mirror of
https://github.com/XRPLF/rippled.git
synced 2025-11-21 03:26:01 +00:00
497 lines
70 KiB
HTML
497 lines
70 KiB
HTML
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "https://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
|
|
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US">
|
|
<head>
|
|
<meta http-equiv="Content-Type" content="text/xhtml;charset=UTF-8"/>
|
|
<meta http-equiv="X-UA-Compatible" content="IE=11"/>
|
|
<meta name="generator" content="Doxygen 1.9.8"/>
|
|
<meta name="viewport" content="width=device-width, initial-scale=1"/>
|
|
<title>rippled: make_SSLContext.cpp Source File</title>
|
|
<link href="tabs.css" rel="stylesheet" type="text/css"/>
|
|
<script type="text/javascript" src="jquery.js"></script>
|
|
<script type="text/javascript" src="dynsections.js"></script>
|
|
<link href="search/search.css" rel="stylesheet" type="text/css"/>
|
|
<script type="text/javascript" src="search/searchdata.js"></script>
|
|
<script type="text/javascript" src="search/search.js"></script>
|
|
<link href="doxygen.css" rel="stylesheet" type="text/css" />
|
|
</head>
|
|
<body>
|
|
<div id="top"><!-- do not remove this div, it is closed by doxygen! -->
|
|
<div id="titlearea">
|
|
<table cellspacing="0" cellpadding="0">
|
|
<tbody>
|
|
<tr id="projectrow">
|
|
<td id="projectalign">
|
|
<div id="projectname">rippled
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
</div>
|
|
<!-- end header part -->
|
|
<!-- Generated by Doxygen 1.9.8 -->
|
|
<script type="text/javascript">
|
|
/* @license magnet:?xt=urn:btih:d3d9a9a6595521f9666a5e94cc830dab83b65699&dn=expat.txt MIT */
|
|
var searchBox = new SearchBox("searchBox", "search/",'.html');
|
|
/* @license-end */
|
|
</script>
|
|
<script type="text/javascript" src="menudata.js"></script>
|
|
<script type="text/javascript" src="menu.js"></script>
|
|
<script type="text/javascript">
|
|
/* @license magnet:?xt=urn:btih:d3d9a9a6595521f9666a5e94cc830dab83b65699&dn=expat.txt MIT */
|
|
$(function() {
|
|
initMenu('',true,false,'search.php','Search');
|
|
$(document).ready(function() { init_search(); });
|
|
});
|
|
/* @license-end */
|
|
</script>
|
|
<div id="main-nav"></div>
|
|
<script type="text/javascript">
|
|
/* @license magnet:?xt=urn:btih:d3d9a9a6595521f9666a5e94cc830dab83b65699&dn=expat.txt MIT */
|
|
$(document).ready(function() { init_codefold(0); });
|
|
/* @license-end */
|
|
</script>
|
|
<!-- window showing the filter options -->
|
|
<div id="MSearchSelectWindow"
|
|
onmouseover="return searchBox.OnSearchSelectShow()"
|
|
onmouseout="return searchBox.OnSearchSelectHide()"
|
|
onkeydown="return searchBox.OnSearchSelectKey(event)">
|
|
</div>
|
|
|
|
<!-- iframe showing the search results (closed by default) -->
|
|
<div id="MSearchResultsWindow">
|
|
<div id="MSearchResults">
|
|
<div class="SRPage">
|
|
<div id="SRIndex">
|
|
<div id="SRResults"></div>
|
|
<div class="SRStatus" id="Loading">Loading...</div>
|
|
<div class="SRStatus" id="Searching">Searching...</div>
|
|
<div class="SRStatus" id="NoMatches">No Matches</div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<div id="nav-path" class="navpath">
|
|
<ul>
|
|
<li class="navelem"><a class="el" href="dir_90ffdbabf412cfdffe6b2193e0ce938a.html">libxrpl</a></li><li class="navelem"><a class="el" href="dir_c9ad8b908996c4ad90b9a0cfb3c90cd8.html">basics</a></li> </ul>
|
|
</div>
|
|
</div><!-- top -->
|
|
<div class="header">
|
|
<div class="headertitle"><div class="title">make_SSLContext.cpp</div></div>
|
|
</div><!--header-->
|
|
<div class="contents">
|
|
<div class="fragment"><div class="line"><a id="l00001" name="l00001"></a><span class="lineno"> 1</span><span class="comment">//------------------------------------------------------------------------------</span></div>
|
|
<div class="line"><a id="l00002" name="l00002"></a><span class="lineno"> 2</span><span class="comment">/*</span></div>
|
|
<div class="line"><a id="l00003" name="l00003"></a><span class="lineno"> 3</span><span class="comment"> This file is part of rippled: https://github.com/ripple/rippled</span></div>
|
|
<div class="line"><a id="l00004" name="l00004"></a><span class="lineno"> 4</span><span class="comment"> Copyright (c) 2012, 2013 Ripple Labs Inc.</span></div>
|
|
<div class="line"><a id="l00005" name="l00005"></a><span class="lineno"> 5</span><span class="comment"></span> </div>
|
|
<div class="line"><a id="l00006" name="l00006"></a><span class="lineno"> 6</span><span class="comment"> Permission to use, copy, modify, and/or distribute this software for any</span></div>
|
|
<div class="line"><a id="l00007" name="l00007"></a><span class="lineno"> 7</span><span class="comment"> purpose with or without fee is hereby granted, provided that the above</span></div>
|
|
<div class="line"><a id="l00008" name="l00008"></a><span class="lineno"> 8</span><span class="comment"> copyright notice and this permission notice appear in all copies.</span></div>
|
|
<div class="line"><a id="l00009" name="l00009"></a><span class="lineno"> 9</span><span class="comment"></span> </div>
|
|
<div class="line"><a id="l00010" name="l00010"></a><span class="lineno"> 10</span><span class="comment"> THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES</span></div>
|
|
<div class="line"><a id="l00011" name="l00011"></a><span class="lineno"> 11</span><span class="comment"> WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF</span></div>
|
|
<div class="line"><a id="l00012" name="l00012"></a><span class="lineno"> 12</span><span class="comment"> MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR</span></div>
|
|
<div class="line"><a id="l00013" name="l00013"></a><span class="lineno"> 13</span><span class="comment"> ANY SPECIAL , DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES</span></div>
|
|
<div class="line"><a id="l00014" name="l00014"></a><span class="lineno"> 14</span><span class="comment"> WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN</span></div>
|
|
<div class="line"><a id="l00015" name="l00015"></a><span class="lineno"> 15</span><span class="comment"> ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF</span></div>
|
|
<div class="line"><a id="l00016" name="l00016"></a><span class="lineno"> 16</span><span class="comment"> OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.</span></div>
|
|
<div class="line"><a id="l00017" name="l00017"></a><span class="lineno"> 17</span><span class="comment">*/</span></div>
|
|
<div class="line"><a id="l00018" name="l00018"></a><span class="lineno"> 18</span><span class="comment">//==============================================================================</span></div>
|
|
<div class="line"><a id="l00019" name="l00019"></a><span class="lineno"> 19</span> </div>
|
|
<div class="line"><a id="l00020" name="l00020"></a><span class="lineno"> 20</span><span class="preprocessor">#include <xrpl/basics/contract.h></span></div>
|
|
<div class="line"><a id="l00021" name="l00021"></a><span class="lineno"> 21</span><span class="preprocessor">#include <xrpl/basics/make_SSLContext.h></span></div>
|
|
<div class="line"><a id="l00022" name="l00022"></a><span class="lineno"> 22</span> </div>
|
|
<div class="line"><a id="l00023" name="l00023"></a><span class="lineno"> 23</span><span class="preprocessor">#include <boost/asio/ssl/context.hpp></span></div>
|
|
<div class="line"><a id="l00024" name="l00024"></a><span class="lineno"> 24</span><span class="preprocessor">#include <boost/asio/ssl/verify_mode.hpp></span></div>
|
|
<div class="line"><a id="l00025" name="l00025"></a><span class="lineno"> 25</span><span class="preprocessor">#include <boost/system/detail/error_code.hpp></span></div>
|
|
<div class="line"><a id="l00026" name="l00026"></a><span class="lineno"> 26</span><span class="preprocessor">#include <boost/system/detail/generic_category.hpp></span></div>
|
|
<div class="line"><a id="l00027" name="l00027"></a><span class="lineno"> 27</span> </div>
|
|
<div class="line"><a id="l00028" name="l00028"></a><span class="lineno"> 28</span><span class="preprocessor">#include <openssl/asn1.h></span></div>
|
|
<div class="line"><a id="l00029" name="l00029"></a><span class="lineno"> 29</span><span class="preprocessor">#include <openssl/bn.h></span></div>
|
|
<div class="line"><a id="l00030" name="l00030"></a><span class="lineno"> 30</span><span class="preprocessor">#include <openssl/evp.h></span></div>
|
|
<div class="line"><a id="l00031" name="l00031"></a><span class="lineno"> 31</span><span class="preprocessor">#include <openssl/objects.h></span></div>
|
|
<div class="line"><a id="l00032" name="l00032"></a><span class="lineno"> 32</span><span class="preprocessor">#include <openssl/ossl_typ.h></span></div>
