6;
473 581
474/* process command-line arguments */ 582 mp_perfdata pd_elapsed_time = perfdata_init();
475int 583 pd_elapsed_time = mp_set_pd_value(pd_elapsed_time, elapsed_time);
476process_arguments (int argc, char **argv) 584 pd_elapsed_time.label = "time";
477{ 585 pd_elapsed_time.uom = "s";
478 int c;
479 char* temp;
480 586
481 bool implicit_tls = false; 587 pd_elapsed_time = mp_pd_set_thresholds(pd_elapsed_time, config.connection_time);
482 588
589 mp_subcheck sc_connection_time = mp_subcheck_init();
590 xasprintf(&sc_connection_time.output, "connection time: %.3gs", elapsed_time);
591 sc_connection_time =
592 mp_set_subcheck_state(sc_connection_time, mp_get_pd_status(pd_elapsed_time));
593 mp_add_subcheck_to_check(&overall, sc_connection_time);
594
595 mp_exit(overall);
596}
597
598/* process command-line arguments */
599check_smtp_config_wrapper process_arguments(int argc, char **argv) {
483 enum { 600 enum {
484 SNI_OPTION 601 SNI_OPTION = CHAR_MAX + 1,
602 output_format_index,
603 ignore_certificate_expiration_index,
485 }; 604 };
486 605
487 int option = 0; 606 int option = 0;
@@ -507,277 +626,301 @@ process_arguments (int argc, char **argv)
507 {"lmtp", no_argument, 0, 'L'}, 626 {"lmtp", no_argument, 0, 'L'},
508 {"ssl", no_argument, 0, 's'}, 627 {"ssl", no_argument, 0, 's'},
509 {"tls", no_argument, 0, 's'}, 628 {"tls", no_argument, 0, 's'},
510 {"starttls",no_argument,0,'S'}, 629 {"starttls", no_argument, 0, 'S'},
511 {"sni", no_argument, 0, SNI_OPTION}, 630 {"sni", no_argument, 0, SNI_OPTION},
512 {"certificate",required_argument,0,'D'}, 631 {"certificate", required_argument, 0, 'D'},
513 {"ignore-quit-failure",no_argument,0,'q'}, 632 {"ignore-quit-failure", no_argument, 0, 'q'},
514 {"proxy",no_argument,0,'r'}, 633 {"proxy", no_argument, 0, 'r'},
515 {0, 0, 0, 0} 634 {"ignore-certificate-expiration", no_argument, 0, ignore_certificate_expiration_index},
635 {"output-format", required_argument, 0, output_format_index},
636 {0, 0, 0, 0}};
637
638 check_smtp_config_wrapper result = {
639 .config = check_smtp_config_init(),
640 .errorcode = OK,
516 }; 641 };
517 642
518 if (argc < 2) 643 if (argc < 2) {
519 return ERROR; 644 result.errorcode = ERROR;
645 return result;
646 }
520 647
521 for (c = 1; c < argc; c++) { 648 for (int index = 1; index < argc; index++) {
522 if (strcmp ("-to", argv[c]) == 0) 649 if (strcmp("-to", argv[index]) == 0) {
523 strcpy (argv[c], "-t"); 650 strcpy(argv[index], "-t");
524 else if (strcmp ("-wt", argv[c]) == 0) 651 } else if (strcmp("-wt", argv[index]) == 0) {
525 strcpy (argv[c], "-w"); 652 strcpy(argv[index], "-w");
526 else if (strcmp ("-ct", argv[c]) == 0) 653 } else if (strcmp("-ct", argv[index]) == 0) {
527 strcpy (argv[c], "-c"); 654 strcpy(argv[index], "-c");
655 }
528 } 656 }
529 657
530 while (1) { 658 unsigned long command_size = 0;
531 c = getopt_long (argc, argv, "+hVv46Lrt:p:f:e:c:w:H:C:R:sSD:F:A:U:P:q", 659 unsigned long response_size = 0;
532 longopts, &option); 660 bool implicit_tls = false;
661 int server_port_option = 0;
662 while (true) {
663 int opt_index =
664 getopt_long(argc, argv, "+hVv46Lrt:p:f:e:c:w:H:C:R:sSD:F:A:U:P:q", longopts, &option);
533 665
534 if (c == -1 || c == EOF) 666 if (opt_index == -1 || opt_index == EOF) {
535 break; 667 break;
668 }
536 669
537 switch (c) { 670 switch (opt_index) {
538 case 'H': /* hostname */ 671 case 'H': /* hostname */
539 if (is_host (optarg)) { 672 if (is_host(optarg)) {
540 server_address = optarg; 673 result.config.server_address = optarg;
541 } 674 } else {
542 else { 675 usage2(_("Invalid hostname/address"), optarg);
543 usage2 (_("Invalid hostname/address"), optarg);
544 } 676 }
545 break; 677 break;
546 case 'p': /* port */ 678 case 'p': /* port */
547 if (is_intpos (optarg)) 679 if (is_intpos(optarg)) {
548 server_port_option = atoi (optarg); 680 server_port_option = atoi(optarg);
549 else 681 } else {
550 usage4 (_("Port must be a positive integer")); 682 usage4(_("Port must be a positive integer"));
683 }
551 break; 684 break;
552 case 'F': 685 case 'F':
553 /* localhostname */ 686 /* localhostname */
554 localhostname = strdup(optarg); 687 result.config.localhostname = strdup(optarg);
555 break; 688 break;
556 case 'f': /* from argument */ 689 case 'f': /* from argument */
557 from_arg = optarg + strspn(optarg, "<"); 690 result.config.from_arg = optarg + strspn(optarg, "<");
558 from_arg = strndup(from_arg, strcspn(from_arg, ">")); 691 result.config.from_arg =
559 send_mail_from = 1; 692 strndup(result.config.from_arg, strcspn(result.config.from_arg, ">"));
693 result.config.send_mail_from = true;
560 break; 694 break;
561 case 'A': 695 case 'A':
562 authtype = optarg; 696 result.config.authtype = optarg;
563 use_ehlo = true; 697 result.config.use_ehlo = true;
564 break; 698 break;
565 case 'U': 699 case 'U':
566 authuser = optarg; 700 result.config.authuser = optarg;
567 break; 701 break;
568 case 'P': 702 case 'P':
569 authpass = optarg; 703 result.config.authpass = optarg;
570 break; 704 break;
571 case 'e': /* server expect string on 220 */ 705 case 'e': /* server expect string on 220 */
572 server_expect = optarg; 706 result.config.server_expect = optarg;
573 break; 707 break;
574 case 'C': /* commands */ 708 case 'C': /* commands */
575 if (ncommands >= command_size) { 709 if (result.config.ncommands >= command_size) {
576 command_size+=8; 710 command_size += 8;
577 commands = realloc (commands, sizeof(char *) * command_size); 711 result.config.commands =
578 if (commands == NULL) 712 realloc(result.config.commands, sizeof(char *) * command_size);
579 die (STATE_UNKNOWN, 713 if (result.config.commands == NULL) {
580 _("Could not realloc() units [%d]\n"), ncommands); 714 die(STATE_UNKNOWN, _("Could not realloc() units [%lu]\n"),
715 result.config.ncommands);
716 }
581 } 717 }
582 commands[ncommands] = (char *) malloc (sizeof(char) * 255); 718 result.config.commands[result.config.ncommands] = (char *)malloc(sizeof(char) * 255);
583 strncpy (commands[ncommands], optarg, 255); 719 strncpy(result.config.commands[result.config.ncommands], optarg, 255);
584 ncommands++; 720 result.config.ncommands++;
585 break; 721 break;
586 case 'R': /* server responses */ 722 case 'R': /* server responses */
587 if (nresponses >= response_size) { 723 if (result.config.nresponses >= response_size) {
588 response_size += 8; 724 response_size += 8;
589 responses = realloc (responses, sizeof(char *) * response_size); 725 result.config.responses =
590 if (responses == NULL) 726 realloc(result.config.responses, sizeof(char *) * response_size);
591 die (STATE_UNKNOWN, 727 if (result.config.responses == NULL) {
592 _("Could not realloc() units [%d]\n"), nresponses); 728 die(STATE_UNKNOWN, _("Could not realloc() units [%lu]\n"),
729 result.config.nresponses);
730 }
593 } 731 }
