5 // Martin Baulig <martin.baulig@xamarin.com>
7 // Copyright (c) 2015 Xamarin, Inc.
9 // Permission is hereby granted, free of charge, to any person obtaining a copy
10 // of this software and associated documentation files (the "Software"), to deal
11 // in the Software without restriction, including without limitation the rights
12 // to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
13 // copies of the Software, and to permit persons to whom the Software is
14 // furnished to do so, subject to the following conditions:
16 // The above copyright notice and this permission notice shall be included in
17 // all copies or substantial portions of the Software.
19 // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
20 // IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
21 // FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
22 // AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
23 // LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
24 // OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
28 #if MONO_SECURITY_ALIAS
29 extern alias MonoSecurity;
32 #if MONO_SECURITY_ALIAS
33 using MonoSecurity::Mono.Security.Interface;
35 using Mono.Security.Interface;
37 using XX509CertificateCollection = System.Security.Cryptography.X509Certificates.X509CertificateCollection;
43 using System.Net.Sockets;
44 using System.Net.Security;
45 using System.Threading.Tasks;
46 using System.Security.Authentication;
47 using System.Security.Cryptography.X509Certificates;
48 using System.Security.Principal;
49 using System.Security.Cryptography;
51 namespace Mono.Net.Security
55 readonly IMonoTlsProvider provider;
56 readonly HttpWebRequest request;
57 readonly NetworkStream networkStream;
59 IMonoSslStream sslStream;
60 WebExceptionStatus status;
62 internal HttpWebRequest Request {
63 get { return request; }
66 internal IMonoSslStream SslStream {
67 get { return sslStream; }
70 internal WebExceptionStatus ExceptionStatus {
71 get { return status; }
74 internal bool CertificateValidationFailed {
79 readonly ChainValidationHelper validationHelper;
80 readonly MonoTlsSettings settings;
82 public MonoTlsStream (HttpWebRequest request, NetworkStream networkStream)
84 this.request = request;
85 this.networkStream = networkStream;
87 settings = request.TlsSettings;
88 provider = request.TlsProvider ?? MonoTlsProviderFactory.GetProviderInternal ();
89 status = WebExceptionStatus.SecureChannelFailure;
91 validationHelper = ChainValidationHelper.Create (provider.Provider, ref settings, this);
94 internal Stream CreateStream (byte[] buffer)
96 sslStream = provider.CreateSslStream (networkStream, false, settings);
99 sslStream.AuthenticateAsClient (
100 request.Address.Host, request.ClientCertificates,
101 (SslProtocols)ServicePointManager.SecurityProtocol,
102 ServicePointManager.CheckCertificateRevocationList);
104 status = WebExceptionStatus.Success;
105 } catch (Exception ex) {
106 status = WebExceptionStatus.SecureChannelFailure;
109 if (CertificateValidationFailed)
110 status = WebExceptionStatus.TrustFailure;
112 if (status == WebExceptionStatus.Success)
113 request.ServicePoint.UpdateClientCertificate (sslStream.InternalLocalCertificate);
115 request.ServicePoint.UpdateClientCertificate (null);
122 sslStream.Write (buffer, 0, buffer.Length);
124 status = WebExceptionStatus.SendFailure;
129 return sslStream.AuthenticatedStream;