web: The beginnings of TLS

This commit is contained in:
2026-03-08 22:08:25 +01:00
parent e09a00a4ba
commit 1f07cc38ba
10 changed files with 1136 additions and 321 deletions

View File

@@ -8,8 +8,12 @@ pub fn build(b: *std.Build) void {
.root_source_file = b.path("src/root.zig"),
.target = target,
.optimize = optimize,
.link_libc = true,
});
module.linkSystemLibrary("ssl", .{});
module.linkSystemLibrary("crypto", .{});
const tests = b.addTest(.{
.root_module = module,
});
@@ -30,6 +34,17 @@ pub fn build(b: *std.Build) void {
b.installArtifact(exe);
const run_step = b.step("run", "Run the app");
const run_cmd = b.addRunArtifact(exe);
run_step.dependOn(&run_cmd.step);
run_cmd.step.dependOn(b.getInstallStep());
if (b.args) |args| {
run_cmd.addArgs(args);
}
const run_tests = b.addRunArtifact(tests);
const test_step = b.step("test", "Run tests");

9
packages/web/cert.pem Normal file
View File

@@ -0,0 +1,9 @@
-----BEGIN CERTIFICATE-----
MIIBPDCB76ADAgECAhRuWLL9k0QOIt4+BPNlFBzRcmvREDAFBgMrZXAwFDESMBAG
A1UEAwwJbG9jYWxob3N0MB4XDTI2MDMwODIwNDczNFoXDTM2MDMwNTIwNDczNFow
FDESMBAGA1UEAwwJbG9jYWxob3N0MCowBQYDK2VwAyEAdgB1CRIUYLCPclWp2+5c
X3I0aqoY7yuhZBE9NxKKbZ+jUzBRMB0GA1UdDgQWBBQXJ3/C7HMVOjXcnqvDKdWo
PWhzsTAfBgNVHSMEGDAWgBQXJ3/C7HMVOjXcnqvDKdWoPWhzsTAPBgNVHRMBAf8E
BTADAQH/MAUGAytlcANBAFirv6F5+TamfddV1sElbfI8jfhPLxWU+z6/mxxbzooX
IKdOh/FrCrPfeUavKH9C5Vr+ztPgoTdCaFqo5mT7MAw=
-----END CERTIFICATE-----

3
packages/web/key.pem Normal file
View File

@@ -0,0 +1,3 @@
-----BEGIN PRIVATE KEY-----
MC4CAQAwBQYDK2VwBCIEIMDUsa31l2xEhX1gyB5w2WABgSbne3GHyUe0RWomq9C5
-----END PRIVATE KEY-----

View File

@@ -3,6 +3,7 @@ const web = @import("web");
const linux = std.os.linux;
const errno = linux.E.init;
const ssl = web.openssl;
const UUID = web.UUID;
var running: std.atomic.Value(bool) = .init(true);
@@ -134,6 +135,20 @@ pub fn main() !void {
var router: Router = .init(allocator);
_ = ssl.c_ssl.SSL_library_init();
_ = ssl.c_ssl.OpenSSL_add_all_algorithms();
_ = ssl.c_ssl.SSL_load_error_strings();
const ssl_ctx = try ssl.Context.new(ssl.Method.tlsServerMethod());
defer ssl_ctx.free();
_ = ssl_ctx.setMinProtoVersion(ssl.c_ssl.TLS1_3_VERSION);
_ = ssl_ctx.setOptions(ssl.c_ssl.SSL_OP_NO_SSLv3 | ssl.c_ssl.SSL_OP_NO_TLSv1 | ssl.c_ssl.SSL_OP_NO_TLSv1_1 | ssl.c_ssl.SSL_OP_NO_TLSv1_2);
try ssl_ctx.useCertificateFile("cert.pem", ssl.c_ssl.SSL_FILETYPE_PEM);
try ssl_ctx.usePrivateKeyFile("key.pem", ssl.c_ssl.SSL_FILETYPE_PEM);
try ssl_ctx.checkPrivateKey();
var server = try web.Server.init(allocator, .{
.request_router = router.interface(),
.address = .initIp4(.{ 127, 0, 0, 1 }, 8000),

View File

@@ -1,4 +1,7 @@
const std = @import("std");
pub const err = @import("openssl/err.zig");
pub const ssl = @import("openssl/ssl.zig");
pub const c_err = @import("openssl/err.zig");
pub const c_ssl = @import("openssl/ssl.zig");
pub const Context = @import("openssl/Context.zig").Context;
pub const Method = @import("openssl/Method.zig").Method;

