rfc2818_verification.hpp 3.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102
  1. //
  2. // ssl/rfc2818_verification.hpp
  3. // ~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  4. //
  5. // Copyright (c) 2003-2015 Christopher M. Kohlhoff (chris at kohlhoff dot com)
  6. //
  7. // Distributed under the Boost Software License, Version 1.0. (See accompanying
  8. // file LICENSE_1_0.txt or copy at http://www.boost.org/LICENSE_1_0.txt)
  9. //
  10. #ifndef BOOST_ASIO_SSL_RFC2818_VERIFICATION_HPP
  11. #define BOOST_ASIO_SSL_RFC2818_VERIFICATION_HPP
  12. #if defined(_MSC_VER) && (_MSC_VER >= 1200)
  13. # pragma once
  14. #endif // defined(_MSC_VER) && (_MSC_VER >= 1200)
  15. #include <boost/asio/detail/config.hpp>
  16. #if !defined(BOOST_ASIO_ENABLE_OLD_SSL)
  17. # include <string>
  18. # include <boost/asio/ssl/detail/openssl_types.hpp>
  19. # include <boost/asio/ssl/verify_context.hpp>
  20. #endif // !defined(BOOST_ASIO_ENABLE_OLD_SSL)
  21. #include <boost/asio/detail/push_options.hpp>
  22. namespace boost {
  23. namespace asio {
  24. namespace ssl {
  25. #if !defined(BOOST_ASIO_ENABLE_OLD_SSL)
  26. /// Verifies a certificate against a hostname according to the rules described
  27. /// in RFC 2818.
  28. /**
  29. * @par Example
  30. * The following example shows how to synchronously open a secure connection to
  31. * a given host name:
  32. * @code
  33. * using boost::asio::ip::tcp;
  34. * namespace ssl = boost::asio::ssl;
  35. * typedef ssl::stream<tcp::socket> ssl_socket;
  36. *
  37. * // Create a context that uses the default paths for finding CA certificates.
  38. * ssl::context ctx(ssl::context::sslv23);
  39. * ctx.set_default_verify_paths();
  40. *
  41. * // Open a socket and connect it to the remote host.
  42. * boost::asio::io_service io_service;
  43. * ssl_socket sock(io_service, ctx);
  44. * tcp::resolver resolver(io_service);
  45. * tcp::resolver::query query("host.name", "https");
  46. * boost::asio::connect(sock.lowest_layer(), resolver.resolve(query));
  47. * sock.lowest_layer().set_option(tcp::no_delay(true));
  48. *
  49. * // Perform SSL handshake and verify the remote host's certificate.
  50. * sock.set_verify_mode(ssl::verify_peer);
  51. * sock.set_verify_callback(ssl::rfc2818_verification("host.name"));
  52. * sock.handshake(ssl_socket::client);
  53. *
  54. * // ... read and write as normal ...
  55. * @endcode
  56. */
  57. class rfc2818_verification
  58. {
  59. public:
  60. /// The type of the function object's result.
  61. typedef bool result_type;
  62. /// Constructor.
  63. explicit rfc2818_verification(const std::string& host)
  64. : host_(host)
  65. {
  66. }
  67. /// Perform certificate verification.
  68. BOOST_ASIO_DECL bool operator()(bool preverified, verify_context& ctx) const;
  69. private:
  70. // Helper function to check a host name against a pattern.
  71. BOOST_ASIO_DECL static bool match_pattern(const char* pattern,
  72. std::size_t pattern_length, const char* host);
  73. // Helper function to check a host name against an IPv4 address
  74. // The host name to be checked.
  75. std::string host_;
  76. };
  77. #endif // defined(BOOST_ASIO_ENABLE_OLD_SSL)
  78. } // namespace ssl
  79. } // namespace asio
  80. } // namespace boost
  81. #include <boost/asio/detail/pop_options.hpp>
  82. #if defined(BOOST_ASIO_HEADER_ONLY)
  83. # include <boost/asio/ssl/impl/rfc2818_verification.ipp>
  84. #endif // defined(BOOST_ASIO_HEADER_ONLY)
  85. #endif // BOOST_ASIO_SSL_RFC2818_VERIFICATION_HPP