Blame gio/gtlsbackend.c

Packit ae235b
/* GIO - GLib Input, Output and Streaming Library
Packit ae235b
 *
Packit ae235b
 * Copyright © 2010 Red Hat, Inc
Packit ae235b
 * Copyright © 2015 Collabora, Ltd.
Packit ae235b
 *
Packit ae235b
 * This library is free software; you can redistribute it and/or
Packit ae235b
 * modify it under the terms of the GNU Lesser General Public
Packit ae235b
 * License as published by the Free Software Foundation; either
Packit ae235b
 * version 2.1 of the License, or (at your option) any later version.
Packit ae235b
 *
Packit ae235b
 * This library is distributed in the hope that it will be useful,
Packit ae235b
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
Packit ae235b
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
Packit ae235b
 * Lesser General Public License for more details.
Packit ae235b
 *
Packit ae235b
 * You should have received a copy of the GNU Lesser General
Packit ae235b
 * Public License along with this library; if not, see <http://www.gnu.org/licenses/>.
Packit ae235b
 */
Packit ae235b
Packit ae235b
#include "config.h"
Packit ae235b
#include "glib.h"
Packit ae235b
Packit ae235b
#include "gtlsbackend.h"
Packit ae235b
#include "gdummytlsbackend.h"
Packit ae235b
#include "gioenumtypes.h"
Packit ae235b
#include "giomodule-priv.h"
Packit ae235b
Packit ae235b
/**
Packit ae235b
 * SECTION:gtls
Packit ae235b
 * @title: TLS Overview
Packit ae235b
 * @short_description: TLS (aka SSL) support for GSocketConnection
Packit ae235b
 * @include: gio/gio.h
Packit ae235b
 *
Packit ae235b
 * #GTlsConnection and related classes provide TLS (Transport Layer
Packit ae235b
 * Security, previously known as SSL, Secure Sockets Layer) support for
Packit ae235b
 * gio-based network streams.
Packit ae235b
 *
Packit ae235b
 * #GDtlsConnection and related classes provide DTLS (Datagram TLS) support for
Packit ae235b
 * GIO-based network sockets, using the #GDatagramBased interface. The TLS and
Packit ae235b
 * DTLS APIs are almost identical, except TLS is stream-based and DTLS is
Packit ae235b
 * datagram-based. They share certificate and backend infrastructure.
Packit ae235b
 *
Packit ae235b
 * In the simplest case, for a client TLS connection, you can just set the
Packit ae235b
 * #GSocketClient:tls flag on a #GSocketClient, and then any
Packit ae235b
 * connections created by that client will have TLS negotiated
Packit ae235b
 * automatically, using appropriate default settings, and rejecting
Packit ae235b
 * any invalid or self-signed certificates (unless you change that
Packit ae235b
 * default by setting the #GSocketClient:tls-validation-flags
Packit ae235b
 * property). The returned object will be a #GTcpWrapperConnection,
Packit ae235b
 * which wraps the underlying #GTlsClientConnection.
Packit ae235b
 *
Packit ae235b
 * For greater control, you can create your own #GTlsClientConnection,
Packit ae235b
 * wrapping a #GSocketConnection (or an arbitrary #GIOStream with
Packit ae235b
 * pollable input and output streams) and then connect to its signals,
Packit ae235b
 * such as #GTlsConnection::accept-certificate, before starting the
Packit ae235b
 * handshake.
Packit ae235b
 *
Packit ae235b
 * Server-side TLS is similar, using #GTlsServerConnection. At the
Packit ae235b
 * moment, there is no support for automatically wrapping server-side
Packit ae235b
 * connections in the way #GSocketClient does for client-side
Packit ae235b
 * connections.
Packit ae235b
 */
Packit ae235b
Packit ae235b
/**
Packit ae235b
 * SECTION:gtlsbackend
Packit ae235b
 * @title: GTlsBackend
Packit ae235b
 * @short_description: TLS backend implementation
Packit ae235b
 * @include: gio/gio.h
Packit ae235b
 *
Packit ae235b
 * TLS (Transport Layer Security, aka SSL) and DTLS backend.
Packit ae235b
 *
Packit ae235b
 * Since: 2.28
Packit ae235b
 */
Packit ae235b
Packit ae235b
/**
Packit ae235b
 * GTlsBackend:
Packit ae235b
 *
Packit ae235b
 * TLS (Transport Layer Security, aka SSL) and DTLS backend. This is an
Packit ae235b
 * internal type used to coordinate the different classes implemented
Packit ae235b
 * by a TLS backend.
Packit ae235b
 *
Packit ae235b
 * Since: 2.28
Packit ae235b
 */
Packit ae235b
Packit ae235b
G_DEFINE_INTERFACE (GTlsBackend, g_tls_backend, G_TYPE_OBJECT)
Packit ae235b
Packit ae235b
static void
Packit ae235b
g_tls_backend_default_init (GTlsBackendInterface *iface)
Packit ae235b
{
Packit ae235b
}
Packit ae235b
Packit ae235b
/**
Packit ae235b
 * g_tls_backend_get_default:
Packit ae235b
 *
Packit ae235b
 * Gets the default #GTlsBackend for the system.
Packit ae235b
 *
Packit ae235b
 * Returns: (transfer none): a #GTlsBackend
Packit ae235b
 *
Packit ae235b
 * Since: 2.28
Packit ae235b
 */
Packit ae235b
GTlsBackend *
Packit ae235b
g_tls_backend_get_default (void)
Packit ae235b
{
Packit ae235b
  return _g_io_module_get_default (G_TLS_BACKEND_EXTENSION_POINT_NAME,
Packit ae235b
				   "GIO_USE_TLS", NULL);
Packit ae235b
}
Packit ae235b
Packit ae235b
/**
Packit ae235b
 * g_tls_backend_supports_tls:
Packit ae235b
 * @backend: the #GTlsBackend
Packit ae235b
 *
Packit ae235b
 * Checks if TLS is supported; if this returns %FALSE for the default
Packit ae235b
 * #GTlsBackend, it means no "real" TLS backend is available.
Packit ae235b
 *
Packit ae235b
 * Returns: whether or not TLS is supported
Packit ae235b
 *
Packit ae235b
 * Since: 2.28
Packit ae235b
 */
Packit ae235b
gboolean
Packit ae235b
g_tls_backend_supports_tls (GTlsBackend *backend)
Packit ae235b
{
Packit ae235b
  if (G_TLS_BACKEND_GET_INTERFACE (backend)->supports_tls)
Packit ae235b
    return G_TLS_BACKEND_GET_INTERFACE (backend)->supports_tls (backend);
Packit ae235b
  else if (G_IS_DUMMY_TLS_BACKEND (backend))
Packit ae235b
    return FALSE;
Packit ae235b
  else
Packit ae235b
    return TRUE;
Packit ae235b
}
Packit ae235b
Packit ae235b
/**
Packit ae235b
 * g_tls_backend_supports_dtls:
Packit ae235b
 * @backend: the #GTlsBackend
Packit ae235b
 *
Packit ae235b
 * Checks if DTLS is supported. DTLS support may not be available even if TLS
Packit ae235b
 * support is available, and vice-versa.
Packit ae235b
 *
Packit ae235b
 * Returns: whether DTLS is supported
Packit ae235b
 *
Packit ae235b
 * Since: 2.48
Packit ae235b
 */
Packit ae235b
gboolean
Packit ae235b
g_tls_backend_supports_dtls (GTlsBackend *backend)
Packit ae235b
{
Packit ae235b
  if (G_TLS_BACKEND_GET_INTERFACE (backend)->supports_dtls)
Packit ae235b
    return G_TLS_BACKEND_GET_INTERFACE (backend)->supports_dtls (backend);
Packit ae235b
Packit ae235b
  return FALSE;
Packit ae235b
}
Packit ae235b
Packit ae235b
/**
Packit ae235b
 * g_tls_backend_get_default_database:
Packit ae235b
 * @backend: the #GTlsBackend
Packit ae235b
 *
Packit ae235b
 * Gets the default #GTlsDatabase used to verify TLS connections.
