Check a certificate against an OCSP responder.
More...
#include <freeradius-devel/server/base.h>
#include <freeradius-devel/curl/base.h>
#include <freeradius-devel/server/module_rlm.h>
#include <freeradius-devel/tls/bio.h>
#include <freeradius-devel/tls/log.h>
#include <freeradius-devel/tls/strerror.h>
#include <freeradius-devel/tls/utils.h>
#include <freeradius-devel/util/slab.h>
Go to the source code of this file.
Check a certificate against an OCSP responder.
- Id
- dba85ac6d27cc1f54e3983cb048fa743461907ee
- Copyright
- 2026 Network RADIUS SAS (legal.nosp@m.@net.nosp@m.workr.nosp@m.adiu.nosp@m.s.com)
Definition in file rlm_ocsp.c.
◆ rlm_ocsp_curl_context_t
| struct rlm_ocsp_curl_context_t |
Definition at line 93 of file rlm_ocsp.c.
| Data Fields |
|
char * |
body |
Pointer to the buffer which contains body data. |
|
struct curl_slist * |
headers |
Any HTTP headers which will be sent with the request. |
|
rlm_ocsp_response_t |
response |
Response context data. |
◆ rlm_ocsp_env_t
◆ rlm_ocsp_response_t
| struct rlm_ocsp_response_t |
Definition at line 80 of file rlm_ocsp.c.
| Data Fields |
|
size_t |
alloc |
Space allocated for buffer. |
|
char * |
buffer |
Raw incoming HTTP data. |
|
int |
code |
HTTP Status Code. |
|
rlm_ocsp_t const * |
inst |
Module instance. |
|
request_t * |
request |
Current request. |
|
write_state_t |
state |
Decoder state. |
|
size_t |
used |
Space used in buffer. |
◆ rlm_ocsp_t
Definition at line 40 of file rlm_ocsp.c.
| Data Fields |
|
char const * |
ca_file |
File containing certs for verifying OCSP responses. |
|
char const * |
ca_path |
Directory containing certs for verifying OCSP responses. |
|
fr_curl_conn_config_t |
conn_config |
Reusable CURL handle config. |
|
int |
leeway |
Seconds of leeway allowed in checking response thisUpdate |
|
int |
max_age |
Maximum age of thisUpdate allowed in response checks. |
|
uint64_t |
max_body_in |
Largest response we accept. |
|
bool |
override_url |
Always use the configured OCSP URL even if the certificate contains one. |
|
bool |
softfail |
Should the module soft fail if the responder is not available. |
|
char const * |
url |
Override / fallback OCSP URL. |
|
bool |
use_nonce |
Include a nonce in OCSP requests/. |
|
bool |
verifycert |
Should the certificate in responses be verified. |
◆ REST_BODY_ALLOC_CHUNK
| #define REST_BODY_ALLOC_CHUNK 1024 |
◆ ocsp_status_t
| Enumerator |
|---|
| OCSP_STATUS_FAILED | |
| OCSP_STATUS_OK | |
| OCSP_STATUS_SKIPPED | |
Definition at line 70 of file rlm_ocsp.c.
◆ write_state_t
| Enumerator |
|---|
| WRITE_STATE_INIT | |
| WRITE_STATE_PARSE_HEADERS | |
| WRITE_STATE_PARSE_CONTENT | |
| WRITE_STATE_DISCARD | |
Definition at line 63 of file rlm_ocsp.c.
◆ mod_instantiate()
Instantiate the module.
Definition at line 803 of file rlm_ocsp.c.
◆ attr_tls_ocsp_cert_valid
◆ attr_tls_ocsp_next_update
◆ dict_freeradius
◆ module_config
Initial value:= {
}
#define CONF_PARSER_TERMINATOR
#define FR_CONF_OFFSET(_name, _struct, _field)
conf_parser_t which parses a single CONF_PAIR, writing the result to a field in a struct
#define FR_CONF_OFFSET_FLAGS(_name, _flags, _struct, _field)
conf_parser_t which parses a single CONF_PAIR, writing the result to a field in a struct
#define FR_CONF_OFFSET_SUBSECTION(_name, _flags, _struct, _field, _subcs)
conf_parser_t which populates a sub-struct using a CONF_SECTION
@ CONF_FLAG_FILE_READABLE
File matching value must exist, and must be readable.
conf_parser_t fr_curl_conn_config[]
static char const * url[FR_RADIUS_FAIL_MAX+1]
Definition at line 102 of file rlm_ocsp.c.
◆ rlm_ocsp
Initial value:= {
.common = {
},
}
#define MODULE_MAGIC_INIT
Stop people using different module/library/server versions together.
static const conf_parser_t config[]
static int mod_instantiate(module_inst_ctx_t const *mctx)
Instantiate the module.
static conf_parser_t module_config[]
Definition at line 823 of file rlm_ocsp.c.
◆ rlm_ocsp_dict
Initial value:= {
}
#define DICT_AUTOLOAD_TERMINATOR
static fr_dict_t const * dict_freeradius
Definition at line 126 of file rlm_ocsp.c.
◆ rlm_ocsp_dict_attr
Initial value:= {
}
@ FR_TYPE_UINT32
32 Bit unsigned integer.
static fr_dict_attr_t const * attr_tls_ocsp_next_update
static fr_dict_attr_t const * attr_tls_ocsp_cert_valid
Definition at line 135 of file rlm_ocsp.c.