594 responses[nresponses] = (char *) malloc (sizeof(char) * 255); 732 result.config.responses[result.config.nresponses] = (char *)malloc(sizeof(char) * 255);
595 strncpy (responses[nresponses], optarg, 255); 733 strncpy(result.config.responses[result.config.nresponses], optarg, 255);
596 nresponses++; 734 result.config.nresponses++;
597 break; 735 break;
598 case 'c': /* critical time threshold */ 736 case 'c': /* critical time threshold */ {
599 if (!is_nonnegative (optarg)) 737 mp_range_parsed tmp = mp_parse_range_string(optarg);
600 usage4 (_("Critical time must be a positive")); 738 if (tmp.error != MP_PARSING_SUCCESS) {
601 else { 739 die(STATE_UNKNOWN, "failed to parse critical time threshold");
602 critical_time = strtod (optarg, NULL);
603 check_critical_time = true;
604 } 740 }
605 break; 741 result.config.connection_time =
606 case 'w': /* warning time threshold */ 742 mp_thresholds_set_warn(result.config.connection_time, tmp.range);
607 if (!is_nonnegative (optarg)) 743 } break;
608 usage4 (_("Warning time must be a positive")); 744 case 'w': /* warning time threshold */ {
609 else { 745 mp_range_parsed tmp = mp_parse_range_string(optarg);
610 warning_time = strtod (optarg, NULL); 746 if (tmp.error != MP_PARSING_SUCCESS) {
611 check_warning_time = true; 747 die(STATE_UNKNOWN, "failed to parse warning time threshold");
612 } 748 }
613 break; 749 result.config.connection_time =
614 case 'v': /* verbose */ 750 mp_thresholds_set_crit(result.config.connection_time, tmp.range);
751 } break;
752 case 'v': /* verbose */
615 verbose++; 753 verbose++;
616 break; 754 break;
617 case 'q': 755 case 'q':
618 ignore_send_quit_failure = true; /* ignore problem sending QUIT */ 756 result.config.ignore_send_quit_failure = true; /* ignore problem sending QUIT */
619 break; 757 break;
620 case 't': /* timeout */ 758 case 't': /* timeout */
621 if (is_intnonneg (optarg)) { 759 if (is_intnonneg(optarg)) {
622 socket_timeout = atoi (optarg); 760 socket_timeout = atoi(optarg);
623 } 761 } else {
624 else { 762 usage4(_("Timeout interval must be a positive integer"));
625 usage4 (_("Timeout interval must be a positive integer"));
626 } 763 }
627 break; 764 break;
628 case 'D': 765 case 'D': {
629 /* Check SSL cert validity */ 766 /* Check SSL cert validity */
630#ifdef USE_OPENSSL 767#ifdef USE_OPENSSL
631 if ((temp=strchr(optarg,','))!=NULL) { 768 char *temp;
632 *temp='\0'; 769 if ((temp = strchr(optarg, ',')) != NULL) {
633 if (!is_intnonneg (optarg)) 770 *temp = '\0';
634 usage2 ("Invalid certificate expiration period", optarg); 771 if (!is_intnonneg(optarg)) {
635 days_till_exp_warn = atoi(optarg); 772 usage2("Invalid certificate expiration period", optarg);
636 *temp=','; 773 }
637 temp++; 774 result.config.days_till_exp_warn = atoi(optarg);
638 if (!is_intnonneg (temp)) 775 *temp = ',';
639 usage2 (_("Invalid certificate expiration period"), temp); 776 temp++;
640 days_till_exp_crit = atoi (temp); 777 if (!is_intnonneg(temp)) {
641 } 778 usage2(_("Invalid certificate expiration period"), temp);
642 else { 779 }
643 days_till_exp_crit=0; 780 result.config.days_till_exp_crit = atoi(temp);
644 if (!is_intnonneg (optarg)) 781 } else {
645 usage2 ("Invalid certificate expiration period", optarg); 782 result.config.days_till_exp_crit = 0;
646 days_till_exp_warn = atoi (optarg); 783 if (!is_intnonneg(optarg)) {
647 } 784 usage2("Invalid certificate expiration period", optarg);
648 check_cert = true; 785 }
