1 /* GIO - GLib Input, Output and Streaming Library
3 * Copyright © 2010 Red Hat, Inc
5 * This library is free software; you can redistribute it and/or
6 * modify it under the terms of the GNU Lesser General Public
7 * License as published by the Free Software Foundation; either
8 * version 2 of the License, or (at your option) any later version.
10 * This library is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
13 * Lesser General Public License for more details.
15 * You should have received a copy of the GNU Lesser General
16 * Public License along with this library; if not, write to the
17 * Free Software Foundation, Inc., 59 Temple Place, Suite 330,
18 * Boston, MA 02111-1307, USA.
24 #include "gtlsbackend.h"
25 #include "gdummytlsbackend.h"
26 #include "gioenumtypes.h"
27 #include "giomodule-priv.h"
31 * @title: TLS Overview
32 * @short_description: TLS (aka SSL) support for GSocketConnection
35 * #GTlsConnection and related classes provide TLS (Transport Layer
36 * Security, previously known as SSL, Secure Sockets Layer) support for
37 * gio-based network streams.
39 * In the simplest case, for a client connection, you can just set the
40 * #GSocketClient:tls flag on a #GSocketClient, and then any
41 * connections created by that client will have TLS negotiated
42 * automatically, using appropriate default settings, and rejecting
43 * any invalid or self-signed certificates (unless you change that
44 * default by setting the #GSocketClient:tls-validation-flags
45 * property). The returned object will be a #GTcpWrapperConnection,
46 * which wraps the underlying #GTlsClientConnection.
48 * For greater control, you can create your own #GTlsClientConnection,
49 * wrapping a #GSocketConnection (or an arbitrary #GIOStream with
50 * pollable input and output streams) and then connect to its signals,
51 * such as #GTlsConnection::accept-certificate, before starting the
54 * Server-side TLS is similar, using #GTlsServerConnection. At the
55 * moment, there is no support for automatically wrapping server-side
56 * connections in the way #GSocketClient does for client-side
63 * @short_description: TLS backend implementation
70 * Type implemented by TLS #GIOModules to provide access to additional
76 G_DEFINE_INTERFACE (GTlsBackend, g_tls_backend, G_TYPE_OBJECT);
79 g_tls_backend_default_init (GTlsBackendInterface *iface)
84 get_default_tls_backend (gpointer arg)
88 GIOExtensionPoint *ep;
89 GIOExtension *extension;
91 _g_io_modules_ensure_loaded ();
93 ep = g_io_extension_point_lookup (G_TLS_BACKEND_EXTENSION_POINT_NAME);
95 use_this = g_getenv ("GIO_USE_TLS");
98 extension = g_io_extension_point_get_extension_by_name (ep, use_this);
100 return g_object_new (g_io_extension_get_type (extension), NULL);
103 extensions = g_io_extension_point_get_extensions (ep);
106 extension = extensions->data;
107 return g_object_new (g_io_extension_get_type (extension), NULL);
114 * g_tls_backend_get_default:
116 * Gets the default #GTlsBackend for the system.
118 * Returns: (transfer none): a #GTlsBackend
123 g_tls_backend_get_default (void)
125 static GOnce once_init = G_ONCE_INIT;
127 return g_once (&once_init, get_default_tls_backend, NULL);
131 * g_tls_backend_supports_tls:
132 * @backend: the #GTlsBackend
134 * Checks if TLS is supported; if this returns %FALSE for the default
135 * #GTlsBackend, it means no "real" TLS backend is available.
137 * Return value: whether or not TLS is supported
142 g_tls_backend_supports_tls (GTlsBackend *backend)
144 if (G_TLS_BACKEND_GET_INTERFACE (backend)->supports_tls)
145 return G_TLS_BACKEND_GET_INTERFACE (backend)->supports_tls (backend);
146 else if (G_IS_DUMMY_TLS_BACKEND (backend))
153 * g_tls_backend_get_default_database:
154 * @backend: the #GTlsBackend
156 * Gets the default #GTlsDatabase used to verify TLS connections.
158 * Return value: (transfer full): the default database, which should be
159 * unreffed when done.
164 g_tls_backend_get_default_database (GTlsBackend *backend)
166 g_return_val_if_fail (G_IS_TLS_BACKEND (backend), NULL);
168 /* This method was added later, so accept the (remote) possibility it can be NULL */
169 if (!G_TLS_BACKEND_GET_INTERFACE (backend)->get_default_database)
172 return G_TLS_BACKEND_GET_INTERFACE (backend)->get_default_database (backend);
176 * g_tls_backend_get_certificate_type:
177 * @backend: the #GTlsBackend
179 * Gets the #GType of @backend's #GTlsCertificate implementation.
181 * Return value: the #GType of @backend's #GTlsCertificate
187 g_tls_backend_get_certificate_type (GTlsBackend *backend)
189 return G_TLS_BACKEND_GET_INTERFACE (backend)->get_certificate_type ();
193 * g_tls_backend_get_client_connection_type:
194 * @backend: the #GTlsBackend
196 * Gets the #GType of @backend's #GTlsClientConnection implementation.
198 * Return value: the #GType of @backend's #GTlsClientConnection
204 g_tls_backend_get_client_connection_type (GTlsBackend *backend)
206 return G_TLS_BACKEND_GET_INTERFACE (backend)->get_client_connection_type ();
210 * g_tls_backend_get_server_connection_type:
211 * @backend: the #GTlsBackend
213 * Gets the #GType of @backend's #GTlsServerConnection implementation.
215 * Return value: the #GType of @backend's #GTlsServerConnection
221 g_tls_backend_get_server_connection_type (GTlsBackend *backend)
223 return G_TLS_BACKEND_GET_INTERFACE (backend)->get_server_connection_type ();
227 * g_tls_backend_get_file_database_type:
228 * @backend: the #GTlsBackend
230 * Gets the #GTyep of @backend's #GTlsFileDatabase implementation.
232 * Return value: the #GType of backend's #GTlsFileDatabase implementation.
237 g_tls_backend_get_file_database_type (GTlsBackend *backend)
239 g_return_val_if_fail (G_IS_TLS_BACKEND (backend), 0);
241 /* This method was added later, so accept the (remote) possibility it can be NULL */
242 if (!G_TLS_BACKEND_GET_INTERFACE (backend)->get_file_database_type)
245 return G_TLS_BACKEND_GET_INTERFACE (backend)->get_file_database_type ();