|
iPXE
|
Transport Layer Security Protocol. More...
#include <stdint.h>#include <stdlib.h>#include <stdarg.h>#include <stdio.h>#include <string.h>#include <errno.h>#include <byteswap.h>#include <ipxe/pending.h>#include <ipxe/hmac.h>#include <ipxe/md5_sha1.h>#include <ipxe/iobuf.h>#include <ipxe/xfer.h>#include <ipxe/open.h>#include <ipxe/x509.h>#include <ipxe/privkey.h>#include <ipxe/certstore.h>#include <ipxe/rootcert.h>#include <ipxe/validator.h>#include <ipxe/job.h>#include <ipxe/ffdhe.h>#include <ipxe/tls.h>#include <config/crypto.h>Go to the source code of this file.
Functions | |
| FILE_LICENCE (GPL2_OR_LATER) | |
| FILE_SECBOOT (PERMITTED) | |
| static | LIST_HEAD (tls_sessions) |
| List of TLS session. | |
| static void | tls_tx_resume_all (struct tls_session *session) |
| Resume TX state machine for all connections within a session. | |
| static struct io_buffer * | tls_alloc_iob (struct tls_connection *tls, size_t len) |
| Allocate I/O buffer for transmitted record(s). | |
| static int | tls_send_alert (struct tls_connection *tls, unsigned int level, unsigned int description) |
| Transmit Alert record. | |
| static int | tls_send_record (struct tls_connection *tls, unsigned int type, struct io_buffer *iobuf) |
| Send plaintext record(s). | |
| static int | tls_send_plaintext (struct tls_connection *tls, unsigned int type, const void *data, size_t len) |
| Send plaintext record. | |
| static void | tls_clear_digest (struct tls_connection *tls) |
| Clear key schedule digest algorithm. | |
| static void | tls_clear_cipher (struct tls_connection *tls, struct tls_cipherspec *cipherspec) |
| static int | tls_replay_handshake (struct tls_connection *tls, struct io_buffer *iobuf) |
| Add Handshake record to transcript digest (without transmitting). | |
| static int | tls_client_hello (struct tls_connection *tls, int(*action)(struct tls_connection *tls, struct io_buffer *iobuf)) |
| Digest or transmit Client Hello record. | |
| static int | tls_validator_start (struct tls_connection *tls) |
| Start certificate validation. | |
| static void | tls_xor (void *dst, const void *src, size_t len) |
| XOR data block. | |
| static int | tls_ready (struct tls_connection *tls) |
| Determine if TLS connection is ready for application data. | |
| static int | tls_version (struct tls_connection *tls, unsigned int version) |
| Check for TLS version. | |
| static int | tls_has_inner (struct tls_connection *tls, struct cipher_algorithm *cipher) |
| Check if TLS inner plaintext is in use. | |
| static int | tls_copy (const struct tls_cursor *src, struct tls_cursor *dst) |
| Duplicate content of a TLS cursor. | |
| static const char * | tls_pipe_name (struct tls_connection *tls, struct secure_pipe *pipe) |
| Get pipe name (for debugging). | |
| static void | free_tls_session (struct refcnt *refcnt) |
| Free TLS session. | |
| static void | free_tls (struct refcnt *refcnt) |
| Free TLS connection. | |
| static void | tls_close (struct tls_connection *tls, int rc) |
| Finish with TLS connection. | |
| static void | tls_close_alert (struct tls_connection *tls, int rc) |
| Send closure alert and finish with TLS connection. | |
| static void | tls_nonce (struct tls_connection *tls, struct tls_random *nonce) |
| Generate deterministic connection nonce. | |
| static void | tls_random (struct tls_connection *tls, void *nonce, size_t len) |
| Generate random nonce. | |
| static int | tls_set_digest (struct tls_connection *tls, struct digest_algorithm *digest) |
| Set key schedule digest algorithm. | |
| static void | tls_add_handshake (struct tls_connection *tls, const void *data, size_t len) |
| Add handshake record to transcript digest. | |
| static const char * | tls_version_name (unsigned int version) |
| Get protocol version name (for debugging). | |
| static const char * | tls_cipher_name (struct tls_cipher_suite *suite) |
| Get cipher suite name (for debugging). | |
| static struct tls_cipher_suite * | tls_find_cipher_suite (unsigned int cipher_suite) |
| Identify cipher suite. | |
| static int | tls_set_verify_len (struct tls_connection *tls, size_t verify_len) |
| Set verification data length. | |
| static int | tls_select_cipher (struct tls_connection *tls, unsigned int version, unsigned int cipher_suite) |
| Select protocol version and cipher suite. | |
| static void | tls_clear_cipher (struct tls_connection *tls __unused, struct tls_cipherspec *cipherspec) |
| Clear cipher specification. | |
| static int | tls_prep_cipher (struct tls_connection *tls, struct tls_cipherspec *cipherspec, const struct tls_phase *phase) |
| Prepare cipher specification for a new traffic phase. | |
| static int | tls_change_cipher (struct tls_connection *tls, struct tls_cipherspec *cipherspec, const struct tls_phase *phase) |
| Change cipher specification. | |
| static int | tls_pending_cipher (struct tls_connection *tls, struct tls_cipherspec *cipherspec) |
| Apply pending traffic phase change (if any). | |
| static struct tls_signature_hash_algorithm * | tls_signature_hash_algorithm (struct pubkey_algorithm *pubkey, struct digest_algorithm *digest) |
| Find TLS signature and hash algorithm. | |
| static struct tls_signature_hash_algorithm * | tls_find_signature_hash (unsigned int code) |
| Find TLS signature and hash algorithm. | |
| static struct tls_named_group * | tls_find_named_group (unsigned int named_group) |
| Identify named key exchange group. | |
| static struct tls_named_group * | tls_find_param_group (const struct tls_cursor *dh_p, const struct tls_cursor *dh_g) |
| Identify named key exchange group by Diffie-Hellman parameters. | |
| static int | tls_parse_null (struct tls_connection *tls, const struct tls_cursor *cursor, struct tls_key_exchange_parameters *kex __unused) |
| Parse key exchange parameters from unexpected Server Key Exchange record. | |
| static int | tls_parse_dhe (struct tls_connection *tls, const struct tls_cursor *cursor, struct tls_key_exchange_parameters *kex) |
| Parse key exchange parameters from DHE Server Key Exchange record. | |
| static int | tls_parse_ecdhe (struct tls_connection *tls, const struct tls_cursor *cursor, struct tls_key_exchange_parameters *kex) |
| Parse key exchange parameters from ECDHE Server Key Exchange record. | |
| static int | tls_keysize_is_variable (struct tls_connection *tls, struct exchange_algorithm *exchange) |
| Check if key exchange keys have a variable size. | |
| static int | tls_key_share (struct tls_connection *tls, struct tls_named_group *group, struct tls_cursor *public) |
| Share public key. | |
| static int | tls_key_agree (struct tls_connection *tls, struct tls_named_group *group, const struct tls_cursor *partner) |
| Agree shared secret. | |
| static int | tls_key_encrypt (struct tls_connection *tls, struct tls_named_group *group, struct asn1_builder *builder) |
| Encrypt (and implicitly bind) shared secret. | |
| static int | tls_hash_sign (struct tls_connection *tls, struct tls_signature_hash_algorithm *sig_hash, struct x509_certificate *cert, struct asn1_builder *sig) |
| Create signature over parameters used to construct shared secret. | |
| static int | tls_hash_verify (struct tls_connection *tls, struct tls_signature_hash_algorithm *sig_hash, struct x509_certificate *cert, const struct tls_cursor *params, const struct asn1_cursor *sig) |
| Verify signature over parameters used to construct shared secret. | |
| static void | tls_channel_reset (struct secure_channel *channel) |
| Reset the key schedule. | |
| static int | tls_channel_apply (struct secure_channel *channel, struct exchange_algorithm *exchange, const void *shared, int *accumulated) |
| Apply a new shared secret to key schedule. | |
| static int | tls_channel_save (struct secure_channel *channel, struct secure_preshared_identity *psid) |
| Save a pre-shared key for future resumption of the key schedule. | |
| static int | tls_channel_load (struct secure_channel *channel, struct secure_preshared_identity *psid) |
| Load a pre-shared key and resume the key schedule. | |
| static int | tls_channel_verify (struct secure_channel *channel, const void *auth, size_t len) |
| Verify authenticator value. | |
| static void | tls_set_session_id (struct tls_connection *tls) |
| Set a random session ID. | |
| static int | tls_session (struct tls_connection *tls, const char *name) |
| Find or create session for TLS connection. | |
| static int | tls_save (struct tls_connection *tls) |
| Save session for future resumption. | |
| static int | tls_resume (struct tls_connection *tls) |
| Resume session. | |
| static void | tls_tx_resume (struct tls_connection *tls) |
| Resume TX state machine. | |
| static void | tls_restart (struct tls_connection *tls) |
| Restart negotiation. | |
| static int | tls_establish (struct tls_connection *tls) |
| Establish secure channel. | |
