diff --git a/examples/esp32/device-dashboard/main/CMakeLists.txt b/examples/esp32/device-dashboard/main/CMakeLists.txt index b5fd7683..37736b9c 100644 --- a/examples/esp32/device-dashboard/main/CMakeLists.txt +++ b/examples/esp32/device-dashboard/main/CMakeLists.txt @@ -7,4 +7,4 @@ component_compile_options(-DMG_ENABLE_LINES) component_compile_options(-DMG_ENABLE_PACKED_FS) component_compile_options(-DHTTP_URL="http://0.0.0.0:80") component_compile_options(-DHTTPS_URL="https://0.0.0.0:443") -component_compile_options(-DMG_ENABLE_MBEDTLS=0) # change to '1' to enable TLS +component_compile_options(-DMG_TLS=MG_TLS_NONE) # change to 'MG_TLS_MBED' to enable TLS diff --git a/examples/http-client/main.c b/examples/http-client/main.c index 2ea49ef4..571b1fcf 100644 --- a/examples/http-client/main.c +++ b/examples/http-client/main.c @@ -59,8 +59,7 @@ int main(int argc, char *argv[]) { if (argc > 1) s_url = argv[1]; // Use URL provided in the command line mg_log_set(atoi(log_level)); // Set to 0 to disable debug mg_mgr_init(&mgr); // Initialise event manager - struct mg_tls_opts opts = {.client_ca = - mg_str(CA_ISRG_ROOT_X2 CA_ISRG_ROOT_X1)}; + struct mg_tls_opts opts = {.client_ca = mg_str(CA_ALL)}; mg_tls_ctx_init(&mgr, &opts); mg_http_connect(&mgr, s_url, fn, &done); // Create client connection while (!done) mg_mgr_poll(&mgr, 50); // Event manager loops until 'done' diff --git a/examples/http-proxy-client/main.c b/examples/http-proxy-client/main.c index 1d80fa1b..a90167bf 100644 --- a/examples/http-proxy-client/main.c +++ b/examples/http-proxy-client/main.c @@ -24,11 +24,6 @@ static void fn(struct mg_connection *c, int ev, void *ev_data, void *fn_data) { mg_printf(c, "CONNECT %.*s:%hu HTTP/1.1\r\nHost: %.*s:%hu\r\n\r\n", (int) host.len, host.ptr, mg_url_port(url), (int) host.len, host.ptr, mg_url_port(url)); - // If target URL is SSL/TLS, command client connection to use TLS - if (mg_url_is_ssl(url)) { - struct mg_tls_opts opts = {.ca = "ca.pem"}; - mg_tls_init(c, &opts); - } } else if (!connected && ev == MG_EV_READ) { struct mg_http_message hm; int n = mg_http_parse((char *) c->recv.buf, c->recv.len, &hm); @@ -57,6 +52,8 @@ int main(int argc, char *argv[]) { } mg_mgr_init(&mgr); // Initialise event manager + struct mg_tls_opts opts = {.client_ca = mg_str(CA_ALL)}; + mg_tls_ctx_init(&mgr, &opts); mg_http_connect(&mgr, argv[1], fn, argv[2]); // Connect to the proxy for (;;) mg_mgr_poll(&mgr, 1000); // Event loop mg_mgr_free(&mgr); diff --git a/examples/http-restful-server/main.c b/examples/http-restful-server/main.c index 3fba2afb..f1899368 100644 --- a/examples/http-restful-server/main.c +++ b/examples/http-restful-server/main.c @@ -18,17 +18,46 @@ static const char *s_http_addr = "http://0.0.0.0:8000"; // HTTP port static const char *s_https_addr = "https://0.0.0.0:8443"; // HTTPS port static const char *s_root_dir = "."; +// Self signed certificates +// https://mongoose.ws/documentation/tutorials/tls/#self-signed-certificates +#ifdef TLS_TWOWAY +static const char *s_tls_ca = + "-----BEGIN CERTIFICATE-----\n" + "MIIBqjCCAU+gAwIBAgIUESoOPGqMhf9uarzblVFwzrQweMcwCgYIKoZIzj0EAwIw\n" + "RDELMAkGA1UEBhMCSUUxDzANBgNVBAcMBkR1YmxpbjEQMA4GA1UECgwHQ2VzYW50\n" + "YTESMBAGA1UEAwwJVGVzdCBSb290MCAXDTIwMDUwOTIxNTE0NFoYDzIwNTAwNTA5\n" + "MjE1MTQ0WjBEMQswCQYDVQQGEwJJRTEPMA0GA1UEBwwGRHVibGluMRAwDgYDVQQK\n" + "DAdDZXNhbnRhMRIwEAYDVQQDDAlUZXN0IFJvb3QwWTATBgcqhkjOPQIBBggqhkjO\n" + "PQMBBwNCAAQsq9ECZiSW1xI+CVBP8VDuUehVA166sR2YsnJ5J6gbMQ1dUCH/QvLa\n" + "dBdeU7JlQcH8hN5KEbmM9BnZxMor6ussox0wGzAMBgNVHRMEBTADAQH/MAsGA1Ud\n" + "DwQEAwIBrjAKBggqhkjOPQQDAgNJADBGAiEAnHFsAIwGQQyRL81B04dH6d86Iq0l\n" + "fL8OKzndegxOaB0CIQCPwSIwEGFdURDqCC0CY2dnMrUGY5ZXu3hHCojZGS7zvg==\n" + "-----END CERTIFICATE-----\n"; +#endif +static const char *s_tls_cert = + "-----BEGIN CERTIFICATE-----\n" + "MIIBhzCCASygAwIBAgIUbnMoVd8TtWH1T09dANkK2LU6IUswCgYIKoZIzj0EAwIw\n" + "RDELMAkGA1UEBhMCSUUxDzANBgNVBAcMBkR1YmxpbjEQMA4GA1UECgwHQ2VzYW50\n" + "YTESMBAGA1UEAwwJVGVzdCBSb290MB4XDTIwMDUwOTIxNTE0OVoXDTMwMDUwOTIx\n" + "NTE0OVowETEPMA0GA1UEAwwGc2VydmVyMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcD\n" + "QgAEkuBGnInDN6l06zVVQ1VcrOvH5FDu9MC6FwJc2e201P8hEpq0Q/SJS2nkbSuW\n" + "H/wBTTBaeXN2uhlBzMUWK790KKMvMC0wCQYDVR0TBAIwADALBgNVHQ8EBAMCA6gw\n" + "EwYDVR0lBAwwCgYIKwYBBQUHAwEwCgYIKoZIzj0EAwIDSQAwRgIhAPo6xx7LjCdZ\n" + "QY133XvLjAgVFrlucOZHONFVQuDXZsjwAiEAzHBNligA08c5U3SySYcnkhurGg50\n" + "BllCI0eYQ9ggp/o=\n" + "-----END CERTIFICATE-----\n"; + +static const char *s_tls_key = + "-----BEGIN PRIVATE KEY-----\n" + "MIGHAgEAMBMGByqGSM49AgEGCCqGSM49AwEHBG0wawIBAQQglNni0t9Dg9icgG8w\n" + "kbfxWSS+TuNgbtNybIQXcm3NHpmhRANCAASS4EacicM3qXTrNVVDVVys68fkUO70\n" + "wLoXAlzZ7bTU/yESmrRD9IlLaeRtK5Yf/AFNMFp5c3a6GUHMxRYrv3Qo\n" + "-----END PRIVATE KEY-----\n"; + // We use the same event handler function for HTTP and HTTPS connections // fn_data is NULL for plain HTTP, and non-NULL for HTTPS static void fn(struct mg_connection *c, int ev, void *ev_data, void *fn_data) { - if (ev == MG_EV_ACCEPT && fn_data != NULL) { - struct mg_tls_opts opts = { - //.ca = "ca.pem", // Uncomment to enable two-way SSL - .cert = "server.pem", // Certificate PEM file - .certkey = "server.pem", // This pem contains both cert and key - }; - mg_tls_init(c, &opts); - } else if (ev == MG_EV_HTTP_MSG) { + if (ev == MG_EV_HTTP_MSG) { struct mg_http_message *hm = (struct mg_http_message *) ev_data; if (mg_http_match_uri(hm, "/api/stats")) { // Print some statistics about currently established connections @@ -58,6 +87,13 @@ int main(void) { struct mg_mgr mgr; // Event manager mg_log_set(MG_LL_DEBUG); // Set log level mg_mgr_init(&mgr); // Initialise event manager + struct mg_tls_opts opts = { +#ifdef TLS_TWOWAY + .client_ca = mg_str(s_tls_ca), +#endif + .server_cert = mg_str(s_tls_cert), + .server_key = mg_str(s_tls_key)}; + mg_tls_ctx_init(&mgr, &opts); mg_http_listen(&mgr, s_http_addr, fn, NULL); // Create HTTP listener mg_http_listen(&mgr, s_https_addr, fn, (void *) 1); // HTTPS listener for (;;) mg_mgr_poll(&mgr, 1000); // Infinite event loop diff --git a/examples/http-reverse-proxy/main.c b/examples/http-reverse-proxy/main.c index 7074bdf5..1a380080 100644 --- a/examples/http-reverse-proxy/main.c +++ b/examples/http-reverse-proxy/main.c @@ -10,7 +10,7 @@ #include "mongoose.h" static const char *s_backend_url = -#if MG_ENABLE_MBEDTLS || MG_ENABLE_OPENSSL +#if MG_TLS "https://cesanta.com"; #else "http://info.cern.ch"; @@ -37,7 +37,7 @@ static void forward_request(struct mg_http_message *hm, } static void fn2(struct mg_connection *c, int ev, void *ev_data, void *fn_data) { - struct mg_connection *c2 = fn_data; + struct mg_connection *c2 = (struct mg_connection *)fn_data; if (ev == MG_EV_READ) { // All incoming data from the backend, forward to the client if (c2 != NULL) mg_send(c2, c->recv.buf, c->recv.len); @@ -58,10 +58,6 @@ static void fn(struct mg_connection *c, int ev, void *ev_data, void *fn_data) { if (c2 == NULL) { mg_error(c, "Cannot create backend connection"); } else { - if (mg_url_is_ssl(s_backend_url)) { - struct mg_tls_opts opts = {.ca = "ca.pem"}; - mg_tls_init(c2, &opts); - } c->fn_data = c2; forward_request(hm, c2); c->is_resp = 0; // process further msgs in keep-alive connection @@ -78,6 +74,8 @@ int main(void) { mg_log_set(MG_LL_DEBUG); // Set log level mg_mgr_init(&mgr); // Initialise event manager + struct mg_tls_opts opts = {.client_ca = mg_str(CA_ALL)}; + mg_tls_ctx_init(&mgr, &opts); mg_http_listen(&mgr, s_listen_url, fn, NULL); // Start proxy for (;;) mg_mgr_poll(&mgr, 1000); // Event loop mg_mgr_free(&mgr); diff --git a/examples/mip-tap/main.c b/examples/mip-tap/main.c index 54ee66bd..bc38381c 100644 --- a/examples/mip-tap/main.c +++ b/examples/mip-tap/main.c @@ -102,9 +102,7 @@ int main(int argc, char *argv[]) { // Start infinite event loop MG_INFO(("Mongoose version : v%s", MG_VERSION)); MG_INFO(("Listening on : %s", HTTP_URL)); -#if MG_ENABLE_MBEDTLS || MG_ENABLE_OPENSSL MG_INFO(("Listening on : %s", HTTPS_URL)); -#endif web_init(&mgr); while (s_signo == 0) mg_mgr_poll(&mgr, 100); // Infinite event loop diff --git a/examples/mqtt-client-aws-iot/main.c b/examples/mqtt-client-aws-iot/main.c index cc411953..117141fa 100644 --- a/examples/mqtt-client-aws-iot/main.c +++ b/examples/mqtt-client-aws-iot/main.c @@ -29,8 +29,8 @@ static const char *s_url = // 3. From the dialog box that appears, download: // xxx-certificate.pem.crt as cert.pem to the example directory // xxx-private.pem.key as key.pem to the example directory -static const char *s_cert = "cert.pem"; -static const char *s_key = "key.pem"; +//static const char *s_cert = "cert.pem"; +//static const char *s_key = "key.pem"; static const char *s_rx_topic = "d/rx"; static const char *s_tx_topic = "d/tx"; @@ -44,11 +44,6 @@ static void fn(struct mg_connection *c, int ev, void *ev_data, void *fn_data) { } else if (ev == MG_EV_ERROR) { // On error, log error message MG_ERROR(("%p %s", c->fd, (char *) ev_data)); - } else if (ev == MG_EV_CONNECT) { - // Set