Blame examples/sslecho.pl

Packit b893dc
#!/usr/bin/perl -w
Packit b893dc
# sslecho.pl - Echo server using SSL
Packit b893dc
#
Packit b893dc
# Copyright (c) 1996,1998 Sampo Kellomaki <sampo@iki.fi>, All Rights Reserved.
Packit b893dc
# Date:   27.6.1996, 8.6.1998
Packit b893dc
# 7.12.2001, added more support for client side certificate testing --Sampo
Packit b893dc
# $Id: sslecho.pl,v 1.2 2001/12/08 17:43:14 sampo Exp $
Packit b893dc
#
Packit b893dc
# Usage: ./sslecho.pl *port* *cert.pem* *key.pem*
Packit b893dc
#
Packit b893dc
# This server always binds to localhost as this is all that is needed
Packit b893dc
# for tests.
Packit b893dc
Packit b893dc
die "Usage: ./sslecho.pl *port* *cert.pem* *key.pem*\n" unless $#ARGV == 2;
Packit b893dc
($port, $cert_pem, $key_pem) = @ARGV;
Packit b893dc
$our_ip = "\x7F\0\0\x01";
Packit b893dc
Packit b893dc
$trace = 2;
Packit b893dc
use Socket;
Packit b893dc
use Net::SSLeay qw(sslcat die_now die_if_ssl_error);
Packit b893dc
$Net::SSLeay::trace = 3; # Super verbose debugging
Packit b893dc
Packit b893dc
#
Packit b893dc
# Create the socket and open a connection
Packit b893dc
#
Packit b893dc
Packit b893dc
$our_serv_params = pack ('S n a4 x8', &AF_INET, $port, $our_ip);
Packit b893dc
socket (S, &AF_INET, &SOCK_STREAM, 0)  or die "socket: $!";
Packit b893dc
bind (S, $our_serv_params)             or die "bind:   $! (port=$port)";
Packit b893dc
listen (S, 5)                          or die "listen: $!";
Packit b893dc
Packit b893dc
#
Packit b893dc
# Prepare SSLeay
Packit b893dc
#
Packit b893dc
Packit b893dc
Net::SSLeay::load_error_strings();
Packit b893dc
Net::SSLeay::ERR_load_crypto_strings();
Packit b893dc
Net::SSLeay::SSLeay_add_ssl_algorithms();
Packit b893dc
Net::SSLeay::randomize();
Packit b893dc
Packit b893dc
print "sslecho: Creating SSL context...\n" if $trace>1;
Packit b893dc
$ctx = Net::SSLeay::CTX_new () or die_now("CTX_new ($ctx): $!\n");
Packit b893dc
print "sslecho: Setting cert and RSA key...\n" if $trace>1;
Packit b893dc
Net::SSLeay::CTX_set_cipher_list($ctx,'ALL');
Packit b893dc
Net::SSLeay::set_cert_and_key($ctx, $cert_pem, $key_pem) or die "key";
Packit b893dc
Packit b893dc
while (1) {
Packit b893dc
    
Packit b893dc
    print "sslecho $$: Accepting connections...\n" if $trace>1;
Packit b893dc
    ($addr = accept (NS, S)) or die "accept: $!";
Packit b893dc
    $old_out = select (NS); $| = 1; select ($old_out);  # Piping hot!
Packit b893dc
    
Packit b893dc
    if ($trace) {
Packit b893dc
	($af,$client_port,$client_ip) = unpack('S n a4 x8',$addr);
Packit b893dc
	@inetaddr = unpack('C4',$client_ip);
Packit b893dc
	print "$af connection from " . join ('.', @inetaddr)
Packit b893dc
	    . ":$client_port\n" if $trace;;
Packit b893dc
    }
Packit b893dc
    
Packit b893dc
    #
Packit b893dc
    # Do SSL negotiation stuff
Packit b893dc
    #
Packit b893dc
Packit b893dc
    print "sslecho: Creating SSL session (cxt=`$ctx')...\n" if $trace>1;
Packit b893dc
    $ssl = Net::SSLeay::new($ctx) or die_now("ssl new ($ssl): $!");
Packit b893dc
Packit b893dc
    print "sslecho: Setting fd (ctx $ctx, con $ssl)...\n" if $trace>1;
Packit b893dc
    Net::SSLeay::set_fd($ssl, fileno(NS));
Packit b893dc
Packit b893dc
    print "sslecho: Entering SSL negotiation phase...\n" if $trace>1;
Packit b893dc
    
Packit b893dc
    Net::SSLeay::accept($ssl);
Packit b893dc
    die_if_ssl_error("ssl_echo: ssl accept: ($!)");
Packit b893dc
    
Packit b893dc
    print "sslecho: Cipher `" . Net::SSLeay::get_cipher($ssl)
Packit b893dc
	. "'\n" if $trace;
Packit b893dc
    
Packit b893dc
    #
Packit b893dc
    # Connected. Exchange some data.
Packit b893dc
    #
Packit b893dc
    
Packit b893dc
    $got = Net::SSLeay::ssl_read_all($ssl) or die "$$: ssl read failed";
Packit b893dc
    print "sslecho $$: got " . length($got) . " bytes\n" if $trace==2;
Packit b893dc
    print "sslecho: Got `$got' (" . length ($got) . " chars)\n" if $trace>2;
Packit b893dc
    $got = uc $got;
Packit b893dc
    if ($got eq 'CLIENT-CERT-TEST') {
Packit b893dc
	$got .= Net::SSLeay::dump_peer_certificate($ssl) . "END CERT\n";
Packit b893dc
    }
Packit b893dc
    Net::SSLeay::ssl_write_all($ssl, $got) or die "$$: ssl write failed";
Packit b893dc
    $got = '';  # in case it was huge
Packit b893dc
    
Packit b893dc
    print "sslecho: Tearing down the connection.\n\n" if $trace>1;
Packit b893dc
    
Packit b893dc
    Net::SSLeay::free ($ssl);
Packit b893dc
    close NS;
Packit b893dc
}
Packit b893dc
Net::SSLeay::CTX_free ($ctx);
Packit b893dc
close S;
Packit b893dc
Packit b893dc
__END__