| OLD | NEW |
| 1 /* | 1 /* |
| 2 * Copyright 2004 The WebRTC Project Authors. All rights reserved. | 2 * Copyright 2004 The WebRTC Project Authors. All rights reserved. |
| 3 * | 3 * |
| 4 * Use of this source code is governed by a BSD-style license | 4 * Use of this source code is governed by a BSD-style license |
| 5 * that can be found in the LICENSE file in the root of the source | 5 * that can be found in the LICENSE file in the root of the source |
| 6 * tree. An additional intellectual property rights grant can be found | 6 * tree. An additional intellectual property rights grant can be found |
| 7 * in the file PATENTS. All contributing project authors may | 7 * in the file PATENTS. All contributing project authors may |
| 8 * be found in the AUTHORS file in the root of the source tree. | 8 * be found in the AUTHORS file in the root of the source tree. |
| 9 */ | 9 */ |
| 10 | 10 |
| 11 // Handling of certificates and keypairs for SSLStreamAdapter's peer mode. | 11 // Handling of certificates and keypairs for SSLStreamAdapter's peer mode. |
| 12 | 12 |
| 13 #ifndef WEBRTC_BASE_SSLIDENTITY_H_ | 13 #ifndef WEBRTC_BASE_SSLIDENTITY_H_ |
| 14 #define WEBRTC_BASE_SSLIDENTITY_H_ | 14 #define WEBRTC_BASE_SSLIDENTITY_H_ |
| 15 | 15 |
| 16 #include <algorithm> | 16 #include <algorithm> |
| 17 #include <string> | 17 #include <string> |
| 18 #include <vector> | 18 #include <vector> |
| 19 | 19 |
| 20 #include "webrtc/base/buffer.h" | 20 #include "webrtc/base/buffer.h" |
| 21 #include "webrtc/base/messagedigest.h" | 21 #include "webrtc/base/messagedigest.h" |
| 22 #include "webrtc/base/timeutils.h" |
| 22 | 23 |
| 23 namespace rtc { | 24 namespace rtc { |
| 24 | 25 |
| 25 // Forward declaration due to circular dependency with SSLCertificate. | 26 // Forward declaration due to circular dependency with SSLCertificate. |
| 26 class SSLCertChain; | 27 class SSLCertChain; |
| 27 | 28 |
| 28 // Abstract interface overridden by SSL library specific | 29 // Abstract interface overridden by SSL library specific |
| 29 // implementations. | 30 // implementations. |
| 30 | 31 |
| 31 // A somewhat opaque type used to encapsulate a certificate. | 32 // A somewhat opaque type used to encapsulate a certificate. |
| (...skipping 29 matching lines...) Expand all Loading... |
| 61 | 62 |
| 62 // Gets the name of the digest algorithm that was used to compute this | 63 // Gets the name of the digest algorithm that was used to compute this |
| 63 // certificate's signature. | 64 // certificate's signature. |
| 64 virtual bool GetSignatureDigestAlgorithm(std::string* algorithm) const = 0; | 65 virtual bool GetSignatureDigestAlgorithm(std::string* algorithm) const = 0; |
| 65 | 66 |
| 66 // Compute the digest of the certificate given algorithm | 67 // Compute the digest of the certificate given algorithm |
| 67 virtual bool ComputeDigest(const std::string& algorithm, | 68 virtual bool ComputeDigest(const std::string& algorithm, |
| 68 unsigned char* digest, | 69 unsigned char* digest, |
| 69 size_t size, | 70 size_t size, |
| 70 size_t* length) const = 0; | 71 size_t* length) const = 0; |
| 72 |
| 73 // Returns the time in seconds relative to epoch. |
| 74 virtual int64_t CertificateExpirationTime() const = 0; |
| 71 }; | 75 }; |
| 72 | 76 |
| 73 // SSLCertChain is a simple wrapper for a vector of SSLCertificates. It serves | 77 // SSLCertChain is a simple wrapper for a vector of SSLCertificates. It serves |
| 74 // primarily to ensure proper memory management (especially deletion) of the | 78 // primarily to ensure proper memory management (especially deletion) of the |
| 75 // SSLCertificate pointers. | 79 // SSLCertificate pointers. |
| 76 class SSLCertChain { | 80 class SSLCertChain { |
| 77 public: | 81 public: |
| 78 // These constructors copy the provided SSLCertificate(s), so the caller | 82 // These constructors copy the provided SSLCertificate(s), so the caller |
| 79 // retains ownership. | 83 // retains ownership. |
