src/context.c

Sun, 12 Dec 2010 22:21:36 +0000

author
Matthew Wild <mwild1@gmail.com>
date
Sun, 12 Dec 2010 22:21:36 +0000
changeset 36
96f23601ce7a
parent 34
510432315106
child 38
4ecd7b0e67ea
permissions
-rw-r--r--

context.c: Add crl_check and crl_check_chain verify options

0
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
1 /*--------------------------------------------------------------------------
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
2 * LuaSec 0.4
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
3 * Copyright (C) 2006-2009 Bruno Silvestre
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
4 *
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
5 *--------------------------------------------------------------------------*/
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
6
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
7 #include <string.h>
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
8 #include <openssl/ssl.h>
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
9 #include <openssl/err.h>
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
10
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
11 #include <lua.h>
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
12 #include <lauxlib.h>
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
13
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
14 #include "context.h"
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
15
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
16 struct ssl_option_s {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
17 const char *name;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
18 unsigned long code;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
19 };
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
20 typedef struct ssl_option_s ssl_option_t;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
21
34
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
22 int luasec_ssl_idx = -1;
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
23
28
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
24 /* The export DH key */
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
25 static DH *dh_512 = NULL;
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
26 /* The larger key (builtin is 2048, caller may specify larger) */
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
27 static DH *dh_larger = NULL;
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
28
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
29 /* Generated via "openssl dhparam -2 -noout -C 512 2>/dev/null" */
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
30 static unsigned char dh512_p[] = {
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
31 0xE4,0x3F,0x75,0x82,0xAD,0x0B,0x28,0xC7,0xEF,0xCE,0xBC,0x3B,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
32 0x14,0xBB,0xA6,0xF4,0xA2,0xE9,0xA6,0x59,0xCF,0x97,0x1C,0x86,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
33 0x43,0x3B,0x92,0x4A,0x6B,0x15,0x4B,0x0C,0xAC,0x8F,0xFA,0x43,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
34 0xE2,0xA8,0xC3,0x3B,0x7B,0x51,0x1B,0x46,0x21,0xBF,0x8C,0x06,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
35 0x6C,0xB1,0x49,0x75,0xC7,0xAC,0x47,0x1D,0x9D,0x64,0xD5,0x99,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
36 0x33,0x86,0xAD,0xEB,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
37 };
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
38
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
39 /* Generated via "openssl dhparam -2 -noout -C 2048 2>/dev/null" */
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
40 static unsigned char dh2048_p[] = {
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
41 0x9B,0xF4,0xC5,0x57,0x81,0x8F,0xCF,0x31,0x78,0x95,0x04,0xCD,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
42 0xEA,0xCC,0x30,0xEA,0xF7,0xCA,0x76,0xC8,0x8F,0x91,0xEA,0x0E,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
43 0x44,0x8D,0xE2,0x63,0x19,0x3B,0x4D,0x04,0xC8,0x7D,0x0D,0xFF,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
44 0x3D,0x52,0x76,0x02,0xF3,0xCA,0x1C,0x44,0xAF,0x0E,0xA9,0x59,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
45 0x02,0x40,0x75,0xD6,0xED,0x35,0x4D,0x11,0x5B,0x2B,0x73,0x23,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
46 0xE5,0x53,0x0B,0x1F,0xB0,0x47,0xC4,0x7F,0x95,0x5D,0xB0,0xD5,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
47 0xF3,0xD3,0xAB,0x5F,0x28,0x2B,0xEC,0x2C,0x15,0x0B,0x1B,0x0C,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
48 0xD4,0xBE,0x24,0x2F,0xC5,0x07,0x3C,0xE4,0xC5,0xE6,0x16,0x42,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
49 0x4C,0x31,0x04,0xBB,0x80,0x96,0xFF,0x64,0x50,0xA4,0xA5,0xB5,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
50 0xF5,0x3A,0xBA,0x57,0xE4,0xE6,0xC2,0x23,0x0A,0xB6,0x27,0xC4,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
51 0x06,0x01,0x1E,0x98,0x20,0x09,0xC8,0xB7,0x90,0x09,0x86,0x06,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
52 0xAA,0x85,0xE7,0x02,0xC8,0xC6,0xD9,0x1D,0xAB,0x17,0xEE,0x78,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
53 0x73,0x78,0x88,0x7F,0xA7,0xF2,0x34,0xA7,0xDD,0x02,0x16,0x36,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
54 0x0D,0x77,0x16,0x3E,0x95,0xAE,0x02,0xEE,0x36,0x37,0xD5,0x61,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
55 0x5D,0xFE,0xC6,0x0B,0xDF,0xCE,0xB9,0x26,0x31,0x6F,0x34,0x92,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
56 0xBB,0xBB,0x91,0x29,0x77,0x62,0x1D,0x75,0xA0,0x51,0x8D,0x31,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
57 0x4C,0x64,0x4E,0xBF,0xDC,0xE8,0x67,0x17,0x90,0x6A,0x80,0xE9,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
58 0xD7,0xD8,0x56,0x4E,0x85,0x21,0x9C,0xFB,0xE6,0x1B,0xD8,0x05,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
59 0xFD,0x13,0x77,0x00,0x96,0x2D,0x0C,0x2A,0x95,0x1A,0x08,0x82,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
60 0x2E,0xB3,0xE2,0xFC,0xE8,0xA6,0xF1,0x16,0x37,0x57,0x82,0xD6,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
61 0xF5,0xAB,0xA9,0x43,0x8F,0x33,0xB0,0x57,0x38,0x6E,0x61,0xD4,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
62 0xDD,0xE0,0x1C,0xCB,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
63 };
0
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
64
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
65 static ssl_option_t ssl_options[] = {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
66 /* OpenSSL 0.9.7 and 0.9.8 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
67 {"all", SSL_OP_ALL},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
68 {"cipher_server_preference", SSL_OP_CIPHER_SERVER_PREFERENCE},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
69 {"dont_insert_empty_fragments", SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
70 {"ephemeral_rsa", SSL_OP_EPHEMERAL_RSA},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
71 {"netscape_ca_dn_bug", SSL_OP_NETSCAPE_CA_DN_BUG},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