649 ignore_send_quit_failure = true; 786 result.config.days_till_exp_warn = atoi(optarg);
787 }
788 result.config.ignore_send_quit_failure = true;
650#else 789#else
651 usage (_("SSL support not available - install OpenSSL and recompile")); 790 usage(_("SSL support not available - install OpenSSL and recompile"));
652#endif 791#endif
653 implicit_tls = true; 792 implicit_tls = true;
654 // fallthrough 793 // fallthrough
655 case 's': 794 case 's':
656 /* ssl */ 795 /* ssl */
657 use_ssl = true; 796 result.config.use_ssl = true;
658 server_port = SMTPS_PORT; 797 result.config.server_port = SMTPS_PORT;
659 break; 798 break;
660 case 'S': 799 case 'S':
661 /* starttls */ 800 /* starttls */
662 use_starttls = true; 801 result.config.use_starttls = true;
663 use_ehlo = true; 802 result.config.use_ehlo = true;
664 break; 803 break;
804 }
665 case SNI_OPTION: 805 case SNI_OPTION:
666#ifdef HAVE_SSL 806#ifdef HAVE_SSL
667 use_sni = true; 807 result.config.use_sni = true;
668#else 808#else
669 usage (_("SSL support not available - install OpenSSL and recompile")); 809 usage(_("SSL support not available - install OpenSSL and recompile"));
670#endif 810#endif
671 break; 811 break;
672 case 'r': 812 case 'r':
673 use_proxy_prefix = true; 813 result.config.use_proxy_prefix = true;
674 break; 814 break;
675 case 'L': 815 case 'L':
676 use_lhlo = true; 816 result.config.use_lhlo = true;
677 break; 817 break;
678 case '4': 818 case '4':
679 address_family = AF_INET; 819 address_family = AF_INET;
680 break; 820 break;
681 case '6': 821 case '6':
682#ifdef USE_IPV6
683 address_family = AF_INET6; 822 address_family = AF_INET6;
684#else
685 usage4 (_("IPv6 support not available"));
686#endif
687 break; 823 break;
688 case 'V': /* version */ 824 case 'V': /* version */
689 print_revision (progname, NP_VERSION); 825 print_revision(progname, NP_VERSION);
690 exit (STATE_UNKNOWN); 826 exit(STATE_UNKNOWN);
691 case 'h': /* help */ 827 case 'h': /* help */
692 print_help (); 828 print_help();
693 exit (STATE_UNKNOWN); 829 exit(STATE_UNKNOWN);
694 case '?': /* help */ 830 case '?': /* help */
695 usage5 (); 831 usage5();
832 case output_format_index: {
833 parsed_output_format parser = mp_parse_output_format(optarg);
834 if (!parser.parsing_success) {
835 // TODO List all available formats here, maybe add anothoer usage function
836 printf("Invalid output format: %s\n", optarg);
837 exit(STATE_UNKNOWN);
838 }
839
840 result.config.output_format_is_set = true;
841 result.config.output_format = parser.output_format;
842 break;
843 }
844 case ignore_certificate_expiration_index: {
845 result.config.ignore_certificate_expiration = true;
846 }
696 } 847 }
697 } 848 }
698 849
699 c = optind; 850 int c = optind;
700 if (server_address == NULL) { 851 if (result.config.server_address == NULL) {
701 if (argv[c]) { 852 if (argv[c]) {
702 if (is_host (argv[c])) 853 if (is_host(argv[c])) {
703 server_address = argv[c]; 854 result.config.server_address = argv[c];
704 else 855 } else {
705 usage2 (_("Invalid hostname/address"), argv[c]); 856 usage2(_("Invalid hostname/address"), argv[c]);
706 } 857 }
707 else { 858 } else {
708 xasprintf (&server_address, "127.0.0.1"); 859 result.config.server_address = strdup("localhost");
709 } 860 }
710 } 861 }
711 862
712 if (server_expect == NULL) 863 if (result.config.use_starttls && result.config.use_ssl) {
713 server_expect = strdup (SMTP_EXPECT);
714
715 if (mail_command == NULL)
