#ifndef SSL_H #define SSL_H #include #include class SSLManager { public: static SSLManager& getInstance() { static SSLManager instance; return instance; } bool initialize(const std::string& cert_file, const std::string& key_file) { // Initialize OpenSSL SSL_library_init(); SSL_load_error_strings(); OpenSSL_add_all_algorithms(); // Create SSL context ctx = SSL_CTX_new(TLS_server_method()); if (!ctx) { ERR_print_errors_fp(stderr); return false; } // Set SSL session caching SSL_CTX_set_session_cache_mode(ctx, SSL_SESS_CACHE_SERVER); SSL_CTX_set_timeout(ctx, 300); // Set the certificate and private key if (SSL_CTX_use_certificate_file(ctx, cert_file.c_str(), SSL_FILETYPE_PEM) <= 0) { ERR_print_errors_fp(stderr); return false; } if (SSL_CTX_use_PrivateKey_file(ctx, key_file.c_str(), SSL_FILETYPE_PEM) <= 0) { ERR_print_errors_fp(stderr); return false; } // Verify private key if (!SSL_CTX_check_private_key(ctx)) { fprintf(stderr, "Private key does not match the public certificate\n"); return false; } return true; } bool setFlags(int flags) { if (SSL_CTX_set_options(ctx, flags) != 1) { ERR_print_errors_fp(stderr); return false; } return true; } bool setCiphers(const char* ciphers) { if (SSL_CTX_set_cipher_list(ctx, ciphers) != 1) { ERR_print_errors_fp(stderr); return false; } return true; } SSL_CTX* getContext() { return ctx; } ~SSLManager() { if (ctx) SSL_CTX_free(ctx); EVP_cleanup(); } private: SSLManager() : ctx(nullptr) {} SSL_CTX* ctx; }; #endif