summaryrefslogtreecommitdiffstats
path: root/tdeio/kssl/ksslcertchain.cc
diff options
context:
space:
mode:
authorDarrell Anderson <humanreadable@yahoo.com>2013-03-02 15:57:34 -0600
committerDarrell Anderson <humanreadable@yahoo.com>2013-03-02 15:57:34 -0600
commit7c0b0c9dc9fcbe9c198925bdc7ee18ac6be49f4f (patch)
treec76702a7f6310fbe9d437e347535422e836e94e9 /tdeio/kssl/ksslcertchain.cc
parenta2a38be7600e2a2c2b49c66902d912ca036a2c0f (diff)
parent27bbee9a5f9dcda53d8eb23863ee670ad1360e41 (diff)
downloadtdelibs-7c0b0c9dc9fcbe9c198925bdc7ee18ac6be49f4f.tar.gz
tdelibs-7c0b0c9dc9fcbe9c198925bdc7ee18ac6be49f4f.zip
Merge branch 'master' of http://scm.trinitydesktop.org/scm/git/tdelibs
Diffstat (limited to 'tdeio/kssl/ksslcertchain.cc')
-rw-r--r--tdeio/kssl/ksslcertchain.cc216
1 files changed, 216 insertions, 0 deletions
diff --git a/tdeio/kssl/ksslcertchain.cc b/tdeio/kssl/ksslcertchain.cc
new file mode 100644
index 000000000..a401aec3d
--- /dev/null
+++ b/tdeio/kssl/ksslcertchain.cc
@@ -0,0 +1,216 @@
+/* This file is part of the KDE project
+ *
+ * Copyright (C) 2001 George Staikos <staikos@kde.org>
+ *
+ * This library is free software; you can redistribute it and/or
+ * modify it under the terms of the GNU Library General Public
+ * License as published by the Free Software Foundation; either
+ * version 2 of the License, or (at your option) any later version.
+ *
+ * This library is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+ * Library General Public License for more details.
+ *
+ * You should have received a copy of the GNU Library General Public License
+ * along with this library; see the file COPYING.LIB. If not, write to
+ * the Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,
+ * Boston, MA 02110-1301, USA.
+ */
+#ifdef HAVE_CONFIG_H
+#include <config.h>
+#endif
+
+#include "kssldefs.h"
+#include "ksslcertificate.h"
+#include "ksslcertchain.h"
+
+// this hack provided by Malte Starostik to avoid glibc/openssl bug
+// on some systems
+#ifdef KSSL_HAVE_SSL
+#define crypt _openssl_crypt
+#include <openssl/ssl.h>
+#include <openssl/x509.h>
+#include <openssl/x509v3.h>
+#include <openssl/x509_vfy.h>
+#include <openssl/pem.h>
+#include <openssl/stack.h>
+#include <openssl/safestack.h>
+#undef crypt
+#endif
+
+#include <kopenssl.h>
+#include <kdebug.h>
+#include <tqstringlist.h>
+
+
+
+#ifdef KSSL_HAVE_SSL
+#define sk_new d->kossl->sk_new
+#define sk_push d->kossl->sk_push
+#define sk_free d->kossl->sk_free
+#define sk_value d->kossl->sk_value
+#define sk_num d->kossl->sk_num
+#define sk_dup d->kossl->sk_dup
+#define sk_pop d->kossl->sk_pop
+#endif
+
+class KSSLCertChainPrivate {
+public:
+ KSSLCertChainPrivate() {
+ kossl = KOSSL::self();
+ }
+
+ ~KSSLCertChainPrivate() {
+ }
+
+ KOSSL *kossl;
+};
+
+KSSLCertChain::KSSLCertChain() {
+ d = new KSSLCertChainPrivate;
