Jean-Paul Calderone | 3de9f62 | 2008-03-12 14:12:19 -0400 | [diff] [blame] | 1 | # -*- coding: latin-1 -*- |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 2 | # |
Jean-Paul Calderone | de0a71e | 2011-03-02 19:55:11 -0500 | [diff] [blame] | 3 | # Copyright (C) AB Strakt |
| 4 | # Copyright (C) Jean-Paul Calderone |
| 5 | # See LICENSE for details. |
Jean-Paul Calderone | 8b63d45 | 2008-03-21 18:31:12 -0400 | [diff] [blame] | 6 | |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 7 | """ |
| 8 | Simple SSL client, using blocking I/O |
| 9 | """ |
| 10 | |
Hynek Schlawack | 8b7e455 | 2016-03-13 07:51:09 +0100 | [diff] [blame] | 11 | import os |
| 12 | import socket |
| 13 | import sys |
| 14 | |
Jim Shaver | b2ff5be | 2015-04-30 08:26:29 -0400 | [diff] [blame] | 15 | from OpenSSL import SSL, crypto |
Hynek Schlawack | 8b7e455 | 2016-03-13 07:51:09 +0100 | [diff] [blame] | 16 | |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 17 | |
| 18 | def verify_cb(conn, cert, errnum, depth, ok): |
Jim Shaver | b2ff5be | 2015-04-30 08:26:29 -0400 | [diff] [blame] | 19 | certsubject = crypto.X509Name(cert.get_subject()) |
| 20 | commonname = certsubject.commonName |
| 21 | print('Got certificate: ' + commonname) |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 22 | return ok |
| 23 | |
Hynek Schlawack | 8b7e455 | 2016-03-13 07:51:09 +0100 | [diff] [blame] | 24 | |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 25 | if len(sys.argv) < 3: |
Jim Shaver | 8a4a7ae | 2015-04-29 01:17:33 -0400 | [diff] [blame] | 26 | print('Usage: python client.py HOST PORT') |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 27 | sys.exit(1) |
| 28 | |
Hynek Schlawack | 8b7e455 | 2016-03-13 07:51:09 +0100 | [diff] [blame] | 29 | |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 30 | dir = os.path.dirname(sys.argv[0]) |
| 31 | if dir == '': |
| 32 | dir = os.curdir |
| 33 | |
Hynek Schlawack | 8b7e455 | 2016-03-13 07:51:09 +0100 | [diff] [blame] | 34 | |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 35 | # Initialize context |
| 36 | ctx = SSL.Context(SSL.SSLv23_METHOD) |
Daniƫl van Eeden | ae8243d | 2016-01-16 18:00:52 +0100 | [diff] [blame] | 37 | ctx.set_options(SSL.OP_NO_SSLv2) |
| 38 | ctx.set_options(SSL.OP_NO_SSLv3) |
Hynek Schlawack | 8b7e455 | 2016-03-13 07:51:09 +0100 | [diff] [blame] | 39 | ctx.set_verify(SSL.VERIFY_PEER, verify_cb) # Demand a certificate |
| 40 | ctx.use_privatekey_file(os.path.join(dir, 'client.pkey')) |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 41 | ctx.use_certificate_file(os.path.join(dir, 'client.cert')) |
| 42 | ctx.load_verify_locations(os.path.join(dir, 'CA.cert')) |
| 43 | |
| 44 | # Set up client |
| 45 | sock = SSL.Connection(ctx, socket.socket(socket.AF_INET, socket.SOCK_STREAM)) |
| 46 | sock.connect((sys.argv[1], int(sys.argv[2]))) |
| 47 | |
| 48 | while 1: |
| 49 | line = sys.stdin.readline() |
| 50 | if line == '': |
| 51 | break |
| 52 | try: |
| 53 | sock.send(line) |
Jim Shaver | b2ff5be | 2015-04-30 08:26:29 -0400 | [diff] [blame] | 54 | sys.stdout.write(sock.recv(1024).decode('utf-8')) |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 55 | sys.stdout.flush() |
| 56 | except SSL.Error: |
Jim Shaver | 71ad368 | 2015-04-29 00:09:14 -0400 | [diff] [blame] | 57 | print('Connection died unexpectedly') |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 58 | break |
| 59 | |
| 60 | |
| 61 | sock.shutdown() |
| 62 | sock.close() |