add CA certificate handling

This commit is contained in:
DIlkhush00 committed 2026-03-12 03:18:52 +05:30
1 parent b190d7d6bb
commit a4d31815df
2 files changed
+40 -2

No files matched your search

+19 -1
View File
@@ -4,6 +4,7 @@
#include "mbedtls/ssl.h"
#include "mbedtls/debug.h"
#include "mbedtls/error.h"
#include "mbedtls/x509_crt.h"
#include <string.h>
#include <stdio.h>
@@ -23,6 +24,7 @@
POST_BODY
#define DEBUG_LEVEL 0
#define CA_CERT_PATH "/etc/ssl/certs/ca-certificates.crt" // most distros use this path for CA certs, adjust if needed
static void my_debug(void *ctx, int level,
const char *file, int line, const char *str)
@@ -40,6 +42,7 @@ int main(void) {
mbedtls_net_context server_fd;
mbedtls_ssl_context ssl;
mbedtls_ssl_config conf;
// mbedtls_x509_crt cacert;
mbedtls_printf("Initializing TLS structures...");
fflush(stdout);
@@ -47,6 +50,7 @@ int main(void) {
mbedtls_net_init(&server_fd);
mbedtls_ssl_init(&ssl);
mbedtls_ssl_config_init(&conf);
// mbedtls_x509_crt_init(&cacert);
mbedtls_printf(" ok\n");
@@ -89,8 +93,21 @@ int main(void) {
goto exit;
}
mbedtls_ssl_conf_authmode(&conf, MBEDTLS_SSL_VERIFY_NONE); // for the demo purposes, not safe for prod
// mbedtls_printf("Loading CA certificate from %s...", CA_CERT_PATH);
// fflush(stdout);
// ret = mbedtls_x509_crt_parse_file(&cacert, CA_CERT_PATH);
// if (ret != 0) {
// mbedtls_printf(" failed\n ! mbedtls_x509_crt_parse_file returned -0x%x\n", -ret);
// goto exit;
// }
// mbedtls_printf(" ok\n");
// mbedtls_ssl_conf_ca_chain(&conf, &cacert, NULL);
// mbedtls_ssl_conf_authmode(&conf, MBEDTLS_SSL_VERIFY_REQUIRED);
mbedtls_ssl_conf_authmode(&conf, MBEDTLS_SSL_VERIFY_NONE); // no good for prod
mbedtls_debug_set_threshold(DEBUG_LEVEL);
mbedtls_ssl_conf_dbg(&conf, my_debug, stdout);
@@ -215,6 +232,7 @@ exit:
mbedtls_net_free(&server_fd);
mbedtls_ssl_free(&ssl);
mbedtls_ssl_config_free(&conf);
// mbedtls_x509_crt_free(&cacert);
mbedtls_printf(" ok\n\n");
+21 -1
View File
@@ -4,6 +4,7 @@
#include "mbedtls/ssl.h"
#include "mbedtls/debug.h"
#include "mbedtls/error.h"
#include "mbedtls/x509_crt.h"
#include <string.h>
#include <stdio.h>
@@ -37,6 +38,7 @@
"Connection: close\r\n\r\n"
#define DEBUG_LEVEL 0
#define CA_CERT_PATH "/etc/ssl/certs/ca-certificates.crt" // most distros use this path for CA certs, adjust if needed
static void my_debug(void *ctx, int level,
const char *file, int line, const char *str)
@@ -96,6 +98,7 @@ int main(void) {
mbedtls_net_context server_fd;
mbedtls_ssl_context ssl;
mbedtls_ssl_config conf;
// mbedtls_x509_crt cacert;
mbedtls_printf("Initializing TLS structures...");
fflush(stdout);
@@ -103,6 +106,7 @@ int main(void) {
mbedtls_net_init(&server_fd);
mbedtls_ssl_init(&ssl);
mbedtls_ssl_config_init(&conf);
// mbedtls_x509_crt_init(&cacert);
mbedtls_printf(" ok\n");
@@ -145,7 +149,22 @@ int main(void) {
goto exit;
}
mbedtls_ssl_conf_authmode(&conf, MBEDTLS_SSL_VERIFY_NONE);
// mbedtls_printf("Loading CA certificate from %s...", CA_CERT_PATH);
// fflush(stdout);
// ret = mbedtls_x509_crt_parse_file(&cacert, CA_CERT_PATH);
// if (ret != 0) {
// mbedtls_printf(" failed\n ! mbedtls_x509_crt_parse_file returned -0x%x\n", -ret);
// goto exit;
// }
// mbedtls_printf(" ok\n");
// mbedtls_ssl_conf_ca_chain(&conf, &cacert, NULL);
// mbedtls_ssl_conf_authmode(&conf, MBEDTLS_SSL_VERIFY_REQUIRED);
mbedtls_ssl_conf_authmode(&conf, MBEDTLS_SSL_VERIFY_NONE); // not good for prod
mbedtls_debug_set_threshold(DEBUG_LEVEL);
mbedtls_ssl_conf_dbg(&conf, my_debug, stdout);
@@ -234,6 +253,7 @@ exit:
mbedtls_net_free(&server_fd);
mbedtls_ssl_free(&ssl);
mbedtls_ssl_config_free(&conf);
// mbedtls_x509_crt_free(&cacert);
mbedtls_printf(" ok\n\n");