InvalidCertificateHandler.h 4.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102
  1. //
  2. // InvalidCertificateHandler.h
  3. //
  4. // $Id: //poco/1.4/NetSSL_OpenSSL/include/Poco/Net/InvalidCertificateHandler.h#1 $
  5. //
  6. // Library: NetSSL_OpenSSL
  7. // Package: SSLCore
  8. // Module: InvalidCertificateHandler
  9. //
  10. // Definition of the InvalidCertificateHandler class.
  11. //
  12. // Copyright (c) 2006-2009, Applied Informatics Software Engineering GmbH.
  13. // and Contributors.
  14. //
  15. // Permission is hereby granted, free of charge, to any person or organization
  16. // obtaining a copy of the software and accompanying documentation covered by
  17. // this license (the "Software") to use, reproduce, display, distribute,
  18. // execute, and transmit the Software, and to prepare derivative works of the
  19. // Software, and to permit third-parties to whom the Software is furnished to
  20. // do so, all subject to the following:
  21. //
  22. // The copyright notices in the Software and this entire statement, including
  23. // the above license grant, this restriction and the following disclaimer,
  24. // must be included in all copies of the Software, in whole or in part, and
  25. // all derivative works of the Software, unless such copies or derivative
  26. // works are solely in the form of machine-executable object code generated by
  27. // a source language processor.
  28. //
  29. // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
  30. // IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
  31. // FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT. IN NO EVENT
  32. // SHALL THE COPYRIGHT HOLDERS OR ANYONE DISTRIBUTING THE SOFTWARE BE LIABLE
  33. // FOR ANY DAMAGES OR OTHER LIABILITY, WHETHER IN CONTRACT, TORT OR OTHERWISE,
  34. // ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
  35. // DEALINGS IN THE SOFTWARE.
  36. //
  37. #ifndef NetSSL_InvalidCertificateHandler_INCLUDED
  38. #define NetSSL_InvalidCertificateHandler_INCLUDED
  39. #include "Poco/Net/NetSSL.h"
  40. #include "Poco/Net/VerificationErrorArgs.h"
  41. namespace Poco {
  42. namespace Net {
  43. class NetSSL_API InvalidCertificateHandler
  44. /// A InvalidCertificateHandler is invoked whenever an error occurs verifying the certificate. It allows the user
  45. /// to inspect and accept/reject the certificate.
  46. /// One can install one's own InvalidCertificateHandler by implementing this interface. Note that
  47. /// in the implementation file of the subclass the following code must be present (assuming you use the namespace My_API
  48. /// and the name of your handler class is MyGuiHandler):
  49. ///
  50. /// #include "Poco/Net/CertificateHandlerFactory.h"
  51. /// ...
  52. /// POCO_REGISTER_CHFACTORY(My_API, MyGuiHandler)
  53. ///
  54. /// One can either set the handler directly in the startup code of the main method of ones application by calling
  55. ///
  56. /// SSLManager::instance().initialize(mypassphraseHandler, myguiHandler, mySSLContext)
  57. ///
  58. /// or in case one uses Poco::Util::Application one can rely on an XML configuration and put the following entry
  59. /// under the path openSSL.invalidCertificateHandler:
  60. ///
  61. /// <invalidCertificateHandler>
  62. /// <name>MyGuiHandler<name>
  63. /// <options>
  64. /// [...] // Put optional config params for the handler here
  65. /// </options>
  66. /// </invalidCertificateHandler>
  67. ///
  68. /// Note that the name of the InvalidCertificateHandler must be same as the one provided to the POCO_REGISTER_CHFACTORY macro.
  69. {
  70. public:
  71. InvalidCertificateHandler(bool handleErrorsOnServerSide);
  72. /// Creates the InvalidCertificateHandler.
  73. ///
  74. /// Set handleErrorsOnServerSide to true if the certificate handler is used on the server side.
  75. /// Automatically registers at one of the SSLManager::VerificationError events.
  76. virtual ~InvalidCertificateHandler();
  77. /// Destroys the InvalidCertificateHandler.
  78. virtual void onInvalidCertificate(const void* pSender, VerificationErrorArgs& errorCert) = 0;
  79. /// Receives the questionable certificate in parameter errorCert. If one wants to accept the
  80. /// certificate, call errorCert.setIgnoreError(true).
  81. protected:
  82. bool _handleErrorsOnServerSide;
  83. /// Stores if the certificate handler gets invoked by the server (i.e. a client certificate is wrong)
  84. /// or the client (a server certificate is wrong)
  85. };
  86. } } // namespace Poco::Net
  87. #endif // NetSSL_InvalidCertificateHandler_INCLUDED