summaryrefslogtreecommitdiff
path: root/src/libtls/tls_server.h
blob: d6b8de153fea6c429379fabadfb404c6e7b91492 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
/*
 * Copyright (C) 2010 Martin Willi
 * Copyright (C) 2010 revosec AG
 *
 * This program is free software; you can redistribute it and/or modify it
 * under the terms of the GNU General Public License as published by the
 * Free Software Foundation; either version 2 of the License, or (at your
 * option) any later version.  See <http://www.fsf.org/copyleft/gpl.txt>.
 *
 * This program is distributed in the hope that it will be useful, but
 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
 * or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
 * for more details.
 */

/**
 * @defgroup tls_server tls_server
 * @{ @ingroup libtls
 */

#ifndef TLS_SERVER_H_
#define TLS_SERVER_H_

typedef struct tls_server_t tls_server_t;

#include "tls_handshake.h"
#include "tls_crypto.h"

#include <library.h>

/**
 * TLS handshake protocol handler as peer.
 */
struct tls_server_t {

	/**
	 * Implements the TLS handshake protocol handler.
	 */
	tls_handshake_t handshake;
};

/**
 * Create a tls_server instance.
 *
 * If a peer identity is given, the client must authenticate with a valid
 * certificate for this identity, or the connection fails. If peer is NULL,
 * but the client authenticates nonetheless, the authenticated identity
 * gets returned by tls_handshake_t.get_peer_id().
 *
 * @param tls		TLS stack
 * @param crypto	TLS crypto helper
 * @param alert		TLS alert handler
 * @param server	server identity
 * @param peer		peer identity, or NULL
 */
tls_server_t *tls_server_create(tls_t *tls,
						tls_crypto_t *crypto, tls_alert_t *alert,
						identification_t *server, identification_t *peer);

#endif /** TLS_SERVER_H_ @}*/