716 mail_command = strdup("MAIL ");
717
718 if (from_arg==NULL)
719 from_arg = strdup(" ");
720
721 if (use_starttls && use_ssl) {
722 if (implicit_tls) { 864 if (implicit_tls) {
723 use_ssl = false; 865 result.config.use_ssl = false;
724 server_port = SMTP_PORT;
725 } else { 866 } else {
726 usage4 (_("Set either -s/--ssl/--tls or -S/--starttls")); 867 usage4(_("Set either -s/--ssl/--tls or -S/--starttls"));
727 } 868 }
728 } 869 }
729 870
730 if (server_port_option != 0) { 871 if (server_port_option != 0) {
731 server_port = server_port_option; 872 result.config.server_port = server_port_option;
732 } 873 }
733 874
734 return validate_arguments (); 875 if (result.config.authtype) {
735} 876 if (strcmp(result.config.authtype, "LOGIN") == 0) {
736 877 if (result.config.authuser == NULL) {
737 878 usage4("no authuser specified");
879 }
880 if (result.config.authpass == NULL) {
881 usage4("no authpass specified");
882 }
883 } else {
884 usage4("only authtype LOGIN is supported");
885 }
886 }
738 887
739int 888 return result;
740validate_arguments (void)
741{
742 return OK;
743} 889}
744 890
745 891char *smtp_quit(check_smtp_config config, char buffer[MAX_INPUT_BUFFER], int socket_descriptor,
746void 892 bool ssl_established) {
747smtp_quit(void) 893 int sent_bytes =
748{ 894 my_send(config, SMTP_QUIT, strlen(SMTP_QUIT), socket_descriptor, ssl_established);
749 int bytes; 895 if (sent_bytes < 0) {
750 int n; 896 if (config.ignore_send_quit_failure) {
751 897 if (verbose) {
752 n = my_send(SMTP_QUIT, strlen(SMTP_QUIT));
753 if(n < 0) {
754 if(ignore_send_quit_failure) {
755 if(verbose) {
756 printf(_("Connection closed by server before sending QUIT command\n")); 898 printf(_("Connection closed by server before sending QUIT command\n"));
757 } 899 }
758 return; 900 return buffer;
759 } 901 }
760 die (STATE_UNKNOWN, 902 die(STATE_UNKNOWN, _("Connection closed by server before sending QUIT command\n"));
761 _("Connection closed by server before sending QUIT command\n"));
762 } 903 }
763 904
764 if (verbose) 905 if (verbose) {
765 printf(_("sent %s\n"), "QUIT"); 906 printf(_("sent %s\n"), "QUIT");
907 }
766 908
767 /* read the response but don't care about problems */ 909 /* read the response but don't care about problems */
768 bytes = recvlines(buffer, MAX_INPUT_BUFFER); 910 int bytes = recvlines(config, buffer, MAX_INPUT_BUFFER, socket_descriptor, ssl_established);
769 if (verbose) { 911 if (verbose) {
770 if (bytes < 0) 912 if (bytes < 0) {
771 printf(_("recv() failed after QUIT.")); 913 printf(_("recv() failed after QUIT."));
772 else if (bytes == 0) 914 } else if (bytes == 0) {
773 printf(_("Connection reset by peer.")); 915 printf(_("Connection reset by peer."));
774 else { 916 } else {
775 buffer[bytes] = '\0'; 917 buffer[bytes] = '\0';
776 printf(_("received %s\n"), buffer); 918 printf(_("received %s\n"), buffer);
777 } 919 }
778 } 920 }
779}
780 921
922 return buffer;
923}
781 924
782/* 925/*
783 * Receive one line, copy it into buf and nul-terminate it. Returns the 926 * Receive one line, copy it into buf and nul-terminate it. Returns the
@@ -788,24 +931,23 @@ smtp_quit(void)
788 * function which buffers the data, move that to netutils.c and change 931 * function which buffers the data, move that to netutils.c and change
789 * check_smtp and other plugins to use that. Also, remove (\r)\n. 932 * check_smtp and other plugins to use that. Also, remove (\r)\n.
