mirror of
https://github.com/curl/curl.git
synced 2026-08-24 19:13:39 +03:00
parent
7a14898264
commit
bdb7d8b004
43 changed files with 70 additions and 67 deletions
|
|
@ -658,7 +658,7 @@ CURLcode Curl_cf_https_setup(struct Curl_easy *data,
|
|||
|
||||
if(conn->bits.tls_enable_alpn) {
|
||||
#ifdef USE_HTTPSRR
|
||||
/* Is there a HTTPSRR use its ALPNs here.
|
||||
/* Is there an HTTPSRR use its ALPNs here.
|
||||
* We are here after having selected a connection to a host+port and
|
||||
* can no longer change that. Any HTTPSRR advice for other hosts and ports
|
||||
* we need to ignore. */
|
||||
|
|
|
|||
|
|
@ -129,7 +129,7 @@ void Curl_sspi_global_cleanup(void)
|
|||
/*
|
||||
* Curl_create_sspi_identity()
|
||||
*
|
||||
* This is used to populate a SSPI identity structure based on the supplied
|
||||
* This is used to populate an SSPI identity structure based on the supplied
|
||||
* username and password.
|
||||
*
|
||||
* Parameters:
|
||||
|
|
@ -221,7 +221,7 @@ CURLcode Curl_create_sspi_identity(const char *userp, const char *passwdp,
|
|||
/*
|
||||
* Curl_sspi_free_identity()
|
||||
*
|
||||
* This is used to free the contents of a SSPI identifier structure.
|
||||
* This is used to free the contents of an SSPI identifier structure.
|
||||
*
|
||||
* Parameters:
|
||||
*
|
||||
|
|
|
|||
|
|
@ -45,7 +45,7 @@
|
|||
CURLcode Curl_sspi_global_init(void);
|
||||
void Curl_sspi_global_cleanup(void);
|
||||
|
||||
/* This is used to populate the domain in a SSPI identity structure */
|
||||
/* This is used to populate the domain in an SSPI identity structure */
|
||||
CURLcode Curl_override_sspi_http_realm(const char *chlg,
|
||||
SEC_WINNT_AUTH_IDENTITY *identity);
|
||||
|
||||
|
|
|
|||
|
|
@ -2716,8 +2716,8 @@ static CURLcode ftp_pp_statemachine(struct Curl_easy *data,
|
|||
#endif
|
||||
|
||||
if(data->set.use_ssl && !conn->bits.ftp_use_control_ssl) {
|
||||
/* We do not have a SSL/TLS control connection yet, but FTPS is
|
||||
requested. Try a FTPS connection now */
|
||||
/* We do not have an SSL/TLS control connection yet, but FTPS is
|
||||
requested. Try an FTPS connection now */
|
||||
|
||||
ftpc->count3 = 0;
|
||||
switch(data->set.ftpsslauth) {
|
||||
|
|
|
|||
|
|
@ -3638,7 +3638,7 @@ static CURLcode http_on_response(struct Curl_easy *data,
|
|||
/* We expect more response from HTTP/2 later */
|
||||
k->header = TRUE;
|
||||
k->headerline = 0; /* restart the header line counter */
|
||||
k->httpversion_sent = 20; /* It's a HTTP/2 request now */
|
||||
k->httpversion_sent = 20; /* It's an HTTP/2 request now */
|
||||
/* Any remaining `buf` bytes are already HTTP/2 and passed to
|
||||
* be processed. */
|
||||
result = Curl_http2_upgrade(data, conn, FIRSTSOCKET, buf, blen);
|
||||
|
|
|
|||
|
|
@ -49,7 +49,7 @@ typedef enum {
|
|||
POST_CR state. */
|
||||
CHUNK_DATA,
|
||||
|
||||
/* POSTLF should get a CR and then a LF and nothing else, then move back to
|
||||
/* POSTLF should get a CR and then an LF and nothing else, then move back to
|
||||
HEX as the CRLF combination marks the end of a chunk. A missing CR is no
|
||||
big deal. */
|
||||
CHUNK_POSTLF,
|
||||
|
|
@ -64,7 +64,7 @@ typedef enum {
|
|||
CHUNK_TRAILER,
|
||||
|
||||
/* A trailer CR has been found - next state is CHUNK_TRAILER_POSTCR.