72 {"netscape_challenge_bug", SSL_OP_NETSCAPE_CHALLENGE_BUG},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
73 {"microsoft_big_sslv3_buffer", SSL_OP_MICROSOFT_BIG_SSLV3_BUFFER},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
74 {"microsoft_sess_id_bug", SSL_OP_MICROSOFT_SESS_ID_BUG},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
75 {"msie_sslv2_rsa_padding", SSL_OP_MSIE_SSLV2_RSA_PADDING},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
76 {"netscape_demo_cipher_change_bug", SSL_OP_NETSCAPE_DEMO_CIPHER_CHANGE_BUG},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
77 {"netscape_reuse_cipher_change_bug", SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
78 {"no_session_resumption_on_renegotiation",
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
79 SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
80 {"no_sslv2", SSL_OP_NO_SSLv2},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
81 {"no_sslv3", SSL_OP_NO_SSLv3},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
82 {"no_tlsv1", SSL_OP_NO_TLSv1},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
83 {"pkcs1_check_1", SSL_OP_PKCS1_CHECK_1},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
84 {"pkcs1_check_2", SSL_OP_PKCS1_CHECK_2},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
85 {"single_dh_use", SSL_OP_SINGLE_DH_USE},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
86 {"ssleay_080_client_dh_bug", SSL_OP_SSLEAY_080_CLIENT_DH_BUG},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
87 {"sslref2_reuse_cert_type_bug", SSL_OP_SSLREF2_REUSE_CERT_TYPE_BUG},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
88 {"tls_block_padding_bug", SSL_OP_TLS_BLOCK_PADDING_BUG},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
89 {"tls_d5_bug", SSL_OP_TLS_D5_BUG},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
90 {"tls_rollback_bug", SSL_OP_TLS_ROLLBACK_BUG},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
91 /* OpenSSL 0.9.8 only */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
92 #if OPENSSL_VERSION_NUMBER > 0x00908000L
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
93 {"cookie_exchange", SSL_OP_COOKIE_EXCHANGE},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
94 {"no_query_mtu", SSL_OP_NO_QUERY_MTU},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
95 {"single_ecdh_use", SSL_OP_SINGLE_ECDH_USE},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
96 #endif
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
97 /* OpenSSL 0.9.8f and above */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
98 #if defined(SSL_OP_NO_TICKET)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
99 {"no_ticket", SSL_OP_NO_TICKET},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
100 #endif
1
5f89e535765a context.c: Add no_compression option for when supported
Matthew Wild <mwild1@gmail.com>
parents: 0
diff changeset
101 #if defined(SSL_OP_NO_COMPRESSION)
5f89e535765a context.c: Add no_compression option for when supported
Matthew Wild <mwild1@gmail.com>
parents: 0
diff changeset
102 {"no_compression", SSL_OP_NO_COMPRESSION},
5f89e535765a context.c: Add no_compression option for when supported
Matthew Wild <mwild1@gmail.com>
parents: 0
diff changeset
103 #endif
0
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
104 {NULL, 0L}
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
105 };
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
106
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
107 /*--------------------------- Auxiliary Functions ----------------------------*/
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
108
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
109 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
110 * Return the context.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
111 */
34
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
112 p_context checkctx(lua_State *L, int idx)
0
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
113 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
114 return (p_context)luaL_checkudata(L, idx, "SSL:Context");
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
115 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
116
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
117 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
118 * Prepare the SSL options flag.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
119 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
120 static int set_option_flag(const char *opt, unsigned long *flag)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
121 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
122 ssl_option_t *p;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
123 for (p = ssl_options; p->name; p++) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
124 if (!strcmp(opt, p->name)) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
125 *flag |= p->code;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
126 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
127 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
128 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
129 return 0;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
130 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
131
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
132 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
133 * Find the protocol.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
134 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
135 static SSL_METHOD* str2method(const char *method)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
136 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
137 if (!strcmp(method, "sslv3")) return SSLv3_method();
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
138 if (!strcmp(method, "tlsv1")) return TLSv1_method();
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
139 if (!strcmp(method, "sslv23")) return SSLv23_method();
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
140 return NULL;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
141 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
142
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
143 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
144 * Prepare the SSL handshake verify flag.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
145 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
146 static int set_verify_flag(const char *str, int *flag)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
147 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
148 if (!strcmp(str, "none")) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
149 *flag |= SSL_VERIFY_NONE;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
150 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
151 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
152 if (!strcmp(str, "peer")) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