| static struct io_buffer * | tls_alloc_handshake (struct tls_connection *tls, struct tls_cursor *cursor, unsigned int type) |
| Allocate Handshake record. | |
| static int | tls_send_handshake (struct tls_connection *tls, struct io_buffer *iobuf) |
| Transmit Handshake record. | |
| static int | tls_send_client_hello (struct tls_connection *tls) |
| Transmit Client Hello record. | |
| static int | tls_send_certificate (struct tls_connection *tls) |
| Transmit Certificate record. | |
| static int | tls_send_client_key_exchange (struct tls_connection *tls) |
| Transmit Client Key Exchange record. | |
| static int | tls_send_certificate_verify (struct tls_connection *tls) |
| Transmit Certificate Verify record. | |
| static int | tls_send_change_cipher (struct tls_connection *tls) |
| Transmit Change Cipher record. | |
| static int | tls_send_finished (struct tls_connection *tls) |
| Transmit Finished record. | |
| static int | tls_new_change_cipher (struct tls_connection *tls, struct io_buffer *iobuf) |
| Receive new Change Cipher record. | |
| static int | tls_new_alert (struct tls_connection *tls, struct io_buffer *iobuf) |
| Receive new Alert record. | |
| static int | tls_new_hello_request (struct tls_connection *tls, const struct tls_cursor *cursor) |
| Receive new Hello Request handshake record. | |
| static int | tls_new_server_hello (struct tls_connection *tls, const struct tls_cursor *cursor) |
| Receive new Server Hello handshake record. | |
| static int | tls_new_session_ticket (struct tls_connection *tls, const struct tls_cursor *cursor) |
| Receive New Session Ticket handshake record. | |
| static int | tls_new_certificate (struct tls_connection *tls, const struct tls_cursor *cursor) |
| Receive new Certificate handshake record. | |
| static int | tls_verify_signature (struct tls_connection *tls, const struct tls_cursor *cursor, const struct tls_cursor *params) |
| Verify a signature record. | |
| static int | tls_new_certificate_verify (struct tls_connection *tls, const struct tls_cursor *cursor) |
| Receive new Certificate Verify handshake record. | |
| static int | tls_new_server_key_exchange (struct tls_connection *tls, const struct tls_cursor *cursor) |
| Receive new Server Key Exchange handshake record. | |
| static int | tls_new_certificate_request (struct tls_connection *tls, const struct tls_cursor *cursor __unused) |
| Receive new Certificate Request handshake record. | |
| static int | tls_new_server_hello_done (struct tls_connection *tls, const struct tls_cursor *cursor) |
| Receive new Server Hello Done handshake record. | |
| static int | tls_new_finished (struct tls_connection *tls, const struct tls_cursor *cursor) |
| Receive new Finished handshake record. | |
| static int | tls_new_handshake (struct tls_connection *tls, struct io_buffer *iobuf) |
| Receive new Handshake record. | |
| static int | tls_new_unknown (struct tls_connection *tls __unused, struct io_buffer *iobuf) |
| Receive new unknown record. | |
| static int | tls_new_data (struct tls_connection *tls, struct list_head *rx_data) |
| Receive new data record. | |
| static int | tls_new_record (struct tls_connection *tls, unsigned int type, struct list_head *rx_data) |
| Receive new record. | |
| static void | tls_hmac_init (struct tls_cipherspec *cipherspec, void *ctx, struct tls_auth_header *authhdr) |
| Initialise HMAC. | |
| static void | tls_hmac_update (struct tls_cipherspec *cipherspec, void *ctx, const void *data, size_t len) |
| Update HMAC. | |
| static void | tls_hmac_final (struct tls_cipherspec *cipherspec, void *ctx, void *hmac) |
| Finalise HMAC. | |
| static void | tls_hmac (struct tls_cipherspec *cipherspec, struct tls_auth_header *authhdr, const void *data, size_t len, void *hmac) |
| Calculate HMAC. | |
| static void | tls_hmac_list (struct tls_cipherspec *cipherspec, struct tls_auth_header *authhdr, struct list_head *list, void *hmac) |
| Calculate HMAC over list of I/O buffers. | |
| static size_t | tls_iob_reserved (struct tls_connection *tls, size_t len) |
| Calculate maximum additional length required for transmitted record(s). | |
| static int | tls_verify_padding (struct tls_connection *tls, struct io_buffer *iobuf) |
| Verify block padding. | |
| static int | tls_extract_inner (struct tls_connection *tls, int type, struct list_head *rx_data) |
| Extract inner plaintext. | |
| static int | tls_new_ciphertext (struct tls_connection *tls, struct tls_header *tlshdr, struct list_head *rx_data) |
| Receive new ciphertext record. | |
| static size_t | tls_plainstream_window (struct tls_connection *tls) |
| Check flow control window. | |
| static int | tls_plainstream_deliver (struct tls_connection *tls, struct io_buffer *iobuf, struct xfer_metadata *meta __unused) |
| Deliver datagram as raw data. | |
| static int | tls_progress (struct tls_connection *tls, struct job_progress *progress) |
| Report job progress. | |
| static int | tls_newdata_process_header (struct tls_connection *tls) |
| Handle received TLS header. | |
| static int | tls_newdata_process_data (struct tls_connection *tls) |
| Handle received TLS data payload. | |
| static size_t | tls_cipherstream_window (struct tls_connection *tls) |
| Check flow control window. | |
| static int | tls_cipherstream_deliver (struct tls_connection *tls, struct io_buffer *iobuf, struct xfer_metadata *xfer __unused) |
| Receive new ciphertext. | |
| static void | tls_validator_done (struct tls_connection *tls, int rc) |
| Handle certificate validation completion. | |
| static void | tls_tx_step (struct tls_connection *tls) |
| TLS TX state machine. | |
| int | add_tls (struct interface *xfer, const char *name, struct x509_root *root, struct private_key *key) |
| Add TLS on an interface. | |
| REQUIRING_SYMBOL (add_tls) | |
| REQUIRE_OBJECT (config_crypto) | |
Variables | |
| struct pubkey_algorithm | rsa_algorithm |
| static const uint8_t | tls_downgrade_magic [7] = TLS_SERVER_DOWNGRADE_MAGIC |
| ServerHello downgrade magic value. | |
| static const struct tls_random | tls_hrr_magic |
| HelloRetryRequest magic value. | |
| struct tls_cipher_suite | tls_cipher_suite_null |
| Null cipher suite. | |
| struct tls_named_group tls_null_named_group | __tls_anon_named_group |
| Null named group. | |
| struct tls_key_exchange_algorithm | tls_null_exchange_algorithm |
| Null key exchange algorithm. | |
| struct tls_key_exchange_algorithm | tls_pubkey_exchange_algorithm |
| Public key exchange algorithm. | |
| struct tls_key_exchange_algorithm | tls_dhe_exchange_algorithm |
| Ephemeral Diffie-Hellman key exchange algorithm. | |
| struct tls_key_exchange_algorithm | tls_ecdhe_exchange_algorithm |
| Ephemeral Elliptic Curve Diffie-Hellman key exchange algorithm. | |
| static struct secure_channel_operations | tls_channel_ops |
| Secure channel operations. | |
| static struct interface_operation | tls_plainstream_ops [] |
| TLS plaintext stream interface operations. | |
| static struct interface_descriptor | tls_plainstream_desc |
| TLS plaintext stream interface descriptor. | |
| static struct interface_operation | tls_cipherstream_ops [] |
| TLS ciphertext stream interface operations. | |
| static struct interface_descriptor | tls_cipherstream_desc |
| TLS ciphertext stream interface descriptor. | |
| static struct interface_operation | tls_validator_ops [] |
| TLS certificate validator interface operations. | |
| static struct interface_descriptor | tls_validator_desc |
| TLS certificate validator interface descriptor. | |
| static struct process_descriptor | tls_process_desc |
| TLS TX process descriptor. | |
Transport Layer Security Protocol.
Definition in file tls.c.
| #define EINVAL_CHANGE_CIPHER __einfo_error ( EINFO_EINVAL_CHANGE_CIPHER ) |
Definition at line 53 of file tls.c.
Referenced by tls_new_change_cipher().
| #define EINFO_EINVAL_CHANGE_CIPHER |
Definition at line 54 of file tls.c.
| #define EINVAL_ALERT __einfo_error ( EINFO_EINVAL_ALERT ) |
Definition at line 57 of file tls.c.
Referenced by tls_new_alert().
| #define EINFO_EINVAL_ALERT |
Definition at line 58 of file tls.c.
| #define EINVAL_IV __einfo_error ( EINFO_EINVAL_IV ) |
Definition at line 61 of file tls.c.
Referenced by tls_new_ciphertext().
| #define EINFO_EINVAL_IV |
Definition at line 62 of file tls.c.
| #define EINVAL_PADDING __einfo_error ( EINFO_EINVAL_PADDING ) |
Definition at line 65 of file tls.c.
Referenced by tls_verify_padding().
| #define EINFO_EINVAL_PADDING |
Definition at line 66 of file tls.c.
| #define EINVAL_RX_STATE __einfo_error ( EINFO_EINVAL_RX_STATE ) |
Definition at line 69 of file tls.c.
Referenced by tls_cipherstream_deliver().
| #define EINFO_EINVAL_RX_STATE |
Definition at line 70 of file tls.c.
| #define EINVAL_MAC __einfo_error ( EINFO_EINVAL_MAC ) |
Definition at line 73 of file tls.c.
