Commit 74096890 authored by Dr. Stephen Henson's avatar Dr. Stephen Henson
Browse files

Initial "opaque SSL" framework. If an application defines OPENSSL_NO_SSL_INTERN

all ssl related structures are opaque and internals cannot be directly
accessed. Many applications will need some modification to support this and
most likely some additional functions added to OpenSSL.

The advantage of this option is that any application supporting it will still
be binary compatible if SSL structures change.

(backport from HEAD).
parent 889c2282
Loading
Loading
Loading
Loading
+6 −0
Changes for CHANGES: 6 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -4,6 +4,12 @@

 Changes between 1.0.0d and 1.0.1  [xx XXX xxxx]
 
  *) New option OPENSSL_NO_SSL_INTERN. If an application can be compiled
     with this defined it will not be affected by any changes to ssl internal
     structures. Add several utility functions to allow openssl application
     to work with OPENSSL_NO_SSL_INTERN defined.
     [Steve Henson]

  *) Add SRP support.
     [Tom Wu <tjw@cs.stanford.edu> and Ben Laurie]

+3 −0
Changes for apps/apps.h: 3 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -357,4 +357,7 @@ int raw_write_stdout(const void *,int);
#define TM_START	0
#define TM_STOP		1
double app_tminterval (int stop,int usertime);

#define OPENSSL_NO_SSL_INTERN

#endif
+1 −1
Changes for apps/ciphers.c: 1 added line, 1 removed line.
Original line number Diff line number Diff line
@@ -196,7 +196,7 @@ int MAIN(int argc, char **argv)
			
			if (Verbose)
				{
				unsigned long id = c->id;
				unsigned long id = SSL_CIPHER_get_id(c);
				int id0 = (int)(id >> 24);
				int id1 = (int)((id >> 16) & 0xffL);
				int id2 = (int)((id >> 8) & 0xffL);
+3 −3
Changes for apps/s_client.c: 3 added lines, 3 removed lines.
Original line number Diff line number Diff line
@@ -1171,7 +1171,7 @@ re_start:
			}
		}
#endif                                              
	if (c_Pause & 0x01) con->debug=1;
	if (c_Pause & 0x01) SSL_set_debug(con, 1);

	if ( SSL_version(con) == DTLS1_VERSION)
		{
@@ -1220,7 +1220,7 @@ re_start:

	if (c_debug)
		{
		con->debug=1;
		SSL_set_debug(con, 1);
		BIO_set_callback(sbio,bio_dump_callback);
		BIO_set_callback_arg(sbio,(char *)bio_c_out);
		}
@@ -1905,7 +1905,7 @@ static void print_stuff(BIO *bio, SSL *s, int full)
			BIO_number_read(SSL_get_rbio(s)),
			BIO_number_written(SSL_get_wbio(s)));
		}
	BIO_printf(bio,((s->hit)?"---\nReused, ":"---\nNew, "));
	BIO_printf(bio,(SSL_cache_hit(s)?"---\nReused, ":"---\nNew, "));
	c=SSL_get_current_cipher(s);
	BIO_printf(bio,"%s, Cipher is %s\n",
		SSL_CIPHER_get_version(c),
+4 −4
Changes for apps/s_server.c: 4 added lines, 4 removed lines.
Original line number Diff line number Diff line
@@ -1960,7 +1960,7 @@ static int sv_body(char *hostname, int s, unsigned char *context)

	if (s_debug)
		{
		con->debug=1;
		SSL_set_debug(con, 1);
		BIO_set_callback(SSL_get_rbio(con),bio_dump_callback);
		BIO_set_callback_arg(SSL_get_rbio(con),(char *)bio_s_out);
		}
@@ -2285,7 +2285,7 @@ static int init_ssl_connection(SSL *con)
		BIO_printf(bio_s_out,"Shared ciphers:%s\n",buf);
	str=SSL_CIPHER_get_name(SSL_get_current_cipher(con));
	BIO_printf(bio_s_out,"CIPHER is %s\n",(str != NULL)?str:"(NONE)");
	if (con->hit) BIO_printf(bio_s_out,"Reused session-id\n");
	if (SSL_cache_hit(con)) BIO_printf(bio_s_out,"Reused session-id\n");
	if (SSL_ctrl(con,SSL_CTRL_GET_FLAGS,0,NULL) &
		TLS1_FLAGS_TLS_PADDING_BUG)
		BIO_printf(bio_s_out,"Peer has incorrect TLSv1 block padding\n");
@@ -2405,7 +2405,7 @@ static int www_body(char *hostname, int s, unsigned char *context)

	if (s_debug)
		{
		con->debug=1;
		SSL_set_debug(con, 1);
		BIO_set_callback(SSL_get_rbio(con),bio_dump_callback);
		BIO_set_callback_arg(SSL_get_rbio(con),(char *)bio_s_out);
		}
@@ -2526,7 +2526,7 @@ static int www_body(char *hostname, int s, unsigned char *context)
					}
				BIO_puts(io,"\n");
				}
			BIO_printf(io,((con->hit)
			BIO_printf(io,(SSL_cache_hit(con)
				?"---\nReused, "
				:"---\nNew, "));
			c=SSL_get_current_cipher(con);
Loading