crypery
Description
crypery is a pure C/CPP network stack of four modules: a TLS 1.2/1.3 cryptography library, an OpenSSL-compatible SSL wrapper layer, an HTTPS server and an HTTPS client.
- All crypto algorithms implemented from scratch - no external crypto libraries. The only optional dependency is zlib for gzip compression (disabled with the HTTP_NO_GZIP flag).
- Portability - runs on Windows (MinGW, Winsock) and Unix-like systems (BSD sockets, pthreads).
- Full cycle: from low-level cryptography (AES-GCM, RSA, ECDH) to ready HTTP server and HTTP client.
Modules used
tls
Base cryptography layer. Pure C/CPP implementation of TLS 1.2 and TLS 1.3 with a built-in primitive set:
- AES-128-GCM symmetric encryption;
- SHA-256 hashing, HMAC-SHA256 MAC, HKDF-SHA256 key derivation;
- asymmetric cryptography: RSA-2048 (PKCS#1 v1.5 and RSASSA-PSS signatures), ECDH on P-256 (secp256r1) and X25519 curves;
- generating and parsing self-signed X.509 certificates (DER/PEM), including PEM file loading;
- TLS connection context: handshake (client/server, version auto-select), application data encryption and decryption, SNI, peer certificate verification, close_notify;
- thread safety: random number generation (xorshift128) is lock-protected, allowing parallel handshakes in a thread pool.
ssl
An OpenSSL-compatible API layer over the built-in TLS implementation, so code written for OpenSSL works unchanged:
- OpenSSL-compatible context and connection types;
- loading certificates and private keys from PEM files, checking key-certificate match;
- server and client handshakes (TLS 1.2/1.3);
- encrypted I/O over sockets;
- tunable timeouts: I/O operation, full handshake, TLS record write wait, fragmented packet assembly;
- peer certificate verification modes;
- platform shim: Winsock on Windows, BSD sockets on POSIX.
http
A self-contained HTTP/1.1 server library built on the built-in TLS stack:
- request routing by method and path with custom handlers;
- serving static files from the root directory with MIME type detection;
- gzip compression: serving precompressed .gz files and on-the-fly compression via zlib (disabled with HTTP_NO_GZIP);
- WebSocket (RFC 6455): connection upgrade, frame reading and sending (text, binary, close, ping/pong);
- Server-Sent Events (SSE);
- query string parsing (URL decoding) and multipart/form-data (including file uploads);
- security: path traversal protection, blocking sensitive paths (.git, .env, config* and others), Host header validation against a domain list, body and header size limits;
- worker thread pool with a ring connection queue, blocking accept loop;
- automatic TLS/HTTP detection by first byte (0x16 → TLS, otherwise HTTP with a 426 response);
- statistics: request counters by status-code category, uptime, req/s;
- own platform shim (sockets, strings, threads, mutexes, events) - the module does not depend on external compat headers.
url
A self-contained HTTP/HTTPS client library built on the built-in TLS stack:
- absolute URL parsing: http/https, explicit port, userinfo, fragments, IPv6 literals;
- HTTP/1.1 requests (GET, POST, HEAD and others) with custom headers, body, Content-Type, Range;
- response reading: status line, headers, body by Content-Length, chunked transfer encoding or until EOF;
- redirect handling (301/302/303/307/308) with RFC 7231 method semantics and a hop limit;
- building multipart/form-data bodies (fields and files, boundary generation, MIME detection by extension);
- transport layer: DNS resolving, connect with timeout, TLS handshake (SNI, option to skip certificate verification), buffered I/O;
- error codes following curl conventions;
- optional verbose logging via callback (disabled with URL_NO_LOG).
Technologies
- Language: pure C/CPP, no external dependencies (zlib - optional)
- Protocols: TLS 1.2, TLS 1.3, HTTP/1.1, HTTPS, WebSocket (RFC 6455), SSE, chunked transfer encoding
- Cryptography: AES-128-GCM, SHA-256, HMAC-SHA256, HKDF-SHA256, RSA-2048 (PKCS#1 v1.5, RSASSA-PSS), ECDH P-256 (secp256r1), X25519, X.509 (DER/PEM), SHA-1 (only for the WebSocket handshake)
- Network layer: Winsock2 (Windows) / BSD sockets (POSIX), select() for timeouts, SO_RCVTIMEO, getaddrinfo for DNS
- Threads: WinAPI threads (Windows) / pthreads (POSIX), worker thread pool, critical sections / mutexes, auto-reset events
- Compression: gzip via zlib (optional)
- API compatibility: OpenSSL (SSL_CTX/SSL) and curl (url_*)
- License: GNU AGPL v3 (Affero GPL)