Referenced by tls_new_ciphertext().
| #define EINFO_EINVAL_MAC |
Definition at line 74 of file tls.c.
| #define EINVAL_KEY_EXCHANGE __einfo_error ( EINFO_EINVAL_KEY_EXCHANGE ) |
Definition at line 77 of file tls.c.
Referenced by tls_key_agree(), tls_key_share(), and tls_parse_null().
| #define EINFO_EINVAL_KEY_EXCHANGE |
Definition at line 78 of file tls.c.
| #define EINVAL_INNER __einfo_error ( EINFO_EINVAL_INNER ) |
Definition at line 81 of file tls.c.
Referenced by tls_extract_inner().
| #define EINFO_EINVAL_INNER |
Definition at line 82 of file tls.c.
| #define EINVAL_BLOCK __einfo_error ( EINFO_EINVAL_BLOCK ) |
Definition at line 85 of file tls.c.
Referenced by tls_new_ciphertext().
| #define EINFO_EINVAL_BLOCK |
Definition at line 86 of file tls.c.
| #define EIO_ALERT __einfo_error ( EINFO_EIO_ALERT ) |
Definition at line 89 of file tls.c.
Referenced by tls_new_alert().
| #define EINFO_EIO_ALERT |
Definition at line 90 of file tls.c.
| #define ENOENT_CERT __einfo_error ( EINFO_ENOENT_CERT ) |
Definition at line 93 of file tls.c.
Referenced by tls_key_encrypt(), tls_send_certificate(), tls_send_certificate_verify(), and tls_verify_signature().
| #define EINFO_ENOENT_CERT |
Definition at line 94 of file tls.c.
| #define ENOENT_KEY_EXCHANGE __einfo_error ( EINFO_ENOENT_KEY_EXCHANGE ) |
| #define EINFO_ENOENT_KEY_EXCHANGE |
Definition at line 98 of file tls.c.
| #define ENOMEM_CONTEXT __einfo_error ( EINFO_ENOMEM_CONTEXT ) |
Definition at line 101 of file tls.c.
Referenced by tls_change_cipher().
| #define EINFO_ENOMEM_CONTEXT |
Definition at line 102 of file tls.c.
| #define ENOMEM_CERTIFICATE __einfo_error ( EINFO_ENOMEM_CERTIFICATE ) |
| #define EINFO_ENOMEM_CERTIFICATE |
Definition at line 106 of file tls.c.
| #define ENOMEM_CHAIN __einfo_error ( EINFO_ENOMEM_CHAIN ) |
Definition at line 109 of file tls.c.
Referenced by tls_new_certificate().
| #define EINFO_ENOMEM_CHAIN |
Definition at line 110 of file tls.c.
| #define ENOMEM_TX_PLAINTEXT __einfo_error ( EINFO_ENOMEM_TX_PLAINTEXT ) |
Definition at line 113 of file tls.c.
Referenced by tls_send_plaintext().
| #define EINFO_ENOMEM_TX_PLAINTEXT |
Definition at line 114 of file tls.c.
| #define ENOMEM_TX_CIPHERTEXT __einfo_error ( EINFO_ENOMEM_TX_CIPHERTEXT ) |
| #define EINFO_ENOMEM_TX_CIPHERTEXT |
Definition at line 118 of file tls.c.
| #define ENOMEM_RX_DATA __einfo_error ( EINFO_ENOMEM_RX_DATA ) |
Definition at line 121 of file tls.c.
Referenced by tls_newdata_process_header().
| #define EINFO_ENOMEM_RX_DATA |
Definition at line 122 of file tls.c.
| #define ENOMEM_RX_CONCAT __einfo_error ( EINFO_ENOMEM_RX_CONCAT ) |
Definition at line 125 of file tls.c.
Referenced by tls_new_record().
| #define EINFO_ENOMEM_RX_CONCAT |
Definition at line 126 of file tls.c.
| #define ENOTSUP_CIPHER __einfo_error ( EINFO_ENOTSUP_CIPHER ) |
Definition at line 129 of file tls.c.
Referenced by tls_select_cipher().
| #define EINFO_ENOTSUP_CIPHER |
Definition at line 130 of file tls.c.
| #define ENOTSUP_NULL __einfo_error ( EINFO_ENOTSUP_NULL ) |
Definition at line 133 of file tls.c.
Referenced by tls_change_cipher().
| #define EINFO_ENOTSUP_NULL |
Definition at line 134 of file tls.c.
| #define ENOTSUP_SIG_HASH __einfo_error ( EINFO_ENOTSUP_SIG_HASH ) |
Definition at line 137 of file tls.c.
Referenced by tls_send_certificate_verify(), and tls_verify_signature().
| #define EINFO_ENOTSUP_SIG_HASH |
Definition at line 138 of file tls.c.
| #define ENOTSUP_VERSION __einfo_error ( EINFO_ENOTSUP_VERSION ) |
| #define EINFO_ENOTSUP_VERSION |
Definition at line 142 of file tls.c.
| #define ENOTSUP_GROUP __einfo_error ( EINFO_ENOTSUP_GROUP ) |
Definition at line 145 of file tls.c.
Referenced by tls_new_server_hello(), tls_parse_dhe(), and tls_parse_ecdhe().
| #define EINFO_ENOTSUP_GROUP |
Definition at line 146 of file tls.c.
| #define EPERM_ALERT __einfo_error ( EINFO_EPERM_ALERT ) |
Definition at line 149 of file tls.c.
Referenced by tls_new_alert().
| #define EINFO_EPERM_ALERT |
Definition at line 150 of file tls.c.
| #define EPERM_VERIFY __einfo_error ( EINFO_EPERM_VERIFY ) |
Definition at line 153 of file tls.c.
Referenced by tls_channel_verify().
| #define EINFO_EPERM_VERIFY |
Definition at line 154 of file tls.c.
| #define EPERM_RENEG_INSECURE __einfo_error ( EINFO_EPERM_RENEG_INSECURE ) |
Definition at line 157 of file tls.c.
Referenced by tls_new_hello_request().
| #define EINFO_EPERM_RENEG_INSECURE |
Definition at line 158 of file tls.c.
| #define EPERM_RENEG_VERIFY __einfo_error ( EINFO_EPERM_RENEG_VERIFY ) |
Definition at line 161 of file tls.c.
Referenced by tls_new_server_hello().
| #define EINFO_EPERM_RENEG_VERIFY |
Definition at line 162 of file tls.c.
| #define EPERM_KEY_EXCHANGE __einfo_error ( EINFO_EPERM_KEY_EXCHANGE ) |
Definition at line 165 of file tls.c.
Referenced by tls_hash_sign(), and tls_hash_verify().
| #define EINFO_EPERM_KEY_EXCHANGE |
Definition at line 166 of file tls.c.
| #define EPERM_SAVE __einfo_error ( EINFO_EPERM_SAVE ) |
Definition at line 169 of file tls.c.
Referenced by tls_channel_save().
| #define EINFO_EPERM_SAVE |
Definition at line 170 of file tls.c.
| #define EPERM_DOWNGRADE __einfo_error ( EINFO_EPERM_DOWNGRADE ) |
Definition at line 173 of file tls.c.
Referenced by tls_new_server_hello().
| #define EINFO_EPERM_DOWNGRADE |
Definition at line 174 of file tls.c.
| #define EPERM_SESSION_ID __einfo_error ( EINFO_EPERM_SESSION_ID ) |
Definition at line 177 of file tls.c.
Referenced by tls_new_server_hello().
| #define EINFO_EPERM_SESSION_ID |
Definition at line 178 of file tls.c.
| #define EPROTO_VERSION __einfo_error ( EINFO_EPROTO_VERSION ) |
Definition at line 181 of file tls.c.
Referenced by tls_select_cipher().
| #define EINFO_EPROTO_VERSION |
Definition at line 182 of file tls.c.
| #define EPROTO_CIPHER_CHANGE __einfo_error ( EINFO_EPROTO_CIPHER_CHANGE ) |
Definition at line 185 of file tls.c.
Referenced by tls_new_handshake(), and tls_select_cipher().
| #define EINFO_EPROTO_CIPHER_CHANGE |
Definition at line 186 of file tls.c.
| #define EPROTO_VALIDATION __einfo_error ( EINFO_EPROTO_VALIDATION ) |
Definition at line 189 of file tls.c.
Referenced by tls_validator_start().
| #define EINFO_EPROTO_VALIDATION |
Definition at line 190 of file tls.c.
| #define EPROTO_RETRY __einfo_error ( EINFO_EPROTO_RETRY ) |
Definition at line 193 of file tls.c.
Referenced by tls_new_server_hello().
| #define EINFO_EPROTO_RETRY |
Definition at line 194 of file tls.c.
| #define TLS_NUM_VERSIONS ( TLS_VERSION_MAX - TLS_VERSION_MIN + 1 ) |
Number of supported TLS versions.
Definition at line 244 of file tls.c.
Referenced by tls_client_hello().
| #define TLS_LEGACY_VERSION_MAX |
Maximum pre-TLSv1.3 version.
Definition at line 247 of file tls.c.
