Mercurial > dovecot > core-2.2
annotate src/lib-ssl-iostream/iostream-ssl.h @ 16161:ef939a32de27
lib-ssl-iostream: Simplified certificate validation. Also give better error messages.
author | Timo Sirainen <tss@iki.fi> |
---|---|
date | Thu, 04 Apr 2013 18:10:04 +0300 |
parents | f4bac0352464 |
children | f0c997709b4d |
rev | line source |
---|---|
12616
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
1 #ifndef IOSTREAM_SSL_H |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
2 #define IOSTREAM_SSL_H |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
3 |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
4 struct ssl_iostream; |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
5 struct ssl_iostream_context; |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
6 |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
7 struct ssl_iostream_settings { |
14723
69626d2ce3f0
lib-ssl-iostream: Added protocols setting.
Timo Sirainen <tss@iki.fi>
parents:
14720
diff
changeset
|
8 const char *protocols; |
12616
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
9 const char *cipher_list; |
14723
69626d2ce3f0
lib-ssl-iostream: Added protocols setting.
Timo Sirainen <tss@iki.fi>
parents:
14720
diff
changeset
|
10 const char *ca, *ca_dir; /* context-only */ |
12616
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
11 const char *cert; |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
12 const char *key; |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
13 const char *key_password; |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
14 const char *cert_username_field; |
14723
69626d2ce3f0
lib-ssl-iostream: Added protocols setting.
Timo Sirainen <tss@iki.fi>
parents:
14720
diff
changeset
|
15 const char *crypto_device; /* context-only */ |
12616
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
16 |
14723
69626d2ce3f0
lib-ssl-iostream: Added protocols setting.
Timo Sirainen <tss@iki.fi>
parents:
14720
diff
changeset
|
17 bool verbose, verbose_invalid_cert; /* stream-only */ |
69626d2ce3f0
lib-ssl-iostream: Added protocols setting.
Timo Sirainen <tss@iki.fi>
parents:
14720
diff
changeset
|
18 bool verify_remote_cert; /* neither/both */ |
69626d2ce3f0
lib-ssl-iostream: Added protocols setting.
Timo Sirainen <tss@iki.fi>
parents:
14720
diff
changeset
|
19 bool require_valid_cert; /* stream-only */ |
12616
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
20 }; |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
21 |
16154
970914436288
lib-ssl-iostream: ssl_iostream_set_handshake_callback() API changed.
Timo Sirainen <tss@iki.fi>
parents:
16145
diff
changeset
|
22 /* Returns 0 if ok, -1 and sets error_r if failed. The returned error string |
970914436288
lib-ssl-iostream: ssl_iostream_set_handshake_callback() API changed.
Timo Sirainen <tss@iki.fi>
parents:
16145
diff
changeset
|
23 becomes available via ssl_iostream_get_last_error() */ |
970914436288
lib-ssl-iostream: ssl_iostream_set_handshake_callback() API changed.
Timo Sirainen <tss@iki.fi>
parents:
16145
diff
changeset
|
24 typedef int |
970914436288
lib-ssl-iostream: ssl_iostream_set_handshake_callback() API changed.
Timo Sirainen <tss@iki.fi>
parents:
16145
diff
changeset
|
25 ssl_iostream_handshake_callback_t(const char **error_r, void *context); |
970914436288
lib-ssl-iostream: ssl_iostream_set_handshake_callback() API changed.
Timo Sirainen <tss@iki.fi>
parents:
16145
diff
changeset
|
26 |
16159
f4bac0352464
lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents:
16154
diff
changeset
|
27 int io_stream_create_ssl_client(struct ssl_iostream_context *ctx, const char *host, |
f4bac0352464
lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents:
16154
diff
changeset
|
28 const struct ssl_iostream_settings *set, |
f4bac0352464
lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents:
16154
diff
changeset
|
29 struct istream **input, struct ostream **output, |
f4bac0352464
lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents:
16154
diff
changeset
|
30 struct ssl_iostream **iostream_r, |
f4bac0352464
lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents:
16154
diff
changeset
|
31 const char **error_r); |
f4bac0352464
lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents:
16154
diff
changeset
|
32 int io_stream_create_ssl_server(struct ssl_iostream_context *ctx, |
f4bac0352464
lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents:
16154
diff
changeset
|
33 const struct ssl_iostream_settings *set, |
f4bac0352464
lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents:
16154
diff
changeset
|
34 struct istream **input, struct ostream **output, |
f4bac0352464
lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents:
16154
diff
changeset
|
35 struct ssl_iostream **iostream_r, |
f4bac0352464
lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents:
16154
diff
changeset
|
36 const char **error_r); |
12616
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
37 /* returned input and output streams must also be unreferenced */ |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
38 void ssl_iostream_unref(struct ssl_iostream **ssl_io); |
14720
ff479f84022f
lib-ssl-iostream: Added ssl_iostream_destroy() to do a clean SSL shutdown.
