2010-01-20 21:53:25 +01:00
|
|
|
#!/usr/bin/python
|
|
|
|
|
|
|
|
from ConfigParser import RawConfigParser
|
2013-04-15 15:10:00 +02:00
|
|
|
from email.mime.base import MIMEBase
|
2010-01-20 21:53:25 +01:00
|
|
|
import email
|
2013-04-14 13:13:52 +02:00
|
|
|
import email.message
|
2013-04-02 21:37:12 +02:00
|
|
|
import re
|
2010-01-20 21:53:25 +01:00
|
|
|
import GnuPG
|
|
|
|
import smtplib
|
|
|
|
import sys
|
2013-10-12 10:26:55 +02:00
|
|
|
import syslog
|
2010-01-20 21:53:25 +01:00
|
|
|
|
|
|
|
# Read configuration from /etc/gpg-mailgate.conf
|
|
|
|
_cfg = RawConfigParser()
|
|
|
|
_cfg.read('/etc/gpg-mailgate.conf')
|
|
|
|
cfg = dict()
|
|
|
|
for sect in _cfg.sections():
|
|
|
|
cfg[sect] = dict()
|
|
|
|
for (name, value) in _cfg.items(sect):
|
|
|
|
cfg[sect][name] = value
|
|
|
|
|
2013-10-12 10:26:55 +02:00
|
|
|
def log(msg):
|
|
|
|
if cfg.has_key('logging') and cfg['logging'].has_key('file'):
|
|
|
|
if cfg['logging']['file'] == "syslog":
|
|
|
|
syslog.syslog(syslog.LOG_INFO | syslog.LOG_MAIL, msg)
|
|
|
|
else:
|
|
|
|
logfile = open(cfg['logging']['file'], 'a')
|
|
|
|
logfile.write(msg + "\n")
|
|
|
|
logfile.close()
|
|
|
|
|
|
|
|
verbose=cfg.has_key('logging') and cfg['logging'].has_key('verbose') and cfg['logging']['verbose'] == 'yes'
|
|
|
|
|
2010-01-20 21:53:25 +01:00
|
|
|
# Read e-mail from stdin
|
|
|
|
raw = sys.stdin.read()
|
|
|
|
raw_message = email.message_from_string( raw )
|
|
|
|
from_addr = raw_message['From']
|
2013-08-09 08:41:06 +02:00
|
|
|
to_addrs = sys.argv[1:]
|
2010-01-20 21:53:25 +01:00
|
|
|
|
|
|
|
def send_msg( message, recipients = None ):
|
|
|
|
if recipients == None:
|
2013-08-09 08:35:57 +02:00
|
|
|
recipients = to_addrs
|
2013-10-12 10:26:55 +02:00
|
|
|
log("Sending email to: <%s>" % '> <'.join( recipients ))
|
2010-01-20 21:53:25 +01:00
|
|
|
relay = (cfg['relay']['host'], int(cfg['relay']['port']))
|
|
|
|
smtp = smtplib.SMTP(relay[0], relay[1])
|
|
|
|
smtp.sendmail( from_addr, recipients, message.as_string() )
|
|
|
|
|
2013-04-03 16:32:38 +02:00
|
|
|
def encrypt_payload( payload, gpg_to_cmdline ):
|
2013-08-11 14:35:48 +02:00
|
|
|
gpg = GnuPG.GPGEncryptor( cfg['gpg']['keyhome'], gpg_to_cmdline, payload.get_content_charset() )
|
2013-04-03 16:32:38 +02:00
|
|
|
raw_payload = payload.get_payload(decode=True)
|
2013-09-22 21:14:09 +02:00
|
|
|
if ("-----BEGIN PGP MESSAGE-----" in raw_payload and "-----END PGP MESSAGE-----" in raw_payload) or ("-----BEGIN PGP SIGNED MESSAGE-----" in raw_payload):
|
2013-06-19 03:46:41 +02:00
|
|
|
return payload
|
2013-08-11 14:35:48 +02:00
|
|
|
gpg = GnuPG.GPGEncryptor( cfg['gpg']['keyhome'], gpg_to_cmdline, payload.get_content_charset() )
|
2013-09-16 19:26:45 +02:00
|
|
|
gpg.update( raw_payload )
|
2013-06-19 03:46:41 +02:00
|
|
|
if "-----BEGIN PGP MESSAGE-----" in raw_payload and "-----END PGP MESSAGE-----" in raw_payload:
|
|
|
|
return payload
|
2013-04-03 16:32:38 +02:00
|
|
|
payload.set_payload( gpg.encrypt() )
|
2013-08-11 14:35:48 +02:00
|
|
|
|
|
|
|
isAttachment = payload.get_param( 'attachment', None, 'Content-Disposition' ) is not None
|
|
|
|
|
|
|
|
if isAttachment:
|
|
|
|
filename = payload.get_filename()
|
|
|
|
|
|
|
|
if filename:
|
|
|
|
pgpFilename = filename + ".pgp"
|
|
|
|
|
|
|
|
if payload.get('Content-Disposition') is not None:
|
|
|
|
payload.set_param( 'filename', pgpFilename, 'Content-Disposition' )
|
|
|
|
if payload.get('Content-Type') is not None:
|
|
|
|
if payload.get_param( 'name' ) is not None:
|
|
|
|
payload.set_param( 'name', pgpFilename )
|
|
|
|
|
|
|
|
if payload.get('Content-Transfer-Encoding') is not None:
