From 03871d368e1fdffd74ffad57197d55c4d59bd77b Mon Sep 17 00:00:00 2001 From: Valerii Hiora Date: Fri, 12 Sep 2014 20:37:23 +0300 Subject: [PATCH] Enabling TLS1.2 support Unfortunately OS X comes with 0.9.8 bundled. There is a way to install a recent version through homebrew, however it is extremely hard to make it link agains brewed version without tricking link version --- src/ssl/ffi.rs | 11 +++++++++++ src/ssl/mod.rs | 7 ++++++- 2 files changed, 17 insertions(+), 1 deletion(-) diff --git a/src/ssl/ffi.rs b/src/ssl/ffi.rs index 2e21a24b..d284353a 100755 --- a/src/ssl/ffi.rs +++ b/src/ssl/ffi.rs @@ -103,8 +103,17 @@ pub static X509_FILETYPE_PEM: c_int = 1; pub static X509_FILETYPE_ASN1: c_int = 2; pub static X509_FILETYPE_DEFAULT: c_int = 3; +#[cfg(target_os = "macos")] +#[link(name="ssl.1.0.0")] +#[link(name="crypto.1.0.0")] +extern {} + + +#[cfg(not(target_os = "macos"))] #[link(name="ssl")] #[link(name="crypto")] +extern {} + extern "C" { pub fn CRYPTO_num_locks() -> c_int; pub fn CRYPTO_set_locking_callback(func: extern "C" fn(mode: c_int, @@ -120,6 +129,8 @@ extern "C" { pub fn SSLv2_method() -> *const SSL_METHOD; pub fn SSLv3_method() -> *const SSL_METHOD; pub fn TLSv1_method() -> *const SSL_METHOD; + pub fn TLSv1_1_method() -> *const SSL_METHOD; + pub fn TLSv1_2_method() -> *const SSL_METHOD; pub fn SSLv23_method() -> *const SSL_METHOD; pub fn SSL_CTX_new(method: *const SSL_METHOD) -> *mut SSL_CTX; diff --git a/src/ssl/mod.rs b/src/ssl/mod.rs index 785b8dfc..f0961ce9 100644 --- a/src/ssl/mod.rs +++ b/src/ssl/mod.rs @@ -48,6 +48,7 @@ fn init() { /// Determines the SSL method supported #[deriving(Show, Hash, PartialEq, Eq)] +#[allow(non_camel_case_types)] pub enum SslMethod { #[cfg(sslv2)] /// Only support the SSLv2 protocol @@ -58,6 +59,8 @@ pub enum SslMethod { Tlsv1, /// Support the SSLv2, SSLv3 and TLSv1 protocols Sslv23, + Tlsv1_1, + Tlsv1_2, } impl SslMethod { @@ -67,7 +70,9 @@ impl SslMethod { Sslv2 => ffi::SSLv2_method(), Sslv3 => ffi::SSLv3_method(), Tlsv1 => ffi::TLSv1_method(), - Sslv23 => ffi::SSLv23_method() + Sslv23 => ffi::SSLv23_method(), + Tlsv1_1 => ffi::TLSv1_1_method(), + Tlsv1_2 => ffi::TLSv1_2_method() } } }