Module openssl

OpenSSL support

Types

SslPtr = ptr SslStruct
  Source
PSslPtr = ptr SslPtr
  Source
SslCtx = SslPtr
  Source
PSSL_METHOD = SslPtr
  Source
PX509 = SslPtr
  Source
PX509_NAME = SslPtr
  Source
PEVP_MD = SslPtr
  Source
PBIO_METHOD = SslPtr
  Source
BIO = SslPtr
  Source
EVP_PKEY = SslPtr
  Source
PRSA = SslPtr
  Source
PASN1_UTCTIME = SslPtr
  Source
PASN1_cInt = SslPtr
  Source
PPasswdCb = SslPtr
  Source
PFunction = proc () {.cdecl.}
  Source
DES_cblock = array[0 .. 7, int8]
  Source
PDES_cblock = ptr DES_cblock
  Source
des_ks_struct = object
  ks*: DES_cblock
  weak_key*: cint
  Source
des_key_schedule = array[1 .. 16, des_ks_struct]
  Source
MD5_LONG = cuint
  Source
MD5_CTX = object
  A, B, C, D, Nl, Nh: MD5_LONG
  data: array[MD5_LBLOCK, MD5_LONG]
  num: cuint
  Source

Consts

SSL_SENT_SHUTDOWN = 1
  Source
SSL_RECEIVED_SHUTDOWN = 2
  Source
EVP_MAX_MD_SIZE = 36
  Source
SSL_ERROR_NONE = 0
  Source
SSL_ERROR_SSL = 1
  Source
SSL_ERROR_WANT_READ = 2
  Source
SSL_ERROR_WANT_WRITE = 3
  Source
SSL_ERROR_WANT_X509_LOOKUP = 4
  Source
SSL_ERROR_SYSCALL = 5
  Source
SSL_ERROR_ZERO_RETURN = 6
  Source
SSL_ERROR_WANT_CONNECT = 7
  Source
SSL_ERROR_WANT_ACCEPT = 8
  Source
SSL_CTRL_NEED_TMP_RSA = 1
  Source
SSL_CTRL_SET_TMP_RSA = 2
  Source
SSL_CTRL_SET_TMP_DH = 3
  Source
SSL_CTRL_SET_TMP_ECDH = 4
  Source
SSL_CTRL_SET_TMP_RSA_CB = 5
  Source
SSL_CTRL_SET_TMP_DH_CB = 6
  Source
SSL_CTRL_SET_TMP_ECDH_CB = 7
  Source
SSL_CTRL_GET_SESSION_REUSED = 8
  Source
SSL_CTRL_GET_CLIENT_CERT_REQUEST = 9
  Source
SSL_CTRL_GET_NUM_RENEGOTIATIONS = 10
  Source
SSL_CTRL_CLEAR_NUM_RENEGOTIATIONS = 11
  Source
SSL_CTRL_GET_TOTAL_RENEGOTIATIONS = 12
  Source
SSL_CTRL_GET_FLAGS = 13
  Source
SSL_CTRL_EXTRA_CHAIN_CERT = 14
  Source
SSL_CTRL_SET_MSG_CALLBACK = 15
  Source
SSL_CTRL_SET_MSG_CALLBACK_ARG = 16
  Source
SSL_CTRL_SET_MTU = 17
  Source
SSL_CTRL_SESS_NUMBER = 20
  Source
SSL_CTRL_SESS_CONNECT = 21
  Source
SSL_CTRL_SESS_CONNECT_GOOD = 22
  Source
SSL_CTRL_SESS_CONNECT_RENEGOTIATE = 23
  Source
SSL_CTRL_SESS_ACCEPT = 24
  Source
SSL_CTRL_SESS_ACCEPT_GOOD = 25
  Source
SSL_CTRL_SESS_ACCEPT_RENEGOTIATE = 26
  Source
SSL_CTRL_SESS_HIT = 27
  Source
SSL_CTRL_SESS_CB_HIT = 28
  Source
SSL_CTRL_SESS_MISSES = 29
  Source
SSL_CTRL_SESS_TIMEOUTS = 30
  Source
SSL_CTRL_SESS_CACHE_FULL = 31
  Source
SSL_CTRL_OPTIONS = 32
  Source
SSL_CTRL_MODE = 33
  Source
SSL_CTRL_GET_READ_AHEAD = 40
  Source
SSL_CTRL_SET_READ_AHEAD = 41
  Source
SSL_CTRL_SET_SESS_CACHE_SIZE = 42
  Source
SSL_CTRL_GET_SESS_CACHE_SIZE = 43
  Source
SSL_CTRL_SET_SESS_CACHE_MODE = 44
  Source
SSL_CTRL_GET_SESS_CACHE_MODE = 45
  Source
SSL_CTRL_GET_MAX_CERT_LIST = 50
  Source
SSL_CTRL_SET_MAX_CERT_LIST = 51
  Source
TLSEXT_NAMETYPE_host_name = 0
  Source
SSL_TLSEXT_ERR_OK = 0
  Source
SSL_TLSEXT_ERR_ALERT_WARNING = 1
  Source
SSL_TLSEXT_ERR_ALERT_FATAL = 2
  Source
SSL_TLSEXT_ERR_NOACK = 3
  Source
SSL_MODE_ENABLE_PARTIAL_WRITE = 1
  Source
SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER = 2
  Source
SSL_MODE_AUTO_RETRY = 4
  Source
SSL_MODE_NO_AUTO_CHAIN = 8
  Source
SSL_OP_NO_SSLv2 = 0x01000000
  Source
SSL_OP_NO_SSLv3 = 0x02000000
  Source
SSL_OP_NO_TLSv1 = 0x04000000
  Source
SSL_OP_ALL = 0x000FFFFF
  Source
SSL_VERIFY_NONE = 0x00000000
  Source
SSL_VERIFY_PEER = 0x00000001
  Source
OPENSSL_DES_DECRYPT = 0
  Source
OPENSSL_DES_ENCRYPT = 1
  Source
X509_V_OK = 0
  Source
X509_V_ILLEGAL = 1
  Source
X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT = 2
  Source
X509_V_ERR_UNABLE_TO_GET_CRL = 3
  Source
X509_V_ERR_UNABLE_TO_DECRYPT_CERT_SIGNATURE = 4
  Source
X509_V_ERR_UNABLE_TO_DECRYPT_CRL_SIGNATURE = 5
  Source
X509_V_ERR_UNABLE_TO_DECODE_ISSUER_PUBLIC_KEY = 6
  Source
X509_V_ERR_CERT_SIGNATURE_FAILURE = 7
  Source
X509_V_ERR_CRL_SIGNATURE_FAILURE = 8
  Source
X509_V_ERR_CERT_NOT_YET_VALID = 9
  Source
X509_V_ERR_CERT_HAS_EXPIRED = 10
  Source
X509_V_ERR_CRL_NOT_YET_VALID = 11
  Source
X509_V_ERR_CRL_HAS_EXPIRED = 12
  Source
X509_V_ERR_ERROR_IN_CERT_NOT_BEFORE_FIELD = 13
  Source
X509_V_ERR_ERROR_IN_CERT_NOT_AFTER_FIELD = 14
  Source
X509_V_ERR_ERROR_IN_CRL_LAST_UPDATE_FIELD = 15
  Source
X509_V_ERR_ERROR_IN_CRL_NEXT_UPDATE_FIELD = 16
  Source
X509_V_ERR_OUT_OF_MEM = 17
  Source
X509_V_ERR_DEPTH_ZERO_SELF_SIGNED_CERT = 18
  Source
X509_V_ERR_SELF_SIGNED_CERT_IN_CHAIN = 19
  Source
X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY = 20
  Source
X509_V_ERR_UNABLE_TO_VERIFY_LEAF_SIGNATURE = 21
  Source
X509_V_ERR_CERT_CHAIN_TOO_LONG = 22
  Source
X509_V_ERR_CERT_REVOKED = 23
  Source
X509_V_ERR_INVALID_CA = 24
  Source
X509_V_ERR_PATH_LENGTH_EXCEEDED = 25
  Source
X509_V_ERR_INVALID_PURPOSE = 26
  Source
X509_V_ERR_CERT_UNTRUSTED = 27
  Source
X509_V_ERR_CERT_REJECTED = 28
  Source
X509_V_ERR_SUBJECT_ISSUER_MISMATCH = 29
  Source
X509_V_ERR_AKID_SKID_MISMATCH = 30
  Source
X509_V_ERR_AKID_ISSUER_SERIAL_MISMATCH = 31
  Source
X509_V_ERR_KEYUSAGE_NO_CERTSIGN = 32
  Source
X509_V_ERR_UNABLE_TO_GET_CRL_ISSUER = 33
  Source
X509_V_ERR_UNHANDLED_CRITICAL_EXTENSION = 34
  Source
X509_V_ERR_APPLICATION_VERIFICATION = 50
  Source
SSL_FILETYPE_ASN1 = 2
  Source
SSL_FILETYPE_PEM = 1
  Source
EVP_PKEY_RSA = 6
  Source
MD5_CBLOCK = 64
  Source
MD5_LBLOCK = 16
  Source
MD5_DIGEST_LENGTH = 16
  Source

Procs

proc SSL_library_init(): cint {.cdecl, dynlib: DLLSSLName, importc, discardable.}
  Source
proc SSL_load_error_strings() {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc ERR_load_BIO_strings() {.cdecl, dynlib: DLLUtilName, importc.}
  Source
proc SSLv23_client_method(): PSSL_METHOD {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSLv23_method(): PSSL_METHOD {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSLv2_method(): PSSL_METHOD {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSLv3_method(): PSSL_METHOD {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc TLSv1_method(): PSSL_METHOD {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSL_new(context: SslCtx): SslPtr {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSL_free(ssl: SslPtr) {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSL_CTX_new(meth: PSSL_METHOD): SslCtx {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSL_CTX_load_verify_locations(ctx: SslCtx; CAfile: cstring; CApath: cstring): cint {.
    cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSL_CTX_free(arg0: SslCtx) {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSL_CTX_set_verify(s: SslCtx; mode: int;
                       cb: proc (a: int; b: pointer): int {.cdecl.}) {.cdecl,
    dynlib: DLLSSLName, importc.}
  Source
proc SSL_get_verify_result(ssl: SslPtr): int {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSL_CTX_set_cipher_list(s: SslCtx; ciphers: cstring): cint {.cdecl,
    dynlib: DLLSSLName, importc.}
  Source
proc SSL_CTX_use_certificate_file(ctx: SslCtx; filename: cstring; typ: cint): cint {.
    stdcall, dynlib: DLLSSLName, importc.}
  Source
proc SSL_CTX_use_certificate_chain_file(ctx: SslCtx; filename: cstring): cint {.
    stdcall, dynlib: DLLSSLName, importc.}
  Source
proc SSL_CTX_use_PrivateKey_file(ctx: SslCtx; filename: cstring; typ: cint): cint {.
    cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSL_CTX_check_private_key(ctx: SslCtx): cint {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSL_set_fd(ssl: SslPtr; fd: SocketHandle): cint {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSL_shutdown(ssl: SslPtr): cint {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSL_set_shutdown(ssl: SslPtr; mode: cint) {.cdecl, dynlib: DLLSSLName,
    importc: "SSL_set_shutdown".}
  Source
proc SSL_get_shutdown(ssl: SslPtr): cint {.cdecl, dynlib: DLLSSLName,
                                       importc: "SSL_get_shutdown".}
  Source
proc SSL_connect(ssl: SslPtr): cint {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSL_read(ssl: SslPtr; buf: pointer; num: int): cint {.cdecl, dynlib: DLLSSLName,
    importc.}
  Source
proc SSL_write(ssl: SslPtr; buf: cstring; num: int): cint {.cdecl, dynlib: DLLSSLName,
    importc.}
  Source