|
|
<div class="line"><a id="l00033" name="l00033"></a><span class="lineno"> 33</span><span class="preprocessor">#include <openssl/pem.h></span></div>
|
|
<div class="line"><a id="l00034" name="l00034"></a><span class="lineno"> 34</span><span class="preprocessor">#include <openssl/rsa.h></span></div>
|
|
<div class="line"><a id="l00035" name="l00035"></a><span class="lineno"> 35</span><span class="preprocessor">#include <openssl/ssl.h></span></div>
|
|
<div class="line"><a id="l00036" name="l00036"></a><span class="lineno"> 36</span><span class="preprocessor">#include <openssl/x509.h></span></div>
|
|
<div class="line"><a id="l00037" name="l00037"></a><span class="lineno"> 37</span><span class="preprocessor">#include <openssl/x509v3.h></span></div>
|
|
<div class="line"><a id="l00038" name="l00038"></a><span class="lineno"> 38</span> </div>
|
|
<div class="line"><a id="l00039" name="l00039"></a><span class="lineno"> 39</span><span class="preprocessor">#include <<a class="codeRef" href="http://en.cppreference.com/w/cpp/header/cerrno.html">cerrno</a>></span></div>
|
|
<div class="line"><a id="l00040" name="l00040"></a><span class="lineno"> 40</span><span class="preprocessor">#include <<a class="codeRef" href="http://en.cppreference.com/w/cpp/header/cstdio.html">cstdio</a>></span></div>
|
|
<div class="line"><a id="l00041" name="l00041"></a><span class="lineno"> 41</span><span class="preprocessor">#include <<a class="codeRef" href="http://en.cppreference.com/w/cpp/header/ctime.html">ctime</a>></span></div>
|
|
<div class="line"><a id="l00042" name="l00042"></a><span class="lineno"> 42</span><span class="preprocessor">#include <<a class="codeRef" href="http://en.cppreference.com/w/cpp/header/exception.html">exception</a>></span></div>
|
|
<div class="line"><a id="l00043" name="l00043"></a><span class="lineno"> 43</span><span class="preprocessor">#include <<a class="codeRef" href="http://en.cppreference.com/w/cpp/header/memory.html">memory</a>></span></div>
|
|
<div class="line"><a id="l00044" name="l00044"></a><span class="lineno"> 44</span><span class="preprocessor">#include <<a class="codeRef" href="http://en.cppreference.com/w/cpp/header/string.html">string</a>></span></div>
|
|
<div class="line"><a id="l00045" name="l00045"></a><span class="lineno"> 45</span> </div>
|
|
<div class="line"><a id="l00046" name="l00046"></a><span class="lineno"> 46</span><span class="keyword">namespace </span><a class="code hl_namespace" href="namespaceripple.html">ripple</a> {</div>
|
|
<div class="foldopen" id="foldopen00047" data-start="{" data-end="}">
|
|
<div class="line"><a id="l00047" name="l00047"></a><span class="lineno"><a class="line" href="namespaceripple_1_1openssl.html"> 47</a></span><span class="keyword">namespace </span>openssl {</div>
|
|
<div class="foldopen" id="foldopen00048" data-start="{" data-end="}">
|
|
<div class="line"><a id="l00048" name="l00048"></a><span class="lineno"><a class="line" href="namespaceripple_1_1openssl_1_1detail.html"> 48</a></span><span class="keyword">namespace </span>detail {</div>
|
|
<div class="line"><a id="l00049" name="l00049"></a><span class="lineno"> 49</span> </div>
|
|
<div class="line"><a id="l00066" name="l00066"></a><span class="lineno"><a class="line" href="namespaceripple_1_1openssl_1_1detail.html#ae431166efcafc1b6d7fc5109bfc7e678"> 66</a></span><span class="keywordtype">int</span> <a class="code hl_variable" href="namespaceripple_1_1openssl_1_1detail.html#ae431166efcafc1b6d7fc5109bfc7e678">defaultRSAKeyBits</a> = 2048;</div>
|
|
<div class="line"><a id="l00067" name="l00067"></a><span class="lineno"> 67</span> </div>
|
|
<div class="line"><a id="l00080" name="l00080"></a><span class="lineno"><a class="line" href="namespaceripple_1_1openssl_1_1detail.html#aee6f7af679257601e8cea90d6a306925"> 80</a></span><span class="keyword">static</span> <span class="keyword">constexpr</span> <span class="keywordtype">char</span> <span class="keyword">const</span> <a class="code hl_variable" href="namespaceripple_1_1openssl_1_1detail.html#aee6f7af679257601e8cea90d6a306925">defaultDH</a>[] =</div>
|
|
<div class="line"><a id="l00081" name="l00081"></a><span class="lineno"> 81</span> <span class="stringliteral">"-----BEGIN DH PARAMETERS-----\n"</span></div>
|
|
<div class="line"><a id="l00082" name="l00082"></a><span class="lineno"> 82</span> <span class="stringliteral">"MIIBCAKCAQEApKSWfR7LKy0VoZ/SDCObCvJ5HKX2J93RJ+QN8kJwHh+uuA8G+t8Q\n"</span></div>
|
|
<div class="line"><a id="l00083" name="l00083"></a><span class="lineno"> 83</span> <span class="stringliteral">"MDRjL5HanlV/sKN9HXqBc7eqHmmbqYwIXKUt9MUZTLNheguddxVlc2IjdP5i9Ps8\n"</span></div>
|
|
<div class="line"><a id="l00084" name="l00084"></a><span class="lineno"> 84</span> <span class="stringliteral">"l7su8tnP0l1JvC6Rfv3epRsEAw/ZW/lC2IwkQPpOmvnENQhQ6TgrUzcGkv4Bn0X6\n"</span></div>
|
|
<div class="line"><a id="l00085" name="l00085"></a><span class="lineno"> 85</span> <span class="stringliteral">"pxrDSBpZ+45oehGCUAtcbY8b02vu8zPFoxqo6V/+MIszGzldlik5bVqrJpVF6E8C\n"</span></div>
|
|
<div class="line"><a id="l00086" name="l00086"></a><span class="lineno"> 86</span> <span class="stringliteral">"tRqHjj6KuDbPbjc+pRGvwx/BSO3SULxmYu9J1NOk090MU1CMt6IJY7TpEc9Xrac9\n"</span></div>
|
|
<div class="line"><a id="l00087" name="l00087"></a><span class="lineno"> 87</span> <span class="stringliteral">"9yqY3xXZID240RRcaJ25+U4lszFPqP+CEwIBAg==\n"</span></div>
|
|
<div class="line"><a id="l00088" name="l00088"></a><span class="lineno"> 88</span> <span class="stringliteral">"-----END DH PARAMETERS-----"</span>;</div>
|
|
<div class="line"><a id="l00089" name="l00089"></a><span class="lineno"> 89</span> </div>
|
|
<div class="line"><a id="l00104" name="l00104"></a><span class="lineno"><a class="line" href="namespaceripple_1_1openssl_1_1detail.html#abc918438dc5c8a648a41bd9ee286f059"> 104</a></span><a class="code hl_classRef" href="http://en.cppreference.com/w/cpp/string/basic_string.html">std::string</a> <span class="keyword">const</span> <a class="code hl_variable" href="namespaceripple_1_1openssl_1_1detail.html#abc918438dc5c8a648a41bd9ee286f059">defaultCipherList</a> = <span class="stringliteral">"TLSv1.2:!CBC:!DSS:!PSK:!eNULL:!aNULL"</span>;</div>
|
|
<div class="line"><a id="l00105" name="l00105"></a><span class="lineno"> 105</span> </div>
|
|
<div class="line"><a id="l00106" name="l00106"></a><span class="lineno"> 106</span><span class="keyword">static</span> <span class="keywordtype">void</span></div>
|
|
<div class="foldopen" id="foldopen00107" data-start="{" data-end="}">
|
|
<div class="line"><a id="l00107" name="l00107"></a><span class="lineno"><a class="line" href="namespaceripple_1_1openssl_1_1detail.html#a5424207e5a700ac59ea8b9ab1e2b9397"> 107</a></span><a class="code hl_function" href="namespaceripple_1_1openssl_1_1detail.html#a5424207e5a700ac59ea8b9ab1e2b9397">initAnonymous</a>(boost::asio::ssl::context& context)</div>
|
|
<div class="line"><a id="l00108" name="l00108"></a><span class="lineno"> 108</span>{</div>
|
|
<div class="line"><a id="l00109" name="l00109"></a><span class="lineno"> 109</span> <span class="keyword">using namespace </span>openssl;</div>
|
|
<div class="line"><a id="l00110" name="l00110"></a><span class="lineno"> 110</span> </div>
|
|
<div class="line"><a id="l00111" name="l00111"></a><span class="lineno"> 111</span> <span class="keyword">static</span> <span class="keyword">auto</span> defaultRSA = []() {</div>
|
|
<div class="line"><a id="l00112" name="l00112"></a><span class="lineno"> 112</span> BIGNUM* bn = BN_new();</div>
|
|
<div class="line"><a id="l00113" name="l00113"></a><span class="lineno"> 113</span> BN_set_word(bn, RSA_F4);</div>
|
|
<div class="line"><a id="l00114" name="l00114"></a><span class="lineno"> 114</span> </div>
|
|
<div class="line"><a id="l00115" name="l00115"></a><span class="lineno"> 115</span> <span class="keyword">auto</span> rsa = RSA_new();</div>
|
|
<div class="line"><a id="l00116" name="l00116"></a><span class="lineno"> 116</span> </div>
|
|
<div class="line"><a id="l00117" name="l00117"></a><span class="lineno"> 117</span> <span class="keywordflow">if</span> (!rsa)</div>
|
|
<div class="line"><a id="l00118" name="l00118"></a><span class="lineno"> 118</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(<span class="stringliteral">"RSA_new failed"</span>);</div>
|
|
<div class="line"><a id="l00119" name="l00119"></a><span class="lineno"> 119</span> </div>
|
|