|
||||
Next char must be a LF */
|
||||
Next char must be an LF */
|
||||
CHUNK_TRAILER_CR,
|
||||
|
||||
/* A trailer LF must be found now, otherwise CHUNKE_BAD_CHUNK will be
|
||||
|
|
|
|||
|
|
@ -1032,7 +1032,7 @@ static CURLcode imap_state_capability_resp(struct Curl_easy *data,
|
|||
|
||||
(void)instate; /* no use for this yet */
|
||||
|
||||
/* Do we have a untagged response? */
|
||||
/* Do we have an untagged response? */
|
||||
if(imapcode == '*') {
|
||||
line += 2;
|
||||
|
||||
|
|
|
|||
|
|
@ -56,7 +56,7 @@
|
|||
* Returns `dst' (as a const)
|
||||
* Note:
|
||||
* - uses no statics
|
||||
* - takes a unsigned char* not an in_addr as input
|
||||
* - takes an unsigned char* not an in_addr as input
|
||||
*/
|
||||
static char *inet_ntop4(const unsigned char *src, char *dst, size_t size)
|
||||
{
|
||||
|
|
|
|||
|
|
@ -874,7 +874,7 @@ static CURLcode pop3_state_capa_resp(struct Curl_easy *data, int pop3code,
|
|||
line = curlx_dyn_ptr(&pop3c->pp.recvbuf);
|
||||
len = pop3c->pp.nfinal;
|
||||
|
||||
/* Do we have a untagged continuation response? */
|
||||
/* Do we have an untagged continuation response? */
|
||||
if(pop3code == '*') {
|
||||
/* Does the server support the STLS capability? */
|
||||
if(len >= 4 && !memcmp(line, "STLS", 4))
|
||||
|
|
|
|||
|
|
@ -2022,7 +2022,7 @@ static CURLcode setopt_cptr(struct Curl_easy *data, CURLoption option,
|
|||
break;
|
||||
case CURLOPT_SSL_CTX_DATA:
|
||||
/*
|
||||
* Set a SSL_CTX callback parameter pointer
|
||||
* Set an SSL_CTX callback parameter pointer
|
||||
*/
|
||||
#ifdef USE_SSL
|
||||
if(Curl_ssl_supports(data, SSLSUPP_SSL_CTX)) {
|
||||
|
|
@ -2787,7 +2787,7 @@ static CURLcode setopt_func(struct Curl_easy *data, CURLoption option,
|
|||
break;
|
||||
case CURLOPT_SSL_CTX_FUNCTION:
|
||||
/*
|
||||
* Set a SSL_CTX callback
|
||||
* Set an SSL_CTX callback
|
||||
*/
|
||||
#ifdef USE_SSL
|
||||
if(Curl_ssl_supports(data, SSLSUPP_SSL_CTX)) {
|
||||
|
|
|
|||
|
|
@ -601,7 +601,7 @@ static CURLcode smtp_perform_authentication(struct Curl_easy *data,
|
|||
*
|
||||
* smtp_perform_command()
|
||||
*
|
||||
* Sends a SMTP based command.
|
||||
* Sends an SMTP based command.
|
||||
*/
|
||||
static CURLcode smtp_perform_command(struct Curl_easy *data,
|
||||
struct smtp_conn *smtpc,
|
||||
|
|
@ -1036,7 +1036,7 @@ static CURLcode smtp_state_ehlo_resp(struct Curl_easy *data,
|
|||
|
||||
if(smtpcode != 1) {
|
||||
if(data->set.use_ssl && !Curl_conn_is_ssl(data->conn, FIRSTSOCKET)) {
|
||||
/* We do not have a SSL/TLS connection yet, but SSL is requested */
|
||||
/* We do not have an SSL/TLS connection yet, but SSL is requested */
|
||||
if(smtpc->tls_supported)
|
||||
/* Switch to TLS connection now */
|
||||
result = smtp_perform_starttls(data, smtpc);
|
||||
|
|
|
|||
|
|
@ -242,7 +242,7 @@ CURLcode Curl_auth_create_digest_md5_message(struct Curl_easy *data,
|
|||
/*
|
||||
* Curl_override_sspi_http_realm()
|
||||
*
|
||||
* This is used to populate the domain in a SSPI identity structure
|
||||
* This is used to populate the domain in an SSPI identity structure
|
||||
* The realm is extracted from the challenge message and used as the
|
||||
* domain if it is not already explicitly set.
