22 #ifndef __KOPENSSLPROXY_H
23 #define __KOPENSSLPROXY_H
25 #define KOSSL KOpenSSLProxy
26 class KOpenSSLProxyPrivate;
28 #include <klibloader.h>
31 #include "ksslconfig_win.h"
33 #include "ksslconfig.h"
37 #define crypt _openssl_crypt
38 #include <openssl/ssl.h>
39 #include <openssl/x509.h>
40 #include <openssl/x509v3.h>
41 #include <openssl/pem.h>
42 #include <openssl/bio.h>
43 #include <openssl/rand.h>
44 #include <openssl/asn1.h>
45 #include <openssl/pkcs7.h>
46 #include <openssl/pkcs12.h>
47 #include <openssl/evp.h>
48 #include <openssl/stack.h>
49 #include <openssl/bn.h>
51 #if OPENSSL_VERSION_NUMBER >= 0x10100000L
52 #define STACK OPENSSL_STACK
54 #if OPENSSL_VERSION_NUMBER >= 0x10000000L
60 #include <kstaticdeleter.h>
62 #if OPENSSL_VERSION_NUMBER < 0x10100000L
63 typedef int (*X509_STORE_CTX_verify_cb)(int, X509_STORE_CTX *);
64 typedef int X509_LOOKUP_TYPE;
76 friend class KStaticDeleter<KOpenSSLProxy>;
83 static KOpenSSLProxy *
self();
88 bool hasLibCrypto()
const;
93 bool hasLibSSL()
const;
107 int SSL_connect(SSL *ssl);
112 int SSL_accept(SSL *ssl);
117 int SSL_get_error(SSL *ssl,
int rc);
122 int SSL_read(SSL *ssl,
void *buf,
int num);
127 int SSL_write(SSL *ssl,
const void *buf,
int num);
132 SSL *SSL_new(SSL_CTX *ctx);
137 void SSL_free(SSL *ssl);
142 int SSL_shutdown(SSL *ssl);
147 SSL_CTX *SSL_CTX_new(SSL_METHOD *method);
152 void SSL_CTX_free(SSL_CTX *ctx);
157 int SSL_set_fd(SSL *ssl,
int fd);
162 int SSL_pending(SSL *ssl);
167 int SSL_peek(SSL *ssl,
void *buf,
int num);
172 int SSL_CTX_set_cipher_list(SSL_CTX *ctx,
const char *str);
177 void SSL_CTX_set_verify(SSL_CTX *ctx,
int mode,
178 int (*verify_callback)(
int, X509_STORE_CTX *));
183 int SSL_use_certificate(SSL *ssl, X509 *x);
188 SSL_CIPHER *SSL_get_current_cipher(SSL *ssl);
191 long _SSL_set_options(SSL *ssl,
long options);
194 int _SSL_session_reused(SSL *ssl);
197 long SSL_ctrl(SSL *ssl,
int cmd,
long larg,
void *parg);
202 int RAND_egd(
const char *path);
208 const char *RAND_file_name(
char *buf,
size_t num);
214 int RAND_load_file(
const char *filename,
long max_bytes);
220 int RAND_write_file(
const char *filename);
226 SSL_METHOD *TLSv1_client_method();
232 SSL_METHOD *SSLv2_client_method();
238 SSL_METHOD *SSLv3_client_method();
244 SSL_METHOD *TLS_client_method();
250 X509 *SSL_get_peer_certificate(SSL *s);
256 STACK_OF(X509) *SSL_get_peer_cert_chain(SSL *s);
261 int SSL_CIPHER_get_bits(SSL_CIPHER *c,
int *alg_bits);
267 char *SSL_CIPHER_get_version(SSL_CIPHER *c);
273 const char *SSL_CIPHER_get_name(SSL_CIPHER *c);
279 char *SSL_CIPHER_description(SSL_CIPHER *,
char *buf,
int size);
286 int SSL_CTX_use_PrivateKey(SSL_CTX *ctx, EVP_PKEY *pkey);
292 int SSL_CTX_use_certificate(SSL_CTX *ctx, X509 *x);
298 X509 * d2i_X509(X509 **a,
unsigned char **pp,
long length);
303 X509_CRL * d2i_X509_CRL(X509_CRL **a,
unsigned char **pp,
long length);
309 int i2d_X509(X509 *a,
unsigned char **pp);
315 int X509_cmp(X509 *a, X509 *b);
321 int X509_subject_name_cmp(
