aboutsummaryrefslogtreecommitdiffstats
path: root/src/lib/net/SecureSocket.h
blob: 773b508860d6a6bdf16983c3873e69b239d86625 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
/*
 * barrier -- mouse and keyboard sharing utility
 * Copyright (C) 2015-2016 Symless Ltd.
 * 
 * This package is free software; you can redistribute it and/or
 * modify it under the terms of the GNU General Public License
 * found in the file LICENSE that should have accompanied this file.
 * 
 * This package is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program.  If not, see <http://www.gnu.org/licenses/>.
 */

#pragma once

#include "net/TCPSocket.h"
#include "net/XSocket.h"

class IEventQueue;
class SocketMultiplexer;
class ISocketMultiplexerJob;

struct Ssl;

//! Secure socket
/*!
A secure socket using SSL.
*/
class SecureSocket : public TCPSocket {
public:
    SecureSocket(IEventQueue* events, SocketMultiplexer* socketMultiplexer, IArchNetwork::EAddressFamily family);
    SecureSocket(IEventQueue* events,
        SocketMultiplexer* socketMultiplexer,
        ArchSocket socket);
    ~SecureSocket();

    // ISocket overrides
    void                close();

    // IDataSocket overrides
    virtual void        connect(const NetworkAddress&);
    
    std::unique_ptr<ISocketMultiplexerJob> newJob() override;
    bool                isFatal() const { return m_fatal; }
    void                isFatal(bool b) { m_fatal = b; }
    bool                isSecureReady();
    void                secureConnect();
    void                secureAccept();
    int                    secureRead(void* buffer, int size, int& read);
    int                    secureWrite(const void* buffer, int size, int& wrote);
    EJobResult            doRead();
    EJobResult            doWrite();
    void                initSsl(bool server);
    bool                loadCertificates(String& CertFile);

private:
    // SSL
    void                initContext(bool server);
    void                createSSL();
    int                    secureAccept(int s);
    int                    secureConnect(int s);
    bool                showCertificate();
    void                checkResult(int n, int& retry);
    void                showError(const char* reason = NULL);
    String                getError();
    void                disconnect();
    void                formatFingerprint(String& fingerprint,
                                            bool hex = true,
                                            bool separator = true);
    bool                verifyCertFingerprint();

    MultiplexerJobStatus serviceConnect(ISocketMultiplexerJob*, bool, bool, bool);
    MultiplexerJobStatus serviceAccept(ISocketMultiplexerJob*, bool, bool, bool);

    void                showSecureConnectInfo();
    void                showSecureLibInfo();
    void                showSecureCipherInfo();
    
    void                handleTCPConnected(const Event& event, void*);

    void freeSSLResources();

private:
    Ssl*                m_ssl;
    bool                m_secureReady;
    bool                m_fatal;
};