1/****************************************************************************
2**
3** Copyright (C) 2016 The Qt Company Ltd.
4** Copyright (C) 2014 BlackBerry Limited. All rights reserved.
5** Contact: https://www.qt.io/licensing/
6**
7** This file is part of the QtNetwork module of the Qt Toolkit.
8**
9** $QT_BEGIN_LICENSE:LGPL$
10** Commercial License Usage
11** Licensees holding valid commercial Qt licenses may use this file in
12** accordance with the commercial license agreement provided with the
13** Software or, alternatively, in accordance with the terms contained in
14** a written agreement between you and The Qt Company. For licensing terms
15** and conditions see https://www.qt.io/terms-conditions. For further
16** information use the contact form at https://www.qt.io/contact-us.
17**
18** GNU Lesser General Public License Usage
19** Alternatively, this file may be used under the terms of the GNU Lesser
20** General Public License version 3 as published by the Free Software
21** Foundation and appearing in the file LICENSE.LGPL3 included in the
22** packaging of this file. Please review the following information to
23** ensure the GNU Lesser General Public License version 3 requirements
24** will be met: https://www.gnu.org/licenses/lgpl-3.0.html.
25**
26** GNU General Public License Usage
27** Alternatively, this file may be used under the terms of the GNU
28** General Public License version 2.0 or (at your option) the GNU General
29** Public license version 3 or any later version approved by the KDE Free
30** Qt Foundation. The licenses are as published by the Free Software
31** Foundation and appearing in the file LICENSE.GPL2 and LICENSE.GPL3
32** included in the packaging of this file. Please review the following
33** information to ensure the GNU General Public License requirements will
34** be met: https://www.gnu.org/licenses/gpl-2.0.html and
35** https://www.gnu.org/licenses/gpl-3.0.html.
36**
37** $QT_END_LICENSE$
38**
39****************************************************************************/
40
41/****************************************************************************
42**
43** In addition, as a special exception, the copyright holders listed above give
44** permission to link the code of its release of Qt with the OpenSSL project's
45** "OpenSSL" library (or modified versions of the "OpenSSL" library that use the
46** same license as the original version), and distribute the linked executables.
47**
48** You must comply with the GNU General Public License version 2 in all
49** respects for all of the code used other than the "OpenSSL" code. If you
50** modify this file, you may extend this exception to your version of the file,
51** but you are not obligated to do so. If you do not wish to do so, delete
52** this exception statement from your version of this file.
53**
54****************************************************************************/
55
56#ifndef QSSLCONFIGURATION_H
57#define QSSLCONFIGURATION_H
58
59#include <QtNetwork/qtnetworkglobal.h>
60#include <QtCore/qmap.h>
61#include <QtCore/qshareddata.h>
62#include <QtNetwork/qsslsocket.h>
63#include <QtNetwork/qssl.h>
64
65#ifndef QT_NO_SSL
66
67QT_BEGIN_NAMESPACE
68
69template<typename T> class QList;
70class QSslCertificate;
71class QSslCipher;
72class QSslKey;
73class QSslEllipticCurve;
74class QSslDiffieHellmanParameters;
75
76namespace dtlsopenssl
77{
78class DtlsState;
79}
80
81class QSslConfigurationPrivate;
82class Q_NETWORK_EXPORT QSslConfiguration
83{
84public:
85 QSslConfiguration();
86 QSslConfiguration(const QSslConfiguration &other);
87 ~QSslConfiguration();
88 QSslConfiguration &operator=(QSslConfiguration &&other) noexcept { swap(other); return *this; }
89 QSslConfiguration &operator=(const QSslConfiguration &other);
90
91 void swap(QSslConfiguration &other) noexcept
92 { qSwap(d, other.d); }
93
94 bool operator==(const QSslConfiguration &other) const;
95 inline bool operator!=(const QSslConfiguration &other) const
96 { return !(*this == other); }
97
98 bool isNull() const;
99