153 *flag |= SSL_VERIFY_PEER;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
154 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
155 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
156 if (!strcmp(str, "client_once")) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
157 *flag |= SSL_VERIFY_CLIENT_ONCE;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
158 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
159 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
160 if (!strcmp(str, "fail_if_no_peer_cert")) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
161 *flag |= SSL_VERIFY_FAIL_IF_NO_PEER_CERT;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
162 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
163 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
164 return 0;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
165 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
166
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
167 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
168 * Password callback for reading the private key.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
169 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
170 static int passwd_cb(char *buf, int size, int flag, void *udata)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
171 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
172 lua_State *L = (lua_State*)udata;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
173 switch (lua_type(L, 3)) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
174 case LUA_TFUNCTION:
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
175 lua_pushvalue(L, 3);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
176 lua_call(L, 0, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
177 if (lua_type(L, -1) != LUA_TSTRING)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
178 return 0;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
179 /* fallback */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
180 case LUA_TSTRING:
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
181 strncpy(buf, lua_tostring(L, -1), size);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
182 buf[size-1] = '\0';
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
183 return (int)strlen(buf);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
184 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
185 return 0;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
186 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
187
28
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
188 static DH *get_dh(const unsigned char *p, int len)
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
189 {
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
190 DH *dh = NULL;
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
191 static unsigned char g[] = { 0x02 };
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
192
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
193 if ((dh = DH_new()) == NULL) return NULL;
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
194 dh->p = BN_bin2bn(p, len, NULL);
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
195 dh->g = BN_bin2bn(g, sizeof(g), NULL);
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
196 if (dh->p == NULL || dh->g == NULL) {
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
197 DH_free(dh);
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
198 return NULL;
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
199 }
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
200
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
201 return dh;
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
202 }
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
203
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
204 /**
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
205 * DH parameter callback
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
206 */
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
207 static DH *dh_param_cb(SSL *ssl, int is_export, int keylength)
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
208 {
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
209 /* Logic in postfix and dovecot, but we're using a 2048-bit group... */
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
210 if (is_export && keylength == 512) {
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
211 if (dh_512 == NULL) { dh_512 = get_dh(dh512_p, sizeof(dh512_p)); }
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
212 return dh_512;
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
213 } else {
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
214 if (dh_larger == NULL) { dh_larger = get_dh(dh2048_p, sizeof(dh2048_p)); }
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
215 return dh_larger;
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
216 }
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
217 }
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
218
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
219
0
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
220 /*------------------------------ Lua Functions -------------------------------*/
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
221
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
222 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
223 * Create a SSL context.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
224 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
225 static int create(lua_State *L)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
226 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
227 p_context ctx;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
228 SSL_METHOD *method;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
229
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
230 method = str2method(luaL_checkstring(L, 1));
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
231 if (!method) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
232 lua_pushnil(L);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
233 lua_pushstring(L, "invalid protocol");
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
234 return 2;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
235 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
236 ctx = (p_context) lua_newuserdata(L, sizeof(t_context));
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
237 if (!ctx) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
238 lua_pushnil(L);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
239 lua_pushstring(L, "error creating context");
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
240 return 2;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
241 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
242 ctx->context = SSL_CTX_new(method);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
243 if (!ctx->context) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
244 lua_pushnil(L);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
