> > From: jackie [mailto:[EMAIL PROTECTED]]
> > Sent: Monday, November 22, 1999 8:30 AM
> > To: [EMAIL PROTECTED]
> > Subject: Re: openssl inside linux kernel
> >
> >
> > I would like to regard "SSL in kernel" as accessing SSL functions
> > through normal socket API. such as the SSL that Microsoft
> > offered in winsock2.
> 
> Hmmm, that's interesting. There is a built in support for SSL in
> winsock2? How can one obtain some info on this matter? All the MSDN
> was willing to say about "SSL AND Winsock2" was the setsockopt manual,
> and no details there. What I learned from
> http://www.sockets.com/winsock2.htm is that there was such a beast,
> but it disappeared soon after it's premier appearance. So, any input?
> 

I'm not sure that Microsoft is supporting this idea anymore.  The
concept was that after a socket() was created but before accept() or
connect() was issued that the program could issue 

  setsocketopt(socket, SOL_SOCKET, SO_SECURE, &optval, sizeof(optval))

to request the negotiation of socket level security.  But there is no
mention of this in the current headers for NT4 or Win2000.  

Here are some quoted sections:

  "Secure Socket Layer Support

  "Windows CE provides support for SSL, including the SSL 2.0, SSL 3.0,
  and PCT 1.0 security protocols. Secure sockets are available from both
  the WinInet API and the Winsock API. To utilize SSL from Winsock, the
  following steps need to be taken.

  "First, create a callback function that will be called by the Winsock
  security provider when a certificate is received from a remote
  party. This function is responsible for ensuring the validity of the
  certificate received. Next, create a socket with the socket API. Set
  the socket options via the setsockopt API, with the level parameter
  set to SO_SOCKET, the optname set to SO_SECURE, and the optval (a
  DWORD), set to SO_SEC_SSL. Call the WSAIoctl API to complete the
  setup. This includes calling WSAIoctl with the
  SO_SSL_SET_VALIDATE_CERT_HOOK option to install the callback function
  created in the first step. Finally, make a connection and use Winsock
  calls in the normal fashion.

  "The most involved step in the process is writing the callback function
  for validating certificates. The purpose of the callback is
  twofold. First, it ensures the certificate has not expired. Second, it
  verifies that the identity contained within the certificate matches
  that of the remote party. More in-depth information on SSL callback
  functions can be found in the Platform SDK."

  ---

  "To set a socket to secure mode, the option level parameter, level,
  must set to SO_SOCKET, the option name, optname to SO_SECURE, and the
  option value, optval, must be a pointer to a DWORD containing
  SO_SEC_SSL. These settings ensure that the Unified Secure Sockets
  Layer (SSL) package be used. The following code example shows how to
  set a socket to secure mode. 

  DWORD optval = SO_SEC_SSL;
  err = setsockopt(
     Socket,
     SOL_SOCKET,
     SO_SECURE,
     &optval,
     sizeof(optval)
     );."

  ---

  "Implementing a Secure Socket

  "The following procedure describes how to establish a secure socket
  connection.

    "To implement a secure socket

    . Create a socket with the socket function. 
    . Set the socket in secure mode with the setsockopt function. Set the
      level parameter to SO_SOCKET, optname to SO_SECURE, and optval to a
      DWORD set to SO_SEC_SSL. 
    . Specify the certificate validation callback function by calling
      WSAIoctl with the SO_SSL_SET_VALIDATE_CERT_HOOK control code. 
      To specify a particular security protocol, call WSAIoctl with the
      SO_SSL_GET_PROTOCOLS control code to determine the default
      protocols. Then call WSAIoctl with the SO_SSL_SET_PROTOCOLS control
      code to select the protocols to be enabled. Otherwise, Windows CE
      selects the protocol. 
    . Make a connection with the connect function. 
      The certificate callback function is automatically called. The
      connection can be completed only if the callback function verifies the
      acceptability of the certificate by returning SSL_ERR_OKAY. 

    . Transmit and send. 
      The send and recv functions automatically encode and decode data. 

    . When finished, close the socket with the closesocket function."

  ---

  "Using a Deferred Handshake

  "A deferred handshake enables an application to create an unsecured
   connection and then later convert it to a secure connection.

  "To implement secure sockets with a deferred handshake

  . Create a socket with the socket function. 
  . Set the socket in secure mode with setsockopt. 
    The level parameter should be set to SO_SOCKET, optname should be set
    to SO_SECURE, and optval should be a DWORD set to SO_SEC_SSL. 

  . Specify the certificate validation callback function by calling
    WSAIoctl with the SO_SSL_SET_VALIDATE_CERT_HOOK control code. 
  . Set the socket in deferred handshake mode with WSAIoctl. The control
    code should be set to SO_SSL_SET_FLAGS and the flag set to
    SSL_FLAG_DEFER_HANDSHAKE. 
  . Establish a nonsecure connection with the remote party using connect. 
  . Transmit and receive unencoded data. 
  . To switch to secure mode, call WSAIoctl with the
    SO_SSL_PERFORM_HANDSHAKE control code passing in the target server
    name. 
    The certificate callback function is automatically called. The
    handshake is successful only if the callback function verifies the
    acceptability of the certificate by returning SSL_ERR_OKAY. 

  . Transmit and receive. 
    The send and recv functions encode and decode the data automatically. 

  . Close the socket with closesocket when finished. 
 








    Jeffrey Altman * Sr.Software Designer * Kermit-95 for Win32 and OS/2
                 The Kermit Project * Columbia University
              612 West 115th St #716 * New York, NY * 10025
  http://www.kermit-project.org/k95.html * [EMAIL PROTECTED]


______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to