- gnutls alert handling

- simplified HTTPS example use
- added alert level to tls-session structs
- some gnutls removed code
This commit is contained in:
lv-426 committed 2008-06-29 21:33:00 +00:00
1 parent 7afe06474b
commit 8538fe9783
8 files changed
+66 -383

No files matched your search

-175
View File
@@ -246,7 +246,6 @@ print_x509_info (gnutls_session_t session, const char *hostname)
}
#ifdef ENABLE_OPENPGP
void
print_openpgp_info (gnutls_session_t session, const char *hostname)
{
@@ -356,7 +355,6 @@ print_openpgp_info (gnutls_session_t session, const char *hostname)
}
}
#endif
void
@@ -662,179 +660,6 @@ print_license (void)
stdout);
}
static int depr_printed = 0;
#define DEPRECATED if (depr_printed==0) { \
fprintf(stderr, "This method of specifying algorithms is deprecated. Please use the --priority option.\n"); \
depr_printed = 1; \
}
void
parse_protocols (char **protocols, int protocols_size, int *protocol_priority)
{
int i, j;
if (protocols != NULL && protocols_size > 0)
{
DEPRECATED;
for (j = i = 0; i < protocols_size; i++)
{
if (strncasecmp (protocols[i], "SSL", 3) == 0)
protocol_priority[j++] = GNUTLS_SSL3;
else if (strncasecmp (protocols[i], "TLS1.1", 6) == 0)
protocol_priority[j++] = GNUTLS_TLS1_1;
else if (strncasecmp (protocols[i], "TLS1.2", 6) == 0)
protocol_priority[j++] = GNUTLS_TLS1_2;
else if (strncasecmp (protocols[i], "TLS", 3) == 0)
protocol_priority[j++] = GNUTLS_TLS1_0;
else
fprintf (stderr, "Unknown protocol: '%s'\n", protocols[i]);
}
protocol_priority[j] = 0;
}
}
void
parse_ciphers (char **ciphers, int nciphers, int *cipher_priority)
{
int j, i;
if (ciphers != NULL && nciphers > 0)
{
DEPRECATED;
for (j = i = 0; i < nciphers; i++)
{
if (strncasecmp (ciphers[i], "AES-2", 5) == 0)
cipher_priority[j++] = GNUTLS_CIPHER_AES_256_CBC;
else if (strncasecmp (ciphers[i], "AES", 3) == 0)
cipher_priority[j++] = GNUTLS_CIPHER_AES_128_CBC;
else if (strncasecmp (ciphers[i], "3DE", 3) == 0)
cipher_priority[j++] = GNUTLS_CIPHER_3DES_CBC;
else if (strcasecmp (ciphers[i], "ARCFOUR-40") == 0)
cipher_priority[j++] = GNUTLS_CIPHER_ARCFOUR_40;
else if (strcasecmp (ciphers[i], "ARCFOUR") == 0)
cipher_priority[j++] = GNUTLS_CIPHER_ARCFOUR_128;
#ifdef ENABLE_CAMELLIA
else if (strncasecmp (ciphers[i], "CAMELLIA-2", 10) == 0)
cipher_priority[j++] = GNUTLS_CIPHER_CAMELLIA_256_CBC;
else if (strncasecmp (ciphers[i], "CAM", 3) == 0)
cipher_priority[j++] = GNUTLS_CIPHER_CAMELLIA_128_CBC;
#endif
else if (strncasecmp (ciphers[i], "NUL", 3) == 0)
cipher_priority[j++] = GNUTLS_CIPHER_NULL;
else
fprintf (stderr, "Unknown cipher: '%s'\n", ciphers[i]);
}
cipher_priority[j] = 0;
}
}
void
parse_macs (char **macs, int nmacs, int *mac_priority)
{
int i, j;
if (macs != NULL && nmacs > 0)
{
DEPRECATED;
for (j = i = 0; i < nmacs; i++)
{
if (strncasecmp (macs[i], "MD5", 3) == 0)
mac_priority[j++] = GNUTLS_MAC_MD5;
else if (strncasecmp (macs[i], "SHA256", 6) == 0)
mac_priority[j++] = GNUTLS_MAC_SHA256;
else if (strncasecmp (macs[i], "SHA", 3) == 0)
mac_priority[j++] = GNUTLS_MAC_SHA1;
else
fprintf (stderr, "Unknown MAC: '%s'\n", macs[i]);
}
mac_priority[j] = 0;
}
}
void
parse_ctypes (char **ctype, int nctype, int *cert_type_priority)
{
int i, j;
if (ctype != NULL && nctype > 0)
{
DEPRECATED;
for (j = i = 0; i < nctype; i++)
{
if (strncasecmp (ctype[i], "OPE", 3) == 0)
cert_type_priority[j++] = GNUTLS_CRT_OPENPGP;
else if (strncasecmp (ctype[i], "X", 1) == 0)
cert_type_priority[j++] = GNUTLS_CRT_X509;
else
fprintf (stderr, "Unknown certificate type: '%s'\n", ctype[i]);
}
cert_type_priority[j] = 0;
}
}
void
parse_kx (char **kx, int nkx, int *kx_priority)
{
int i, j;
if (kx != NULL && nkx > 0)
{
DEPRECATED;
for (j = i = 0; i < nkx; i++)
{
if (strcasecmp (kx[i], "SRP") == 0)
kx_priority[j++] = GNUTLS_KX_SRP;
