mirror of https://github.com/grpc/grpc.git
Merge pull request #990 from jtattermusch/csharp_tls_server
C# server-side TLS supportpull/1012/head
commit
6063b9ff52
13 changed files with 336 additions and 21 deletions
@ -0,0 +1,68 @@ |
||||
#region Copyright notice and license |
||||
// Copyright 2015, Google Inc. |
||||
// All rights reserved. |
||||
// |
||||
// Redistribution and use in source and binary forms, with or without |
||||
// modification, are permitted provided that the following conditions are |
||||
// met: |
||||
// |
||||
// * Redistributions of source code must retain the above copyright |
||||
// notice, this list of conditions and the following disclaimer. |
||||
// * Redistributions in binary form must reproduce the above |
||||
// copyright notice, this list of conditions and the following disclaimer |
||||
// in the documentation and/or other materials provided with the |
||||
// distribution. |
||||
// * Neither the name of Google Inc. nor the names of its |
||||
// contributors may be used to endorse or promote products derived from |
||||
// this software without specific prior written permission. |
||||
// |
||||
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
||||
// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
||||
// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR |
||||
// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT |
||||
// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
||||
// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT |
||||
// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
||||
// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
||||
// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
||||
// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
||||
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
||||
#endregion |
||||
using System; |
||||
using System.Runtime.InteropServices; |
||||
using System.Threading; |
||||
using System.Threading.Tasks; |
||||
using Grpc.Core.Utils; |
||||
|
||||
namespace Grpc.Core.Internal |
||||
{ |
||||
/// <summary> |
||||
/// grpc_server_credentials from <grpc/grpc_security.h> |
||||
/// </summary> |
||||
internal class ServerCredentialsSafeHandle : SafeHandleZeroIsInvalid |
||||
{ |
||||
[DllImport("grpc_csharp_ext.dll", CharSet = CharSet.Ansi)] |
||||
static extern ServerCredentialsSafeHandle grpcsharp_ssl_server_credentials_create(string pemRootCerts, string[] keyCertPairCertChainArray, string[] keyCertPairPrivateKeyArray, UIntPtr numKeyCertPairs); |
||||
|
||||
[DllImport("grpc_csharp_ext.dll")] |
||||
static extern void grpcsharp_server_credentials_release(IntPtr credentials); |
||||
|
||||
private ServerCredentialsSafeHandle() |
||||
{ |
||||
} |
||||
|
||||
public static ServerCredentialsSafeHandle CreateSslCredentials(string[] keyCertPairCertChainArray, string[] keyCertPairPrivateKeyArray) |
||||
{ |
||||
Preconditions.CheckArgument(keyCertPairCertChainArray.Length == keyCertPairPrivateKeyArray.Length); |
||||
return grpcsharp_ssl_server_credentials_create(null, |
||||
keyCertPairCertChainArray, keyCertPairPrivateKeyArray, |
||||
new UIntPtr((ulong)keyCertPairCertChainArray.Length)); |
||||
} |
||||
|
||||
protected override bool ReleaseHandle() |
||||
{ |
||||
grpcsharp_server_credentials_release(handle); |
||||
return true; |
||||
} |
||||
} |
||||
} |
@ -0,0 +1,107 @@ |
||||
#region Copyright notice and license |
||||
|
||||
// Copyright 2015, Google Inc. |
||||
// All rights reserved. |
||||
// |
||||
// Redistribution and use in source and binary forms, with or without |
||||
// modification, are permitted provided that the following conditions are |
||||
// met: |
||||
// |
||||
// * Redistributions of source code must retain the above copyright |
||||
// notice, this list of conditions and the following disclaimer. |
||||
// * Redistributions in binary form must reproduce the above |
||||
// copyright notice, this list of conditions and the following disclaimer |
||||
// in the documentation and/or other materials provided with the |
||||
// distribution. |
||||
// * Neither the name of Google Inc. nor the names of its |
||||
// contributors may be used to endorse or promote products derived from |
||||
// this software without specific prior written permission. |
||||
// |
||||
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
||||
// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
||||
// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR |
||||
// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT |
||||
// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
||||
// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT |
||||
// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
||||
// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
||||
// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
||||
// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
||||
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
||||
|
||||
#endregion |
||||
|
||||
using System; |
||||
using System.Collections.Generic; |
||||
using Grpc.Core.Internal; |
||||
|
||||
namespace Grpc.Core |
||||
{ |
||||
