2007-04-02 18:10:12 -04:00
|
|
|
/*
|
|
|
|
* Copyright (C) 2004-2007 Technorama Ltd. <oss-ruby@technorama.net>
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include "ossl.h"
|
|
|
|
|
|
|
|
VALUE cSSLSession;
|
|
|
|
static VALUE eSSLSession;
|
|
|
|
|
2014-12-12 16:58:25 -05:00
|
|
|
static void
|
|
|
|
ossl_ssl_session_free(void *ptr)
|
|
|
|
{
|
|
|
|
SSL_SESSION_free(ptr);
|
|
|
|
}
|
|
|
|
|
|
|
|
const rb_data_type_t ossl_ssl_session_type = {
|
|
|
|
"OpenSSL/SSL/Session",
|
|
|
|
{
|
|
|
|
0, ossl_ssl_session_free,
|
|
|
|
},
|
|
|
|
0, 0, RUBY_TYPED_FREE_IMMEDIATELY,
|
|
|
|
};
|
|
|
|
|
2007-04-02 18:10:12 -04:00
|
|
|
static VALUE ossl_ssl_session_alloc(VALUE klass)
|
|
|
|
{
|
2014-12-12 16:58:25 -05:00
|
|
|
return TypedData_Wrap_Struct(klass, &ossl_ssl_session_type, NULL);
|
2007-04-02 18:10:12 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* call-seq:
|
2016-08-29 01:47:09 -04:00
|
|
|
* Session.new(ssl_socket) -> Session
|
|
|
|
* Session.new(string) -> Session
|
2007-04-02 18:10:12 -04:00
|
|
|
*
|
2016-08-29 01:47:09 -04:00
|
|
|
* Creates a new Session object from an instance of SSLSocket or DER/PEM encoded
|
|
|
|
* String.
|
|
|
|
*/
|
2007-04-02 18:10:12 -04:00
|
|
|
static VALUE ossl_ssl_session_initialize(VALUE self, VALUE arg1)
|
|
|
|
{
|
|
|
|
SSL_SESSION *ctx = NULL;
|
|
|
|
|
|
|
|
if (RDATA(self)->data)
|
|
|
|
ossl_raise(eSSLSession, "SSL Session already initialized");
|
|
|
|
|
|
|
|
if (rb_obj_is_instance_of(arg1, cSSLSocket)) {
|
|
|
|
SSL *ssl;
|
|
|
|
|
2014-12-12 16:57:33 -05:00
|
|
|
GetSSL(arg1, ssl);
|
2007-04-02 18:10:12 -04:00
|
|
|
|
openssl: move SSLSocket#initialize to C extension
* ext/openssl/lib/openssl/ssl.rb (SSLSocket): Move the implementation of
SSLSocket#initialize to C. Initialize the SSL (OpenSSL object) in it.
Currently this is delayed until ossl_ssl_setup(), which is called from
SSLSocket#accept or #connect. Say we call SSLSocket#hostname= with an
illegal value. We expect an exception to be raised in #hostname= but
actually we get it in the later SSLSocket#connect. Because the SSL is
not ready at #hostname=, the actual call of SSL_set_tlsext_host_name()
is also delayed.
This also fixes: [ruby-dev:49376] [Bug #11724]
* ext/openssl/ossl_ssl.c (ossl_ssl_initialize): Added. Almost the same
as the Ruby version but this instantiate the SSL object at the same
time.
(ossl_ssl_setup): Adjust to the changes. Just set the underlying IO to
the SSL.
(ssl_started): Added. Make use of SSL_get_fd(). This returns -1 if not
yet set by SSL_set_fd().
(ossl_ssl_data_get_struct): Removed. Now GetSSL() checks that the SSL
exists.
(ossl_ssl_set_session): Don't call ossl_ssl_setup() here as now the
SSL is already instantiated in #initialize.
(ossl_ssl_shutdown, ossl_start_ssl, ossl_ssl_read_internal,
ossl_ssl_write_internal, ossl_ssl_stop, ossl_ssl_get_cert,
ossl_ssl_get_peer_cert, ossl_ssl_get_peer_cert_chain,
ossl_ssl_get_version, ossl_ssl_get_cipher, ossl_ssl_get_state,
ossl_ssl_pending, ossl_ssl_session_reused,
ossl_ssl_get_verify_result, ossl_ssl_get_client_ca_list,
ossl_ssl_npn_protocol, ossl_ssl_alpn_protocol, ossl_ssl_tmp_key): Use
GetSSL() instead of ossl_ssl_data_get_struct(). Use ssl_started().
(Init_ossl_ssl): Add method declarations of SSLSocket#{initialize,
hostname=}.
* ext/openssl/ossl_ssl.h (GetSSL): Check that the SSL is not NULL. It
should not be NULL because we now set it in #initialize.
* ext/openssl/ossl_ssl_session.c (ossl_ssl_session_initialize): No need
to check if the SSL is NULL.
git-svn-id: svn+ssh://ci.ruby-lang.org/ruby/trunk@55191 b2dd03c8-39d4-4d8f-98ff-823fe69b080e
2016-05-28 01:00:36 -04:00
|
|
|
if ((ctx = SSL_get1_session(ssl)) == NULL)
|
2007-04-02 18:10:12 -04:00
|
|
|
ossl_raise(eSSLSession, "no session available");
|
|
|
|
} else {
|
|
|
|
BIO *in = ossl_obj2bio(arg1);
|
|
|
|
|
|
|
|
ctx = PEM_read_bio_SSL_SESSION(in, NULL, NULL, NULL);
|
|
|
|
|
|
|
|
if (!ctx) {
|
2011-06-22 04:41:08 -04:00
|
|
|
OSSL_BIO_reset(in);
|
2007-04-02 18:10:12 -04:00
|
|
|
ctx = d2i_SSL_SESSION_bio(in, NULL);
|
|
|
|
}
|
|
|
|
|
|
|
|
BIO_free(in);
|
|
|
|
|
|
|
|
if (!ctx)
|
|
|
|
ossl_raise(rb_eArgError, "unknown type");
|
|
|
|
}
|
|
|
|
|
|
|
|
/* should not happen */
|
|
|
|
if (ctx == NULL)
|
|
|
|
ossl_raise(eSSLSession, "ctx not set - internal error");
|
|
|
|
|
|
|
|
RDATA(self)->data = ctx;
|
|
|
|
|
|
|
|
return self;
|
|
|
|
}
|
|
|
|
|
2016-08-29 01:47:09 -04:00
|
|
|
static VALUE
|
|
|
|
ossl_ssl_session_initialize_copy(VALUE self, VALUE other)
|
|
|
|
{
|
|
|
|
SSL_SESSION *sess, *sess_other, *sess_new;
|
|
|
|
|
|
|
|
rb_check_frozen(self);
|
|
|
|
sess = RTYPEDDATA_DATA(self); /* XXX */
|
|
|
|
SafeGetSSLSession(other, sess_other);
|
|
|
|
|
|
|
|
sess_new = ASN1_dup((i2d_of_void *)i2d_SSL_SESSION, (d2i_of_void *)d2i_SSL_SESSION,
|
|
|
|
(char *)sess_other);
|
|
|
|
if (!sess_new)
|
|
|
|
ossl_raise(eSSLSession, "ASN1_dup");
|
|
|
|
|
|
|
|
RTYPEDDATA_DATA(self) = sess_new;
|
|
|
|
SSL_SESSION_free(sess);
|
|
|
|
|
|
|
|
return self;
|
|
|
|
}
|
|
|
|
|
2010-04-23 04:37:55 -04:00
|
|
|
#if HAVE_SSL_SESSION_CMP == 0
|
2010-04-23 11:16:02 -04:00
|
|
|
int SSL_SESSION_cmp(const SSL_SESSION *a,const SSL_SESSION *b)
|
2010-04-23 04:37:55 -04:00
|
|
|
{
|
2016-06-05 11:35:12 -04:00
|
|
|
unsigned int a_len;
|
|
|
|
const unsigned char *a_sid = SSL_SESSION_get_id(a, &a_len);
|
|
|
|
unsigned int b_len;
|
|
|
|
const unsigned char *b_sid = SSL_SESSION_get_id(b, &b_len);
|
|
|
|
|
|
|
|
#if !defined(HAVE_OPAQUE_OPENSSL) /* missing SSL_SESSION_get_ssl_version() ? */
|
|
|
|
if (a->ssl_version != b->ssl_version)
|
|
|
|
return 1;
|
|
|
|
#endif
|
|
|
|
if (a_len != b_len)
|
2010-04-23 04:37:55 -04:00
|
|
|
return 1;
|
2016-06-05 11:35:12 -04:00
|
|
|
|
2015-01-02 21:50:31 -05:00
|
|
|
#if defined(_WIN32)
|
2016-06-05 11:35:12 -04:00
|
|
|
return memcmp(a_sid, b_sid, a_len);
|
2015-01-02 21:50:31 -05:00
|
|
|
#else
|
2016-06-05 11:35:12 -04:00
|
|
|
return CRYPTO_memcmp(a_sid, b_sid, a_len);
|
2015-01-02 21:50:31 -05:00
|
|
|
#endif
|
2010-04-23 04:37:55 -04:00
|
|
|
}
|
|
|
|
#endif
|
|
|
|
|
2007-04-02 18:10:12 -04:00
|
|
|
/*
|
|
|
|
* call-seq:
|
2016-08-29 01:47:09 -04:00
|
|
|
* session1 == session2 -> boolean
|
2007-04-02 18:10:12 -04:00
|
|
|
*
|
2016-08-29 01:47:09 -04:00
|
|
|
* Returns true if the two Session is the same, false if not.
|
|
|
|
*/
|
2007-04-02 18:10:12 -04:00
|
|
|
static VALUE ossl_ssl_session_eq(VALUE val1, VALUE val2)
|
|
|
|
{
|
|
|
|
SSL_SESSION *ctx1, *ctx2;
|
|
|
|
|
|
|
|
GetSSLSession(val1, ctx1);
|
|
|
|
SafeGetSSLSession(val2, ctx2);
|
|
|
|
|
|
|
|
switch (SSL_SESSION_cmp(ctx1, ctx2)) {
|
|
|
|
case 0: return Qtrue;
|
|
|
|
default: return Qfalse;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* call-seq:
|
|
|
|
* session.time -> Time
|
|
|
|
*
|
2016-08-29 01:47:09 -04:00
|
|
|
* Returns the time at which the session was established.
|
|
|
|
*/
|
2007-04-02 18:10:12 -04:00
|
|
|
static VALUE ossl_ssl_session_get_time(VALUE self)
|
|
|
|
{
|
|
|
|
SSL_SESSION *ctx;
|
|
|
|
time_t t;
|
|
|
|
|
|
|
|
GetSSLSession(self, ctx);
|
|
|
|
|
|
|
|
t = SSL_SESSION_get_time(ctx);
|
|
|
|
|
|
|
|
if (t == 0)
|
|
|
|
return Qnil;
|
|
|
|
|
2009-03-13 03:45:35 -04:00
|
|
|
return rb_funcall(rb_cTime, rb_intern("at"), 1, TIMET2NUM(t));
|
2007-04-02 18:10:12 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* call-seq:
|
2016-08-29 01:47:09 -04:00
|
|
|
* session.timeout -> Integer
|
2007-04-02 18:10:12 -04:00
|
|
|
*
|
2016-08-29 01:47:09 -04:00
|
|
|
* Returns the timeout value set for the session, in seconds from the
|
|
|
|
* established time.
|
2007-04-02 18:10:12 -04:00
|
|
|
*
|
2016-08-29 01:47:09 -04:00
|
|
|
*/
|
2007-04-02 18:10:12 -04:00
|
|
|
static VALUE ossl_ssl_session_get_timeout(VALUE self)
|
|
|
|
{
|
|
|
|
SSL_SESSION *ctx;
|
|
|
|
time_t t;
|
|
|
|
|
|
|
|
GetSSLSession(self, ctx);
|
|
|
|
|
|
|
|
t = SSL_SESSION_get_timeout(ctx);
|
|
|
|
|
2009-03-13 03:45:35 -04:00
|
|
|
return TIMET2NUM(t);
|
2007-04-02 18:10:12 -04:00
|
|
|
}
|
|
|
|
|
2011-06-23 06:36:09 -04:00
|
|
|
/*
|
|
|
|
* call-seq:
|
2016-08-29 01:47:09 -04:00
|
|
|
* session.time = time
|
|
|
|
* session.time = integer
|
2011-06-23 06:36:09 -04:00
|
|
|
*
|
|
|
|
* Sets start time of the session. Time resolution is in seconds.
|
|
|
|
*
|
2016-08-29 01:47:09 -04:00
|
|
|
*/
|
2011-06-23 06:36:09 -04:00
|
|
|
static VALUE ossl_ssl_session_set_time(VALUE self, VALUE time_v)
|
|
|
|
{
|
|
|
|
SSL_SESSION *ctx;
|
|
|
|
long t;
|
|
|
|
|
|
|
|
GetSSLSession(self, ctx);
|
|
|
|
if (rb_obj_is_instance_of(time_v, rb_cTime)) {
|
|
|
|
time_v = rb_funcall(time_v, rb_intern("to_i"), 0);
|
2007-04-02 18:10:12 -04:00
|
|
|
}
|
2011-06-23 06:36:09 -04:00
|
|
|
t = NUM2LONG(time_v);
|
|
|
|
SSL_SESSION_set_time(ctx, t);
|
|
|
|
return ossl_ssl_session_get_time(self);
|
|
|
|
}
|
2007-04-02 18:10:12 -04:00
|
|
|
|
2011-06-23 06:36:09 -04:00
|
|
|
/*
|
|
|
|
* call-seq:
|
2016-08-29 01:47:09 -04:00
|
|
|
* session.timeout = integer
|
2011-06-23 06:36:09 -04:00
|
|
|
*
|
|
|
|
* Sets how long until the session expires in seconds.
