Steffen Jaeckel
bddb80a192
add support for a password callback
...
In order to be able to load password-protected key files a password
callback was added.
This also adds support for PKCS#12 containers instead of certificate+key.
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-03-21 00:24:22 +01:00
Steffen Jaeckel
fc6ba89c61
properly rename internal [v]snprintf() functions
...
Otherwise it clashes when we want to re-introduce the `xmpp_` prefix'ed
versions.
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-03-16 14:39:20 +01:00
Steffen Jaeckel
528c16e6c8
fix build with OpenSSL 1.1.0l
...
Debian 9.13 (stretch) brings this version and building failed there.
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-03-09 16:48:07 +01:00
Steffen Jaeckel
93e04b8d03
make logging functions private
...
Fixes #189
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-02-06 12:36:38 +01:00
Steffen Jaeckel
a97714da18
make alloc-class of functions private
...
Fixes #189
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-02-06 12:36:38 +01:00
Steffen Jaeckel
2850fd7792
fix build with libressl
...
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-02-04 13:36:17 +01:00
Steffen Jaeckel
d8d0e75466
improve OpenSSL error logging
...
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2022-02-04 13:36:17 +01:00
Steffen Jaeckel
b0631e322f
use lower-case labels
...
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2021-12-03 12:04:29 +01:00
Steffen Jaeckel
12009a009d
implement certificate verification API for OpenSSL
...
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2021-10-28 17:23:32 +02:00
Dmitry Podgorny
ee5f9fb77b
tls/openssl: fix openssl-3.0.0 support
...
3.0.0 includes the "id-on-xmppAddr" object and OBJ_create() returns
NID_undef if we try to create a new one.
2021-03-23 02:08:22 +02:00
Dmitry Podgorny
4790a61437
tls/openssl: fix openssl-0.9.8 support
...
0.9.8 doesn't implement GENERAL_NAME_get0_otherName().
2021-03-23 02:07:00 +02:00
Steffen Jaeckel
18c95fa7bd
add support for client authentication via certificates
...
The SASL EXTERNAL method is implemented to make this possible.
Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de >
2021-03-23 02:04:59 +02:00
Dmitry Podgorny
db8a511f68
style: remove extra const keyword from interfaces
...
Const variables in prototypes don't add much value, but make the code
larger and redundant. Remove these const keywords.
Note, this doesn't apply to pointers to const memory.
2021-03-19 22:12:15 +02:00
Dmitry Podgorny
acced31192
tls/openssl: Fix undefined error codes for LibreSSL
...
LibreSSL doesn't define all error codes which OpenSSL defines. Wrap them
with #ifndef.
Reference: https://bugs.gentoo.org/744127
2020-09-24 13:34:49 +03:00
Dmitry Podgorny
4dd78be10d
tls/openssl: fix compilation with older openssl
...
Not all error codes are present in older versions of openssl.
2020-09-15 03:07:02 +03:00
Dmitry Podgorny
197896ba1b
tls/openssl: improve logging
...
Log error names and codes to increase verbosity in debug mode.
2020-06-18 22:18:59 +03:00
Oleg Synelnykov
198bdd77d0
Remove -Wno-unused-parameter
...
Introduced UNUSED macro with cast to void in commoh.h for internal
use. Used cast to void directly in those files which do not
include common.h. Although this change doesn't fix semantic issues
with unused function parameters, it does explicitly mark all those
places, which might require attention in future.
2020-03-31 17:37:12 +03:00
Dmitry Podgorny
562a06425b
Unify coding style
...
@sjaeckel integrated clang-format with formal coding style. Run his
script and commit changes.
There are pros and cons of this commit.
Mixed coding style is a "broken window". A good single style simplifies
reading and writing code.
On the other hand, this is a big change which will lead to conflicts.
2020-01-31 01:16:50 +02:00
Steffen Jaeckel
abd1b08a97
trim trailing spaces
2020-01-31 01:14:32 +02:00
Manuel Kasper
f0436490b0
Enable SNI with OpenSSL 0.9.8f as well
2019-12-24 09:07:51 +01:00
Manuel Kasper
243664926f
Enable TLS SNI
2019-12-23 14:34:19 +01:00
Dmitry Podgorny
284e8f4421
tls/openssl: check return code
...
Check return code of SSL_CTX_set_default_verify_paths() and fail TLS on
an error. However, ignore the error when XMPP_CONN_FLAG_TRUST_TLS is
set.
2019-11-10 15:57:23 +02:00
Dmitry Podgorny
296df2fca9
tls/openssl: don't use deprecated function in 1.1.0+
...
SSLv23_client_method() was deprecated in OpenSSL 1.1.0. It is left as
macro to TLS_client_method.
2019-11-25 13:45:51 +00:00
François Revol
234bef4025
Haiku: C89
2019-11-17 14:28:26 +01:00
Dmitry Podgorny
18b67d6eaf
tls/openssl: add LibreSSL support
...