245 lua_pushstring(L, "error creating context");
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
246 return 2;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
247 }
34
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
248 ctx->verify_flags = LUASEC_VERIFY_FLAGS_NONE;
0
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
249 ctx->mode = MD_CTX_INVALID;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
250 /* No session support */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
251 SSL_CTX_set_session_cache_mode(ctx->context, SSL_SESS_CACHE_OFF);
28
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
252 /*
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
253 * Support ephemeral diffie-hellman key exchange. This is only needed
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
254 * for server mode, but clearer to put it here rather than set_mode.
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
255 */
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
256 SSL_CTX_set_tmp_dh_callback(ctx->context, dh_param_cb);
0
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
257 luaL_getmetatable(L, "SSL:Context");
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
258 lua_setmetatable(L, -2);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
259 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
260 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
261
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
262 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
263 * Load the trusting certificates.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
264 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
265 static int load_locations(lua_State *L)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
266 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
267 SSL_CTX *ctx = ctx_getcontext(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
268 const char *cafile = luaL_optstring(L, 2, NULL);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
269 const char *capath = luaL_optstring(L, 3, NULL);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
270 if (SSL_CTX_load_verify_locations(ctx, cafile, capath) != 1) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
271 lua_pushboolean(L, 0);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
272 lua_pushfstring(L, "error loading CA locations (%s)",
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
273 ERR_reason_error_string(ERR_get_error()));
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
274 return 2;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
275 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
276 lua_pushboolean(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
277 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
278 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
279
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
280 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
281 * Load the certificate file.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
282 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
283 static int load_cert(lua_State *L)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
284 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
285 SSL_CTX *ctx = ctx_getcontext(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
286 const char *filename = luaL_checkstring(L, 2);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
287 if (SSL_CTX_use_certificate_chain_file(ctx, filename) != 1) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
288 lua_pushboolean(L, 0);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
289 lua_pushfstring(L, "error loading certificate (%s)",
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
290 ERR_reason_error_string(ERR_get_error()));
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
291 return 2;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
292 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
293 lua_pushboolean(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
294 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
295 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
296
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
297 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
298 * Load the key file -- only in PEM format.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
299 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
300 static int load_key(lua_State *L)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
301 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
302 int ret = 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
303 SSL_CTX *ctx = ctx_getcontext(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
304 const char *filename = luaL_checkstring(L, 2);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
305 switch (lua_type(L, 3)) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
306 case LUA_TSTRING:
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
307 case LUA_TFUNCTION:
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
308 SSL_CTX_set_default_passwd_cb(ctx, passwd_cb);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
309 SSL_CTX_set_default_passwd_cb_userdata(ctx, L);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
310 /* fallback */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
311 case LUA_TNIL:
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
312 if (SSL_CTX_use_PrivateKey_file(ctx, filename, SSL_FILETYPE_PEM) == 1)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
313 lua_pushboolean(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
314 else {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
315 ret = 2;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
316 lua_pushboolean(L, 0);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
317 lua_pushfstring(L, "error loading private key (%s)",
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
318 ERR_reason_error_string(ERR_get_error()));
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
319 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
320 SSL_CTX_set_default_passwd_cb(ctx, NULL);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
321 SSL_CTX_set_default_passwd_cb_userdata(ctx, NULL);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
322 break;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
323 default:
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
324 lua_pushstring(L, "invalid callback value");
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
325 lua_error(L);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
326 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
327 return ret;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
328 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
329
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
330 /**
28
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
331 * Load a DH params files. This is a global LuaSec thing.