<div class="line"><a id="l00120" name="l00120"></a><span class="lineno"> 120</span> <span class="keywordflow">if</span> (RSA_generate_key_ex(rsa, <a class="code hl_variable" href="namespaceripple_1_1openssl_1_1detail.html#ae431166efcafc1b6d7fc5109bfc7e678">defaultRSAKeyBits</a>, bn, <span class="keyword">nullptr</span>) != 1)</div>
|
|
<div class="line"><a id="l00121" name="l00121"></a><span class="lineno"> 121</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(<span class="stringliteral">"RSA_generate_key_ex failure"</span>);</div>
|
|
<div class="line"><a id="l00122" name="l00122"></a><span class="lineno"> 122</span> </div>
|
|
<div class="line"><a id="l00123" name="l00123"></a><span class="lineno"> 123</span> BN_clear_free(bn);</div>
|
|
<div class="line"><a id="l00124" name="l00124"></a><span class="lineno"> 124</span> </div>
|
|
<div class="line"><a id="l00125" name="l00125"></a><span class="lineno"> 125</span> <span class="keywordflow">return</span> rsa;</div>
|
|
<div class="line"><a id="l00126" name="l00126"></a><span class="lineno"> 126</span> }();</div>
|
|
<div class="line"><a id="l00127" name="l00127"></a><span class="lineno"> 127</span> </div>
|
|
<div class="line"><a id="l00128" name="l00128"></a><span class="lineno"> 128</span> <span class="keyword">static</span> <span class="keyword">auto</span> defaultEphemeralPrivateKey = []() {</div>
|
|
<div class="line"><a id="l00129" name="l00129"></a><span class="lineno"> 129</span> <span class="keyword">auto</span> pkey = EVP_PKEY_new();</div>
|
|
<div class="line"><a id="l00130" name="l00130"></a><span class="lineno"> 130</span> </div>
|
|
<div class="line"><a id="l00131" name="l00131"></a><span class="lineno"> 131</span> <span class="keywordflow">if</span> (!pkey)</div>
|
|
<div class="line"><a id="l00132" name="l00132"></a><span class="lineno"> 132</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(<span class="stringliteral">"EVP_PKEY_new failed"</span>);</div>
|
|
<div class="line"><a id="l00133" name="l00133"></a><span class="lineno"> 133</span> </div>
|
|
<div class="line"><a id="l00134" name="l00134"></a><span class="lineno"> 134</span> <span class="comment">// We need to up the reference count of here, since we are retaining a</span></div>
|
|
<div class="line"><a id="l00135" name="l00135"></a><span class="lineno"> 135</span> <span class="comment">// copy of the key for (potential) reuse.</span></div>
|
|
<div class="line"><a id="l00136" name="l00136"></a><span class="lineno"> 136</span> <span class="keywordflow">if</span> (RSA_up_ref(defaultRSA) != 1)</div>
|
|
<div class="line"><a id="l00137" name="l00137"></a><span class="lineno"> 137</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(</div>
|
|
<div class="line"><a id="l00138" name="l00138"></a><span class="lineno"> 138</span> <span class="stringliteral">"EVP_PKEY_assign_RSA: incrementing reference count failed"</span>);</div>
|
|
<div class="line"><a id="l00139" name="l00139"></a><span class="lineno"> 139</span> </div>
|
|
<div class="line"><a id="l00140" name="l00140"></a><span class="lineno"> 140</span> <span class="keywordflow">if</span> (!EVP_PKEY_assign_RSA(pkey, defaultRSA))</div>
|
|
<div class="line"><a id="l00141" name="l00141"></a><span class="lineno"> 141</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(<span class="stringliteral">"EVP_PKEY_assign_RSA failed"</span>);</div>
|
|
<div class="line"><a id="l00142" name="l00142"></a><span class="lineno"> 142</span> </div>
|
|
<div class="line"><a id="l00143" name="l00143"></a><span class="lineno"> 143</span> <span class="keywordflow">return</span> pkey;</div>
|
|
<div class="line"><a id="l00144" name="l00144"></a><span class="lineno"> 144</span> }();</div>
|
|
<div class="line"><a id="l00145" name="l00145"></a><span class="lineno"> 145</span> </div>
|
|
<div class="line"><a id="l00146" name="l00146"></a><span class="lineno"> 146</span> <span class="keyword">static</span> <span class="keyword">auto</span> defaultCert = []() {</div>
|
|
<div class="line"><a id="l00147" name="l00147"></a><span class="lineno"> 147</span> <span class="keyword">auto</span> x509 = X509_new();</div>
|
|
<div class="line"><a id="l00148" name="l00148"></a><span class="lineno"> 148</span> </div>
|
|
<div class="line"><a id="l00149" name="l00149"></a><span class="lineno"> 149</span> <span class="keywordflow">if</span> (x509 == <span class="keyword">nullptr</span>)</div>
|
|
<div class="line"><a id="l00150" name="l00150"></a><span class="lineno"> 150</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(<span class="stringliteral">"X509_new failed"</span>);</div>
|
|
<div class="line"><a id="l00151" name="l00151"></a><span class="lineno"> 151</span> </div>
|
|
<div class="line"><a id="l00152" name="l00152"></a><span class="lineno"> 152</span> <span class="comment">// According to the standards (X.509 et al), the value should be one</span></div>
|
|
<div class="line"><a id="l00153" name="l00153"></a><span class="lineno"> 153</span> <span class="comment">// less than the actualy certificate version we want. Since we want</span></div>
|
|
<div class="line"><a id="l00154" name="l00154"></a><span class="lineno"> 154</span> <span class="comment">// version 3, we must use a 2.</span></div>
|
|
<div class="line"><a id="l00155" name="l00155"></a><span class="lineno"> 155</span> X509_set_version(x509, 2);</div>
|
|
<div class="line"><a id="l00156" name="l00156"></a><span class="lineno"> 156</span> </div>
|
|
<div class="line"><a id="l00157" name="l00157"></a><span class="lineno"> 157</span> <span class="comment">// To avoid leaking information about the precise time that the</span></div>
|
|
<div class="line"><a id="l00158" name="l00158"></a><span class="lineno"> 158</span> <span class="comment">// server started up, we adjust the validity period:</span></div>
|
|
<div class="line"><a id="l00159" name="l00159"></a><span class="lineno"> 159</span> <span class="keywordtype">char</span> buf[16] = {0};</div>
|
|
<div class="line"><a id="l00160" name="l00160"></a><span class="lineno"> 160</span> </div>
|
|
<div class="line"><a id="l00161" name="l00161"></a><span class="lineno"> 161</span> <span class="keyword">auto</span> <span class="keyword">const</span> ts = <a class="code hl_functionRef" href="http://en.cppreference.com/w/cpp/chrono/c/time.html">std::time</a>(<span class="keyword">nullptr</span>) - (25 * 60 * 60);</div>
|
|
<div class="line"><a id="l00162" name="l00162"></a><span class="lineno"> 162</span> </div>
|
|
<div class="line"><a id="l00163" name="l00163"></a><span class="lineno"> 163</span> <span class="keywordtype">int</span> ret = <a class="code hl_functionRef" href="http://en.cppreference.com/w/cpp/chrono/c/strftime.html">std::strftime</a>(</div>
|
|
<div class="line"><a id="l00164" name="l00164"></a><span class="lineno"> 164</span> buf, <span class="keyword">sizeof</span>(buf) - 1, <span class="stringliteral">"%y%m%d000000Z"</span>, <a class="code hl_functionRef" href="http://en.cppreference.com/w/cpp/chrono/c/gmtime.html">std::gmtime</a>(&ts));</div>
|
|
<div class="line"><a id="l00165" name="l00165"></a><span class="lineno"> 165</span> </div>
|
|
<div class="line"><a id="l00166" name="l00166"></a><span class="lineno"> 166</span> buf[ret] = 0;</div>
|
|
<div class="line"><a id="l00167" name="l00167"></a><span class="lineno"> 167</span> </div>
|
|
<div class="line"><a id="l00168" name="l00168"></a><span class="lineno"> 168</span> <span class="keywordflow">if</span> (ASN1_TIME_set_string_X509(X509_get_notBefore(x509), buf) != 1)</div>
|
|
<div class="line"><a id="l00169" name="l00169"></a><span class="lineno"> 169</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(<span class="stringliteral">"Unable to set certificate validity date"</span>);</div>
|
|
<div class="line"><a id="l00170" name="l00170"></a><span class="lineno"> 170</span> </div>
|
|
<div class="line"><a id="l00171" name="l00171"></a><span class="lineno"> 171</span> <span class="comment">// And make it valid for two years</span></div>
|
|
<div class="line"><a id="l00172" name="l00172"></a><span class="lineno"> 172</span> X509_gmtime_adj(X509_get_notAfter(x509), 2 * 365 * 24 * 60 * 60);</div>
|
|
<div class="line"><a id="l00173" name="l00173"></a><span class="lineno"> 173</span> </div>
|
|
<div class="line"><a id="l00174" name="l00174"></a><span class="lineno"> 174</span> <span class="comment">// Set a serial number</span></div>
|
|
<div class="line"><a id="l00175" name="l00175"></a><span class="lineno"> 175</span> <span class="keywordflow">if</span> (<span class="keyword">auto</span> b = BN_new(); b != <span class="keyword">nullptr</span>)</div>
|
|
<div class="line"><a id="l00176" name="l00176"></a><span class="lineno"> 176</span> {</div>
|
|
