DnsHelper.php 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309
  1. <?php
  2. namespace ThurData\Servers\KerioEmail\Core\Helper;
  3. use ThurData\Servers\KerioEmail\Core\Models\Whmcs\Server;
  4. use ThurData\Servers\KerioEmail\Api\KerioWhmcs;
  5. use \WHMCS\Database\Capsule;
  6. require_once '/usr/share/php/Net/DNS2.php';
  7. use \Net\DNS2\Net_DNS2_Resolver as Net_DNS2_Resolver;
  8. /**
  9. * Wrapper for WHMCS params passed to controler functions
  10. *
  11. * @autor ThurData <info@thurdata.ch>
  12. */
  13. class DnsHelper
  14. {
  15. use \ThurData\Servers\KerioEmail\Core\UI\Traits\WhmcsParams;
  16. public function __construct()
  17. {
  18. $this->params = $this->getWhmcsParamsByKeys(['domain', 'userid', 'serverhostname', 'serverusername', 'serverpassword', 'domainid', 'serverid', 'pid']);
  19. $this->server = Server::select('id', 'nameserver1ip', 'nameserver2ip')->findOrFail($this->params['serverid']);
  20. // $this->nameserver = array(trim($this->server->nameserver1ip), trim($this->server->nameserver2ip));
  21. $this->nameserver = array('127.0.0.1', '127.0.0.2'); //test
  22. $this->clientDomains = localAPI('GetClientsDomains', array('clientid' => $this->params['userid']));
  23. $api = new KerioWhmcs('whmcsKerioEmail', 'Thurdata', '1.0');
  24. try {
  25. $api->login($this->params['serverhostname'], $this->params['serverusername'], $this->params['serverpassword']);
  26. } catch (KerioApiException $error) {
  27. logModuleCall(
  28. 'kerioEmail',
  29. __FUNCTION__,
  30. $this->params,
  31. 'Error: cannot login to ' . $this->params['kerioServer'],
  32. $error->getMessage()
  33. );
  34. }
  35. $dkimSet = $api->getDkimDnsRecord($this->params['domain']);
  36. $dkimArray = explode(PHP_EOL,$dkimSet['detail']);
  37. $dkimValue = explode(":",$dkimArray[1]);
  38. $this->domainKey = ltrim($dkimValue[1]);
  39. $dkimName = explode(":",$dkimArray[0]);
  40. $this->dkimName = ltrim($dkimName[1]);
  41. }
  42. public function KerioEmailCheckDNS()
  43. {
  44. $vars['maildomain'] = $this->params['domain'];
  45. $vars['dmarcconfig'] = $this->dmarcConfig;
  46. $vars['spfconfig'] = $this->spfConfig;
  47. $vars['domainkey'] = $this->domainKey;
  48. $vars['dkimname'] = $this->dkimName;
  49. if($this->clientDomains['totalresults'] == 0){
  50. $vars['selfdomain'] = FALSE;
  51. $vars['dmarcconfig'] = $this->dmarcConfig;
  52. $vars['spfconfig'] = $this->spfConfig;
  53. $vars['correctable'] = FALSE;
  54. return $vars;
  55. } else {
  56. $vars['selfdomain'] = TRUE;
  57. }
  58. $resolver = new \Net_DNS2_Resolver(array('nameservers' => $this->nameserver));
  59. try {
  60. $result = $resolver->query($this->params['domain'], 'MX');
  61. } catch(\Net_DNS2_Exception $e) {
  62. echo "::query() failed: ", $e->getMessage(), "\n";
  63. }
  64. $domainMX = $result->answer;
  65. try {
  66. $result = $resolver->query($this->params['domain'], 'TXT');
  67. } catch(\Net_DNS2_Exception $e) {
  68. echo "::query() failed: ", $e->getMessage(), "\n";
  69. }
  70. $domainTXT = $result->answer;
  71. $domainSPF = array();
  72. $domainDKIM = array();
  73. $domainDMARC = array();
  74. foreach($domainTXT as $txtRecord) {
  75. foreach($txtRecord->text as $txtData) {