public abstract class ServerCredentials |
||||
{ |
||||
/// <summary> |
||||
/// Creates native object for the credentials. |
||||
/// </summary> |
||||
/// <returns>The native credentials.</returns> |
||||
internal abstract ServerCredentialsSafeHandle ToNativeCredentials(); |
||||
} |
||||
|
||||
/// <summary> |
||||
/// Key certificate pair (in PEM encoding). |
||||
/// </summary> |
||||
public class KeyCertificatePair |
||||
{ |
||||
string certChain; |
||||
string privateKey; |
||||
|
||||
public KeyCertificatePair(string certChain, string privateKey) |
||||
{ |
||||
this.certChain = certChain; |
||||
this.privateKey = privateKey; |
||||
} |
||||
|
||||
public string CertChain |
||||
{ |
||||
get |
||||
{ |
||||
return certChain; |
||||
} |
||||
} |
||||
|
||||
public string PrivateKey |
||||
{ |
||||
get |
||||
{ |
||||
return privateKey; |
||||
} |
||||
} |
||||
} |
||||
|
||||
/// <summary> |
||||
/// Server-side SSL credentials. |
||||
/// </summary> |
||||
public class SslServerCredentials : ServerCredentials |
||||
{ |
||||
// TODO: immutable list... |
||||
List<KeyCertificatePair> keyCertPairs; |
||||
|
||||
public SslServerCredentials(List<KeyCertificatePair> keyCertPairs) |
||||
{ |
||||
this.keyCertPairs = keyCertPairs; |
||||
} |
||||
|
||||
internal override ServerCredentialsSafeHandle ToNativeCredentials() |
||||
{ |
||||
int count = keyCertPairs.Count; |
||||
string[] certChains = new string[count]; |
||||
string[] keys = new string[count]; |
||||
for (int i = 0; i < count; i++) |
||||
{ |
||||
certChains[i] = keyCertPairs[i].CertChain; |
||||
keys[i] = keyCertPairs[i].PrivateKey; |
||||
} |
||||
return ServerCredentialsSafeHandle.CreateSslCredentials(certChains, keys); |
||||
} |
||||
} |
||||
} |
||||
|
@ -0,0 +1,83 @@ |
||||
#region Copyright notice and license |
||||
|
||||
// Copyright 2015, Google Inc. |
||||
// All rights reserved. |
||||
// |
||||
// Redistribution and use in source and binary forms, with or without |
||||
// modification, are permitted provided that the following conditions are |
||||
// met: |
||||
// |
||||
// * Redistributions of source code must retain the above copyright |
||||
// notice, this list of conditions and the following disclaimer. |
||||
// * Redistributions in binary form must reproduce the above |
||||
// copyright notice, this list of conditions and the following disclaimer |
||||
// in the documentation and/or other materials provided with the |
||||
// distribution. |
||||
// * Neither the name of Google Inc. nor the names of its |
||||
// contributors may be used to endorse or promote products derived from |
||||
// this software without specific prior written permission. |
||||
// |
||||
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
||||
// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
||||
// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR |
||||
// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT |
||||
// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
||||
// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT |
||||
// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
||||
// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
||||
// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
||||
// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
||||
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
||||
|
||||
#endregion |
||||
|
||||
using System; |
||||
using System.Collections.Generic; |
||||
using System.Diagnostics; |
||||
using System.IO; |
||||
using System.Text.RegularExpressions; |
||||
using System.Threading.Tasks; |
||||
using Google.ProtocolBuffers; |
||||
using Grpc.Core; |
||||
using Grpc.Core.Utils; |
||||
using NUnit.Framework; |
||||
using grpc.testing; |
||||
|
||||
namespace Grpc.IntegrationTesting |
||||
{ |
||||
/// <summary> |
||||
/// SSL Credentials for testing. |
||||
/// </summary> |
||||
public static class TestCredentials |
||||
{ |
||||
public const string DefaultHostOverride = "foo.test.google.fr"; |
||||
|
||||
public const string ClientCertAuthorityPath = "data/ca.pem"; |
||||
public const string ClientCertAuthorityEnvName = "SSL_CERT_FILE"; |
||||
|
||||
public const string ServerCertChainPath = "data/server1.pem"; |
||||
public const string ServerPrivateKeyPath = "data/server1.key"; |
||||
|
||||
public static SslCredentials CreateTestClientCredentials(bool useTestCa) |
||||
{ |
||||
string caPath = ClientCertAuthorityPath; |
||||
if (!useTestCa) |
||||
{ |
||||
caPath = Environment.GetEnvironmentVariable(ClientCertAuthorityEnvName); |
||||
if (string.IsNullOrEmpty(caPath)) |
||||
{ |
||||
throw new ArgumentException("CA path environment variable is not set."); |
||||
} |
||||
} |
||||
return new SslCredentials(File.ReadAllText(caPath)); |
||||
} |
||||
|
||||
public static SslServerCredentials CreateTestServerCredentials() |
||||
{ |
||||
var keyCertPair = new KeyCertificatePair( |
||||
File.ReadAllText(ServerCertChainPath), |
||||
File.ReadAllText(ServerPrivateKeyPath)); |
||||
return new SslServerCredentials(new List<KeyCertificatePair> {keyCertPair}); |
||||
} |
||||
} |
||||
} |
Loading…
Reference in new issue