AppleTLSContext.h 3.1 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697
  1. /* <!-- copyright */
  2. /*
  3. * aria2 - The high speed download utility
  4. *
  5. * Copyright (C) 2013 Nils Maier
  6. *
  7. * This program is free software; you can redistribute it and/or modify
  8. * it under the terms of the GNU General Public License as published by
  9. * the Free Software Foundation; either version 2 of the License, or
  10. * (at your option) any later version.
  11. *
  12. * This program is distributed in the hope that it will be useful,
  13. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  14. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  15. * GNU General Public License for more details.
  16. *
  17. * You should have received a copy of the GNU General Public License
  18. * along with this program; if not, write to the Free Software
  19. * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
  20. *
  21. * In addition, as a special exception, the copyright holders give
  22. * permission to link the code of portions of this program with the
  23. * OpenSSL library under certain conditions as described in each
  24. * individual source file, and distribute linked combinations
  25. * including the two.
  26. * You must obey the GNU General Public License in all respects
  27. * for all of the code used other than OpenSSL. If you modify
  28. * file(s) with this exception, you may extend this exception to your
  29. * version of the file(s), but you are not obligated to do so. If you
  30. * do not wish to do so, delete this exception statement from your
  31. * version. If you delete this exception statement from all source
  32. * files in the program, then also delete it here.
  33. */
  34. /* copyright --> */
  35. #ifndef D_APPLE_TLS_CONTEXT_H
  36. #define D_APPLE_TLS_CONTEXT_H
  37. #include "common.h"
  38. #include <string>
  39. #include <Security/Security.h>
  40. #include <Security/SecureTransport.h>
  41. #include "TLSContext.h"
  42. #include "DlAbortEx.h"
  43. namespace aria2 {
  44. class AppleTLSContext : public TLSContext {
  45. public:
  46. AppleTLSContext(TLSSessionSide side, TLSVersion ver)
  47. : side_(side), minTLSVer_(ver), verifyPeer_(true), credentials_(nullptr)
  48. {
  49. }
  50. virtual ~AppleTLSContext();
  51. // private key `keyfile' must be decrypted.
  52. virtual bool addCredentialFile(const std::string& certfile,
  53. const std::string& keyfile) CXX11_OVERRIDE;
  54. virtual bool addSystemTrustedCACerts() CXX11_OVERRIDE { return true; }
  55. // certfile can contain multiple certificates.
  56. virtual bool addTrustedCACertFile(const std::string& certfile) CXX11_OVERRIDE;
  57. virtual bool good() const CXX11_OVERRIDE { return true; }
  58. virtual TLSSessionSide getSide() const CXX11_OVERRIDE { return side_; }
  59. virtual bool getVerifyPeer() const CXX11_OVERRIDE { return verifyPeer_; }
  60. virtual void setVerifyPeer(bool verify) CXX11_OVERRIDE
  61. {
  62. verifyPeer_ = verify;
  63. }
  64. SecIdentityRef getCredentials();
  65. TLSVersion getMinTLSVersion() const { return minTLSVer_; }
  66. private:
  67. TLSSessionSide side_;
  68. TLSVersion minTLSVer_;
  69. bool verifyPeer_;
  70. SecIdentityRef credentials_;
  71. bool tryAsFingerprint(const std::string& fingerprint);
  72. bool tryAsPKCS12(const std::string& certfile);
  73. bool tryAsPKCS12(CFDataRef data, const char* password);
  74. };
  75. } // namespace aria2
  76. #endif // D_LIBSSL_TLS_CONTEXT_H