bind option uses sockaddr - [ ! MHD_USE_IPv6 should be removed in favor of a generic addrlen argument ]

openpgp support currently disabled
This commit is contained in:
lv-426 committed 2008-08-14 16:13:04 +00:00
1 parent 63f23d2131
commit c5ad835c7c
26 files changed
+544 -1836

No files matched your search

+2 -4
View File
@@ -26,10 +26,10 @@ auth_rsa.c \
auth_rsa_export.c \
debug.c \
ext_cert_type.c \
ext_inner_application.c \
ext_max_record.c \
ext_oprfi.c \
ext_server_name.c \
ext_inner_application.c \
gnutls_alert.c \
gnutls_algorithms.c \
gnutls_anon_cred.c \
@@ -68,6 +68,4 @@ gnutls_supplemental.c \
gnutls_ui.c \
gnutls_x509.c \
pkix_asn1_tab.c \
x509_b64.c
x509_b64.c
+7 -6
View File
@@ -23,13 +23,14 @@
*/
#ifndef AUTH_CERT_H
# define AUTH_CERT_H
#define AUTH_CERT_H
# include "gnutls_cert.h"
# include "gnutls_auth.h"
# include "auth_dh_common.h"
# include "x509.h"
# include "openpgp.h"
#include "gnutls_cert.h"
#include "gnutls_auth.h"
#include "auth_dh_common.h"
#include "x509.h"
#include "openpgp.h"
#include "extra.h"
/* This structure may be complex, but it's the only way to
* support a server that has multiple certificates
+2 -1
View File
@@ -63,7 +63,8 @@ mhd_gtls_inner_app_rcv_params (mhd_gtls_session_t session,
}
/* returns data_size or a negative number on failure
/**
* returns data_size or a negative number on failure
*/
int
mhd_gtls_inner_app_send_params (mhd_gtls_session_t session,
+9 -7
View File
@@ -314,11 +314,11 @@ MHD_gtls_certificate_server_set_request (mhd_gtls_session_t session,
* This function sets a callback to be called in order to retrieve the certificate
* to be used in the handshake.
* The callback's function prototype is:
* int (*callback)(mhd_gtls_session_t, const gnutls_datum_t* req_ca_dn, int nreqs,
* int (*callback)(mhd_gtls_session_t, const gnutls_datum_t* req_ca_dn, int nreqs,
* const gnutls_pk_algorithm_t* pk_algos, int pk_algos_length, gnutls_retr_st* st);
*
* @req_ca_cert is only used in X.509 certificates.
* Contains a list with the CA names that the server considers trusted.
* @req_ca_cert is only used in X.509 certificates.
* Contains a list with the CA names that the server considers trusted.
* Normally we should send a certificate that is signed
* by one of these CAs. These names are DER encoded. To get a more
* meaningful value use the function gnutls_x509_rdn_get().
@@ -441,7 +441,7 @@ _gnutls_x509_get_raw_crt_expiration_time (const gnutls_datum_t * cert)
* _gnutls_openpgp_crt_verify_peers - This function returns the peer's certificate status
* @session: is a gnutls session
*
* This function will try to verify the peer's certificate and return its status (TRUSTED, INVALID etc.).
* This function will try to verify the peer's certificate and return its status (TRUSTED, INVALID etc.).
* Returns a negative error code in case of an error, or GNUTLS_E_NO_CERTIFICATE_FOUND if no certificate was sent.
*
-*/
@@ -484,7 +484,7 @@ _gnutls_openpgp_crt_verify_peers (mhd_gtls_session_t session,
return GNUTLS_E_INTERNAL_ERROR;
}
/* Verify certificate
/* Verify certificate
*/
if (_E_gnutls_openpgp_verify_key == NULL)
{
@@ -715,6 +715,7 @@ mhd_gtls_raw_privkey_to_gkey (gnutls_privkey * key,
{
case MHD_GNUTLS_CRT_X509:
return _gnutls_x509_raw_privkey_to_gkey (key, raw_key, key_enc);
#if ENABLE_OPENPGP
case MHD_GNUTLS_CRT_OPENPGP:
if (_E_gnutls_openpgp_raw_privkey_to_gkey == NULL)
{
@@ -724,6 +725,7 @@ mhd_gtls_raw_privkey_to_gkey (gnutls_privkey * key,
return _E_gnutls_openpgp_raw_privkey_to_gkey (key, raw_key,
(gnutls_openpgp_crt_fmt_t)
key_enc);
#endif
default:
gnutls_assert ();
return GNUTLS_E_INTERNAL_ERROR;
@@ -733,11 +735,11 @@ mhd_gtls_raw_privkey_to_gkey (gnutls_privkey * key,
/* This function will convert a der certificate to a format
* (structure) that gnutls can understand and use. Actually the
* important thing on this function is that it extracts the
* important thing on this function is that it extracts the
* certificate's (public key) parameters.
*
* The noext flag is used to complete the handshake even if the
* extensions found in the certificate are unsupported and critical.
* extensions found in the certificate are unsupported and critical.
* The critical extensions will be catched by the verification functions.
*/
int
+1 -1
View File
@@ -301,7 +301,7 @@ mhd_gtls_negotiate_version (mhd_gtls_session_t session,
}
int
mhd_gtls_user_hello_func (gnutls_session session,
mhd_gtls_user_hello_func (mhd_gtls_session_t session,
gnutls_protocol_t adv_version)
{
int ret;
+1 -1
View File
@@ -50,7 +50,7 @@ int mhd_gtls_server_select_suite (mhd_gtls_session_t session, opaque * data,
int datalen);
int mhd_gtls_negotiate_version( mhd_gtls_session_t session, gnutls_protocol_t adv_version);
int mhd_gtls_user_hello_func( gnutls_session, gnutls_protocol_t adv_version);
int mhd_gtls_user_hello_func( mhd_gtls_session_t, gnutls_protocol_t adv_version);
#if MHD_DEBUG_TLS
int mhd_gtls_handshake_client (mhd_gtls_session_t session);
+1 -6
View File
@@ -28,9 +28,9 @@
#include <defines.h>
#include "gnutls.h"
#include "extra.h"
#include "microhttpd.h"
#include "extra.h"
#include "gnutls_mem.h"
/* FIXME: delete this once opencdk has reentrant keyring functions
@@ -599,11 +599,6 @@ typedef struct
*/
int direction;
/* This callback will be used (if set) to receive an
* openpgp key. (if the peer sends a fingerprint)
*/
mhd_gtls_openpgp_recv_key_func openpgp_recv_key_func;
/* If non zero the server will not advertize the CA's he
* trusts (do not send an RDN sequence).
*/