|
2016-08-29 01:47:09 -04:00
|
|
|
*/
|
2011-06-23 06:36:09 -04:00
|
|
|
static VALUE ossl_ssl_session_set_timeout(VALUE self, VALUE time_v)
|
|
|
|
{
|
|
|
|
SSL_SESSION *ctx;
|
|
|
|
long t;
|
|
|
|
|
|
|
|
GetSSLSession(self, ctx);
|
|
|
|
t = NUM2LONG(time_v);
|
|
|
|
SSL_SESSION_set_timeout(ctx, t);
|
|
|
|
return ossl_ssl_session_get_timeout(self);
|
|
|
|
}
|
2007-04-02 18:10:12 -04:00
|
|
|
|
|
|
|
/*
|
|
|
|
* call-seq:
|
2016-08-29 01:47:09 -04:00
|
|
|
* session.id -> String
|
2007-04-02 18:10:12 -04:00
|
|
|
*
|
|
|
|
* Returns the Session ID.
|
|
|
|
*/
|
|
|
|
static VALUE ossl_ssl_session_get_id(VALUE self)
|
|
|
|
{
|
|
|
|
SSL_SESSION *ctx;
|
|
|
|
const unsigned char *p = NULL;
|
|
|
|
unsigned int i = 0;
|
|
|
|
|
|
|
|
GetSSLSession(self, ctx);
|
|
|
|
|
|
|
|
p = SSL_SESSION_get_id(ctx, &i);
|
|
|
|
|
2008-02-26 02:07:26 -05:00
|
|
|
return rb_str_new((const char *) p, i);
|
2007-04-02 18:10:12 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* call-seq:
|
2016-08-29 01:47:09 -04:00
|
|
|
* session.to_der -> String
|
2007-04-02 18:10:12 -04:00
|
|
|
*
|
|
|
|
* Returns an ASN1 encoded String that contains the Session object.
|
2016-08-29 01:47:09 -04:00
|
|
|
*/
|
2007-04-02 18:10:12 -04:00
|
|
|
static VALUE ossl_ssl_session_to_der(VALUE self)
|
|
|
|
{
|
|
|
|
SSL_SESSION *ctx;
|
2011-06-21 23:43:38 -04:00
|
|
|
unsigned char *p;
|
2007-04-02 18:10:12 -04:00
|
|
|
int len;
|
2011-06-21 23:43:38 -04:00
|
|
|
VALUE str;
|
2007-04-02 18:10:12 -04:00
|
|
|
|
|
|
|
GetSSLSession(self, ctx);
|
2011-06-21 23:43:38 -04:00
|
|
|
len = i2d_SSL_SESSION(ctx, NULL);
|
|
|
|
if (len <= 0) {
|
2007-04-02 18:10:12 -04:00
|
|
|
ossl_raise(eSSLSession, "i2d_SSL_SESSION");
|
2011-06-21 23:43:38 -04:00
|
|
|
}
|
2007-04-02 18:10:12 -04:00
|
|
|
|
2011-06-21 23:43:38 -04:00
|
|
|
str = rb_str_new(0, len);
|
|
|
|
p = (unsigned char *)RSTRING_PTR(str);
|
|
|
|
i2d_SSL_SESSION(ctx, &p);
|
|
|
|
ossl_str_adjust(str, p);
|
|
|
|
return str;
|
2007-04-02 18:10:12 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* call-seq:
|
|
|
|
* session.to_pem -> String
|
|
|
|
*
|
|
|
|
* Returns a PEM encoded String that contains the Session object.