Timo Sirainen <tss@iki.fi>
parents:
13774
diff
changeset
|
39 /* shutdown SSL connection and unreference ssl iostream */ |
ff479f84022f
lib-ssl-iostream: Added ssl_iostream_destroy() to do a clean SSL shutdown.
Timo Sirainen <tss@iki.fi>
parents:
13774
diff
changeset
|
40 void ssl_iostream_destroy(struct ssl_iostream **ssl_io); |
12616
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
41 |
16159
f4bac0352464
lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents:
16154
diff
changeset
|
42 /* If verbose logging is enabled, use the specified log prefix */ |
f4bac0352464
lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents:
16154
diff
changeset
|
43 void ssl_iostream_set_log_prefix(struct ssl_iostream *ssl_io, |
f4bac0352464
lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents:
16154
diff
changeset
|
44 const char *prefix); |
f4bac0352464
lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents:
16154
diff
changeset
|
45 |
12616
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
46 int ssl_iostream_handshake(struct ssl_iostream *ssl_io); |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
47 void ssl_iostream_set_handshake_callback(struct ssl_iostream *ssl_io, |
16154
970914436288
lib-ssl-iostream: ssl_iostream_set_handshake_callback() API changed.
Timo Sirainen <tss@iki.fi>
parents:
16145
diff
changeset
|
48 ssl_iostream_handshake_callback_t *callback, |
12616
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
49 void *context); |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
50 |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
51 bool ssl_iostream_is_handshaked(const struct ssl_iostream *ssl_io); |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
52 bool ssl_iostream_has_valid_client_cert(const struct ssl_iostream *ssl_io); |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
53 bool ssl_iostream_has_broken_client_cert(struct ssl_iostream *ssl_io); |
16161
ef939a32de27
lib-ssl-iostream: Simplified certificate validation. Also give better error messages.
Timo Sirainen <tss@iki.fi>
parents:
16159
diff
changeset
|
54 int ssl_iostream_check_cert_validity(struct ssl_iostream *ssl_io, |
ef939a32de27
lib-ssl-iostream: Simplified certificate validation. Also give better error messages.
Timo Sirainen <tss@iki.fi>
parents:
16159
diff
changeset
|
55 const char *host, const char **error_r); |
13404
c3dc563c9800
lib-ssl-iostream: Added ssl_iostream_cert_match_name()
Timo Sirainen <tss@iki.fi>
parents:
12616
diff
changeset
|
56 int ssl_iostream_cert_match_name(struct ssl_iostream *ssl_io, const char *name); |
12616
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
57 const char *ssl_iostream_get_peer_name(struct ssl_iostream *ssl_io); |
16159
f4bac0352464
lib-ssl-iostream: Added support for TLS SNI, which caused some API changes.
Timo Sirainen <tss@iki.fi>
parents:
16154
diff
changeset
|
58 const char *ssl_iostream_get_server_name(struct ssl_iostream *ssl_io); |
12616
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
59 const char *ssl_iostream_get_security_string(struct ssl_iostream *ssl_io); |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
60 const char *ssl_iostream_get_last_error(struct ssl_iostream *ssl_io); |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
61 |
16145
02f6b66458b1
lib-ssl-iostream: API changes to return error strings if init() functions fail.
Timo Sirainen <tss@iki.fi>
parents:
14723
diff
changeset
|
62 int ssl_iostream_generate_params(buffer_t *output, const char **error_r); |
12616
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
63 int ssl_iostream_context_import_params(struct ssl_iostream_context *ctx, |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
64 const buffer_t *input); |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
65 |
16145
02f6b66458b1
lib-ssl-iostream: API changes to return error strings if init() functions fail.
Timo Sirainen <tss@iki.fi>
parents:
14723
diff
changeset
|
66 int ssl_iostream_context_init_client(const struct ssl_iostream_settings *set, |
02f6b66458b1
lib-ssl-iostream: API changes to return error strings if init() functions fail.
Timo Sirainen <tss@iki.fi>
parents:
14723
diff
changeset
|
67 struct ssl_iostream_context **ctx_r, |
02f6b66458b1
lib-ssl-iostream: API changes to return error strings if init() functions fail.
Timo Sirainen <tss@iki.fi>
parents:
14723
diff
changeset
|
68 const char **error_r); |
02f6b66458b1
lib-ssl-iostream: API changes to return error strings if init() functions fail.
Timo Sirainen <tss@iki.fi>
parents:
14723
diff
changeset
|
69 int ssl_iostream_context_init_server(const struct ssl_iostream_settings *set, |
02f6b66458b1
lib-ssl-iostream: API changes to return error strings if init() functions fail.
Timo Sirainen <tss@iki.fi>
parents:
14723
diff
changeset
|
70 struct ssl_iostream_context **ctx_r, |
02f6b66458b1
lib-ssl-iostream: API changes to return error strings if init() functions fail.
Timo Sirainen <tss@iki.fi>
parents:
14723
diff
changeset
|
71 const char **error_r); |
12616
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
72 void ssl_iostream_context_deinit(struct ssl_iostream_context **ctx); |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
73 |
bd23d4e10fa1
Added lib-ssl-iostream for handling SSL connections more easily.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
74 #endif |