|
| 1 | +#[feature(struct_variant)]; |
1 | 2 | #[link(name = "nss", vers = "0.0")]
|
2 | 3 |
|
3 | 4 | use std::os;
|
4 | 5 | use std::ptr;
|
5 |
| -use ffi::{NSS_Init, SECStatus, SECMOD_LoadUserModule, PRTrue, PRFalse, SECFailure, SECSuccess}; |
| 6 | +use std::rt::io::net::ip::{SocketAddr}; |
| 7 | +use ffi::{NSS_InitContext, SECStatus, SECMOD_LoadUserModule, PRTrue, PRFalse, |
| 8 | + SECFailure, SECSuccess, PR_OpenTCPSocket, PR_AF_INET, SECMOD_DestroyModule, |
| 9 | + NSS_ShutdownContext, SECMODModule, NSS_INIT_READONLY, NSS_INIT_PK11RELOAD}; |
| 10 | +use std::libc::{c_void}; |
| 11 | +use std::default::Default; |
6 | 12 |
|
7 | 13 | #[cfg(test)]
|
8 | 14 | mod tests;
|
9 | 15 |
|
10 | 16 | mod ffi;
|
11 | 17 |
|
12 |
| -pub fn init() -> SECStatus { |
| 18 | +pub struct NSS { |
| 19 | + |
| 20 | + nss_ctx: Option<*c_void>, |
| 21 | + nss_cert_mod: Option<SECMODModule>, |
| 22 | + |
| 23 | +} |
| 24 | + |
| 25 | +impl NSS { |
| 26 | + |
| 27 | +pub fn new() -> NSS { |
| 28 | + NSS { nss_ctx: None, nss_cert_mod: None } |
| 29 | +} |
| 30 | + |
| 31 | +pub fn init(&mut self) -> SECStatus { |
| 32 | + |
| 33 | + info!("NSS Init - Context: {}", self.nss_ctx.is_none()); |
| 34 | + if(self.nss_ctx.is_none()) { return SECSuccess; } |
13 | 35 | let dir = format!("sql:{}/.pki/nssdb", os::getenv("HOME").unwrap_or(~""));
|
14 |
| - dir.with_c_str(|nssdb| unsafe { NSS_Init(nssdb) }); |
15 |
| - |
16 |
| - unsafe { |
17 |
| - let module = *SECMOD_LoadUserModule("library=libnssckbi.so name=\"Root Certs\"".to_c_str().unwrap(), ptr::null(), PRFalse); |
18 |
| - if(module.loaded != PRTrue) |
19 |
| - { |
20 |
| - return SECFailure; |
21 |
| - } |
22 |
| - |
23 |
| - SECSuccess |
| 36 | + dir.with_c_str(|nssdb| self.nss_ctx = Some(unsafe { NSS_InitContext(nssdb, ptr::null(), ptr::null(), ptr::null(), ptr::null(), NSS_INIT_READONLY | NSS_INIT_PK11RELOAD) })); |
| 37 | + |
| 38 | + self.nss_cert_mod = Some(unsafe { *SECMOD_LoadUserModule("library=libnssckbi.so name=\"Root Certs\"".to_c_str().unwrap(), ptr::null(), PRFalse)}); |
| 39 | + if(self.nss_cert_mod.unwrap().loaded != PRTrue) |
| 40 | + { |
| 41 | + return SECFailure; |
24 | 42 | }
|
| 43 | + |
| 44 | + SECSuccess |
| 45 | +} |
| 46 | + |
| 47 | +pub fn uninit(&mut self) -> SECStatus { |
| 48 | + if(self.nss_ctx.is_none()) { return SECSuccess; } |
| 49 | + unsafe { |
| 50 | + SECMOD_DestroyModule(&self.nss_cert_mod.unwrap()); |
| 51 | + NSS_ShutdownContext(self.nss_ctx.unwrap()); |
| 52 | + } |
| 53 | + self.nss_ctx = None; |
| 54 | + SECSuccess |
| 55 | +} |
| 56 | + |
| 57 | +} |
| 58 | + |
| 59 | + |
| 60 | + |
| 61 | + |
| 62 | +pub fn ssl_connect(addr: SocketAddr) |
| 63 | +{ |
| 64 | + let socket = unsafe { PR_OpenTCPSocket(PR_AF_INET) }; |
25 | 65 | }
|
26 | 66 |
|
0 commit comments