else if (strcasecmp (kx[i], "SRP-RSA") == 0)
kx_priority[j++] = GNUTLS_KX_SRP_RSA;
else if (strcasecmp (kx[i], "SRP-DSS") == 0)
kx_priority[j++] = GNUTLS_KX_SRP_DSS;
else if (strcasecmp (kx[i], "RSA") == 0)
kx_priority[j++] = GNUTLS_KX_RSA;
else if (strcasecmp (kx[i], "PSK") == 0)
kx_priority[j++] = GNUTLS_KX_PSK;
else if (strcasecmp (kx[i], "DHE-PSK") == 0)
kx_priority[j++] = GNUTLS_KX_DHE_PSK;
else if (strcasecmp (kx[i], "RSA-EXPORT") == 0)
kx_priority[j++] = GNUTLS_KX_RSA_EXPORT;
else if (strncasecmp (kx[i], "DHE-RSA", 7) == 0)
kx_priority[j++] = GNUTLS_KX_DHE_RSA;
else if (strncasecmp (kx[i], "DHE-DSS", 7) == 0)
kx_priority[j++] = GNUTLS_KX_DHE_DSS;
else if (strncasecmp (kx[i], "ANON", 4) == 0)
kx_priority[j++] = GNUTLS_KX_ANON_DH;
else
fprintf (stderr, "Unknown key exchange: '%s'\n", kx[i]);
}
kx_priority[j] = 0;
}
}
void
parse_comp (char **comp, int ncomp, int *comp_priority)
{
int i, j;
if (comp != NULL && ncomp > 0)
{
DEPRECATED;
for (j = i = 0; i < ncomp; i++)
{
if (strncasecmp (comp[i], "NUL", 3) == 0)
comp_priority[j++] = GNUTLS_COMP_NULL;
else if (strncasecmp (comp[i], "ZLI", 3) == 0)
comp_priority[j++] = GNUTLS_COMP_DEFLATE;
else if (strncasecmp (comp[i], "DEF", 3) == 0)
comp_priority[j++] = GNUTLS_COMP_DEFLATE;
else if (strncasecmp (comp[i], "LZO", 3) == 0)
comp_priority[j++] = GNUTLS_COMP_LZO;
else
fprintf (stderr, "Unknown compression: '%s'\n", comp[i]);
}
comp_priority[j] = 0;
}
}
void
sockets_init (void)
{
+1 -1
View File
@@ -28,7 +28,7 @@
#include "gnutls_int.h"
#include "gnutls_errors.h"
#include "gnutls_session.h"
// #include "gnutls_session.h"
#include <gnutls_db.h>
#include "debug.h"
#include <gnutls_session_pack.h>
+1
View File
@@ -447,6 +447,7 @@ typedef struct
int read_eof; /* non-zero if we have received a closure alert. */
int last_alert; /* last alert received */
int last_alert_level; /* last alert level */
/* The last handshake messages sent or received.
*/
+3 -3
View File
@@ -657,6 +657,7 @@ static int record_check_type(gnutls_session_t session,
data[0], data[1], gnutls_alert_get_name ((int) data[1]));
session->internals.last_alert = data[1];
session->internals.last_alert_level = data[0];
/* if close notify is received and
* the alert is not fatal
@@ -674,7 +675,6 @@ static int record_check_type(gnutls_session_t session,
/* if the alert is FATAL or WARNING
* return the apropriate message
*/
gnutls_assert ();
ret = GNUTLS_E_WARNING_ALERT_RECEIVED;
if (data[0] == GNUTLS_AL_FATAL)
@@ -968,8 +968,7 @@ ssize_t _gnutls_recv_int(gnutls_session_t session,
return ret;
}
/* decrypt the data we got.
*/
/* decrypt the data we got. */
ret = _gnutls_decrypt(session, ciphertext, length, tmp.data, tmp.size,
recv_type);
if (ret < 0)
@@ -1015,6 +1014,7 @@ ssize_t _gnutls_recv_int(gnutls_session_t session,
return GNUTLS_E_RECORD_LIMIT_REACHED;
}
/* check type - this will also invalidate sessions if a fatal alert has been received */
ret = record_check_type(session, recv_type, type, htype, tmp.data,
decrypted_length);
if (ret < 0)
-23
View File
@@ -1,23 +0,0 @@
/*
* Copyright (C) 2000, 2001, 2002, 2003, 2004, 2005 Free Software Foundation
*
* Author: Nikos Mavrogiannopoulos
*
* This file is part of GNUTLS.
*
* The GNUTLS library is free software; you can redistribute it and/or
* modify it under the terms of the GNU Lesser General Public License
* as published by the Free Software Foundation; either version 2.1 of
* the License, or (at your option) any later version.
*
* This library is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
* Lesser General Public License for more details.
*
* You should have received a copy of the GNU Lesser General Public
* License along with this library; if not, write to the Free Software
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301,
* USA
*
*/