790 */ 933 */
791int 934int recvline(char *buf, size_t bufsize, check_smtp_config config, int socket_descriptor,
792recvline(char *buf, size_t bufsize) 935 bool ssl_established) {
793{
794 int result; 936 int result;
795 unsigned i; 937 size_t counter;
796 938
797 for (i = result = 0; i < bufsize - 1; i++) { 939 for (counter = result = 0; counter < bufsize - 1; counter++) {
798 if ((result = my_recv(&buf[i], 1)) != 1) 940 if ((result = my_recv(config, &buf[counter], 1, socket_descriptor, ssl_established)) != 1) {
799 break; 941 break;
800 if (buf[i] == '\n') { 942 }
801 buf[++i] = '\0'; 943 if (buf[counter] == '\n') {
802 return i; 944 buf[++counter] = '\0';
945 return (int)counter;
803 } 946 }
804 } 947 }
805 return (result == 1 || i == 0) ? -2 : result; /* -2 if out of space */ 948 return (result == 1 || counter == 0) ? -2 : result; /* -2 if out of space */
806} 949}
807 950
808
809/* 951/*
810 * Receive one or more lines, copy them into buf and nul-terminate it. Returns 952 * Receive one or more lines, copy them into buf and nul-terminate it. Returns
811 * the number of bytes written to buf (excluding the '\0') or 0 on EOF or <0 on 953 * the number of bytes written to buf (excluding the '\0') or 0 on EOF or <0 on
@@ -820,117 +962,114 @@ recvline(char *buf, size_t bufsize)
820 * 962 *
821 * TODO: Move this to netutils.c. Also, remove \r and possibly the final \n. 963 * TODO: Move this to netutils.c. Also, remove \r and possibly the final \n.
822 */ 964 */
823int 965int recvlines(check_smtp_config config, char *buf, size_t bufsize, int socket_descriptor,
824recvlines(char *buf, size_t bufsize) 966 bool ssl_established) {
825{ 967 int result;
826 int result, i; 968 int counter;
827 969
828 for (i = 0; /* forever */; i += result) 970 for (counter = 0; /* forever */; counter += result) {
829 if (!((result = recvline(buf + i, bufsize - i)) > 3 && 971 if (!((result = recvline(buf + counter, bufsize - counter, config, socket_descriptor,
830 isdigit((int)buf[i]) && 972 ssl_established)) > 3 &&
831 isdigit((int)buf[i + 1]) && 973 isdigit((int)buf[counter]) && isdigit((int)buf[counter + 1]) &&
832 isdigit((int)buf[i + 2]) && 974 isdigit((int)buf[counter + 2]) && buf[counter + 3] == '-')) {
833 buf[i + 3] == '-'))
834 break; 975 break;
976 }
977 }
835 978
836 return (result <= 0) ? result : result + i; 979 return (result <= 0) ? result : result + counter;
837} 980}
838 981
839 982int my_close(int socket_descriptor) {
840int
841my_close (void)
842{
843 int result; 983 int result;
844 result = close(sd); 984 result = close(socket_descriptor);
845#ifdef HAVE_SSL 985#ifdef HAVE_SSL
846 np_net_ssl_cleanup(); 986 np_net_ssl_cleanup();
847#endif 987#endif
848 return result; 988 return result;
849} 989}
850 990
851 991void print_help(void) {
852void
853print_help (void)
854{
855 char *myport; 992 char *myport;
856 xasprintf (&myport, "%d", SMTP_PORT); 993 xasprintf(&myport, "%d", SMTP_PORT);
857 994
858 print_revision (progname, NP_VERSION); 995 print_revision(progname, NP_VERSION);
859 996
860 printf ("Copyright (c) 1999-2001 Ethan Galstad <nagios@nagios.org>\n"); 997 printf("Copyright (c) 1999-2001 Ethan Galstad <nagios@nagios.org>\n");