<div class="line"><a id="l00177" name="l00177"></a><span class="lineno"> 177</span> <span class="keywordflow">if</span> (BN_rand(b, 128, BN_RAND_TOP_ANY, BN_RAND_BOTTOM_ANY))</div>
|
|
<div class="line"><a id="l00178" name="l00178"></a><span class="lineno"> 178</span> {</div>
|
|
<div class="line"><a id="l00179" name="l00179"></a><span class="lineno"> 179</span> <span class="keywordflow">if</span> (<span class="keyword">auto</span> a = ASN1_INTEGER_new(); a != <span class="keyword">nullptr</span>)</div>
|
|
<div class="line"><a id="l00180" name="l00180"></a><span class="lineno"> 180</span> {</div>
|
|
<div class="line"><a id="l00181" name="l00181"></a><span class="lineno"> 181</span> <span class="keywordflow">if</span> (BN_to_ASN1_INTEGER(b, a))</div>
|
|
<div class="line"><a id="l00182" name="l00182"></a><span class="lineno"> 182</span> X509_set_serialNumber(x509, a);</div>
|
|
<div class="line"><a id="l00183" name="l00183"></a><span class="lineno"> 183</span> </div>
|
|
<div class="line"><a id="l00184" name="l00184"></a><span class="lineno"> 184</span> ASN1_INTEGER_free(a);</div>
|
|
<div class="line"><a id="l00185" name="l00185"></a><span class="lineno"> 185</span> }</div>
|
|
<div class="line"><a id="l00186" name="l00186"></a><span class="lineno"> 186</span> }</div>
|
|
<div class="line"><a id="l00187" name="l00187"></a><span class="lineno"> 187</span> </div>
|
|
<div class="line"><a id="l00188" name="l00188"></a><span class="lineno"> 188</span> BN_clear_free(b);</div>
|
|
<div class="line"><a id="l00189" name="l00189"></a><span class="lineno"> 189</span> }</div>
|
|
<div class="line"><a id="l00190" name="l00190"></a><span class="lineno"> 190</span> </div>
|
|
<div class="line"><a id="l00191" name="l00191"></a><span class="lineno"> 191</span> <span class="comment">// Some certificate details</span></div>
|
|
<div class="line"><a id="l00192" name="l00192"></a><span class="lineno"> 192</span> {</div>
|
|
<div class="line"><a id="l00193" name="l00193"></a><span class="lineno"> 193</span> X509V3_CTX ctx;</div>
|
|
<div class="line"><a id="l00194" name="l00194"></a><span class="lineno"> 194</span> </div>
|
|
<div class="line"><a id="l00195" name="l00195"></a><span class="lineno"> 195</span> X509V3_set_ctx_nodb(&ctx);</div>
|
|
<div class="line"><a id="l00196" name="l00196"></a><span class="lineno"> 196</span> X509V3_set_ctx(&ctx, x509, x509, <span class="keyword">nullptr</span>, <span class="keyword">nullptr</span>, 0);</div>
|
|
<div class="line"><a id="l00197" name="l00197"></a><span class="lineno"> 197</span> </div>
|
|
<div class="line"><a id="l00198" name="l00198"></a><span class="lineno"> 198</span> <span class="keywordflow">if</span> (<span class="keyword">auto</span> ext = X509V3_EXT_conf_nid(</div>
|
|
<div class="line"><a id="l00199" name="l00199"></a><span class="lineno"> 199</span> <span class="keyword">nullptr</span>, &ctx, NID_basic_constraints, <span class="stringliteral">"critical,CA:FALSE"</span>))</div>
|
|
<div class="line"><a id="l00200" name="l00200"></a><span class="lineno"> 200</span> {</div>
|
|
<div class="line"><a id="l00201" name="l00201"></a><span class="lineno"> 201</span> X509_add_ext(x509, ext, -1);</div>
|
|
<div class="line"><a id="l00202" name="l00202"></a><span class="lineno"> 202</span> X509_EXTENSION_free(ext);</div>
|
|
<div class="line"><a id="l00203" name="l00203"></a><span class="lineno"> 203</span> }</div>
|
|
<div class="line"><a id="l00204" name="l00204"></a><span class="lineno"> 204</span> </div>
|
|
<div class="line"><a id="l00205" name="l00205"></a><span class="lineno"> 205</span> <span class="keywordflow">if</span> (<span class="keyword">auto</span> ext = X509V3_EXT_conf_nid(</div>
|
|
<div class="line"><a id="l00206" name="l00206"></a><span class="lineno"> 206</span> <span class="keyword">nullptr</span>,</div>
|
|
<div class="line"><a id="l00207" name="l00207"></a><span class="lineno"> 207</span> &ctx,</div>
|
|
<div class="line"><a id="l00208" name="l00208"></a><span class="lineno"> 208</span> NID_ext_key_usage,</div>
|
|
<div class="line"><a id="l00209" name="l00209"></a><span class="lineno"> 209</span> <span class="stringliteral">"critical,serverAuth,clientAuth"</span>))</div>
|
|
<div class="line"><a id="l00210" name="l00210"></a><span class="lineno"> 210</span> {</div>
|
|
<div class="line"><a id="l00211" name="l00211"></a><span class="lineno"> 211</span> X509_add_ext(x509, ext, -1);</div>
|
|
<div class="line"><a id="l00212" name="l00212"></a><span class="lineno"> 212</span> X509_EXTENSION_free(ext);</div>
|
|
<div class="line"><a id="l00213" name="l00213"></a><span class="lineno"> 213</span> }</div>
|
|
<div class="line"><a id="l00214" name="l00214"></a><span class="lineno"> 214</span> </div>
|
|
<div class="line"><a id="l00215" name="l00215"></a><span class="lineno"> 215</span> <span class="keywordflow">if</span> (<span class="keyword">auto</span> ext = X509V3_EXT_conf_nid(</div>
|
|
<div class="line"><a id="l00216" name="l00216"></a><span class="lineno"> 216</span> <span class="keyword">nullptr</span>, &ctx, NID_key_usage, <span class="stringliteral">"critical,digitalSignature"</span>))</div>
|
|
<div class="line"><a id="l00217" name="l00217"></a><span class="lineno"> 217</span> {</div>
|
|
<div class="line"><a id="l00218" name="l00218"></a><span class="lineno"> 218</span> X509_add_ext(x509, ext, -1);</div>
|
|
<div class="line"><a id="l00219" name="l00219"></a><span class="lineno"> 219</span> X509_EXTENSION_free(ext);</div>
|
|
<div class="line"><a id="l00220" name="l00220"></a><span class="lineno"> 220</span> }</div>
|
|
<div class="line"><a id="l00221" name="l00221"></a><span class="lineno"> 221</span> </div>
|
|
<div class="line"><a id="l00222" name="l00222"></a><span class="lineno"> 222</span> <span class="keywordflow">if</span> (<span class="keyword">auto</span> ext = X509V3_EXT_conf_nid(</div>
|
|
<div class="line"><a id="l00223" name="l00223"></a><span class="lineno"> 223</span> <span class="keyword">nullptr</span>, &ctx, NID_subject_key_identifier, <span class="stringliteral">"hash"</span>))</div>
|
|
<div class="line"><a id="l00224" name="l00224"></a><span class="lineno"> 224</span> {</div>
|
|
<div class="line"><a id="l00225" name="l00225"></a><span class="lineno"> 225</span> X509_add_ext(x509, ext, -1);</div>
|
|
<div class="line"><a id="l00226" name="l00226"></a><span class="lineno"> 226</span> X509_EXTENSION_free(ext);</div>
|
|
<div class="line"><a id="l00227" name="l00227"></a><span class="lineno"> 227</span> }</div>
|
|
<div class="line"><a id="l00228" name="l00228"></a><span class="lineno"> 228</span> }</div>
|
|
<div class="line"><a id="l00229" name="l00229"></a><span class="lineno"> 229</span> </div>
|
|
<div class="line"><a id="l00230" name="l00230"></a><span class="lineno"> 230</span> <span class="comment">// And a private key</span></div>
|
|
<div class="line"><a id="l00231" name="l00231"></a><span class="lineno"> 231</span> X509_set_pubkey(x509, defaultEphemeralPrivateKey);</div>
|
|
<div class="line"><a id="l00232" name="l00232"></a><span class="lineno"> 232</span> </div>
|
|
<div class="line"><a id="l00233" name="l00233"></a><span class="lineno"> 233</span> <span class="keywordflow">if</span> (!X509_sign(x509, defaultEphemeralPrivateKey, EVP_sha256()))</div>
|
|
<div class="line"><a id="l00234" name="l00234"></a><span class="lineno"> 234</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(<span class="stringliteral">"X509_sign failed"</span>);</div>
|
|
<div class="line"><a id="l00235" name="l00235"></a><span class="lineno"> 235</span> </div>
|
|
<div class="line"><a id="l00236" name="l00236"></a><span class="lineno"> 236</span> <span class="keywordflow">return</span> x509;</div>
|
|
<div class="line"><a id="l00237" name="l00237"></a><span class="lineno"> 237</span> }();</div>
|
|
<div class="line"><a id="l00238" name="l00238"></a><span class="lineno"> 238</span> </div>
|
|
<div class="line"><a id="l00239" name="l00239"></a><span class="lineno"> 239</span> SSL_CTX* <span class="keyword">const</span> ctx = context.native_handle();</div>
|
|
<div class="line"><a id="l00240" name="l00240"></a><span class="lineno"> 240</span> </div>
|
|
<div class="line"><a id="l00241" name="l00241"></a><span class="lineno"> 241</span> <span class="keywordflow">if</span> (SSL_CTX_use_certificate(ctx, defaultCert) <= 0)</div>
|
|
<div class="line"><a id="l00242" name="l00242"></a><span class="lineno"> 242</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(<span class="stringliteral">"SSL_CTX_use_certificate failed"</span>);</div>
|
|
<div class="line"><a id="l00243" name="l00243"></a><span class="lineno"> 243</span> </div>
|
|
