web: The beginnings of TLS

This commit is contained in:
2026-03-08 22:08:25 +01:00
parent e09a00a4ba
commit 1f07cc38ba
10 changed files with 1136 additions and 321 deletions

View File

@@ -3,6 +3,7 @@ const web = @import("web");
const linux = std.os.linux;
const errno = linux.E.init;
const ssl = web.openssl;
const UUID = web.UUID;
var running: std.atomic.Value(bool) = .init(true);
@@ -134,6 +135,20 @@ pub fn main() !void {
var router: Router = .init(allocator);
_ = ssl.c_ssl.SSL_library_init();
_ = ssl.c_ssl.OpenSSL_add_all_algorithms();
_ = ssl.c_ssl.SSL_load_error_strings();
const ssl_ctx = try ssl.Context.new(ssl.Method.tlsServerMethod());
defer ssl_ctx.free();
_ = ssl_ctx.setMinProtoVersion(ssl.c_ssl.TLS1_3_VERSION);
_ = ssl_ctx.setOptions(ssl.c_ssl.SSL_OP_NO_SSLv3 | ssl.c_ssl.SSL_OP_NO_TLSv1 | ssl.c_ssl.SSL_OP_NO_TLSv1_1 | ssl.c_ssl.SSL_OP_NO_TLSv1_2);
try ssl_ctx.useCertificateFile("cert.pem", ssl.c_ssl.SSL_FILETYPE_PEM);
try ssl_ctx.usePrivateKeyFile("key.pem", ssl.c_ssl.SSL_FILETYPE_PEM);
try ssl_ctx.checkPrivateKey();
var server = try web.Server.init(allocator, .{
.request_router = router.interface(),
.address = .initIp4(.{ 127, 0, 0, 1 }, 8000),