tls: Support a null encryption flag on TLS socket abstraction

This commit is contained in:
Martin Willi
2014-04-01 14:28:55 +02:00
parent ddf5222096
commit 5313880261
5 changed files with 21 additions and 7 deletions
@@ -876,7 +876,8 @@ static bool soap_init(private_tnc_ifmap_soap_t *this)
} }
/* open TLS socket */ /* open TLS socket */
this->tls = tls_socket_create(FALSE, server_id, client_id, this->fd, NULL); this->tls = tls_socket_create(FALSE, server_id, client_id, this->fd,
NULL, FALSE);
if (!this->tls) if (!this->tls)
{ {
DBG1(DBG_TNC, "creating TLS socket failed"); DBG1(DBG_TNC, "creating TLS socket failed");
@@ -923,4 +924,3 @@ tnc_ifmap_soap_t *tnc_ifmap_soap_create()
return &this->public; return &this->public;
} }
+2 -1
View File
@@ -84,7 +84,8 @@ static bool make_connection(private_pt_tls_client_t *this)
return FALSE; return FALSE;
} }
this->tls = tls_socket_create(FALSE, this->server, this->client, fd, NULL); this->tls = tls_socket_create(FALSE, this->server, this->client, fd,
NULL, FALSE);
if (!this->tls) if (!this->tls)
{ {
close(fd); close(fd);
+1 -1
View File
@@ -532,7 +532,7 @@ pt_tls_server_t *pt_tls_server_create(identification_t *server, int fd,
.destroy = _destroy, .destroy = _destroy,
}, },
.state = PT_TLS_SERVER_VERSION, .state = PT_TLS_SERVER_VERSION,
.tls = tls_socket_create(TRUE, server, NULL, fd, NULL), .tls = tls_socket_create(TRUE, server, NULL, fd, NULL, FALSE),
.tnccs = (tls_t*)tnccs, .tnccs = (tls_t*)tnccs,
.auth = auth, .auth = auth,
); );
+13 -2
View File
@@ -406,9 +406,11 @@ METHOD(tls_socket_t, destroy, void,
* See header * See header
*/ */
tls_socket_t *tls_socket_create(bool is_server, identification_t *server, tls_socket_t *tls_socket_create(bool is_server, identification_t *server,
identification_t *peer, int fd, tls_cache_t *cache) identification_t *peer, int fd, tls_cache_t *cache,
bool nullok)
{ {
private_tls_socket_t *this; private_tls_socket_t *this;
tls_purpose_t purpose;
INIT(this, INIT(this,
.public = { .public = {
@@ -430,7 +432,16 @@ tls_socket_t *tls_socket_create(bool is_server, identification_t *server,
.fd = fd, .fd = fd,
); );
this->tls = tls_create(is_server, server, peer, TLS_PURPOSE_GENERIC, if (nullok)
{
purpose = TLS_PURPOSE_GENERIC_NULLOK;
}
else
{
purpose = TLS_PURPOSE_GENERIC;
}
this->tls = tls_create(is_server, server, peer, purpose,
&this->app.application, cache); &this->app.application, cache);
if (!this->tls) if (!this->tls)
{ {
+3 -1
View File
@@ -104,9 +104,11 @@ struct tls_socket_t {
* @param peer client identity, NULL for no client authentication * @param peer client identity, NULL for no client authentication
* @param fd socket to read/write from * @param fd socket to read/write from
* @param cache session cache to use, or NULL * @param cache session cache to use, or NULL
* @param nullok accept NULL encryption ciphers
* @return TLS socket wrapper * @return TLS socket wrapper
*/ */
tls_socket_t *tls_socket_create(bool is_server, identification_t *server, tls_socket_t *tls_socket_create(bool is_server, identification_t *server,
identification_t *peer, int fd, tls_cache_t *cache); identification_t *peer, int fd, tls_cache_t *cache,
bool nullok);
#endif /** TLS_SOCKET_H_ @}*/ #endif /** TLS_SOCKET_H_ @}*/