<div class="line"><a id="l00244" name="l00244"></a><span class="lineno"> 244</span> <span class="keywordflow">if</span> (SSL_CTX_use_PrivateKey(ctx, defaultEphemeralPrivateKey) <= 0)</div>
|
|
<div class="line"><a id="l00245" name="l00245"></a><span class="lineno"> 245</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(<span class="stringliteral">"SSL_CTX_use_PrivateKey failed"</span>);</div>
|
|
<div class="line"><a id="l00246" name="l00246"></a><span class="lineno"> 246</span>}</div>
|
|
</div>
|
|
<div class="line"><a id="l00247" name="l00247"></a><span class="lineno"> 247</span> </div>
|
|
<div class="line"><a id="l00248" name="l00248"></a><span class="lineno"> 248</span><span class="keyword">static</span> <span class="keywordtype">void</span></div>
|
|
<div class="foldopen" id="foldopen00249" data-start="{" data-end="}">
|
|
<div class="line"><a id="l00249" name="l00249"></a><span class="lineno"><a class="line" href="namespaceripple_1_1openssl_1_1detail.html#a70f3d81f87a75113774c421267a670b7"> 249</a></span><a class="code hl_function" href="namespaceripple_1_1openssl_1_1detail.html#a70f3d81f87a75113774c421267a670b7">initAuthenticated</a>(</div>
|
|
<div class="line"><a id="l00250" name="l00250"></a><span class="lineno"> 250</span> boost::asio::ssl::context& context,</div>
|
|
<div class="line"><a id="l00251" name="l00251"></a><span class="lineno"> 251</span> <a class="code hl_classRef" href="http://en.cppreference.com/w/cpp/string/basic_string.html">std::string</a> <span class="keyword">const</span>& key_file,</div>
|
|
<div class="line"><a id="l00252" name="l00252"></a><span class="lineno"> 252</span> <a class="code hl_classRef" href="http://en.cppreference.com/w/cpp/string/basic_string.html">std::string</a> <span class="keyword">const</span>& cert_file,</div>
|
|
<div class="line"><a id="l00253" name="l00253"></a><span class="lineno"> 253</span> <a class="code hl_classRef" href="http://en.cppreference.com/w/cpp/string/basic_string.html">std::string</a> <span class="keyword">const</span>& chain_file)</div>
|
|
<div class="line"><a id="l00254" name="l00254"></a><span class="lineno"> 254</span>{</div>
|
|
<div class="line"><a id="l00255" name="l00255"></a><span class="lineno"> 255</span> <span class="keyword">auto</span> fmt_error = [](boost::system::error_code ec) -> <a class="code hl_classRef" href="http://en.cppreference.com/w/cpp/string/basic_string.html">std::string</a> {</div>
|
|
<div class="line"><a id="l00256" name="l00256"></a><span class="lineno"> 256</span> <span class="keywordflow">return</span> <span class="stringliteral">" ["</span> + <a class="code hl_functionRef" href="http://en.cppreference.com/w/cpp/string/basic_string/to_string.html">std::to_string</a>(ec.value()) + <span class="stringliteral">": "</span> + ec.message() + <span class="stringliteral">"]"</span>;</div>
|
|
<div class="line"><a id="l00257" name="l00257"></a><span class="lineno"> 257</span> };</div>
|
|
<div class="line"><a id="l00258" name="l00258"></a><span class="lineno"> 258</span> </div>
|
|
<div class="line"><a id="l00259" name="l00259"></a><span class="lineno"> 259</span> SSL_CTX* <span class="keyword">const</span> ssl = context.native_handle();</div>
|
|
<div class="line"><a id="l00260" name="l00260"></a><span class="lineno"> 260</span> </div>
|
|
<div class="line"><a id="l00261" name="l00261"></a><span class="lineno"> 261</span> <span class="keywordtype">bool</span> cert_set = <span class="keyword">false</span>;</div>
|
|
<div class="line"><a id="l00262" name="l00262"></a><span class="lineno"> 262</span> </div>
|
|
<div class="line"><a id="l00263" name="l00263"></a><span class="lineno"> 263</span> <span class="keywordflow">if</span> (!cert_file.<a class="code hl_functionRef" href="http://en.cppreference.com/w/cpp/string/basic_string/empty.html">empty</a>())</div>
|
|
<div class="line"><a id="l00264" name="l00264"></a><span class="lineno"> 264</span> {</div>
|
|
<div class="line"><a id="l00265" name="l00265"></a><span class="lineno"> 265</span> boost::system::error_code ec;</div>
|
|
<div class="line"><a id="l00266" name="l00266"></a><span class="lineno"> 266</span> </div>
|
|
<div class="line"><a id="l00267" name="l00267"></a><span class="lineno"> 267</span> context.use_certificate_file(</div>
|
|
<div class="line"><a id="l00268" name="l00268"></a><span class="lineno"> 268</span> cert_file, boost::asio::ssl::context::pem, ec);</div>
|
|
<div class="line"><a id="l00269" name="l00269"></a><span class="lineno"> 269</span> </div>
|
|
<div class="line"><a id="l00270" name="l00270"></a><span class="lineno"> 270</span> <span class="keywordflow">if</span> (ec)</div>
|
|
<div class="line"><a id="l00271" name="l00271"></a><span class="lineno"> 271</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(<span class="stringliteral">"Problem with SSL certificate file"</span> + fmt_error(ec));</div>
|
|
<div class="line"><a id="l00272" name="l00272"></a><span class="lineno"> 272</span> </div>
|
|
<div class="line"><a id="l00273" name="l00273"></a><span class="lineno"> 273</span> cert_set = <span class="keyword">true</span>;</div>
|
|
<div class="line"><a id="l00274" name="l00274"></a><span class="lineno"> 274</span> }</div>
|
|
<div class="line"><a id="l00275" name="l00275"></a><span class="lineno"> 275</span> </div>
|
|
<div class="line"><a id="l00276" name="l00276"></a><span class="lineno"> 276</span> <span class="keywordflow">if</span> (!chain_file.<a class="code hl_functionRef" href="http://en.cppreference.com/w/cpp/string/basic_string/empty.html">empty</a>())</div>
|
|
<div class="line"><a id="l00277" name="l00277"></a><span class="lineno"> 277</span> {</div>
|
|
<div class="line"><a id="l00278" name="l00278"></a><span class="lineno"> 278</span> <span class="comment">// VFALCO Replace fopen() with RAII</span></div>
|
|
<div class="line"><a id="l00279" name="l00279"></a><span class="lineno"> 279</span> FILE* f = fopen(chain_file.<a class="code hl_functionRef" href="http://en.cppreference.com/w/cpp/string/basic_string/c_str.html">c_str</a>(), <span class="stringliteral">"r"</span>);</div>
|
|
<div class="line"><a id="l00280" name="l00280"></a><span class="lineno"> 280</span> </div>
|
|
<div class="line"><a id="l00281" name="l00281"></a><span class="lineno"> 281</span> <span class="keywordflow">if</span> (!f)</div>
|
|
<div class="line"><a id="l00282" name="l00282"></a><span class="lineno"> 282</span> {</div>
|
|
<div class="line"><a id="l00283" name="l00283"></a><span class="lineno"> 283</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(</div>
|
|
<div class="line"><a id="l00284" name="l00284"></a><span class="lineno"> 284</span> <span class="stringliteral">"Problem opening SSL chain file"</span> +</div>
|
|
<div class="line"><a id="l00285" name="l00285"></a><span class="lineno"> 285</span> fmt_error(boost::system::error_code(</div>
|
|
<div class="line"><a id="l00286" name="l00286"></a><span class="lineno"> 286</span> errno, boost::system::generic_category())));</div>
|
|
<div class="line"><a id="l00287" name="l00287"></a><span class="lineno"> 287</span> }</div>
|
|
<div class="line"><a id="l00288" name="l00288"></a><span class="lineno"> 288</span> </div>
|
|
<div class="line"><a id="l00289" name="l00289"></a><span class="lineno"> 289</span> <span class="keywordflow">try</span></div>
|
|
<div class="line"><a id="l00290" name="l00290"></a><span class="lineno"> 290</span> {</div>
|
|
<div class="line"><a id="l00291" name="l00291"></a><span class="lineno"> 291</span> <span class="keywordflow">for</span> (;;)</div>
|
|
<div class="line"><a id="l00292" name="l00292"></a><span class="lineno"> 292</span> {</div>
|
|
<div class="line"><a id="l00293" name="l00293"></a><span class="lineno"> 293</span> X509* <span class="keyword">const</span> x = PEM_read_X509(f, <span class="keyword">nullptr</span>, <span class="keyword">nullptr</span>, <span class="keyword">nullptr</span>);</div>
|
|
<div class="line"><a id="l00294" name="l00294"></a><span class="lineno"> 294</span> </div>
|
|
<div class="line"><a id="l00295" name="l00295"></a><span class="lineno"> 295</span> <span class="keywordflow">if</span> (x == <span class="keyword">nullptr</span>)</div>
|
|
<div class="line"><a id="l00296" name="l00296"></a><span class="lineno"> 296</span> <span class="keywordflow">break</span>;</div>
|
|
<div class="line"><a id="l00297" name="l00297"></a><span class="lineno"> 297</span> </div>
|
|
<div class="line"><a id="l00298" name="l00298"></a><span class="lineno"> 298</span> <span class="keywordflow">if</span> (!cert_set)</div>
|
|
<div class="line"><a id="l00299" name="l00299"></a><span class="lineno"> 299</span> {</div>
