diff options
Diffstat (limited to 'include')
| -rw-r--r-- | include/mod_gnutls.h | 122 |
1 files changed, 122 insertions, 0 deletions
diff --git a/include/mod_gnutls.h b/include/mod_gnutls.h new file mode 100644 index 0000000..70e641f --- /dev/null +++ b/include/mod_gnutls.h | |||
| @@ -0,0 +1,122 @@ | |||
| 1 | /* ==================================================================== | ||
| 2 | * Copyright 2004 Paul Querna | ||
| 3 | * | ||
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); | ||
| 5 | * you may not use this file except in compliance with the License. | ||
| 6 | * You may obtain a copy of the License at | ||
| 7 | * | ||
| 8 | * http://www.apache.org/licenses/LICENSE-2.0 | ||
| 9 | * | ||
| 10 | * Unless required by applicable law or agreed to in writing, software | ||
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, | ||
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| 13 | * See the License for the specific language governing permissions and | ||
| 14 | * limitations under the License. | ||
| 15 | * | ||
| 16 | */ | ||
| 17 | |||
| 18 | #ifndef __mod_gnutls_h_inc | ||
| 19 | #define __mod_gnutls_h_inc | ||
| 20 | |||
| 21 | #include "httpd.h" | ||
| 22 | #include "http_config.h" | ||
| 23 | #include "http_protocol.h" | ||
| 24 | #include "http_connection.h" | ||
| 25 | #include "http_core.h" | ||
| 26 | #include "http_log.h" | ||
| 27 | #include "apr_buckets.h" | ||
| 28 | #include "apr_strings.h" | ||
| 29 | #include "apr_tables.h" | ||
| 30 | |||
| 31 | #include <gcrypt.h> | ||
| 32 | #include <gnutls/gnutls.h> | ||
| 33 | |||
| 34 | module AP_MODULE_DECLARE_DATA gnutls_module; | ||
| 35 | |||
| 36 | #define GNUTLS_OUTPUT_FILTER_NAME "gnutls_output_filter" | ||
| 37 | #define GNUTLS_INPUT_FILTER_NAME "gnutls_input_filter" | ||
| 38 | |||
| 39 | #define GNUTLS_ENABLED_FALSE 0 | ||
| 40 | #define GNUTLS_ENABLED_TRUE 1 | ||
| 41 | |||
| 42 | |||
| 43 | typedef struct | ||
| 44 | { | ||
| 45 | gnutls_certificate_credentials_t certs; | ||
| 46 | gnutls_anon_server_credentials_t anoncred; | ||
| 47 | char *key_file; | ||
| 48 | char *cert_file; | ||
| 49 | int enabled; | ||
| 50 | int ciphers[16]; | ||
| 51 | int key_exchange[16]; | ||
| 52 | int macs[16]; | ||
| 53 | int protocol[16]; | ||
| 54 | int compression[16]; | ||
| 55 | } gnutls_srvconf_rec; | ||
| 56 | |||
| 57 | typedef struct gnutls_handle_t gnutls_handle_t; | ||
| 58 | struct gnutls_handle_t | ||
| 59 | { | ||
| 60 | gnutls_srvconf_rec *sc; | ||
| 61 | gnutls_session_t session; | ||
| 62 | ap_filter_t *input_filter; | ||
| 63 | apr_bucket_brigade *input_bb; | ||
| 64 | apr_read_type_e input_block; | ||
| 65 | int status; | ||
| 66 | int non_https; | ||
| 67 | }; | ||
| 68 | |||
| 69 | /** Functions in gnutls_io.c **/ | ||
| 70 | |||
| 71 | /** | ||
| 72 | * mod_gnutls_filter_input will filter the input data | ||
| 73 | * by decrypting it using GnuTLS and passes it cleartext. | ||
| 74 | * | ||
| 75 | * @param f the filter info record | ||
| 76 | * @param bb the bucket brigade, where to store the result to | ||
| 77 | * @param mode what shall we read? | ||
| 78 | * @param block a block index we shall read from? | ||
| 79 | * @return result status | ||
| 80 | */ | ||
| 81 | apr_status_t mod_gnutls_filter_input(ap_filter_t * f, | ||
| 82 | apr_bucket_brigade * bb, | ||
| 83 | ap_input_mode_t mode, | ||
| 84 | apr_read_type_e block, apr_off_t readbytes); | ||
| 85 | |||
| 86 | /** | ||
| 87 | * mod_gnutls_filter_output will filter the encrypt | ||
| 88 | * the incoming bucket using GnuTLS and passes it onto the next filter. | ||
| 89 | * | ||
| 90 | * @param f the filter info record | ||
| 91 | * @param bb the bucket brigade, where to store the result to | ||
| 92 | * @return result status | ||
| 93 | */ | ||
| 94 | apr_status_t mod_gnutls_filter_output(ap_filter_t * f, apr_bucket_brigade * bb); | ||
| 95 | |||
| 96 | |||
| 97 | /** | ||
| 98 | * mod_gnutls_transport_read is called from GnuTLS to provide encrypted | ||
| 99 | * data from the client. | ||
| 100 | * | ||
| 101 | * @param ptr pointer to the filter context | ||
| 102 | * @param buffer place to put data | ||
| 103 | * @param len maximum size | ||
| 104 | * @return size length of the data stored in buffer | ||
| 105 | */ | ||
| 106 | ssize_t mod_gnutls_transport_read(gnutls_transport_ptr_t ptr, | ||
| 107 | void *buffer, size_t len); | ||
| 108 | |||
| 109 | /** | ||
| 110 | * mod_gnutls_transport_write is called from GnuTLS to | ||
| 111 | * write data to the client. | ||
| 112 | * | ||
| 113 | * @param ptr pointer to the filter context | ||
| 114 | * @param buffer buffer to write to the client | ||
| 115 | * @param len size of the buffer | ||
| 116 | * @return size length of the data written | ||
| 117 | */ | ||
| 118 | ssize_t mod_gnutls_transport_write(gnutls_transport_ptr_t ptr, | ||
| 119 | const void *buffer, size_t len); | ||
| 120 | |||
| 121 | |||
| 122 | #endif /* __mod_gnutls_h_inc */ | ||
