1 /* 2 * 3 * Copyright 2016 gRPC authors. 4 * 5 * Licensed under the Apache License, Version 2.0 (the "License"); 6 * you may not use this file except in compliance with the License. 7 * You may obtain a copy of the License at 8 * 9 * http://www.apache.org/licenses/LICENSE-2.0 10 * 11 * Unless required by applicable law or agreed to in writing, software 12 * distributed under the License is distributed on an "AS IS" BASIS, 13 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 14 * See the License for the specific language governing permissions and 15 * limitations under the License. 16 * 17 */ 18 #ifndef GRPC_CORE_LIB_SECURITY_CREDENTIALS_SSL_SSL_CREDENTIALS_H 19 #define GRPC_CORE_LIB_SECURITY_CREDENTIALS_SSL_SSL_CREDENTIALS_H 20 21 #include <grpc/support/port_platform.h> 22 23 #include "src/core/lib/security/credentials/credentials.h" 24 25 #include "src/core/lib/security/security_connector/ssl/ssl_security_connector.h" 26 27 class grpc_ssl_credentials : public grpc_channel_credentials { 28 public: 29 grpc_ssl_credentials(const char* pem_root_certs, 30 grpc_ssl_pem_key_cert_pair* pem_key_cert_pair, 31 const grpc_ssl_verify_peer_options* verify_options); 32 33 ~grpc_ssl_credentials() override; 34 35 grpc_core::RefCountedPtr<grpc_channel_security_connector> 36 create_security_connector( 37 grpc_core::RefCountedPtr<grpc_call_credentials> call_creds, 38 const char* target, const grpc_channel_args* args, 39 grpc_channel_args** new_args) override; 40 41 // TODO(mattstev): Plumb to wrapped languages. Until then, setting the TLS 42 // version should be done for testing purposes only. 43 void set_min_tls_version(grpc_tls_version min_tls_version); 44 void set_max_tls_version(grpc_tls_version max_tls_version); 45 46 private: 47 void build_config(const char* pem_root_certs, 48 grpc_ssl_pem_key_cert_pair* pem_key_cert_pair, 49 const grpc_ssl_verify_peer_options* verify_options); 50 51 grpc_ssl_config config_; 52 }; 53 54 struct grpc_ssl_server_certificate_config { 55 grpc_ssl_pem_key_cert_pair* pem_key_cert_pairs = nullptr; 56 size_t num_key_cert_pairs = 0; 57 char* pem_root_certs = nullptr; 58 }; 59 60 struct grpc_ssl_server_certificate_config_fetcher { 61 grpc_ssl_server_certificate_config_callback cb = nullptr; 62 void* user_data; 63 }; 64 65 class grpc_ssl_server_credentials final : public grpc_server_credentials { 66 public: 67 explicit grpc_ssl_server_credentials( 68 const grpc_ssl_server_credentials_options& options); 69 ~grpc_ssl_server_credentials() override; 70 71 grpc_core::RefCountedPtr<grpc_server_security_connector> 72 create_security_connector(const grpc_channel_args* /* args */) override; 73 has_cert_config_fetcher()74 bool has_cert_config_fetcher() const { 75 return certificate_config_fetcher_.cb != nullptr; 76 } 77 FetchCertConfig(grpc_ssl_server_certificate_config ** config)78 grpc_ssl_certificate_config_reload_status FetchCertConfig( 79 grpc_ssl_server_certificate_config** config) { 80 GPR_DEBUG_ASSERT(has_cert_config_fetcher()); 81 return certificate_config_fetcher_.cb(certificate_config_fetcher_.user_data, 82 config); 83 } 84 85 // TODO(mattstev): Plumb to wrapped languages. Until then, setting the TLS 86 // version should be done for testing purposes only. 87 void set_min_tls_version(grpc_tls_version min_tls_version); 88 void set_max_tls_version(grpc_tls_version max_tls_version); 89 config()90 const grpc_ssl_server_config& config() const { return config_; } 91 92 private: 93 void build_config( 94 const char* pem_root_certs, 95 grpc_ssl_pem_key_cert_pair* pem_key_cert_pairs, size_t num_key_cert_pairs, 96 grpc_ssl_client_certificate_request_type client_certificate_request); 97 98 grpc_ssl_server_config config_; 99 grpc_ssl_server_certificate_config_fetcher certificate_config_fetcher_; 100 }; 101 102 tsi_ssl_pem_key_cert_pair* grpc_convert_grpc_to_tsi_cert_pairs( 103 const grpc_ssl_pem_key_cert_pair* pem_key_cert_pairs, 104 size_t num_key_cert_pairs); 105 106 void grpc_tsi_ssl_pem_key_cert_pairs_destroy(tsi_ssl_pem_key_cert_pair* kp, 107 size_t num_key_cert_pairs); 108 109 #endif /* GRPC_CORE_LIB_SECURITY_CREDENTIALS_SSL_SSL_CREDENTIALS_H */ 110