module Network.CommSec.KeyExchange
( connect
, accept
, CS.send, CS.recv, CS.Connection(..), CS.close
, Net.HostName, Net.PortNumber
) where
import qualified Network.Socket as Net
import qualified Network.Socket.ByteString as NetBS
import Crypto.Types.PubKey.RSA
import Crypto.Cipher.AES128
import Crypto.Classes
import Crypto.Util
import Crypto.Modes (zeroIV)
import Crypto.Hash.CryptoAPI
import Control.Exception (bracket)
import Control.Monad
import Control.Monad.CryptoRandom
import Data.Maybe (isNothing, fromMaybe)
import qualified Codec.Crypto.RSA as RSA
import qualified Data.ByteString as B
import Data.ByteString (ByteString)
import Data.ByteString.Lazy (fromStrict, toChunks)
import qualified Data.ByteString.Lazy as L
import Data.Serialize
import Data.Serialize.Get
import Data.Serialize.Put
import Crypto.Random.DRBG
import Data.Maybe (listToMaybe)
import Control.Concurrent
import Foreign.Storable
import qualified Network.CommSec as CS
import Network.CommSec hiding (accept, connect)
import Network.CommSec.Package (InContext(..), OutContext(..))
import qualified Network.CommSec.KeyExchange.Internal as I
import qualified Network.CommSec.KeyExchange.Socket as S
connect :: Net.HostName
-> Net.PortNumber
-> [PublicKey]
-> PrivateKey
-> IO (PublicKey,Connection)
connect host port thems us = do
ai <- resolve1 Active (Just host) port
socket <- openSocket ai
res <- S.connect socket (Net.addrAddress ai) thems us
case res of
Nothing -> fail "Could not agree on a key."
Just x -> return x
data IsPassive = Passive | Active
resolve1 :: IsPassive -> Maybe Net.HostName -> Net.PortNumber -> IO Net.AddrInfo
resolve1 psv h port = do
let passiveFlag =
case psv of
Passive -> [Net.AI_PASSIVE]
Active -> []
flags = Net.defaultHints
{ Net.addrSocketType = Net.Stream
, Net.addrFlags = passiveFlag ++ [Net.AI_ADDRCONFIG]
}
ais <- Net.getAddrInfo (Just flags) h (Just (show port))
case ais of
[] -> fail ("Could not resolve host " ++ fromMaybe "" h)
ai:_ -> return ai
openSocket :: Net.AddrInfo -> IO Net.Socket
openSocket Net.AddrInfo{..} = Net.socket addrFamily addrSocketType addrProtocol
accept :: Net.PortNumber -> [PublicKey] -> PrivateKey -> Maybe Net.HostName -> IO (PublicKey,Connection)
accept port thems us addr = do
ai <- resolve1 Passive addr port
bracket (openSocket ai) Net.close $ \sock -> do
Net.setSocketOption sock Net.ReuseAddr 1
Net.bind sock (Net.addrAddress ai)
Net.listen sock 1
mconn <- S.accept sock thems us
case mconn of
Nothing -> fail "Failed to perform key exchange"
Just res -> return res