xref: /minix3/crypto/external/bsd/openssl/dist/demos/ssl/serv.cpp (revision ebfedea0ce5bbe81e252ddf32d732e40fb633fae)
1*ebfedea0SLionel Sambuc /* serv.cpp  -  Minimal ssleay server for Unix
2*ebfedea0SLionel Sambuc    30.9.1996, Sampo Kellomaki <sampo@iki.fi> */
3*ebfedea0SLionel Sambuc 
4*ebfedea0SLionel Sambuc 
5*ebfedea0SLionel Sambuc /* mangled to work with SSLeay-0.9.0b and OpenSSL 0.9.2b
6*ebfedea0SLionel Sambuc    Simplified to be even more minimal
7*ebfedea0SLionel Sambuc    12/98 - 4/99 Wade Scholine <wades@mail.cybg.com> */
8*ebfedea0SLionel Sambuc 
9*ebfedea0SLionel Sambuc #include <stdio.h>
10*ebfedea0SLionel Sambuc #include <unistd.h>
11*ebfedea0SLionel Sambuc #include <stdlib.h>
12*ebfedea0SLionel Sambuc #include <memory.h>
13*ebfedea0SLionel Sambuc #include <errno.h>
14*ebfedea0SLionel Sambuc #include <sys/types.h>
15*ebfedea0SLionel Sambuc #include <sys/socket.h>
16*ebfedea0SLionel Sambuc #include <netinet/in.h>
17*ebfedea0SLionel Sambuc #include <arpa/inet.h>
18*ebfedea0SLionel Sambuc #include <netdb.h>
19*ebfedea0SLionel Sambuc 
20*ebfedea0SLionel Sambuc #include <openssl/rsa.h>       /* SSLeay stuff */
21*ebfedea0SLionel Sambuc #include <openssl/crypto.h>
22*ebfedea0SLionel Sambuc #include <openssl/x509.h>
23*ebfedea0SLionel Sambuc #include <openssl/pem.h>
24*ebfedea0SLionel Sambuc #include <openssl/ssl.h>
25*ebfedea0SLionel Sambuc #include <openssl/err.h>
26*ebfedea0SLionel Sambuc 
27*ebfedea0SLionel Sambuc 
28*ebfedea0SLionel Sambuc /* define HOME to be dir for key and cert files... */
29*ebfedea0SLionel Sambuc #define HOME "./"
30*ebfedea0SLionel Sambuc /* Make these what you want for cert & key files */
31*ebfedea0SLionel Sambuc #define CERTF  HOME "foo-cert.pem"
32*ebfedea0SLionel Sambuc #define KEYF  HOME  "foo-cert.pem"
33*ebfedea0SLionel Sambuc 
34*ebfedea0SLionel Sambuc 
35*ebfedea0SLionel Sambuc #define CHK_NULL(x) if ((x)==NULL) exit (1)
36*ebfedea0SLionel Sambuc #define CHK_ERR(err,s) if ((err)==-1) { perror(s); exit(1); }
37*ebfedea0SLionel Sambuc #define CHK_SSL(err) if ((err)==-1) { ERR_print_errors_fp(stderr); exit(2); }
38*ebfedea0SLionel Sambuc 
main()39*ebfedea0SLionel Sambuc void main ()
40*ebfedea0SLionel Sambuc {
41*ebfedea0SLionel Sambuc   int err;
42*ebfedea0SLionel Sambuc   int listen_sd;
43*ebfedea0SLionel Sambuc   int sd;
44*ebfedea0SLionel Sambuc   struct sockaddr_in sa_serv;
45*ebfedea0SLionel Sambuc   struct sockaddr_in sa_cli;
46*ebfedea0SLionel Sambuc   size_t client_len;
47*ebfedea0SLionel Sambuc   SSL_CTX* ctx;
48*ebfedea0SLionel Sambuc   SSL*     ssl;
49*ebfedea0SLionel Sambuc   X509*    client_cert;
50*ebfedea0SLionel Sambuc   char*    str;
51*ebfedea0SLionel Sambuc   char     buf [4096];
52*ebfedea0SLionel Sambuc   SSL_METHOD *meth;
53*ebfedea0SLionel Sambuc 
