mirror of
https://github.com/mollyim/webrtc.git
synced 2025-05-18 08:07:56 +01:00

Promotes rtc::CryptoOptions to webrtc::CryptoOptions converting it from class that only handles SRTP configuration to a more generic structure that can be used and extended for all per peer connection CryptoOptions that can be on a given PeerConnection. Now all SRTP related options are under webrtc::CryptoOptions::Srtp and can be accessed as crypto_options.srtp.whatever_option_name. This is more inline with other structures we have in WebRTC such as VideoConfig. As additional features are added over time this will allow the structure to remain compartmentalized and concerned components can only request a subset of the overall configuration structure e.g: void MySrtpFunction(const webrtc::CryptoOptions::Srtp& srtp_config); In addition to this it made little sense for sslstreamadapter.h to hold all Srtp related configuration options. The header has become loo large and takes on too many responsibilities and spilting this up will lead to more maintainable code going forward. This will be used in a future CL to enable configuration options for the newly supported Frame Crypto. Reland Fix: - cryptooptions.h - now has enable_aes128_sha1_32_crypto_cipher as an optional root level configuration. - peerconnectionfactory - If this optional is set will now overwrite the underyling value. This along with the other field will be deprecated once dependent projects are updated. TBR=sakal@webrtc.org,kthelgason@webrtc.org,emadomara@webrtc.org,qingsi@webrtc.org Bug: webrtc:9681 Change-Id: Iaa6b741baafb85d352e42f54226119f19d97151d Reviewed-on: https://webrtc-review.googlesource.com/c/105560 Reviewed-by: Benjamin Wright <benwright@webrtc.org> Reviewed-by: Steve Anton <steveanton@webrtc.org> Reviewed-by: Emad Omara <emadomara@webrtc.org> Commit-Queue: Benjamin Wright <benwright@webrtc.org> Cr-Commit-Position: refs/heads/master@{#25135}
67 lines
2.6 KiB
C++
67 lines
2.6 KiB
C++
/*
|
|
* Copyright 2018 The WebRTC Project Authors. All rights reserved.
|
|
*
|
|
* Use of this source code is governed by a BSD-style license
|
|
* that can be found in the LICENSE file in the root of the source
|
|
* tree. An additional intellectual property rights grant can be found
|
|
* in the file PATENTS. All contributing project authors may
|
|
* be found in the AUTHORS file in the root of the source tree.
|
|
*/
|
|
|
|
#ifndef API_CRYPTO_CRYPTOOPTIONS_H_
|
|
#define API_CRYPTO_CRYPTOOPTIONS_H_
|
|
|
|
#include <vector>
|
|
#include "absl/types/optional.h"
|
|
|
|
namespace webrtc {
|
|
|
|
// CryptoOptions defines advanced cryptographic settings for native WebRTC.
|
|
// These settings must be passed into PeerConnectionFactoryInterface::Options
|
|
// and are only applicable to native use cases of WebRTC.
|
|
struct CryptoOptions {
|
|
CryptoOptions();
|
|
CryptoOptions(const CryptoOptions& other);
|
|
~CryptoOptions();
|
|
|
|
// Helper method to return an instance of the CryptoOptions with GCM crypto
|
|
// suites disabled. This method should be used instead of depending on current
|
|
// default values set by the constructor.
|
|
static CryptoOptions NoGcm();
|
|
|
|
// Returns a list of the supported DTLS-SRTP Crypto suites based on this set
|
|
// of crypto options.
|
|
std::vector<int> GetSupportedDtlsSrtpCryptoSuites() const;
|
|
|
|
// TODO(webrtc:9859) - Remove duplicates once chromium is fixed.
|
|
// Will be removed once srtp.enable_gcm_crypto_suites is updated in Chrome.
|
|
absl::optional<bool> enable_gcm_crypto_suites;
|
|
// TODO(webrtc:9859) - Remove duplicates once chromium is fixed.
|
|
// Will be removed once srtp.enable_encrypted_rtp_header_extensions is
|
|
// updated in Chrome.
|
|
absl::optional<bool> enable_encrypted_rtp_header_extensions;
|
|
// Will be removed once srtp.enable_encrypted_rtp_header_extensions is
|
|
// updated in Tacl.
|
|
absl::optional<bool> enable_aes128_sha1_32_crypto_cipher;
|
|
|
|
// SRTP Related Peer Connection options.
|
|
struct Srtp {
|
|
// Enable GCM crypto suites from RFC 7714 for SRTP. GCM will only be used
|
|
// if both sides enable it.
|
|
bool enable_gcm_crypto_suites = false;
|
|
|
|
// If set to true, the (potentially insecure) crypto cipher
|
|
// SRTP_AES128_CM_SHA1_32 will be included in the list of supported ciphers
|
|
// during negotiation. It will only be used if both peers support it and no
|
|
// other ciphers get preferred.
|
|
bool enable_aes128_sha1_32_crypto_cipher = false;
|
|
|
|
// If set to true, encrypted RTP header extensions as defined in RFC 6904
|
|
// will be negotiated. They will only be used if both peers support them.
|
|
bool enable_encrypted_rtp_header_extensions = false;
|
|
} srtp;
|
|
};
|
|
|
|
} // namespace webrtc
|
|
|
|
#endif // API_CRYPTO_CRYPTOOPTIONS_H_
|