View File

@@ -0,0 +1,657 @@
const std = @import("std");
const c_ssl = @import("ssl.zig");
const Method = @import("Method.zig").Method;
const Session = @import("Session.zig").Session;
const Ssl = @import("Ssl.zig").Ssl;
pub const Context = opaque {
// --- MACROS --------------------------------------------------------------
pub inline fn setMode(self: *Context, op: anytype) i64 {
return self.ctrl(c_ssl.c_ssl.SSL_CTRL_MODE, op, null);
}
pub inline fn clearMode(self: *Context, op: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_CLEAR_MODE, op, null);
}
pub inline fn getMode(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_MODE, 0, null);
}
pub inline fn setCertFlags(self: *Context, op: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_CERT_FLAGS, op, null);
}
pub inline fn clearCertFlags(self: *Context, op: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_CLEAR_CERT_FLAGS, op, null);
}
pub inline fn setMsgCallbackArg(self: *Context, arg: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_MSG_CALLBACK_ARG, 0, arg);
}
pub inline fn sessNumber(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SESS_NUMBER, 0, null);
}
pub inline fn sessConnect(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SESS_CONNECT, 0, null);
}
pub inline fn sessConnectGood(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SESS_CONNECT_GOOD, 0, null);
}
pub inline fn sessConnectRenegotiate(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SESS_CONNECT_RENEGOTIATE, 0, null);
}
pub inline fn sessAccept(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SESS_ACCEPT, 0, null);
}
pub inline fn sessAcceptRenegotiate(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SESS_ACCEPT_RENEGOTIATE, 0, null);
}
pub inline fn sessAcceptGood(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SESS_ACCEPT_GOOD, 0, null);
}
pub inline fn sessHits(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SESS_HIT, 0, null);
}
pub inline fn sessCbHits(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SESS_CB_HIT, 0, null);
}
pub inline fn sessMisses(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SESS_MISSES, 0, null);
}
pub inline fn sessTimeouts(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SESS_TIMEOUTS, 0, null);
}
pub inline fn sessCacheFull(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SESS_CACHE_FULL, 0, null);
}
pub inline fn setTlsextServernameArg(self: *Context, arg: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_TLSEXT_SERVERNAME_ARG, 0, arg);
}
pub inline fn getTlsextTicketKeys(self: *Context, keys: anytype, keylen: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_GET_TLSEXT_TICKET_KEYS, keylen, keys);
}
pub inline fn setTlsextTicketKeys(self: *Context, keys: anytype, keylen: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_TLSEXT_TICKET_KEYS, keylen, keys);
}
pub inline fn getTlsextStatusCb(self: *Context, cb: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_GET_TLSEXT_STATUS_REQ_CB, 0, @import("std").zig.c_translation.cast(?*anyopaque, cb));
}
pub inline fn getTlsextStatusArg(self: *Context, arg: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_GET_TLSEXT_STATUS_REQ_CB_ARG, 0, arg);
}
pub inline fn setTlsextStatusArg(self: *Context, arg: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_TLSEXT_STATUS_REQ_CB_ARG, 0, arg);
}
pub inline fn setTlsextStatusType(self: *Context, @"type": anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_TLSEXT_STATUS_REQ_TYPE, @"type", null);
}
pub inline fn getTlsextStatusType(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_GET_TLSEXT_STATUS_REQ_TYPE, 0, null);
}
pub inline fn getAppData(self: *const Context) ?*anyopaque {
return self.getExData(0);
}
pub inline fn setAppData(self: *Context, data: ?*anyopaque) i32 {
return self.setExData(0, data);
}
pub inline fn setTmpDh(self: *Context, dh: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_TMP_DH, 0, @import("std").zig.c_translation.cast([*c]u8, dh));
}
pub inline fn setDhAuto(self: *Context, onoff: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_DH_AUTO, onoff, null);
}
pub inline fn setTmpEcdh(self: *Context, ecdh: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_TMP_ECDH, 0, @import("std").zig.c_translation.cast([*c]u8, ecdh));
}
pub inline fn addExtraChainCert(self: *Context, x509: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_EXTRA_CHAIN_CERT, 0, @import("std").zig.c_translation.cast([*c]u8, x509));
}
pub inline fn getExtraChainCerts(self: *Context, px509: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_GET_EXTRA_CHAIN_CERTS, 0, px509);
}
