• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  *
3  * Copyright 2016 gRPC authors.
4  *
5  * Licensed under the Apache License, Version 2.0 (the "License");
6  * you may not use this file except in compliance with the License.
7  * You may obtain a copy of the License at
8  *
9  *     http://www.apache.org/licenses/LICENSE-2.0
10  *
11  * Unless required by applicable law or agreed to in writing, software
12  * distributed under the License is distributed on an "AS IS" BASIS,
13  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14  * See the License for the specific language governing permissions and
15  * limitations under the License.
16  *
17  */
18 #ifndef GRPC_CORE_LIB_SECURITY_CREDENTIALS_SSL_SSL_CREDENTIALS_H
19 #define GRPC_CORE_LIB_SECURITY_CREDENTIALS_SSL_SSL_CREDENTIALS_H
20 
21 #include <grpc/support/port_platform.h>
22 
23 #include "src/core/lib/security/credentials/credentials.h"
24 
25 #include "src/core/lib/security/security_connector/ssl/ssl_security_connector.h"
26 
27 class grpc_ssl_credentials : public grpc_channel_credentials {
28  public:
29   grpc_ssl_credentials(const char* pem_root_certs,
30                        grpc_ssl_pem_key_cert_pair* pem_key_cert_pair,
31                        const grpc_ssl_verify_peer_options* verify_options);
32 
33   ~grpc_ssl_credentials() override;
34 
35   grpc_core::RefCountedPtr<grpc_channel_security_connector>
36   create_security_connector(
37       grpc_core::RefCountedPtr<grpc_call_credentials> call_creds,
38       const char* target, const grpc_channel_args* args,
39       grpc_channel_args** new_args) override;
40 
41   // TODO(mattstev): Plumb to wrapped languages. Until then, setting the TLS
42   // version should be done for testing purposes only.
43   void set_min_tls_version(grpc_tls_version min_tls_version);
44   void set_max_tls_version(grpc_tls_version max_tls_version);
45 
46  private:
47   void build_config(const char* pem_root_certs,
48                     grpc_ssl_pem_key_cert_pair* pem_key_cert_pair,
49                     const grpc_ssl_verify_peer_options* verify_options);
50 
51   grpc_ssl_config config_;
52 };
53 
54 struct grpc_ssl_server_certificate_config {
55   grpc_ssl_pem_key_cert_pair* pem_key_cert_pairs = nullptr;
56   size_t num_key_cert_pairs = 0;
57   char* pem_root_certs = nullptr;
58 };
59 
60 struct grpc_ssl_server_certificate_config_fetcher {
61   grpc_ssl_server_certificate_config_callback cb = nullptr;
62   void* user_data;
63 };
64 
65 class grpc_ssl_server_credentials final : public grpc_server_credentials {
66  public:
67   explicit grpc_ssl_server_credentials(
68       const grpc_ssl_server_credentials_options& options);
69   ~grpc_ssl_server_credentials() override;
70 
71   grpc_core::RefCountedPtr<grpc_server_security_connector>
72   create_security_connector(const grpc_channel_args* /* args */) override;
73 
has_cert_config_fetcher()74   bool has_cert_config_fetcher() const {
75     return certificate_config_fetcher_.cb != nullptr;
76   }
77 
FetchCertConfig(grpc_ssl_server_certificate_config ** config)78   grpc_ssl_certificate_config_reload_status FetchCertConfig(
79       grpc_ssl_server_certificate_config** config) {
80     GPR_DEBUG_ASSERT(has_cert_config_fetcher());
81     return certificate_config_fetcher_.cb(certificate_config_fetcher_.user_data,
82                                           config);
83   }
84 
85   // TODO(mattstev): Plumb to wrapped languages. Until then, setting the TLS
86   // version should be done for testing purposes only.
87   void set_min_tls_version(grpc_tls_version min_tls_version);
88   void set_max_tls_version(grpc_tls_version max_tls_version);
89 
config()90   const grpc_ssl_server_config& config() const { return config_; }
91 
92  private:
93   void build_config(
94       const char* pem_root_certs,
95       grpc_ssl_pem_key_cert_pair* pem_key_cert_pairs, size_t num_key_cert_pairs,
96       grpc_ssl_client_certificate_request_type client_certificate_request);
97 
98   grpc_ssl_server_config config_;
99   grpc_ssl_server_certificate_config_fetcher certificate_config_fetcher_;
100 };
101 
102 tsi_ssl_pem_key_cert_pair* grpc_convert_grpc_to_tsi_cert_pairs(
103     const grpc_ssl_pem_key_cert_pair* pem_key_cert_pairs,
104     size_t num_key_cert_pairs);
105 
106 void grpc_tsi_ssl_pem_key_cert_pairs_destroy(tsi_ssl_pem_key_cert_pair* kp,
107                                              size_t num_key_cert_pairs);
108 
109 #endif /* GRPC_CORE_LIB_SECURITY_CREDENTIALS_SSL_SSL_CREDENTIALS_H */
110