4 * The secure anycast tunneling protocol (satp) defines a protocol used
5 * for communication between any combination of unicast and anycast
6 * tunnel endpoints. It has less protocol overhead than IPSec in Tunnel
7 * mode and allows tunneling of every ETHER TYPE protocol (e.g.
8 * ethernet, ip, arp ...). satp directly includes cryptography and
9 * message authentication based on the methodes used by SRTP. It is
10 * intended to deliver a generic, scaleable and secure solution for
11 * tunneling and relaying of packets of any protocol.
14 * Copyright (C) 2007-2008 Othmar Gsenger, Erwin Nindl,
15 * Christian Pointner <satp@wirdorange.org>
17 * This file is part of Anytun.
19 * Anytun is free software: you can redistribute it and/or modify
20 * it under the terms of the GNU General Public License version 3 as
21 * published by the Free Software Foundation.
23 * Anytun is distributed in the hope that it will be useful,
24 * but WITHOUT ANY WARRANTY; without even the implied warranty of
25 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
26 * GNU General Public License for more details.
28 * You should have received a copy of the GNU General Public License
29 * along with anytun. If not, see <http://www.gnu.org/licenses/>.
32 #ifndef _CRYPTINIT_HPP
33 #define _CRYPTINIT_HPP
36 #ifndef USE_SSL_CRYPTO
39 // boost thread callbacks for libgcrypt
40 #if defined(BOOST_HAS_PTHREADS)
42 static int boost_mutex_init(void **priv)
44 boost::mutex *lock = new boost::mutex();
51 static int boost_mutex_destroy(void **lock)
53 delete reinterpret_cast<boost::mutex*>(*lock);
57 static int boost_mutex_lock(void **lock)
59 reinterpret_cast<boost::mutex*>(*lock)->lock();
63 static int boost_mutex_unlock(void **lock)
65 reinterpret_cast<boost::mutex*>(*lock)->unlock();
69 static struct gcry_thread_cbs gcry_threads_boost =
70 { GCRY_THREAD_OPTION_USER, NULL,
71 boost_mutex_init, boost_mutex_destroy,
72 boost_mutex_lock, boost_mutex_unlock };
74 #error this libgcrypt thread callbacks only work with pthreads
78 #define MIN_GCRYPT_VERSION "1.2.0"
82 // make libgcrypt thread safe
83 // this must be called before any other libgcrypt call
84 gcry_control( GCRYCTL_SET_THREAD_CBS, &gcry_threads_boost );
86 // this must be called right after the GCRYCTL_SET_THREAD_CBS command
87 // no other function must be called till now
88 if( !gcry_check_version( MIN_GCRYPT_VERSION ) ) {
89 std::cout << "initLibGCrypt: Invalid Version of libgcrypt, should be >= " << MIN_GCRYPT_VERSION << std::endl;
93 gcry_error_t err = gcry_control (GCRYCTL_DISABLE_SECMEM, 0);
95 std::cout << "initLibGCrypt: Failed to disable secure memory: " << AnytunGpgError(err) << std::endl;
99 // Tell Libgcrypt that initialization has completed.
100 err = gcry_control(GCRYCTL_INITIALIZATION_FINISHED);
102 std::cout << "initLibGCrypt: Failed to finish initialization: " << AnytunGpgError(err) << std::endl;
106 cLog.msg(Log::PRIO_NOTICE) << "initLibGCrypt: libgcrypt init finished";