1#ifndef HEADER_CURL_SSLUSE_H
2#define HEADER_CURL_SSLUSE_H
3/***************************************************************************
4 * _ _ ____ _
5 * Project ___| | | | _ \| |
6 * / __| | | | |_) | |
7 * | (__| |_| | _ <| |___
8 * \___|\___/|_| \_\_____|
9 *
10 * Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
11 *
12 * This software is licensed as described in the file COPYING, which
13 * you should have received as part of this distribution. The terms
14 * are also available at https://curl.se/docs/copyright.html.
15 *
16 * You may opt to use, copy, modify, merge, publish, distribute and/or sell
17 * copies of the Software, and permit persons to whom the Software is
18 * furnished to do so, under the terms of the COPYING file.
19 *
20 * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
21 * KIND, either express or implied.
22 *
23 * SPDX-License-Identifier: curl
24 *
25 ***************************************************************************/
26
27#include "curl_setup.h"
28
29#ifdef USE_OPENSSL
30/*
31 * This header should only be needed to get included by vtls.c, openssl.c
32 * and ngtcp2.c
33 */
34#include <openssl/ssl.h>
35
36#include "urldata.h"
37
38/*
39 * In an effort to avoid using 'X509 *' here, we instead use the struct
40 * x509_st version of the type so that we can forward-declare it here without
41 * having to include <openssl/x509v3.h>. Including that header causes name
42 * conflicts when libcurl is built with both Schannel and OpenSSL support.
43 */
44struct x509_st;
45CURLcode Curl_ossl_verifyhost(struct Curl_easy *data, struct connectdata *conn,
46 struct x509_st *server_cert);
47extern const struct Curl_ssl Curl_ssl_openssl;
48
49struct ssl_ctx_st;
50CURLcode Curl_ossl_set_client_cert(struct Curl_easy *data,
51 struct ssl_ctx_st *ctx, char *cert_file,
52 const struct curl_blob *cert_blob,
53 const char *cert_type, char *key_file,
54 const struct curl_blob *key_blob,
55 const char *key_type, char *key_passwd);
56
57CURLcode Curl_ossl_certchain(struct Curl_easy *data, SSL *ssl);
58
59/**
60 * Setup the OpenSSL X509_STORE in `ssl_ctx` for the cfilter `cf` and
61 * easy handle `data`. Will allow reuse of a shared cache if suitable
62 * and configured.
63 */
64CURLcode Curl_ssl_setup_x509_store(struct Curl_cfilter *cf,
65 struct Curl_easy *data,
66 SSL_CTX *ssl_ctx);
67
68#endif /* USE_OPENSSL */
69#endif /* HEADER_CURL_SSLUSE_H */
70