54*ebfedea0SLionel Sambuc   /* SSL preliminaries. We keep the certificate and key with the context. */
55*ebfedea0SLionel Sambuc 
56*ebfedea0SLionel Sambuc   SSL_load_error_strings();
57*ebfedea0SLionel Sambuc   SSLeay_add_ssl_algorithms();
58*ebfedea0SLionel Sambuc   meth = SSLv23_server_method();
59*ebfedea0SLionel Sambuc   ctx = SSL_CTX_new (meth);
60*ebfedea0SLionel Sambuc   if (!ctx) {
61*ebfedea0SLionel Sambuc     ERR_print_errors_fp(stderr);
62*ebfedea0SLionel Sambuc     exit(2);
63*ebfedea0SLionel Sambuc   }
64*ebfedea0SLionel Sambuc 
65*ebfedea0SLionel Sambuc   if (SSL_CTX_use_certificate_file(ctx, CERTF, SSL_FILETYPE_PEM) <= 0) {
66*ebfedea0SLionel Sambuc     ERR_print_errors_fp(stderr);
67*ebfedea0SLionel Sambuc     exit(3);
68*ebfedea0SLionel Sambuc   }
69*ebfedea0SLionel Sambuc   if (SSL_CTX_use_PrivateKey_file(ctx, KEYF, SSL_FILETYPE_PEM) <= 0) {
70*ebfedea0SLionel Sambuc     ERR_print_errors_fp(stderr);
71*ebfedea0SLionel Sambuc     exit(4);
72*ebfedea0SLionel Sambuc   }
73*ebfedea0SLionel Sambuc 
74*ebfedea0SLionel Sambuc   if (!SSL_CTX_check_private_key(ctx)) {
75*ebfedea0SLionel Sambuc     fprintf(stderr,"Private key does not match the certificate public key\n");
76*ebfedea0SLionel Sambuc     exit(5);
77*ebfedea0SLionel Sambuc   }
78*ebfedea0SLionel Sambuc 
79*ebfedea0SLionel Sambuc   /* ----------------------------------------------- */
80*ebfedea0SLionel Sambuc   /* Prepare TCP socket for receiving connections */
81*ebfedea0SLionel Sambuc 
82*ebfedea0SLionel Sambuc   listen_sd = socket (AF_INET, SOCK_STREAM, 0);   CHK_ERR(listen_sd, "socket");
83*ebfedea0SLionel Sambuc 
84*ebfedea0SLionel Sambuc   memset (&sa_serv, '\0', sizeof(sa_serv));
85*ebfedea0SLionel Sambuc   sa_serv.sin_family      = AF_INET;
86*ebfedea0SLionel Sambuc   sa_serv.sin_addr.s_addr = INADDR_ANY;
87*ebfedea0SLionel Sambuc   sa_serv.sin_port        = htons (1111);          /* Server Port number */
88*ebfedea0SLionel Sambuc 
89*ebfedea0SLionel Sambuc   err = bind(listen_sd, (struct sockaddr*) &sa_serv,
90*ebfedea0SLionel Sambuc 	     sizeof (sa_serv));                   CHK_ERR(err, "bind");
91*ebfedea0SLionel Sambuc 
92*ebfedea0SLionel Sambuc   /* Receive a TCP connection. */
93*ebfedea0SLionel Sambuc 
94*ebfedea0SLionel Sambuc   err = listen (listen_sd, 5);                    CHK_ERR(err, "listen");
95*ebfedea0SLionel Sambuc 
96*ebfedea0SLionel Sambuc   client_len = sizeof(sa_cli);
97*ebfedea0SLionel Sambuc   sd = accept (listen_sd, (struct sockaddr*) &sa_cli, &client_len);
98*ebfedea0SLionel Sambuc   CHK_ERR(sd, "accept");
99*ebfedea0SLionel Sambuc   close (listen_sd);
100*ebfedea0SLionel Sambuc 
101*ebfedea0SLionel Sambuc   printf ("Connection from %lx, port %x\n",
102*ebfedea0SLionel Sambuc 	  sa_cli.sin_addr.s_addr, sa_cli.sin_port);
103*ebfedea0SLionel Sambuc 