861 printf (COPYRIGHT, copyright, email); 998 printf(COPYRIGHT, copyright, email);
862 999
863 printf("%s\n", _("This plugin will attempt to open an SMTP connection with the host.")); 1000 printf("%s\n", _("This plugin will attempt to open an SMTP connection with the host."));
864 1001
865 printf ("\n\n"); 1002 printf("\n\n");
866 1003
867 print_usage (); 1004 print_usage();
868 1005
869 printf (UT_HELP_VRSN); 1006 printf(UT_HELP_VRSN);
870 printf (UT_EXTRA_OPTS); 1007 printf(UT_EXTRA_OPTS);
871 1008
872 printf (UT_HOST_PORT, 'p', myport); 1009 printf(UT_HOST_PORT, 'p', myport);
873 1010
874 printf (UT_IPv46); 1011 printf(UT_IPv46);
875 1012
876 printf (" %s\n", "-e, --expect=STRING"); 1013 printf(" %s\n", "-e, --expect=STRING");
877 printf (_(" String to expect in first line of server response (default: '%s')\n"), SMTP_EXPECT); 1014 printf(_(" String to expect in first line of server response (default: '%s')\n"),
878 printf (" %s\n", "-C, --command=STRING"); 1015 SMTP_EXPECT);
879 printf (" %s\n", _("SMTP command (may be used repeatedly)")); 1016 printf(" %s\n", "-C, --command=STRING");
880 printf (" %s\n", "-R, --response=STRING"); 1017 printf(" %s\n", _("SMTP command (may be used repeatedly)"));
881 printf (" %s\n", _("Expected response to command (may be used repeatedly)")); 1018 printf(" %s\n", "-R, --response=STRING");
882 printf (" %s\n", "-f, --from=STRING"); 1019 printf(" %s\n", _("Expected response to command (may be used repeatedly)"));
883 printf (" %s\n", _("FROM-address to include in MAIL command, required by Exchange 2000")), 1020 printf(" %s\n", "-f, --from=STRING");
884 printf (" %s\n", "-F, --fqdn=STRING"); 1021 printf(" %s\n", _("FROM-address to include in MAIL command, required by Exchange 2000")),
885 printf (" %s\n", _("FQDN used for HELO")); 1022 printf(" %s\n", "-F, --fqdn=STRING");
886 printf (" %s\n", "-r, --proxy"); 1023 printf(" %s\n", _("FQDN used for HELO"));
887 printf (" %s\n", _("Use PROXY protocol prefix for the connection.")); 1024 printf(" %s\n", "-r, --proxy");
1025 printf(" %s\n", _("Use PROXY protocol prefix for the connection."));
888#ifdef HAVE_SSL 1026#ifdef HAVE_SSL
889 printf (" %s\n", "-D, --certificate=INTEGER[,INTEGER]"); 1027 printf(" %s\n", "-D, --certificate=INTEGER[,INTEGER]");
890 printf (" %s\n", _("Minimum number of days a certificate has to be valid.")); 1028 printf(" %s\n", _("Minimum number of days a certificate has to be valid."));
891 printf (" %s\n", "-s, --ssl, --tls"); 1029 printf(" %s\n", "-s, --ssl, --tls");
892 printf (" %s\n", _("Use SSL/TLS for the connection.")); 1030 printf(" %s\n", _("Use SSL/TLS for the connection."));
893 printf (_(" Sets default port to %d.\n"), SMTPS_PORT); 1031 printf(_(" Sets default port to %d.\n"), SMTPS_PORT);
894 printf (" %s\n", "-S, --starttls"); 1032 printf(" %s\n", "-S, --starttls");
895 printf (" %s\n", _("Use STARTTLS for the connection.")); 1033 printf(" %s\n", _("Use STARTTLS for the connection."));
896 printf (" %s\n", "--sni"); 1034 printf(" %s\n", "--sni");
897 printf (" %s\n", _("Enable SSL/TLS hostname extension support (SNI)")); 1035 printf(" %s\n", _("Enable SSL/TLS hostname extension support (SNI)"));
