private-network.h 6.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192
  1. /*
  2. * libwebsockets - small server side websockets and web server implementation
  3. *
  4. * Copyright (C) 2010 - 2019 Andy Green <[email protected]>
  5. *
  6. * Permission is hereby granted, free of charge, to any person obtaining a copy
  7. * of this software and associated documentation files (the "Software"), to
  8. * deal in the Software without restriction, including without limitation the
  9. * rights to use, copy, modify, merge, publish, distribute, sublicense, and/or
  10. * sell copies of the Software, and to permit persons to whom the Software is
  11. * furnished to do so, subject to the following conditions:
  12. *
  13. * The above copyright notice and this permission notice shall be included in
  14. * all copies or substantial portions of the Software.
  15. *
  16. * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
  17. * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
  18. * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
  19. * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
  20. * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
  21. * FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS
  22. * IN THE SOFTWARE.
  23. *
  24. * This is included from private-lib-core.h if LWS_WITH_TLS
  25. */
  26. struct lws_context_per_thread;
  27. struct lws_tls_ops {
  28. int (*fake_POLLIN_for_buffered)(struct lws_context_per_thread *pt);
  29. };
  30. struct lws_context_tls {
  31. char alpn_discovered[32];
  32. const char *alpn_default;
  33. time_t last_cert_check_s;
  34. struct lws_dll2_owner cc_owner;
  35. int count_client_contexts;
  36. };
  37. struct lws_pt_tls {
  38. struct lws_dll2_owner dll_pending_tls_owner;
  39. };
  40. struct lws_tls_ss_pieces;
  41. struct alpn_ctx {
  42. uint8_t data[23];
  43. uint8_t len;
  44. };
  45. struct lws_vhost_tls {
  46. lws_tls_ctx *ssl_ctx;
  47. lws_tls_ctx *ssl_client_ctx;
  48. const char *alpn;
  49. struct lws_tls_ss_pieces *ss; /* for acme tls certs */
  50. char *alloc_cert_path;
  51. char *key_path;
  52. #if defined(LWS_WITH_MBEDTLS)
  53. lws_tls_x509 *x509_client_CA;
  54. #endif
  55. char ecdh_curve[16];
  56. struct alpn_ctx alpn_ctx;
  57. int use_ssl;
  58. int allow_non_ssl_on_ssl_port;
  59. int ssl_info_event_mask;
  60. unsigned int user_supplied_ssl_ctx:1;
  61. unsigned int skipped_certs:1;
  62. };
  63. struct lws_lws_tls {
  64. lws_tls_conn *ssl;
  65. lws_tls_bio *client_bio;
  66. struct lws_dll2 dll_pending_tls;
  67. unsigned int use_ssl;
  68. unsigned int redirect_to_https:1;
  69. };
  70. LWS_EXTERN void
  71. lws_context_init_alpn(struct lws_vhost *vhost);
  72. LWS_EXTERN int LWS_WARN_UNUSED_RESULT
  73. lws_ssl_capable_read(struct lws *wsi, unsigned char *buf, int len);
  74. LWS_EXTERN int LWS_WARN_UNUSED_RESULT
  75. lws_ssl_capable_write(struct lws *wsi, unsigned char *buf, int len);
  76. LWS_EXTERN int LWS_WARN_UNUSED_RESULT
  77. lws_ssl_pending(struct lws *wsi);
  78. LWS_EXTERN int LWS_WARN_UNUSED_RESULT
  79. lws_server_socket_service_ssl(struct lws *new_wsi, lws_sockfd_type accept_fd,
  80. char is_pollin);
  81. LWS_EXTERN int
  82. lws_ssl_close(struct lws *wsi);
  83. LWS_EXTERN void
  84. lws_ssl_SSL_CTX_destroy(struct lws_vhost *vhost);
  85. LWS_EXTERN void
  86. lws_ssl_context_destroy(struct lws_context *context);
  87. void
  88. __lws_ssl_remove_wsi_from_buffered_list(struct lws *wsi);