104*ebfedea0SLionel Sambuc   /* ----------------------------------------------- */
105*ebfedea0SLionel Sambuc   /* TCP connection is ready. Do server side SSL. */
106*ebfedea0SLionel Sambuc 
107*ebfedea0SLionel Sambuc   ssl = SSL_new (ctx);                           CHK_NULL(ssl);
108*ebfedea0SLionel Sambuc   SSL_set_fd (ssl, sd);
109*ebfedea0SLionel Sambuc   err = SSL_accept (ssl);                        CHK_SSL(err);
110*ebfedea0SLionel Sambuc 
111*ebfedea0SLionel Sambuc   /* Get the cipher - opt */
112*ebfedea0SLionel Sambuc 
113*ebfedea0SLionel Sambuc   printf ("SSL connection using %s\n", SSL_get_cipher (ssl));
114*ebfedea0SLionel Sambuc 
115*ebfedea0SLionel Sambuc   /* Get client's certificate (note: beware of dynamic allocation) - opt */
116*ebfedea0SLionel Sambuc 
117*ebfedea0SLionel Sambuc   client_cert = SSL_get_peer_certificate (ssl);
118*ebfedea0SLionel Sambuc   if (client_cert != NULL) {
119*ebfedea0SLionel Sambuc     printf ("Client certificate:\n");
120*ebfedea0SLionel Sambuc 
121*ebfedea0SLionel Sambuc     str = X509_NAME_oneline (X509_get_subject_name (client_cert), 0, 0);
122*ebfedea0SLionel Sambuc     CHK_NULL(str);
123*ebfedea0SLionel Sambuc     printf ("\t subject: %s\n", str);
124*ebfedea0SLionel Sambuc     OPENSSL_free (str);
125*ebfedea0SLionel Sambuc 
126*ebfedea0SLionel Sambuc     str = X509_NAME_oneline (X509_get_issuer_name  (client_cert), 0, 0);
127*ebfedea0SLionel Sambuc     CHK_NULL(str);
128*ebfedea0SLionel Sambuc     printf ("\t issuer: %s\n", str);
129*ebfedea0SLionel Sambuc     OPENSSL_free (str);
130*ebfedea0SLionel Sambuc 
131*ebfedea0SLionel Sambuc     /* We could do all sorts of certificate verification stuff here before
132*ebfedea0SLionel Sambuc        deallocating the certificate. */
133*ebfedea0SLionel Sambuc 
134*ebfedea0SLionel Sambuc     X509_free (client_cert);
135*ebfedea0SLionel Sambuc   } else
136*ebfedea0SLionel Sambuc     printf ("Client does not have certificate.\n");
137*ebfedea0SLionel Sambuc 
138*ebfedea0SLionel Sambuc   /* DATA EXCHANGE - Receive message and send reply. */
139*ebfedea0SLionel Sambuc 
140*ebfedea0SLionel Sambuc   err = SSL_read (ssl, buf, sizeof(buf) - 1);                   CHK_SSL(err);
141*ebfedea0SLionel Sambuc   buf[err] = '\0';
142*ebfedea0SLionel Sambuc   printf ("Got %d chars:'%s'\n", err, buf);
143*ebfedea0SLionel Sambuc 
144*ebfedea0SLionel Sambuc   err = SSL_write (ssl, "I hear you.", strlen("I hear you."));  CHK_SSL(err);
145*ebfedea0SLionel Sambuc 
146*ebfedea0SLionel Sambuc   /* Clean up. */
147*ebfedea0SLionel Sambuc 
148*ebfedea0SLionel Sambuc   close (sd);
149*ebfedea0SLionel Sambuc   SSL_free (ssl);
150*ebfedea0SLionel Sambuc   SSL_CTX_free (ctx);
151*ebfedea0SLionel Sambuc }
152*ebfedea0SLionel Sambuc /* EOF - serv.cpp */
153