|
|
<div class="line"><a id="l00300" name="l00300"></a><span class="lineno"> 300</span> <span class="keywordflow">if</span> (SSL_CTX_use_certificate(ssl, x) != 1)</div>
|
|
<div class="line"><a id="l00301" name="l00301"></a><span class="lineno"> 301</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(</div>
|
|
<div class="line"><a id="l00302" name="l00302"></a><span class="lineno"> 302</span> <span class="stringliteral">"Problem retrieving SSL certificate from chain "</span></div>
|
|
<div class="line"><a id="l00303" name="l00303"></a><span class="lineno"> 303</span> <span class="stringliteral">"file."</span>);</div>
|
|
<div class="line"><a id="l00304" name="l00304"></a><span class="lineno"> 304</span> </div>
|
|
<div class="line"><a id="l00305" name="l00305"></a><span class="lineno"> 305</span> cert_set = <span class="keyword">true</span>;</div>
|
|
<div class="line"><a id="l00306" name="l00306"></a><span class="lineno"> 306</span> }</div>
|
|
<div class="line"><a id="l00307" name="l00307"></a><span class="lineno"> 307</span> <span class="keywordflow">else</span> <span class="keywordflow">if</span> (SSL_CTX_add_extra_chain_cert(ssl, x) != 1)</div>
|
|
<div class="line"><a id="l00308" name="l00308"></a><span class="lineno"> 308</span> {</div>
|
|
<div class="line"><a id="l00309" name="l00309"></a><span class="lineno"> 309</span> X509_free(x);</div>
|
|
<div class="line"><a id="l00310" name="l00310"></a><span class="lineno"> 310</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(<span class="stringliteral">"Problem adding SSL chain certificate."</span>);</div>
|
|
<div class="line"><a id="l00311" name="l00311"></a><span class="lineno"> 311</span> }</div>
|
|
<div class="line"><a id="l00312" name="l00312"></a><span class="lineno"> 312</span> }</div>
|
|
<div class="line"><a id="l00313" name="l00313"></a><span class="lineno"> 313</span> </div>
|
|
<div class="line"><a id="l00314" name="l00314"></a><span class="lineno"> 314</span> fclose(f);</div>
|
|
<div class="line"><a id="l00315" name="l00315"></a><span class="lineno"> 315</span> }</div>
|
|
<div class="line"><a id="l00316" name="l00316"></a><span class="lineno"> 316</span> <span class="keywordflow">catch</span> (<a class="code hl_classRef" href="http://en.cppreference.com/w/cpp/error/exception.html">std::exception</a> <span class="keyword">const</span>& ex)</div>
|
|
<div class="line"><a id="l00317" name="l00317"></a><span class="lineno"> 317</span> {</div>
|
|
<div class="line"><a id="l00318" name="l00318"></a><span class="lineno"> 318</span> fclose(f);</div>
|
|
<div class="line"><a id="l00319" name="l00319"></a><span class="lineno"> 319</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(</div>
|
|
<div class="line"><a id="l00320" name="l00320"></a><span class="lineno"> 320</span> <a class="code hl_classRef" href="http://en.cppreference.com/w/cpp/string/basic_string.html">std::string</a>(</div>
|
|
<div class="line"><a id="l00321" name="l00321"></a><span class="lineno"> 321</span> <span class="stringliteral">"Reading the SSL chain file generated an exception: "</span>) +</div>
|
|
<div class="line"><a id="l00322" name="l00322"></a><span class="lineno"> 322</span> ex.<a class="code hl_functionRef" href="http://en.cppreference.com/w/cpp/error/exception/what.html">what</a>());</div>
|
|
<div class="line"><a id="l00323" name="l00323"></a><span class="lineno"> 323</span> }</div>
|
|
<div class="line"><a id="l00324" name="l00324"></a><span class="lineno"> 324</span> }</div>
|
|
<div class="line"><a id="l00325" name="l00325"></a><span class="lineno"> 325</span> </div>
|
|
<div class="line"><a id="l00326" name="l00326"></a><span class="lineno"> 326</span> <span class="keywordflow">if</span> (!key_file.<a class="code hl_functionRef" href="http://en.cppreference.com/w/cpp/string/basic_string/empty.html">empty</a>())</div>
|
|
<div class="line"><a id="l00327" name="l00327"></a><span class="lineno"> 327</span> {</div>
|
|
<div class="line"><a id="l00328" name="l00328"></a><span class="lineno"> 328</span> boost::system::error_code ec;</div>
|
|
<div class="line"><a id="l00329" name="l00329"></a><span class="lineno"> 329</span> </div>
|
|
<div class="line"><a id="l00330" name="l00330"></a><span class="lineno"> 330</span> context.use_private_key_file(</div>
|
|
<div class="line"><a id="l00331" name="l00331"></a><span class="lineno"> 331</span> key_file, boost::asio::ssl::context::pem, ec);</div>
|
|
<div class="line"><a id="l00332" name="l00332"></a><span class="lineno"> 332</span> </div>
|
|
<div class="line"><a id="l00333" name="l00333"></a><span class="lineno"> 333</span> <span class="keywordflow">if</span> (ec)</div>
|
|
<div class="line"><a id="l00334" name="l00334"></a><span class="lineno"> 334</span> {</div>
|
|
<div class="line"><a id="l00335" name="l00335"></a><span class="lineno"> 335</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(</div>
|
|
<div class="line"><a id="l00336" name="l00336"></a><span class="lineno"> 336</span> <span class="stringliteral">"Problem using the SSL private key file"</span> + fmt_error(ec));</div>
|
|
<div class="line"><a id="l00337" name="l00337"></a><span class="lineno"> 337</span> }</div>
|
|
<div class="line"><a id="l00338" name="l00338"></a><span class="lineno"> 338</span> }</div>
|
|
<div class="line"><a id="l00339" name="l00339"></a><span class="lineno"> 339</span> </div>
|
|
<div class="line"><a id="l00340" name="l00340"></a><span class="lineno"> 340</span> <span class="keywordflow">if</span> (SSL_CTX_check_private_key(ssl) != 1)</div>
|
|
<div class="line"><a id="l00341" name="l00341"></a><span class="lineno"> 341</span> {</div>
|
|
<div class="line"><a id="l00342" name="l00342"></a><span class="lineno"> 342</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(<span class="stringliteral">"Invalid key in SSL private key file."</span>);</div>
|
|
<div class="line"><a id="l00343" name="l00343"></a><span class="lineno"> 343</span> }</div>
|
|
<div class="line"><a id="l00344" name="l00344"></a><span class="lineno"> 344</span>}</div>
|
|
</div>
|
|
<div class="line"><a id="l00345" name="l00345"></a><span class="lineno"> 345</span> </div>
|
|
<div class="line"><a id="l00346" name="l00346"></a><span class="lineno"> 346</span><a class="code hl_classRef" href="http://en.cppreference.com/w/cpp/memory/shared_ptr.html">std::shared_ptr<boost::asio::ssl::context></a></div>
|
|
<div class="foldopen" id="foldopen00347" data-start="{" data-end="}">
|
|
<div class="line"><a id="l00347" name="l00347"></a><span class="lineno"><a class="line" href="namespaceripple_1_1openssl_1_1detail.html#a52976a91300df20ce0c6a9c80f63fd52"> 347</a></span><a class="code hl_function" href="namespaceripple_1_1openssl_1_1detail.html#a52976a91300df20ce0c6a9c80f63fd52">get_context</a>(<a class="code hl_classRef" href="http://en.cppreference.com/w/cpp/string/basic_string.html">std::string</a> cipherList)</div>
|
|
<div class="line"><a id="l00348" name="l00348"></a><span class="lineno"> 348</span>{</div>
|
|
<div class="line"><a id="l00349" name="l00349"></a><span class="lineno"> 349</span> <span class="keyword">auto</span> c = <a class="code hl_variableRef" href="http://en.cppreference.com/w/cpp/types/is_same.html">std::make_shared<boost::asio::ssl::context></a>(</div>
|
|
<div class="line"><a id="l00350" name="l00350"></a><span class="lineno"> 350</span> boost::asio::ssl::context::sslv23);</div>
|
|
<div class="line"><a id="l00351" name="l00351"></a><span class="lineno"> 351</span> </div>
|
|
<div class="line"><a id="l00352" name="l00352"></a><span class="lineno"> 352</span> c->set_options(</div>
|
|
<div class="line"><a id="l00353" name="l00353"></a><span class="lineno"> 353</span> boost::asio::ssl::context::default_workarounds |</div>
|
|
<div class="line"><a id="l00354" name="l00354"></a><span class="lineno"> 354</span> boost::asio::ssl::context::no_sslv2 |</div>
|
|
<div class="line"><a id="l00355" name="l00355"></a><span class="lineno"> 355</span> boost::asio::ssl::context::no_sslv3 |</div>
|
|
<div class="line"><a id="l00356" name="l00356"></a><span class="lineno"> 356</span> boost::asio::ssl::context::no_tlsv1 |</div>
|
|
<div class="line"><a id="l00357" name="l00357"></a><span class="lineno"> 357</span> boost::asio::ssl::context::no_tlsv1_1 |</div>
|
|
<div class="line"><a id="l00358" name="l00358"></a><span class="lineno"> 358</span> boost::asio::ssl::context::single_dh_use |</div>
|
|
<div class="line"><a id="l00359" name="l00359"></a><span class="lineno"> 359</span> boost::asio::ssl::context::no_compression);</div>
|
|
<div class="line"><a id="l00360" name="l00360"></a><span class="lineno"> 360</span> </div>