pub inline fn getExtraChainCertsOnly(self: *Context, px509: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_GET_EXTRA_CHAIN_CERTS, @as(c_int, 1), px509);
}
pub inline fn clearExtraChainCerts(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_CLEAR_EXTRA_CHAIN_CERTS, 0, null);
}
pub inline fn set0Chain(self: *Context, sk: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_CHAIN, 0, @import("std").zig.c_translation.cast([*c]u8, sk));
}
pub inline fn set1Chain(self: *Context, sk: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_CHAIN, @as(c_int, 1), @import("std").zig.c_translation.cast([*c]u8, sk));
}
pub inline fn add0ChainCert(self: *Context, x509: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_CHAIN_CERT, 0, @import("std").zig.c_translation.cast([*c]u8, x509));
}
pub inline fn add1ChainCert(self: *Context, x509: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_CHAIN_CERT, @as(c_int, 1), @import("std").zig.c_translation.cast([*c]u8, x509));
}
pub inline fn get0ChainCerts(self: *Context, px509: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_GET_CHAIN_CERTS, 0, px509);
}
pub inline fn clearChainCerts(self: *Context) i64 {
return self.set0Chain(null);
}
pub inline fn buildCertChain(self: *Context, flags: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_BUILD_CERT_CHAIN, flags, null);
}
pub inline fn selectCurrentCert(self: *Context, x509: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SELECT_CURRENT_CERT, 0, @import("std").zig.c_translation.cast([*c]u8, x509));
}
pub inline fn setCurrentCert(self: *Context, op: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_CURRENT_CERT, op, null);
}
pub inline fn set0VerifyCertStore(self: *Context, st: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_VERIFY_CERT_STORE, 0, @import("std").zig.c_translation.cast([*c]u8, st));
}
pub inline fn set1VerifyCertStore(self: *Context, st: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_VERIFY_CERT_STORE, @as(c_int, 1), @import("std").zig.c_translation.cast([*c]u8, st));
}
pub inline fn get0VerifyCertStore(self: *Context, st: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_GET_VERIFY_CERT_STORE, 0, @import("std").zig.c_translation.cast([*c]u8, st));
}
pub inline fn set0ChainCertStore(self: *Context, st: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_CHAIN_CERT_STORE, 0, @import("std").zig.c_translation.cast([*c]u8, st));
}
pub inline fn set1ChainCertStore(self: *Context, st: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_CHAIN_CERT_STORE, @as(c_int, 1), @import("std").zig.c_translation.cast([*c]u8, st));
}
pub inline fn get0ChainCertStore(self: *Context, st: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_GET_CHAIN_CERT_STORE, 0, @import("std").zig.c_translation.cast([*c]u8, st));
}
pub inline fn set1Groups(self: *Context, glist: anytype, glistlen: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_GROUPS, glistlen, @import("std").zig.c_translation.cast([*c]c_int, glist));
}
pub inline fn set1GroupsList(self: *Context, s: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_GROUPS_LIST, 0, @import("std").zig.c_translation.cast([*c]u8, s));
}
pub inline fn set1Sigalgs(self: *Context, slist: anytype, slistlen: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_SIGALGS, slistlen, @import("std").zig.c_translation.cast([*c]c_int, slist));
}
pub inline fn set1SigalgsList(self: *Context, s: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_SIGALGS_LIST, 0, @import("std").zig.c_translation.cast([*c]u8, s));
}
pub inline fn set1ClientSigalgs(self: *Context, slist: anytype, slistlen: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_CLIENT_SIGALGS, slistlen, @import("std").zig.c_translation.cast([*c]c_int, slist));
}
pub inline fn set1ClientSigalgsList(self: *Context, s: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_CLIENT_SIGALGS_LIST, 0, @import("std").zig.c_translation.cast([*c]u8, s));
}
pub inline fn set1ClientCertificateTypes(self: *Context, clist: anytype, clistlen: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_CLIENT_CERT_TYPES, clistlen, @import("std").zig.c_translation.cast([*c]u8, clist));
}
pub inline fn setMinProtoVersion(self: *Context, version: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_MIN_PROTO_VERSION, version, null);
}
pub inline fn setMaxProtoVersion(self: *Context, version: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_MAX_PROTO_VERSION, version, null);
}
pub inline fn getMinProtoVersion(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_GET_MIN_PROTO_VERSION, 0, null);
}
pub inline fn getMaxProtoVersion(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_GET_MAX_PROTO_VERSION, 0, null);
