blob: b87758091f375884855ffb6c5c2012620363e015 [file] [log] [blame]
Emeric Brun46591952012-05-18 15:47:34 +02001/*
2 * include/proto/ssl_sock.h
3 * This file contains definition for ssl stream socket operations
4 *
5 * Copyright (C) 2012 EXCELIANCE, Emeric Brun <ebrun@exceliance.fr>
6 *
7 * This library is free software; you can redistribute it and/or
8 * modify it under the terms of the GNU Lesser General Public
9 * License as published by the Free Software Foundation, version 2.1
10 * exclusively.
11 *
12 * This library is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15 * Lesser General Public License for more details.
16 *
17 * You should have received a copy of the GNU Lesser General Public
18 * License along with this library; if not, write to the Free Software
19 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
20 */
21
22#ifndef _PROTO_SSL_SOCK_H
23#define _PROTO_SSL_SOCK_H
Emeric Brunfc0421f2012-09-07 17:30:07 +020024#include <openssl/ssl.h>
Emeric Brun46591952012-05-18 15:47:34 +020025
Willy Tarreaud1d54542012-09-12 22:58:11 +020026#include <types/connection.h>
27#include <types/listener.h>
28#include <types/proxy.h>
Emeric Brun46591952012-05-18 15:47:34 +020029#include <types/stream_interface.h>
30
Willy Tarreauf7bc57c2012-10-03 00:19:48 +020031extern struct xprt_ops ssl_sock;
Willy Tarreau71b734c2014-01-28 15:19:44 +010032extern int sslconns;
33extern int totalsslconns;
34
David Safb76832014-05-08 23:42:08 -040035/* boolean, returns true if connection is over SSL */
36static inline
37int ssl_sock_is_ssl(struct connection *conn)
38{
39 if (!conn || conn->xprt != &ssl_sock || !conn->xprt_ctx)
40 return 0;
41 else
42 return 1;
43}
44
Emeric Brun46591952012-05-18 15:47:34 +020045int ssl_sock_handshake(struct connection *conn, unsigned int flag);
Willy Tarreau2a65ff02012-09-13 17:54:29 +020046int ssl_sock_prepare_ctx(struct bind_conf *bind_conf, SSL_CTX *ctx, struct proxy *proxy);
Willy Tarreau2a65ff02012-09-13 17:54:29 +020047int ssl_sock_prepare_all_ctx(struct bind_conf *bind_conf, struct proxy *px);
Emeric Brun94324a42012-10-11 14:00:19 +020048int ssl_sock_prepare_srv_ctx(struct server *srv, struct proxy *px);
Christopher Faulet77fe80c2015-07-29 13:02:40 +020049void ssl_sock_free_srv_ctx(struct server *srv);
Willy Tarreau2a65ff02012-09-13 17:54:29 +020050void ssl_sock_free_all_ctx(struct bind_conf *bind_conf);
Christopher Faulet31af49d2015-06-09 17:29:50 +020051int ssl_sock_load_ca(struct bind_conf *bind_conf, struct proxy *px);
52void ssl_sock_free_ca(struct bind_conf *bind_conf);
Willy Tarreauffc3fcd2012-10-12 20:17:54 +020053const char *ssl_sock_get_cipher_name(struct connection *conn);
54const char *ssl_sock_get_proto_version(struct connection *conn);
David Safb76832014-05-08 23:42:08 -040055char *ssl_sock_get_version(struct connection *conn);
Willy Tarreau63076412015-07-10 11:33:32 +020056void ssl_sock_set_servername(struct connection *conn, const char *hostname);
Dave McCowan328fb582014-07-30 10:39:13 -040057int ssl_sock_get_cert_used_sess(struct connection *conn);
58int ssl_sock_get_cert_used_conn(struct connection *conn);
Emeric Brun0abf8362014-06-24 18:26:41 +020059int ssl_sock_get_remote_common_name(struct connection *conn, struct chunk *out);
David Safb76832014-05-08 23:42:08 -040060unsigned int ssl_sock_get_verify_result(struct connection *conn);
Lukas Tribuse4e30f72014-12-09 16:32:51 +010061#if (defined SSL_CTRL_SET_TLSEXT_STATUS_REQ_CB && !defined OPENSSL_NO_OCSP)
Emeric Brun4147b2e2014-06-16 18:36:30 +020062int ssl_sock_update_ocsp_response(struct chunk *ocsp_response, char **err);
63#endif
Nenad Merdanovic200b0fa2015-05-09 08:46:01 +020064#if (defined SSL_CTRL_SET_TLSEXT_TICKET_KEY_CB && TLS_TICKETS_NO > 0)
65int ssl_sock_update_tlskey(char *filename, struct chunk *tlskey, char **err);
66struct tls_keys_ref *tlskeys_ref_lookup(const char *filename);
67struct tls_keys_ref *tlskeys_ref_lookupid(int unique_id);
68void tlskeys_finalize_config(void);
69#endif
Remi Gacogne47783ef2015-05-29 15:53:22 +020070#ifndef OPENSSL_NO_DH
71int ssl_sock_load_global_dh_param_from_file(const char *filename);
72#endif
Emeric Brun46591952012-05-18 15:47:34 +020073
Christopher Faulet30548802015-06-11 13:39:32 +020074SSL_CTX *ssl_sock_create_cert(const char *servername, unsigned int serial, X509 *cacert, EVP_PKEY *capkey);
75SSL_CTX *ssl_sock_get_generated_cert(unsigned int serial, X509 *cacert);
Christopher Fauletd2cab922015-07-28 16:03:47 +020076int ssl_sock_set_generated_cert(SSL_CTX *ctx, unsigned int serial, X509 *cacert);
Willy Tarreau646b8642015-07-07 18:09:15 +020077unsigned int ssl_sock_generated_cert_serial(const void *data, size_t len);
Christopher Faulet30548802015-06-11 13:39:32 +020078
Emeric Brun46591952012-05-18 15:47:34 +020079#endif /* _PROTO_SSL_SOCK_H */
80
81/*
82 * Local variables:
83 * c-indent-level: 8
84 * c-basic-offset: 8
85 * End:
86 */