Referenced by add_tls(), tls_client_hello(), and tls_select_cipher().
| #define TLS_NUM_CIPHER_SUITES table_num_entries ( TLS_CIPHER_SUITES ) |
Number of supported cipher suites.
Definition at line 627 of file tls.c.
Referenced by tls_client_hello().
| #define TLS_NUM_SIG_HASH_ALGORITHMS table_num_entries ( TLS_SIG_HASH_ALGORITHMS ) |
Number of supported signature and hash algorithms.
Definition at line 1008 of file tls.c.
Referenced by tls_client_hello().
| FILE_LICENCE | ( | GPL2_OR_LATER | ) |
| FILE_SECBOOT | ( | PERMITTED | ) |
|
static |
List of TLS session.
|
static |
Resume TX state machine for all connections within a session.
| session | TLS session |
Definition at line 1863 of file tls.c.
References tls_session::conn, tls_connection::list, list_for_each_entry, tls_connection::session, and tls_tx_resume().
Referenced by tls_close(), and tls_establish().
|
static |
Allocate I/O buffer for transmitted record(s).
| tls | TLS connection |
| len | I/O buffer payload length |
| iobuf | I/O buffer |
Definition at line 3618 of file tls.c.
References tls_connection::cipherstream, iob_reserve, len, NULL, tls_iob_reserved(), and xfer_alloc_iob().
Referenced by tls_alloc_handshake(), and tls_send_plaintext().
|
static |
Transmit Alert record.
| tls | TLS connection |
| level | Alert level |
| description | Alert description |
| rc | Return status code |
Definition at line 2559 of file tls.c.
References __attribute__, alert(), tls_send_plaintext(), and TLS_TYPE_ALERT.
Referenced by tls_close_alert().
|
static |
Send plaintext record(s).
| tls | TLS connection |
| type | Record type |
| iobuf | I/O buffer |
| rc | Return status code |
Definition at line 3645 of file tls.c.
References __attribute__, assert, cipher_algorithm::authsize, cipher_algorithm::blocksize, tls_connection::channel, secure_pipe::cipher, tls_cipher_suite::cipher, cipher_auth(), cipher_encrypt, cipher_setiv(), tls_tx::cipherspec, tls_connection::cipherstream, cpu_to_be64, secure_pipe::ctx, io_buffer::data, DBGC, DBGC2, DBGC2_HDA, tls_cipher_suite::digest, digest_algorithm::digestsize, fixed, tls_cipherspec::fixed_iv, tls_cipher_suite::fixed_iv_len, tls_cipher_suite::flags, free_iob(), tls_auth_header::header, htons, iob_disown, iob_len(), iob_push, iob_put, iob_unput, is_auth_cipher(), is_block_cipher(), iv, tls_connection::legacy_version, len, tls_header::length, mac, tls_cipher_suite::mac_len, memcpy(), memmove(), memset(), NULL, rc, tls_cipher_suite::record_iv_len, tls_auth_header::seq, tls_cipherspec::seq, strerror(), tls_cipherspec::suite, tls_add_handshake(), TLS_CIPHER_FL_SEQUENTIAL_IV, tls_has_inner(), tls_hmac(), tls_iob_reserved(), tls_random(), TLS_TX_BUFSIZE, TLS_TYPE_DATA, TLS_TYPE_HANDSHAKE, tls_version(), TLS_VERSION_TLS_1_3, tls_xor(), secure_channel::tx, tls_connection::tx, tls_header::type, type, tls_header::version, and xfer_deliver_iob().
Referenced by tls_plainstream_deliver(), tls_send_handshake(), and tls_send_plaintext().
|
static |
Send plaintext record.
| rc | Return status code |
Definition at line 3828 of file tls.c.
References data, ENOMEM_TX_PLAINTEXT, iob_disown, iob_put, len, memcpy(), rc, tls_alloc_iob(), tls_send_record(), and type.
Referenced by tls_send_alert(), and tls_send_change_cipher().
|
static |
Clear key schedule digest algorithm.
| tls | TLS connection |
Definition at line 549 of file tls.c.
References tls_connection::channel, channel_unkey(), tls_connection::key, and tlskey_stop().
Referenced by add_tls(), free_tls(), and tls_set_digest().
|
static |
Referenced by free_tls(), and tls_change_cipher().
|
static |
Add Handshake record to transcript digest (without transmitting).
| tls | TLS connection |
| iobuf | I/O buffer |
| rc | Return status code |
Definition at line 1988 of file tls.c.
References io_buffer::data, free_iob(), iob_len(), and tls_add_handshake().
Referenced by tls_select_cipher().
|
static |
Digest or transmit Client Hello record.
| tls | TLS connection |
| action | Action to take on Client Hello record |
| rc | Return status code |
Definition at line 2007 of file tls.c.
References assert, tls_verify_data::client, code, tls_cipher_suite::code, tls_named_group::code, tls_signature_hash_algorithm::code, tls_connection::cookie, tls_cursor::data, tls_session_id::data, DBGC, ENOMEM, tls_named_group::exchange, ext, for_each_table_entry, free_iob(), group, tls_connection::group, hello, htons, tls_session::id, iob_disown, key, tls_cursor::len, tls_session_id::len, tls_verify_data::len, tls_key_share_client_hello::list, tls_named_group_list::list, tls_server_name_list::list, tls_signature_scheme_list::list, tls_supported_versions::list, memset(), name, tls_session::name, exchange_algorithm::pubsize, rc, tls_connection::secure_renegotiation, tls_connection::session, strerror(), strlen(), tls_session::ticket, tls_alloc_handshake(), tls_build, TLS_CIPHER_SUITES, TLS_CLIENT_HELLO, tls_key_share(), TLS_LEGACY_VERSION_MAX, TLS_MAX_FRAGMENT_LENGTH_VALUE, TLS_NAMED_GROUPS, tls_nonce(), TLS_NUM_CIPHER_SUITES, TLS_NUM_NAMED_GROUPS, TLS_NUM_SIG_HASH_ALGORITHMS, TLS_NUM_VERSIONS, TLS_SIG_HASH_ALGORITHMS, tls_size, TLS_VERSION_MAX, typeof(), tls_connection::verify, tls_renegotiation_info::verify, tls_connection::version, and version.
Referenced by tls_send_client_hello().
|
static |
Start certificate validation.
| tls | TLS connection |
| rc | Return status code |
Definition at line 4437 of file tls.c.
References tls_server::chain, create_validator(), DBGC, EPROTO_VALIDATION, is_pending(), pending_get(), rc, tls_server::root, tls_connection::server, strerror(), tls_server::validation, and tls_server::validator.
Referenced by tls_new_finished(), and tls_new_server_hello_done().
|
static |
XOR data block.
Definition at line 258 of file tls.c.
Referenced by tls_new_ciphertext(), and tls_send_record().
|
static |
Determine if TLS connection is ready for application data.
| tls | TLS connection |
| is_ready | TLS connection is ready |
Definition at line 272 of file tls.c.
References tls_connection::channel, and channel_is_established().
Referenced by tls_cipherstream_window(), tls_new_data(), tls_new_hello_request(), tls_plainstream_deliver(), and tls_plainstream_window().
|
inlinestatic |
Check for TLS version.
| tls | TLS connection |
| version | TLS version |
| at_least | TLS connection is using at least the specified version |
Check that TLS connection uses at least the specified protocol version. Optimise down to a compile-time constant true result if this is already guaranteed by the minimum or maximum supported version check.
Definition at line 290 of file tls.c.
References TLS_VERSION_MAX, TLS_VERSION_MIN, tls_connection::version, and version.
Referenced by tls_has_inner(), tls_keysize_is_variable(), tls_new_change_cipher(), tls_new_ciphertext(), tls_new_finished(), tls_new_server_hello(), tls_new_session_ticket(), tls_select_cipher(), tls_send_certificate_verify(), tls_send_finished(), tls_send_record(), tls_set_digest(), tls_validator_done(), and tls_verify_signature().
|
inlinestatic |
Check if TLS inner plaintext is in use.
| tls | TLS connection |
| cipher | Active cipher algorithm |
| has_inner | Inner plaintext is in use |
Definition at line 305 of file tls.c.
References cipher_null, tls_version(), and TLS_VERSION_TLS_1_3.
Referenced by tls_new_ciphertext(), and tls_send_record().
|
static |
Duplicate content of a TLS cursor.
| src | Source cursor |
| dst | Destination cursor |
The content of the source cursor (if any) will be copied.
If the source cursor is not present (e.g. because it represents an extension that was not present, rather than being present but empty) then the destination cursor will also become not present.
If the source cursor is present but empty (e.g. because it represents an extension that was present but empty) then the destination cursor will also become present but empty (with its pointer being the sentinel value as returned by malloc(0)).
If the source cursor is either empty or not present, then this function is guaranteed to succeed.
Definition at line 331 of file tls.c.
References assert, tls_cursor::data, ENOMEM, tls_cursor::len, malloc(), memcpy(), NULL, src, and zfree().
Referenced by tls_new_server_hello(), and tls_new_session_ticket().
|
static |
Get pipe name (for debugging).
| tls | TLS connection |
| pipe | Secure pipe |
| name | Secure pipe name |
Definition at line 361 of file tls.c.