}
pub inline fn getExNewIndex(
argl: i64,
argp: ?*anyopaque,
new_func: ?*const c_ssl.CRYPTO_EX_new,
dup_func: ?*const c_ssl.CRYPTO_EX_dup,
free_func: ?*const c_ssl.CRYPTO_EX_free,
) i32 {
return c_ssl.CRYPTO_get_ex_new_index(c_ssl.CRYPTO_EX_INDEX_SSL_CTX, argl, argp, new_func, dup_func, free_func);
}
pub inline fn sessSetCacheSize(self: *Context, t: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_SESS_CACHE_SIZE, t, null);
}
pub inline fn sessGetCacheSize(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_GET_SESS_CACHE_SIZE, 0, null);
}
pub inline fn setSessionCacheMode(self: *Context, m: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_SESS_CACHE_MODE, m, null);
}
pub inline fn getSessionCacheMode(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_GET_SESS_CACHE_MODE, 0, null);
}
pub inline fn getDefaultReadAhead(self: *Context) i64 {
return self.getReadAhead();
}
pub inline fn setDefaultReadAhead(self: *Context, m: anytype) i64 {
return self.setReadAhead(m);
}
pub inline fn getReadAhead(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_GET_READ_AHEAD, 0, null);
}
pub inline fn setReadAhead(self: *Context, m: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_READ_AHEAD, m, null);
}
pub inline fn getMaxCertList(self: *Context) i64 {
return self.ctrl(c_ssl.SSL_CTRL_GET_MAX_CERT_LIST, 0, null);
}
pub inline fn setMaxCertList(self: *Context, m: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_MAX_CERT_LIST, m, null);
}
pub inline fn setMaxSendFragment(self: *Context, m: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_MAX_SEND_FRAGMENT, m, null);
}
pub inline fn setSplitSendFragment(self: *Context, m: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_SPLIT_SEND_FRAGMENT, m, null);
}
pub inline fn setMaxPipelines(self: *Context, m: anytype) i64 {
return self.ctrl(c_ssl.SSL_CTRL_SET_MAX_PIPELINES, m, null);
}
// --- METHODS -------------------------------------------------------------
pub inline fn checkPrivateKey(self: *const Context) !void {
if (import.SSL_CTX_check_private_key(self) == 0) {
return error.InvalidPrivateKey;
}
}
pub inline fn ctrl(self: *Context, cmd: i32, larg: i64, parg: ?*anyopaque) i64 {
return import.SSL_CTX_ctrl(self, cmd, larg, parg);
}
pub inline fn free(self: *Context) void {
import.SSL_CTX_free(self);
}
pub inline fn getExData(self: *const Context, index: i32) ?*anyopaque {
return import.SSL_CTX_get_ex_data(self, index);
}
pub inline fn new(method: ?*const Method) !*Context {
return import.SSL_CTX_new(method) orelse error.OpenSslError;
}
pub inline fn setExData(self: *Context, index: i32, data: ?*anyopaque) i32 {
return import.SSL_CTX_set_ex_data(self, index, data);
}
pub inline fn setOptions(self: *Context, op: u64) u64 {
return import.SSL_CTX_set_options(self, op);
}
pub inline fn useCertificateFile(self: *Context, file: [*:0]const u8, @"type": i32) !void {
const res = import.SSL_CTX_use_certificate_file(self, file, @"type");
if (res <= 0) {
return error.OpenSslError;
}
}
pub inline fn usePrivateKeyFile(self: *Context, file: [*:0]const u8, @"type": i32) !void {
const res = import.SSL_CTX_use_PrivateKey_file(self, file, @"type");
if (res <= 0) {
return error.OpenSslError;
}
}
};
const import = struct {
pub extern fn SSL_CTX_add_client_CA(ctx: *Context, x: ?*c_ssl.X509) i32;
pub extern fn SSL_CTX_add_client_custom_ext(
ctx: *Context,
ext_type: u32,
add_cb: c_ssl.custom_ext_add_cb,
free_cb: c_ssl.custom_ext_free_cb,
add_arg: ?*anyopaque,
parse_cb: c_ssl.custom_ext_parse_cb,
parse_arg: ?*anyopaque,
) i32;
pub extern fn SSL_CTX_add_custom_ext(
ctx: *Context,
ext_type: u32,
context: u32,
add_cb: c_ssl.SSL_custom_ext_add_cb_ex,
free_cb: c_ssl.SSL_custom_ext_free_cb_ex,
add_arg: ?*anyopaque,
parse_cb: c_ssl.SSL_custom_ext_parse_cb_ex,
parse_arg: ?*anyopaque,
) i32;
pub extern fn SSL_CTX_add_server_custom_ext(
ctx: *Context,
ext_type: u32,
add_cb: c_ssl.custom_ext_add_cb,
free_cb: c_ssl.custom_ext_free_cb,
add_arg: ?*anyopaque,
parse_cb: c_ssl.custom_ext_parse_cb,
parse_arg: ?*anyopaque,
) i32;
pub extern fn SSL_CTX_add_session(ctx: *Context, session: ?*c_ssl.Session) i32;
pub extern fn SSL_CTX_add1_to_CA_list(ctx: *Context, x: ?*const c_ssl.X509) i32;
pub extern fn SSL_CTX_callback_ctrl(*Context, i32, ?*const fn () callconv(.c) void) i64;
pub extern fn SSL_CTX_check_private_key(ctx: *const Context) i32;
pub extern fn SSL_CTX_clear_options(ctx: *Context, op: u64) u64;
pub extern fn SSL_CTX_config(ctx: *Context, name: [*c]const u8) i32;
pub extern fn SSL_CTX_ct_is_enabled(ctx: *const Context) i32;
pub extern fn SSL_CTX_ctrl(ctx: *Context, cmd: i32, larg: i64, parg: ?*anyopaque) i64;