|
2016-08-29 01:47:09 -04:00
|
|
|
*/
|
2007-04-02 18:10:12 -04:00
|
|
|
static VALUE ossl_ssl_session_to_pem(VALUE self)
|
|
|
|
{
|
|
|
|
SSL_SESSION *ctx;
|
|
|
|
BIO *out;
|
|
|
|
BUF_MEM *buf;
|
|
|
|
VALUE str;
|
|
|
|
int i;
|
2010-04-22 04:04:13 -04:00
|
|
|
|
2007-04-02 18:10:12 -04:00
|
|
|
GetSSLSession(self, ctx);
|
|
|
|
|
|
|
|
if (!(out = BIO_new(BIO_s_mem()))) {
|
|
|
|
ossl_raise(eSSLSession, "BIO_s_mem()");
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!(i=PEM_write_bio_SSL_SESSION(out, ctx))) {
|
|
|
|
BIO_free(out);
|
|
|
|
ossl_raise(eSSLSession, "SSL_SESSION_print()");
|
|
|
|
}
|
|
|
|
|
|
|
|
BIO_get_mem_ptr(out, &buf);
|
|
|
|
str = rb_str_new(buf->data, buf->length);
|
|
|
|
BIO_free(out);
|
|
|
|
|
|
|
|
return str;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
* call-seq:
|
|
|
|
* session.to_text -> String
|
|
|
|
*
|
2016-08-29 01:47:09 -04:00
|
|
|
* Shows everything in the Session object. This is for diagnostic purposes.
|
|
|
|
*/
|
2007-04-02 18:10:12 -04:00
|
|
|
static VALUE ossl_ssl_session_to_text(VALUE self)
|
|
|
|
{
|
|
|
|
SSL_SESSION *ctx;
|
|
|
|
BIO *out;
|
|
|
|
BUF_MEM *buf;
|
|
|
|
VALUE str;
|
2010-04-22 04:04:13 -04:00
|
|
|
|
2007-04-02 18:10:12 -04:00
|
|
|
GetSSLSession(self, ctx);
|
|
|
|
|
|
|
|
if (!(out = BIO_new(BIO_s_mem()))) {
|
|
|
|
ossl_raise(eSSLSession, "BIO_s_mem()");
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!SSL_SESSION_print(out, ctx)) {
|
|
|
|
BIO_free(out);
|
|
|
|
ossl_raise(eSSLSession, "SSL_SESSION_print()");
|
|
|
|
}
|
|
|
|
|
|
|
|
BIO_get_mem_ptr(out, &buf);
|
|
|
|
str = rb_str_new(buf->data, buf->length);
|
|
|
|
BIO_free(out);
|
|
|
|
|
|
|
|
return str;
|
|
|
|
}
|
2010-04-22 04:04:13 -04:00
|
|
|
|
2007-04-02 18:10:12 -04:00
|
|
|
|
|
|
|
void Init_ossl_ssl_session(void)
|
|
|
|
{
|
2010-12-05 19:54:44 -05:00
|
|
|
#if 0
|
2016-08-29 01:47:09 -04:00
|
|
|
mOSSL = rb_define_module("OpenSSL");
|
|
|
|
mSSL = rb_define_module_under(mOSSL, "SSL");
|
|
|
|
eOSSLError = rb_define_class_under(mOSSL, "OpenSSLError", rb_eStandardError);
|
2007-04-02 18:10:12 -04:00
|
|
|
#endif
|
|
|
|
cSSLSession = rb_define_class_under(mSSL, "Session", rb_cObject);
|
|
|
|
eSSLSession = rb_define_class_under(cSSLSession, "SessionError", eOSSLError);
|
|
|
|
|
|
|
|
rb_define_alloc_func(cSSLSession, ossl_ssl_session_alloc);
|
|
|
|
rb_define_method(cSSLSession, "initialize", ossl_ssl_session_initialize, 1);
|
2016-08-29 01:47:09 -04:00
|
|
|
rb_define_copy_func(cSSLSession, ossl_ssl_session_initialize_copy);
|
2007-04-02 18:10:12 -04:00
|
|
|
|
|
|
|
rb_define_method(cSSLSession, "==", ossl_ssl_session_eq, 1);
|
|
|
|
|
|
|
|
rb_define_method(cSSLSession, "time", ossl_ssl_session_get_time, 0);
|
|
|
|
rb_define_method(cSSLSession, "time=", ossl_ssl_session_set_time, 1);
|
|
|
|
rb_define_method(cSSLSession, "timeout", ossl_ssl_session_get_timeout, 0);
|
|
|
|
rb_define_method(cSSLSession, "timeout=", ossl_ssl_session_set_timeout, 1);
|
|
|
|
rb_define_method(cSSLSession, "id", ossl_ssl_session_get_id, 0);
|
|
|
|
rb_define_method(cSSLSession, "to_der", ossl_ssl_session_to_der, 0);
|
|
|
|
rb_define_method(cSSLSession, "to_pem", ossl_ssl_session_to_pem, 0);
|
|
|
|
rb_define_method(cSSLSession, "to_text", ossl_ssl_session_to_text, 0);
|
|
|
|
}
|