+ _chain = NULL;
+}
+
+
+KSSLCertChain::~KSSLCertChain() {
+#ifdef KSSL_HAVE_SSL
+ if (_chain) {
+ STACK_OF(X509) *x = (STACK_OF(X509) *)_chain;
+
+ for (;;) {
+ X509* x5 = sk_X509_pop(x);
+ if (!x5) break;
+ d->kossl->X509_free(x5);
+ }
+ sk_X509_free(x);
+ }
+#endif
+ delete d;
+}
+
+
+bool KSSLCertChain::isValid() {
+ return (_chain && depth() > 0);
+}
+
+
+KSSLCertChain *KSSLCertChain::replicate() {
+KSSLCertChain *x = new KSSLCertChain;
+TQPtrList<KSSLCertificate> ch = getChain();
+
+ x->setChain(ch); // this will do a deep copy for us
+ ch.setAutoDelete(true);
+return x;
+}
+
+
+int KSSLCertChain::depth() {
+#ifdef KSSL_HAVE_SSL
+ return sk_X509_num((STACK_OF(X509)*)_chain);
+#endif
+return 0;
+}
+
+
+TQPtrList<KSSLCertificate> KSSLCertChain::getChain() {
+TQPtrList<KSSLCertificate> cl;
+if (!_chain) return cl;
+#ifdef KSSL_HAVE_SSL
+STACK_OF(X509) *x = (STACK_OF(X509) *)_chain;
+
+ for (int i = 0; i < sk_X509_num(x); i++) {
+ X509* x5 = sk_X509_value(x, i);
+ if (!x5) continue;
+ KSSLCertificate *nc = new KSSLCertificate;
+ nc->setCert(d->kossl->X509_dup(x5));
+ cl.append(nc);
+ }
+
+#endif
+return cl;
+}
+
+
+void KSSLCertChain::setChain(TQPtrList<KSSLCertificate>& chain) {
+#ifdef KSSL_HAVE_SSL
+if (_chain) {
+ STACK_OF(X509) *x = (STACK_OF(X509) *)_chain;
+
+ for (;;) {
+ X509* x5 = sk_X509_pop(x);
+ if (!x5) break;
+ d->kossl->X509_free(x5);
+ }
+ sk_X509_free(x);
+ _chain = NULL;
+}
+
+ if (chain.count() == 0) return;
+ _chain = (void *)sk_new(NULL);
+ for (KSSLCertificate *x = chain.first(); x != 0; x = chain.next()) {
+ sk_X509_push((STACK_OF(X509)*)_chain, d->kossl->X509_dup(x->getCert()));
+ }
+
+#endif
+}
+
+
+void KSSLCertChain::setChain(void *stack_of_x509) {
+#ifdef KSSL_HAVE_SSL
+if (_chain) {
+ STACK_OF(X509) *x = (STACK_OF(X509) *)_chain;
+
+ for (;;) {
+ X509* x5 = sk_X509_pop(x);
+ if (!x5) break;
+ d->kossl->X509_free(x5);
+ }
+ sk_X509_free(x);
+ _chain = NULL;
+}
+
+if (!stack_of_x509) return;
+
+_chain = (void *)sk_new(NULL);
+STACK_OF(X509) *x = (STACK_OF(X509) *)stack_of_x509;
+
+ for (int i = 0; i < sk_X509_num(x); i++) {
+ X509* x5 = sk_X509_value(x, i);
+ if (!x5) continue;
+ sk_X509_push((STACK_OF(X509)*)_chain,d->kossl->X509_dup(x5));
+ }
+
+#else
+_chain = NULL;
+#endif
+}
+
+
+void KSSLCertChain::setChain(TQStringList chain) {
+ setCertChain(chain);
+}
+
+void KSSLCertChain::setCertChain(const TQStringList& chain) {
+ TQPtrList<KSSLCertificate> cl;
+ cl.setAutoDelete(true);
+ for (TQStringList::ConstIterator s = chain.begin(); s != chain.end(); ++s) {
+ KSSLCertificate *c = KSSLCertificate::fromString((*s).local8Bit());
+ if (c) {
+ cl.append(c);
+ }
+ }
+ setChain(cl);
+}
+
+
+#ifdef KSSL_HAVE_SSL
+#undef sk_new
+#undef sk_push
+#undef sk_free
+#undef sk_value
+#undef sk_num
+#undef sk_dup
+#undef sk_pop
+#endif
+