  89. LWS_VISIBLE void
  90. lws_ssl_remove_wsi_from_buffered_list(struct lws *wsi);
  91. LWS_EXTERN int
  92. lws_ssl_client_bio_create(struct lws *wsi);
  93. LWS_EXTERN int
  94. lws_ssl_client_connect1(struct lws *wsi, char *errbuf, int len);
  95. LWS_EXTERN int
  96. lws_ssl_client_connect2(struct lws *wsi, char *errbuf, int len);
  97. LWS_EXTERN int
  98. lws_tls_fake_POLLIN_for_buffered(struct lws_context_per_thread *pt);
  99. LWS_EXTERN int
  100. lws_gate_accepts(struct lws_context *context, int on);
  101. LWS_EXTERN void
  102. lws_ssl_bind_passphrase(lws_tls_ctx *ssl_ctx, int is_client,
  103. const struct lws_context_creation_info *info);
  104. LWS_EXTERN void
  105. lws_ssl_info_callback(const lws_tls_conn *ssl, int where, int ret);
  106. LWS_EXTERN int
  107. lws_tls_server_certs_load(struct lws_vhost *vhost, struct lws *wsi,
  108. const char *cert, const char *private_key,
  109. const char *mem_cert, size_t len_mem_cert,
  110. const char *mem_privkey, size_t mem_privkey_len);
  111. LWS_EXTERN enum lws_tls_extant
  112. lws_tls_generic_cert_checks(struct lws_vhost *vhost, const char *cert,
  113. const char *private_key);
  114. #if defined(LWS_WITH_SERVER)
  115. LWS_EXTERN int
  116. lws_context_init_server_ssl(const struct lws_context_creation_info *info,
  117. struct lws_vhost *vhost);
  118. void
  119. lws_tls_acme_sni_cert_destroy(struct lws_vhost *vhost);
  120. #else
  121. #define lws_context_init_server_ssl(_a, _b) (0)
  122. #define lws_tls_acme_sni_cert_destroy(_a)
  123. #endif
  124. LWS_EXTERN void
  125. lws_ssl_destroy(struct lws_vhost *vhost);
  126. /*
  127. * lws_tls_ abstract backend implementations
  128. */
  129. LWS_EXTERN int
  130. lws_tls_server_client_cert_verify_config(struct lws_vhost *vh);
  131. LWS_EXTERN int
  132. lws_tls_server_vhost_backend_init(const struct lws_context_creation_info *info,
  133. struct lws_vhost *vhost, struct lws *wsi);
  134. LWS_EXTERN int
  135. lws_tls_server_new_nonblocking(struct lws *wsi, lws_sockfd_type accept_fd);
  136. LWS_EXTERN enum lws_ssl_capable_status
  137. lws_tls_server_accept(struct lws *wsi);
  138. LWS_EXTERN enum lws_ssl_capable_status
  139. lws_tls_server_abort_connection(struct lws *wsi);
  140. LWS_EXTERN enum lws_ssl_capable_status
  141. __lws_tls_shutdown(struct lws *wsi);
  142. LWS_EXTERN enum lws_ssl_capable_status
  143. lws_tls_client_connect(struct lws *wsi, char *errbuf, int len);
  144. LWS_EXTERN int
  145. lws_tls_client_confirm_peer_cert(struct lws *wsi, char *ebuf, int ebuf_len);
  146. LWS_EXTERN int
  147. lws_tls_client_create_vhost_context(struct lws_vhost *vh,
  148. const struct lws_context_creation_info *info,
  149. const char *cipher_list,
  150. const char *ca_filepath,
  151. const void *ca_mem,
  152. unsigned int ca_mem_len,
  153. const char *cert_filepath,
  154. const void *cert_mem,
  155. unsigned int cert_mem_len,
  156. const char *private_key_filepath,
  157. const void *key_mem,
  158. unsigned int key_mem_len);
  159. LWS_EXTERN lws_tls_ctx *
  160. lws_tls_ctx_from_wsi(struct lws *wsi);
  161. LWS_EXTERN int
  162. lws_ssl_get_error(struct lws *wsi, int n);
  163. LWS_EXTERN int
  164. lws_context_init_client_ssl(const struct lws_context_creation_info *info,
  165. struct lws_vhost *vhost);
  166. LWS_EXTERN void
  167. lws_ssl_info_callback(const lws_tls_conn *ssl, int where, int ret);
  168. int
  169. lws_tls_fake_POLLIN_for_buffered(struct lws_context_per_thread *pt);