Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(280)

Side by Side Diff: rtc_base/opensslidentity.h

Issue 3010363002: Implement GetChain for OpenSSLCertificate.
Patch Set: Adding unit tests and clean up. Created 3 years, 2 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
« no previous file with comments | « rtc_base/BUILD.gn ('k') | rtc_base/opensslidentity.cc » ('j') | no next file with comments »
Toggle Intra-line Diffs ('i') | Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
OLDNEW
1 /* 1 /*
2 * Copyright 2004 The WebRTC Project Authors. All rights reserved. 2 * Copyright 2004 The WebRTC Project Authors. All rights reserved.
3 * 3 *
4 * Use of this source code is governed by a BSD-style license 4 * Use of this source code is governed by a BSD-style license
5 * that can be found in the LICENSE file in the root of the source 5 * that can be found in the LICENSE file in the root of the source
6 * tree. An additional intellectual property rights grant can be found 6 * tree. An additional intellectual property rights grant can be found
7 * in the file PATENTS. All contributing project authors may 7 * in the file PATENTS. All contributing project authors may
8 * be found in the AUTHORS file in the root of the source tree. 8 * be found in the AUTHORS file in the root of the source tree.
9 */ 9 */
10 10
11 #ifndef RTC_BASE_OPENSSLIDENTITY_H_ 11 #ifndef RTC_BASE_OPENSSLIDENTITY_H_
12 #define RTC_BASE_OPENSSLIDENTITY_H_ 12 #define RTC_BASE_OPENSSLIDENTITY_H_
13 13
14 #include <openssl/evp.h> 14 #include <openssl/evp.h>
15 #include <openssl/x509.h> 15 #include <openssl/x509.h>
16 16
17 #include <memory> 17 #include <memory>
18 #include <string> 18 #include <string>
19 #include <vector>
19 20
20 #include "rtc_base/checks.h" 21 #include "rtc_base/checks.h"
21 #include "rtc_base/constructormagic.h" 22 #include "rtc_base/constructormagic.h"
22 #include "rtc_base/sslidentity.h" 23 #include "rtc_base/sslidentity.h"
23 24
24 typedef struct ssl_ctx_st SSL_CTX; 25 typedef struct ssl_ctx_st SSL_CTX;
25 26
26 namespace rtc { 27 namespace rtc {
27 28
28 // OpenSSLKeyPair encapsulates an OpenSSL EVP_PKEY* keypair object, 29 // OpenSSLKeyPair encapsulates an OpenSSL EVP_PKEY* keypair object,
29 // which is reference counted inside the OpenSSL library. 30 // which is reference counted inside the OpenSSL library.
30 class OpenSSLKeyPair { 31 class OpenSSLKeyPair {
31 public: 32 public:
32 explicit OpenSSLKeyPair(EVP_PKEY* pkey) : pkey_(pkey) { 33 explicit OpenSSLKeyPair(EVP_PKEY* pkey) : pkey_(pkey) {
33 RTC_DCHECK(pkey_ != nullptr); 34 RTC_DCHECK(pkey_ != nullptr);
34 } 35 }
35 36
36 static OpenSSLKeyPair* Generate(const KeyParams& key_params); 37 static OpenSSLKeyPair* Generate(const KeyParams& key_params);
37 // Constructs a key pair from the private key PEM string. This must not result 38 // Constructs a key pair from the private key PEM string. This must not result
38 // in missing public key parameters. Returns null on error. 39 // in missing public key parameters. Returns null on error.
39 static OpenSSLKeyPair* FromPrivateKeyPEMString( 40 static OpenSSLKeyPair* FromPrivateKeyPEMString(const std::string& pem_string);
40 const std::string& pem_string);
41 41
42 virtual ~OpenSSLKeyPair(); 42 virtual ~OpenSSLKeyPair();
43 43
44 virtual OpenSSLKeyPair* GetReference(); 44 virtual OpenSSLKeyPair* GetReference();
45 45
46 EVP_PKEY* pkey() const { return pkey_; } 46 EVP_PKEY* pkey() const { return pkey_; }
47 std::string PrivateKeyToPEMString() const; 47 std::string PrivateKeyToPEMString() const;
48 std::string PublicKeyToPEMString() const; 48 std::string PublicKeyToPEMString() const;
49 bool operator==(const OpenSSLKeyPair& other) const; 49 bool operator==(const OpenSSLKeyPair& other) const;
50 bool operator!=(const OpenSSLKeyPair& other) const; 50 bool operator!=(const OpenSSLKeyPair& other) const;
51 51
52 private: 52 private:
53 void AddReference(); 53 void AddReference();
54 54
55 EVP_PKEY* pkey_; 55 EVP_PKEY* pkey_;
56 56
57 RTC_DISALLOW_COPY_AND_ASSIGN(OpenSSLKeyPair); 57 RTC_DISALLOW_COPY_AND_ASSIGN(OpenSSLKeyPair);
58 }; 58 };
59 59
60 // OpenSSLCertificate encapsulates an OpenSSL X509* certificate object, 60 // OpenSSLCertificate encapsulates an OpenSSL X509* certificate object,
61 // which is also reference counted inside the OpenSSL library. 61 // which is also reference counted inside the OpenSSL library.
62 class OpenSSLCertificate : public SSLCertificate { 62 class OpenSSLCertificate : public SSLCertificate {
63 public: 63 public:
64 // Caller retains ownership of the X509 object. 64 // Caller retains ownership of the X509 object.