References tls_connection::channel, secure_channel::rx, and secure_channel::tx.
Referenced by tls_change_cipher(), and tls_prep_cipher().
|
static |
Free TLS session.
| refcnt | Reference counter |
Definition at line 385 of file tls.c.
References assert, channel_clear_preshared(), tls_session::conn, container_of, tls_cursor::data, tls_session::key, tls_session::list, list_del, list_empty, privkey_put(), tls_session::psid, tls_session::root, tls_session::ticket, x509_root_put(), and zfree().
Referenced by tls_session().
|
static |
Free TLS connection.
| refcnt | Reference counter |
Definition at line 412 of file tls.c.
References assert, tls_client::chain, tls_server::chain, tls_rx::cipherspec, tls_tx::cipherspec, tls_connection::client, container_of, tls_connection::cookie, tls_cursor::data, tls_rx::data, tls_verify_data::dynamic, free_iob(), tls_rx::handshake, tls_client::key, io_buffer::list, tls_connection::list, list_del, list_empty, list_for_each_entry_safe, tls_connection::new_ticket, privkey_put(), ref_put, tls_session::refcnt, tls_server::root, tls_connection::rx, tls_connection::server, tls_connection::session, tls_clear_cipher(), tls_clear_digest(), tmp, tls_connection::tx, tls_connection::verify, x509_chain_put(), x509_root_put(), and zfree().
Referenced by add_tls().
|
static |
Finish with TLS connection.
| tls | TLS connection |
| rc | Status code |
Definition at line 450 of file tls.c.
References tls_connection::channel, channel_close(), tls_connection::cipherstream, tls_connection::client, INIT_LIST_HEAD, intf_shutdown(), tls_connection::list, list_del, tls_client::negotiation, tls_server::negotiation, pending_put(), tls_connection::plainstream, tls_tx::process, process_del(), rc, tls_connection::server, tls_connection::session, tls_tx_resume_all(), tls_connection::tx, tls_server::validation, and tls_server::validator.
Referenced by tls_close_alert(), and tls_new_alert().
|
static |
Send closure alert and finish with TLS connection.
| tls | TLS connection |
| rc | Status code |
Definition at line 482 of file tls.c.
References rc, TLS_ALERT_CLOSE_NOTIFY, TLS_ALERT_WARNING, tls_close(), and tls_send_alert().
Referenced by tls_cipherstream_deliver(), tls_tx_step(), and tls_validator_done().
|
static |
Generate deterministic connection nonce.
| tls | TLS connection |
| random | Connection nonce to fill in |
The nonce is guaranteed to be deterministic and to be unique for each connection (or renegotiation within a connection).
We choose to regenerate it afresh whenever the value is required (rather than generating it once and storing it) so that it is impossible to accidentally use a stale nonce.
Definition at line 511 of file tls.c.
References tls_connection::channel, channel_ephemeral_label(), and nonce.
Referenced by tls_client_hello(), and tls_set_digest().
|
static |
Generate random nonce.
Definition at line 527 of file tls.c.
References tls_connection::channel, channel_ephemeral(), len, and nonce.
Referenced by tls_send_record(), and tls_set_session_id().
|
static |
Set key schedule digest algorithm.
| tls | TLS connection |
| digest | Key schedule digest algorithm |
| rc | Return status code |
Definition at line 565 of file tls.c.
References DBGC, tls_connection::key, nonce, op, rc, strerror(), tls_clear_digest(), tls_nonce(), tls_version(), TLS_VERSION_TLS_1_2, TLS_VERSION_TLS_1_3, tlskey_hash, tlskey_hkdf, tlskey_md5_sha1, and tlskey_start().
Referenced by tls_select_cipher().
|
static |
Add handshake record to transcript digest.
Definition at line 603 of file tls.c.
References data, tls_connection::key, len, and tlskey_digest().
Referenced by tls_new_handshake(), tls_replay_handshake(), and tls_send_record().
|
static |
Get protocol version name (for debugging).
| version | Protocol version |
| name | Protocol version name |
Definition at line 635 of file tls.c.
References snprintf(), TLS_VERSION_TLS_1_1, TLS_VERSION_TLS_1_2, TLS_VERSION_TLS_1_3, and version.
Referenced by tls_select_cipher().
|
static |
Get cipher suite name (for debugging).
| suite | Cipher suite |
| name | Cipher suite name |
Definition at line 654 of file tls.c.
References tls_cipher_suite::cipher, tls_cipher_suite::digest, digest_null, tls_cipher_suite::exchange, tls_cipher_suite::handshake, tls_cipher_suite::key_len, cipher_algorithm::name, digest_algorithm::name, pubkey_algorithm::name, tls_key_exchange_algorithm::name, NULL, tls_cipher_suite::pubkey, pubkey_null, snprintf(), tls_null_exchange_algorithm, and tls_pubkey_exchange_algorithm.
Referenced by tls_change_cipher(), and tls_select_cipher().
|
static |
Identify cipher suite.
| cipher_suite | Cipher suite specification |
| suite | Cipher suite, or NULL |
Definition at line 691 of file tls.c.
References tls_cipher_suite::code, for_each_table_entry, NULL, and TLS_CIPHER_SUITES.
Referenced by tls_select_cipher().
|
static |
Set verification data length.
| tls | TLS connection |
| verify_len | Verification data length |
| rc | Return status code |
Definition at line 710 of file tls.c.
References assert, tls_verify_data::client, tls_verify_data::dynamic, ENOMEM, tls_verify_data::len, memset(), tls_verify_data::server, tls_connection::verify, zalloc(), and zfree().
Referenced by tls_select_cipher().
|
static |
Select protocol version and cipher suite.
| tls | TLS connection |
| version | Protocol version |
| cipher_suite | Cipher suite specification |
| rc | Return status code |
Definition at line 744 of file tls.c.
References tls_cipher_suite::cipher, DBGC, tls_cipher_suite::digest, ENOTSUP_CIPHER, ENOTSUP_VERSION, EPROTO_CIPHER_CHANGE, EPROTO_VERSION, tls_cipher_suite::exchange, tls_connection::group, tls_key_exchange_algorithm::group, tls_cipher_suite::handshake, tls_connection::legacy_version, md5_sha1_algorithm, ntohs, tls_cipher_suite::pubkey, rc, tls_connection::suite, tls_cipher_name(), tls_cipher_suite_null, tls_find_cipher_suite(), TLS_LEGACY_VERSION_MAX, tls_replay_handshake(), tls_set_digest(), tls_set_verify_len(), tls_version(), TLS_VERSION_MIN, tls_version_name(), TLS_VERSION_TLS_1_2, tls_cipher_suite::verify_len, tls_connection::version, and version.
Referenced by tls_new_server_hello().
|
static |
Clear cipher specification.
| tls | TLS connection |
| cipherspec | TLS cipher specification |
Definition at line 838 of file tls.c.
References __unused, channel_clear_cipher(), tls_cipherspec::cipher_key, tls_cipherspec::dynamic, tls_cipherspec::fixed_iv, tls_cipherspec::mac_secret, NULL, tls_cipherspec::pipe, tls_cipherspec::seq, tls_cipherspec::suite, tls_cipher_suite_null, and zfree().
|
static |
Prepare cipher specification for a new traffic phase.
| tls | TLS connection |
| cipherspec | TLS cipher specification |
| phase | Traffic phase |
| rc | Return status code |
Definition at line 866 of file tls.c.
References DBGC, tls_connection::key, tls_endpoint::name, tls_cipherspec::pipe, rc, strerror(), tls_pipe_name(), tlskey_traffic(), and tls_cipherspec::writer.
Referenced by tls_change_cipher(), and tls_send_finished().
|
static |
Change cipher specification.
| tls | TLS connection |
| cipherspec | TLS cipher specification |
| phase | New traffic phase (or NULL to retain existing phase) |
| rc | Return status code |
Definition at line 892 of file tls.c.
References assert, tls_connection::channel, channel_set_cipher(), tls_cipher_suite::cipher, tls_cipherspec::cipher_key, DBGC, tls_cipherspec::dynamic, ENOMEM_CONTEXT, ENOTSUP_NULL, tls_cipherspec::fixed_iv, tls_cipher_suite::fixed_iv_len, tls_connection::key, tls_cipher_suite::key_len, tls_cipher_suite::mac_len, tls_cipherspec::mac_secret, tls_endpoint::name, tls_cipherspec::pipe, rc, strerror(), tls_cipherspec::suite, tls_connection::suite, tls_cipher_name(), tls_cipher_suite_null, tls_clear_cipher(), tls_pipe_name(), tls_prep_cipher(), tlskey_cipher(), tls_cipherspec::writer, and zalloc().
Referenced by tls_pending_cipher(), tls_send_change_cipher(), and tls_send_finished().
|
static |
Apply pending traffic phase change (if any).
| tls | TLS connection |
| cipherspec | TLS cipher specification |
| rc | Return status code |
Definition at line 980 of file tls.c.
References NULL, pending, tls_cipherspec::pending, rc, and tls_change_cipher().
