2012-04-13 12:47:30 +00:00
|
|
|
/*
|
2015-02-24 18:19:20 +00:00
|
|
|
* SSLsplit - transparent SSL/TLS interception
|
2016-03-25 11:19:23 +00:00
|
|
|
* Copyright (c) 2009-2016, Daniel Roethlisberger <daniel@roe.ch>
|
2012-04-13 12:47:30 +00:00
|
|
|
* All rights reserved.
|
|
|
|
* http://www.roe.ch/SSLsplit
|
|
|
|
*
|
|
|
|
* Redistribution and use in source and binary forms, with or without
|
|
|
|
* modification, are permitted provided that the following conditions
|
|
|
|
* are met:
|
|
|
|
* 1. Redistributions of source code must retain the above copyright
|
2015-02-24 18:19:20 +00:00
|
|
|
* notice, this list of conditions, and the following disclaimer.
|
2012-04-13 12:47:30 +00:00
|
|
|
* 2. Redistributions in binary form must reproduce the above copyright
|
|
|
|
* notice, this list of conditions and the following disclaimer in the
|
|
|
|
* documentation and/or other materials provided with the distribution.
|
|
|
|
*
|
|
|
|
* THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
|
|
|
|
* IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
|
|
|
|
* OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
|
|
|
|
* IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
|
|
|
|
* INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
|
|
|
|
* NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
|
|
|
|
* DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
|
|
|
|
* THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
|
|
|
|
* (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
|
|
|
|
* THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef OPTS_H
|
|
|
|
#define OPTS_H
|
|
|
|
|
2014-11-14 15:20:07 +00:00
|
|
|
#include "proc.h"
|
2012-04-13 12:47:30 +00:00
|
|
|
#include "nat.h"
|
|
|
|
#include "ssl.h"
|
|
|
|
#include "attrib.h"
|
|
|
|
|
|
|
|
#include <sys/types.h>
|
|
|
|
#include <sys/socket.h>
|
|
|
|
|
|
|
|
typedef struct proxyspec {
|
|
|
|
unsigned int ssl : 1;
|
|
|
|
unsigned int http : 1;
|
2015-04-21 14:00:55 +00:00
|
|
|
unsigned int upgrade: 1;
|
2017-08-03 11:55:57 +00:00
|
|
|
unsigned int mail : 1;
|
2017-08-19 22:46:57 +00:00
|
|
|
unsigned int pop3 : 1;
|
|
|
|
unsigned int smtp : 1;
|
2015-09-27 14:39:24 +00:00
|
|
|
unsigned int dns : 1; /* set if spec needs DNS lookups */
|
2012-04-13 12:47:30 +00:00
|
|
|
struct sockaddr_storage listen_addr;
|
|
|
|
socklen_t listen_addrlen;
|
|
|
|
/* connect_addr and connect_addrlen are set: static mode;
|
|
|
|
* natlookup is set: NAT mode; natsocket /may/ be set too;
|
|
|
|
* sni_port is set, in which case we use SNI lookups */
|
|
|
|
struct sockaddr_storage connect_addr;
|
|
|
|
socklen_t connect_addrlen;
|
|
|
|
unsigned short sni_port;
|
|
|
|
char *natengine;
|
|
|
|
nat_lookup_cb_t natlookup;
|
|
|
|
nat_socket_cb_t natsocket;
|
|
|
|
struct proxyspec *next;
|
2017-05-29 09:22:23 +00:00
|
|
|
|
2017-07-12 21:45:12 +00:00
|
|
|
// @todo Make these config options
|
|
|
|
struct sockaddr_storage parent_dst_addr;
|
|
|
|
socklen_t parent_dst_addrlen;
|
2017-05-29 09:22:23 +00:00
|
|
|
|
2017-07-12 21:45:12 +00:00
|
|
|
struct sockaddr_storage child_src_addr;
|
|
|
|
socklen_t child_src_addrlen;
|
2012-04-13 12:47:30 +00:00
|
|
|
} proxyspec_t;
|
|
|
|
|
|
|
|
typedef struct opts {
|
|
|
|
unsigned int debug : 1;
|
|
|
|
unsigned int detach : 1;
|
|
|
|
unsigned int sslcomp : 1;
|
2015-07-28 21:23:53 +00:00
|
|
|
#ifdef HAVE_SSLV2
|
2014-11-05 19:06:11 +00:00
|
|
|
unsigned int no_ssl2 : 1;
