diff options
author | Andrey Suvorov <a.suvorov@f5.com> | 2021-08-17 16:52:32 -0700 |
---|---|---|
committer | Andrey Suvorov <a.suvorov@f5.com> | 2021-08-17 16:52:32 -0700 |
commit | e0aa132172f03fe7c31484ce7d301813b5dacb89 (patch) | |
tree | 86c83ac1ffc2c842d99aca6ba47c7d7ad67ca82d /src/nxt_tls.h | |
parent | 3bd60e317c142f4596bdc0ef4747ea0f2cc03503 (diff) | |
download | unit-e0aa132172f03fe7c31484ce7d301813b5dacb89.tar.gz unit-e0aa132172f03fe7c31484ce7d301813b5dacb89.tar.bz2 |
Added TLS session tickets support.
Diffstat (limited to 'src/nxt_tls.h')
-rw-r--r-- | src/nxt_tls.h | 21 |
1 files changed, 21 insertions, 0 deletions
diff --git a/src/nxt_tls.h b/src/nxt_tls.h index a92f1c21..eeb4e7ba 100644 --- a/src/nxt_tls.h +++ b/src/nxt_tls.h @@ -29,6 +29,8 @@ typedef struct nxt_tls_conf_s nxt_tls_conf_t; typedef struct nxt_tls_bundle_conf_s nxt_tls_bundle_conf_t; typedef struct nxt_tls_init_s nxt_tls_init_t; +typedef struct nxt_tls_ticket_s nxt_tls_ticket_t; +typedef struct nxt_tls_tickets_s nxt_tls_tickets_t; typedef struct { nxt_int_t (*library_init)(nxt_task_t *task); @@ -63,6 +65,8 @@ struct nxt_tls_conf_s { nxt_tls_bundle_conf_t *bundle; nxt_lvlhsh_t bundle_hash; + nxt_tls_tickets_t *tickets; + void (*conn_init)(nxt_task_t *task, nxt_tls_conf_t *conf, nxt_conn_t *c); @@ -82,17 +86,34 @@ struct nxt_tls_init_s { size_t cache_size; nxt_time_t timeout; nxt_conf_value_t *conf_cmds; + nxt_conf_value_t *tickets_conf; nxt_tls_conf_t *conf; }; +struct nxt_tls_ticket_s { + uint8_t aes128; + u_char name[16]; + u_char hmac_key[32]; + u_char aes_key[32]; +}; + + +struct nxt_tls_tickets_s { + nxt_uint_t count; + nxt_tls_ticket_t tickets[]; +}; + + #if (NXT_HAVE_OPENSSL) extern const nxt_tls_lib_t nxt_openssl_lib; void nxt_cdecl nxt_openssl_log_error(nxt_task_t *task, nxt_uint_t level, const char *fmt, ...); u_char *nxt_openssl_copy_error(u_char *p, u_char *end); +nxt_int_t nxt_openssl_base64_decode(u_char *d, size_t dlen, const u_char *s, + size_t slen); #endif #if (NXT_HAVE_GNUTLS) |