2012-05-10 12:06:41 +02:00
|
|
|
/******************************************************************************
|
|
|
|
* Icinga 2 *
|
|
|
|
* Copyright (C) 2012 Icinga Development Team (http://www.icinga.org/) *
|
|
|
|
* *
|
|
|
|
* This program is free software; you can redistribute it and/or *
|
|
|
|
* modify it under the terms of the GNU General Public License *
|
|
|
|
* as published by the Free Software Foundation; either version 2 *
|
|
|
|
* of the License, or (at your option) any later version. *
|
|
|
|
* *
|
|
|
|
* This program is distributed in the hope that it will be useful, *
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of *
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the *
|
|
|
|
* GNU General Public License for more details. *
|
|
|
|
* *
|
|
|
|
* You should have received a copy of the GNU General Public License *
|
|
|
|
* along with this program; if not, write to the Free Software Foundation *
|
2012-05-11 13:33:57 +02:00
|
|
|
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA. *
|
2012-05-10 12:06:41 +02:00
|
|
|
******************************************************************************/
|
|
|
|
|
2012-11-22 12:04:32 +01:00
|
|
|
#ifndef TLSSTREAM_H
|
|
|
|
#define TLSSTREAM_H
|
2012-04-24 14:02:15 +02:00
|
|
|
|
2013-03-16 21:18:53 +01:00
|
|
|
#include "base/i2-base.h"
|
2013-04-04 16:08:02 +02:00
|
|
|
#include "base/bufferedstream.h"
|
2013-03-16 21:18:53 +01:00
|
|
|
#include "base/stream.h"
|
|
|
|
#include "base/fifo.h"
|
2013-03-18 19:02:42 +01:00
|
|
|
#include "base/tlsutility.h"
|
2013-03-16 21:18:53 +01:00
|
|
|
|
2012-04-24 14:02:15 +02:00
|
|
|
namespace icinga
|
|
|
|
{
|
|
|
|
|
2012-11-23 11:04:08 +01:00
|
|
|
enum TlsRole
|
2012-11-22 12:04:32 +01:00
|
|
|
{
|
|
|
|
TlsRoleClient,
|
|
|
|
TlsRoleServer
|
2012-11-23 11:04:08 +01:00
|
|
|
};
|
2012-11-22 12:04:32 +01:00
|
|
|
|
2012-05-15 10:58:14 +02:00
|
|
|
/**
|
2012-11-22 12:04:32 +01:00
|
|
|
* A TLS stream.
|
2012-05-18 22:21:28 +02:00
|
|
|
*
|
|
|
|
* @ingroup base
|
2012-05-15 10:58:14 +02:00
|
|
|
*/
|
2012-11-22 12:04:32 +01:00
|
|
|
class I2_BASE_API TlsStream : public Stream
|
2012-04-24 14:02:15 +02:00
|
|
|
{
|
2012-05-21 23:42:54 +02:00
|
|
|
public:
|
2013-07-09 08:42:08 +02:00
|
|
|
DECLARE_PTR_TYPEDEFS(TlsStream);
|
2012-05-21 23:42:54 +02:00
|
|
|
|
2012-11-22 12:04:32 +01:00
|
|
|
TlsStream(const Stream::Ptr& innerStream, TlsRole role, shared_ptr<SSL_CTX> sslContext);
|
2012-06-24 02:56:48 +02:00
|
|
|
|
2012-05-21 23:42:54 +02:00
|
|
|
shared_ptr<X509> GetClientCertificate(void) const;
|
|
|
|
shared_ptr<X509> GetPeerCertificate(void) const;
|
|
|
|
|
2013-04-04 16:08:02 +02:00
|
|
|
void Handshake(void);
|
|
|
|
|
2012-11-22 12:04:32 +01:00
|
|
|
virtual void Close(void);
|
2012-05-21 23:42:54 +02:00
|
|
|
|
2012-11-22 12:04:32 +01:00
|
|
|
virtual size_t Read(void *buffer, size_t count);
|
|
|
|
virtual void Write(const void *buffer, size_t count);
|
|
|
|
|
2013-08-27 12:21:41 +02:00
|
|
|
virtual bool IsEof(void) const;
|
|
|
|
|
2012-04-24 14:02:15 +02:00
|
|
|
private:
|
|
|
|
shared_ptr<SSL_CTX> m_SSLContext;
|
|
|
|
shared_ptr<SSL> m_SSL;
|
2012-11-22 12:04:32 +01:00
|
|
|
BIO *m_BIO;
|
2012-04-24 14:02:15 +02:00
|
|
|
|
2013-04-04 16:08:02 +02:00
|
|
|
BufferedStream::Ptr m_InnerStream;
|
2012-11-22 12:04:32 +01:00
|
|
|
TlsRole m_Role;
|
2012-04-27 14:15:22 +02:00
|
|
|
|
2012-04-24 14:54:05 +02:00
|
|
|
static int m_SSLIndex;
|
|
|
|
static bool m_SSLIndexInitialized;
|
|
|
|
|
2012-11-23 11:04:08 +01:00
|
|
|
static void NullCertificateDeleter(X509 *certificate);
|
2012-11-22 12:04:32 +01:00
|
|
|
};
|
2012-04-24 14:02:15 +02:00
|
|
|
|
|
|
|
}
|
|
|
|
|
2012-11-22 12:04:32 +01:00
|
|
|
#endif /* TLSSTREAM_H */
|