pub extern fn SSL_CTX_dane_clear_flags(ctx: *Context, flags: i64) i64;
pub extern fn SSL_CTX_dane_enable(ctx: *Context) i32;
pub extern fn SSL_CTX_dane_mtype_set(ctx: *Context, md: ?*const c_ssl.EVP_MD, mtype: u8, ord: u8) i32;
pub extern fn SSL_CTX_dane_set_flags(ctx: *Context, flags: i64) i64;
pub extern fn SSL_CTX_enable_ct(ctx: *Context, validation_mode: i32) i32;
pub extern fn SSL_CTX_flush_sessions(ctx: *Context, tm: i64) void;
pub extern fn SSL_CTX_free(*Context) void;
pub extern fn SSL_CTX_get_cert_store(*const Context) ?*c_ssl.X509_STORE;
pub extern fn SSL_CTX_get_ciphers(ctx: *const Context) ?*c_ssl.struct_stack_st_SSL_CIPHER;
pub extern fn SSL_CTX_get_client_CA_list(s: *const Context) ?*c_ssl.struct_stack_st_X509_NAME;
pub extern fn SSL_CTX_get_client_cert_cb(ctx: *Context) ?*const fn (?*Ssl, [*c]?*c_ssl.X509, [*c]?*c_ssl.EVP_PKEY) callconv(.c) i32;
pub extern fn SSL_CTX_get_default_passwd_cb_userdata(ctx: *Context) ?*anyopaque;
pub extern fn SSL_CTX_get_default_passwd_cb(ctx: *Context) ?*const c_ssl.pem_password_cb;
pub extern fn SSL_CTX_get_ex_data(ssl: *const Context, idx: i32) ?*anyopaque;
pub extern fn SSL_CTX_get_info_callback(ctx: *Context) ?*const fn (?*const Ssl, i32, i32) callconv(.c) void;
pub extern fn SSL_CTX_get_keylog_callback(ctx: *const Context) c_ssl.SSL_CTX_keylog_cb_func;
pub extern fn SSL_CTX_get_max_early_data(ctx: *const Context) u32;
pub extern fn SSL_CTX_get_num_tickets(ctx: *const Context) usize;
pub extern fn SSL_CTX_get_options(ctx: *const Context) u64;
pub extern fn SSL_CTX_get_quiet_shutdown(ctx: *const Context) i32;
pub extern fn SSL_CTX_get_record_padding_callback_arg(ctx: *const Context) ?*anyopaque;
pub extern fn SSL_CTX_get_recv_max_early_data(ctx: *const Context) u32;
pub extern fn SSL_CTX_get_security_callback(ctx: *const Context) ?*const fn (
?*const Ssl,
*const Context,
i32,
i32,
i32,
?*anyopaque,
?*anyopaque,
) callconv(.c) i32;
pub extern fn SSL_CTX_get_security_level(ctx: *const Context) i32;
pub extern fn SSL_CTX_get_ssl_method(ctx: *const Context) ?*const Method;
pub extern fn SSL_CTX_get_timeout(ctx: *const Context) i64;
pub extern fn SSL_CTX_get_verify_callback(ctx: *const Context) c_ssl.SSL_verify_cb;
pub extern fn SSL_CTX_get_verify_depth(ctx: *const Context) i32;
pub extern fn SSL_CTX_get_verify_mode(ctx: *const Context) i32;
pub extern fn SSL_CTX_get0_CA_list(ctx: *const Context) ?*const c_ssl.struct_stack_st_X509_NAME;
pub extern fn SSL_CTX_get0_certificate(ctx: *const Context) ?*c_ssl.X509;
pub extern fn SSL_CTX_get0_ctlog_store(ctx: *const Context) ?*const c_ssl.CTLOG_STORE;
pub extern fn SSL_CTX_get0_param(ctx: *Context) ?*c_ssl.X509_VERIFY_PARAM;
pub extern fn SSL_CTX_get0_privatekey(ctx: *const Context) ?*c_ssl.EVP_PKEY;
pub extern fn SSL_CTX_get0_security_ex_data(ctx: *const Context) ?*anyopaque;
pub extern fn SSL_CTX_has_client_custom_ext(ctx: *const Context, ext_type: u32) i32;
pub extern fn SSL_CTX_load_verify_dir(ctx: *Context, CApath: [*c]const u8) i32;
pub extern fn SSL_CTX_load_verify_file(ctx: *Context, CAfile: [*c]const u8) i32;
pub extern fn SSL_CTX_load_verify_locations(ctx: *Context, CAfile: [*c]const u8, CApath: [*c]const u8) i32;
pub extern fn SSL_CTX_load_verify_store(ctx: *Context, CAstore: [*c]const u8) i32;
pub extern fn SSL_CTX_new_ex(libctx: ?*c_ssl.OSSL_LIB_CTX, propq: [*c]const u8, meth: ?*const Method) ?*Context;
pub extern fn SSL_CTX_new(meth: ?*const Method) ?*Context;
pub extern fn SSL_CTX_remove_session(ctx: *Context, session: ?*Session) i32;
pub extern fn SSL_CTX_sess_get_get_cb(ctx: *Context) ?*const fn (
?*c_ssl.struct_ssl_st,
[*c]const u8,
i32,
[*c]i32,
) callconv(.c) ?*Session;
pub extern fn SSL_CTX_sess_get_new_cb(ctx: *Context) ?*const fn (
?*c_ssl.struct_ssl_st,
?*Session,
) callconv(.c) i32;
pub extern fn SSL_CTX_sess_get_remove_cb(ctx: *Context) ?*const fn (
?*c_ssl.struct_ssl_ctx_st,
?*Session,
) callconv(.c) void;
pub extern fn SSL_CTX_sess_set_get_cb(
ctx: *Context,
get_session_cb: ?*const fn (
?*c_ssl.struct_ssl_st,
[*c]const u8,
i32,
[*c]i32,
) callconv(.c) ?*Session,
) void;
pub extern fn SSL_CTX_sess_set_new_cb(
ctx: *Context,
new_session_cb: ?*const fn (
?*c_ssl.struct_ssl_st,
?*Session,
) callconv(.c) i32,
) void;
pub extern fn SSL_CTX_sess_set_remove_cb(
ctx: *Context,
remove_session_cb: ?*const fn (
?*c_ssl.struct_ssl_ctx_st,
?*Session,
) callconv(.c) void,
) void;
pub extern fn SSL_CTX_sessions(ctx: *Context) ?*c_ssl.struct_lhash_st_SSL_SESSION;
pub extern fn SSL_CTX_set_allow_early_data_cb(ctx: *Context, cb: c_ssl.SSL_allow_early_data_cb_fn, arg: ?*anyopaque) void;
