summaryrefslogtreecommitdiff
path: root/include/ossl_wrappers.hpp
AgeCommit message (Collapse)AuthorFilesLines
2026-07-02Allow setting Mozilla modernEd Tanous1-6/+50
Mozilla publishes recommendations for TLS cipher suites to support. For many years bmcweb selected "intermediate" because of compatibility with clients that didn't yet support TLS1.3. This commit adds the ability to use the Mozilla modern recommendations, and disable TLS1.2 support through a new meson option, tls-profile. Tested: Loaded on qemu, and verified with testssl.sh[1] that parameters were applied. [1] https://github.com/testssl/testssl.sh Change-Id: I38e915b3943b5dbe5fb31e54eb3ebda9bbaeb811 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-06-12Generate 64 bit serial numbersEd Tanous1-2/+2
Even though the certificate is self signed, we should pass as many certificate tests as possible. testssl.sh prints ``` Serial 4B32D4F0 NOT ok: length should be >= 64 bits entropy (is: 4 bytes) ``` On our default certificate. This is relatively easy to fix. Change-Id: Ib1eb07b637ebf49ecf954b3d98ced9e9ef0f5a34 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-06-12OpenSSL cleanupEd Tanous1-36/+401
Continue moving OpenSSL into reusable RAII classes that can be used in unit tests and other places. This is slightly more code, but as we're adding unit tests, it allows reuse between unit tests rather than writing C directly. It also encapsulates the complexity of parsing openssl output (usually in bytes) into standard types (string) that can be compared/modified. Functionally this adds two new classes to the "wrappers" functions, OpenSSLSSLCtx and OpenSSLSSL, which each wrap SSL_CTX and SSL objects respectively from openssl. These are rough approximations of the boost equivalents. Change-Id: Id87ac4ccde88890bd70861deffdb256188ec0e39 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-04-27Add more unit tests for UPN functionalityIgor Kanyuka1-3/+32
Current unit tests only covers happy path. Add more unit tests before changing the code. Tested: unit tests Change-Id: Ibba5dbbc1457b59670d5d8f3c828fa9ca112f88c Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
2026-04-27RAII OpenSSLEd Tanous1-0/+789
bmcweb openssl usage is a mess. Start cleaning it up. 1. Make RAII objects for any held memory. 2. Move methods from hostname monitor into the ssl namespace, so not all compile units need to pull in openssl headers 3. Move methods to static where functions can be encapsulated. Because we're now testing openssl, we need to register memory init so that the sanitizers don't cause issues when mallocing from non bootstrapped openssl binaries. Openssl provides a handle for this, so use it in those unit tests. Tested: Unit tests pass. bmcweb launches and can open ssl with curl as it did previously. Change-Id: If0340692d2c56a6c45bb8d661d654a4b58ff3d2c Signed-off-by: Ed Tanous <etanous@nvidia.com>