  76. if(strstr($txtData,'v=spf')) {
  77. array_push($domainSPF,$txtData);
  78. }
  79. if(strstr($txtData,'v=DKIM')) {
  80. array_push($domainDKIM,$txtData);
  81. }
  82. if(strstr($txtData,'v=DMARC')) {
  83. array_push($domainDMARC,$txtData);
  84. }
  85. }
  86. }
  87. # self hosted DNS
  88. $vars['selfDNS'] = FALSE;
  89. for($i=$this->clientDomains['startnumber'];$i<=$this->clientDomains['numreturned'];$i++) {
  90. if($this->params['domain'] == $this->clientDomains['domains']['domain'][$i]['domainname']) {
  91. $vars['selfDNS'] = TRUE;
  92. $vars['domainId'] = $this->clientDomains['domains']['domain'][$i]['id'];
  93. }
  94. }
  95. # SPF, multi verboten
  96. if (count($domainSPF) > 1) {
  97. $vars['multiSPF'] = TRUE;
  98. $vars['spf'] = 'wrong';
  99. } else {
  100. $vars['multiSPF'] = FALSE;
  101. if (empty($domainSPF)) {
  102. $vars['spf'] = 'unset';
  103. } else {
  104. if($domainSPF[0] === $spfConfig) {
  105. $vars['spf'] = 'set';
  106. } else {
  107. $vars['spf'] = 'wrong';
  108. }
  109. }
  110. }
  111. # DKIM
  112. if (count($domainDKIM) > 1) {
  113. $vars['multiDKIM'] = TRUE;
  114. } else {
  115. $vars['multiDKIM'] = FALSE;
  116. }
  117. if (empty($domainDKIM)) {
  118. $vars['dkim'] = 'unset';
  119. } else {
  120. $vars['dkim'] = 'set';
  121. }
  122. $vars['domainDKIM'] = $domainDKIM;
  123. # DMARC
  124. if (count($domainDMARC) > 1) {
  125. $vars['multiDMARC'] = TRUE;
  126. } else {
  127. $vars['multiDMARC'] = FALSE;
  128. }
  129. $vars['dmarc'] = 'wrong';
  130. if (empty($domainDMARC)) {
  131. $vars['dmarc'] = 'unset';
  132. } else {
  133. foreach($domainDMARC as $dmarc) {
  134. if($dmarc === $dmarcConfig) {
  135. $vars['dmarc'] = 'set';
  136. }
  137. }
  138. }
  139. $vars['domainDMARC'] = $domainDMARC;
  140. # MX
  141. if(count($domainMX) > 1) {
  142. $vars['multiMX'] = TRUE;
  143. } else {
  144. $vars['multiMX'] = FALSE;
  145. }
  146. if(empty($domainMX)){
  147. $vars['mx'] = 'unset';
  148. $vars['mxtarget'] = $this->params['serverhostname'];
  149. } else {
  150. $vars['domainMX'] = $domainMX;
  151. $domainMXrecord = array_shift($domainMX);
  152. $vars['mxtarget'] = $domainMXrecord->exchange;
  153. if($domainMXrecord->exchange == $this->params['serverhostname']) {
  154. $vars['mx'] = 'set';
  155. } else {
  156. $var['mx'] = 'wrong';
  157. }
  158. }
  159. // summary
  160. if($vars['mx'] == 'set' && $vars['dmarc'] == 'set' && $vars['dkim'] == 'set' && $vars['spf'] == 'set') {
  161. $vars['dnscheck'] = TRUE;
  162. } else {
  163. $vars['dnscheck'] = FALSE;
  164. $vars['correctable'] = TRUE;
  165. }
  166. return $vars;
  167. }
  168. function KerioEmailsetDNS()
  169. {
  170. return 'success';
  171. $zoneIDcollection = Capsule::table('dns_manager2_zone')
  172. ->select('id')
  173. ->where('name', '=', $this->params['domain'])
  174. ->get();
  175. $zoneIDobj = $zoneIDcollection[0];
  176. $zoneID = $zoneIDobj->{'id'};
  177. if(!isset($zoneID)) {
  178. return 'Error: zone ID not found for domain ' . $this->params['domain'];
  179. }
  180. $dnsZone = localAPI('dnsmanager', array( 'dnsaction' => 'getZone', 'zone_id' => $zoneID));
  181. logModuleCall(
  182. 'kerioEmail',
  183. __FUNCTION__,
  184. $this->params,
  185. 'DEbug',