|
||||
*
|
||||
|
|
|
|||
|
|
@ -39,7 +39,7 @@
|
|||
/*
|
||||
* Curl_auth_build_spn()
|
||||
*
|
||||
* This is used to build a SPN string in the following formats:
|
||||
* This is used to build an SPN string in the following formats:
|
||||
*
|
||||
* service/host@realm (Not currently used)
|
||||
* service/host (Not used by GSS-API)
|
||||
|
|
|
|||
|
|
@ -60,7 +60,7 @@ struct gsasldata;
|
|||
*/
|
||||
bool Curl_auth_allowed_to_host(struct Curl_easy *data);
|
||||
|
||||
/* This is used to build a SPN string */
|
||||
/* This is used to build an SPN string */
|
||||
#if !defined(USE_WINDOWS_SSPI)
|
||||
char *Curl_auth_build_spn(const char *service, const char *host,
|
||||
const char *realm);
|
||||
|
|
|
|||
|
|
@ -233,7 +233,7 @@ static void unload_file(gnutls_datum_t data)
|
|||
}
|
||||
|
||||
|
||||
/* this function does a SSL/TLS (re-)handshake */
|
||||
/* this function does an SSL/TLS (re-)handshake */
|
||||
static CURLcode handshake(struct Curl_cfilter *cf,
|
||||
struct Curl_easy *data)
|
||||
{
|
||||
|
|
|
|||
|
|
@ -94,7 +94,7 @@ Curl_tls_keylog_write_line(const char *line)
|
|||
|
||||
linelen = strlen(line);
|
||||
if(linelen == 0 || linelen > sizeof(buf) - 2) {
|
||||
/* Empty line or too big to fit in a LF and NUL. */
|
||||
/* Empty line or too big to fit in an LF and NUL. */
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -61,7 +61,7 @@ bool Curl_tls_keylog_write(const char *label,
|
|||
const unsigned char *secret, size_t secretlen);
|
||||
|
||||
/*
|
||||
* Appends a line to the key log file, ensure it is terminated by a LF.
|
||||
* Appends a line to the key log file, ensure it is terminated by an LF.
|
||||
* Returns true iff the key log file is open and a valid line was provided.
|
||||
*/
|
||||
bool Curl_tls_keylog_write_line(const char *line);
|
||||
|
|
|
|||
|
|
@ -4048,7 +4048,7 @@ CURLcode Curl_ossl_ctx_init(struct ossl_ctx *octx,
|
|||
CVE-2010-4180 when using previous OpenSSL versions we no longer enable
|
||||
this option regardless of OpenSSL version and SSL_OP_ALL definition.
|
||||
|
||||
OpenSSL added a work-around for a SSL 3.0/TLS 1.0 CBC vulnerability:
|
||||
OpenSSL added a work-around for an SSL 3.0/TLS 1.0 CBC vulnerability:
|
||||
https://web.archive.org/web/20240114184648/openssl.org/~bodo/tls-cbc.txt.
|
||||
In 0.9.6e they added a bit to SSL_OP_ALL that _disables_ that work-around
|
||||
despite the fact that SSL_OP_ALL is documented to do "rather harmless"
|
||||
|
|
|
|||
|
|
@ -113,7 +113,7 @@ CURLcode Curl_ssl_scache_add_obj(struct Curl_cfilter *cf,
|
|||
void *sobj,
|
||||
Curl_ssl_scache_obj_dtor *sobj_dtor_cb);
|
||||
|
||||
/* All about a SSL session ticket */
|
||||
/* All about an SSL session ticket */
|
||||
struct Curl_ssl_session {
|
||||
const void *sdata; /* session ticket data, plain bytes */
|
||||
size_t sdata_len; /* number of bytes in sdata */
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue