MCPcopy Create free account
hub / github.com/apache/qpid-proton / init_ssl_socket

Function init_ssl_socket

c/src/ssl/openssl.c:1424–1475  ·  view source on GitHub ↗

Source from the content-addressed store, hash-verified

1422}
1423
1424static int init_ssl_socket(pn_transport_t* transport, pni_ssl_t *ssl, pn_ssl_domain_t *domain)
1425{
1426 if (ssl->ssl) return 0;
1427 if (!domain) return -1;
1428
1429 ssl->ssl = SSL_new(domain->ctx);
1430 if (!ssl->ssl) {
1431 ssl_log(transport, PN_LEVEL_ERROR, "SSL socket setup failure." );
1432 ssl_log_flush(transport, PN_LEVEL_ERROR);
1433 return -1;
1434 }
1435
1436 // store backpointer to pn_transport_t in SSL object:
1437 SSL_set_ex_data(ssl->ssl, ssl_ex_data_index, transport);
1438
1439#ifdef SSL_CTRL_SET_TLSEXT_HOSTNAME
1440 if (ssl->peer_hostname && ssl->mode == PN_SSL_MODE_CLIENT) {
1441 SSL_set_tlsext_host_name(ssl->ssl, ssl->peer_hostname);
1442 }
1443#endif
1444
1445 // restore session, if available
1446 ssn_restore(transport, ssl);
1447
1448 // now layer a BIO over the SSL socket
1449 ssl->bio_ssl = BIO_new(BIO_f_ssl());
1450 if (!ssl->bio_ssl) {
1451 ssl_log(transport, PN_LEVEL_ERROR, "BIO setup failure." );
1452 return -1;
1453 }
1454 (void)BIO_set_ssl(ssl->bio_ssl, ssl->ssl, BIO_NOCLOSE);
1455
1456 // create the "lower" BIO "pipe", and attach it below the SSL layer
1457 if (!BIO_new_bio_pair(&ssl->bio_ssl_io, 0, &ssl->bio_net_io, 0)) {
1458 ssl_log(transport, PN_LEVEL_ERROR, "BIO setup failure." );
1459 return -1;
1460 }
1461 SSL_set_bio(ssl->ssl, ssl->bio_ssl_io, ssl->bio_ssl_io);
1462
1463 if (ssl->mode == PN_SSL_MODE_SERVER) {
1464 SSL_set_accept_state(ssl->ssl);
1465 BIO_set_ssl_mode(ssl->bio_ssl, 0); // server mode
1466 ssl_log( transport, PN_LEVEL_TRACE, "Server SSL socket created." );
1467 } else { // client mode
1468 SSL_set_connect_state(ssl->ssl);
1469 BIO_set_ssl_mode(ssl->bio_ssl, 1); // client mode
1470 ssl_log( transport, PN_LEVEL_TRACE, "Client SSL socket created." );
1471 }
1472 ssl->subject = NULL;
1473 ssl->peer_certificate = NULL;
1474 return 0;
1475}
1476
1477static void release_ssl_socket(pni_ssl_t *ssl)
1478{

Callers 3

pn_ssl_initFunction · 0.70
process_input_sslFunction · 0.70
process_output_sslFunction · 0.70

Calls 3

ssl_logFunction · 0.70
ssl_log_flushFunction · 0.70
ssn_restoreFunction · 0.70

Tested by

no test coverage detected