[package] firewall: make ESTABLISHED,RELATED rules match before INVALID, use conntrac...
[openwrt.git] / package / uhttpd / src / uhttpd-tls.c
1 /*
2 * uhttpd - Tiny single-threaded httpd - TLS helper
3 *
4 * Copyright (C) 2010 Jo-Philipp Wich <xm@subsignal.org>
5 *
6 * Licensed under the Apache License, Version 2.0 (the "License");
7 * you may not use this file except in compliance with the License.
8 * You may obtain a copy of the License at
9 *
10 * http://www.apache.org/licenses/LICENSE-2.0
11 *
12 * Unless required by applicable law or agreed to in writing, software
13 * distributed under the License is distributed on an "AS IS" BASIS,
14 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
15 * See the License for the specific language governing permissions and
16 * limitations under the License.
17 */
18
19 #include "uhttpd.h"
20 #include "uhttpd-tls.h"
21 #include "uhttpd-utils.h"
22
23
24 SSL_CTX * uh_tls_ctx_init()
25 {
26 SSL_CTX *c;
27
28 SSL_load_error_strings();
29 SSL_library_init();
30
31 if( (c = SSL_CTX_new(TLSv1_server_method())) != NULL )
32 SSL_CTX_set_verify(c, SSL_VERIFY_NONE, NULL);
33
34 return c;
35 }
36
37 int uh_tls_ctx_cert(SSL_CTX *c, const char *file)
38 {
39 int rv;
40
41 if( (rv = SSL_CTX_use_certificate_file(c, file, SSL_FILETYPE_PEM)) < 1 )
42 rv = SSL_CTX_use_certificate_file(c, file, SSL_FILETYPE_ASN1);
43
44 return rv;
45 }
46
47 int uh_tls_ctx_key(SSL_CTX *c, const char *file)
48 {
49 int rv;
50
51 if( (rv = SSL_CTX_use_PrivateKey_file(c, file, SSL_FILETYPE_PEM)) < 1 )
52 rv = SSL_CTX_use_PrivateKey_file(c, file, SSL_FILETYPE_ASN1);
53
54 return rv;
55 }
56
57 void uh_tls_ctx_free(struct listener *l)
58 {
59 SSL_CTX_free(l->tls);
60 }
61
62
63 int uh_tls_client_accept(struct client *c)
64 {
65 int rv;
66
67 if( c->server && c->server->tls )
68 {
69 c->tls = SSL_new(c->server->tls);
70 if( c->tls )
71 {
72 if( (rv = SSL_set_fd(c->tls, c->socket)) < 1 )
73 goto cleanup;
74 if( (rv = SSL_accept(c->tls)) < 1 )
75 goto cleanup;
76 }
77 else
78 rv = 0;
79 }
80 else
81 {
82 c->tls = NULL;
83 rv = 1;
84 }
85
86 done:
87 return rv;
88
89 cleanup:
90 SSL_free(c->tls);
91 c->tls = NULL;
92 goto done;
93 }
94
95 int uh_tls_client_recv(struct client *c, void *buf, int len)
96 {
97 int rv = SSL_read(c->tls, buf, len);
98 return (rv > 0) ? rv : -1;
99 }
100
101 int uh_tls_client_send(struct client *c, void *buf, int len)
102 {
103 int rv = SSL_write(c->tls, buf, len);
104 return (rv > 0) ? rv : -1;
105 }
106
107 void uh_tls_client_close(struct client *c)
108 {
109 if( c->tls )
110 {
111 SSL_shutdown(c->tls);
112 SSL_free(c->tls);
113
114 c->tls = NULL;
115 }
116 }
This page took 0.049616 seconds and 5 git commands to generate.