From: "Marshall T. Vandegrift" Date: 2006-06-15T00:36:12+09:00 Subject: [PATCH] SSL client certificate support for OpenURI --=-=-= Hello: The attached patch modifies 'open-uri.rb' to allow users to specify SSL client certificates and keys for HTTPS sessions. -- Marshall T. Vandegrift ISS.Researcher | 404.236.3986w 518.859.4559m --=-=-= Content-Type: text/x-patch Content-Disposition: attachment; filename=open-uri-ssl_cert-patch.diff Content-Description: Patch to add SSL client certificate and key support to OpenURI --- ruby-trunk/lib/open-uri.rb 2006-06-13 13:46:48.000000000 -0400 +++ ruby-modified/lib/open-uri.rb 2006-06-13 13:51:09.000000000 -0400 @@ -101,6 +101,8 @@ :read_timeout => true, :ssl_ca_cert => nil, :ssl_verify_mode => nil, + :ssl_cert => nil, + :ssl_key => nil } def OpenURI.check_options(options) # :nodoc: @@ -282,6 +284,24 @@ else store.set_default_paths end + if options[:ssl_cert] + if options[:ssl_cert].is_a? OpenSSL::X509::Certificate + http.cert = options[:ssl_cert] + else + http.cert = OpenSSL::X509::Certificate.new(File.read(options[:ssl_cert])) + end + end + if options[:ssl_key] + if options[:ssl_key].is_a? OpenSSL::PKey::PKey + http.key = options[:ssl_key] + else + begin + http.key = OpenSSL::PKey::DSA.new(File.read(options[:ssl_key])) + rescue OpenSSL::PKey::DSAError + http.key = OpenSSL::PKey::RSA.new(File.read(options[:ssl_key])) + end + end + end store.set_default_paths http.cert_store = store end @@ -607,6 +627,23 @@ # # :ssl_verify_mode is used to specify openssl verify mode. # + # [:ssl_cert] + # Synopsis: + # :ssl_cert=>filename + # :ssl_cert=>x509cert + # + # :ssl_cert is used to specify a client certificate for SSL. It + # may be either a filename or an OpenSSL::X509::Certificate + # object. + # + # [:ssl_key] + # Synopsis: + # :ssl_key=>filename + # :ssl_key=>pkey + # + # :ssl_cert is used to specify a detached private key for SSL. + # It may be either a filename or an OpenSSL::PKey::PKey object. + # # OpenURI::OpenRead#open returns an IO like object if block is not given. # Otherwise it yields the IO object and return the value of the block. # The IO object is extended with OpenURI::Meta. --=-=-=--