icinga2/lib/base/tlsstream.hpp

169 lines
4.0 KiB
C++
Raw Normal View History

/* Icinga 2 | (c) 2012 Icinga GmbH | GPLv2+ */
2012-11-22 12:04:32 +01:00
#ifndef TLSSTREAM_H
#define TLSSTREAM_H
2012-04-24 14:02:15 +02:00
2014-05-25 16:23:35 +02:00
#include "base/i2-base.hpp"
#include "base/socket.hpp"
#include "base/socketevents.hpp"
2014-05-25 16:23:35 +02:00
#include "base/stream.hpp"
#include "base/tlsutility.hpp"
#include "base/fifo.hpp"
2019-02-12 14:56:47 +01:00
#include <utility>
#include <boost/asio/buffered_stream.hpp>
#include <boost/asio/io_service.hpp>
#include <boost/asio/ip/tcp.hpp>
#include <boost/asio/ssl/context.hpp>
2019-02-12 14:56:47 +01:00
#include <boost/asio/ssl/stream.hpp>
2013-03-16 21:18:53 +01:00
2012-04-24 14:02:15 +02:00
namespace icinga
{
enum TlsAction
{
TlsActionNone,
TlsActionRead,
TlsActionWrite,
TlsActionHandshake
};
/**
2012-11-22 12:04:32 +01:00
* A TLS stream.
2012-05-18 22:21:28 +02:00
*
* @ingroup base
*/
class TlsStream final : public SocketEvents
2012-04-24 14:02:15 +02:00
{
public:
2014-11-07 12:32:25 +01:00
DECLARE_PTR_TYPEDEFS(TlsStream);
TlsStream(const Socket::Ptr& socket, const String& hostname, ConnectionRole role, const std::shared_ptr<SSL_CTX>& sslContext = MakeSSLContext());
TlsStream(const Socket::Ptr& socket, const String& hostname, ConnectionRole role, const std::shared_ptr<boost::asio::ssl::context>& sslContext);
~TlsStream() override;
2012-06-24 02:56:48 +02:00
Socket::Ptr GetSocket() const;
std::shared_ptr<X509> GetClientCertificate() const;
std::shared_ptr<X509> GetPeerCertificate() const;
void Handshake();
2013-04-04 16:08:02 +02:00
void Close() override;
void Shutdown() override;
size_t Peek(void *buffer, size_t count, bool allow_partial = false) override;
size_t Read(void *buffer, size_t count, bool allow_partial = false) override;
void Write(const void *buffer, size_t count) override;
2012-11-22 12:04:32 +01:00
bool IsEof() const override;
bool SupportsWaiting() const override;
bool IsDataAvailable() const override;
bool IsVerifyOK() const;
String GetVerifyError() const;
2012-04-24 14:02:15 +02:00
private:
std::shared_ptr<SSL> m_SSL;
bool m_Eof;
mutable boost::mutex m_Mutex;
mutable boost::condition_variable m_CV;
bool m_HandshakeOK;
bool m_VerifyOK;
String m_VerifyError;
int m_ErrorCode;
bool m_ErrorOccurred;
2012-04-24 14:02:15 +02:00
Socket::Ptr m_Socket;
ConnectionRole m_Role;
FIFO::Ptr m_SendQ;
FIFO::Ptr m_RecvQ;
TlsAction m_CurrentAction;
bool m_Retry;
2015-06-22 11:11:21 +02:00
bool m_Shutdown;
static int m_SSLIndex;
static bool m_SSLIndexInitialized;
TlsStream(const Socket::Ptr& socket, const String& hostname, ConnectionRole role, SSL_CTX* sslContext);
void OnEvent(int revents) override;
void HandleError() const;
static int ValidateCertificate(int preverify_ok, X509_STORE_CTX *ctx);
2012-11-23 11:04:08 +01:00
static void NullCertificateDeleter(X509 *certificate);
void CloseInternal(bool inDestructor);
2012-11-22 12:04:32 +01:00
};
2012-04-24 14:02:15 +02:00
struct UnbufferedAsioTlsStreamParams
{
boost::asio::io_service& IoService;
boost::asio::ssl::context& SslContext;
const String& Hostname;
};
typedef boost::asio::ssl::stream<boost::asio::ip::tcp::socket> AsioTcpTlsStream;
class UnbufferedAsioTlsStream : public AsioTcpTlsStream
{
2019-02-12 14:56:47 +01:00
public:
inline
UnbufferedAsioTlsStream(UnbufferedAsioTlsStreamParams& init)
: stream(init.IoService, init.SslContext), m_VerifyOK(true), m_Hostname(init.Hostname)
2019-02-12 14:56:47 +01:00
{
}
bool IsVerifyOK() const;
String GetVerifyError() const;
template<class... Args>
inline
auto async_handshake(handshake_type type, Args&&... args) -> decltype(AsioTcpTlsStream::async_handshake(type, std::forward<Args>(args)...))
{
BeforeHandshake(type);
return AsioTcpTlsStream::async_handshake(type, std::forward<Args>(args)...);
}
template<class... Args>
inline
auto handshake(handshake_type type, Args&&... args) -> decltype(AsioTcpTlsStream::handshake(type, std::forward<Args>(args)...))
{
BeforeHandshake(type);
return AsioTcpTlsStream::handshake(type, std::forward<Args>(args)...);
}
private:
bool m_VerifyOK;
String m_VerifyError;
String m_Hostname;
void BeforeHandshake(handshake_type type);
2019-02-12 14:56:47 +01:00
};
class AsioTlsStream : public boost::asio::buffered_stream<UnbufferedAsioTlsStream>
2019-02-12 14:56:47 +01:00
{
public:
inline
AsioTlsStream(boost::asio::io_service& ioService, boost::asio::ssl::context& sslContext, const String& hostname = String())
: AsioTlsStream(UnbufferedAsioTlsStreamParams{ioService, sslContext, hostname})
2019-02-12 14:56:47 +01:00
{
}
private:
inline
AsioTlsStream(UnbufferedAsioTlsStreamParams init)
2019-02-12 14:56:47 +01:00
: buffered_stream(init)
{
}
};
2012-04-24 14:02:15 +02:00
}
2012-11-22 12:04:32 +01:00
#endif /* TLSSTREAM_H */