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
332 */
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
333 static int load_dhparams(lua_State *L)
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
334 {
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
335 const char *filename = luaL_checkstring(L, 1);
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
336 FILE *paramfile;
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
337 DH *dh;
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
338
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
339 paramfile = fopen(filename, "r");
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
340 if (!paramfile) {
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
341 lua_pushboolean(L, 0);
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
342 lua_pushfstring(L, "error reading dh param file %s: %s", filename,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
343 strerror(errno));
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
344 return 2;
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
345 }
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
346
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
347 dh = PEM_read_DHparams(paramfile, NULL, NULL, NULL);
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
348 fclose(paramfile);
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
349 if (!dh) {
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
350 lua_pushboolean(L, 0);
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
351 lua_pushfstring(L, "error loading dh param file %s: %s", filename,
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
352 ERR_reason_error_string(ERR_get_error()));
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
353 return 2;
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
354 }
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
355
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
356 if (dh_larger)
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
357 DH_free(dh_larger);
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
358
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
359 dh_larger = dh;
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
360
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
361 lua_pushboolean(L, 1);
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
362 return 1;
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
363 }
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
364
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
365 /**
0
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
366 * Set the cipher list.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
367 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
368 static int set_cipher(lua_State *L)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
369 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
370 SSL_CTX *ctx = ctx_getcontext(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
371 const char *list = luaL_checkstring(L, 2);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
372 if (SSL_CTX_set_cipher_list(ctx, list) != 1) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
373 lua_pushboolean(L, 0);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
374 lua_pushfstring(L, "error setting cipher list (%s)",
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
375 ERR_reason_error_string(ERR_get_error()));
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
376 return 2;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
377 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
378 lua_pushboolean(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
379 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
380 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
381
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
382 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
383 * Set the depth for certificate checking.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
384 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
385 static int set_depth(lua_State *L)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
386 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
387 SSL_CTX *ctx = ctx_getcontext(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
388 SSL_CTX_set_verify_depth(ctx, luaL_checkint(L, 2));
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
389 lua_pushboolean(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
390 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
391 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
392
30
36ed99e1ce1e ssl.core, context: Add ability to verify and continue, retrieve verification result
Paul Aurich <paul@darkrain42.org>
parents: 28
diff changeset
393 int verify_cb(int preverify_ok, X509_STORE_CTX *x509_ctx)
36ed99e1ce1e ssl.core, context: Add ability to verify and continue, retrieve verification result
Paul Aurich <paul@darkrain42.org>
parents: 28
diff changeset
394 {
34
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
395 SSL *ssl;
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
396 p_context ctx = NULL;
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
397
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
398 /* Short-circuit optimization */
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
399 if (preverify_ok)
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
400 return 1;
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
401
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
402 ssl = X509_STORE_CTX_get_ex_data(x509_ctx, SSL_get_ex_data_X509_STORE_CTX_idx());
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
403 ctx = SSL_get_ex_data(ssl, luasec_ssl_idx);
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
404
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
405 if (ctx->verify_flags & LUASEC_VERIFY_FLAGS_IGNORE_PURPOSE) {
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
406 int err, depth;
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
407
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
408 err = X509_STORE_CTX_get_error(x509_ctx);
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
409 depth = X509_STORE_CTX_get_error_depth(x509_ctx);
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
410
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
411 if (depth == 0 && err == X509_V_ERR_INVALID_PURPOSE) {
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
412 /* You see nothing! */
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
413 X509_STORE_CTX_set_error(x509_ctx, X509_V_OK);
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
414 preverify_ok = 1;
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
415 }
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
416 }
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
417 return (ctx->verify_flags & LUASEC_VERIFY_FLAGS_ALWAYS_CONTINUE ? 1 : preverify_ok);
30
36ed99e1ce1e ssl.core, context: Add ability to verify and continue, retrieve verification result
Paul Aurich <paul@darkrain42.org>
parents: 28
diff changeset
418 }
36ed99e1ce1e ssl.core, context: Add ability to verify and continue, retrieve verification result
Paul Aurich <paul@darkrain42.org>
parents: 28
diff changeset
419
0
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
420 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
421 * Set the handshake verify options.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
422 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
