• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 //
2 //
3 // Copyright 2018 gRPC authors.
4 //
5 // Licensed under the Apache License, Version 2.0 (the "License");
6 // you may not use this file except in compliance with the License.
7 // You may obtain a copy of the License at
8 //
9 //     http://www.apache.org/licenses/LICENSE-2.0
10 //
11 // Unless required by applicable law or agreed to in writing, software
12 // distributed under the License is distributed on an "AS IS" BASIS,
13 // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14 // See the License for the specific language governing permissions and
15 // limitations under the License.
16 //
17 //
18 
19 #ifndef GRPC_SRC_CORE_LIB_SECURITY_SECURITY_CONNECTOR_SSL_SSL_SECURITY_CONNECTOR_H
20 #define GRPC_SRC_CORE_LIB_SECURITY_SECURITY_CONNECTOR_SSL_SSL_SECURITY_CONNECTOR_H
21 #include <grpc/credentials.h>
22 #include <grpc/grpc.h>
23 #include <grpc/grpc_security.h>
24 #include <grpc/grpc_security_constants.h>
25 #include <grpc/support/port_platform.h>
26 #include <stddef.h>
27 
28 #include "src/core/lib/security/security_connector/security_connector.h"
29 #include "src/core/tsi/ssl_transport_security.h"
30 #include "src/core/util/ref_counted_ptr.h"
31 
32 struct grpc_ssl_config {
33   tsi_ssl_pem_key_cert_pair* pem_key_cert_pair;
34   char* pem_root_certs;
35   verify_peer_options verify_options;
36   grpc_tls_version min_tls_version = grpc_tls_version::TLS1_2;
37   grpc_tls_version max_tls_version = grpc_tls_version::TLS1_3;
38 };
39 
40 // Creates an SSL channel_security_connector.
41 // - request_metadata_creds is the credentials object which metadata
42 //   will be sent with each request. This parameter can be NULL.
43 // - config is the SSL config to be used for the SSL channel establishment.
44 // - is_client should be 0 for a server or a non-0 value for a client.
45 // - secure_peer_name is the secure peer name that should be checked in
46 //   grpc_channel_security_connector_check_peer. This parameter may be NULL in
47 //   which case the peer name will not be checked. Note that if this parameter
48 //   is not NULL, then, pem_root_certs should not be NULL either.
49 // - sc is a pointer on the connector to be created.
50 // This function returns GRPC_SECURITY_OK in case of success or a
51 // specific error code otherwise.
52 //
53 grpc_core::RefCountedPtr<grpc_channel_security_connector>
54 grpc_ssl_channel_security_connector_create(
55     grpc_core::RefCountedPtr<grpc_channel_credentials> channel_creds,
56     grpc_core::RefCountedPtr<grpc_call_credentials> request_metadata_creds,
57     const grpc_ssl_config* config, const char* target_name,
58     const char* overridden_target_name,
59     tsi_ssl_client_handshaker_factory* factory);
60 
61 // Config for ssl servers.
62 struct grpc_ssl_server_config {
63   tsi_ssl_pem_key_cert_pair* pem_key_cert_pairs = nullptr;
64   size_t num_key_cert_pairs = 0;
65   char* pem_root_certs = nullptr;
66   grpc_ssl_client_certificate_request_type client_certificate_request =
67       GRPC_SSL_DONT_REQUEST_CLIENT_CERTIFICATE;
68   grpc_tls_version min_tls_version = grpc_tls_version::TLS1_2;
69   grpc_tls_version max_tls_version = grpc_tls_version::TLS1_3;
70 };
71 // Creates an SSL server_security_connector.
72 // - config is the SSL config to be used for the SSL channel establishment.
73 // - sc is a pointer on the connector to be created.
74 // This function returns GRPC_SECURITY_OK in case of success or a
75 // specific error code otherwise.
76 //
77 grpc_core::RefCountedPtr<grpc_server_security_connector>
78 grpc_ssl_server_security_connector_create(
79     grpc_core::RefCountedPtr<grpc_server_credentials> server_credentials);
80 
81 #endif  // GRPC_SRC_CORE_LIB_SECURITY_SECURITY_CONNECTOR_SSL_SSL_SECURITY_CONNECTOR_H
82