This commit is contained in:
Christian Grothoff committed 2008-08-24 18:44:21 +00:00
1 parent 337922f27f
commit 909af47012
8 files changed
+175 -246

No files matched your search

-2
View File
@@ -110,8 +110,6 @@ extern "C"
GNUTLS_A_CERTIFICATE_UNOBTAINABLE = 111,
GNUTLS_A_UNRECOGNIZED_NAME = 112,
GNUTLS_A_UNKNOWN_PSK_IDENTITY = 115,
GNUTLS_A_INNER_APPLICATION_FAILURE = 208,
GNUTLS_A_INNER_APPLICATION_VERIFICATION = 209
} gnutls_alert_description_t;
typedef enum
+1 -2
View File
@@ -16,7 +16,7 @@ noinst_LTLIBRARIES = libtls.la
libtls_la_LDFLAGS = \
-L$(GCRYPT_LIB_PATH)
libtls_la_SOURCES = \
auth_anon.c \
auth_cert.c \
@@ -29,7 +29,6 @@ ext_cert_type.c \
ext_max_record.c \
ext_oprfi.c \
ext_server_name.c \
ext_inner_application.c \
gnutls_alert.c \
gnutls_algorithms.c \
gnutls_anon_cred.c \
@@ -1,152 +0,0 @@
/*
* Copyright (C) 2005, 2006 Free Software Foundation
*
* Author: Simon Josefsson
*
* This file is part of GNUTLS.
*
* The GNUTLS library is free software; you can redistribute it and/or
* modify it under the terms of the GNU Lesser General Public License
* as published by the Free Software Foundation; either version 2.1 of
* the License, or (at your option) any later version.
*
* This library is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
* Lesser General Public License for more details.
*
* You should have received a copy of the GNU Lesser General Public
* License along with this library; if not, write to the Free Software
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
* 02110-1301, USA
*
*/
#include "gnutls_int.h"
#include "gnutls_auth_int.h"
#include "gnutls_errors.h"
#include "gnutls_num.h"
#include "ext_inner_application.h"
#define NO 0
#define YES 1
int
mhd_gtls_inner_app_rcv_params (mhd_gtls_session_t session,
const opaque * data, size_t data_size)
{
mhd_gtls_ext_st *ext = &session->security_parameters.extensions;
if (data_size != 1)
{
gnutls_assert ();
return GNUTLS_E_UNEXPECTED_PACKET_LENGTH;
}
ext->gnutls_ia_peer_enable = 1;
ext->gnutls_ia_peer_allowskip = 0;
switch ((unsigned char) *data)
{
case NO: /* Peer's ia_on_resume == no */
ext->gnutls_ia_peer_allowskip = 1;
break;
case YES:
break;
default:
gnutls_assert ();
}
return 0;
}
/**
* returns data_size or a negative number on failure
*/
int
mhd_gtls_inner_app_send_params (mhd_gtls_session_t session,
opaque * data, size_t data_size)
{
mhd_gtls_ext_st *ext = &session->security_parameters.extensions;
/* Set ext->gnutls_ia_enable depending on whether we have a TLS/IA
credential in the session. */
#if MHD_DEBUG_TLS
if (session->security_parameters.entity == GNUTLS_CLIENT)
{
gnutls_ia_client_credentials_t cred = (gnutls_ia_client_credentials_t)
mhd_gtls_get_cred (session->key, MHD_GNUTLS_CRD_IA, NULL);
if (cred)
ext->gnutls_ia_enable = 1;
}
else
#endif
{
struct gnutls_ia_server_credentials_st *cred =
(struct gnutls_ia_server_credentials_st *)
mhd_gtls_get_cred (session->key, MHD_GNUTLS_CRD_IA, NULL);
if (cred)
ext->gnutls_ia_enable = 1;
}
/* If we don't want gnutls_ia locally, or we are a server and the
* client doesn't want it, don't advertise TLS/IA support at all, as
* required. */
if (!ext->gnutls_ia_enable)
return 0;
if (session->security_parameters.entity == GNUTLS_SERVER &&
!ext->gnutls_ia_peer_enable)
return 0;
/* We'll advertise. Check if there's room in the hello buffer. */
if (data_size < 1)
{
gnutls_assert ();
return GNUTLS_E_SHORT_MEMORY_BUFFER;
}
/* default: require new application phase */
*data = YES;
#if MHD_DEBUG_TLS
if (session->security_parameters.entity == GNUTLS_CLIENT)
{
/* Client: value follows local setting */
if (ext->gnutls_ia_allowskip)
*data = NO;
}
else
#endif
{
/* Server: value follows local setting and client's setting, but only
* if we are resuming.
*
* XXX Can server test for resumption at this stage?
*
* Ai! It seems that read_client_hello only calls parse_extensions if
* we're NOT resuming! That would make us automatically violate the IA
* draft; if we're resuming, we must first learn what the client wants
* -- IA or no IA -- and then prepare our response. Right now we'll
* always skip IA on resumption, because recv_ext isn't even called
* to record the peer's support for IA at all. Simon? */
if (ext->gnutls_ia_allowskip &&
ext->gnutls_ia_peer_allowskip &&
session->internals.resumed == RESUME_TRUE)
*data = NO;
}
return 1;
}
@@ -1,28 +0,0 @@
/*
* Copyright (C) 2005 Free Software Foundation
*
* Author: Simon Josefsson
*
* This file is part of GNUTLS.
*
* The GNUTLS library is free software; you can redistribute it and/or
* modify it under the terms of the GNU Lesser General Public License
* as published by the Free Software Foundation; either version 2.1 of
* the License, or (at your option) any later version.
*
* This library is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
* Lesser General Public License for more details.
*
* You should have received a copy of the GNU Lesser General Public
* License along with this library; if not, write to the Free Software
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301,
* USA
*
*/
int mhd_gtls_inner_app_rcv_params (mhd_gtls_session_t session,
const opaque * data, size_t data_size);
int mhd_gtls_inner_app_send_params (mhd_gtls_session_t session,
opaque * data, size_t);
-5
View File
@@ -64,11 +64,6 @@ static const gnutls_alert_entry mhd_gtls_sup_alerts[] = {
"The server name sent was not recognized"},
{GNUTLS_A_UNKNOWN_PSK_IDENTITY,
"The SRP/PSK username is missing or not known"},
{GNUTLS_A_INNER_APPLICATION_FAILURE,
"Inner application negotiation failed"},
{GNUTLS_A_INNER_APPLICATION_VERIFICATION,
"Inner application verification failed"},
{0, NULL}
};
#define GNUTLS_ALERT_LOOP(b) \
-5
View File
@@ -34,7 +34,6 @@
#include <ext_cert_type.h>
#include <ext_server_name.h>
#include <ext_oprfi.h>
#include <ext_inner_application.h>
#include <gnutls_num.h>
/* Key Exchange Section */
@@ -70,10 +69,6 @@ mhd_gtls_extension_entry mhd_gtls_extensions[MAX_EXT_SIZE] = {
_gnutls_srp_recv_params,
_gnutls_srp_send_params),
#endif
GNUTLS_EXTENSION_ENTRY (GNUTLS_EXTENSION_INNER_APPLICATION,
EXTENSION_TLS,
mhd_gtls_inner_app_rcv_params,
mhd_gtls_inner_app_send_params),
{0, 0, 0, 0}
};