Files
digFTP/src/ssl.h

77 lines
1.6 KiB
C
Raw Normal View History

#ifndef SSL_H
#define SSL_H
#include <openssl/ssl.h>
#include <openssl/err.h>
class SSLManager {
public:
static SSLManager& getInstance() {
static SSLManager instance;
return instance;
}
bool initialize(const std::string& cert_file, const std::string& key_file) {
// Initialize OpenSSL
SSL_library_init();
SSL_load_error_strings();
OpenSSL_add_all_algorithms();
// Create SSL context
ctx = SSL_CTX_new(TLS_server_method());
if (!ctx) {
ERR_print_errors_fp(stderr);
return false;
}
// Set SSL session caching
SSL_CTX_set_session_cache_mode(ctx, SSL_SESS_CACHE_SERVER);
SSL_CTX_set_timeout(ctx, 300);
// Set the certificate and private key
if (SSL_CTX_use_certificate_file(ctx, cert_file.c_str(), SSL_FILETYPE_PEM) <= 0) {
ERR_print_errors_fp(stderr);
return false;
}
if (SSL_CTX_use_PrivateKey_file(ctx, key_file.c_str(), SSL_FILETYPE_PEM) <= 0) {
ERR_print_errors_fp(stderr);
return false;
}
// Verify private key
if (!SSL_CTX_check_private_key(ctx)) {
fprintf(stderr, "Private key does not match the public certificate\n");
return false;
}
return true;
}
bool setFlags(int flags) {
if (SSL_CTX_set_options(ctx, flags) != 1) {
ERR_print_errors_fp(stderr);
return false;
}
return true;
}
bool setCiphers(const char* ciphers) {
if (SSL_CTX_set_cipher_list(ctx, ciphers) != 1) {
ERR_print_errors_fp(stderr);
return false;
}
return true;
}
SSL_CTX* getContext() { return ctx; }
~SSLManager() {
if (ctx) SSL_CTX_free(ctx);
EVP_cleanup();
}
private:
SSLManager() : ctx(nullptr) {}
SSL_CTX* ctx;
};
#endif