77 lines
1.6 KiB
C
77 lines
1.6 KiB
C
|
|
#ifndef SSL_H
|
||
|
|
#define SSL_H
|
||
|
|
#include <openssl/ssl.h>
|
||
|
|
#include <openssl/err.h>
|
||
|
|
|
||
|
|
class SSLManager {
|
||
|
|
public:
|
||
|
|
static SSLManager& getInstance() {
|
||
|
|
static SSLManager instance;
|
||
|
|
return instance;
|
||
|
|
}
|
||
|
|
|
||
|
|
bool initialize(const std::string& cert_file, const std::string& key_file) {
|
||
|
|
// Initialize OpenSSL
|
||
|
|
SSL_library_init();
|
||
|
|
SSL_load_error_strings();
|
||
|
|
OpenSSL_add_all_algorithms();
|
||
|
|
|
||
|
|
// Create SSL context
|
||
|
|
ctx = SSL_CTX_new(TLS_server_method());
|
||
|
|
if (!ctx) {
|
||
|
|
ERR_print_errors_fp(stderr);
|
||
|
|
return false;
|
||
|
|
}
|
||
|
|
|
||
|
|
// Set SSL session caching
|
||
|
|
SSL_CTX_set_session_cache_mode(ctx, SSL_SESS_CACHE_SERVER);
|
||
|
|
SSL_CTX_set_timeout(ctx, 300);
|
||
|
|
|
||
|
|
// Set the certificate and private key
|
||
|
|
if (SSL_CTX_use_certificate_file(ctx, cert_file.c_str(), SSL_FILETYPE_PEM) <= 0) {
|
||
|
|
ERR_print_errors_fp(stderr);
|
||
|
|
return false;
|
||
|
|
}
|
||
|
|
|
||
|
|
if (SSL_CTX_use_PrivateKey_file(ctx, key_file.c_str(), SSL_FILETYPE_PEM) <= 0) {
|
||
|
|
ERR_print_errors_fp(stderr);
|
||
|
|
return false;
|
||
|
|
}
|
||
|
|
|
||
|
|
// Verify private key
|
||
|
|
if (!SSL_CTX_check_private_key(ctx)) {
|
||
|
|
fprintf(stderr, "Private key does not match the public certificate\n");
|
||
|
|
return false;
|
||
|
|
}
|
||
|
|
|
||
|
|
return true;
|
||
|
|
}
|
||
|
|
|
||
|
|
bool setFlags(int flags) {
|
||
|
|
if (SSL_CTX_set_options(ctx, flags) != 1) {
|
||
|
|
ERR_print_errors_fp(stderr);
|
||
|
|
return false;
|
||
|
|
}
|
||
|
|
return true;
|
||
|
|
}
|
||
|
|
|
||
|
|
bool setCiphers(const char* ciphers) {
|
||
|
|
if (SSL_CTX_set_cipher_list(ctx, ciphers) != 1) {
|
||
|
|
ERR_print_errors_fp(stderr);
|
||
|
|
return false;
|
||
|
|
}
|
||
|
|
return true;
|
||
|
|
}
|
||
|
|
|
||
|
|
SSL_CTX* getContext() { return ctx; }
|
||
|
|
|
||
|
|
~SSLManager() {
|
||
|
|
if (ctx) SSL_CTX_free(ctx);
|
||
|
|
EVP_cleanup();
|
||
|
|
}
|
||
|
|
|
||
|
|
private:
|
||
|
|
SSLManager() : ctx(nullptr) {}
|
||
|
|
SSL_CTX* ctx;
|
||
|
|
};
|
||
|
|
#endif
|