gtls.h 4.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121
  1. #ifndef HEADER_CURL_GTLS_H
  2. #define HEADER_CURL_GTLS_H
  3. /***************************************************************************
  4. * _ _ ____ _
  5. * Project ___| | | | _ \| |
  6. * / __| | | | |_) | |
  7. * | (__| |_| | _ <| |___
  8. * \___|\___/|_| \_\_____|
  9. *
  10. * Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
  11. *
  12. * This software is licensed as described in the file COPYING, which
  13. * you should have received as part of this distribution. The terms
  14. * are also available at https://curl.se/docs/copyright.html.
  15. *
  16. * You may opt to use, copy, modify, merge, publish, distribute and/or sell
  17. * copies of the Software, and permit persons to whom the Software is
  18. * furnished to do so, under the terms of the COPYING file.
  19. *
  20. * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
  21. * KIND, either express or implied.
  22. *
  23. * SPDX-License-Identifier: curl
  24. *
  25. ***************************************************************************/
  26. #include "curl_setup.h"
  27. #include <curl/curl.h>
  28. #ifdef USE_GNUTLS
  29. #include <gnutls/gnutls.h>
  30. #include "timeval.h"
  31. #ifdef HAVE_GNUTLS_SRP
  32. /* the function exists */
  33. #ifdef USE_TLS_SRP
  34. /* the functionality is not disabled */
  35. #define USE_GNUTLS_SRP
  36. #endif
  37. #endif
  38. struct Curl_easy;
  39. struct Curl_cfilter;
  40. struct ssl_primary_config;
  41. struct ssl_config_data;
  42. struct ssl_peer;
  43. struct ssl_connect_data;
  44. struct Curl_ssl_session;
  45. int Curl_glts_get_ietf_proto(gnutls_session_t session);
  46. struct gtls_shared_creds {
  47. gnutls_certificate_credentials_t creds;
  48. char *CAfile; /* CAfile path used to generate X509 store */
  49. struct curltime time; /* when the shared creds was created */
  50. size_t refcount;
  51. BIT(trust_setup); /* x509 anchors + CRLs have been set up */
  52. };
  53. CURLcode Curl_gtls_shared_creds_create(struct Curl_easy *data,
  54. struct gtls_shared_creds **pcreds);
  55. CURLcode Curl_gtls_shared_creds_up_ref(struct gtls_shared_creds *creds);
  56. void Curl_gtls_shared_creds_free(struct gtls_shared_creds **pcreds);
  57. struct gtls_ctx {
  58. gnutls_session_t session;
  59. struct gtls_shared_creds *shared_creds;
  60. #ifdef USE_GNUTLS_SRP
  61. gnutls_srp_client_credentials_t srp_client_cred;
  62. #endif
  63. CURLcode io_result; /* result of last IO cfilter operation */
  64. BIT(sent_shutdown);
  65. };
  66. size_t Curl_gtls_version(char *buffer, size_t size);
  67. typedef CURLcode Curl_gtls_ctx_setup_cb(struct Curl_cfilter *cf,
  68. struct Curl_easy *data,
  69. void *user_data);
  70. typedef CURLcode Curl_gtls_init_session_reuse_cb(struct Curl_cfilter *cf,
  71. struct Curl_easy *data,
  72. struct Curl_ssl_session *scs,
  73. bool *do_early_data);
  74. CURLcode Curl_gtls_ctx_init(struct gtls_ctx *gctx,
  75. struct Curl_cfilter *cf,
  76. struct Curl_easy *data,
  77. struct ssl_peer *peer,
  78. const unsigned char *alpn, size_t alpn_len,
  79. Curl_gtls_ctx_setup_cb *cb_setup,
  80. void *cb_user_data,
  81. void *ssl_user_data,
  82. Curl_gtls_init_session_reuse_cb *sess_reuse_cb);
  83. CURLcode Curl_gtls_client_trust_setup(struct Curl_cfilter *cf,
  84. struct Curl_easy *data,
  85. struct gtls_ctx *gtls);
  86. CURLcode Curl_gtls_verifyserver(struct Curl_easy *data,
  87. gnutls_session_t session,
  88. struct ssl_primary_config *config,
  89. struct ssl_config_data *ssl_config,
  90. struct ssl_peer *peer,
  91. const char *pinned_key);
  92. /* Extract TLS session and place in cache, if configured. */
  93. CURLcode Curl_gtls_cache_session(struct Curl_cfilter *cf,
  94. struct Curl_easy *data,
  95. const char *ssl_peer_key,
  96. gnutls_session_t session,
  97. int lifetime_secs,
  98. const char *alpn,
  99. unsigned char *quic_tp,
  100. size_t quic_tp_len);
  101. extern const struct Curl_ssl Curl_ssl_gnutls;
  102. #endif /* USE_GNUTLS */
  103. #endif /* HEADER_CURL_GTLS_H */