pub extern fn SSL_CTX_set_alpn_protos(ctx: *Context, protos: [*c]const u8, protos_len: u32) i32;
pub extern fn SSL_CTX_set_alpn_select_cb(ctx: *Context, cb: c_ssl.SSL_CTX_alpn_select_cb_func, arg: ?*anyopaque) void;
pub extern fn SSL_CTX_set_async_callback_arg(ctx: *Context, arg: ?*anyopaque) i32;
pub extern fn SSL_CTX_set_async_callback(ctx: *Context, callback: c_ssl.SSL_async_callback_fn) i32;
pub extern fn SSL_CTX_set_block_padding(ctx: *Context, block_size: usize) i32;
pub extern fn SSL_CTX_set_cert_cb(c: *Context, cb: ?*const fn (?*Ssl, ?*anyopaque) callconv(.c) i32, arg: ?*anyopaque) void;
pub extern fn SSL_CTX_set_cert_store(*Context, ?*c_ssl.X509_STORE) void;
pub extern fn SSL_CTX_set_cert_verify_callback(
ctx: *Context,
cb: ?*const fn (
?*c_ssl.X509_STORE_CTX,
?*anyopaque,
) callconv(.c) i32,
arg: ?*anyopaque,
) void;
pub extern fn SSL_CTX_set_cipher_list(*Context, str: [*c]const u8) i32;
pub extern fn SSL_CTX_set_ciphersuites(ctx: *Context, str: [*c]const u8) i32;
pub extern fn SSL_CTX_set_client_CA_list(ctx: *Context, name_list: ?*c_ssl.struct_stack_st_X509_NAME) void;
pub extern fn SSL_CTX_set_client_cert_cb(
ctx: *Context,
client_cert_cb: ?*const fn (
?*Ssl,
[*c]?*c_ssl.X509,
[*c]?*c_ssl.EVP_PKEY,
) callconv(.c) i32,
) void;
pub extern fn SSL_CTX_set_client_cert_engine(ctx: *Context, e: ?*c_ssl.ENGINE) i32;
pub extern fn SSL_CTX_set_client_hello_cb(c: *Context, cb: c_ssl.SSL_client_hello_cb_fn, arg: ?*anyopaque) void;
pub extern fn SSL_CTX_set_cookie_generate_cb(ctx: *Context, app_gen_cookie_cb: ?*const fn (?*Ssl, [*c]u8, [*c]u32) callconv(.c) i32) void;
pub extern fn SSL_CTX_set_cookie_verify_cb(ctx: *Context, app_verify_cookie_cb: ?*const fn (?*Ssl, [*c]const u8, u32) callconv(.c) i32) void;
pub extern fn SSL_CTX_set_ct_validation_callback(ctx: *Context, callback: c_ssl.ssl_ct_validation_cb, arg: ?*anyopaque) i32;
pub extern fn SSL_CTX_set_ctlog_list_file(ctx: *Context, path: [*c]const u8) i32;
pub extern fn SSL_CTX_set_default_ctlog_list_file(ctx: *Context) i32;
pub extern fn SSL_CTX_set_default_passwd_cb_userdata(ctx: *Context, u: ?*anyopaque) void;
pub extern fn SSL_CTX_set_default_passwd_cb(ctx: *Context, cb: ?*const c_ssl.pem_password_cb) void;
pub extern fn SSL_CTX_set_default_read_buffer_len(ctx: *Context, len: usize) void;
pub extern fn SSL_CTX_set_default_verify_dir(ctx: *Context) i32;
pub extern fn SSL_CTX_set_default_verify_file(ctx: *Context) i32;
pub extern fn SSL_CTX_set_default_verify_paths(ctx: *Context) i32;
pub extern fn SSL_CTX_set_default_verify_store(ctx: *Context) i32;
pub extern fn SSL_CTX_set_ex_data(ssl: *Context, idx: i32, data: ?*anyopaque) i32;
pub extern fn SSL_CTX_set_generate_session_id(ctx: *Context, cb: c_ssl.GEN_SESSION_CB) i32;
pub extern fn SSL_CTX_set_info_callback(ctx: *Context, cb: ?*const fn (?*const Ssl, i32, i32) callconv(.c) void) void;
pub extern fn SSL_CTX_set_keylog_callback(ctx: *Context, cb: c_ssl.SSL_CTX_keylog_cb_func) void;
pub extern fn SSL_CTX_set_max_early_data(ctx: *Context, max_early_data: u32) i32;
pub extern fn SSL_CTX_set_msg_callback(
ctx: *Context,
cb: ?*const fn (
i32,
i32,
i32,
?*const anyopaque,
usize,
?*Ssl,
?*anyopaque,
) callconv(.c) void,
) void;
pub extern fn SSL_CTX_set_next_proto_select_cb(s: *Context, cb: c_ssl.SSL_CTX_npn_select_cb_func, arg: ?*anyopaque) void;
pub extern fn SSL_CTX_set_next_protos_advertised_cb(s: *Context, cb: c_ssl.SSL_CTX_npn_advertised_cb_func, arg: ?*anyopaque) void;
pub extern fn SSL_CTX_set_not_resumable_session_callback(ctx: *Context, cb: ?*const fn (?*Ssl, i32) callconv(.c) i32) void;
pub extern fn SSL_CTX_set_num_tickets(ctx: *Context, num_tickets: usize) i32;
pub extern fn SSL_CTX_set_options(ctx: *Context, op: u64) u64;
pub extern fn SSL_CTX_set_post_handshake_auth(ctx: *Context, val: i32) void;
pub extern fn SSL_CTX_set_psk_client_callback(ctx: *Context, cb: c_ssl.SSL_psk_client_cb_func) void;
pub extern fn SSL_CTX_set_psk_find_session_callback(ctx: *Context, cb: c_ssl.SSL_psk_find_session_cb_func) void;
pub extern fn SSL_CTX_set_psk_server_callback(ctx: *Context, cb: c_ssl.SSL_psk_server_cb_func) void;
pub extern fn SSL_CTX_set_psk_use_session_callback(ctx: *Context, cb: c_ssl.SSL_psk_use_session_cb_func) void;
pub extern fn SSL_CTX_set_purpose(ctx: *Context, purpose: i32) i32;
pub extern fn SSL_CTX_set_quiet_shutdown(ctx: *Context, mode: i32) void;
pub extern fn SSL_CTX_set_record_padding_callback_arg(ctx: *Context, arg: ?*anyopaque) void;
pub extern fn SSL_CTX_set_record_padding_callback(ctx: *Context, cb: ?*const fn (?*Ssl, i32, usize, ?*anyopaque) callconv(.c) usize) void;
