1 /*
2  * include/proto/ssl_sock.h
3  * This file contains definition for ssl stream socket operations
4  *
5  * Copyright (C) 2012 EXCELIANCE, Emeric Brun <ebrun@exceliance.fr>
6  *
7  * This library is free software; you can redistribute it and/or
8  * modify it under the terms of the GNU Lesser General Public
9  * License as published by the Free Software Foundation, version 2.1
10  * exclusively.
11  *
12  * This library is distributed in the hope that it will be useful,
13  * but WITHOUT ANY WARRANTY; without even the implied warranty of
14  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
15  * Lesser General Public License for more details.
16  *
17  * You should have received a copy of the GNU Lesser General Public
18  * License along with this library; if not, write to the Free Software
19  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA  02110-1301  USA
20  */
21 
22 #ifndef _PROTO_SSL_SOCK_H
23 #define _PROTO_SSL_SOCK_H
24 #include <openssl/ssl.h>
25 
26 #include <types/connection.h>
27 #include <types/listener.h>
28 #include <types/proxy.h>
29 #include <types/stream_interface.h>
30 
31 extern int sslconns;
32 extern int totalsslconns;
33 
34 /* boolean, returns true if connection is over SSL */
35 static inline
ssl_sock_is_ssl(struct connection * conn)36 int ssl_sock_is_ssl(struct connection *conn)
37 {
38 	if (!conn || conn->xprt != xprt_get(XPRT_SSL) || !conn->xprt_ctx)
39 		return 0;
40 	else
41 		return 1;
42 }
43 
44 int ssl_sock_handshake(struct connection *conn, unsigned int flag);
45 int ssl_sock_prepare_ctx(struct bind_conf *bind_conf, struct ssl_bind_conf *, SSL_CTX *ctx);
46 int ssl_sock_prepare_all_ctx(struct bind_conf *bind_conf);
47 int ssl_sock_prepare_bind_conf(struct bind_conf *bind_conf);
48 int ssl_sock_prepare_srv_ctx(struct server *srv);
49 void ssl_sock_free_srv_ctx(struct server *srv);
50 void ssl_sock_free_all_ctx(struct bind_conf *bind_conf);
51 int ssl_sock_load_ca(struct bind_conf *bind_conf);
52 void ssl_sock_free_ca(struct bind_conf *bind_conf);
53 const char *ssl_sock_get_cipher_name(struct connection *conn);
54 const char *ssl_sock_get_proto_version(struct connection *conn);
55 void ssl_sock_set_servername(struct connection *conn, const char *hostname);
56 int ssl_sock_get_cert_used_sess(struct connection *conn);
57 int ssl_sock_get_cert_used_conn(struct connection *conn);
58 int ssl_sock_get_remote_common_name(struct connection *conn, struct chunk *out);
59 unsigned int ssl_sock_get_verify_result(struct connection *conn);
60 #if (defined SSL_CTRL_SET_TLSEXT_STATUS_REQ_CB && !defined OPENSSL_NO_OCSP)
61 int ssl_sock_update_ocsp_response(struct chunk *ocsp_response, char **err);
62 #endif
63 #if (defined SSL_CTRL_SET_TLSEXT_TICKET_KEY_CB && TLS_TICKETS_NO > 0)
64 void ssl_sock_update_tlskey_ref(struct tls_keys_ref *ref, struct chunk *tlskey);
65 int ssl_sock_update_tlskey(char *filename, struct chunk *tlskey, char **err);
66 struct tls_keys_ref *tlskeys_ref_lookup(const char *filename);
67 struct tls_keys_ref *tlskeys_ref_lookupid(int unique_id);
68 #endif
69 #ifndef OPENSSL_NO_DH
70 int ssl_sock_load_global_dh_param_from_file(const char *filename);
71 void ssl_free_dh(void);
72 #endif
73 void ssl_free_engines(void);
74 
75 SSL_CTX *ssl_sock_create_cert(struct connection *conn, const char *servername, unsigned int key);
76 SSL_CTX *ssl_sock_assign_generated_cert(unsigned int key, struct bind_conf *bind_conf, SSL *ssl);
77 SSL_CTX *ssl_sock_get_generated_cert(unsigned int key, struct bind_conf *bind_conf);
78 int ssl_sock_set_generated_cert(SSL_CTX *ctx, unsigned int key, struct bind_conf *bind_conf);
79 unsigned int ssl_sock_generated_cert_key(const void *data, size_t len);
80 
81 
82 /* ssl shctx macro */
83 
84 #define sh_ssl_sess_tree_delete(s)     ebmb_delete(&(s)->key);
85 
86 #define sh_ssl_sess_tree_insert(s)     (struct sh_ssl_sess_hdr *)ebmb_insert(sh_ssl_sess_tree, \
87                                                                     &(s)->key, SSL_MAX_SSL_SESSION_ID_LENGTH);
88 
89 #define sh_ssl_sess_tree_lookup(k)     (struct sh_ssl_sess_hdr *)ebmb_lookup(sh_ssl_sess_tree, \
90                                                                     (k), SSL_MAX_SSL_SESSION_ID_LENGTH);
91 #endif /* _PROTO_SSL_SOCK_H */
92 
93 /*
94  * Local variables:
95  *  c-indent-level: 8
96  *  c-basic-offset: 8
97  * End:
98  */
99