AppleTLSContext.h 3.1 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48
/* <!-- copyright */
/*
 * aria2 - The high speed download utility
 *
 * Copyright (C) 2013 Nils Maier
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published by
 * the Free Software Foundation; either version 2 of the License, or
 * (at your option) any later version.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, write to the Free Software
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
 *
 * In addition, as a special exception, the copyright holders give
 * permission to link the code of portions of this program with the
 * OpenSSL library under certain conditions as described in each
 * individual source file, and distribute linked combinations
 * including the two.
 * You must obey the GNU General Public License in all respects
 * for all of the code used other than OpenSSL.  If you modify
 * file(s) with this exception, you may extend this exception to your
 * version of the file(s), but you are not obligated to do so.  If you
 * do not wish to do so, delete this exception statement from your
 * version.  If you delete this exception statement from all source
 * files in the program, then also delete it here.
 */
/* copyright --> */
#ifndef D_APPLE_TLS_CONTEXT_H
#define D_APPLE_TLS_CONTEXT_H

#include "common.h"

#include <string>
#include <Security/Security.h>
#include <Security/SecureTransport.h>

#include "TLSContext.h"
#include "DlAbortEx.h"

namespace aria2 {

49
class AppleTLSContext : public TLSContext {
50
public:
51 52 53 54
  AppleTLSContext(TLSSessionSide side, TLSVersion ver)
      : side_(side), minTLSVer_(ver), verifyPeer_(true), credentials_(nullptr)
  {
  }
55 56 57 58 59

  virtual ~AppleTLSContext();

  // private key `keyfile' must be decrypted.
  virtual bool addCredentialFile(const std::string& certfile,
60
                                 const std::string& keyfile) CXX11_OVERRIDE;
61

62
  virtual bool addSystemTrustedCACerts() CXX11_OVERRIDE { return true; }
63 64

  // certfile can contain multiple certificates.
65
  virtual bool addTrustedCACertFile(const std::string& certfile) CXX11_OVERRIDE;
66

67
  virtual bool good() const CXX11_OVERRIDE { return true; }
68

69
  virtual TLSSessionSide getSide() const CXX11_OVERRIDE { return side_; }
70

71
  virtual bool getVerifyPeer() const CXX11_OVERRIDE { return verifyPeer_; }
72 73 74

  virtual void setVerifyPeer(bool verify) CXX11_OVERRIDE
  {
75 76 77 78 79
    verifyPeer_ = verify;
  }

  SecIdentityRef getCredentials();

80 81
  TLSVersion getMinTLSVersion() const { return minTLSVer_; }

82 83
private:
  TLSSessionSide side_;
84
  TLSVersion minTLSVer_;
85 86 87 88
  bool verifyPeer_;
  SecIdentityRef credentials_;

  bool tryAsFingerprint(const std::string& fingerprint);
89

90
  bool tryAsPKCS12(const std::string& certfile);
91

92
  bool tryAsPKCS12(CFDataRef data, const char* password);
93 94 95 96 97
};

} // namespace aria2

#endif // D_LIBSSL_TLS_CONTEXT_H