Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 1 | /* |
| 2 | * ssl.c |
| 3 | * |
| 4 | * Copyright (C) AB Strakt 2001, All rights reserved |
Jean-Paul Calderone | 8b63d45 | 2008-03-21 18:31:12 -0400 | [diff] [blame] | 5 | * Copyright (C) Jean-Paul Calderone 2008, All rights reserved |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 6 | * |
| 7 | * Main file of the SSL sub module. |
| 8 | * See the file RATIONALE for a short explanation of why this module was written. |
| 9 | * |
| 10 | * Reviewed 2001-07-23 |
| 11 | */ |
| 12 | #include <Python.h> |
Jean-Paul Calderone | 12ea9a0 | 2008-02-22 12:24:39 -0500 | [diff] [blame] | 13 | |
Jean-Paul Calderone | 12ea9a0 | 2008-02-22 12:24:39 -0500 | [diff] [blame] | 14 | #ifndef MS_WINDOWS |
| 15 | # include <sys/socket.h> |
| 16 | # include <netinet/in.h> |
| 17 | # if !(defined(__BEOS__) || defined(__CYGWIN__)) |
| 18 | # include <netinet/tcp.h> |
| 19 | # endif |
| 20 | #else |
| 21 | # include <winsock.h> |
| 22 | # include <wincrypt.h> |
| 23 | #endif |
| 24 | |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 25 | #define SSL_MODULE |
| 26 | #include "ssl.h" |
| 27 | |
| 28 | static char ssl_doc[] = "\n\ |
| 29 | Main file of the SSL sub module.\n\ |
Jean-Paul Calderone | 5aa15c7 | 2008-03-04 22:20:17 -0500 | [diff] [blame] | 30 | See the file RATIONALE for a short explanation of why this module was written.\n\ |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 31 | "; |
| 32 | |
Jean-Paul Calderone | 31ba576 | 2010-11-01 17:30:41 -0400 | [diff] [blame] | 33 | crypto_X509Obj* (*new_x509)(X509*, int); |
| 34 | crypto_X509NameObj* (*new_x509name)(X509_NAME*, int); |
| 35 | crypto_X509StoreObj* (*new_x509store)(X509_STORE*, int); |
| 36 | |
| 37 | |
Jean-Paul Calderone | 83dbcfd | 2010-08-11 20:20:57 -0400 | [diff] [blame] | 38 | #ifndef PY3 |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 39 | void **crypto_API; |
Jean-Paul Calderone | 83dbcfd | 2010-08-11 20:20:57 -0400 | [diff] [blame] | 40 | #endif |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 41 | |
Jean-Paul Calderone | 00db9da | 2008-09-21 17:42:34 -0400 | [diff] [blame] | 42 | int _pyOpenSSL_tstate_key; |
| 43 | |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 44 | /* Exceptions defined by the SSL submodule */ |
| 45 | PyObject *ssl_Error, /* Base class */ |
| 46 | *ssl_ZeroReturnError, /* Used with SSL_get_error */ |
| 47 | *ssl_WantReadError, /* ... */ |
| 48 | *ssl_WantWriteError, /* ... */ |
| 49 | *ssl_WantX509LookupError, /* ... */ |
| 50 | *ssl_SysCallError; /* Uses (errno,errstr) */ |
| 51 | |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 52 | |
| 53 | /* Methods in the OpenSSL.SSL module */ |