|
|
<div class="line"><a id="l00361" name="l00361"></a><span class="lineno"> 361</span> <span class="keywordflow">if</span> (cipherList.<a class="code hl_functionRef" href="http://en.cppreference.com/w/cpp/string/basic_string/empty.html">empty</a>())</div>
|
|
<div class="line"><a id="l00362" name="l00362"></a><span class="lineno"> 362</span> cipherList = <a class="code hl_variable" href="namespaceripple_1_1openssl_1_1detail.html#abc918438dc5c8a648a41bd9ee286f059">defaultCipherList</a>;</div>
|
|
<div class="line"><a id="l00363" name="l00363"></a><span class="lineno"> 363</span> </div>
|
|
<div class="line"><a id="l00364" name="l00364"></a><span class="lineno"> 364</span> <span class="keywordflow">if</span> (<span class="keyword">auto</span> result =</div>
|
|
<div class="line"><a id="l00365" name="l00365"></a><span class="lineno"> 365</span> SSL_CTX_set_cipher_list(c->native_handle(), cipherList.<a class="code hl_functionRef" href="http://en.cppreference.com/w/cpp/string/basic_string/c_str.html">c_str</a>());</div>
|
|
<div class="line"><a id="l00366" name="l00366"></a><span class="lineno"> 366</span> result != 1)</div>
|
|
<div class="line"><a id="l00367" name="l00367"></a><span class="lineno"> 367</span> <a class="code hl_function" href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">LogicError</a>(<span class="stringliteral">"SSL_CTX_set_cipher_list failed"</span>);</div>
|
|
<div class="line"><a id="l00368" name="l00368"></a><span class="lineno"> 368</span> </div>
|
|
<div class="line"><a id="l00369" name="l00369"></a><span class="lineno"> 369</span> c->use_tmp_dh({<a class="code hl_functionRef" href="http://en.cppreference.com/w/cpp/memory/addressof.html">std::addressof</a>(<a class="code hl_variable" href="namespaceripple_1_1openssl_1_1detail.html#aee6f7af679257601e8cea90d6a306925">detail::defaultDH</a>), <span class="keyword">sizeof</span>(<a class="code hl_variable" href="namespaceripple_1_1openssl_1_1detail.html#aee6f7af679257601e8cea90d6a306925">defaultDH</a>)});</div>
|
|
<div class="line"><a id="l00370" name="l00370"></a><span class="lineno"> 370</span> </div>
|
|
<div class="line"><a id="l00371" name="l00371"></a><span class="lineno"> 371</span> <span class="comment">// Disable all renegotiation support in TLS v1.2. This can help prevent</span></div>
|
|
<div class="line"><a id="l00372" name="l00372"></a><span class="lineno"> 372</span> <span class="comment">// exploitation of the bug described in CVE-2021-3499 (for details see</span></div>
|
|
<div class="line"><a id="l00373" name="l00373"></a><span class="lineno"> 373</span> <span class="comment">// https://www.openssl.org/news/secadv/20210325.txt) when linking</span></div>
|
|
<div class="line"><a id="l00374" name="l00374"></a><span class="lineno"> 374</span> <span class="comment">// against OpenSSL versions prior to 1.1.1k.</span></div>
|
|
<div class="line"><a id="l00375" name="l00375"></a><span class="lineno"> 375</span> SSL_CTX_set_options(c->native_handle(), SSL_OP_NO_RENEGOTIATION);</div>
|
|
<div class="line"><a id="l00376" name="l00376"></a><span class="lineno"> 376</span> </div>
|
|
<div class="line"><a id="l00377" name="l00377"></a><span class="lineno"> 377</span> <span class="keywordflow">return</span> c;</div>
|
|
<div class="line"><a id="l00378" name="l00378"></a><span class="lineno"> 378</span>}</div>
|
|
</div>
|
|
<div class="line"><a id="l00379" name="l00379"></a><span class="lineno"> 379</span> </div>
|
|
<div class="line"><a id="l00380" name="l00380"></a><span class="lineno"> 380</span>} <span class="comment">// namespace detail</span></div>
|
|
</div>
|
|
<div class="line"><a id="l00381" name="l00381"></a><span class="lineno"> 381</span>} <span class="comment">// namespace openssl</span></div>
|
|
</div>
|
|
<div class="line"><a id="l00382" name="l00382"></a><span class="lineno"> 382</span> </div>
|
|
<div class="line"><a id="l00383" name="l00383"></a><span class="lineno"> 383</span><span class="comment">//------------------------------------------------------------------------------</span></div>
|
|
<div class="line"><a id="l00384" name="l00384"></a><span class="lineno"> 384</span><a class="code hl_classRef" href="http://en.cppreference.com/w/cpp/memory/shared_ptr.html">std::shared_ptr<boost::asio::ssl::context></a></div>
|
|
<div class="foldopen" id="foldopen00385" data-start="{" data-end="}">
|
|
<div class="line"><a id="l00385" name="l00385"></a><span class="lineno"><a class="line" href="namespaceripple.html#a75121fd263018f521eb29d1b5a07eb69"> 385</a></span><a class="code hl_function" href="namespaceripple.html#a75121fd263018f521eb29d1b5a07eb69">make_SSLContext</a>(<a class="code hl_classRef" href="http://en.cppreference.com/w/cpp/string/basic_string.html">std::string</a> <span class="keyword">const</span>& cipherList)</div>
|
|
<div class="line"><a id="l00386" name="l00386"></a><span class="lineno"> 386</span>{</div>
|
|
<div class="line"><a id="l00387" name="l00387"></a><span class="lineno"> 387</span> <span class="keyword">auto</span> context = <a class="code hl_function" href="namespaceripple_1_1openssl_1_1detail.html#a52976a91300df20ce0c6a9c80f63fd52">openssl::detail::get_context</a>(cipherList);</div>
|
|
<div class="line"><a id="l00388" name="l00388"></a><span class="lineno"> 388</span> <a class="code hl_function" href="namespaceripple_1_1openssl_1_1detail.html#a5424207e5a700ac59ea8b9ab1e2b9397">openssl::detail::initAnonymous</a>(*context);</div>
|
|
<div class="line"><a id="l00389" name="l00389"></a><span class="lineno"> 389</span> <span class="comment">// VFALCO NOTE, It seems the WebSocket context never has</span></div>
|
|
<div class="line"><a id="l00390" name="l00390"></a><span class="lineno"> 390</span> <span class="comment">// set_verify_mode called, for either setting of WEBSOCKET_SECURE</span></div>
|
|
<div class="line"><a id="l00391" name="l00391"></a><span class="lineno"> 391</span> context->set_verify_mode(boost::asio::ssl::verify_none);</div>
|
|
<div class="line"><a id="l00392" name="l00392"></a><span class="lineno"> 392</span> <span class="keywordflow">return</span> context;</div>
|
|
<div class="line"><a id="l00393" name="l00393"></a><span class="lineno"> 393</span>}</div>
|
|
</div>
|
|
<div class="line"><a id="l00394" name="l00394"></a><span class="lineno"> 394</span> </div>
|
|
<div class="line"><a id="l00395" name="l00395"></a><span class="lineno"> 395</span><a class="code hl_classRef" href="http://en.cppreference.com/w/cpp/memory/shared_ptr.html">std::shared_ptr<boost::asio::ssl::context></a></div>
|
|
<div class="foldopen" id="foldopen00396" data-start="{" data-end="}">
|
|
<div class="line"><a id="l00396" name="l00396"></a><span class="lineno"><a class="line" href="namespaceripple.html#adadc476df0a03ae08bd0c378ccf3b194"> 396</a></span><a class="code hl_function" href="namespaceripple.html#adadc476df0a03ae08bd0c378ccf3b194">make_SSLContextAuthed</a>(</div>
|
|
<div class="line"><a id="l00397" name="l00397"></a><span class="lineno"> 397</span> <a class="code hl_classRef" href="http://en.cppreference.com/w/cpp/string/basic_string.html">std::string</a> <span class="keyword">const</span>& keyFile,</div>
|
|
<div class="line"><a id="l00398" name="l00398"></a><span class="lineno"> 398</span> <a class="code hl_classRef" href="http://en.cppreference.com/w/cpp/string/basic_string.html">std::string</a> <span class="keyword">const</span>& certFile,</div>
|
|
<div class="line"><a id="l00399" name="l00399"></a><span class="lineno"> 399</span> <a class="code hl_classRef" href="http://en.cppreference.com/w/cpp/string/basic_string.html">std::string</a> <span class="keyword">const</span>& chainFile,</div>
|
|
<div class="line"><a id="l00400" name="l00400"></a><span class="lineno"> 400</span> <a class="code hl_classRef" href="http://en.cppreference.com/w/cpp/string/basic_string.html">std::string</a> <span class="keyword">const</span>& cipherList)</div>
|
|
<div class="line"><a id="l00401" name="l00401"></a><span class="lineno"> 401</span>{</div>
|
|
<div class="line"><a id="l00402" name="l00402"></a><span class="lineno"> 402</span> <span class="keyword">auto</span> context = <a class="code hl_function" href="namespaceripple_1_1openssl_1_1detail.html#a52976a91300df20ce0c6a9c80f63fd52">openssl::detail::get_context</a>(cipherList);</div>
|
|
<div class="line"><a id="l00403" name="l00403"></a><span class="lineno"> 403</span> <a class="code hl_function" href="namespaceripple_1_1openssl_1_1detail.html#a70f3d81f87a75113774c421267a670b7">openssl::detail::initAuthenticated</a>(*context, keyFile, certFile, chainFile);</div>
|
|