pub extern fn SSL_CTX_set_recv_max_early_data(ctx: *Context, recv_max_early_data: u32) i32;
pub extern fn SSL_CTX_set_security_callback(
ctx: *Context,
cb: ?*const fn (
?*const Ssl,
*const Context,
i32,
i32,
i32,
?*anyopaque,
?*anyopaque,
) callconv(.c) i32,
) void;
pub extern fn SSL_CTX_set_security_level(ctx: *Context, level: i32) void;
pub extern fn SSL_CTX_set_session_id_context(ctx: *Context, sid_ctx: [*c]const u8, sid_ctx_len: u32) i32;
pub extern fn SSL_CTX_set_session_ticket_cb(
ctx: *Context,
gen_cb: c_ssl.SSL_CTX_generate_session_ticket_fn,
dec_cb: c_ssl.SSL_CTX_decrypt_session_ticket_fn,
arg: ?*anyopaque,
) i32;
pub extern fn SSL_CTX_set_srp_cb_arg(ctx: *Context, arg: ?*anyopaque) i32;
pub extern fn SSL_CTX_set_srp_client_pwd_callback(ctx: *Context, cb: ?*const fn (?*Ssl, ?*anyopaque) callconv(.c) [*c]u8) i32;
pub extern fn SSL_CTX_set_srp_password(ctx: *Context, password: [*c]u8) i32;
pub extern fn SSL_CTX_set_srp_strength(ctx: *Context, strength: i32) i32;
pub extern fn SSL_CTX_set_srp_username_callback(ctx: *Context, cb: ?*const fn (?*Ssl, [*c]i32, ?*anyopaque) callconv(.c) i32) i32;
pub extern fn SSL_CTX_set_srp_username(ctx: *Context, name: [*c]u8) i32;
pub extern fn SSL_CTX_set_srp_verify_param_callback(ctx: *Context, cb: ?*const fn (?*Ssl, ?*anyopaque) callconv(.c) i32) i32;
pub extern fn SSL_CTX_set_ssl_version(ctx: *Context, meth: ?*const Method) i32;
pub extern fn SSL_CTX_set_stateless_cookie_generate_cb(
ctx: *Context,
gen_stateless_cookie_cb: ?*const fn (
?*Ssl,
[*c]u8,
[*c]usize,
) callconv(.c) i32,
) void;
pub extern fn SSL_CTX_set_stateless_cookie_verify_cb(
ctx: *Context,
verify_stateless_cookie_cb: ?*const fn (
?*Ssl,
[*c]const u8,
usize,
) callconv(.c) i32,
) void;
pub extern fn SSL_CTX_set_timeout(ctx: *Context, t: i64) i64;
pub extern fn SSL_CTX_set_tlsext_max_fragment_length(ctx: *Context, mode: u8) i32;
pub extern fn SSL_CTX_set_tlsext_ticket_key_evp_cb(
ctx: *Context,
fp: ?*const fn (
?*Ssl,
[*c]u8,
[*c]u8,
?*c_ssl.EVP_CIPHER_CTX,
?*c_ssl.EVP_MAC_CTX,
i32,
) callconv(.c) i32,
) i32;
pub extern fn SSL_CTX_set_tlsext_use_srtp(ctx: *Context, profiles: [*c]const u8) i32;
pub extern fn SSL_CTX_set_tmp_dh_callback(ctx: *Context, dh: ?*const fn (?*Ssl, i32, i32) callconv(.c) ?*c_ssl.DH) void;
pub extern fn SSL_CTX_set_trust(ctx: *Context, trust: i32) i32;
pub extern fn SSL_CTX_set_verify_depth(ctx: *Context, depth: i32) void;
pub extern fn SSL_CTX_set_verify(ctx: *Context, mode: i32, callback: c_ssl.SSL_verify_cb) void;
pub extern fn SSL_CTX_set0_CA_list(ctx: *Context, name_list: ?*c_ssl.struct_stack_st_X509_NAME) void;
pub extern fn SSL_CTX_set0_ctlog_store(ctx: *Context, logs: ?*c_ssl.CTLOG_STORE) void;
pub extern fn SSL_CTX_set0_security_ex_data(ctx: *Context, ex: ?*anyopaque) void;
pub extern fn SSL_CTX_set0_tmp_dh_pkey(ctx: *Context, dhpkey: ?*c_ssl.EVP_PKEY) i32;
pub extern fn SSL_CTX_set1_cert_store(*Context, ?*c_ssl.X509_STORE) void;
pub extern fn SSL_CTX_set1_param(ctx: *Context, vpm: ?*c_ssl.X509_VERIFY_PARAM) i32;
pub extern fn SSL_CTX_SRP_CTX_free(ctx: *Context) i32;
pub extern fn SSL_CTX_SRP_CTX_init(ctx: *Context) i32;
pub extern fn SSL_CTX_up_ref(ctx: *Context) i32;
pub extern fn SSL_CTX_use_cert_and_key(
ctx: *Context,
x509: ?*c_ssl.X509,
privatekey: ?*c_ssl.EVP_PKEY,
chain: ?*c_ssl.struct_stack_st_X509,
override: i32,
) i32;
pub extern fn SSL_CTX_use_certificate_ASN1(ctx: *Context, len: i32, d: [*c]const u8) i32;
pub extern fn SSL_CTX_use_certificate_chain_file(ctx: *Context, file: [*c]const u8) i32;
pub extern fn SSL_CTX_use_certificate_file(ctx: *Context, file: [*c]const u8, @"type": i32) i32;
pub extern fn SSL_CTX_use_certificate(ctx: *Context, x: ?*c_ssl.X509) i32;
pub extern fn SSL_CTX_use_PrivateKey_ASN1(pk: i32, ctx: *Context, d: [*c]const u8, len: i64) i32;
pub extern fn SSL_CTX_use_PrivateKey_file(ctx: *Context, file: [*c]const u8, @"type": i32) i32;
pub extern fn SSL_CTX_use_PrivateKey(ctx: *Context, pkey: ?*c_ssl.EVP_PKEY) i32;
pub extern fn SSL_CTX_use_psk_identity_hint(ctx: *Context, identity_hint: [*c]const u8) i32;
pub extern fn SSL_CTX_use_RSAPrivateKey_ASN1(ctx: *Context, d: [*c]const u8, len: i64) i32;
pub extern fn SSL_CTX_use_RSAPrivateKey_file(ctx: *Context, file: [*c]const u8, @"type": i32) i32;
pub extern fn SSL_CTX_use_RSAPrivateKey(ctx: *Context, rsa: ?*c_ssl.RSA) i32;
pub extern fn SSL_CTX_use_serverinfo_ex(ctx: *Context, version: u32, serverinfo: [*c]const u8, serverinfo_length: usize) i32;
pub extern fn SSL_CTX_use_serverinfo_file(ctx: *Context, file: [*c]const u8) i32;
pub extern fn SSL_CTX_use_serverinfo(ctx: *Context, serverinfo: [*c]const u8, serverinfo_length: usize) i32;
};