up 2-way TLS that is required by AWS IoT - struct mg_tls_opts opts = { - .ca = "ca.pem", .cert = s_cert, .certkey = s_key}; - mg_tls_init(c, &opts); } else if (ev == MG_EV_MQTT_OPEN) { // MQTT connect is successful struct mg_str topic = mg_str(s_rx_topic); @@ -92,6 +87,9 @@ int main(void) { struct mg_mqtt_opts opts = {.clean = true}; bool done = false; mg_mgr_init(&mgr); // Initialise event manager + struct mg_tls_opts topts = {.client_ca = mg_str(CA_ALL)}; +//TODO() 2-way auth and certificate loading + mg_tls_ctx_init(&mgr, &topts); MG_INFO(("Connecting to %s", s_url)); // Inform that we're starting mg_mqtt_connect(&mgr, s_url, &opts, fn, &done); // Create client connection while (!done) mg_mgr_poll(&mgr, 1000); // Loop until done diff --git a/examples/mqtt-client/main.c b/examples/mqtt-client/main.c index 177bea3f..67352de1 100644 --- a/examples/mqtt-client/main.c +++ b/examples/mqtt-client/main.c @@ -101,7 +101,8 @@ int main(int argc, char *argv[]) { signal(SIGTERM, signal_handler); // manager loop on SIGINT and SIGTERM mg_mgr_init(&mgr); - mg_tls_init_client(&mgr, "ca.pem"); + struct mg_tls_opts opts = {.client_ca = mg_str(CA_ALL)}; + mg_tls_ctx_init(&mgr, &opts); mg_timer_add(&mgr, 3000, MG_TIMER_REPEAT | MG_TIMER_RUN_NOW, timer_fn, &mgr); while (s_signo == 0) mg_mgr_poll(&mgr, 1000); // Event loop, 1s timeout mg_mgr_free(&mgr); // Finished, cleanup diff --git a/examples/mqtt-over-ws-client/main.c b/examples/mqtt-over-ws-client/main.c index 5fd23cdb..c91eaae9 100644 --- a/examples/mqtt-over-ws-client/main.c +++ b/examples/mqtt-over-ws-client/main.c @@ -9,27 +9,21 @@ // // To enable SSL/TLS, see https://mongoose.ws/tutorials/tls/#how-to-build +#include "mongoose.h" + static const char *s_url = -#if defined(MG_ENABLE_MBEDTLS) || defined(MG_ENABLE_OPENSSL) +#if MG_TLS "wss://broker.hivemq.com:8884/mqtt"; #else "ws://broker.hivemq.com:8000/mqtt"; #endif -#include "mongoose.h" - static const char *s_topic = "mg/test"; static void fn(struct mg_connection *c, int ev, void *ev_data, void *fn_data) { if (ev == MG_EV_ERROR) { // On error, log error message MG_ERROR(("%p %s", c->fd, (char *) ev_data)); - } else if (ev == MG_EV_CONNECT) { - // If target URL is SSL/TLS, command client connection to use TLS - if (mg_url_is_ssl(s_url)) { - struct mg_tls_opts opts = {.ca = "ca.pem"}; - mg_tls_init(c, &opts); - } } else if (ev == MG_EV_WS_OPEN) { // WS connection established. Perform MQTT login MG_INFO(("Connected to WS. Logging in to MQTT...")); @@ -98,6 +92,8 @@ int main(void) { struct mg_mgr mgr; // Event manager bool done = false; // Event handler flips it to true when done mg_mgr_init(&mgr); // Initialise event manager + struct mg_tls_opts opts = {.client_ca = mg_str(CA_ALL)}; + mg_tls_ctx_init(&mgr, &opts); mg_log_set(MG_LL_DEBUG); // Set log level mg_ws_connect(&mgr, s_url, fn, &done, NULL); // Create client connection while (done == false) mg_mgr_poll(&mgr, 1000); // Event loop diff --git a/examples/wifi-router-dashboard/net.c b/examples/wifi-router-dashboard/net.c index 3d634054..e7bdf35b 100644 --- a/examples/wifi-router-dashboard/net.c +++ b/examples/wifi-router-dashboard/net.c @@ -89,7 +89,7 @@ static uint64_t s_boot_timestamp = 0; // Updated by SNTP // Certificate generation procedure: // openssl ecparam -name prime256v1 -genkey -noout -out key.pem // openssl req -new -key key.pem -x509 -nodes -days 3650 -out cert.pem -static const char *s_ssl_cert = +static const char *s_tls_cert = "-----BEGIN CERTIFICATE-----\n" "MIIBCTCBsAIJAK9wbIDkHnAoMAoGCCqGSM49BAMCMA0xCzAJBgNVBAYTAklFMB4X\n" "DTIzMDEyOTIxMjEzOFoXDTMzMDEyNjIxMjEzOFowDTELMAkGA1UEBhMCSUUwWTAT\n" @@ -99,7 +99,7 @@ static const char *s_ssl_cert = "aEWiBp1xshs4iz6WbpxrS1IHucrqkZuJLfNZGZI=\n" "-----END CERTIFICATE-----\n"; -static const char *s_ssl_key = +static const char *s_tls_key = "-----BEGIN EC PRIVATE KEY-----\n" "MHcCAQEEICBz3HOkQLPBDtdknqC7k1PNsWj6HfhyNB5MenfjmqiooAoGCCqGSM49\n" "AwEHoUQDQgAEc0kEuTh3de5VHjSPupKfVmLtHMbhCIvyU46YWwpnSQ9XFL4ZszPf\n" @@ -276,10 +276,7 @@ static void handle_dhcp_get(struct mg_connection *c) { // HTTP request handler function static void fn(struct mg_connection *c, int ev, void *ev_data, void *fn_data) { - if (ev == MG_EV_ACCEPT && fn_data != NULL) { - struct mg_tls_opts opts = {.cert = s_ssl_cert, .certkey = s_ssl_key}; - mg_tls_init(c, &opts); - } else if (ev == MG_EV_HTTP_MSG) { + if (ev == MG_EV_HTTP_MSG) { struct mg_http_message *hm = (struct mg_http_message *) ev_data; struct user *u = authenticate(hm); @@ -316,13 +313,16 @@ static void fn(struct mg_connection *c, int ev, void *ev_data, void *fn_data) { hm->method.ptr, (int) hm->uri.len, hm->uri.ptr, (int) 3, &c->send.buf[9])); } + (void) fn_data; } void web_init(struct mg_mgr *mgr) { + struct mg_tls_opts opts = {0}; + opts.server_cert = mg_str(s_tls_cert); + opts.server_key = mg_str(s_tls_key); + mg_tls_ctx_init(mgr, &opts); mg_http_listen(mgr, HTTP_URL, fn, NULL); -#if MG_ENABLE_MBEDTLS || MG_ENABLE_OPENSSL - mg_http_listen(mgr, HTTPS_URL, fn, ""); -#endif + mg_http_listen(mgr, HTTPS_URL, fn, NULL); // mg_timer_add(c->mgr, 1000, MG_TIMER_REPEAT, timer_mqtt_fn, c->mgr); mg_timer_add(mgr, 3600 * 1000, MG_TIMER_RUN_NOW | MG_TIMER_REPEAT, diff --git a/test/unit_test.c b/test/unit_test.c index 9c20fd60..82ffcf64 100644 --- a/test/unit_test.c +++ b/test/unit_test.c @@ -744,9 +744,7 @@ static int fetch(struct mg_mgr *mgr, char *buf, const char *url, if (mgr->tls_ctx == NULL) { struct mg_tls_opts opts; memset(&opts, 0, sizeof(opts)); -#if MG_TLS opts.client_ca = mg_str(CA_ISRG_ROOT_X1); -#endif if (strstr(url, "127.0.0.1") != NULL) { // Local connection, use self-signed certificates opts.client_ca = mg_str(s_tls_ca); @@ -1234,9 +1232,7 @@ static void test_http_client(void) { int i, ok = 0; memset(&opts, 0, sizeof(opts)); mg_mgr_init(&mgr); -#if MG_TLS opts.client_ca = mg_str(CA_ISRG_ROOT_X2 CA_ISRG_ROOT_X1); -#endif mg_tls_ctx_init(&mgr, &opts); c = mg_http_connect(&mgr, "http://cesanta.com", f3, &ok); ASSERT(c != NULL);