|
2015-07-28 21:23:53 +00:00
|
|
|
#endif /* HAVE_SSLV2 */
|
|
|
|
#ifdef HAVE_SSLV3
|
2014-11-05 19:06:11 +00:00
|
|
|
unsigned int no_ssl3 : 1;
|
2015-07-28 21:23:53 +00:00
|
|
|
#endif /* HAVE_SSLV3 */
|
|
|
|
#ifdef HAVE_TLSV10
|
2014-11-05 19:06:11 +00:00
|
|
|
unsigned int no_tls10 : 1;
|
2015-07-28 21:23:53 +00:00
|
|
|
#endif /* HAVE_TLSV10 */
|
|
|
|
#ifdef HAVE_TLSV11
|
2014-11-05 19:06:11 +00:00
|
|
|
unsigned int no_tls11 : 1;
|
2015-07-28 21:23:53 +00:00
|
|
|
#endif /* HAVE_TLSV11 */
|
|
|
|
#ifdef HAVE_TLSV12
|
2014-11-05 19:06:11 +00:00
|
|
|
unsigned int no_tls12 : 1;
|
2015-07-28 21:23:53 +00:00
|
|
|
#endif /* HAVE_TLSV12 */
|
2012-04-13 12:47:30 +00:00
|
|
|
unsigned int passthrough : 1;
|
2012-04-22 17:12:38 +00:00
|
|
|
unsigned int deny_ocsp : 1;
|
2014-11-21 11:03:08 +00:00
|
|
|
unsigned int contentlog_isdir : 1;
|
|
|
|
unsigned int contentlog_isspec : 1;
|
2014-11-14 15:20:07 +00:00
|
|
|
#ifdef HAVE_LOCAL_PROCINFO
|
|
|
|
unsigned int lprocinfo : 1;
|
|
|
|
#endif /* HAVE_LOCAL_PROCINFO */
|
2014-12-13 01:36:45 +00:00
|
|
|
unsigned int certgen_writeall: 1;
|
2012-04-13 12:47:30 +00:00
|
|
|
char *ciphers;
|
2014-12-13 01:36:45 +00:00
|
|
|
char *certgendir;
|
2012-04-13 12:47:30 +00:00
|
|
|
char *tgcrtdir;
|
|
|
|
char *dropuser;
|
2014-10-18 06:34:51 +00:00
|
|
|
char *dropgroup;
|
2012-04-13 12:47:30 +00:00
|
|
|
char *jaildir;
|
|
|
|
char *pidfile;
|
2017-08-16 13:01:52 +00:00
|
|
|
char *conffile;
|
2012-04-13 12:47:30 +00:00
|
|
|
char *connectlog;
|
2017-08-13 01:36:33 +00:00
|
|
|
int statslog;
|
2012-04-13 12:47:30 +00:00
|
|
|
char *contentlog;
|
2014-11-24 21:01:52 +00:00
|
|
|
char *contentlog_basedir; /* static part of logspec, for privsep srv */
|
2014-11-19 21:38:21 +00:00
|
|
|
CONST_SSL_METHOD *(*sslmethod)(void);
|
2012-04-13 12:47:30 +00:00
|
|
|
X509 *cacrt;
|
|
|
|
EVP_PKEY *cakey;
|
|
|
|
EVP_PKEY *key;
|
|
|
|
STACK_OF(X509) *chain;
|
|
|
|
#ifndef OPENSSL_NO_DH
|
|
|
|
DH *dh;
|
|
|
|
#endif /* !OPENSSL_NO_DH */
|
|
|
|
#ifndef OPENSSL_NO_ECDH
|
|
|
|
char *ecdhcurve;
|
|
|
|
#endif /* !OPENSSL_NO_ECDH */
|
|
|
|
proxyspec_t *spec;
|
2017-08-16 13:01:52 +00:00
|
|
|
unsigned int conn_idle_timeout;
|
|
|
|
unsigned int expired_conn_check_period;
|
|
|
|
unsigned int ssl_shutdown_retry_delay;
|
|
|
|
int log_stats;
|
|
|
|
unsigned int stats_period;
|
2012-04-13 12:47:30 +00:00
|
|
|
} opts_t;
|
|
|
|
|
|
|
|
opts_t *opts_new(void) MALLOC;
|
2014-01-06 13:28:33 +00:00
|
|
|
void opts_free(opts_t *) NONNULL(1);
|
|
|
|
int opts_has_ssl_spec(opts_t *) NONNULL(1) WUNRES;
|
2015-09-27 14:39:24 +00:00
|
|
|
int opts_has_dns_spec(opts_t *) NONNULL(1) WUNRES;
|
2014-11-05 19:06:11 +00:00
|
|
|
void opts_proto_force(opts_t *, const char *, const char *) NONNULL(1,2,3);
|
|
|
|
void opts_proto_disable(opts_t *, const char *, const char *) NONNULL(1,2,3);
|
2014-11-05 20:18:53 +00:00
|
|
|
void opts_proto_dbg_dump(opts_t *) NONNULL(1);
|
2012-05-13 13:24:50 +00:00
|
|
|
#define OPTS_DEBUG(opts) unlikely((opts)->debug)
|
2012-04-13 12:47:30 +00:00
|
|
|
|
2017-08-16 13:01:52 +00:00
|
|
|
void proxyspec_parse(int *, char **[], const char *, opts_t *);
|
|
|
|
|
2014-01-06 13:28:33 +00:00
|
|
|
void proxyspec_free(proxyspec_t *) NONNULL(1);
|
2015-03-15 21:55:34 +00:00
|
|
|
char * proxyspec_str(proxyspec_t *) NONNULL(1) MALLOC;
|
2012-04-13 12:47:30 +00:00
|
|
|
|
|
|
|
#endif /* !OPTS_H */
|
|
|
|
|
|
|
|
/* vim: set noet ft=c: */
|