TSDuck v3.45-4766
MPEG Transport Stream Toolkit
Loading...
Searching...
No Matches
ts::TLSCertificate Class Reference

Encapsulate a SSL/TLS server certificate. More...

#include <tsTLSCertificate.h>

Inheritance diagram for ts::TLSCertificate:
Collaboration diagram for ts::TLSCertificate:

Public Member Functions

 TLSCertificate (Report *report)
 Constructor.
 
 TLSCertificate (ReporterBase *delegate)
 Constructor.
 
virtual ~TLSCertificate () override
 Destructor.
 
bool createEphemeralCertificate (size_t rsa_bits)
 Create an ephemeral self-signed certificate.
 
void * getCertificate () const
 Get the certificate context, for usage in OpenSSL (UNIX) or SChannel (Windows).
 
bool initServerCertificate (const TLSServerBase &params)
 Initialize (get or create) a server certificate, if not already done.
 
bool isValid () const
 Check if a certificate is loaded and valid.
 
bool loadCertificate (const UString &certificate_path, const UString &key_path, const UString &store_name)
 Load a certificate from a store.
 
bool muteReport (bool mute)
 Temporarily mute the associated report.
 
virtual Reportreport () const override
 Access the Report which is associated with this object.
 
void reset ()
 Reset the content of the certificate.
 
ReportsetReport (Report *report)
 Associate this object with another Report to log errors.
 
ReporterBasesetReport (ReporterBase *delegate)
 Associate this object with another ReporterBase to log errors.
 

Static Public Member Functions

static int SilentLevel (bool silent, int default_severity=Severity::Error)
 Compute a log severity level from a "silent" parameter.
 

Detailed Description

Encapsulate a SSL/TLS server certificate.

Constructor & Destructor Documentation

◆ TLSCertificate() [1/2]

ts::TLSCertificate::TLSCertificate ( Report report)
explicit

Constructor.

Parameters
[in]reportWhere to report errors. The report object must remain valid as long as this object exists or setReport() is used with another Report object. If report is null, log messages are discarded.

◆ TLSCertificate() [2/2]

ts::TLSCertificate::TLSCertificate ( ReporterBase delegate)
explicit

Constructor.

Parameters
[in]delegateUse the report of another ReporterBase. If delegate is null, log messages are discarded.

Member Function Documentation

◆ getCertificate()

void * ts::TLSCertificate::getCertificate ( ) const

Get the certificate context, for usage in OpenSSL (UNIX) or SChannel (Windows).

Returns
The certificate context, or a null pointer if none is available.
  • On UNIX systems with OpenSSL, a pointer to SSL_CTX.
  • On Windows systems whith SChannel, a pointer to CERT_CONTEXT.

◆ isValid()

bool ts::TLSCertificate::isValid ( ) const
inline

Check if a certificate is loaded and valid.

Returns
Trues if a certificate is loaded and valid, false otherwise.

◆ createEphemeralCertificate()

bool ts::TLSCertificate::createEphemeralCertificate ( size_t  rsa_bits)

Create an ephemeral self-signed certificate.

The previous certificate, if any, is replaced.

Parameters
[in]rsa_bitsSize in bits of the RSA key to create for the certificate.
Returns
True on success, false on error.

◆ loadCertificate()

bool ts::TLSCertificate::loadCertificate ( const UString certificate_path,
const UString key_path,
const UString store_name 
)

Load a certificate from a store.

The previous certificate, if any, is replaced.

Parameters
[in]certificate_pathPath to the certificate.
  • On UNIX systems (with OpenSSL), this is the path name of the certificate file in PEM format.
  • On Windows, this is the name of a certificate, either its "friendly name", its subject name (without "CN="), its DNS name.
[in]key_pathPath to the private key.
  • On UNIX systems (with OpenSSL), this is the path name of the private key file in PEM format.
  • On Windows, the private key is retrieved with the certificate and this parameter is unused.
[in]store_nameName of certificate store.
  • On UNIX systems (with OpenSSL), this parameter is unused.
  • On Windows, the possible values are "system" (Cert:\LocalMachine\My) and "user" (Cert:\CurrentUser\My). The default is "user".
Returns
True on success, false on error.

◆ initServerCertificate()

bool ts::TLSCertificate::initServerCertificate ( const TLSServerBase params)

Initialize (get or create) a server certificate, if not already done.

If a certificate is already present, don't replace it.

Parameters
[in]paramsServer parameters.
Returns
True on success, false on error.

◆ report()

virtual Report & ts::ReporterBase::report ( ) const
overridevirtualinherited

Access the Report which is associated with this object.

Can be called from another thread only if the Report object is thread-safe.

Returns
A reference to the associated report.

Implements ts::ReporterInterface.

◆ setReport() [1/2]

Report * ts::ReporterBase::setReport ( Report report)
inherited

Associate this object with another Report to log errors.

Parameters
[in]reportWhere to report errors. The report object must remain valid as long as this object exists or setReport() is used with another Report object. If report is null, log messages are discarded.
Returns
The address of the previous Report object or a null pointer if there was none.

◆ setReport() [2/2]

ReporterBase * ts::ReporterBase::setReport ( ReporterBase delegate)
inherited

Associate this object with another ReporterBase to log errors.

Parameters
[in]delegateUse the report of another ReporterBase. If delegate is null, the previous explicit Report is used..
Returns
The address of the previous ReporterBase object or a null pointer if there was none.

◆ muteReport()

bool ts::ReporterBase::muteReport ( bool  mute)
inherited

Temporarily mute the associated report.

Parameters
[in]muteIt true, report() will return a null report (log messages are discarded), until muteReport() is invoked again with mute set to false.
Returns
Previous state of the mute field.

◆ SilentLevel()

static int ts::ReporterBase::SilentLevel ( bool  silent,
int  default_severity = Severity::Error 
)
inlinestaticinherited

Compute a log severity level from a "silent" parameter.

Some subclass methods have a "silent" parameter to avoid reporting errors which may be insignificant, typically when closing a device after an error, in which case the close operation may produce other errors if the previous error left the device in an inconsistent state. While those errors should not be displayed as errors, we still display them at debug level.

Parameters
[in]silentIf true, do not report errors, report debug messages instead.
[in]default_severityDefault severity, in non-silent mode (error by default).
Returns
Error when silent is false, Debug otherwise.

The documentation for this class was generated from the following file: