5#ifndef QTLS_SCHANNEL_P_H
6#define QTLS_SCHANNEL_P_H
19#include <QtNetwork/private/qtnetworkglobal_p.h>
23#include "../shared/qwincrypt_p.h"
27#include <QtNetwork/private/qsslsocket_p.h>
30#define SCHANNEL_USE_BLACKLISTS 1
34#undef SCHANNEL_USE_BLACKLISTS
48 void init(QSslSocket *q, QSslSocketPrivate *d)
override;
61 enum class SchannelState {
67 } schannelState = SchannelState::InitializeHandshake;
71 struct MessageBufferResult {
73 QByteArray messageBuffer;
75 MessageBufferResult getNextEncryptedMessage();
78 bool acquireCredentialsHandle();
79 ULONG getContextRequirements();
82 bool performHandshake();
83 bool verifyHandshake();
86 bool sendToken(
void *token,
unsigned long tokenLength,
bool emitError =
true);
87 QString targetName()
const;
89 bool checkSslErrors();
90 void deallocateContext();
91 void freeCredentialsHandle();
92 void closeCertificateStores();
95 void initializeCertificateStores();
96 bool verifyCertContext(CERT_CONTEXT *certContext);
98 bool rootCertOnDemandLoadingAllowed();
102 QSslSocket *q =
nullptr;
103 QSslSocketPrivate *d =
nullptr;
105 SecPkgContext_CipherInfo cipherInfo = {};
106 SecPkgContext_ConnectionInfo connectionInfo = {};
107 SecPkgContext_StreamSizes streamSizes = {};
109 CredHandle credentialHandle;
110 CtxtHandle contextHandle;
112 QByteArray intermediateBuffer;
118 ULONG contextAttributes = 0;
119 qint64 missingData = 0;
121 bool renegotiating =
false;
122 bool shutdown =
false;
123 QList<QSslError> sslErrors;
void startClientEncryption() override
void disconnected() override
void continueHandshake() override
void init(QSslSocket *q, QSslSocketPrivate *d) override
void startServerEncryption() override
QSsl::SslProtocol sessionProtocol() const override
void disconnectFromHost() override
~TlsCryptographSchannel()
bool hasUndecryptedData() const override
QSslCipher sessionCipher() const override
QList< QSslError > tlsErrors() const override
QByteArray derFromPem(const QByteArray &pem, QMap< QByteArray, QByteArray > *headers) const override
bool isPkcs8() const override
QByteArray toPem(const QByteArray &passPhrase) const override
int length() const override
void decodePem(KeyType type, KeyAlgorithm algorithm, const QByteArray &pem, const QByteArray &passPhrase, bool deepClear) override
void fromHandle(Qt::HANDLE opaque, KeyType expectedType) override
Qt::HANDLE handle() const override
void clear(bool deep) override
void decodeDer(KeyType type, KeyAlgorithm algorithm, const QByteArray &der, const QByteArray &passPhrase, bool deepClear) override
QByteArray decrypt(Cipher cipher, const QByteArray &data, const QByteArray &key, const QByteArray &iv) const override
QByteArray encrypt(Cipher cipher, const QByteArray &data, const QByteArray &key, const QByteArray &iv) const override
TlsKey * publicKey() const override
Qt::HANDLE handle() const override
static bool importPkcs12(QIODevice *device, QSslKey *key, QSslCertificate *cert, QList< QSslCertificate > *caCertificates, const QByteArray &passPhrase)
QPCCertContextPointer certificateContext
X509CertificateSchannel()
~X509CertificateSchannel()
Q_DISABLE_COPY_MOVE(X509CertificateSchannel)
static QSslCertificate QSslCertificate_from_CERT_CONTEXT(const CERT_CONTEXT *certificateContext)
Namespace containing onternal types that TLS backends implement.
QT_WARNING_PUSH QT_WARNING_DISABLE_DEPRECATED std::array< SchannelCipherInfo, 44 > schannelCipherInfo
QList< QSslCipher > defaultCiphers()
UNICODE_STRING cbcChainingMode
QList< CRYPTO_SETTINGS > cryptoSettingsForCiphers(const QList< QSslCipher > &ciphers)
bool containsTls13Cipher(const QList< QSslCipher > &ciphers)
UNICODE_STRING gcmChainingMode
QList< QSslCipher > ciphersByName(QStringView schannelSuiteName)
static void attachPrivateKeyToCertificate(const QSslCertificate &certificate, const QSslKey &privateKey)
Q_LOGGING_CATEGORY(lcEventDispatcher, "qt.eventdispatcher")
Q_GLOBAL_STATIC(QReadWriteLock, g_updateMutex)
QT_REQUIRE_CONFIG(thread)
#define SP_PROT_TLS1_0_SERVER
#define SP_PROT_TLS1_1_SERVER
#define SP_PROT_TLS1_2_SERVER
#define BCRYPT_ECDSA_ALGORITHM
#define SP_PROT_TLS1_3_SERVER
#define MAP_PROTOCOL(sp_protocol, q_protocol)
#define CHECK_STATUS(status)
#define CHECK_ATTRIBUTE(attributeName)
#define DEBUG_WARN(message)
QByteArray _q_makePkcs12(const QList< QSslCertificate > &certs, const QSslKey &key, const QString &passPhrase)
#define SP_PROT_TLS1_1_CLIENT
#define SP_PROT_TLS1_SERVER
QAsn1Element _q_PKCS12_key(const QSslKey &key)
#define BCRYPT_ECDH_ALGORITHM
#define SP_PROT_TLS1_3_CLIENT
#define SEC_E_APPLICATION_PROTOCOL_MISMATCH
#define SP_PROT_TLS1_CLIENT
#define SP_PROT_TLS1_0_CLIENT
#define SP_PROT_TLS1_2_CLIENT
std::unique_ptr< void, QHCertStoreDeleter > QHCertStorePointer
const char * authenticationMethod
const char * schannelCipherSuite
QList< QSsl::SslProtocol > protocols
const char * encryptionMethod
const char * openSslCipherSuite
const char * keyExchangeMethod