acl/lib_acl_cpp/include/acl_cpp/stream/openssl_conf.hpp

148 lines
3.5 KiB
C++
Raw Normal View History

2022-08-20 19:31:37 +08:00
#pragma once
#include "../acl_cpp_define.hpp"
#include <vector>
#include <set>
#include "../stdlib/thread_mutex.hpp"
2022-08-21 17:34:05 +08:00
#include "../stdlib/string.hpp"
#include "../stdlib/token_tree.hpp"
2022-08-20 19:31:37 +08:00
#include "sslbase_conf.hpp"
typedef struct ssl_st SSL;
typedef struct ssl_ctx_st SSL_CTX;
2022-08-20 19:31:37 +08:00
namespace acl {
class token_tree;
2022-08-20 19:31:37 +08:00
class openssl_io;
class ACL_CPP_API openssl_conf : public sslbase_conf {
public:
2022-08-29 18:40:15 +08:00
openssl_conf(bool server_side = false, int timeout = 30);
2022-08-20 19:31:37 +08:00
~openssl_conf(void);
/**
* @override
*/
bool load_ca(const char* ca_file, const char* ca_path);
/**
* @override
*/
2022-08-20 21:32:08 +08:00
bool add_cert(const char* crt_file, const char* key_file,
2022-08-20 19:31:37 +08:00
const char* key_pass = NULL);
2022-08-21 17:34:05 +08:00
/**
* @override
* @deprecate use add_cert(const char*, const char*, const char*)
*/
bool add_cert(const char* crt_file);
/**
* @override
* @deprecate use add_cert(const char*, const char*, const char*)
*/
bool set_key(const char* key_file, const char* key_pass);
2022-08-20 19:31:37 +08:00
/**
* @override
*/
void enable_cache(bool on);
public:
/**
2022-08-22 22:32:23 +08:00
* <EFBFBD><EFBFBD><EFBFBD>ñ<EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>һ<EFBFBD><EFBFBD><EFBFBD><EFBFBD>̬<EFBFBD><EFBFBD><EFBFBD><EFBFBD>ȫ·<EFBFBD><EFBFBD>
* @param libcrypto {const char*} libcrypto.so <EFBFBD><EFBFBD>̬<EFBFBD><EFBFBD><EFBFBD><EFBFBD>ȫ·<EFBFBD><EFBFBD>
* @param libssl {const char*} libssl.so <EFBFBD><EFBFBD>̬<EFBFBD><EFBFBD><EFBFBD><EFBFBD>ȫ·<EFBFBD><EFBFBD>
*/
2022-08-22 22:03:38 +08:00
static void set_libpath(const char* libcrypto, const char* libssl);
/**
2022-08-22 22:32:23 +08:00
* <EFBFBD><EFBFBD>ʽ<EFBFBD><EFBFBD><EFBFBD>ñ<EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>̬<EFBFBD><EFBFBD><EFBFBD><EFBFBD> libssl.so <EFBFBD><EFBFBD>̬<EFBFBD><EFBFBD>
* @return {bool} <EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>Ƿ<EFBFBD><EFBFBD>ɹ<EFBFBD>
*/
static bool load(void);
/**
* <EFBFBD><EFBFBD><EFBFBD><EFBFBD> load() <EFBFBD>ɹ<EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> OpenSSL <EFBFBD><EFBFBD>̬<EFBFBD><EFBFBD><EFBFBD>󣬵<EFBFBD><EFBFBD>ñ<EFBFBD><EFBFBD><EFBFBD>̬<EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> libssl
* <EFBFBD><EFBFBD>̬<EFBFBD><EFBFBD><EFBFBD>ؿ<EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>Ӷ<EFBFBD><EFBFBD><EFBFBD><EFBFBD>ԴӸþ<EFBFBD><EFBFBD><EFBFBD><EFBFBD>л<EFBFBD><EFBFBD><EFBFBD>ָ<EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>ָ<EFBFBD><EFBFBD>
* @return {void*} <EFBFBD><EFBFBD><EFBFBD><EFBFBD> NULL <EFBFBD><EFBFBD>ʾ<EFBFBD><EFBFBD>δ<EFBFBD><EFBFBD><EFBFBD><EFBFBD>
*/
static void* get_libssl_handle(void);
/**
* <EFBFBD><EFBFBD><EFBFBD><EFBFBD> libcrypto <EFBFBD><EFBFBD>̬<EFBFBD><EFBFBD><EFBFBD>ؿ<EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>
* @return {void*} <EFBFBD><EFBFBD><EFBFBD><EFBFBD> NULL <EFBFBD><EFBFBD>ʾ<EFBFBD><EFBFBD>δ<EFBFBD><EFBFBD><EFBFBD><EFBFBD>
*/
static void* get_libcrypto_handle(void);
2022-08-20 19:31:37 +08:00
public:
// @override sslbase_conf
sslbase_io* create(bool nblock);
