mirror of
https://git.gnunet.org/libmicrohttpd.git
synced 2026-10-01 04:03:18 +03:00
bind option uses sockaddr - [ ! MHD_USE_IPv6 should be removed in favor of a generic addrlen argument ]
openpgp support currently disabled
This commit is contained in:
1 parent
63f23d2131
commit
c5ad835c7c
26 files changed
+544
-1836
No files matched your search
@@ -26,10 +26,10 @@ auth_rsa.c \
|
||||
auth_rsa_export.c \
|
||||
debug.c \
|
||||
ext_cert_type.c \
|
||||
ext_inner_application.c \
|
||||
ext_max_record.c \
|
||||
ext_oprfi.c \
|
||||
ext_server_name.c \
|
||||
ext_inner_application.c \
|
||||
gnutls_alert.c \
|
||||
gnutls_algorithms.c \
|
||||
gnutls_anon_cred.c \
|
||||
@@ -68,6 +68,4 @@ gnutls_supplemental.c \
|
||||
gnutls_ui.c \
|
||||
gnutls_x509.c \
|
||||
pkix_asn1_tab.c \
|
||||
x509_b64.c
|
||||
|
||||
|
||||
x509_b64.c
|
||||
@@ -23,13 +23,14 @@
|
||||
*/
|
||||
|
||||
#ifndef AUTH_CERT_H
|
||||
# define AUTH_CERT_H
|
||||
#define AUTH_CERT_H
|
||||
|
||||
# include "gnutls_cert.h"
|
||||
# include "gnutls_auth.h"
|
||||
# include "auth_dh_common.h"
|
||||
# include "x509.h"
|
||||
# include "openpgp.h"
|
||||
#include "gnutls_cert.h"
|
||||
#include "gnutls_auth.h"
|
||||
#include "auth_dh_common.h"
|
||||
#include "x509.h"
|
||||
#include "openpgp.h"
|
||||
#include "extra.h"
|
||||
|
||||
/* This structure may be complex, but it's the only way to
|
||||
* support a server that has multiple certificates
|
||||
|
||||
@@ -63,7 +63,8 @@ mhd_gtls_inner_app_rcv_params (mhd_gtls_session_t session,
|
||||
}
|
||||
|
||||
|
||||
/* returns data_size or a negative number on failure
|
||||
/**
|
||||
* returns data_size or a negative number on failure
|
||||
*/
|
||||
int
|
||||
mhd_gtls_inner_app_send_params (mhd_gtls_session_t session,
|
||||
|
||||
@@ -314,11 +314,11 @@ MHD_gtls_certificate_server_set_request (mhd_gtls_session_t session,
|
||||
* This function sets a callback to be called in order to retrieve the certificate
|
||||
* to be used in the handshake.
|
||||
* The callback's function prototype is:
|
||||
* int (*callback)(mhd_gtls_session_t, const gnutls_datum_t* req_ca_dn, int nreqs,
|
||||
* int (*callback)(mhd_gtls_session_t, const gnutls_datum_t* req_ca_dn, int nreqs,
|
||||
* const gnutls_pk_algorithm_t* pk_algos, int pk_algos_length, gnutls_retr_st* st);
|
||||
*
|
||||
* @req_ca_cert is only used in X.509 certificates.
|
||||
* Contains a list with the CA names that the server considers trusted.
|
||||
* @req_ca_cert is only used in X.509 certificates.
|
||||
* Contains a list with the CA names that the server considers trusted.
|
||||
* Normally we should send a certificate that is signed
|
||||
* by one of these CAs. These names are DER encoded. To get a more
|
||||
* meaningful value use the function gnutls_x509_rdn_get().
|
||||
@@ -441,7 +441,7 @@ _gnutls_x509_get_raw_crt_expiration_time (const gnutls_datum_t * cert)
|
||||
* _gnutls_openpgp_crt_verify_peers - This function returns the peer's certificate status
|
||||
* @session: is a gnutls session
|
||||
*
|
||||
* This function will try to verify the peer's certificate and return its status (TRUSTED, INVALID etc.).
|
||||
* This function will try to verify the peer's certificate and return its status (TRUSTED, INVALID etc.).
|
||||
* Returns a negative error code in case of an error, or GNUTLS_E_NO_CERTIFICATE_FOUND if no certificate was sent.
|
||||
*
|
||||
-*/
|
||||
@@ -484,7 +484,7 @@ _gnutls_openpgp_crt_verify_peers (mhd_gtls_session_t session,
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
|
||||
/* Verify certificate
|
||||
/* Verify certificate
|
||||
*/
|
||||
if (_E_gnutls_openpgp_verify_key == NULL)
|
||||
{
|
||||
@@ -715,6 +715,7 @@ mhd_gtls_raw_privkey_to_gkey (gnutls_privkey * key,
|
||||
{
|
||||
case MHD_GNUTLS_CRT_X509:
|
||||
return _gnutls_x509_raw_privkey_to_gkey (key, raw_key, key_enc);
|
||||
#if ENABLE_OPENPGP
|
||||
case MHD_GNUTLS_CRT_OPENPGP:
|
||||
if (_E_gnutls_openpgp_raw_privkey_to_gkey == NULL)
|
||||
{
|
||||
@@ -724,6 +725,7 @@ mhd_gtls_raw_privkey_to_gkey (gnutls_privkey * key,
|
||||
return _E_gnutls_openpgp_raw_privkey_to_gkey (key, raw_key,
|
||||
(gnutls_openpgp_crt_fmt_t)
|
||||
key_enc);
|
||||
#endif
|
||||
default:
|
||||
gnutls_assert ();
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
@@ -733,11 +735,11 @@ mhd_gtls_raw_privkey_to_gkey (gnutls_privkey * key,
|
||||
|
||||
/* This function will convert a der certificate to a format
|
||||
* (structure) that gnutls can understand and use. Actually the
|
||||
* important thing on this function is that it extracts the
|
||||
* important thing on this function is that it extracts the
|
||||
* certificate's (public key) parameters.
|
||||
*
|
||||
* The noext flag is used to complete the handshake even if the
|
||||
* extensions found in the certificate are unsupported and critical.
|
||||
* extensions found in the certificate are unsupported and critical.
|
||||
* The critical extensions will be catched by the verification functions.
|
||||
*/
|
||||
int
|
||||
|
||||
@@ -301,7 +301,7 @@ mhd_gtls_negotiate_version (mhd_gtls_session_t session,
|
||||
}
|
||||
|
||||
int
|
||||
mhd_gtls_user_hello_func (gnutls_session session,
|
||||
mhd_gtls_user_hello_func (mhd_gtls_session_t session,
|
||||
gnutls_protocol_t adv_version)
|
||||
{
|
||||
int ret;
|
||||
|
||||
@@ -50,7 +50,7 @@ int mhd_gtls_server_select_suite (mhd_gtls_session_t session, opaque * data,
|
||||
int datalen);
|
||||
|
||||
int mhd_gtls_negotiate_version( mhd_gtls_session_t session, gnutls_protocol_t adv_version);
|
||||
int mhd_gtls_user_hello_func( gnutls_session, gnutls_protocol_t adv_version);
|
||||
int mhd_gtls_user_hello_func( mhd_gtls_session_t, gnutls_protocol_t adv_version);
|
||||
|
||||
#if MHD_DEBUG_TLS
|
||||
int mhd_gtls_handshake_client (mhd_gtls_session_t session);
|
||||
|
||||
@@ -28,9 +28,9 @@
|
||||
#include <defines.h>
|
||||
|
||||
#include "gnutls.h"
|
||||
#include "extra.h"
|
||||
#include "microhttpd.h"
|
||||
|
||||
#include "extra.h"
|
||||
#include "gnutls_mem.h"
|
||||
|
||||
/* FIXME: delete this once opencdk has reentrant keyring functions
|
||||
@@ -599,11 +599,6 @@ typedef struct
|
||||
*/
|
||||
int direction;
|
||||
|
||||
/* This callback will be used (if set) to receive an
|
||||
* openpgp key. (if the peer sends a fingerprint)
|
||||
*/
|
||||
mhd_gtls_openpgp_recv_key_func openpgp_recv_key_func;
|
||||
|
||||
/* If non zero the server will not advertize the CA's he
|
||||
* trusts (do not send an RDN sequence).
|
||||
*/
|
||||
|
||||
Reference in new issue
Block a user