| 54 | static PyMethodDef ssl_methods[] = { |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 55 | { NULL, NULL } |
| 56 | }; |
| 57 | |
Jean-Paul Calderone | 83dbcfd | 2010-08-11 20:20:57 -0400 | [diff] [blame] | 58 | #ifdef PY3 |
| 59 | static struct PyModuleDef sslmodule = { |
| 60 | PyModuleDef_HEAD_INIT, |
| 61 | "SSL", |
| 62 | ssl_doc, |
| 63 | -1, |
| 64 | ssl_methods |
| 65 | }; |
| 66 | #endif |
| 67 | |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 68 | /* |
| 69 | * Initialize SSL sub module |
| 70 | * |
| 71 | * Arguments: None |
| 72 | * Returns: None |
| 73 | */ |
Jean-Paul Calderone | 83dbcfd | 2010-08-11 20:20:57 -0400 | [diff] [blame] | 74 | PyOpenSSL_MODINIT(SSL) { |
| 75 | PyObject *module; |
| 76 | #ifndef PY3 |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 77 | static void *ssl_API[ssl_API_pointers]; |
| 78 | PyObject *ssl_api_object; |
Jean-Paul Calderone | 83dbcfd | 2010-08-11 20:20:57 -0400 | [diff] [blame] | 79 | |
| 80 | import_crypto(); |
Jean-Paul Calderone | e56627a | 2010-11-01 00:03:15 -0400 | [diff] [blame] | 81 | |
| 82 | new_x509 = crypto_X509_New; |
| 83 | new_x509name = crypto_X509Name_New; |
| 84 | new_x509store = crypto_X509Store_New; |
Jean-Paul Calderone | 305626a | 2010-10-31 20:51:17 -0400 | [diff] [blame] | 85 | #else |
Jean-Paul Calderone | ff077d6 | 2010-10-31 21:09:45 -0400 | [diff] [blame] | 86 | # ifdef _WIN32 |
Jean-Paul Calderone | 305626a | 2010-10-31 20:51:17 -0400 | [diff] [blame] | 87 | HMODULE crypto = GetModuleHandle("crypto.pyd"); |
| 88 | if (crypto == NULL) { |
| 89 | PyErr_SetString(PyExc_RuntimeError, "Unable to get crypto module"); |
Jean-Paul Calderone | d1ce64c | 2010-10-31 21:18:37 -0400 | [diff] [blame] | 90 | PyOpenSSL_MODRETURN(NULL); |
Jean-Paul Calderone | 305626a | 2010-10-31 20:51:17 -0400 | [diff] [blame] | 91 | } |
| 92 | |
Jean-Paul Calderone | 040112f | 2010-10-31 23:26:13 -0400 | [diff] [blame] | 93 | new_x509 = (crypto_X509Obj* (*)(X509*, int))GetProcAddress(crypto, "crypto_X509_New"); |
Jean-Paul Calderone | 5bcb303 | 2010-10-31 23:30:29 -0400 | [diff] [blame] | 94 | new_x509name = (crypto_X509NameObj* (*)(X509_NAME*, int))GetProcAddress(crypto, "crypto_X509Name_New"); |
| 95 | new_x509store = (crypto_X509StoreObj* (*)(X509_STORE*, int))GetProcAddress(crypto, "crypto_X509Store_New"); |
Jean-Paul Calderone | 305626a | 2010-10-31 20:51:17 -0400 | [diff] [blame] | 96 | # else |
Jean-Paul Calderone | 1e9312e | 2010-10-31 21:26:18 -0400 | [diff] [blame] | 97 | new_x509 = crypto_X509_New; |
Jean-Paul Calderone | 305626a | 2010-10-31 20:51:17 -0400 | [diff] [blame] | 98 | new_x509name = crypto_X509Name_New; |
Jean-Paul Calderone | 1e9312e | 2010-10-31 21:26:18 -0400 | [diff] [blame] | 99 | new_x509store = crypto_X509Store_New; |