proc SSL_get_error(s: SslPtr; ret_code: cint): cint {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSL_accept(ssl: SslPtr): cint {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc SSL_pending(ssl: SslPtr): cint {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc BIO_new_ssl_connect(ctx: SslCtx): BIO {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc BIO_ctrl(bio: BIO; cmd: cint; larg: int; arg: cstring): int {.cdecl,
    dynlib: DLLSSLName, importc.}
  Source
proc BIO_get_ssl(bio: BIO; ssl: ptr SslPtr): int {.raises: [], tags: [].}
  Source
proc BIO_set_conn_hostname(bio: BIO; name: cstring): int {.raises: [], tags: [].}
  Source
proc BIO_do_handshake(bio: BIO): int {.raises: [], tags: [].}
  Source
proc BIO_do_connect(bio: BIO): int {.raises: [], tags: [].}
  Source
proc BIO_read(b: BIO; data: cstring; length: cint): cint {.cdecl, dynlib: DLLUtilName,
    importc.}
  Source
proc BIO_write(b: BIO; data: cstring; length: cint): cint {.cdecl, dynlib: DLLUtilName,
    importc.}
  Source
proc BIO_free(b: BIO): cint {.cdecl, dynlib: DLLUtilName, importc.}
  Source
proc ERR_print_errors_fp(fp: File) {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc ERR_error_string(e: cint; buf: cstring): cstring {.cdecl, dynlib: DLLUtilName,
    importc.}
  Source
proc ERR_get_error(): cint {.cdecl, dynlib: DLLUtilName, importc.}
  Source
proc ERR_peek_last_error(): cint {.cdecl, dynlib: DLLUtilName, importc.}
  Source
proc OpenSSL_add_all_algorithms() {.cdecl, dynlib: DLLUtilName,
                                  importc: "OPENSSL_add_all_algorithms_conf".}
  Source
proc OPENSSL_config(configName: cstring) {.cdecl, dynlib: DLLSSLName, importc.}
  Source
proc CRYPTO_malloc_init() {.raises: [], tags: [].}
  Source
proc SSL_CTX_ctrl(ctx: SslCtx; cmd: cint; larg: int; parg: pointer): int {.cdecl,
    dynlib: DLLSSLName, importc.}
  Source
proc SSLCTXSetMode(ctx: SslCtx; mode: int): int {.raises: [], tags: [].}
  Source
proc SSL_ctrl(ssl: SslPtr; cmd: cint; larg: int; parg: pointer): int {.cdecl,
    dynlib: DLLSSLName, importc.}
  Source
proc SSL_set_tlsext_host_name(ssl: SslPtr; name: cstring): int {.raises: [], tags: [].}
Set the SNI server name extension to be used in a client hello. Returns 1 if SNI was set, 0 if current SSL configuration doesn't support SNI.   Source
proc SSL_get_servername(ssl: SslPtr; typ: cint = TLSEXT_NAMETYPE_host_name): cstring {.
    cdecl, dynlib: DLLSSLName, importc.}
Retrieve the server name requested in the client hello. This can be used in the callback set in SSL_CTX_set_tlsext_servername_callback to implement virtual hosting. May return nil.   Source
proc SSL_CTX_set_tlsext_servername_callback(ctx: SslCtx;
    cb: proc (ssl: SslPtr; cb_id: int; arg: pointer): int {.cdecl.}): int {.
    raises: [Exception], tags: [RootEffect].}

Set the callback to be used on listening SSL connections when the client hello is received.

The callback should return one of:

  • SSL_TLSEXT_ERR_OK
  • SSL_TLSEXT_ERR_ALERT_WARNING
  • SSL_TLSEXT_ERR_ALERT_FATAL
  • SSL_TLSEXT_ERR_NOACK
  Source
proc SSL_CTX_set_tlsext_servername_arg(ctx: SslCtx; arg: pointer): int {.raises: [],
    tags: [].}
Set the pointer to be used in the callback registered to SSL_CTX_set_tlsext_servername_callback.   Source
proc bioNew(b: PBIO_METHOD): BIO {.cdecl, dynlib: DLLUtilName, importc: "BIO_new".}
  Source
proc bioFreeAll(b: BIO) {.cdecl, dynlib: DLLUtilName, importc: "BIO_free_all".}
  Source
proc bioSMem(): PBIO_METHOD {.cdecl, dynlib: DLLUtilName, importc: "BIO_s_mem".}
  Source
proc bioCtrlPending(b: BIO): cint {.cdecl, dynlib: DLLUtilName,
                                importc: "BIO_ctrl_pending".}
  Source
proc bioRead(b: BIO; Buf: cstring; length: cint): cint {.cdecl, dynlib: DLLUtilName,
    importc: "BIO_read".}
  Source
proc bioWrite(b: BIO; Buf: cstring; length: cint): cint {.cdecl, dynlib: DLLUtilName,
    importc: "BIO_write".}
  Source
proc sslSetConnectState(s: SslPtr) {.cdecl, dynlib: DLLSSLName,
                                  importc: "SSL_set_connect_state".}
  Source
proc sslSetAcceptState(s: SslPtr) {.cdecl, dynlib: DLLSSLName,
                                 importc: "SSL_set_accept_state".}
  Source
proc sslRead(ssl: SslPtr; buf: cstring; num: cint): cint {.cdecl, dynlib: DLLSSLName,
    importc: "SSL_read".}
  Source
proc sslPeek(ssl: SslPtr; buf: cstring; num: cint): cint {.cdecl, dynlib: DLLSSLName,
    importc: "SSL_peek".}
  Source
proc sslWrite(ssl: SslPtr; buf: cstring; num: cint): cint {.cdecl, dynlib: DLLSSLName,
    importc: "SSL_write".}
  Source
proc sslSetBio(ssl: SslPtr; rbio, wbio: BIO) {.cdecl, dynlib: DLLSSLName,
    importc: "SSL_set_bio".}
  Source
proc sslDoHandshake(ssl: SslPtr): cint {.cdecl, dynlib: DLLSSLName,
                                     importc: "SSL_do_handshake".}
  Source
proc ErrClearError() {.cdecl, dynlib: DLLUtilName, importc: "ERR_clear_error".}
  Source
proc ErrFreeStrings() {.cdecl, dynlib: DLLUtilName, importc: "ERR_free_strings".}
  Source
proc ErrRemoveState(pid: cint) {.cdecl, dynlib: DLLUtilName,
                              importc: "ERR_remove_state".}
  Source
proc md5_Init(c: var MD5_CTX): cint {.importc: "$1".}
  Source
proc md5_Update(c: var MD5_CTX; data: pointer; len: csize): cint {.importc: "$1".}
  Source
proc md5_Final(md: cstring; c: var MD5_CTX): cint {.importc: "$1".}
  Source
proc md5(d: ptr cuchar; n: csize; md: ptr cuchar): ptr cuchar {.importc: "$1".}
  Source
proc md5_Transform(c: var MD5_CTX; b: ptr cuchar) {.importc: "$1".}
  Source
proc md5_File(file: string): string {.raises: [IOError, Exception],
                                  tags: [ReadIOEffect].}
Generate MD5 hash for a file. Result is a 32 character   Source
proc md5_Str(str: string): string {.raises: [IOError], tags: [].}
Generate MD5 hash for a string. Result is a 32 character   Source