423 static int set_verify(lua_State *L)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
424 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
425 int i;
36
96f23601ce7a context.c: Add crl_check and crl_check_chain verify options
Matthew Wild <mwild1@gmail.com>
parents: 34
diff changeset
426 int flag = 0, vflag = 0;
30
36ed99e1ce1e ssl.core, context: Add ability to verify and continue, retrieve verification result
Paul Aurich <paul@darkrain42.org>
parents: 28
diff changeset
427 int ignore_errors = 0;
34
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
428 p_context ctx = checkctx(L, 1);
0
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
429 int max = lua_gettop(L);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
430 /* any flag? */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
431 if (max > 1) {
34
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
432 ctx->verify_flags = LUASEC_VERIFY_FLAGS_NONE;
0
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
433 for (i = 2; i <= max; i++) {
30
36ed99e1ce1e ssl.core, context: Add ability to verify and continue, retrieve verification result
Paul Aurich <paul@darkrain42.org>
parents: 28
diff changeset
434 const char *s = luaL_checkstring(L, i);
36ed99e1ce1e ssl.core, context: Add ability to verify and continue, retrieve verification result
Paul Aurich <paul@darkrain42.org>
parents: 28
diff changeset
435 if (!strcmp(s, "continue")) {
34
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
436 ctx->verify_flags |= LUASEC_VERIFY_FLAGS_ALWAYS_CONTINUE;
30
36ed99e1ce1e ssl.core, context: Add ability to verify and continue, retrieve verification result
Paul Aurich <paul@darkrain42.org>
parents: 28
diff changeset
437 ignore_errors = 1;
34
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
438 } else if (!strcmp(s, "ignore_purpose")) {
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
439 ctx->verify_flags |= LUASEC_VERIFY_FLAGS_IGNORE_PURPOSE;
36
96f23601ce7a context.c: Add crl_check and crl_check_chain verify options
Matthew Wild <mwild1@gmail.com>
parents: 34
diff changeset
440 } else if (!strcmp(s, "crl_check")) {
96f23601ce7a context.c: Add crl_check and crl_check_chain verify options
Matthew Wild <mwild1@gmail.com>
parents: 34
diff changeset
441 vflag |= X509_V_FLAG_CRL_CHECK;
96f23601ce7a context.c: Add crl_check and crl_check_chain verify options
Matthew Wild <mwild1@gmail.com>
parents: 34
diff changeset
442 } else if (!strcmp(s, "crl_check_chain")) {
96f23601ce7a context.c: Add crl_check and crl_check_chain verify options
Matthew Wild <mwild1@gmail.com>
parents: 34
diff changeset
443 vflag |= X509_V_FLAG_CRL_CHECK_ALL;
30
36ed99e1ce1e ssl.core, context: Add ability to verify and continue, retrieve verification result
Paul Aurich <paul@darkrain42.org>
parents: 28
diff changeset
444 } else if (!set_verify_flag(s, &flag)) {
0
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
445 lua_pushboolean(L, 0);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
446 lua_pushstring(L, "invalid verify option");
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
447 return 2;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
448 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
449 }
34
510432315106 verify: Flag to ignore 'invalid purpose' errors on end cert
Paul Aurich <paul@darkrain42.org>
parents: 30
diff changeset
450 SSL_CTX_set_verify(ctx->context, flag, ctx->verify_flags ? verify_cb : NULL);
36
96f23601ce7a context.c: Add crl_check and crl_check_chain verify options
Matthew Wild <mwild1@gmail.com>
parents: 34
diff changeset
451 if(vflag)
96f23601ce7a context.c: Add crl_check and crl_check_chain verify options
Matthew Wild <mwild1@gmail.com>
parents: 34
diff changeset
452 {
96f23601ce7a context.c: Add crl_check and crl_check_chain verify options
Matthew Wild <mwild1@gmail.com>
parents: 34
diff changeset
453 X509_STORE *store = SSL_CTX_get_cert_store(ctx->context);
96f23601ce7a context.c: Add crl_check and crl_check_chain verify options
Matthew Wild <mwild1@gmail.com>
parents: 34
diff changeset
454 X509_STORE_set_flags(store, vflag);
96f23601ce7a context.c: Add crl_check and crl_check_chain verify options
Matthew Wild <mwild1@gmail.com>
parents: 34
diff changeset
455 }
0
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
456 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
457 lua_pushboolean(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
458 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
459 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
460
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
461 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
462 * Set the protocol options.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
463 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
464 static int set_options(lua_State *L)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
465 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
466 int i;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
467 unsigned long flag = 0L;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
468 SSL_CTX *ctx = ctx_getcontext(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
469 int max = lua_gettop(L);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
470 /* any option? */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
471 if (max > 1) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
472 for (i = 2; i <= max; i++) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
473 if (!set_option_flag(luaL_checkstring(L, i), &flag)) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
474 lua_pushboolean(L, 0);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
475 lua_pushstring(L, "invalid option");
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
476 return 2;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
477 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
478 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
479 SSL_CTX_set_options(ctx, flag);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
480 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
481 lua_pushboolean(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
482 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
483 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
484
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
485 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
486 * Set the context mode.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
487 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
488 static int set_mode(lua_State *L)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
489 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
490 p_context ctx = checkctx(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
491 const char *str = luaL_checkstring(L, 2);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
492 if (!strcmp("server", str)) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
493 ctx->mode = MD_CTX_SERVER;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
494 lua_pushboolean(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
495 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
496 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
497 if(!strcmp("client", str)) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
498 ctx->mode = MD_CTX_CLIENT;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
499 lua_pushboolean(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
500 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
501 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