Jean-Paul Calderone | 305626a | 2010-10-31 20:51:17 -0400 | [diff] [blame] | 100 | # endif |
Jean-Paul Calderone | 83dbcfd | 2010-08-11 20:20:57 -0400 | [diff] [blame] | 101 | #endif |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 102 | |
| 103 | SSL_library_init(); |
| 104 | ERR_load_SSL_strings(); |
| 105 | |
Jean-Paul Calderone | 83dbcfd | 2010-08-11 20:20:57 -0400 | [diff] [blame] | 106 | #ifdef PY3 |
| 107 | module = PyModule_Create(&sslmodule); |
| 108 | #else |
| 109 | module = Py_InitModule3("SSL", ssl_methods, ssl_doc); |
| 110 | #endif |
| 111 | if (module == NULL) { |
Jean-Paul Calderone | b6d7525 | 2010-08-11 23:55:45 -0400 | [diff] [blame] | 112 | PyOpenSSL_MODRETURN(NULL); |
Jean-Paul Calderone | 1bd11fa | 2009-05-27 17:09:15 -0400 | [diff] [blame] | 113 | } |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 114 | |
Jean-Paul Calderone | 83dbcfd | 2010-08-11 20:20:57 -0400 | [diff] [blame] | 115 | #ifndef PY3 |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 116 | /* Initialize the C API pointer array */ |
| 117 | ssl_API[ssl_Context_New_NUM] = (void *)ssl_Context_New; |
| 118 | ssl_API[ssl_Connection_New_NUM] = (void *)ssl_Connection_New; |
| 119 | ssl_api_object = PyCObject_FromVoidPtr((void *)ssl_API, NULL); |
| 120 | if (ssl_api_object != NULL) |
| 121 | PyModule_AddObject(module, "_C_API", ssl_api_object); |
Jean-Paul Calderone | 83dbcfd | 2010-08-11 20:20:57 -0400 | [diff] [blame] | 122 | #endif |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 123 | |
| 124 | /* Exceptions */ |
| 125 | /* |
| 126 | * ADD_EXCEPTION(dict,name,base) expands to a correct Exception declaration, |
| 127 | * inserting OpenSSL.SSL.name into dict, derviving the exception from base. |
| 128 | */ |
| 129 | #define ADD_EXCEPTION(_name, _base) \ |
| 130 | do { \ |
| 131 | ssl_##_name = PyErr_NewException("OpenSSL.SSL."#_name, _base, NULL);\ |
| 132 | if (ssl_##_name == NULL) \ |
| 133 | goto error; \ |
| 134 | if (PyModule_AddObject(module, #_name, ssl_##_name) != 0) \ |
| 135 | goto error; \ |
| 136 | } while (0) |
| 137 | |
| 138 | ssl_Error = PyErr_NewException("OpenSSL.SSL.Error", NULL, NULL); |
| 139 | if (ssl_Error == NULL) |
| 140 | goto error; |
| 141 | if (PyModule_AddObject(module, "Error", ssl_Error) != 0) |
| 142 | goto error; |
| 143 | |
| 144 | ADD_EXCEPTION(ZeroReturnError, ssl_Error); |
| 145 | ADD_EXCEPTION(WantReadError, ssl_Error); |
| 146 | ADD_EXCEPTION(WantWriteError, ssl_Error); |
| 147 | ADD_EXCEPTION(WantX509LookupError, ssl_Error); |
| 148 | ADD_EXCEPTION(SysCallError, ssl_Error); |
| 149 | #undef ADD_EXCEPTION |
| 150 | |
| 151 | /* Method constants */ |
| 152 | PyModule_AddIntConstant(module, "SSLv2_METHOD", ssl_SSLv2_METHOD); |
| 153 | PyModule_AddIntConstant(module, "SSLv3_METHOD", ssl_SSLv3_METHOD); |