const X509 *a,
const X509 *b);
327 X509 *X509_dup(X509 *x509);
333 void X509_get0_signature(
const ASN1_BIT_STRING **psig,
334 const X509_ALGOR **palg,
const X509 *x);
341 ASN1_TIME *X509_getm_notAfter(
const X509 *x);
347 ASN1_TIME *X509_getm_notBefore(
const X509 *x);
353 X509_STORE_CTX *X509_STORE_CTX_new(
void);
359 void X509_STORE_CTX_free(X509_STORE_CTX *v);
365 void X509_STORE_CTX_set0_untrusted(X509_STORE_CTX *v, STACK_OF(X509)* x);
371 void X509_STORE_CTX_set_purpose(X509_STORE_CTX *v,
int purpose);
377 X509 *X509_STORE_CTX_get_current_cert(X509_STORE_CTX *ctx);
383 int X509_STORE_CTX_get_error(X509_STORE_CTX *ctx);
389 int X509_STORE_CTX_get_error_depth(X509_STORE_CTX *ctx);
395 void X509_STORE_CTX_set_error(X509_STORE_CTX *ctx,
int s);
401 void X509_STORE_set_verify_cb(X509_STORE *ctx,
402 X509_STORE_CTX_verify_cb verify_cb);
408 STACK_OF(X509_OBJECT) *X509_STORE_get0_objects(X509_STORE *v);
414 X509_LOOKUP_TYPE X509_OBJECT_get_type(
const X509_OBJECT *a);
420 X509 *X509_OBJECT_get0_X509(
const X509_OBJECT *a);
426 int X509_verify_cert(X509_STORE_CTX *v);
432 X509_STORE *X509_STORE_new(
void);
438 void X509_STORE_free(X509_STORE *v);
444 void X509_free(X509 *v);
449 void X509_CRL_free(X509_CRL *v);
455 const ASN1_TIME *X509_CRL_get0_lastUpdate(
const X509_CRL *crl);
461 const ASN1_TIME *X509_CRL_get0_nextUpdate(
const X509_CRL *crl);
467 char *X509_NAME_oneline(X509_NAME *a,
char *buf,
int size);
473 X509_NAME *X509_get_subject_name(X509 *a);
479 X509_NAME *X509_get_issuer_name(X509 *a);
485 X509_LOOKUP *X509_STORE_add_lookup(X509_STORE *v, X509_LOOKUP_METHOD *m);
491 X509_LOOKUP_METHOD *X509_LOOKUP_file(
void);
497 void X509_LOOKUP_free(X509_LOOKUP *x);
503 int X509_LOOKUP_ctrl(X509_LOOKUP *ctx,
int cmd,
const char *argc,
long argl,
char **ret);
509 void X509_STORE_CTX_init(X509_STORE_CTX *ctx, X509_STORE *store, X509 *x509, STACK_OF(X509) *chain);
515 void CRYPTO_free(
void *x);
520 BIO *BIO_new(BIO_METHOD *type);
525 BIO_METHOD *BIO_s_mem(
void);
530 BIO *BIO_new_fp(FILE *stream,
int close_flag);
535 BIO *BIO_new_mem_buf(
void *buf,
int len);
540 int BIO_free(BIO *a);
545 long BIO_ctrl(BIO *bp,
int cmd,
long larg,
void *parg);
550 int BIO_write(BIO *b,
const void *data,
int len);
555 void *BIO_get_data(BIO *a);
560 int PEM_write_bio_X509(BIO *bp, X509 *x);
562 #if OPENSSL_VERSION_NUMBER < 0x10000000L
566 ASN1_METHOD *X509_asn1_meth();
572 int ASN1_i2d_fp(FILE *out,
unsigned char *x);
578 X509 *X509_d2i_fp(FILE *out, X509** buf);
584 int X509_print(FILE *fp, X509 *x);
590 PKCS12 *d2i_PKCS12_fp(FILE *fp, PKCS12 **p12);
596 int PKCS12_newpass(PKCS12 *p12,
char *oldpass,
char *newpass);
602 int i2d_PKCS12(PKCS12 *p12,
unsigned char **p);
608 int i2d_PKCS12_fp(FILE *fp, PKCS12 *p12);
614 PKCS12 *PKCS12_new(
void);
620 void PKCS12_free(PKCS12 *a);
626 int PKCS12_parse(PKCS12 *p12,
const char *pass, EVP_PKEY **pkey,
627 X509 **cert, STACK_OF(X509) **ca);
633 void EVP_PKEY_free(EVP_PKEY *x);
639 char *OPENSSL_sk_pop(STACK *s);