Referenced by tls_new_ciphertext().
|
static |
Find TLS signature and hash algorithm.
| pubkey | Public-key algorithm |
| digest | Digest algorithm |
| sig_hash | Signature and hash algorithm, or NULL |
Definition at line 1019 of file tls.c.
References tls_signature_hash_algorithm::digest, for_each_table_entry, NULL, tls_signature_hash_algorithm::pubkey, and TLS_SIG_HASH_ALGORITHMS.
Referenced by tls_send_certificate_verify().
|
static |
Find TLS signature and hash algorithm.
| code | Signature and hash algorithm identifier |
| sig_hash | Signature and hash algorithm, or NULL |
Definition at line 1041 of file tls.c.
References code, tls_signature_hash_algorithm::code, for_each_table_entry, NULL, and TLS_SIG_HASH_ALGORITHMS.
Referenced by tls_verify_signature().
|
static |
Identify named key exchange group.
| named_group | Named group specification |
| group | Named group, or NULL |
Definition at line 1067 of file tls.c.
References for_each_table_entry, group, NULL, and TLS_NAMED_GROUPS.
Referenced by tls_new_server_hello(), and tls_parse_ecdhe().
|
static |
Identify named key exchange group by Diffie-Hellman parameters.
| dh_p | Prime modulus |
| dh_g | Generator |
| group | Named group, or NULL |
Definition at line 1087 of file tls.c.
References tls_cursor::data, ffdhe_has_params(), for_each_table_entry, group, is_ffdhe(), tls_cursor::len, NULL, and TLS_NAMED_GROUPS.
Referenced by tls_parse_dhe().
|
static |
Parse key exchange parameters from unexpected Server Key Exchange record.
| cursor | Server Key Exchange handshake record |
| kex | Key exchange parameters to fill in |
| rc | Return status code |
Definition at line 1111 of file tls.c.
References __unused, tls_cursor::data, DBGC, DBGC_HDA, EINVAL_KEY_EXCHANGE, and tls_cursor::len.
|
static |
Parse key exchange parameters from DHE Server Key Exchange record.
| tls | TLS connection |
| cursor | Server Key Exchange handshake record |
| kex | Key exchange parameters to fill in |
| rc | Return status code |
Definition at line 1153 of file tls.c.
References tls_cursor::data, DBGC, DBGC_HDA, tls_server_key_exchange_dhe::dh_g, tls_server_key_exchange_dhe::dh_p, tls_server_key_exchange_dhe::dh_ys, tls_server_key_exchange_dhe::dsig, ENOTSUP_GROUP, group, tls_key_exchange_parameters::group, tls_cursor::len, tls_key_exchange_parameters::len, tls_key_exchange_parameters::partner, rc, strerror(), tls_find_param_group(), tls_parse, and tls_connection::version.
|
static |
Parse key exchange parameters from ECDHE Server Key Exchange record.
| tls | TLS connection |
| cursor | Server Key Exchange handshake record |
| len | Length of Server Key Exchange handshake record |
| kex | Key exchange parameters to fill in |
| rc | Return status code |
Definition at line 1202 of file tls.c.
References tls_server_key_exchange_ecdhe::curve, tls_cursor::data, DBGC, DBGC_HDA, tls_server_key_exchange_ecdhe::dsig, ENOTSUP_GROUP, group, tls_key_exchange_parameters::group, tls_server_key_exchange_ecdhe::group, tls_cursor::len, tls_key_exchange_parameters::len, ntohs, tls_key_exchange_parameters::partner, tls_server_key_exchange_ecdhe::point, rc, strerror(), tls_find_named_group(), TLS_NAMED_CURVE_TYPE, tls_parse, tls_server_key_exchange_ecdhe::type, and tls_connection::version.
|
static |
Check if key exchange keys have a variable size.
| tls | TLS connection |
| exchange | Key exchange algorithm |
| is_variable | Key exchange keys have a variable size |
TLS versions 1.2 and earlier treat FFDHE public and shared keys as unsigned big-endian integers using a minimal byte representation. For all other purposes, key exchange keys have a fixed size determined by the key exchange algorithm.
Definition at line 1260 of file tls.c.
References is_ffdhe(), tls_version(), and TLS_VERSION_TLS_1_3.
Referenced by tls_channel_apply(), and tls_key_agree().
|
static |
Share public key.
| tls | TLS connection |
| group | Named group |
| public | Public key to fill in |
| rc | Return status code |
Definition at line 1286 of file tls.c.
References channel, tls_connection::channel, channel_key_share(), DBGC, EINVAL_KEY_EXCHANGE, group, exchange_algorithm::name, exchange_algorithm::pubsize, rc, and strerror().
Referenced by tls_client_hello(), and tls_send_client_key_exchange().
|
static |
Agree shared secret.
| rc | Return status code |
Definition at line 1320 of file tls.c.
References channel, tls_connection::channel, channel_key_agree(), DBGC, DBGC_HDA, EINVAL_KEY_EXCHANGE, ENOMEM, group, memcpy(), exchange_algorithm::name, partner, exchange_algorithm::pubsize, rc, strerror(), tls_keysize_is_variable(), tmp, zalloc(), and zfree().
Referenced by tls_new_server_hello(), and tls_new_server_key_exchange().
|
static |
Encrypt (and implicitly bind) shared secret.
| tls | TLS connection |
| group | Named group |
| builder | ASN.1 builder |
| rc | Return status code |
Definition at line 1382 of file tls.c.
References x509_public_key::algorithm, tls_server::chain, channel, tls_connection::channel, channel_bind_encrypt(), DBGC, ENOENT_CERT, group, exchange_algorithm::name, asn1_algorithm::pubkey, x509_subject::public_key, rc, tls_connection::server, strerror(), x509_certificate::subject, and x509_first().
Referenced by tls_send_client_key_exchange().
|
static |
Create signature over parameters used to construct shared secret.
| tls | TLS connection |
| sig_hash | Signature hash algorithm |
| cert | Certificate |
| sig | Signature to fill in |
| rc | Return status code |
Definition at line 1423 of file tls.c.
References tls_signature_hash_algorithm::algorithm, x509_public_key::algorithm, tls_connection::client, DBGC, tls_signature_hash_algorithm::digest, digest_algorithm::digestsize, EPERM_KEY_EXCHANGE, key, tls_client::key, tls_connection::key, asn1_algorithm::name, digest_algorithm::name, pubkey_algorithm::name, NULL, privkey_cursor(), tls_signature_hash_algorithm::pubkey, pubkey_sign(), x509_subject::public_key, rc, sig, strerror(), x509_certificate::subject, and tlskey_tbshash().
Referenced by tls_send_certificate_verify().
|
static |
Verify signature over parameters used to construct shared secret.
| tls | TLS connection |
| sig_hash | Signature hash algorithm |
| cert | Certificate |
| params | Additional parameters |
| sig | Signature |
| rc | Return status code |
Definition at line 1472 of file tls.c.
References tls_signature_hash_algorithm::algorithm, x509_public_key::algorithm, tls_connection::channel, channel_bind_verify(), tls_cursor::data, DBGC, tls_signature_hash_algorithm::digest, digest_algorithm::digestsize, EPERM_KEY_EXCHANGE, tls_connection::key, tls_cursor::len, asn1_algorithm::name, digest_algorithm::name, pubkey_algorithm::name, tls_signature_hash_algorithm::pubkey, x509_subject::public_key, rc, sig, strerror(), x509_certificate::subject, and tlskey_tbshash().
Referenced by tls_verify_signature().
|
static |
Reset the key schedule.
| channel | Secure channel |
Definition at line 1524 of file tls.c.
References channel, container_of, tls_connection::key, and tlskey_reset().
|
static |
Apply a new shared secret to key schedule.
| channel | Secure channel |
| exchange | Key exchange algorithm |
| shared | New shared secret |
| accumulated | Accumulation flag to fill in |
| rc | Return status code |
Definition at line 1541 of file tls.c.
References assert, channel, container_of, DBGC, DBGC_HDA, tls_connection::key, rc, exchange_algorithm::sharedsize, strerror(), tls_keysize_is_variable(), tlskey_apply(), and tlskey_is_accumulating().
|
static |
Save a pre-shared key for future resumption of the key schedule.
| channel | Secure channel |
| psid | Pre-shared bound peer identity |
| rc | Return status code |
Definition at line 1586 of file tls.c.
References channel, channel_is_established(), container_of, DBGC, EPERM_SAVE, tls_connection::key, NULL, tls_session::psid, tls_session::psk, rc, strerror(), and tlskey_save().
|
static |
Load a pre-shared key and resume the key schedule.
| channel | Secure channel |
| psid | Pre-shared bound peer identity |
| rc | Return status code |
Definition at line 1623 of file tls.c.
References channel, container_of, DBGC, tls_connection::extended_master_secret, tls_connection::key, tls_session::psid, tls_session::psk, rc, strerror(), and tlskey_load().
|
static |
Verify authenticator value.
| rc | Return status code |
Definition at line 1650 of file tls.c.
References channel, container_of, DBGC, DBGC_HDA, EPERM_VERIFY, tls_connection::key, len, tls_verify_data::len, memcmp(), rc, tls_verify_data::server, strerror(), tlskey_verify(), and tls_connection::verify.
|
static |
Set a random session ID.
| tls | TLS connection |
The session ID will be generated deterministically using the per-connection ephemeral secret and will therefore be guaranteed to differ between connections (including restarted connections).