| 154 | PyModule_AddIntConstant(module, "SSLv23_METHOD", ssl_SSLv23_METHOD); |
| 155 | PyModule_AddIntConstant(module, "TLSv1_METHOD", ssl_TLSv1_METHOD); |
| 156 | |
| 157 | /* Verify constants */ |
| 158 | PyModule_AddIntConstant(module, "VERIFY_NONE", SSL_VERIFY_NONE); |
| 159 | PyModule_AddIntConstant(module, "VERIFY_PEER", SSL_VERIFY_PEER); |
| 160 | PyModule_AddIntConstant(module, "VERIFY_FAIL_IF_NO_PEER_CERT", |
| 161 | SSL_VERIFY_FAIL_IF_NO_PEER_CERT); |
| 162 | PyModule_AddIntConstant(module, "VERIFY_CLIENT_ONCE", |
| 163 | SSL_VERIFY_CLIENT_ONCE); |
| 164 | |
| 165 | /* File type constants */ |
| 166 | PyModule_AddIntConstant(module, "FILETYPE_PEM", SSL_FILETYPE_PEM); |
| 167 | PyModule_AddIntConstant(module, "FILETYPE_ASN1", SSL_FILETYPE_ASN1); |
| 168 | |
| 169 | /* SSL option constants */ |
| 170 | PyModule_AddIntConstant(module, "OP_SINGLE_DH_USE", SSL_OP_SINGLE_DH_USE); |
| 171 | PyModule_AddIntConstant(module, "OP_EPHEMERAL_RSA", SSL_OP_EPHEMERAL_RSA); |
| 172 | PyModule_AddIntConstant(module, "OP_NO_SSLv2", SSL_OP_NO_SSLv2); |
| 173 | PyModule_AddIntConstant(module, "OP_NO_SSLv3", SSL_OP_NO_SSLv3); |
| 174 | PyModule_AddIntConstant(module, "OP_NO_TLSv1", SSL_OP_NO_TLSv1); |
| 175 | |
| 176 | /* More SSL option constants */ |
| 177 | PyModule_AddIntConstant(module, "OP_MICROSOFT_SESS_ID_BUG", SSL_OP_MICROSOFT_SESS_ID_BUG); |
| 178 | PyModule_AddIntConstant(module, "OP_NETSCAPE_CHALLENGE_BUG", SSL_OP_NETSCAPE_CHALLENGE_BUG); |
| 179 | PyModule_AddIntConstant(module, "OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG", SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG); |
| 180 | PyModule_AddIntConstant(module, "OP_SSLREF2_REUSE_CERT_TYPE_BUG", SSL_OP_SSLREF2_REUSE_CERT_TYPE_BUG); |
| 181 | PyModule_AddIntConstant(module, "OP_MICROSOFT_BIG_SSLV3_BUFFER", SSL_OP_MICROSOFT_BIG_SSLV3_BUFFER); |
| 182 | PyModule_AddIntConstant(module, "OP_MSIE_SSLV2_RSA_PADDING", SSL_OP_MSIE_SSLV2_RSA_PADDING); |
| 183 | PyModule_AddIntConstant(module, "OP_SSLEAY_080_CLIENT_DH_BUG", SSL_OP_SSLEAY_080_CLIENT_DH_BUG); |
| 184 | PyModule_AddIntConstant(module, "OP_TLS_D5_BUG", SSL_OP_TLS_D5_BUG); |
| 185 | PyModule_AddIntConstant(module, "OP_TLS_BLOCK_PADDING_BUG", SSL_OP_TLS_BLOCK_PADDING_BUG); |
| 186 | PyModule_AddIntConstant(module, "OP_DONT_INSERT_EMPTY_FRAGMENTS", SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS); |
| 187 | PyModule_AddIntConstant(module, "OP_ALL", SSL_OP_ALL); |
| 188 | PyModule_AddIntConstant(module, "OP_CIPHER_SERVER_PREFERENCE", SSL_OP_CIPHER_SERVER_PREFERENCE); |
| 189 | PyModule_AddIntConstant(module, "OP_TLS_ROLLBACK_BUG", SSL_OP_TLS_ROLLBACK_BUG); |
| 190 | PyModule_AddIntConstant(module, "OP_PKCS1_CHECK_1", SSL_OP_PKCS1_CHECK_1); |
| 191 | PyModule_AddIntConstant(module, "OP_PKCS1_CHECK_2", SSL_OP_PKCS1_CHECK_2); |
