FFmpeg
Loading...
Searching...
No Matches
tls.h
Go to the documentation of this file.
1/*
2 * TLS/DTLS/SSL Protocol
3 * Copyright (c) 2011 Martin Storsjo
4 * Copyright (c) 2025 Jack Lau
5 *
6 * This file is part of FFmpeg.
7 *
8 * FFmpeg is free software; you can redistribute it and/or
9 * modify it under the terms of the GNU Lesser General Public
10 * License as published by the Free Software Foundation; either
11 * version 2.1 of the License, or (at your option) any later version.
12 *
13 * FFmpeg is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 * Lesser General Public License for more details.
17 *
18 * You should have received a copy of the GNU Lesser General Public
19 * License along with FFmpeg; if not, write to the Free Software
20 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
21 */
22
23#ifndef AVFORMAT_TLS_H
24#define AVFORMAT_TLS_H
25
26#include "libavutil/bprint.h"
27#include "libavutil/opt.h"
28
29#include "url.h"
30
31/**
32 * Maximum size limit of a certificate and private key size.
33 */
34#define MAX_CERTIFICATE_SIZE 8192
35
36/**
37 * The DTLS content type.
38 * See https://tools.ietf.org/html/rfc2246#section-6.2.1
39 * change_cipher_spec(20), alert(21), handshake(22), application_data(23)
40 */
41#define DTLS_CONTENT_TYPE_CHANGE_CIPHER_SPEC 20
42/**
43 * The DTLS record layer header has a total size of 13 bytes, consisting of
44 * ContentType (1 byte), ProtocolVersion (2 bytes), Epoch (2 bytes),
45 * SequenceNumber (6 bytes), and Length (2 bytes).
46 * See https://datatracker.ietf.org/doc/html/rfc9147#section-4
47 */
48#define DTLS_RECORD_LAYER_HEADER_LEN 13
49/**
50 * The DTLS version number, which is 0xfeff for DTLS 1.0, or 0xfefd for DTLS 1.2.
51 * See https://datatracker.ietf.org/doc/html/rfc9147#name-the-dtls-record-layer
52 */
53#define DTLS_VERSION_10 0xfeff
54#define DTLS_VERSION_12 0xfefd
55
56typedef struct TLSShared {
57 const AVClass *class;
58 char *ca_file;
59 int verify;
60 char *cert_file;
61 char *key_file;
62 int listen;
63
64 char *host;
66
67 char underlying_host[200];
69
73
76
77 /* The certificate and private key content used for DTLS handshake */
78 char* cert_buf;
79 char* key_buf;
80
81 /**
82 * The size of RTP packet, should generally be set to MTU.
83 * Note that pion requires a smaller value, for example, 1200.
84 */
85 int mtu;
86} TLSShared;
87
88#define TLS_OPTFL (AV_OPT_FLAG_DECODING_PARAM | AV_OPT_FLAG_ENCODING_PARAM)
89
90#define FF_TLS_CLIENT_OPTIONS(pstruct, options_field) \
91 {"ca_file", "Certificate Authority database file", offsetof(pstruct, options_field . ca_file), AV_OPT_TYPE_STRING, .flags = TLS_OPTFL }, \
92 {"cafile", "Certificate Authority database file", offsetof(pstruct, options_field . ca_file), AV_OPT_TYPE_STRING, .flags = TLS_OPTFL }, \
93 {"tls_verify", "Verify the peer certificate", offsetof(pstruct, options_field . verify), AV_OPT_TYPE_BOOL, { .i64 = 1 }, 0, 1, .flags = TLS_OPTFL }, \
94 {"verify", "Verify the peer certificate", offsetof(pstruct, options_field . verify), AV_OPT_TYPE_BOOL, { .i64 = 1 }, 0, 1, .flags = TLS_OPTFL }, \
95 {"cert_file", "Certificate file", offsetof(pstruct, options_field . cert_file), AV_OPT_TYPE_STRING, .flags = TLS_OPTFL }, \
96 {"cert", "Certificate file", offsetof(pstruct, options_field . cert_file), AV_OPT_TYPE_STRING, .flags = TLS_OPTFL }, \
97 {"key_file", "Private key file", offsetof(pstruct, options_field . key_file), AV_OPT_TYPE_STRING, .flags = TLS_OPTFL }, \
98 {"key", "Private key file", offsetof(pstruct, options_field . key_file), AV_OPT_TYPE_STRING, .flags = TLS_OPTFL }, \
99 {"verifyhost", "Verify against a specific hostname", offsetof(pstruct, options_field . host), AV_OPT_TYPE_STRING, .flags = TLS_OPTFL }
100
101#define TLS_COMMON_OPTIONS(pstruct, options_field) \
102 {"listen", "Listen for incoming connections", offsetof(pstruct, options_field . listen), AV_OPT_TYPE_INT, { .i64 = 0 }, 0, 1, .flags = TLS_OPTFL }, \