<div class="line"><a id="l00404" name="l00404"></a><span class="lineno"> 404</span> <span class="keywordflow">return</span> context;</div>
|
|
<div class="line"><a id="l00405" name="l00405"></a><span class="lineno"> 405</span>}</div>
|
|
</div>
|
|
<div class="line"><a id="l00406" name="l00406"></a><span class="lineno"> 406</span> </div>
|
|
<div class="line"><a id="l00407" name="l00407"></a><span class="lineno"> 407</span>} <span class="comment">// namespace ripple</span></div>
|
|
<div class="ttc" id="aaddressof_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/memory/addressof.html">std::addressof</a></div><div class="ttdeci">T addressof(T... args)</div></div>
|
|
<div class="ttc" id="abasic_string_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/string/basic_string.html">std::string</a></div></div>
|
|
<div class="ttc" id="ac_str_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/string/basic_string/c_str.html">std::string::c_str</a></div><div class="ttdeci">T c_str(T... args)</div></div>
|
|
<div class="ttc" id="acerrno_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/header/cerrno.html">cerrno</a></div></div>
|
|
<div class="ttc" id="acstdio_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/header/cstdio.html">cstdio</a></div></div>
|
|
<div class="ttc" id="actime_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/header/ctime.html">ctime</a></div></div>
|
|
<div class="ttc" id="aempty_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/string/basic_string/empty.html">std::string::empty</a></div><div class="ttdeci">T empty(T... args)</div></div>
|
|
<div class="ttc" id="aexception_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/header/exception.html">exception</a></div></div>
|
|
<div class="ttc" id="agmtime_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/chrono/c/gmtime.html">std::gmtime</a></div><div class="ttdeci">T gmtime(T... args)</div></div>
|
|
<div class="ttc" id="ais_same_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/types/is_same.html">std::is_same_v</a></div><div class="ttdeci">T is_same_v</div></div>
|
|
<div class="ttc" id="amemory_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/header/memory.html">memory</a></div></div>
|
|
<div class="ttc" id="anamespaceripple_1_1openssl_1_1detail_html_a52976a91300df20ce0c6a9c80f63fd52"><div class="ttname"><a href="namespaceripple_1_1openssl_1_1detail.html#a52976a91300df20ce0c6a9c80f63fd52">ripple::openssl::detail::get_context</a></div><div class="ttdeci">std::shared_ptr< boost::asio::ssl::context > get_context(std::string cipherList)</div><div class="ttdef"><b>Definition</b> <a href="make__SSLContext_8cpp_source.html#l00347">make_SSLContext.cpp:347</a></div></div>
|
|
<div class="ttc" id="anamespaceripple_1_1openssl_1_1detail_html_a5424207e5a700ac59ea8b9ab1e2b9397"><div class="ttname"><a href="namespaceripple_1_1openssl_1_1detail.html#a5424207e5a700ac59ea8b9ab1e2b9397">ripple::openssl::detail::initAnonymous</a></div><div class="ttdeci">static void initAnonymous(boost::asio::ssl::context &context)</div><div class="ttdef"><b>Definition</b> <a href="make__SSLContext_8cpp_source.html#l00107">make_SSLContext.cpp:107</a></div></div>
|
|
<div class="ttc" id="anamespaceripple_1_1openssl_1_1detail_html_a70f3d81f87a75113774c421267a670b7"><div class="ttname"><a href="namespaceripple_1_1openssl_1_1detail.html#a70f3d81f87a75113774c421267a670b7">ripple::openssl::detail::initAuthenticated</a></div><div class="ttdeci">static void initAuthenticated(boost::asio::ssl::context &context, std::string const &key_file, std::string const &cert_file, std::string const &chain_file)</div><div class="ttdef"><b>Definition</b> <a href="make__SSLContext_8cpp_source.html#l00249">make_SSLContext.cpp:249</a></div></div>
|
|
<div class="ttc" id="anamespaceripple_1_1openssl_1_1detail_html_abc918438dc5c8a648a41bd9ee286f059"><div class="ttname"><a href="namespaceripple_1_1openssl_1_1detail.html#abc918438dc5c8a648a41bd9ee286f059">ripple::openssl::detail::defaultCipherList</a></div><div class="ttdeci">std::string const defaultCipherList</div><div class="ttdoc">The default list of ciphers we accept over TLS.</div><div class="ttdef"><b>Definition</b> <a href="make__SSLContext_8cpp_source.html#l00104">make_SSLContext.cpp:104</a></div></div>
|
|
<div class="ttc" id="anamespaceripple_1_1openssl_1_1detail_html_ae431166efcafc1b6d7fc5109bfc7e678"><div class="ttname"><a href="namespaceripple_1_1openssl_1_1detail.html#ae431166efcafc1b6d7fc5109bfc7e678">ripple::openssl::detail::defaultRSAKeyBits</a></div><div class="ttdeci">int defaultRSAKeyBits</div><div class="ttdoc">The default strength of self-signed RSA certifices.</div><div class="ttdef"><b>Definition</b> <a href="make__SSLContext_8cpp_source.html#l00066">make_SSLContext.cpp:66</a></div></div>
|
|
<div class="ttc" id="anamespaceripple_1_1openssl_1_1detail_html_aee6f7af679257601e8cea90d6a306925"><div class="ttname"><a href="namespaceripple_1_1openssl_1_1detail.html#aee6f7af679257601e8cea90d6a306925">ripple::openssl::detail::defaultDH</a></div><div class="ttdeci">static constexpr char const defaultDH[]</div><div class="ttdoc">The default DH parameters.</div><div class="ttdef"><b>Definition</b> <a href="make__SSLContext_8cpp_source.html#l00080">make_SSLContext.cpp:80</a></div></div>
|
|
<div class="ttc" id="anamespaceripple_html"><div class="ttname"><a href="namespaceripple.html">ripple</a></div><div class="ttdoc">Use hash_* containers for keys that do not need a cryptographically secure hashing algorithm.</div><div class="ttdef"><b>Definition</b> <a href="algorithm_8h_source.html#l00025">algorithm.h:25</a></div></div>
|
|
<div class="ttc" id="anamespaceripple_html_a75121fd263018f521eb29d1b5a07eb69"><div class="ttname"><a href="namespaceripple.html#a75121fd263018f521eb29d1b5a07eb69">ripple::make_SSLContext</a></div><div class="ttdeci">std::shared_ptr< boost::asio::ssl::context > make_SSLContext(std::string const &cipherList)</div><div class="ttdoc">Create a self-signed SSL context that allows anonymous Diffie Hellman.</div><div class="ttdef"><b>Definition</b> <a href="make__SSLContext_8cpp_source.html#l00385">make_SSLContext.cpp:385</a></div></div>
|
|
<div class="ttc" id="anamespaceripple_html_adadc476df0a03ae08bd0c378ccf3b194"><div class="ttname"><a href="namespaceripple.html#adadc476df0a03ae08bd0c378ccf3b194">ripple::make_SSLContextAuthed</a></div><div class="ttdeci">std::shared_ptr< boost::asio::ssl::context > make_SSLContextAuthed(std::string const &keyFile, std::string const &certFile, std::string const &chainFile, std::string const &cipherList)</div><div class="ttdoc">Create an authenticated SSL context using the specified files.</div><div class="ttdef"><b>Definition</b> <a href="make__SSLContext_8cpp_source.html#l00396">make_SSLContext.cpp:396</a></div></div>
|
|
<div class="ttc" id="anamespaceripple_html_aefd2f77338ce3c9a2fffc4f0b289b483"><div class="ttname"><a href="namespaceripple.html#aefd2f77338ce3c9a2fffc4f0b289b483">ripple::LogicError</a></div><div class="ttdeci">void LogicError(std::string const &how) noexcept</div><div class="ttdoc">Called when faulty logic causes a broken invariant.</div><div class="ttdef"><b>Definition</b> <a href="libxrpl_2basics_2contract_8cpp_source.html#l00037">libxrpl/basics/contract.cpp:37</a></div></div>
|
|
<div class="ttc" id="ashared_ptr_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/memory/shared_ptr.html">std::shared_ptr</a></div></div>
|
|
<div class="ttc" id="astrftime_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/chrono/c/strftime.html">std::strftime</a></div><div class="ttdeci">T strftime(T... args)</div></div>
|
|
<div class="ttc" id="astring_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/header/string.html">string</a></div></div>
|
|
<div class="ttc" id="atime_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/chrono/c/time.html">std::time</a></div><div class="ttdeci">T time(T... args)</div></div>
|
|
<div class="ttc" id="ato_string_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/string/basic_string/to_string.html">std::to_string</a></div><div class="ttdeci">T to_string(T... args)</div></div>
|
|
<div class="ttc" id="awhat_html"><div class="ttname"><a href="http://en.cppreference.com/w/cpp/error/exception/what.html">std::exception::what</a></div><div class="ttdeci">T what(T... args)</div></div>
|
|
</div><!-- fragment --></div><!-- contents -->
|
|
<!-- start footer part -->
|
|
<hr class="footer"/><address class="footer"><small>
|
|
Generated by <a href="https://www.doxygen.org/index.html"><img class="footer" src="doxygen.svg" width="104" height="31" alt="doxygen"/></a> 1.9.8
|
|
</small></address>
|
|
</body>
|
|
</html>
|