| 80 explicit SSLCertChain(const std::vector<SSLCertificate*>& certs); | 84 explicit SSLCertChain(const std::vector<SSLCertificate*>& certs); |
| (...skipping 80 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
| 161 // TODO(hbos): Remove once rtc::KeyType (to be modified) and | 165 // TODO(hbos): Remove once rtc::KeyType (to be modified) and |
| 162 // blink::WebRTCKeyType (to be landed) match. By using this function in Chromium | 166 // blink::WebRTCKeyType (to be landed) match. By using this function in Chromium |
| 163 // appropriately we can change KeyType enum -> class without breaking Chromium. | 167 // appropriately we can change KeyType enum -> class without breaking Chromium. |
| 164 KeyType IntKeyTypeFamilyToKeyType(int key_type_family); | 168 KeyType IntKeyTypeFamilyToKeyType(int key_type_family); |
| 165 | 169 |
| 166 // Parameters for generating a certificate. If |common_name| is non-empty, it | 170 // Parameters for generating a certificate. If |common_name| is non-empty, it |
| 167 // will be used for the certificate's subject and issuer name, otherwise a | 171 // will be used for the certificate's subject and issuer name, otherwise a |
| 168 // random string will be used. | 172 // random string will be used. |
| 169 struct SSLIdentityParams { | 173 struct SSLIdentityParams { |
| 170 std::string common_name; | 174 std::string common_name; |
| 171 int not_before; // offset from current time in seconds. | 175 time_t not_before; // Absolute time since epoch in seconds. |
| 172 int not_after; // offset from current time in seconds. | 176 time_t not_after; // Absolute time since epoch in seconds. |
| 173 KeyParams key_params; | 177 KeyParams key_params; |
| 174 }; | 178 }; |
| 175 | 179 |
| 176 // Our identity in an SSL negotiation: a keypair and certificate (both | 180 // Our identity in an SSL negotiation: a keypair and certificate (both |
| 177 // with the same public key). | 181 // with the same public key). |
| 178 // This too is pretty much immutable once created. | 182 // This too is pretty much immutable once created. |
| 179 class SSLIdentity { | 183 class SSLIdentity { |
| 180 public: | 184 public: |
| 181 // Generates an identity (keypair and self-signed certificate). If | 185 // Generates an identity (keypair and self-signed certificate). If |
| 182 // common_name is non-empty, it will be used for the certificate's | 186 // common_name is non-empty, it will be used for the certificate's |
| (...skipping 27 matching lines...) Expand all Loading... |
| 210 | 214 |
| 211 // Helpers for parsing converting between PEM and DER format. | 215 // Helpers for parsing converting between PEM and DER format. |
| 212 static bool PemToDer(const std::string& pem_type, | 216 static bool PemToDer(const std::string& pem_type, |
| 213 const std::string& pem_string, | 217 const std::string& pem_string, |
| 214 std::string* der); | 218 std::string* der); |
| 215 static std::string DerToPem(const std::string& pem_type, | 219 static std::string DerToPem(const std::string& pem_type, |
| 216 const unsigned char* data, | 220 const unsigned char* data, |
| 217 size_t length); | 221 size_t length); |
| 218 }; | 222 }; |
| 219 | 223 |
| 224 // Convert from ASN1 time as restricted by RFC 5280 to seconds from 1970-01-01 |
| 225 // 00.00 ("epoch"). If the ASN1 time cannot be read, return -1. The data at |
| 226 // |s| is not 0-terminated; its char count is defined by |length|. |
| 227 int64_t ASN1TimeToSec(const unsigned char* s, size_t length, bool long_format); |
| 228 |
| 220 extern const char kPemTypeCertificate[]; | 229 extern const char kPemTypeCertificate[]; |
| 221 extern const char kPemTypeRsaPrivateKey[]; | 230 extern const char kPemTypeRsaPrivateKey[]; |
| 222 extern const char kPemTypeEcPrivateKey[]; | 231 extern const char kPemTypeEcPrivateKey[]; |
| 223 | 232 |
| 224 } // namespace rtc | 233 } // namespace rtc |
| 225 | 234 |
| 226 #endif // WEBRTC_BASE_SSLIDENTITY_H_ | 235 #endif // WEBRTC_BASE_SSLIDENTITY_H_ |
| OLD | NEW |