add CA certificate handling
This commit is contained in:
1 parent
b190d7d6bb
commit
a4d31815df
2 files changed
+40
-2
No files matched your search
+19
-1
@@ -4,6 +4,7 @@
|
||||
#include "mbedtls/ssl.h"
|
||||
#include "mbedtls/debug.h"
|
||||
#include "mbedtls/error.h"
|
||||
#include "mbedtls/x509_crt.h"
|
||||
|
||||
#include <string.h>
|
||||
#include <stdio.h>
|
||||
@@ -23,6 +24,7 @@
|
||||
POST_BODY
|
||||
|
||||
#define DEBUG_LEVEL 0
|
||||
#define CA_CERT_PATH "/etc/ssl/certs/ca-certificates.crt" // most distros use this path for CA certs, adjust if needed
|
||||
|
||||
static void my_debug(void *ctx, int level,
|
||||
const char *file, int line, const char *str)
|
||||
@@ -40,6 +42,7 @@ int main(void) {
|
||||
mbedtls_net_context server_fd;
|
||||
mbedtls_ssl_context ssl;
|
||||
mbedtls_ssl_config conf;
|
||||
// mbedtls_x509_crt cacert;
|
||||
|
||||
mbedtls_printf("Initializing TLS structures...");
|
||||
fflush(stdout);
|
||||
@@ -47,6 +50,7 @@ int main(void) {
|
||||
mbedtls_net_init(&server_fd);
|
||||
mbedtls_ssl_init(&ssl);
|
||||
mbedtls_ssl_config_init(&conf);
|
||||
// mbedtls_x509_crt_init(&cacert);
|
||||
|
||||
mbedtls_printf(" ok\n");
|
||||
|
||||
@@ -89,8 +93,21 @@ int main(void) {
|
||||
goto exit;
|
||||
}
|
||||
|
||||
mbedtls_ssl_conf_authmode(&conf, MBEDTLS_SSL_VERIFY_NONE); // for the demo purposes, not safe for prod
|
||||
// mbedtls_printf("Loading CA certificate from %s...", CA_CERT_PATH);
|
||||
// fflush(stdout);
|
||||
|
||||
// ret = mbedtls_x509_crt_parse_file(&cacert, CA_CERT_PATH);
|
||||
// if (ret != 0) {
|
||||
// mbedtls_printf(" failed\n ! mbedtls_x509_crt_parse_file returned -0x%x\n", -ret);
|
||||
// goto exit;
|
||||
// }
|
||||
// mbedtls_printf(" ok\n");
|
||||
|
||||
// mbedtls_ssl_conf_ca_chain(&conf, &cacert, NULL);
|
||||
// mbedtls_ssl_conf_authmode(&conf, MBEDTLS_SSL_VERIFY_REQUIRED);
|
||||
|
||||
mbedtls_ssl_conf_authmode(&conf, MBEDTLS_SSL_VERIFY_NONE); // no good for prod
|
||||
|
||||
mbedtls_debug_set_threshold(DEBUG_LEVEL);
|
||||
mbedtls_ssl_conf_dbg(&conf, my_debug, stdout);
|
||||
|
||||
@@ -215,6 +232,7 @@ exit:
|
||||
mbedtls_net_free(&server_fd);
|
||||
mbedtls_ssl_free(&ssl);
|
||||
mbedtls_ssl_config_free(&conf);
|
||||
// mbedtls_x509_crt_free(&cacert);
|
||||
|
||||
mbedtls_printf(" ok\n\n");
|
||||
|
||||
|
||||
+21
-1
@@ -4,6 +4,7 @@
|
||||
#include "mbedtls/ssl.h"
|
||||
#include "mbedtls/debug.h"
|
||||
#include "mbedtls/error.h"
|
||||
#include "mbedtls/x509_crt.h"
|
||||
|
||||
#include <string.h>
|
||||
#include <stdio.h>
|
||||
@@ -37,6 +38,7 @@
|
||||
"Connection: close\r\n\r\n"
|
||||
|
||||
#define DEBUG_LEVEL 0
|
||||
#define CA_CERT_PATH "/etc/ssl/certs/ca-certificates.crt" // most distros use this path for CA certs, adjust if needed
|
||||
|
||||
static void my_debug(void *ctx, int level,
|
||||
const char *file, int line, const char *str)
|
||||
@@ -96,6 +98,7 @@ int main(void) {
|
||||
mbedtls_net_context server_fd;
|
||||
mbedtls_ssl_context ssl;
|
||||
mbedtls_ssl_config conf;
|
||||
// mbedtls_x509_crt cacert;
|
||||
|
||||
mbedtls_printf("Initializing TLS structures...");
|
||||
fflush(stdout);
|
||||
@@ -103,6 +106,7 @@ int main(void) {
|
||||
mbedtls_net_init(&server_fd);
|
||||
mbedtls_ssl_init(&ssl);
|
||||
mbedtls_ssl_config_init(&conf);
|
||||
// mbedtls_x509_crt_init(&cacert);
|
||||
|
||||
mbedtls_printf(" ok\n");
|
||||
|
||||
@@ -145,7 +149,22 @@ int main(void) {
|
||||
goto exit;
|
||||
}
|
||||
|
||||
mbedtls_ssl_conf_authmode(&conf, MBEDTLS_SSL_VERIFY_NONE);
|
||||
// mbedtls_printf("Loading CA certificate from %s...", CA_CERT_PATH);
|
||||
// fflush(stdout);
|
||||
|
||||
// ret = mbedtls_x509_crt_parse_file(&cacert, CA_CERT_PATH);
|
||||
// if (ret != 0) {
|
||||
// mbedtls_printf(" failed\n ! mbedtls_x509_crt_parse_file returned -0x%x\n", -ret);
|
||||
// goto exit;
|
||||
// }
|
||||
// mbedtls_printf(" ok\n");
|
||||
|
||||
|
||||
// mbedtls_ssl_conf_ca_chain(&conf, &cacert, NULL);
|
||||
// mbedtls_ssl_conf_authmode(&conf, MBEDTLS_SSL_VERIFY_REQUIRED);
|
||||
|
||||
mbedtls_ssl_conf_authmode(&conf, MBEDTLS_SSL_VERIFY_NONE); // not good for prod
|
||||
|
||||
mbedtls_debug_set_threshold(DEBUG_LEVEL);
|
||||
mbedtls_ssl_conf_dbg(&conf, my_debug, stdout);
|
||||
|
||||
@@ -234,6 +253,7 @@ exit:
|
||||
mbedtls_net_free(&server_fd);
|
||||
mbedtls_ssl_free(&ssl);
|
||||
mbedtls_ssl_config_free(&conf);
|
||||
// mbedtls_x509_crt_free(&cacert);
|
||||
|
||||
mbedtls_printf(" ok\n\n");
|
||||
|
||||
|
||||
Reference in new issue
Block a user