| | | 1 | | // Licensed to the .NET Foundation under one or more agreements. |
| | | 2 | | // The .NET Foundation licenses this file to you under the MIT license. |
| | | 3 | | |
| | | 4 | | using System.Runtime.Versioning; |
| | | 5 | | using System.Collections.Generic; |
| | | 6 | | using System.Runtime.InteropServices; |
| | | 7 | | using System.Security.Authentication; |
| | | 8 | | using System.Security.Cryptography.X509Certificates; |
| | | 9 | | |
| | | 10 | | namespace System.Net.Security |
| | | 11 | | { |
| | | 12 | | public class SslClientAuthenticationOptions |
| | | 13 | | { |
| | 0 | 14 | | private EncryptionPolicy _encryptionPolicy = EncryptionPolicy.RequireEncryption; |
| | 0 | 15 | | private X509RevocationMode _checkCertificateRevocation = SslAuthenticationOptions.DefaultRevocationMode; |
| | 0 | 16 | | private SslProtocols _enabledSslProtocols = SslProtocols.None; |
| | 0 | 17 | | private bool _allowRenegotiation = true; |
| | 0 | 18 | | private bool _allowTlsResume = true; |
| | | 19 | | |
| | | 20 | | public bool AllowRenegotiation |
| | | 21 | | { |
| | 0 | 22 | | get => _allowRenegotiation; |
| | 0 | 23 | | set => _allowRenegotiation = value; |
| | | 24 | | } |
| | | 25 | | |
| | | 26 | | /// <summary> |
| | | 27 | | /// Gets or sets a value that indicates whether the SslStream should allow TLS resumption. |
| | | 28 | | /// </summary> |
| | | 29 | | public bool AllowTlsResume |
| | | 30 | | { |
| | 0 | 31 | | get => _allowTlsResume; |
| | 0 | 32 | | set => _allowTlsResume = value; |
| | | 33 | | } |
| | | 34 | | |
| | 0 | 35 | | public LocalCertificateSelectionCallback? LocalCertificateSelectionCallback { get; set; } |
| | | 36 | | |
| | 0 | 37 | | public RemoteCertificateValidationCallback? RemoteCertificateValidationCallback { get; set; } |
| | | 38 | | |
| | 0 | 39 | | public List<SslApplicationProtocol>? ApplicationProtocols { get; set; } |
| | | 40 | | |
| | 0 | 41 | | public string? TargetHost { get; set; } |
| | | 42 | | |
| | 0 | 43 | | public X509CertificateCollection? ClientCertificates { get; set; } |
| | | 44 | | |
| | | 45 | | /// <summary> |
| | | 46 | | /// Gets or sets the client certificate context. |
| | | 47 | | /// </summary> |
| | 0 | 48 | | public SslStreamCertificateContext? ClientCertificateContext { get; set; } |
| | | 49 | | |
| | | 50 | | public X509RevocationMode CertificateRevocationCheckMode |
| | | 51 | | { |
| | 0 | 52 | | get => _checkCertificateRevocation; |
| | | 53 | | set |
| | 0 | 54 | | { |
| | 0 | 55 | | if (value != X509RevocationMode.NoCheck && value != X509RevocationMode.Offline && value != X509Revocatio |
| | 0 | 56 | | { |
| | 0 | 57 | | throw new ArgumentException(SR.Format(SR.net_invalid_enum, nameof(X509RevocationMode)), nameof(value |
| | | 58 | | } |
| | | 59 | | |
| | 0 | 60 | | _checkCertificateRevocation = value; |
| | 0 | 61 | | } |
| | | 62 | | } |
| | | 63 | | |
| | | 64 | | public EncryptionPolicy EncryptionPolicy |
| | | 65 | | { |
| | 0 | 66 | | get => _encryptionPolicy; |
| | | 67 | | set |
| | 0 | 68 | | { |
| | | 69 | | #pragma warning disable SYSLIB0040 // NoEncryption and AllowNoEncryption are obsolete |
| | 0 | 70 | | if (value != EncryptionPolicy.RequireEncryption && value != EncryptionPolicy.AllowNoEncryption && value |
| | 0 | 71 | | { |
| | 0 | 72 | | throw new ArgumentException(SR.Format(SR.net_invalid_enum, nameof(EncryptionPolicy)), nameof(value)) |
| | | 73 | | } |
| | | 74 | | #pragma warning restore SYSLIB0040 |
| | | 75 | | |
| | 0 | 76 | | _encryptionPolicy = value; |
| | 0 | 77 | | } |
| | | 78 | | } |
| | | 79 | | |
| | | 80 | | public SslProtocols EnabledSslProtocols |
| | | 81 | | { |
| | 0 | 82 | | get => _enabledSslProtocols; |
| | 0 | 83 | | set => _enabledSslProtocols = value; |
| | | 84 | | } |
| | | 85 | | |
| | | 86 | | /// <summary> |
| | | 87 | | /// Specifies cipher suites allowed to be used for TLS. |
| | | 88 | | /// When set to null operating system default will be used. |
| | | 89 | | /// Use extreme caution when changing this setting. |
| | | 90 | | /// </summary> |
| | 0 | 91 | | public CipherSuitesPolicy? CipherSuitesPolicy { get; set; } |
| | | 92 | | |
| | | 93 | | /// <summary> |
| | | 94 | | /// Gets or sets an optional customized policy for remote certificate |
| | | 95 | | /// validation. If not <see langword="null"/>, |
| | | 96 | | /// <see cref="CertificateRevocationCheckMode"/> and <see cref="SslCertificateTrust"/> |
| | | 97 | | /// are ignored. |
| | | 98 | | /// </summary> |
| | 0 | 99 | | public X509ChainPolicy? CertificateChainPolicy { get; set; } |
| | | 100 | | |
| | 0 | 101 | | private bool _allowRsaPssPadding = true; |
| | | 102 | | /// <summary> |
| | | 103 | | /// Gets or sets a value that indicates whether the the rsa_pss_* family of TLS signature algorithms is enabled |
| | | 104 | | /// </summary> |
| | | 105 | | public bool AllowRsaPssPadding |
| | | 106 | | { |
| | 0 | 107 | | get => _allowRsaPssPadding; |
| | | 108 | | |
| | | 109 | | [SupportedOSPlatform("windows")] |
| | | 110 | | [SupportedOSPlatform("linux")] |
| | 0 | 111 | | set { _allowRsaPssPadding = value; } |
| | | 112 | | } |
| | | 113 | | |
| | 0 | 114 | | private bool _allowRsaPkcs1Padding = true; |
| | | 115 | | /// <summary> |
| | | 116 | | /// Gets or sets a value that indicates whether the the rsa_pkcs1_* family of TLS signature algorithms is enable |
| | | 117 | | /// </summary> |
| | | 118 | | public bool AllowRsaPkcs1Padding |
| | | 119 | | { |
| | 0 | 120 | | get => _allowRsaPkcs1Padding; |
| | | 121 | | |
| | | 122 | | [SupportedOSPlatform("windows")] |
| | | 123 | | [SupportedOSPlatform("linux")] |
| | 0 | 124 | | set { _allowRsaPkcs1Padding = value; } |
| | | 125 | | } |
| | | 126 | | } |
| | | 127 | | } |
| | | 128 | | |