diff --git a/src/microhttpd/connection_https_openssl.c b/src/microhttpd/connection_https_openssl.c new file mode 100644 index 00000000..85e99655 --- /dev/null +++ b/src/microhttpd/connection_https_openssl.c @@ -0,0 +1,166 @@ +/* + This file is part of libmicrohttpd + Copyright (C) 2007, 2008, 2010 Daniel Pittman and Christian Grothoff + Copyright (C) 2015-2021 Karlson2k (Evgeny Grin) + + This library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + This library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with this library; if not, write to the Free Software + Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA + +*/ + +/** + * @file connection_https_openssl.c + * @brief Methods for managing SSL/TLS connections with the library OpenSSL. This file is only + * compiled if ENABLE_HTTPS is set. + * @author Edouard LEFIZELIER + */ + +#include "internal.h" +#include "connection_https_openssl.h" +#include "openssl/bio.h" +#include "openssl/ssl.h" +#include "openssl/err.h" + +/* Initializing OpenSSL */ + +SSL_load_error_strings (); +ERR_load_BIO_strings (); +OpenSSL_add_all_algorithms (); + +/** + * create a new SSL_CTX structure + * + * @return the SSL_CTX structure +*/ +SSL_CTX * +create_context () +{ + SSL_CTX *ctx; + ctx = SSL_CTX_new (SSLv23_client_method ()); + if (! ctx) + { + ERR_print_errors (stderr); + } + return ctx; +} + + +/** + * set the context of the SSL_CTX structure, especially the path to the trust store file + * + * @param ctx the SSL_CTX structure + * @param path the path and the filename of the trust store file +*/ +void +set_context (SSL_CTX *ctx, char *path) +{ + if (! SSL_CTX_load_verify_locations (ctx, path, NULL)) + { + ERR_print_errors_fp (stderr); + } +} + + +/** + * Create a secure connection with the server + * + * @param bio the BIO structure + * @param path the path to the certificate file + * @return 1 if an error occured, 0 otherwise +*/ +int +create_secure_connection (BIO *bio, const char *path) +{ + SSL_CTX *ctx = SSL_CTX_new (SSLv23_client_method ()); + SSL ssl; + + // Load the client certificate into the SSL_CTX structure + if (! SSL_CTX_load_verify_locations (ctx, path, NULL)) + { + // Error Handler + } + + bio = BIO_new_ssl_connect (ctx); + BIO_get_ssl (bio, &ssl); + // if the server want a new handshake, OpenSSL will open it in the background + SSL_set_mode (ssl, SSL_MODE_AUTO_RETRY); +} + + +/** + * Open a secure connection with the server + * + * @param bio the BIO structure + * @param port the port to connect to + * @return 1 if an error occured, 0 otherwise +*/ +int +open_secure_connection (BIO *bio, const char *port) +{ + BIO_set_conn_hostname (bio, port); + if (BIO_do_connect (bio) <= 0) + { + return 1; + } + SSL ssl; + BIO_get_ssl (bio, &ssl); + if (SSL_get_verify_result (ssl) != X509_V_OK) + { + return 1; + } + ; + return 0; +} + + +/** + * Reset the BIO structure + * + * @param bio the BIO structure + * @return 1 if an error occured, 0 otherwise +*/ +int +reset_bio (BIO *bio) +{ + return ! BIO_reset (bio); +} + + +/** + * Close the connection with the server + * + * @param bio the BIO structure + * @return 1 if an error occured, 0 otherwise +*/ +int +close_connection (BIO *bio) +{ + return ! BIO_free (bio); +} + + +/** + * Free memory allocated by OpenSSL when the application is shutting down + * + * @param ctx the SSL_CTX structure +*/ +void +shutting_down (SSL_CTX *ctx) +{ + SSL_CTX_free (ctx); + // Free the error strings for libcrypto and libssl + ERR_free_strings (); + // Cleanup all the ciphers and digests + EVP_cleanup (); +} diff --git a/src/microhttpd/connection_https_openssl.h b/src/microhttpd/connection_https_openssl.h new file mode 100644 index 00000000..4e733f4d --- /dev/null +++ b/src/microhttpd/connection_https_openssl.h @@ -0,0 +1,27 @@ +/* + This file is part of libmicrohttpd + Copyright (C) 2008 Daniel Pittman and Christian Grothoff + + This library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + This library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with this library; if not, write to the Free Software + Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA +*/ + +/** + * @file connection_https.h + * @brief Methods for managing connections + * @author Edouard LEFIZELIER + */ + +#ifndef CONNECTION_HTTPS_EXT_OPENSSL_H +#define CONNECTION_HTTPS_EXT_OPENSSL_H \ No newline at end of file diff --git a/src/microhttpd/sha1_ext_openssl.c b/src/microhttpd/sha1_ext_openssl.c new file mode 100644 index 00000000..d2b30c6e --- /dev/null +++ b/src/microhttpd/sha1_ext_openssl.c @@ -0,0 +1,71 @@ +/* + This file is part of libmicrohttpd + Copyright (C) 2019-2021 Karlson2k (Evgeny Grin) + + libmicrohttpd is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + This library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with this library. + If not, see . +*/ + +/** + * @file microhttpd/sha1.c + * @brief Calculation of SHA-1 digest as defined in FIPS PUB 180-4 (2015) + * @author Édouard LEFIZELIER + */ + +#include +#include "sha1_ext_openssl.h" + +/** + * Initialise structure for SHA-1 calculation + * + * @param ctx the calculation context + */ +void +MHD_SHA1_init (struct Sha1CtxExt_openssl *ctx) +{ + ctx->ext_error = ! SHA1_Init (&ctx->c); +} + + +/** + * Process portion of bytes. + * + * @param ctx the calculation context + * @param data bytes to add to hash + * @param length number of bytes in @a data + */ +void +MHD_SHA1_update (struct Sha1CtxExt_openssl *ctx, const void *buf, int len) +{ + if (0 == ctx->ext_error) + { + ctx->ext_error = ! SHA1_Update (&ctx->c, buf, len); + } +} + + +/** + * Finalise SHA-1 calculation, return digest. + * + * @param ctx the calculation context + * @param md where to store the digest + */ +void +MHD_SHA1_final (struct Sha1CtxExt_openssl *ctx, void *md) +{ + if (0 == ctx->ext_error) + { + ctx->ext_error = ! SHA1_Final (md, &ctx->c); + } +} diff --git a/src/microhttpd/sha1_ext_openssl.h b/src/microhttpd/sha1_ext_openssl.h new file mode 100644 index 00000000..3c792b13 --- /dev/null +++ b/src/microhttpd/sha1_ext_openssl.h @@ -0,0 +1,68 @@ +/* + This file is part of GNU libmicrohttpd + Copyright (C) 2022 Evgeny Grin (Karlson2k) + + GNU libmicrohttpd is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + This library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with GNU libmicrohttpd. + If not, see . +*/ + +/** + * @file microhttpd/md5_ext.h + * @brief Wrapper declarations for MD5 calculation performed by TLS library + * @author Édouard LEFIZELIER + */ + +#ifndef MHD_SHA1_EXT_OPENSSL +#define MHD_SHA1_EXT_OPENSSL 1 + +#include + +/** + * SHA1 calculation context + */ +struct Sha1CtxExt_openssl +{ + SHA_CTX c; /* Hash context*/ + int ext_error; /**< Non-zero if external error occurs during init or hashing */ +}; + +/** + * Initialise structure for MD5 calculation + * + * @param ctx the calculation context +*/ +void +MHD_MD5_init (struct Md5CtxExt_openssl *ctx); + +/** + * Process portion of bytes. + * + * @param ctx the calculation context + * @param data bytes to add to hash + * @param length number of bytes in @a data +*/ +void +MHD_MD5_update (struct Md5CtxExt_openssl *ctx, const void *buf, int len); + +/** + * Finalise MD5 calculation, return digest. + * + * @param ctx the calculation context + * @param[out] digest set to the hash, must be #MD5_DIGEST_SIZE bytes + */ +void +MHD_MD5_final (struct Md5CtxExt_openssl *ctx, unsigned char *md); + + +#endif