Packit ae235b
 *
Packit ae235b
 * Returns: (transfer full): the default database, which should be
Packit ae235b
 *               unreffed when done.
Packit ae235b
 *
Packit ae235b
 * Since: 2.30
Packit ae235b
 */
Packit ae235b
GTlsDatabase *
Packit ae235b
g_tls_backend_get_default_database (GTlsBackend *backend)
Packit ae235b
{
Packit ae235b
  g_return_val_if_fail (G_IS_TLS_BACKEND (backend), NULL);
Packit ae235b
Packit ae235b
  /* This method was added later, so accept the (remote) possibility it can be NULL */
Packit ae235b
  if (!G_TLS_BACKEND_GET_INTERFACE (backend)->get_default_database)
Packit ae235b
    return NULL;
Packit ae235b
Packit ae235b
  return G_TLS_BACKEND_GET_INTERFACE (backend)->get_default_database (backend);
Packit ae235b
}
Packit ae235b
Packit ae235b
/**
Packit ae235b
 * g_tls_backend_get_certificate_type:
Packit ae235b
 * @backend: the #GTlsBackend
Packit ae235b
 *
Packit ae235b
 * Gets the #GType of @backend's #GTlsCertificate implementation.
Packit ae235b
 *
Packit ae235b
 * Returns: the #GType of @backend's #GTlsCertificate
Packit ae235b
 *   implementation.
Packit ae235b
 *
Packit ae235b
 * Since: 2.28
Packit ae235b
 */
Packit ae235b
GType
Packit ae235b
g_tls_backend_get_certificate_type (GTlsBackend *backend)
Packit ae235b
{
Packit ae235b
  return G_TLS_BACKEND_GET_INTERFACE (backend)->get_certificate_type ();
Packit ae235b
}
Packit ae235b
Packit ae235b
/**
Packit ae235b
 * g_tls_backend_get_client_connection_type:
Packit ae235b
 * @backend: the #GTlsBackend
Packit ae235b
 *
Packit ae235b
 * Gets the #GType of @backend's #GTlsClientConnection implementation.
Packit ae235b
 *
Packit ae235b
 * Returns: the #GType of @backend's #GTlsClientConnection
Packit ae235b
 *   implementation.
Packit ae235b
 *
Packit ae235b
 * Since: 2.28
Packit ae235b
 */
Packit ae235b
GType
Packit ae235b
g_tls_backend_get_client_connection_type (GTlsBackend *backend)
Packit ae235b
{
Packit ae235b
  return G_TLS_BACKEND_GET_INTERFACE (backend)->get_client_connection_type ();
Packit ae235b
}
Packit ae235b
Packit ae235b
/**
Packit ae235b
 * g_tls_backend_get_server_connection_type:
Packit ae235b
 * @backend: the #GTlsBackend
Packit ae235b
 *
Packit ae235b
 * Gets the #GType of @backend's #GTlsServerConnection implementation.
Packit ae235b
 *
Packit ae235b
 * Returns: the #GType of @backend's #GTlsServerConnection
Packit ae235b
 *   implementation.
Packit ae235b
 *
Packit ae235b
 * Since: 2.28
Packit ae235b
 */
Packit ae235b
GType
Packit ae235b
g_tls_backend_get_server_connection_type (GTlsBackend *backend)
Packit ae235b
{
Packit ae235b
  return G_TLS_BACKEND_GET_INTERFACE (backend)->get_server_connection_type ();
Packit ae235b
}
Packit ae235b
Packit ae235b
/**
Packit ae235b
 * g_tls_backend_get_dtls_client_connection_type:
Packit ae235b
 * @backend: the #GTlsBackend
Packit ae235b
 *
Packit ae235b
 * Gets the #GType of @backend’s #GDtlsClientConnection implementation.