OpenSSL and LibreSSL versions are incompatible. Moreover, LibreSSL
always define OPENSSL_VERSION_NUMBER as 0x20000000L. Instead of checking
for LibreSSL everywhere explicitly, redefine OPENSSL_VERSION_NUMBER.
See similar issues with nginx project: https://trac.nginx.org/nginx/ticket/1605
2019-10-11 01:59:34 +03:00
Hoenig Mark (TT/EIS3-Lol)
5ee06776ee
tls/openssl: don't call SSL_shutdown() after a fatal error
...
According to SSL_shutdown(3), the function must not be called
if previous fatal error occurred.
2019-07-03 15:14:01 +02:00
Dmitry Podgorny
9cc9ea86bb
tls/openssl: log some info about certificate
...
Log subject name and issuer name from certificate after TLS connection
is established or fails to connect.
2018-11-06 10:53:46 +02:00
Dmitry Podgorny
7ede9c6d03
tls/openssl: suppress error in special case in tls_stop()
...
When peer closes connection instead of proper shutdown SSL_shutdown()
fails in bidirectional mode. Handle this case and suppress the error.
2018-02-18 12:03:11 +02:00
Dmitry Podgorny
d0644c5e95
tls/openssl: print errno on unrecoverable error
2017-08-23 09:23:51 +03:00
Dmitry Podgorny
8d2d59e914
tls/openssl: add OpenSSL-1.1.0 support ( #109 )
...
OpenSSL-1.1.0 marks cleanup functions as deprecated and changes
initialization function. It implements implicit de-initialization.
Reported by @zygmund2000.
2017-07-12 02:07:14 +03:00
Dmitry Podgorny
9269d6b0d5
conn: add flag XMPP_CONN_FLAG_TRUST_TLS
...
TLS modules accept invalid server's certificates when the flag is set.
2017-07-04 17:20:33 +03:00
Dmitry Podgorny
cc53012cfa
tls/openssl: enable cert verification for openssl older then 1.0.2
...
TODO: add flag to trust certificate even if verification fails.
2017-07-01 15:51:49 +03:00
Steffen Jaeckel
f226891520
fix openssl memory leaks
2017-06-29 16:54:41 +02:00
Alexander Krotov
92d006a41b
Disable hostname verification for pre-1.0.2 OpenSSL
2017-06-23 13:45:24 +03:00
Alexander Krotov
0741820711
Verify certificate hostname when using OpenSSL ( fixes #100 )
2017-06-23 03:00:26 +03:00
Alexander Krotov
c9ddc2b7ef
Make tls_new accept xmpp_conn_t
2017-06-23 02:59:05 +03:00
Alexander Krotov
f776b34d8c
Fix tls_openssl.c indentation
2017-06-22 19:44:41 +03:00
Alexander Krotov
f47609c1f0
Disable insecure SSL/TLS versions
2017-06-20 22:44:39 +03:00
Dmitry Podgorny
0c60e8d384
tls_openssl: coding style
2016-09-02 00:49:32 +03:00
Dmitry Podgorny
ab80d72518
tls/openssl: handle SSL_shutdown() properly
...
Handle SSL_ERROR_WANT_READ/WRITE and return value 0.
2016-04-19 19:57:52 +00:00
Dmitry Podgorny
ba7422c893
tls/openssl: be more verbose
...
Log non-recoverable errors. The openssl error queue can contain useful
information.
2016-04-19 18:21:27 +00:00
Dmitry Podgorny
4b444ea699
tls/openssl: fixed indentation
2016-04-19 16:33:47 +00:00
Dmitry Podgorny
b04c40d3ea
tls: don't hang with openssl implementation
...
* Exit from tls_start() on fatal errors. If SSL_connect() fails and
returns -1 this leads to endless loop in case of fatal error.
* Don't set writefds on SSL_ERROR_WANT_READ. Otherwise, this makes
select(2) exit immediately what leads to CPU usage.
2015-10-13 02:43:23 +03:00
Dariusz Dwornikowski
71f75b2e2e
Closes #31
2014-10-23 08:44:52 +02:00
Dmitry Podgorny
65d2535302
tls_openssl: removed unused openssl/rand.h
2014-09-06 22:31:53 +03:00
Jack Moffitt
ee8afdb64e
Memory leak fixes from @elisamanfrin.
...
Fixes issue #4 .
2012-02-07 22:46:38 -07:00
Vlad-Mihai Sima
511606835d
Bug fix: when using tls, if a stanza is bigger than the buffer of 4096 in event.c, the stanza will not be read as select will return 0 on the ssl socket and the data will be in ssl buffers. Partial fix, only for Linux for now
2012-01-01 20:09:18 +01:00
Jack Moffitt
370a371800
Dual licensed libstrophe under MIT and GPLv3.
...
Updated copyright headers.
2009-06-15 15:26:10 -06:00
Jack Moffitt
4f608fd957
First pass at fixing up OpenSSL support. It now seems to work.
2008-12-10 09:25:22 -07:00
Jack Moffitt
1c0bbb1f5d
Reverting r513. I mistakenly committed my entire tree.
2008-08-26 04:46:41 +00:00