898#endif 1036#endif
899 1037
900 printf (" %s\n", "-A, --authtype=STRING"); 1038 printf(" %s\n", "-A, --authtype=STRING");
901 printf (" %s\n", _("SMTP AUTH type to check (default none, only LOGIN supported)")); 1039 printf(" %s\n", _("SMTP AUTH type to check (default none, only LOGIN supported)"));
902 printf (" %s\n", "-U, --authuser=STRING"); 1040 printf(" %s\n", "-U, --authuser=STRING");
903 printf (" %s\n", _("SMTP AUTH username")); 1041 printf(" %s\n", _("SMTP AUTH username"));
904 printf (" %s\n", "-P, --authpass=STRING"); 1042 printf(" %s\n", "-P, --authpass=STRING");
905 printf (" %s\n", _("SMTP AUTH password")); 1043 printf(" %s\n", _("SMTP AUTH password"));
906 printf (" %s\n", "-L, --lmtp"); 1044 printf(" %s\n", "-L, --lmtp");
907 printf (" %s\n", _("Send LHLO instead of HELO/EHLO")); 1045 printf(" %s\n", _("Send LHLO instead of HELO/EHLO"));
908 printf (" %s\n", "-q, --ignore-quit-failure"); 1046 printf(" %s\n", "-q, --ignore-quit-failure");
909 printf (" %s\n", _("Ignore failure when sending QUIT command to server")); 1047 printf(" %s\n", _("Ignore failure when sending QUIT command to server"));
910 1048 printf(" %s\n", "--ignore-certificate-expiration");
911 printf (UT_WARN_CRIT); 1049 printf(" %s\n", _("Ignore certificate expiration"));
912
913 printf (UT_CONN_TIMEOUT, DEFAULT_SOCKET_TIMEOUT);
914 1050
915 printf (UT_VERBOSE); 1051 printf(UT_WARN_CRIT);
916 1052
917 printf("\n"); 1053 printf(UT_CONN_TIMEOUT, DEFAULT_SOCKET_TIMEOUT);
918 printf ("%s\n", _("Successful connects return STATE_OK, refusals and timeouts return"));
919 printf ("%s\n", _("STATE_CRITICAL, other errors return STATE_UNKNOWN. Successful"));
920 printf ("%s\n", _("connects, but incorrect response messages from the host result in"));
921 printf ("%s\n", _("STATE_WARNING return values."));
922 1054
923 printf (UT_SUPPORT); 1055 printf(UT_OUTPUT_FORMAT);
924}
925 1056
1057 printf(UT_VERBOSE);
926 1058
1059 printf("\n");
1060 printf("%s\n", _("Successful connects return STATE_OK, refusals and timeouts return"));
1061 printf("%s\n", _("STATE_CRITICAL, other errors return STATE_UNKNOWN. Successful"));
1062 printf("%s\n", _("connects, but incorrect response messages from the host result in"));
1063 printf("%s\n", _("STATE_WARNING return values."));
927 1064
928void 1065 printf(UT_SUPPORT);
929print_usage (void)
930{
931 printf ("%s\n", _("Usage:"));
932 printf ("%s -H host [-p port] [-4|-6] [-e expect] [-C command] [-R response] [-f from addr]\n", progname);
933 printf ("[-A authtype -U authuser -P authpass] [-w warn] [-c crit] [-t timeout] [-q]\n");
934 printf ("[-F fqdn] [-S] [-L] [-D warn days cert expire[,crit days cert expire]] [-r] [--sni] [-v] \n");
935} 1066}
936 1067
1068void print_usage(void) {
1069 printf("%s\n", _("Usage:"));
1070 printf("%s -H host [-p port] [-4|-6] [-e expect] [-C command] [-R response] [-f from addr]\n",
1071 progname);
1072 printf("[-A authtype -U authuser -P authpass] [-w warn] [-c crit] [-t timeout] [-q]\n");
1073 printf("[-F fqdn] [-S] [-L] [-D warn days cert expire[,crit days cert expire]] [-r] [--sni] "
1074 "[-v] \n");
1075}