65 explicit OpenSSLCertificate(X509* x509) : x509_(x509) { 65 explicit OpenSSLCertificate(X509* x509);
66 AddReference(); 66
67 } 67 // Caller retains owership of STACK_OF(X509).
68 explicit OpenSSLCertificate(STACK_OF(X509) * chain);
68 69
69 static OpenSSLCertificate* Generate(OpenSSLKeyPair* key_pair, 70 static OpenSSLCertificate* Generate(OpenSSLKeyPair* key_pair,
70 const SSLIdentityParams& params); 71 const SSLIdentityParams& params);
71 static OpenSSLCertificate* FromPEMString(const std::string& pem_string); 72 static OpenSSLCertificate* FromPEMString(const std::string& pem_string);
72 73
73 ~OpenSSLCertificate() override; 74 ~OpenSSLCertificate() override;
74 75
75 OpenSSLCertificate* GetReference() const override; 76 OpenSSLCertificate* GetReference() const override;
76 77
77 X509* x509() const { return x509_; } 78 X509* x509() const { return x509_; }
79 X509* GetX509Reference() const;
78 80
79 std::string ToPEMString() const override; 81 std::string ToPEMString() const override;
80 void ToDER(Buffer* der_buffer) const override; 82 void ToDER(Buffer* der_buffer) const override;
81 bool operator==(const OpenSSLCertificate& other) const; 83 bool operator==(const OpenSSLCertificate& other) const;
82 bool operator!=(const OpenSSLCertificate& other) const; 84 bool operator!=(const OpenSSLCertificate& other) const;
83 85
84 // Compute the digest of the certificate given algorithm 86 // Compute the digest of the certificate given algorithm
85 bool ComputeDigest(const std::string& algorithm, 87 bool ComputeDigest(const std::string& algorithm,
86 unsigned char* digest, 88 unsigned char* digest,
87 size_t size, 89 size_t size,
88 size_t* length) const override; 90 size_t* length) const override;
89 91
90 // Compute the digest of a certificate as an X509 * 92 // Compute the digest of a certificate as an X509 *
91 static bool ComputeDigest(const X509* x509, 93 static bool ComputeDigest(const X509* x509,
92 const std::string& algorithm, 94 const std::string& algorithm,
93 unsigned char* digest, 95 unsigned char* digest,
94 size_t size, 96 size_t size,
95 size_t* length); 97 size_t* length);
96 98
97 bool GetSignatureDigestAlgorithm(std::string* algorithm) const override; 99 bool GetSignatureDigestAlgorithm(std::string* algorithm) const override;
98 std::unique_ptr<SSLCertChain> GetChain() const override; 100 std::unique_ptr<SSLCertChain> GetChain() const override;
99 101
100 int64_t CertificateExpirationTime() const override; 102 int64_t CertificateExpirationTime() const override;
101 103
102 private: 104 private:
103 void AddReference() const; 105 void AddReference(X509* x509) const;
104 106
105 X509* x509_; 107 X509* x509_;
108 // Non-leaf certificate chain.
109 std::vector<SSLCertificate*> cert_chain_;
106 110
107 RTC_DISALLOW_COPY_AND_ASSIGN(OpenSSLCertificate); 111 RTC_DISALLOW_COPY_AND_ASSIGN(OpenSSLCertificate);
108 }; 112 };
109 113
110 // Holds a keypair and certificate together, and a method to generate 114 // Holds a keypair and certificate together, and a method to generate
111 // them consistently. 115 // them consistently.
112 class OpenSSLIdentity : public SSLIdentity { 116 class OpenSSLIdentity : public SSLIdentity {
113 public: 117 public:
114 static OpenSSLIdentity* GenerateWithExpiration(const std::string& common_name, 118 static OpenSSLIdentity* GenerateWithExpiration(const std::string& common_name,
115 const KeyParams& key_params, 119 const KeyParams& key_params,
(...skipping 18 matching lines...) Expand all
134 OpenSSLIdentity(OpenSSLKeyPair* key_pair, OpenSSLCertificate* certificate); 138 OpenSSLIdentity(OpenSSLKeyPair* key_pair, OpenSSLCertificate* certificate);
135 139
136 static OpenSSLIdentity* GenerateInternal(const SSLIdentityParams& params); 140 static OpenSSLIdentity* GenerateInternal(const SSLIdentityParams& params);
137 141
138 std::unique_ptr<OpenSSLKeyPair> key_pair_; 142 std::unique_ptr<OpenSSLKeyPair> key_pair_;
139 std::unique_ptr<OpenSSLCertificate> certificate_; 143 std::unique_ptr<OpenSSLCertificate> certificate_;
140 144
141 RTC_DISALLOW_COPY_AND_ASSIGN(OpenSSLIdentity); 145 RTC_DISALLOW_COPY_AND_ASSIGN(OpenSSLIdentity);
142 }; 146 };
143 147
144
145 } // namespace rtc 148 } // namespace rtc
146 149
147 #endif // RTC_BASE_OPENSSLIDENTITY_H_ 150 #endif // RTC_BASE_OPENSSLIDENTITY_H_
OLDNEW
« no previous file with comments | « rtc_base/BUILD.gn ('k') | rtc_base/opensslidentity.cc » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698