/src/freeradius-server/src/lib/tls/base.h
Line | Count | Source |
1 | | #pragma once |
2 | | /* |
3 | | * This program is free software; you can redistribute it and/or modify |
4 | | * it under the terms of the GNU General Public License as published by |
5 | | * the Free Software Foundation; either version 2 of the License, or |
6 | | * (at your option) any later version. |
7 | | * |
8 | | * This program is distributed in the hope that it will be useful, |
9 | | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
10 | | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
11 | | * GNU General Public License for more details. |
12 | | * |
13 | | * You should have received a copy of the GNU General Public License |
14 | | * along with this program; if not, write to the Free Software |
15 | | * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA |
16 | | */ |
17 | | #ifdef WITH_TLS |
18 | | /** |
19 | | * $Id: e997d401c2e23d0aab2dcf070e2274b1e79129bf $ |
20 | | * |
21 | | * @file lib/tls/tls.h |
22 | | * @brief Structures and prototypes for TLS wrappers |
23 | | * |
24 | | * @copyright 2010 Network RADIUS SARL (legal@networkradius.com) |
25 | | * @copyright 2016 The FreeRADIUS project |
26 | | */ |
27 | | RCSIDH(tls_h, "$Id: e997d401c2e23d0aab2dcf070e2274b1e79129bf $") |
28 | | |
29 | | #include "openssl_user_macros.h" |
30 | | |
31 | | #include <freeradius-devel/server/cf_parse.h> |
32 | | #include <freeradius-devel/server/tmpl.h> |
33 | | #include <freeradius-devel/unlang/function.h> |
34 | | |
35 | | #undef HAVE_OPENSSL_OCSP_H |
36 | | |
37 | | #include <openssl/ssl.h> |
38 | | #include <openssl/err.h> |
39 | | |
40 | | #include "cache.h" |
41 | | #include "conf.h" |
42 | | #include "index.h" |
43 | | #include "session.h" |
44 | | |
45 | | #ifdef __cplusplus |
46 | | extern "C" { |
47 | | #endif |
48 | | extern int fr_tls_ex_index_vps; |
49 | | extern int fr_tls_max_threads; |
50 | | |
51 | | /** Drain log messages from an OpenSSL bio and print them using the specified logging macro |
52 | | * |
53 | | * @param _macro Logging macro e.g. RDEBUG. |
54 | | * @param _prefix Prefix, should be "" if not used. |
55 | | * @param _queue OpenSSL BIO. |
56 | | */ |
57 | | #define FR_OPENSSL_DRAIN_LOG_QUEUE(_macro, _prefix, _queue) \ |
58 | | do {\ |
59 | | char const *_p = NULL, *_q, *_end; \ |
60 | | size_t _len; \ |
61 | | _len = BIO_get_mem_data(_queue, &_p); \ |
62 | | _end = _p + _len; \ |
63 | | if (!_p) break; \ |
64 | | while ((_q = memchr(_p, '\n', _end - _p))) { \ |
65 | | _macro(_prefix "%.*s", (int) (_q - _p), _p); \ |
66 | | _p = _q + 1; \ |
67 | | } \ |
68 | | if (_p != _end) _macro(_prefix "%.*s", (int) (_end - _p), _p); \ |
69 | | (void) BIO_reset(_queue); \ |
70 | | } while (0) |
71 | | |
72 | | /** Drain errors from an OpenSSL bio and print print them using the specified logging macro |
73 | | * |
74 | | * @param _macro Logging macro e.g. RDEBUG. |
75 | | * @param _prefix Prefix, should be "" if not used. |
76 | | * @param _queue OpenSSL BIO. |
77 | | */ |
78 | | #define FR_OPENSSL_DRAIN_ERROR_QUEUE(_macro, _prefix, _queue) \ |
79 | | do {\ |
80 | | ERR_print_errors(_queue); \ |
81 | | FR_OPENSSL_DRAIN_LOG_QUEUE(_macro, _prefix, _queue); \ |
82 | | } while (0) |
83 | | |
84 | | extern conf_parser_t fr_tls_server_config[]; |
85 | | extern conf_parser_t fr_tls_client_config[]; |
86 | | |
87 | | /** Holds the temporary context |
88 | | * |
89 | | */ |
90 | | extern _Thread_local TALLOC_CTX *ssl_talloc_ctx; |
91 | | |