View File

@@ -0,0 +1,111 @@
const std = @import("std");
pub const Method = opaque {
pub inline fn dtlsClientMethod() ?*const Method {
return import.DTLS_client_method();
}
pub inline fn dtlsMethod() ?*const Method {
return import.DTLS_method();
}
pub inline fn dtlsServerMethod() ?*const Method {
return import.DTLS_server_method();
}
pub inline fn dtlsV1_2ClientMethod() ?*const Method {
return import.DTLSv1_2_client_method();
}
pub inline fn dtlsV1_2Method() ?*const Method {
return import.DTLSv1_2_method();
}
pub inline fn dtlsV1_2ServerMethod() ?*const Method {
return import.DTLSv1_2_server_method();
}
pub inline fn dtlsV1ClientMethod() ?*const Method {
return import.DTLSv1_client_method();
}
pub inline fn dtlsV1Method() ?*const Method {
return import.DTLSv1_method();
}
pub inline fn dtlsV1ServerMethod() ?*const Method {
return import.DTLSv1_server_method();
}
pub inline fn tlsClientMethod() ?*const Method {
return import.TLS_client_method();
}
pub inline fn tlsMethod() ?*const Method {
return import.TLS_method();
}
pub inline fn tlsServerMethod() ?*const Method {
return import.TLS_server_method();
}
pub inline fn tlsV1_1ClientMethod() ?*const Method {
return import.TLSv1_1_client_method();
}
pub inline fn tlsV1_1Method() ?*const Method {
return import.TLSv1_1_method();
}
pub inline fn tlsV1_1ServerMethod() ?*const Method {
return import.TLSv1_1_server_method();
}
pub inline fn tlsV1_2ClientMethod() ?*const Method {
return import.TLSv1_2_client_method();
}
pub inline fn tlsV1_2Method() ?*const Method {
return import.TLSv1_2_method();
}
pub inline fn tlsV1_2ServerMethod() ?*const Method {
return import.TLSv1_2_server_method();
}
pub inline fn tlsV1ClientMethod() ?*const Method {
return import.TLSv1_client_method();
}
pub inline fn tlsV1Method() ?*const Method {
return import.TLSv1_method();
}
pub inline fn tlsV1ServerMethod() ?*const Method {
return import.TLSv1_server_method();
}
};
const import = struct {
pub extern fn DTLS_client_method() ?*const Method;
pub extern fn DTLS_method() ?*const Method;
pub extern fn DTLS_server_method() ?*const Method;
pub extern fn DTLSv1_2_client_method() ?*const Method;
pub extern fn DTLSv1_2_method() ?*const Method;
pub extern fn DTLSv1_2_server_method() ?*const Method;
pub extern fn DTLSv1_client_method() ?*const Method;
pub extern fn DTLSv1_method() ?*const Method;
pub extern fn DTLSv1_server_method() ?*const Method;
pub extern fn TLS_client_method() ?*const Method;
pub extern fn TLS_method() ?*const Method;
pub extern fn TLS_server_method() ?*const Method;
pub extern fn TLSv1_1_client_method() ?*const Method;
pub extern fn TLSv1_1_method() ?*const Method;
pub extern fn TLSv1_1_server_method() ?*const Method;
pub extern fn TLSv1_2_client_method() ?*const Method;
pub extern fn TLSv1_2_method() ?*const Method;
pub extern fn TLSv1_2_server_method() ?*const Method;
pub extern fn TLSv1_client_method() ?*const Method;
pub extern fn TLSv1_method() ?*const Method;
pub extern fn TLSv1_server_method() ?*const Method;
};

View File

@@ -0,0 +1,3 @@
const std = @import("std");
pub const Session = opaque {};

View File

@@ -0,0 +1,3 @@
const std = @import("std");
pub const Ssl = opaque {};

File diff suppressed because it is too large Load Diff