2 * QEMU crypto TLS credential support
4 * Copyright (c) 2015 Red Hat, Inc.
6 * This library is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU Lesser General Public
8 * License as published by the Free Software Foundation; either
9 * version 2 of the License, or (at your option) any later version.
11 * This library is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14 * Lesser General Public License for more details.
16 * You should have received a copy of the GNU Lesser General Public
17 * License along with this library; if not, see <http://www.gnu.org/licenses/>.
21 #include "qemu/osdep.h"
22 #include "crypto/tlscredspriv.h"
29 qcrypto_tls_creds_get_dh_params_file(QCryptoTLSCreds
*creds
,
31 gnutls_dh_params_t
*dh_params
,
36 trace_qcrypto_tls_creds_load_dh(creds
, filename
? filename
: "<generated>");
38 if (filename
== NULL
) {
39 ret
= gnutls_dh_params_init(dh_params
);
41 error_setg(errp
, "Unable to initialize DH parameters: %s",
42 gnutls_strerror(ret
));
45 ret
= gnutls_dh_params_generate2(*dh_params
, DH_BITS
);
47 gnutls_dh_params_deinit(*dh_params
);
49 error_setg(errp
, "Unable to generate DH parameters: %s",
50 gnutls_strerror(ret
));
58 if (!g_file_get_contents(filename
,
63 error_setg(errp
, "%s", gerr
->message
);
67 data
.data
= (unsigned char *)contents
;
69 ret
= gnutls_dh_params_init(dh_params
);
72 error_setg(errp
, "Unable to initialize DH parameters: %s",
73 gnutls_strerror(ret
));
76 ret
= gnutls_dh_params_import_pkcs3(*dh_params
,
81 gnutls_dh_params_deinit(*dh_params
);
83 error_setg(errp
, "Unable to load DH parameters from %s: %s",
84 filename
, gnutls_strerror(ret
));
94 qcrypto_tls_creds_get_path(QCryptoTLSCreds
*creds
,
105 error_setg(errp
, "Missing 'dir' property value");
112 *cred
= g_strdup_printf("%s/%s", creds
->dir
, filename
);
114 if (stat(*cred
, &sb
) < 0) {
115 if (errno
== ENOENT
&& !required
) {
118 error_setg_errno(errp
, errno
,
119 "Unable to access credentials %s",
129 trace_qcrypto_tls_creds_get_path(creds
, filename
,
130 *cred
? *cred
: "<none>");
135 #endif /* ! CONFIG_GNUTLS */
139 qcrypto_tls_creds_prop_set_verify(Object
*obj
,
141 Error
**errp G_GNUC_UNUSED
)
143 QCryptoTLSCreds
*creds
= QCRYPTO_TLS_CREDS(obj
);
145 creds
->verifyPeer
= value
;
150 qcrypto_tls_creds_prop_get_verify(Object
*obj
,
151 Error
**errp G_GNUC_UNUSED
)
153 QCryptoTLSCreds
*creds
= QCRYPTO_TLS_CREDS(obj
);
155 return creds
->verifyPeer
;
160 qcrypto_tls_creds_prop_set_dir(Object
*obj
,
162 Error
**errp G_GNUC_UNUSED
)
164 QCryptoTLSCreds
*creds
= QCRYPTO_TLS_CREDS(obj
);
166 creds
->dir
= g_strdup(value
);
171 qcrypto_tls_creds_prop_get_dir(Object
*obj
,
172 Error
**errp G_GNUC_UNUSED
)
174 QCryptoTLSCreds
*creds
= QCRYPTO_TLS_CREDS(obj
);
176 return g_strdup(creds
->dir
);
181 qcrypto_tls_creds_prop_set_endpoint(Object
*obj
,
183 Error
**errp G_GNUC_UNUSED
)
185 QCryptoTLSCreds
*creds
= QCRYPTO_TLS_CREDS(obj
);
187 creds
->endpoint
= value
;
192 qcrypto_tls_creds_prop_get_endpoint(Object
*obj
,
193 Error
**errp G_GNUC_UNUSED
)
195 QCryptoTLSCreds
*creds
= QCRYPTO_TLS_CREDS(obj
);
197 return creds
->endpoint
;
202 qcrypto_tls_creds_class_init(ObjectClass
*oc
, void *data
)
204 object_class_property_add_bool(oc
, "verify-peer",
205 qcrypto_tls_creds_prop_get_verify
,
206 qcrypto_tls_creds_prop_set_verify
,
208 object_class_property_add_str(oc
, "dir",
209 qcrypto_tls_creds_prop_get_dir
,
210 qcrypto_tls_creds_prop_set_dir
,
212 object_class_property_add_enum(oc
, "endpoint",
213 "QCryptoTLSCredsEndpoint",
214 QCryptoTLSCredsEndpoint_lookup
,
215 qcrypto_tls_creds_prop_get_endpoint
,
216 qcrypto_tls_creds_prop_set_endpoint
,
222 qcrypto_tls_creds_init(Object
*obj
)
224 QCryptoTLSCreds
*creds
= QCRYPTO_TLS_CREDS(obj
);
226 creds
->verifyPeer
= true;
231 qcrypto_tls_creds_finalize(Object
*obj
)
233 QCryptoTLSCreds
*creds
= QCRYPTO_TLS_CREDS(obj
);
239 static const TypeInfo qcrypto_tls_creds_info
= {
240 .parent
= TYPE_OBJECT
,
241 .name
= TYPE_QCRYPTO_TLS_CREDS
,
242 .instance_size
= sizeof(QCryptoTLSCreds
),
243 .instance_init
= qcrypto_tls_creds_init
,
244 .instance_finalize
= qcrypto_tls_creds_finalize
,
245 .class_init
= qcrypto_tls_creds_class_init
,
246 .class_size
= sizeof(QCryptoTLSCredsClass
),
252 qcrypto_tls_creds_register_types(void)
254 type_register_static(&qcrypto_tls_creds_info
);
258 type_init(qcrypto_tls_creds_register_types
);