• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 #ifndef HEADER_CURL_GTLS_H
2 #define HEADER_CURL_GTLS_H
3 /***************************************************************************
4  *                                  _   _ ____  _
5  *  Project                     ___| | | |  _ \| |
6  *                             / __| | | | |_) | |
7  *                            | (__| |_| |  _ <| |___
8  *                             \___|\___/|_| \_\_____|
9  *
10  * Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
11  *
12  * This software is licensed as described in the file COPYING, which
13  * you should have received as part of this distribution. The terms
14  * are also available at https://curl.se/docs/copyright.html.
15  *
16  * You may opt to use, copy, modify, merge, publish, distribute and/or sell
17  * copies of the Software, and permit persons to whom the Software is
18  * furnished to do so, under the terms of the COPYING file.
19  *
20  * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
21  * KIND, either express or implied.
22  *
23  * SPDX-License-Identifier: curl
24  *
25  ***************************************************************************/
26 
27 #include "curl_setup.h"
28 #include <curl/curl.h>
29 
30 #ifdef USE_GNUTLS
31 
32 #include <gnutls/gnutls.h>
33 #include "timeval.h"
34 
35 #ifdef HAVE_GNUTLS_SRP
36 /* the function exists */
37 #ifdef USE_TLS_SRP
38 /* the functionality is not disabled */
39 #define USE_GNUTLS_SRP
40 #endif
41 #endif
42 
43 struct Curl_easy;
44 struct Curl_cfilter;
45 struct ssl_primary_config;
46 struct ssl_config_data;
47 struct ssl_peer;
48 struct ssl_connect_data;
49 struct Curl_ssl_session;
50 
51 int Curl_glts_get_ietf_proto(gnutls_session_t session);
52 
53 struct gtls_shared_creds {
54   gnutls_certificate_credentials_t creds;
55   char *CAfile; /* CAfile path used to generate X509 store */
56   struct curltime time; /* when the shared creds was created */
57   size_t refcount;
58   BIT(trust_setup); /* x509 anchors + CRLs have been set up */
59 };
60 
61 CURLcode Curl_gtls_shared_creds_create(struct Curl_easy *data,
62                                        struct gtls_shared_creds **pcreds);
63 CURLcode Curl_gtls_shared_creds_up_ref(struct gtls_shared_creds *creds);
64 void Curl_gtls_shared_creds_free(struct gtls_shared_creds **pcreds);
65 
66 struct gtls_ctx {
67   gnutls_session_t session;
68   struct gtls_shared_creds *shared_creds;
69 #ifdef USE_GNUTLS_SRP
70   gnutls_srp_client_credentials_t srp_client_cred;
71 #endif
72   CURLcode io_result; /* result of last IO cfilter operation */
73   BIT(sent_shutdown);
74 };
75 
76 size_t Curl_gtls_version(char *buffer, size_t size);
77 
78 typedef CURLcode Curl_gtls_ctx_setup_cb(struct Curl_cfilter *cf,
79                                         struct Curl_easy *data,
80                                         void *user_data);
81 
82 typedef CURLcode Curl_gtls_init_session_reuse_cb(struct Curl_cfilter *cf,
83                                                  struct Curl_easy *data,
84                                                  struct Curl_ssl_session *scs,
85                                                  bool *do_early_data);
86 
87 CURLcode Curl_gtls_ctx_init(struct gtls_ctx *gctx,
88                             struct Curl_cfilter *cf,
89                             struct Curl_easy *data,
90                             struct ssl_peer *peer,
91                             const unsigned char *alpn, size_t alpn_len,
92                             Curl_gtls_ctx_setup_cb *cb_setup,
93                             void *cb_user_data,
94                             void *ssl_user_data,
95                             Curl_gtls_init_session_reuse_cb *sess_reuse_cb);
96 
97 CURLcode Curl_gtls_client_trust_setup(struct Curl_cfilter *cf,
98                                       struct Curl_easy *data,
99                                       struct gtls_ctx *gtls);
100 
101 CURLcode Curl_gtls_verifyserver(struct Curl_easy *data,
102                                 gnutls_session_t session,
103                                 struct ssl_primary_config *config,
104                                 struct ssl_config_data *ssl_config,
105                                 struct ssl_peer *peer,
106                                 const char *pinned_key);
107 
108 /* Extract TLS session and place in cache, if configured. */
109 CURLcode Curl_gtls_cache_session(struct Curl_cfilter *cf,
110                                  struct Curl_easy *data,
111                                  const char *ssl_peer_key,
112                                  gnutls_session_t session,
113                                  curl_off_t valid_until,
114                                  const char *alpn,
115                                  unsigned char *quic_tp,
116                                  size_t quic_tp_len);
117 
118 extern const struct Curl_ssl Curl_ssl_gnutls;
119 
120 #endif /* USE_GNUTLS */
121 #endif /* HEADER_CURL_GTLS_H */
122