Files
digFTP/src/ssl.h
Wirlaburla 5ff35c26ab * Added plugin support
* Improved Filer (LocalFiler)
* Supports Explicit SSL/TLS with OpenSSL/Crypto
* Fixed most of the bugs that drove me nuts.
* Properly handled socket closes
* Improved socket cleanup
* Buffered file downloads
* Lots 'o errors!

I did it again! I made a single commit with everything!
2024-12-13 10:51:10 -06:00

77 lines
1.6 KiB
C++

#ifndef SSL_H
#define SSL_H
#include <openssl/ssl.h>
#include <openssl/err.h>
class SSLManager {
public:
static SSLManager& getInstance() {
static SSLManager instance;
return instance;
}
bool initialize(const std::string& cert_file, const std::string& key_file) {
// Initialize OpenSSL
SSL_library_init();
SSL_load_error_strings();
OpenSSL_add_all_algorithms();
// Create SSL context
ctx = SSL_CTX_new(TLS_server_method());
if (!ctx) {
ERR_print_errors_fp(stderr);
return false;
}
// Set SSL session caching
SSL_CTX_set_session_cache_mode(ctx, SSL_SESS_CACHE_SERVER);
SSL_CTX_set_timeout(ctx, 300);
// Set the certificate and private key
if (SSL_CTX_use_certificate_file(ctx, cert_file.c_str(), SSL_FILETYPE_PEM) <= 0) {
ERR_print_errors_fp(stderr);
return false;
}
if (SSL_CTX_use_PrivateKey_file(ctx, key_file.c_str(), SSL_FILETYPE_PEM) <= 0) {
ERR_print_errors_fp(stderr);
return false;
}
// Verify private key
if (!SSL_CTX_check_private_key(ctx)) {
fprintf(stderr, "Private key does not match the public certificate\n");
return false;
}
return true;
}
bool setFlags(int flags) {
if (SSL_CTX_set_options(ctx, flags) != 1) {
ERR_print_errors_fp(stderr);
return false;
}
return true;
}
bool setCiphers(const char* ciphers) {
if (SSL_CTX_set_cipher_list(ctx, ciphers) != 1) {
ERR_print_errors_fp(stderr);
return false;
}
return true;
}
SSL_CTX* getContext() { return ctx; }
~SSLManager() {
if (ctx) SSL_CTX_free(ctx);
EVP_cleanup();
}
private:
SSLManager() : ctx(nullptr) {}
SSL_CTX* ctx;
};
#endif