Definition at line 1705 of file tls.c.
References tls_session_id::data, tls_session::id, tls_session_id::len, tls_connection::session, and tls_random().
Referenced by tls_save(), and tls_session().
|
static |
Find or create session for TLS connection.
| tls | TLS connection |
| name | Server name |
| rc | Return status code |
Definition at line 1720 of file tls.c.
References tls_connection::client, tls_session::conn, tls_session_id::data, DBGC, DBGC_HDA, ENOMEM, free_tls_session(), tls_session::id, INIT_LIST_HEAD, tls_client::key, tls_session::key, tls_cursor::len, tls_session_id::len, tls_session::list, list_add, list_for_each_entry, name, tls_session::name, privkey_get(), rc, ref_get, ref_init, ref_put, tls_session::refcnt, tls_server::root, tls_session::root, tls_connection::server, tls_connection::session, strcmp(), strcpy(), strlen(), tls_session::ticket, tls_set_session_id(), x509_root_get(), and zalloc().
|
static |
Save session for future resumption.
| tls | TLS connection |
| rc | Return status code |
Definition at line 1775 of file tls.c.
References assert, tls_connection::channel, channel_save(), tls_cursor::data, tls_session_id::data, DBGC, DBGC_HDA, tls_session::id, tls_cursor::len, tls_session_id::len, memcpy(), name, tls_session::name, tls_connection::new_id, tls_connection::new_ticket, NULL, tls_session::psid, rc, tls_connection::session, strerror(), tls_session::ticket, tls_set_session_id(), and zfree().
Referenced by tls_establish().
|
static |
Resume session.
| tls | TLS connection |
| rc | Return status code |
Definition at line 1824 of file tls.c.
References tls_connection::channel, channel_load(), DBGC, tls_cursor::len, tls_session::name, tls_session::psid, rc, tls_connection::session, strerror(), and tls_session::ticket.
Referenced by tls_new_server_hello().
|
static |
Resume TX state machine.
| tls | TLS connection |
Definition at line 1854 of file tls.c.
References tls_tx::process, process_add(), and tls_connection::tx.
Referenced by tls_new_finished(), tls_new_server_hello(), tls_restart(), tls_tx_resume_all(), tls_tx_step(), and tls_validator_done().
|
static |
Restart negotiation.
| tls | TLS connection |
Definition at line 1875 of file tls.c.
References assert, tls_connection::channel, channel_reopen(), tls_connection::client, is_pending(), tls_client::negotiation, tls_server::negotiation, tls_tx::pending, pending_get(), tls_connection::server, tls_connection::suite, tls_cipher_suite_null, TLS_TX_CLIENT_HELLO, tls_tx_resume(), tls_connection::tx, and tls_server::validation.
Referenced by add_tls(), and tls_new_hello_request().
|
static |
Establish secure channel.
| tls | TLS connection |
| rc | Return status code |
Definition at line 1902 of file tls.c.
References tls_connection::channel, channel_establish(), tls_session::conn, DBGC, tls_cursor::len, tls_session_id::len, tls_connection::list, list_add_tail, list_del, tls_session::name, tls_connection::new_id, tls_connection::new_ticket, tls_connection::plainstream, rc, tls_server::root, tls_connection::server, tls_connection::session, strerror(), tls_save(), tls_tx_resume_all(), and xfer_window_changed().
Referenced by tls_new_finished(), and tls_send_finished().
|
static |
Allocate Handshake record.
| tls | TLS connection |
| cursor | Cursor to hold handshake message |
| type | Record type |
| iobuf | I/O buffer, or NULL on error |
Definition at line 1939 of file tls.c.
References tls_cursor::data, htonl, iob_put, tls_cursor::len, NULL, tls_alloc_iob(), tls_handshake_header::type, type, and tls_handshake_header::type_len.
Referenced by tls_client_hello(), tls_send_certificate(), tls_send_certificate_verify(), tls_send_client_key_exchange(), and tls_send_finished().
|
static |
Transmit Handshake record.
| tls | TLS connection |
| iobuf | I/O buffer |
| rc | Return status code |
Definition at line 1968 of file tls.c.
References iob_disown, rc, tls_send_record(), and TLS_TYPE_HANDSHAKE.
Referenced by tls_send_certificate(), tls_send_certificate_verify(), tls_send_client_hello(), tls_send_client_key_exchange(), and tls_send_finished().
|
static |
Transmit Client Hello record.
| tls | TLS connection |
| rc | Return status code |
Definition at line 2190 of file tls.c.
References tls_client_hello(), and tls_send_handshake().
Referenced by tls_tx_step().
|
static |
Transmit Certificate record.
| tls | TLS connection |
| rc | Return status code |
Definition at line 2201 of file tls.c.
References assert, tls_certificate_entry::cert, tls_client::chain, tls_connection::client, asn1_cursor::data, tls_cursor::data, DBGC, ENOENT_CERT, ENOMEM, free_iob(), iob_disown, asn1_cursor::len, tls_cursor::len, link, x509_chain::links, io_buffer::list, tls_certificate::list, list_for_each_entry, memset(), next, tls_certificate_entry::next, x509_certificate::raw, rc, strerror(), io_buffer::tail, tls_alloc_handshake(), tls_build, TLS_CERTIFICATE, tls_send_handshake(), tls_size, tls_connection::version, version, and x509_name().
Referenced by tls_tx_step().
|
static |
Transmit Client Key Exchange record.
| tls | TLS connection |
| rc | Return status code |
Definition at line 2286 of file tls.c.
References tls_client_key_exchange::cursor, asn1_builder::data, tls_cursor::data, DBGC, tls_client_key_exchange::desc, ENOMEM, tls_cipher_suite::exchange, tls_connection::extended_master_secret, free_iob(), group, tls_connection::group, iob_disown, is_key_transport(), tls_connection::key, asn1_builder::len, tls_cursor::len, map, tls_key_exchange_algorithm::map, NULL, exchange_algorithm::pubsize, rc, strerror(), tls_connection::suite, tls_alloc_handshake(), tls_build_map(), TLS_CLIENT_KEY_EXCHANGE, tls_key_encrypt(), tls_key_share(), tls_send_handshake(), tls_size_map(), tlskey_master(), tls_connection::version, and zfree().
Referenced by tls_tx_step().
|
static |
Transmit Certificate Verify record.
| tls | TLS connection |
| rc | Return status code |
Definition at line 2359 of file tls.c.
References x509_public_key::algorithm, tls_client::chain, tls_connection::client, tls_signature_hash_algorithm::code, asn1_builder::data, tls_cursor::data, DBGC, tls_key_schedule::digest, tls_signature_hash_algorithm::digest, ENOENT_CERT, ENOMEM, ENOTSUP_SIG_HASH, free_iob(), iob_disown, tls_connection::key, asn1_builder::len, tls_cursor::len, md5_sha1_algorithm, memset(), digest_algorithm::name, pubkey_algorithm::name, NULL, asn1_algorithm::pubkey, tls_signature_hash_algorithm::pubkey, x509_subject::public_key, rc, rsa_algorithm, sha1_algorithm, tls_digitally_signed::sig, tls_digitally_signed::sig_hash, strerror(), x509_certificate::subject, tls_alloc_handshake(), tls_build, TLS_CERTIFICATE_VERIFY, tls_hash_sign(), tls_send_handshake(), tls_signature_hash_algorithm(), tls_size, tls_version(), TLS_VERSION_TLS_1_2, tmp, tls_connection::version, x509_first(), and zfree().
Referenced by tls_tx_step().
|
static |
Transmit Change Cipher record.
| tls | TLS connection |
| rc | Return status code |
Definition at line 2456 of file tls.c.
References __attribute__, tls_tx::cipherspec, rc, spec, tls_application, tls_change_cipher(), TLS_CHANGE_CIPHER_SPEC, tls_send_plaintext(), TLS_TYPE_CHANGE_CIPHER, and tls_connection::tx.
Referenced by tls_tx_step().
|
static |
Transmit Finished record.
| tls | TLS connection |
| rc | Return status code |
Definition at line 2486 of file tls.c.
References tls_tx::cipherspec, tls_connection::client, tls_verify_data::client, tls_cursor::data, DBGC, ENOMEM, free_iob(), iob_disown, is_pending(), tls_connection::key, tls_cursor::len, tls_verify_data::len, memcpy(), tls_client::negotiation, tls_server::negotiation, NULL, pending_put(), rc, tls_connection::server, strerror(), tls_alloc_handshake(), tls_application, tls_change_cipher(), tls_establish(), TLS_FINISHED, tls_prep_cipher(), tls_send_handshake(), tls_version(), TLS_VERSION_TLS_1_3, tlskey_verify(), tls_connection::tx, and tls_connection::verify.
Referenced by tls_tx_step().
|
static |
Receive new Change Cipher record.
| tls | TLS connection |
| iobuf | I/O buffer |
| rc | Return status code |
Definition at line 2581 of file tls.c.