502 lua_pushboolean(L, 0);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
503 lua_pushstring(L, "invalid mode");
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
504 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
505 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
506
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
507 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
508 * Return a pointer to SSL_CTX structure.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
509 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
510 static int raw_ctx(lua_State *L)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
511 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
512 p_context ctx = checkctx(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
513 lua_pushlightuserdata(L, (void*)ctx->context);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
514 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
515 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
516
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
517 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
518 * Package functions
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
519 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
520 static luaL_Reg funcs[] = {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
521 {"create", create},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
522 {"locations", load_locations},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
523 {"loadcert", load_cert},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
524 {"loadkey", load_key},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
525 {"setcipher", set_cipher},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
526 {"setdepth", set_depth},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
527 {"setverify", set_verify},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
528 {"setoptions", set_options},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
529 {"setmode", set_mode},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
530 {"rawcontext", raw_ctx},
28
8c61b29d87ec context: support for diffie-hellman key exchange
Paul Aurich <paul@darkrain42.org>
parents: 1
diff changeset
531 {"loaddhparams", load_dhparams},
0
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
532 {NULL, NULL}
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
533 };
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
534
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
535 /*-------------------------------- Metamethods -------------------------------*/
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
536
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
537 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
538 * Collect SSL context -- GC metamethod.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
539 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
540 static int meth_destroy(lua_State *L)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
541 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
542 p_context ctx = checkctx(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
543 if (ctx->context) {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
544 SSL_CTX_free(ctx->context);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
545 ctx->context = NULL;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
546 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
547 return 0;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
548 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
549
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
550 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
551 * Object information -- tostring metamethod.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
552 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
553 static int meth_tostring(lua_State *L)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
554 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
555 p_context ctx = checkctx(L, 1);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
556 lua_pushfstring(L, "SSL context: %p", ctx);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
557 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
558 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
559
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
560 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
561 * Context metamethods.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
562 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
563 static luaL_Reg meta[] = {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
564 {"__gc", meth_destroy},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
565 {"__tostring", meth_tostring},
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
566 {NULL, NULL}
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
567 };
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
568
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
569
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
570 /*----------------------------- Public Functions ---------------------------*/
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
571
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
572 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
573 * Retrieve the SSL context from the Lua stack.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
574 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
575 SSL_CTX* ctx_getcontext(lua_State *L, int idx)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
576 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
577 p_context ctx = checkctx(L, idx);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
578 return ctx->context;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
579 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
580
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
581 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
582 * Retrieve the mode from the context in the Lua stack.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
583 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
584 char ctx_getmode(lua_State *L, int idx)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
585 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
586 p_context ctx = checkctx(L, idx);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
587 return ctx->mode;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
588 }
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
589
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
590 /*------------------------------ Initialization ------------------------------*/
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
591
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
592 /**
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
593 * Registre the module.
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
594 */
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
595 int luaopen_ssl_context(lua_State *L)
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
596 {
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
597 luaL_newmetatable(L, "SSL:Context");
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
598 luaL_register(L, NULL, meta);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
599 luaL_register(L, "ssl.context", funcs);
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
600 return 1;
f7d2d78eb424 Initial commit (LuaSec 0.4)
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
601 }

mercurial