annotate src/lib-ssl-iostream/iostream-ssl.h @ 16161:ef939a32de27

lib-ssl-iostream: Simplified certificate validation. Also give better error messages.
author Timo Sirainen <tss@iki.fi>
date Thu, 04 Apr 2013 18:10:04 +0300
parents f4bac0352464
children f0c997709b4d
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
12616
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
1 #ifndef IOSTREAM_SSL_H
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
2 #define IOSTREAM_SSL_H
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
3
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
4 struct ssl_iostream;
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
5 struct ssl_iostream_context;
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
6
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
7 struct ssl_iostream_settings {
14723
69626d2ce3f0 lib-ssl-iostream: Added protocols setting.
Timo Sirainen <tss@iki.fi>
parents: 14720
diff changeset
8 const char *protocols;
12616
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
9 const char *cipher_list;
14723
69626d2ce3f0 lib-ssl-iostream: Added protocols setting.
Timo Sirainen <tss@iki.fi>
parents: 14720
diff changeset
10 const char *ca, *ca_dir; /* context-only */
12616
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
11 const char *cert;
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
12 const char *key;
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
13 const char *key_password;
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
14 const char *cert_username_field;
14723
69626d2ce3f0 lib-ssl-iostream: Added protocols setting.
Timo Sirainen <tss@iki.fi>
parents: 14720
diff changeset
15 const char *crypto_device; /* context-only */
12616
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
16
14723
69626d2ce3f0 lib-ssl-iostream: Added protocols setting.
Timo Sirainen <tss@iki.fi>
parents: 14720
diff changeset
17 bool verbose, verbose_invalid_cert; /* stream-only */
69626d2ce3f0 lib-ssl-iostream: Added protocols setting.
Timo Sirainen <tss@iki.fi>
parents: 14720
diff changeset
18 bool verify_remote_cert; /* neither/both */
69626d2ce3f0 lib-ssl-iostream: Added protocols setting.
Timo Sirainen <tss@iki.fi>
parents: 14720
diff changeset
19 bool require_valid_cert; /* stream-only */
12616
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
20 };
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
21
16154
970914436288 lib-ssl-iostream: ssl_iostream_set_handshake_callback() API changed.
Timo Sirainen <tss@iki.fi>
parents: 16145
diff changeset
22 /* Returns 0 if ok, -1 and sets error_r if failed. The returned error string
970914436288 lib-ssl-iostream: ssl_iostream_set_handshake_callback() API changed.
Timo Sirainen <tss@iki.fi>
parents: 16145
diff changeset
23 becomes available via ssl_iostream_get_last_error() */
970914436288 lib-ssl-iostream: ssl_iostream_set_handshake_callback() API changed.
Timo Sirainen <tss@iki.fi>
parents: 16145
diff changeset
24 typedef int
970914436288 lib-ssl-iostream: ssl_iostream_set_handshake_callback() API changed.
Timo Sirainen <tss@iki.fi>
parents: 16145
diff changeset
25 ssl_iostream_handshake_callback_t(const char **error_r, void *context);
970914436288 lib-ssl-iostream: ssl_iostream_set_handshake_callback() API changed.
Timo Sirainen <tss@iki.fi>
parents: 16145
diff changeset
26
16159
f4bac0352464 lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents: 16154
diff changeset
27 int io_stream_create_ssl_client(struct ssl_iostream_context *ctx, const char *host,
f4bac0352464 lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents: 16154
diff changeset
28 const struct ssl_iostream_settings *set,
f4bac0352464 lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents: 16154
diff changeset
29 struct istream **input, struct ostream **output,
f4bac0352464 lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents: 16154
diff changeset
30 struct ssl_iostream **iostream_r,
f4bac0352464 lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents: 16154
diff changeset
31 const char **error_r);
f4bac0352464 lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents: 16154
diff changeset
32 int io_stream_create_ssl_server(struct ssl_iostream_context *ctx,
f4bac0352464 lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents: 16154
diff changeset
33 const struct ssl_iostream_settings *set,
f4bac0352464 lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents: 16154
diff changeset
34 struct istream **input, struct ostream **output,
f4bac0352464 lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents: 16154
diff changeset
35 struct ssl_iostream **iostream_r,
f4bac0352464 lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents: 16154
diff changeset
36 const char **error_r);
12616
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
37 /* returned input and output streams must also be unreferenced */
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
38 void ssl_iostream_unref(struct ssl_iostream **ssl_io);
14720
ff479f84022f lib-ssl-iostream: Added ssl_iostream_destroy() to do a clean SSL shutdown.
