1 /* GIO - GLib Input, Output and Streaming Library
3 * Copyright © 2010 Red Hat, Inc
5 * This library is free software; you can redistribute it and/or
6 * modify it under the terms of the GNU Lesser General Public
7 * License as published by the Free Software Foundation; either
8 * version 2 of the License, or (at your option) any later version.
10 * This library is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
13 * Lesser General Public License for more details.
15 * You should have received a copy of the GNU Lesser General
16 * Public License along with this library; if not, see <http://www.gnu.org/licenses/>.
22 #include "gtlsbackend.h"
23 #include "gdummytlsbackend.h"
24 #include "gioenumtypes.h"
25 #include "giomodule-priv.h"
29 * @title: TLS Overview
30 * @short_description: TLS (aka SSL) support for GSocketConnection
33 * #GTlsConnection and related classes provide TLS (Transport Layer
34 * Security, previously known as SSL, Secure Sockets Layer) support for
35 * gio-based network streams.
37 * In the simplest case, for a client connection, you can just set the
38 * #GSocketClient:tls flag on a #GSocketClient, and then any
39 * connections created by that client will have TLS negotiated
40 * automatically, using appropriate default settings, and rejecting
41 * any invalid or self-signed certificates (unless you change that
42 * default by setting the #GSocketClient:tls-validation-flags
43 * property). The returned object will be a #GTcpWrapperConnection,
44 * which wraps the underlying #GTlsClientConnection.
46 * For greater control, you can create your own #GTlsClientConnection,
47 * wrapping a #GSocketConnection (or an arbitrary #GIOStream with
48 * pollable input and output streams) and then connect to its signals,
49 * such as #GTlsConnection::accept-certificate, before starting the
52 * Server-side TLS is similar, using #GTlsServerConnection. At the
53 * moment, there is no support for automatically wrapping server-side
54 * connections in the way #GSocketClient does for client-side
61 * @short_description: TLS backend implementation
68 * TLS (Transport Layer Security, aka SSL) backend. This is an
69 * internal type used to coordinate the different classes implemented
75 G_DEFINE_INTERFACE (GTlsBackend, g_tls_backend, G_TYPE_OBJECT);
78 g_tls_backend_default_init (GTlsBackendInterface *iface)
83 * g_tls_backend_get_default:
85 * Gets the default #GTlsBackend for the system.
87 * Returns: (transfer none): a #GTlsBackend
92 g_tls_backend_get_default (void)
94 return _g_io_module_get_default (G_TLS_BACKEND_EXTENSION_POINT_NAME,
99 * g_tls_backend_supports_tls:
100 * @backend: the #GTlsBackend
102 * Checks if TLS is supported; if this returns %FALSE for the default
103 * #GTlsBackend, it means no "real" TLS backend is available.
105 * Returns: whether or not TLS is supported
110 g_tls_backend_supports_tls (GTlsBackend *backend)
112 if (G_TLS_BACKEND_GET_INTERFACE (backend)->supports_tls)
113 return G_TLS_BACKEND_GET_INTERFACE (backend)->supports_tls (backend);
114 else if (G_IS_DUMMY_TLS_BACKEND (backend))
121 * g_tls_backend_get_default_database:
122 * @backend: the #GTlsBackend
124 * Gets the default #GTlsDatabase used to verify TLS connections.
126 * Returns: (transfer full): the default database, which should be
127 * unreffed when done.
132 g_tls_backend_get_default_database (GTlsBackend *backend)
134 g_return_val_if_fail (G_IS_TLS_BACKEND (backend), NULL);
136 /* This method was added later, so accept the (remote) possibility it can be NULL */
137 if (!G_TLS_BACKEND_GET_INTERFACE (backend)->get_default_database)
140 return G_TLS_BACKEND_GET_INTERFACE (backend)->get_default_database (backend);
144 * g_tls_backend_get_certificate_type:
145 * @backend: the #GTlsBackend
147 * Gets the #GType of @backend's #GTlsCertificate implementation.
149 * Returns: the #GType of @backend's #GTlsCertificate
155 g_tls_backend_get_certificate_type (GTlsBackend *backend)
157 return G_TLS_BACKEND_GET_INTERFACE (backend)->get_certificate_type ();
161 * g_tls_backend_get_client_connection_type:
162 * @backend: the #GTlsBackend
164 * Gets the #GType of @backend's #GTlsClientConnection implementation.
166 * Returns: the #GType of @backend's #GTlsClientConnection
172 g_tls_backend_get_client_connection_type (GTlsBackend *backend)
174 return G_TLS_BACKEND_GET_INTERFACE (backend)->get_client_connection_type ();
178 * g_tls_backend_get_server_connection_type:
179 * @backend: the #GTlsBackend
181 * Gets the #GType of @backend's #GTlsServerConnection implementation.
183 * Returns: the #GType of @backend's #GTlsServerConnection
189 g_tls_backend_get_server_connection_type (GTlsBackend *backend)
191 return G_TLS_BACKEND_GET_INTERFACE (backend)->get_server_connection_type ();
195 * g_tls_backend_get_file_database_type:
196 * @backend: the #GTlsBackend
198 * Gets the #GType of @backend's #GTlsFileDatabase implementation.
200 * Returns: the #GType of backend's #GTlsFileDatabase implementation.
205 g_tls_backend_get_file_database_type (GTlsBackend *backend)
207 g_return_val_if_fail (G_IS_TLS_BACKEND (backend), 0);
209 /* This method was added later, so accept the (remote) possibility it can be NULL */
210 if (!G_TLS_BACKEND_GET_INTERFACE (backend)->get_file_database_type)
213 return G_TLS_BACKEND_GET_INTERFACE (backend)->get_file_database_type ();