TLSBase Class Reference

An abstract base class for TLS implementations. More...

#include <tlsbase.h>

Inheritance diagram for TLSBase:

Inheritance graph
[legend]
Collaboration diagram for TLSBase:

Collaboration graph
[legend]

List of all members.

Public Member Functions

 TLSBase (TLSHandler *th, const std::string server)
virtual ~TLSBase ()
virtual bool encrypt (const std::string &data)=0
virtual int decrypt (const std::string &data)=0
virtual void cleanup ()=0
virtual bool handshake ()=0
virtual bool isSecure () const
virtual void setCACerts (const StringList &cacerts)=0
virtual const CertInfofetchTLSInfo () const
virtual void setClientCert (const std::string &clientKey, const std::string &clientCerts)=0


Detailed Description

An abstract base class for TLS implementations.

Author:
Jakob Schröter <js@camaya.net>
Since:
0.9

Definition at line 30 of file tlsbase.h.


Constructor & Destructor Documentation

TLSBase ( TLSHandler th,
const std::string  server 
) [inline]

Constructor.

Parameters:
th The TLSHandler to handle TLS-related events.
server The server to use in certificate verification.

Definition at line 38 of file tlsbase.h.

virtual ~TLSBase (  )  [inline, virtual]

Virtual destructor.

Definition at line 44 of file tlsbase.h.


Member Function Documentation

virtual bool encrypt ( const std::string &  data  )  [pure virtual]

Use this function to feed unencrypted data to the encryption implementation. The encrypted result will be pushed to the TLSHandler's handleEncryptedData() function.

Parameters:
data The data to encrypt.
Returns:
Whether or not the data was used successfully.

Implemented in TLSDefault, GnuTLSBase, OpenSSL, and SChannel.

virtual int decrypt ( const std::string &  data  )  [pure virtual]

Use this function to feed encrypted data or received handshake data to the encryption implementation. Handshake data will be eaten, unencrypted data will be pushed to the TLSHandler's handleDecryptedData() function.

Parameters:
data The data to decrypt.
Returns:
The number of bytes used from the input.

Implemented in TLSDefault, GnuTLSBase, OpenSSL, and SChannel.

virtual void cleanup (  )  [pure virtual]

This function performs internal cleanup and will be called after a failed handshake attempt.

Implemented in TLSDefault, GnuTLSBase, GnuTLSClient, GnuTLSClientAnon, GnuTLSServerAnon, OpenSSL, and SChannel.

virtual bool handshake (  )  [pure virtual]

This functiopn performs the TLS handshake. Handshake data from the server side should be fed in using decrypt(). Handshake data that is to be sent to the other side is pushed through TLSBase's handleEncryptedData().

Returns:
True if the handshake was successful or if more input is needed, false if the handshake failed.

Implemented in TLSDefault, GnuTLSBase, OpenSSL, and SChannel.

virtual bool isSecure (  )  const [inline, virtual]

Returns the state of the encryption.

Returns:
The state of the encryption.

Reimplemented in TLSDefault.

Definition at line 81 of file tlsbase.h.

virtual void setCACerts ( const StringList cacerts  )  [pure virtual]

Use this function to set a number of trusted root CA certificates which shall be used to verify a servers certificate.

Parameters:
cacerts A list of absolute paths to CA root certificate files in PEM format.

Implemented in TLSDefault, GnuTLSBase, GnuTLSClient, OpenSSL, and SChannel.

virtual const CertInfo& fetchTLSInfo (  )  const [inline, virtual]

This function is used to retrieve certificate and connection info of a encrypted connection.

Returns:
Certificate information.

Reimplemented in TLSDefault.

Definition at line 94 of file tlsbase.h.

virtual void setClientCert ( const std::string &  clientKey,
const std::string &  clientCerts 
) [pure virtual]

Use this function to set the user's certificate and private key. The certificate will be presented to the server upon request and can be used for SASL EXTERNAL authentication. The user's certificate file should be a bundle of more than one certificate in PEM format. The first one in the file should be the user's certificate, each cert following that one should have signed the previous one.

Note:
These certificates are not necessarily the same as those used to verify the server's certificate.
Parameters:
clientKey The absolute path to the user's private key in PEM format.
clientCerts A path to a certificate bundle in PEM format.

Implemented in TLSDefault, GnuTLSBase, GnuTLSClient, OpenSSL, and SChannel.


The documentation for this class was generated from the following file:
Generated on Sat Nov 10 08:50:44 2007 for gloox by  doxygen 1.5.3-20071008