100 QSsl::SslProtocol protocol() const;
101 void setProtocol(QSsl::SslProtocol protocol);
102
103 // Verification
104 QSslSocket::PeerVerifyMode peerVerifyMode() const;
105 void setPeerVerifyMode(QSslSocket::PeerVerifyMode mode);
106
107 int peerVerifyDepth() const;
108 void setPeerVerifyDepth(int depth);
109
110 // Certificate & cipher configuration
111 QList<QSslCertificate> localCertificateChain() const;
112 void setLocalCertificateChain(const QList<QSslCertificate> &localChain);
113
114 QSslCertificate localCertificate() const;
115 void setLocalCertificate(const QSslCertificate &certificate);
116
117 QSslCertificate peerCertificate() const;
118 QList<QSslCertificate> peerCertificateChain() const;
119 QSslCipher sessionCipher() const;
120 QSsl::SslProtocol sessionProtocol() const;
121
122 // Private keys, for server sockets
123 QSslKey privateKey() const;
124 void setPrivateKey(const QSslKey &key);
125
126 // Cipher settings
127 QList<QSslCipher> ciphers() const;
128 void setCiphers(const QList<QSslCipher> &ciphers);
129 static QList<QSslCipher> supportedCiphers();
130
131 // Certificate Authority (CA) settings
132 QList<QSslCertificate> caCertificates() const;
133 void setCaCertificates(const QList<QSslCertificate> &certificates);
134 static QList<QSslCertificate> systemCaCertificates();
135
136 void setSslOption(QSsl::SslOption option, bool on);
137 bool testSslOption(QSsl::SslOption option) const;
138
139 QByteArray sessionTicket() const;
140 void setSessionTicket(const QByteArray &sessionTicket);
141 int sessionTicketLifeTimeHint() const;
142
143 QSslKey ephemeralServerKey() const;
144
145 // EC settings
146 QVector<QSslEllipticCurve> ellipticCurves() const;
147 void setEllipticCurves(const QVector<QSslEllipticCurve> &curves);
148 static QVector<QSslEllipticCurve> supportedEllipticCurves();
149
150 QByteArray preSharedKeyIdentityHint() const;
151 void setPreSharedKeyIdentityHint(const QByteArray &hint);
152
153 QSslDiffieHellmanParameters diffieHellmanParameters() const;
154 void setDiffieHellmanParameters(const QSslDiffieHellmanParameters &dhparams);
155
156 QMap<QByteArray, QVariant> backendConfiguration() const;
157 void setBackendConfigurationOption(const QByteArray &name, const QVariant &value);
158 void setBackendConfiguration(const QMap<QByteArray, QVariant> &backendConfiguration = QMap<QByteArray, QVariant>());
159
160 static QSslConfiguration defaultConfiguration();
161 static void setDefaultConfiguration(const QSslConfiguration &configuration);
162
163#if QT_CONFIG(dtls) || defined(Q_CLANG_QDOC)
164 bool dtlsCookieVerificationEnabled() const;
165 void setDtlsCookieVerificationEnabled(bool enable);
166
167 static QSslConfiguration defaultDtlsConfiguration();
168 static void setDefaultDtlsConfiguration(const QSslConfiguration &configuration);
169#endif // dtls
170
171 void setOcspStaplingEnabled(bool enable);
172 bool ocspStaplingEnabled() const;
173
174 enum NextProtocolNegotiationStatus {
175 NextProtocolNegotiationNone,
176 NextProtocolNegotiationNegotiated,
177 NextProtocolNegotiationUnsupported
178 };
179
180#if QT_VERSION >= QT_VERSION_CHECK(6,0,0)
181 void setAllowedNextProtocols(const QList<QByteArray> &protocols);
182#else
183 void setAllowedNextProtocols(QList<QByteArray> protocols);
184#endif
185 QList<QByteArray> allowedNextProtocols() const;
186
187 QByteArray nextNegotiatedProtocol() const;
188 NextProtocolNegotiationStatus nextProtocolNegotiationStatus() const;
189
190 static const char ALPNProtocolHTTP2[];
191 static const char NextProtocolSpdy3_0[];
192 static const char NextProtocolHttp1_1[];
193
194private:
195 friend class QSslSocket;
196 friend class QSslConfigurationPrivate;
197 friend class QSslSocketBackendPrivate;
198 friend class QSslContext;
199 friend class QDtlsBasePrivate;
200 friend class dtlsopenssl::DtlsState;
201 QSslConfiguration(QSslConfigurationPrivate *dd);
202 QSharedDataPointer<QSslConfigurationPrivate> d;
203};
204
205Q_DECLARE_SHARED(QSslConfiguration)
206
207QT_END_NAMESPACE
208
209Q_DECLARE_METATYPE(QSslConfiguration)
210
211#endif // QT_NO_SSL
212
213#endif
214