Packit ae235b
 *
Packit ae235b
 * Returns: the #GType of @backend’s #GDtlsClientConnection
Packit ae235b
 *   implementation, or %G_TYPE_INVALID if this backend doesn’t support DTLS.
Packit ae235b
 *
Packit ae235b
 * Since: 2.48
Packit ae235b
 */
Packit ae235b
GType
Packit ae235b
g_tls_backend_get_dtls_client_connection_type (GTlsBackend *backend)
Packit ae235b
{
Packit ae235b
  GTlsBackendInterface *iface;
Packit ae235b
Packit ae235b
  g_return_val_if_fail (G_IS_TLS_BACKEND (backend), G_TYPE_INVALID);
Packit ae235b
Packit ae235b
  iface = G_TLS_BACKEND_GET_INTERFACE (backend);
Packit ae235b
  if (iface->get_dtls_client_connection_type == NULL)
Packit ae235b
    return G_TYPE_INVALID;
Packit ae235b
Packit ae235b
  return iface->get_dtls_client_connection_type ();
Packit ae235b
}
Packit ae235b
Packit ae235b
/**
Packit ae235b
 * g_tls_backend_get_dtls_server_connection_type:
Packit ae235b
 * @backend: the #GTlsBackend
Packit ae235b
 *
Packit ae235b
 * Gets the #GType of @backend’s #GDtlsServerConnection implementation.
Packit ae235b
 *
Packit ae235b
 * Returns: the #GType of @backend’s #GDtlsServerConnection
Packit ae235b
 *   implementation, or %G_TYPE_INVALID if this backend doesn’t support DTLS.
Packit ae235b
 *
Packit ae235b
 * Since: 2.48
Packit ae235b
 */
Packit ae235b
GType
Packit ae235b
g_tls_backend_get_dtls_server_connection_type (GTlsBackend *backend)
Packit ae235b
{
Packit ae235b
  GTlsBackendInterface *iface;
Packit ae235b
Packit ae235b
  g_return_val_if_fail (G_IS_TLS_BACKEND (backend), G_TYPE_INVALID);
Packit ae235b
Packit ae235b
  iface = G_TLS_BACKEND_GET_INTERFACE (backend);
Packit ae235b
  if (iface->get_dtls_server_connection_type == NULL)
Packit ae235b
    return G_TYPE_INVALID;
Packit ae235b
Packit ae235b
  return iface->get_dtls_server_connection_type ();
Packit ae235b
}
Packit ae235b
Packit ae235b
/**
Packit ae235b
 * g_tls_backend_get_file_database_type:
Packit ae235b
 * @backend: the #GTlsBackend
Packit ae235b
 *
Packit ae235b
 * Gets the #GType of @backend's #GTlsFileDatabase implementation.
Packit ae235b
 *
Packit ae235b
 * Returns: the #GType of backend's #GTlsFileDatabase implementation.
Packit ae235b
 *
Packit ae235b
 * Since: 2.30
Packit ae235b
 */
Packit ae235b
GType
Packit ae235b
g_tls_backend_get_file_database_type (GTlsBackend *backend)
Packit ae235b
{
Packit ae235b
  g_return_val_if_fail (G_IS_TLS_BACKEND (backend), 0);
Packit ae235b
Packit ae235b
  /* This method was added later, so accept the (remote) possibility it can be NULL */
Packit ae235b
  if (!G_TLS_BACKEND_GET_INTERFACE (backend)->get_file_database_type)
Packit ae235b
    return 0;
Packit ae235b
Packit ae235b
  return G_TLS_BACKEND_GET_INTERFACE (backend)->get_file_database_type ();
Packit ae235b
}