92 | | /** Bind any memory allocated by an OpenSSL function to the object it created |
93 | | * |
94 | | * This is a horrible workaround for OpenSSL memory leaks. But should always |
95 | | * work, unless OpenSSL allocates memory for global structures whilst allocating |
96 | | * non-global ones. |
97 | | * |
98 | | * It is technically threadsafe as ssl_talloc_ctx is thread specific. |
99 | | * |
100 | | * This should always work so long as OpenSSL does not become talloc aware and |
101 | | * so will free the allocated object last, after doing manual cleanups. |
102 | | * |
103 | | @code{.c} |
104 | | FR_OPENSSL_BIND_MEMORY(ctx = SSL_CTX_new(TLS_method())); |
105 | | if (!ctx) ..error |
106 | | @endcode |
107 | | * @param _expr The call to the OpenSSL function and storage of the |
108 | | * result. |
109 | | */ |
110 | | #define FR_OPENSSL_BIND_OBJ_MEMORY(_expr) \ |
111 | | do { \ |
112 | | void *_nmem; \ |
113 | | MEM(ssl_talloc_ctx = talloc_init_const(STRINGIFY(_expr))); \ |
114 | | _nmem = (_expr);\ |
115 | | if (!_nmem) { \ |
116 | | TALLOC_FREE(ssl_talloc_ctx); \ |
117 | | } else { \ |
118 | | talloc_steal(_nmem, ssl_talloc_ctx); \ |
119 | | } \ |
120 | | ssl_talloc_ctx = NULL; \ |
121 | | } while (0) |
122 | | |
123 | | /** Bind all memory allocated from this point until the next instance of FR_OPENSSL_BIND_MEMORY_END to _obj |
124 | | * |
125 | | * @param[in] _obj to bind memory to. |
126 | | */ |
127 | | #define FR_OPENSSL_BIND_MEMORY_BEGIN(_obj) \ |
128 | | do { \ |
129 | | if (fr_cond_assert(!ssl_talloc_ctx && (_obj))) { \ |
130 | | MEM(ssl_talloc_ctx = talloc_init_const(STRINGIFY(_obj))); \ |
131 | | talloc_steal(_obj, ssl_talloc_ctx); \ |
132 | | } \ |
133 | | } while(0) |
134 | | |
135 | | #define FR_OPENSSL_BIND_MEMORY_END ssl_talloc_ctx = NULL |
136 | | |
137 | | /* |
138 | | * tls/ctx.c |
139 | | */ |
140 | | |
141 | | /** Return the tls config associated with a SSL_CTX |
142 | | * |
143 | | * @param[in] ssl_ctx to retrieve the configuration from. |
144 | | * @return #fr_tls_conf_t associated with the ctx. |
145 | | */ |
146 | | static inline fr_tls_conf_t *fr_tls_ctx_conf(SSL_CTX *ssl_ctx) |
147 | 0 | { |
148 | | return talloc_get_type_abort(SSL_CTX_get_ex_data(ssl_ctx, FR_TLS_EX_INDEX_CONF), fr_tls_conf_t); |
149 | 0 | } Unexecuted instantiation: base.c:fr_tls_ctx_conf Unexecuted instantiation: cache.c:fr_tls_ctx_conf Unexecuted instantiation: conf.c:fr_tls_ctx_conf Unexecuted instantiation: connection.c:fr_tls_ctx_conf Unexecuted instantiation: pairs.c:fr_tls_ctx_conf Unexecuted instantiation: session.c:fr_tls_ctx_conf Unexecuted instantiation: strerror.c:fr_tls_ctx_conf Unexecuted instantiation: virtual_server.c:fr_tls_ctx_conf |
150 | | |
151 | | SSL_CTX *fr_tls_ctx_alloc(fr_tls_conf_t const *conf, bool client); |
152 | | |
153 | | /* |
154 | | * tls/base.c |
155 | | */ |
156 | | int fr_openssl_thread_init(size_t async_pool_size_init, size_t async_pool_size_max); |
157 | | |
158 | | int fr_openssl_init(void); |
159 | | |
160 | | int fr_openssl_fips_mode(bool enabled); |
161 | | |
162 | | void fr_openssl_free(void); |
163 | | |
164 | | int fr_tls_dict_init(void); |
165 | | |
166 | | void fr_tls_dict_free(void); |
167 | | |
168 | | /* |
169 | | * tls/virtual_server.c |
170 | | */ |
171 | | unlang_action_t fr_tls_call_push(request_t *child, unlang_function_no_result_t resume, |
172 | | fr_tls_conf_t *conf, fr_tls_session_t *tls_session, bool cache_required); |
173 | | |
174 | | #ifdef __cplusplus |
175 | | } |
176 | | #endif |
177 | | #endif /* WITH_TLS */ |