|
2013-08-11 17:17:46 +02:00
|
|
|
payload.replace_header( 'Content-Transfer-Encoding', "quoted-printable" )
|
2013-08-11 14:35:48 +02:00
|
|
|
|
2013-04-03 16:32:38 +02:00
|
|
|
return payload
|
|
|
|
|
2013-08-11 14:35:48 +02:00
|
|
|
def encrypt_all_payloads( message, gpg_to_cmdline ):
|
2013-04-04 20:07:32 +02:00
|
|
|
encrypted_payloads = list()
|
2013-08-11 14:35:48 +02:00
|
|
|
if type( message.get_payload() ) == str:
|
|
|
|
return encrypt_payload( message, gpg_to_cmdline ).get_payload()
|
|
|
|
for payload in message.get_payload():
|
2013-04-04 20:07:32 +02:00
|
|
|
if( type( payload.get_payload() ) == list ):
|
2013-08-12 04:20:12 +02:00
|
|
|
encrypted_payloads.extend( encrypt_all_payloads( payload, gpg_to_cmdline ) )
|
2013-04-04 20:07:32 +02:00
|
|
|
else:
|
2013-08-11 17:06:27 +02:00
|
|
|
encrypted_payloads.append( encrypt_payload( payload, gpg_to_cmdline ) )
|
|
|
|
return encrypted_payloads
|
2013-04-04 20:07:32 +02:00
|
|
|
|
2010-01-21 15:50:51 +01:00
|
|
|
def get_msg( message ):
|
|
|
|
if not message.is_multipart():
|
|
|
|
return message.get_payload()
|
2013-04-02 21:30:53 +02:00
|
|
|
return '\n\n'.join( [str(m) for m in message.get_payload()] )
|
2010-01-21 15:50:51 +01:00
|
|
|
|
2013-04-14 12:18:14 +02:00
|
|
|
keys = GnuPG.public_keys( cfg['gpg']['keyhome'] )
|
2010-01-20 21:53:25 +01:00
|
|
|
gpg_to = list()
|
2010-01-20 22:09:34 +01:00
|
|
|
ungpg_to = list()
|
2013-09-22 21:13:15 +02:00
|
|
|
|
|
|
|
for enc in encrypted_to_addrs:
|
|
|
|
if enc in keys:
|
|
|
|
gpg_to.append( (enc, enc) )
|
|
|
|
elif cfg.has_key('keymap') and cfg['keymap'].has_key(enc):
|
|
|
|
gpg_to.append( (enc, cfg['keymap'][enc]) )
|
|
|
|
else:
|
|
|
|
ungpg_to.append(enc)
|
|
|
|
|
2010-01-20 21:53:25 +01:00
|
|
|
for to in to_addrs:
|
2013-09-22 21:13:15 +02:00
|
|
|
if to in keys:
|
|
|
|
gpg_to.append( (to, to) )
|
|
|
|
elif cfg.has_key('keymap') and cfg['keymap'].has_key(to):
|
|
|
|
gpg_to.append( (to, cfg['keymap'][to]) )
|
2010-01-20 22:09:34 +01:00
|
|
|
else:
|
2013-10-12 10:26:55 +02:00
|
|
|
if verbose:
|
|
|
|
log("Recipient (%s) not in domain list." % to)
|
2010-01-20 22:09:34 +01:00
|
|
|
ungpg_to.append(to)
|
2010-01-20 21:53:25 +01:00
|
|
|
|
|
|
|
if gpg_to == list():
|
|
|
|
if cfg['default'].has_key('add_header') and cfg['default']['add_header'] == 'yes':
|
|
|
|
raw_message['X-GPG-Mailgate'] = 'Not encrypted, public key not found'
|
2013-10-12 10:26:55 +02:00
|
|
|
if verbose:
|
|
|
|
log("No encrypted recipients.")
|
2010-01-20 21:53:25 +01:00
|
|
|
send_msg( raw_message )
|
2013-04-02 21:37:12 +02:00
|
|
|
exit()
|
2010-01-20 21:53:25 +01:00
|
|
|
|
2010-01-20 22:09:34 +01:00
|
|
|
if ungpg_to != list():
|
|
|
|
send_msg( raw_message, ungpg_to )
|
|
|
|
|
2013-10-12 10:26:55 +02:00
|
|
|
log("Encrypting email to: %s" % ' '.join( map(lambda x: x[0], gpg_to) ))
|
2010-01-21 15:50:51 +01:00
|
|
|
|
2010-01-20 21:53:25 +01:00
|
|
|
if cfg['default'].has_key('add_header') and cfg['default']['add_header'] == 'yes':
|
2010-01-21 15:50:51 +01:00
|
|
|
raw_message['X-GPG-Mailgate'] = 'Encrypted by GPG Mailgate'
|
2010-01-20 21:53:25 +01:00
|
|
|
|
2010-01-20 22:09:34 +01:00
|
|
|
gpg_to_cmdline = list()
|
|
|
|
gpg_to_smtp = list()
|
|
|
|
for rcpt in gpg_to:
|
|
|
|
gpg_to_smtp.append(rcpt[0])
|
|
|
|
gpg_to_cmdline.extend(rcpt[1].split(','))
|
|
|
|
|
2013-08-11 14:35:48 +02:00
|
|
|
encrypted_payloads = encrypt_all_payloads( raw_message, gpg_to_cmdline )
|
2013-04-03 16:32:38 +02:00
|
|
|
raw_message.set_payload( encrypted_payloads )
|
|
|
|
|
2010-01-20 22:09:34 +01:00
|
|
|
send_msg( raw_message, gpg_to_smtp )
|