| 192 | PyModule_AddIntConstant(module, "OP_NETSCAPE_CA_DN_BUG", SSL_OP_NETSCAPE_CA_DN_BUG); |
| 193 | PyModule_AddIntConstant(module, "OP_NETSCAPE_DEMO_CIPHER_CHANGE_BUG", SSL_OP_NETSCAPE_DEMO_CIPHER_CHANGE_BUG); |
| 194 | |
Jean-Paul Calderone | b43c391 | 2008-12-28 22:30:56 -0500 | [diff] [blame] | 195 | /* DTLS related options. The first two of these were introduced in |
| 196 | * 2005, the third in 2007. To accomodate systems which are still using |
| 197 | * older versions, make them optional. */ |
| 198 | #ifdef SSL_OP_NO_QUERY_MTU |
Jean-Paul Calderone | 327d8f9 | 2008-12-28 21:55:56 -0500 | [diff] [blame] | 199 | PyModule_AddIntConstant(module, "OP_NO_QUERY_MTU", SSL_OP_NO_QUERY_MTU); |
Jean-Paul Calderone | b43c391 | 2008-12-28 22:30:56 -0500 | [diff] [blame] | 200 | #endif |
| 201 | #ifdef SSL_OP_COOKIE_EXCHANGE |
Jean-Paul Calderone | 327d8f9 | 2008-12-28 21:55:56 -0500 | [diff] [blame] | 202 | PyModule_AddIntConstant(module, "OP_COOKIE_EXCHANGE", SSL_OP_COOKIE_EXCHANGE); |
Jean-Paul Calderone | b43c391 | 2008-12-28 22:30:56 -0500 | [diff] [blame] | 203 | #endif |
Jean-Paul Calderone | 327d8f9 | 2008-12-28 21:55:56 -0500 | [diff] [blame] | 204 | #ifdef SSL_OP_NO_TICKET |
| 205 | PyModule_AddIntConstant(module, "OP_NO_TICKET", SSL_OP_NO_TICKET); |
| 206 | #endif |
| 207 | |
| 208 | /* For SSL_set_shutdown */ |
Jean-Paul Calderone | 72b8f0f | 2008-02-21 23:57:40 -0500 | [diff] [blame] | 209 | PyModule_AddIntConstant(module, "SENT_SHUTDOWN", SSL_SENT_SHUTDOWN); |
| 210 | PyModule_AddIntConstant(module, "RECEIVED_SHUTDOWN", SSL_RECEIVED_SHUTDOWN); |
| 211 | |
Jean-Paul Calderone | 1bd11fa | 2009-05-27 17:09:15 -0400 | [diff] [blame] | 212 | if (!init_ssl_context(module)) |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 213 | goto error; |
Jean-Paul Calderone | 1bd11fa | 2009-05-27 17:09:15 -0400 | [diff] [blame] | 214 | if (!init_ssl_connection(module)) |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 215 | goto error; |
| 216 | |
Jean-Paul Calderone | 00db9da | 2008-09-21 17:42:34 -0400 | [diff] [blame] | 217 | #ifdef WITH_THREAD |
| 218 | /* |
| 219 | * Initialize this module's threading support structures. |
| 220 | */ |
| 221 | _pyOpenSSL_tstate_key = PyThread_create_key(); |
| 222 | #endif |
| 223 | |
Jean-Paul Calderone | b6d7525 | 2010-08-11 23:55:45 -0400 | [diff] [blame] | 224 | PyOpenSSL_MODRETURN(module); |
Jean-Paul Calderone | 83dbcfd | 2010-08-11 20:20:57 -0400 | [diff] [blame] | 225 | |
| 226 | error: |
Jean-Paul Calderone | b6d7525 | 2010-08-11 23:55:45 -0400 | [diff] [blame] | 227 | PyOpenSSL_MODRETURN(NULL); |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 228 | ; |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 229 | } |