  186. $dnsZone['result']
  187. );
  188. if($dnsZone['result'] != 'success') {
  189. return 'Error: cloud not fetch zone for ID ' . $zoneID;
  190. }
  191. $zoneRecords = array();
  192. $mxRecord = array(
  193. 'line' => $this->params['domain'].'.|MX|0',
  194. 'name' => '@',
  195. 'type' => 'MX',
  196. 'class' => 'IN',
  197. 'data' => array(
  198. 'preference' => '10',
  199. 'exchange' => $this->params['serverhostname'],
  200. ),
  201. );
  202. array_push($zoneRecords, $mxRecord);
  203. $spfRecord = array(
  204. 'line' => $this->params['domain'].'.|TXT|0',
  205. 'name' => '@',
  206. 'type' => 'TXT',
  207. 'class' => 'IN',
  208. 'data' => $this->spfConfig
  209. );
  210. array_push($zoneRecords, $spfRecord);
  211. $dmarcRecord = array(
  212. 'line' => $this->params['domain'].'.|TXT|0',
  213. 'name' => '@',
  214. 'type' => 'TXT',
  215. 'class' => 'IN',
  216. 'data' => $this->dmarcConfig
  217. );
  218. array_push($zoneRecords, $dmarcRecord);
  219. foreach($dnsZone['data']->records as $record) {
  220. if($record->type == 'MX') continue;
  221. if(!$record->type === 'TXT') {
  222. // skip dmarc
  223. if(preg_match('/^v=DMARC1(.*)$/i', trim($record->rdata->txtdata,'"'))) continue;
  224. // skip spf
  225. if(preg_match('/^v=spf(.*)$/i', trim($record->rdata->txtdata,'"'))) continue;
  226. // skip own dkim
  227. if(($this->dkimName == $record->name) && ($this->domainKey == trim($record->rdata->txtdata,'"'))) continue;
  228. };
  229. array_push($zoneRecords, $record);
  230. }
  231. logModuleCall(
  232. 'kerioEmail',
  233. __FUNCTION__,
  234. $this->params,
  235. 'DEbug',
  236. $zoneRecords
  237. );
  238. /* $result = localAPI('dnsmanager' ,
  239. array(
  240. 'dnsaction' => 'updateZone',
  241. 'zone_id' => $zoneID,
  242. 'records' => $zoneRecords,
  243. )
  244. );
  245. if($result['result'] != 'success') {
  246. return 'Error: cloud not update zone for ID ' . $zoneID;
  247. } */
  248. return 'success';
  249. }
  250. function KerioEmailunsetMX()
  251. {
  252. $zoneIDcollection = Capsule::table('dns_manager2_zone')
  253. ->select('id')
  254. ->where('name', '=', $this->params['domain'])
  255. ->get();
  256. $zoneIDobj = $zoneIDcollection[0];
  257. $zoneID = $zoneIDobj->{'id'};
  258. if(!isset($zoneID)) {
  259. return 'Error: zone ID not found for domain ' . $this->params['domain'];
  260. }
  261. $dnsZone = localAPI('dnsmanager', array( 'dnsaction' => 'getZone', 'zone_id' => $zoneID));
  262. if($dnsZone['result'] != 'success') {
  263. return 'Error: cloud not fetch zone for ID ' . $zoneID;
  264. }
  265. $zoneRecords = array();
  266. foreach($dnsZone['data']->records as $record) {
  267. if($record->type == 'MX') continue;
  268. array_push($zoneRecords, $record);
  269. }
  270. logModuleCall(
  271. 'kerioEmail',
  272. __FUNCTION__,
  273. $this->params,
  274. 'DEbug',
  275. $zoneRecords
  276. );
  277. /* $result = localAPI('dnsmanager' ,
  278. array(
  279. 'dnsaction' => 'updateZone',
  280. 'zone_id' => $zoneID,
  281. 'records' => $zoneRecords,
  282. )
  283. );
  284. if($result['result'] != 'success') {
  285. return 'Error: cloud not update zone for ID ' . $zoneID;
  286. } */
  287. return 'success';
  288. }
  289. }