public:
bool setup_certs(void* ssl);
/**
* <EFBFBD>Ƿ<EFBFBD>Ϊ SSL <EFBFBD><EFBFBD><EFBFBD><EFBFBD>ģʽ
* @return {bool}
*/
2023-02-11 10:45:44 +08:00
bool is_server_side(void) const {
2022-08-20 19:31:37 +08:00
return server_side_;
}
/**
2023-02-11 10:45:44 +08:00
* <EFBFBD><EFBFBD><EFBFBD><EFBFBD>ȱʡ<EFBFBD><EFBFBD>SSL_CTX<EFBFBD><EFBFBD><EFBFBD><EFBFBD>
* @return {SSL_CTX*}
*/
SSL_CTX* get_ssl_ctx(void) const;
2022-08-20 19:31:37 +08:00
2023-02-13 14:33:13 +08:00
/**
* <EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>е<EFBFBD><EFBFBD>Ѿ<EFBFBD><EFBFBD><EFBFBD>ʼ<EFBFBD><EFBFBD><EFBFBD>ɵ<EFBFBD> SSL_CTX <EFBFBD><EFBFBD><EFBFBD><EFBFBD>
* @param out {std::vector<SSL_CTX*>&}
*/
void get_ssl_ctxes(std::vector<SSL_CTX*>& out);
/**
2023-02-11 10:45:44 +08:00
* <EFBFBD><EFBFBD><EFBFBD><EFBFBD>ģʽ<EFBFBD><EFBFBD>,<EFBFBD><EFBFBD><EFBFBD><EFBFBD> SSL_CTX <EFBFBD><EFBFBD><EFBFBD><EFBFBD>,<EFBFBD>ڲ<EFBFBD><EFBFBD>Զ<EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> SNI <EFBFBD>ص<EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>,<EFBFBD><EFBFBD>Ȼ<EFBFBD>ڲ<EFBFBD>Ҳ<EFBFBD><EFBFBD>
* ͨ<EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> SSL_CTX_new() API <EFBFBD><EFBFBD><EFBFBD><EFBFBD> SSL_CTX <EFBFBD><EFBFBD><EFBFBD><EFBFBD>,<EFBFBD><EFBFBD><EFBFBD>ڲ<EFBFBD><EFBFBD><EFBFBD><EFBFBD>Զ<EFBFBD><EFBFBD><EFBFBD><EFBFBD>ֶ<EFBFBD>̬
* <EFBFBD><EFBFBD><EFBFBD>ػ<EFBFBD><EFBFBD><EFBFBD>̬<EFBFBD><EFBFBD><EFBFBD>ص<EFBFBD> SSL_CTX_new() API.
* @return {SSL_CTX*} <EFBFBD><EFBFBD><EFBFBD><EFBFBD> NULL <EFBFBD><EFBFBD>ʾδ<EFBFBD><EFBFBD><EFBFBD><EFBFBD> OpenSSL <EFBFBD><EFBFBD><EFBFBD><EFBFBD>
*/
SSL_CTX* create_ssl_ctx(void);
/**
* <EFBFBD><EFBFBD><EFBFBD><EFBFBD>ģʽ<EFBFBD><EFBFBD>, <EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>ⲿ<EFBFBD>Ѿ<EFBFBD><EFBFBD><EFBFBD>ʼ<EFBFBD><EFBFBD><EFBFBD>ϵ<EFBFBD> SSL_CTX, <EFBFBD>ö<EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>
* create_ssl_ctx() <EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>,<EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>̬<EFBFBD><EFBFBD><EFBFBD><EFBFBD>̬<EFBFBD><EFBFBD><EFBFBD><EFBFBD> OpenSSL <EFBFBD>IJ<EFBFBD>ͬ<EFBFBD><EFBFBD>ʽ.
* @param {SSL_CTX*} <EFBFBD><EFBFBD><EFBFBD>û<EFBFBD><EFBFBD><EFBFBD><EFBFBD>Լ<EFBFBD><EFBFBD><EFBFBD>ʼ<EFBFBD><EFBFBD><EFBFBD>õ<EFBFBD> SSL_CTX <EFBFBD><EFBFBD><EFBFBD>󣬴<EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>
* Ȩ<EFBFBD><EFBFBD><EFBFBD><EFBFBD> openssl_conf <EFBFBD>ڲ<EFBFBD>ͳһ<EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>ͷ<EFBFBD>
*/
void push_ssl_ctx(SSL_CTX* ctx);
2022-08-20 19:31:37 +08:00
private:
friend class openssl_io;
bool server_side_;
SSL_CTX* ssl_ctx_; // The default SSL_CTX.
token_tree* ssl_ctx_table_; // Holding the map of host/SSL_CTX.
int ssl_ctx_count_;
std::set<SSL_CTX*> ssl_ctxes_; // Holding all ctx just for freeing.
int timeout_;
string crt_file_;
unsigned init_status_;
thread_mutex lock_;
bool init_once(void);
void add_ssl_ctx(SSL_CTX* ctx);
SSL_CTX* find_ssl_ctx(const char* host);
void get_hosts(const SSL_CTX* ctx, std::vector<string>& hosts);
size_t bind_host(SSL_CTX* ctx, string& host);
bool create_host_key(string& host, string& key, size_t skip = 0);
int on_sni_callback(SSL* ssl, const char*host);
static int sni_callback(SSL *ssl, int *ad, void *arg);
2022-08-20 19:31:37 +08:00
};
} // namespace acl