4 * The secure anycast tunneling protocol (satp) defines a protocol used
5 * for communication between any combination of unicast and anycast
6 * tunnel endpoints. It has less protocol overhead than IPSec in Tunnel
7 * mode and allows tunneling of every ETHER TYPE protocol (e.g.
8 * ethernet, ip, arp ...). satp directly includes cryptography and
9 * message authentication based on the methodes used by SRTP. It is
10 * intended to deliver a generic, scaleable and secure solution for
11 * tunneling and relaying of packets of any protocol.
14 * Copyright (C) 2007-2009 Othmar Gsenger, Erwin Nindl,
15 * Christian Pointner <satp@wirdorange.org>
17 * This file is part of Anytun.
19 * Anytun is free software: you can redistribute it and/or modify
20 * it under the terms of the GNU General Public License as published by
21 * the Free Software Foundation, either version 3 of the License, or
24 * Anytun is distributed in the hope that it will be useful,
25 * but WITHOUT ANY WARRANTY; without even the implied warranty of
26 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
27 * GNU General Public License for more details.
29 * You should have received a copy of the GNU General Public License
30 * along with anytun. If not, see <http://www.gnu.org/licenses/>.
33 #ifndef ANYTUN_cryptinit_hpp_INCLUDED
34 #define ANYTUN_cryptinit_hpp_INCLUDED
37 #ifndef USE_SSL_CRYPTO
40 // boost thread callbacks for libgcrypt
41 static int boost_mutex_init(void** priv)
43 boost::mutex* lock = new boost::mutex();
51 static int boost_mutex_destroy(void** lock)
53 delete reinterpret_cast<boost::mutex*>(*lock);
57 static int boost_mutex_lock(void** lock)
59 reinterpret_cast<boost::mutex*>(*lock)->lock();
63 static int boost_mutex_unlock(void** lock)
65 reinterpret_cast<boost::mutex*>(*lock)->unlock();
69 static struct gcry_thread_cbs gcry_threads_boost = {
70 GCRY_THREAD_OPTION_USER, NULL,
71 boost_mutex_init, boost_mutex_destroy,
72 boost_mutex_lock, boost_mutex_unlock
75 #define MIN_GCRYPT_VERSION "1.2.0"
79 // make libgcrypt thread safe
80 // this must be called before any other libgcrypt call
81 gcry_control(GCRYCTL_SET_THREAD_CBS, &gcry_threads_boost);
83 // this must be called right after the GCRYCTL_SET_THREAD_CBS command
84 // no other function must be called till now
85 if(!gcry_check_version(MIN_GCRYPT_VERSION)) {
86 std::cout << "initLibGCrypt: Invalid Version of libgcrypt, should be >= " << MIN_GCRYPT_VERSION << std::endl;
90 gcry_error_t err = gcry_control(GCRYCTL_DISABLE_SECMEM, 0);
92 std::cout << "initLibGCrypt: Failed to disable secure memory: " << AnytunGpgError(err) << std::endl;
96 // Tell Libgcrypt that initialization has completed.
97 err = gcry_control(GCRYCTL_INITIALIZATION_FINISHED);
99 std::cout << "initLibGCrypt: Failed to finish initialization: " << AnytunGpgError(err) << std::endl;
103 cLog.msg(Log::PRIO_NOTICE) << "initLibGCrypt: libgcrypt init finished";
112 #ifndef USE_SSL_CRYPTO
113 return initLibGCrypt();