103 {"http_proxy", "Set proxy to tunnel through", offsetof(pstruct, options_field . http_proxy), AV_OPT_TYPE_STRING, .flags = TLS_OPTFL }, \
104 {"external_sock", "Use external socket", offsetof(pstruct, options_field . external_sock), AV_OPT_TYPE_BOOL, { .i64 = 0 }, 0, 1, .flags = TLS_OPTFL }, \
105 {"use_srtp", "Enable use_srtp DTLS extension", offsetof(pstruct, options_field . use_srtp), AV_OPT_TYPE_BOOL, { .i64 = 0 }, 0, 1, .flags = TLS_OPTFL }, \
106 {"mtu", "Maximum Transmission Unit", offsetof(pstruct, options_field . mtu), AV_OPT_TYPE_INT, { .i64 = 0 }, 0, INT_MAX, .flags = TLS_OPTFL}, \
107 {"cert_pem", "Certificate PEM string", offsetof(pstruct, options_field . cert_buf), AV_OPT_TYPE_STRING, .flags = TLS_OPTFL }, \
108 {"key_pem", "Private key PEM string", offsetof(pstruct, options_field . key_buf), AV_OPT_TYPE_STRING, .flags = TLS_OPTFL }, \
109 FF_TLS_CLIENT_OPTIONS(pstruct, options_field)
110
111int ff_tls_parse_host(TLSShared *s, char *hostname, int hostname_size, int *port_ptr, const char *uri);
112
113int ff_tls_open_underlying(TLSShared *c, URLContext *parent, const char *uri, AVDictionary **options);
114
115int ff_url_read_all(const char *url, AVBPrint *bp);
116
118
119int ff_dtls_export_materials(URLContext *h, char *dtls_srtp_materials, size_t materials_sz);
120
121int ff_ssl_read_key_cert(char *key_url, char *cert_url, char *key_buf, size_t key_sz, char *cert_buf, size_t cert_sz, char **fingerprint);
122
123int ff_ssl_gen_key_cert(char *key_buf, size_t key_sz, char *cert_buf, size_t cert_sz, char **fingerprint);
124
125void ff_gnutls_init(void);
126void ff_gnutls_deinit(void);
127
128/**
129 * Whether the packet is a DTLS packet, as defined by RFC 5764 Section 5.1.2.
130 */
131int ff_is_dtls_packet(const uint8_t *buf, int size);
132
133#endif /* AVFORMAT_TLS_H */
AVBPrint public header.
#define s(width, name)
Definition cbs_vp9.c:198
AVOptions.
Describe the class of an AVClass context structure.
Definition log.h:76
char underlying_host[200]
Definition tls.h:67
int use_srtp
Definition tls.h:75
int listen
Definition tls.h:62
int numerichost
Definition tls.h:68
int verify
Definition tls.h:59
char * ca_file
Definition tls.h:58
URLContext * udp
Definition tls.h:71
int is_dtls
Definition tls.h:74
int mtu
The size of RTP packet, should generally be set to MTU.
Definition tls.h:85
int external_sock
Definition tls.h:70
URLContext * tcp
Definition tls.h:72
char * key_file
Definition tls.h:61
char * key_buf
Definition tls.h:79
char * host
Definition tls.h:64
char * cert_buf
Definition tls.h:78
char * cert_file
Definition tls.h:60
char * http_proxy
Definition tls.h:65
void ff_gnutls_deinit(void)
Definition tls_gnutls.c:359
void ff_gnutls_init(void)
Definition tls_gnutls.c:348
int ff_ssl_gen_key_cert(char *key_buf, size_t key_sz, char *cert_buf, size_t cert_sz, char **fingerprint)
Definition tls_gnutls.c:299
int ff_ssl_read_key_cert(char *key_url, char *cert_url, char *key_buf, size_t key_sz, char *cert_buf, size_t cert_sz, char **fingerprint)
Definition tls_gnutls.c:115
int ff_dtls_export_materials(URLContext *h, char *dtls_srtp_materials, size_t materials_sz)
Definition tls_gnutls.c:379
int ff_url_read_all(const char *url, AVBPrint *bp)
Read all data from the given URL url and store it in the given buffer bp.
Definition tls.c:128
int ff_tls_open_underlying(TLSShared *c, URLContext *parent, const char *uri, AVDictionary **options)
Definition tls.c:54
int ff_tls_parse_host(TLSShared *s, char *hostname, int hostname_size, int *port_ptr, const char *uri)
Definition tls.c:35
int ff_is_dtls_packet(const uint8_t *buf, int size)
Whether the packet is a DTLS packet, as defined by RFC 5764 Section 5.1.2.
Definition tls.c:167
int ff_tls_set_external_socket(URLContext *h, URLContext *sock)
Definition tls_gnutls.c:366
int size
unbuffered private I/O API
static double c[64]