641 char *OPENSSL_sk_pop(
void *s) {
return OPENSSL_sk_pop(reinterpret_cast<STACK*>(s)); }
647 void OPENSSL_sk_free(STACK *s);
649 void OPENSSL_sk_free(
void *s) { OPENSSL_sk_free(reinterpret_cast<STACK*>(s)); }
654 int OPENSSL_sk_num(STACK *s);
656 int OPENSSL_sk_num(
void *s) {
return OPENSSL_sk_num(reinterpret_cast<STACK*>(s)); }
661 char *OPENSSL_sk_value(STACK *s,
int n);
663 char *OPENSSL_sk_value(
void *s,
int n) {
return OPENSSL_sk_value(reinterpret_cast<STACK*>(s), n); }
668 STACK *OPENSSL_sk_new(
int (*cmp)());
674 int OPENSSL_sk_push(STACK *s,
char *d);
676 int OPENSSL_sk_push(
void *s,
void *d) {
return OPENSSL_sk_push(reinterpret_cast<STACK*>(s), reinterpret_cast<char*>(d)); }
681 STACK *OPENSSL_sk_dup(
const STACK *s);
683 STACK *OPENSSL_sk_dup(
const void *s) {
return OPENSSL_sk_dup(reinterpret_cast<const STACK*>(s)); }
688 char *i2s_ASN1_INTEGER(X509V3_EXT_METHOD *meth, ASN1_INTEGER *aint);
694 ASN1_INTEGER *X509_get_serialNumber(X509 *x);
700 EVP_PKEY *X509_get_pubkey(X509 *x);
706 int i2d_PublicKey(EVP_PKEY *a,
unsigned char **pp);
712 int X509_check_private_key(X509 *x, EVP_PKEY *p);
718 char *BN_bn2hex(
const BIGNUM *a);
724 int X509_digest(
const X509 *x,
const EVP_MD *t,
unsigned char *md,
unsigned int *len);
736 void ASN1_INTEGER_free(ASN1_INTEGER *x);
742 unsigned char *ASN1_STRING_data(ASN1_STRING *x);
747 int ASN1_STRING_length(ASN1_STRING *x);
752 int OBJ_obj2nid(ASN1_OBJECT *o);
757 const char * OBJ_nid2ln(
int n);
762 int X509_get_ext_count(X509 *x);
767 int X509_get_ext_by_NID(X509 *x,
int nid,
int lastpos);
772 int X509_get_ext_by_OBJ(X509 *x,ASN1_OBJECT *obj,
int lastpos);
777 X509_EXTENSION *X509_get_ext(X509 *x,
int loc);
782 X509_EXTENSION *X509_delete_ext(X509 *x,
int loc);
787 int X509_add_ext(X509 *x, X509_EXTENSION *ex,
int loc);
792 void *X509_get_ext_d2i(X509 *x,
int nid,
int *crit,
int *idx);
797 char *i2s_ASN1_OCTET_STRING(X509V3_EXT_METHOD *method, ASN1_OCTET_STRING *ia5);
802 int ASN1_BIT_STRING_get_bit(ASN1_BIT_STRING *a,
int n);
807 PKCS7 *PKCS7_new(
void);
812 void PKCS7_free(PKCS7 *a);
817 void PKCS7_content_free(PKCS7 *a);
822 int i2d_PKCS7(PKCS7 *a,
unsigned char **pp);
827 PKCS7 *d2i_PKCS7(PKCS7 **a,
unsigned char **pp,
long length);
832 int i2d_PKCS7_fp(FILE *fp,PKCS7 *p7);
837 PKCS7 *d2i_PKCS7_fp(FILE *fp,PKCS7 **p7);
842 int i2d_PKCS7_bio(BIO *bp,PKCS7 *p7);
847 PKCS7 *d2i_PKCS7_bio(BIO *bp,PKCS7 **p7);
852 PKCS7 *PKCS7_dup(PKCS7 *p7);
857 PKCS7 *PKCS7_sign(X509 *signcert, EVP_PKEY *pkey, STACK_OF(X509) *certs,
858 BIO *data,
int flags);
863 int PKCS7_verify(PKCS7 *p7, STACK_OF(X509) *certs, X509_STORE *store,
864 BIO *indata, BIO *out,
int flags);
869 STACK_OF(X509) *PKCS7_get0_signers(PKCS7 *p7, STACK_OF(X509) *certs,
int flags);
874 PKCS7 *PKCS7_encrypt(STACK_OF(X509) *certs, BIO *in, EVP_CIPHER *cipher,
880 int PKCS7_decrypt(PKCS7 *p7, EVP_PKEY *pkey, X509 *cert, BIO *data,
int flags);
886 STACK_OF(X509_NAME) *SSL_load_client_CA_file(
const char *file);
891 STACK_OF(X509_INFO) *PEM_X509_INFO_read(FILE *fp, STACK_OF(X509_INFO) *sk,
892 pem_password_cb *cb,
void *u);
897 int X509_PURPOSE_get_count();
903 int X509_PURPOSE_get_id(X509_PURPOSE *);
909 int X509_check_purpose(X509 *x,
int id,
int ca);
915 X509_PURPOSE * X509_PURPOSE_get0(
int idx);
921 EVP_PKEY* EVP_PKEY_new();
927 int EVP_PKEY_base_id(
const EVP_PKEY *pkey);
933 int EVP_PKEY_assign(EVP_PKEY *pkey,
int type,
char *key);
939 RSA *EVP_PKEY_get0_RSA(EVP_PKEY *pkey);
945 DSA *EVP_PKEY_get0_DSA(EVP_PKEY *pkey);
951 void RSA_get0_key(
const RSA *r,
952 const BIGNUM **n,
const BIGNUM **e,
const BIGNUM **d);
958 RSA *RSA_generate_key(
int bits,
unsigned long e,
void
959 (*callback)(
int,
int,
void *),
void *cb_arg);
965 void DSA_get0_pqg(
const DSA *d,
966 const BIGNUM **p,
const BIGNUM **q,
const BIGNUM **g);
972 void DSA_get0_key(
const DSA *d,
973 const BIGNUM **pub_key,
const BIGNUM **priv_key);
979 X509_REQ *X509_REQ_new();
980 void X509_REQ_free(X509_REQ *a);
986 int X509_REQ_set_pubkey(X509_REQ *x, EVP_PKEY *pkey);
989 int i2d_X509_REQ_fp(FILE *fp, X509_REQ *x);
992 STACK *X509_get1_email(X509 *x);
993 void X509_email_free(STACK *sk);
996 EVP_CIPHER *EVP_des_ede3_cbc();
997 EVP_CIPHER *EVP_des_cbc();
998 EVP_CIPHER *EVP_rc2_cbc();
999 EVP_CIPHER *EVP_rc2_64_cbc();
1000 EVP_CIPHER *EVP_rc2_40_cbc();
1003 void ERR_clear_error();
1006 unsigned long ERR_get_error();
1009 void ERR_print_errors_fp(FILE *fp);
1012 SSL_SESSION *SSL_get1_session(SSL *ssl);
1015 void SSL_SESSION_free(SSL_SESSION *session);
1018 int SSL_set_session(SSL *ssl, SSL_SESSION *session);
1021 SSL_SESSION *d2i_SSL_SESSION(SSL_SESSION **a,
unsigned char **pp,
long length);
1023 int i2d_SSL_SESSION(SSL_SESSION *in,
unsigned char **pp);
1026 int i2d_PrivateKey_fp(FILE*, EVP_PKEY*);
1029 int i2d_PKCS8PrivateKey_fp(FILE*, EVP_PKEY*,
const EVP_CIPHER*,
char*,
int, pem_password_cb*,
void*);
1032 void RSA_free(RSA*);
1035 EVP_CIPHER *EVP_bf_cbc();
1038 int X509_REQ_sign(X509_REQ*, EVP_PKEY*,
const EVP_MD*);
1041 int X509_NAME_add_entry_by_txt(X509_NAME*,
char*,
int,
unsigned char*,
int,
int,
int);
1044 X509_NAME *X509_NAME_new();
1047 int X509_REQ_set_subject_name(X509_REQ*,X509_NAME*);
1050 STACK_OF(SSL_CIPHER) *SSL_get_ciphers(
const SSL* ssl);
1054 #if OPENSSL_VERSION_NUMBER >= 0x10100000L && OPENSSL_API_COMPAT < 0x10100000L
1062 # undef X509_STORE_CTX_set_chain
1063 # undef SSLv23_client_method
1065 STACK *sk_dup(
const STACK *s) KDE_DEPRECATED;
1066 void sk_free(STACK *s) KDE_DEPRECATED;
1067 STACK *sk_new(
int (*cmp)()) KDE_DEPRECATED;
1068 int sk_num(STACK *s) KDE_DEPRECATED;
1069 char *sk_pop(STACK *s) KDE_DEPRECATED;
1070 int sk_push(STACK *s,
char *d) KDE_DEPRECATED;
1071 char *sk_value(STACK *s,
int n) KDE_DEPRECATED;
1072 void X509_STORE_CTX_set_chain(X509_STORE_CTX *v, STACK_OF(X509)* x) KDE_DEPRECATED;
1073 SSL_METHOD *SSLv23_client_method() KDE_DEPRECATED;
1080 KOpenSSLProxyPrivate *d;
1083 KLibrary *_cryptoLib;
1084 static KOpenSSLProxy *_me;
Dynamically load and wrap OpenSSL.