Timo Sirainen <tss@iki.fi>
parents: 13774
diff changeset
39 /* shutdown SSL connection and unreference ssl iostream */
ff479f84022f lib-ssl-iostream: Added ssl_iostream_destroy() to do a clean SSL shutdown.
Timo Sirainen <tss@iki.fi>
parents: 13774
diff changeset
40 void ssl_iostream_destroy(struct ssl_iostream **ssl_io);
12616
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
41
16159
f4bac0352464 lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents: 16154
diff changeset
42 /* If verbose logging is enabled, use the specified log prefix */
f4bac0352464 lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents: 16154
diff changeset
43 void ssl_iostream_set_log_prefix(struct ssl_iostream *ssl_io,
f4bac0352464 lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents: 16154
diff changeset
44 const char *prefix);
f4bac0352464 lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents: 16154
diff changeset
45
12616
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
46 int ssl_iostream_handshake(struct ssl_iostream *ssl_io);
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
47 void ssl_iostream_set_handshake_callback(struct ssl_iostream *ssl_io,
16154
970914436288 lib-ssl-iostream: ssl_iostream_set_handshake_callback() API changed.
Timo Sirainen <tss@iki.fi>
parents: 16145
diff changeset
48 ssl_iostream_handshake_callback_t *callback,
12616
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
49 void *context);
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
50
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
51 bool ssl_iostream_is_handshaked(const struct ssl_iostream *ssl_io);
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
52 bool ssl_iostream_has_valid_client_cert(const struct ssl_iostream *ssl_io);
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
53 bool ssl_iostream_has_broken_client_cert(struct ssl_iostream *ssl_io);
16161
ef939a32de27 lib-ssl-iostream: Simplified certificate validation. Also give better error messages.
Timo Sirainen <tss@iki.fi>
parents: 16159
diff changeset
54 int ssl_iostream_check_cert_validity(struct ssl_iostream *ssl_io,
ef939a32de27 lib-ssl-iostream: Simplified certificate validation. Also give better error messages.
Timo Sirainen <tss@iki.fi>
parents: 16159
diff changeset
55 const char *host, const char **error_r);
13404
c3dc563c9800 lib-ssl-iostream: Added ssl_iostream_cert_match_name()
Timo Sirainen <tss@iki.fi>
parents: 12616
diff changeset
56 int ssl_iostream_cert_match_name(struct ssl_iostream *ssl_io, const char *name);
12616
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
57 const char *ssl_iostream_get_peer_name(struct ssl_iostream *ssl_io);
16159
f4bac0352464 lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents: 16154
diff changeset
58 const char *ssl_iostream_get_server_name(struct ssl_iostream *ssl_io);
12616
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
59 const char *ssl_iostream_get_security_string(struct ssl_iostream *ssl_io);
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
60 const char *ssl_iostream_get_last_error(struct ssl_iostream *ssl_io);
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
61
16145
02f6b66458b1 lib-ssl-iostream: API changes to return error strings if init() functions fail.
Timo Sirainen <tss@iki.fi>
parents: 14723
diff changeset
62 int ssl_iostream_generate_params(buffer_t *output, const char **error_r);
12616
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
63 int ssl_iostream_context_import_params(struct ssl_iostream_context *ctx,
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
64 const buffer_t *input);
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
65
16145
02f6b66458b1 lib-ssl-iostream: API changes to return error strings if init() functions fail.
Timo Sirainen <tss@iki.fi>
parents: 14723
diff changeset
66 int ssl_iostream_context_init_client(const struct ssl_iostream_settings *set,
02f6b66458b1 lib-ssl-iostream: API changes to return error strings if init() functions fail.
Timo Sirainen <tss@iki.fi>
parents: 14723
diff changeset
67 struct ssl_iostream_context **ctx_r,
02f6b66458b1 lib-ssl-iostream: API changes to return error strings if init() functions fail.
Timo Sirainen <tss@iki.fi>
parents: 14723
diff changeset
68 const char **error_r);
02f6b66458b1 lib-ssl-iostream: API changes to return error strings if init() functions fail.
Timo Sirainen <tss@iki.fi>
parents: 14723
diff changeset
69 int ssl_iostream_context_init_server(const struct ssl_iostream_settings *set,
02f6b66458b1 lib-ssl-iostream: API changes to return error strings if init() functions fail.
Timo Sirainen <tss@iki.fi>
parents: 14723
diff changeset
70 struct ssl_iostream_context **ctx_r,
02f6b66458b1 lib-ssl-iostream: API changes to return error strings if init() functions fail.
Timo Sirainen <tss@iki.fi>
parents: 14723
diff changeset
71 const char **error_r);
12616
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
72 void ssl_iostream_context_deinit(struct ssl_iostream_context **ctx);
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
73
bd23d4e10fa1 Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
74 #endif