References __attribute__, tls_rx::cipherspec, io_buffer::data, DBGC, DBGC_HD, EINVAL_CHANGE_CIPHER, iob_len(), iob_pull, len, tls_cipherspec::pending, tls_connection::rx, spec, tls_application, TLS_CHANGE_CIPHER_SPEC, tls_version(), and TLS_VERSION_TLS_1_3.
Referenced by tls_new_record().
|
static |
Receive new Alert record.
| tls | TLS connection |
| iobuf | I/O buffer |
| rc | Return status code |
Definition at line 2611 of file tls.c.
References __attribute__, alert(), io_buffer::data, DBGC, DBGC_HD, EINVAL_ALERT, EIO_ALERT, EPERM_ALERT, iob_len(), iob_pull, len, next, TLS_ALERT_CLOSE_NOTIFY, TLS_ALERT_FATAL, TLS_ALERT_WARNING, and tls_close().
Referenced by tls_new_record().
|
static |
Receive new Hello Request handshake record.
| tls | TLS connection |
| cursor | Plaintext handshake record |
| rc | Return status code |
Definition at line 2660 of file tls.c.
References DBGC, EPERM_RENEG_INSECURE, tls_connection::extended_master_secret, rc, request, tls_connection::secure_renegotiation, strerror(), tls_parse, tls_ready(), tls_restart(), and tls_connection::version.
Referenced by tls_new_handshake().
|
static |
Receive new Server Hello handshake record.
| tls | TLS connection |
| cursor | Plaintext handshake record |
| rc | Return status code |
Definition at line 2699 of file tls.c.
References tls_rx::cipherspec, tls_tx::cipherspec, tls_connection::client, container_of, tls_connection::cookie, tls_cursor::data, tls_session_id::data, DBGC, DBGC_HDA, tls_verify_data::dynamic, ENOTSUP_GROUP, EPERM_DOWNGRADE, EPERM_RENEG_VERIFY, EPERM_SESSION_ID, EPROTO_RETRY, tls_connection::extended_master_secret, group, tls_connection::group, hello, tls_session::id, is_pending(), key, tls_connection::key, key_map, tls_cursor::len, tls_session_id::len, tls_verify_data::len, memcmp(), memcpy(), tls_client::negotiation, tls_connection::new_id, ntohs, NULL, tls_cipherspec::pending, tls_tx::pending, random(), rc, tls_connection::rx, tls_connection::secure_renegotiation, tls_supported_version::selected, tls_connection::session, strerror(), tls_connection::suite, tls_cipher_suite_null, tls_copy(), tls_downgrade_magic, tls_find_named_group(), tls_handshake, tls_hrr_magic, tls_key_agree(), tls_parse, tls_parse_opt, tls_parse_opt_map(), tls_resume(), tls_select_cipher(), TLS_TX_CLIENT_HELLO, tls_tx_resume(), tls_version(), TLS_VERSION_MAX, TLS_VERSION_TLS_1_1, TLS_VERSION_TLS_1_3, tlskey_message(), tls_connection::tx, tls_connection::verify, tls_renegotiation_info::verify, tls_connection::version, and version.
Referenced by tls_new_handshake().
|
static |
Receive New Session Ticket handshake record.
| tls | TLS connection |
| cursor | Plaintext handshake record |
| rc | Return status code |
Definition at line 2885 of file tls.c.
References DBGC, tls_connection::new_ticket, rc, strerror(), tls_new_session_ticket::ticket, tls_copy(), tls_parse, tls_version(), TLS_VERSION_TLS_1_3, and tls_connection::version.
|
static |
Receive new Certificate handshake record.
| tls | TLS connection |
| cursor | Plaintext handshake record |
| rc | Return status code |
Definition at line 2919 of file tls.c.
References tls_certificate_entry::cert, tls_server::chain, tls_cursor::data, DBGC, ENOMEM_CHAIN, tls_cursor::len, tls_certificate::list, tls_certificate_entry::next, NULL, rc, tls_connection::server, strerror(), tls_parse, tls_connection::version, x509_alloc_chain(), x509_append_raw(), and x509_chain_put().
Referenced by tls_new_handshake().
|
static |
Verify a signature record.
| tls | TLS connection |
| cursor | Signature record |
| params | Additional parameters |
| rc | Return status code |
Definition at line 2985 of file tls.c.
References x509_public_key::algorithm, assert, tls_server::chain, DBGC, tls_signature_hash_algorithm::digest, ENOENT_CERT, ENOTSUP_SIG_HASH, md5_sha1_algorithm, memset(), ntohs, NULL, asn1_algorithm::pubkey, tls_signature_hash_algorithm::pubkey, x509_subject::public_key, rc, rsa_algorithm, tls_connection::server, sha1_algorithm, tls_digitally_signed::sig, tls_digitally_signed::sig_hash, strerror(), x509_certificate::subject, tls_asn1(), tls_find_signature_hash(), tls_hash_verify(), tls_parse, tls_version(), TLS_VERSION_TLS_1_2, tmp, tls_connection::version, and x509_first().
Referenced by tls_new_certificate_verify(), and tls_new_server_key_exchange().
|
static |
Receive new Certificate Verify handshake record.
| tls | TLS connection |
| cursor | Plaintext handshake record |
| rc | Return status code |
Definition at line 3052 of file tls.c.
References rc, and tls_verify_signature().
Referenced by tls_new_handshake().
|
static |
Receive new Server Key Exchange handshake record.
| tls | TLS connection |
| cursor | Plaintext handshake record |
| rc | Return status code |
Definition at line 3071 of file tls.c.
References assert, tls_cursor::data, DBGC, tls_cipher_suite::exchange, tls_named_group::exchange, tls_connection::group, tls_key_exchange_parameters::group, tls_cursor::len, tls_key_exchange_parameters::len, exchange_algorithm::name, tls_key_exchange_algorithm::name, tls_key_exchange_algorithm::parse, tls_key_exchange_parameters::partner, rc, tls_connection::suite, tls_key_agree(), and tls_verify_signature().
Referenced by tls_new_handshake().
|
static |
Receive new Certificate Request handshake record.
| tls | TLS connection |
| cursor | Plaintext handshake record |
| len | Length of plaintext handshake record |
| rc | Return status code |
Definition at line 3115 of file tls.c.
References __unused, certstore, tls_client::chain, tls_connection::client, DBGC, ENOMEM, tls_client::key, NULL, rc, x509_alloc_chain(), x509_append(), x509_auto_append(), x509_chain_put(), x509_find_key(), and x509_name().
Referenced by tls_new_handshake().
|
static |
Receive new Server Hello Done handshake record.
| tls | TLS connection |
| cursor | Plaintext handshake record |
| rc | Return status code |
Definition at line 3173 of file tls.c.
References DBGC, done, rc, strerror(), tls_parse, tls_validator_start(), and tls_connection::version.
Referenced by tls_new_handshake().
|
static |
Receive new Finished handshake record.
| tls | TLS connection |
| cursor | Plaintext handshake record |
| rc | Return status code |
Definition at line 3200 of file tls.c.
References tls_server::chain, tls_connection::channel, channel_confirm(), tls_rx::cipherspec, tls_connection::client, tls_cursor::data, DBGC, is_pending(), tls_connection::key, tls_cursor::len, tls_client::negotiation, tls_server::negotiation, tls_cipherspec::pending, tls_tx::pending, pending_put(), rc, tls_connection::rx, tls_connection::server, strerror(), tls_application, tls_establish(), TLS_TX_CHANGE_CIPHER, TLS_TX_FINISHED, tls_tx_resume(), tls_validator_start(), tls_version(), TLS_VERSION_TLS_1_3, tlskey_master(), and tls_connection::tx.
Referenced by tls_new_handshake().
|
static |
Receive new Handshake record.
| tls | TLS connection |
| iobuf | I/O buffer |
| rc | Return status code |
Following the general robustness principle, we accept handshake records in any order of arrival and rely on the secure channel abstraction to determine whether or not the resulting sequence of operations is sufficient to establish the channel.
Most non-standard handshake record sequences would not manage to successfully establish the channel. For example: a premature Finished that attempts to skip the ServerKeyExchange would fail because the channel will reject an attempt to confirm an unbound peer identity.
It would be possible for an inventive server to construct non-standard sequences of handshake records that do successfully establish the secure channel. For example: a server could choose to send a second ServerKeyExchange record with a second valid signature (over the updated transcript digest that includes the first ServerKeyExchange). This would be non-standard and rather pointless, but would be accepted for the purpose of establishing the secure channel since it does in fact provide the required security properties.
Definition at line 3282 of file tls.c.
References tls_rx::cipherspec, io_buffer::data, tls_cursor::data, DBGC, EPROTO_CIPHER_CHANGE, iob_len(), iob_pull, len, tls_cursor::len, NULL, tls_cipherspec::pending, rc, tls_connection::rx, tls_add_handshake(), TLS_CERTIFICATE, TLS_CERTIFICATE_REQUEST, TLS_CERTIFICATE_VERIFY, TLS_FINISHED, TLS_HANDSHAKE_LEN, TLS_HELLO_REQUEST, tls_new_certificate(), tls_new_certificate_request(), tls_new_certificate_verify(), tls_new_finished(), tls_new_hello_request(), tls_new_server_hello(), tls_new_server_hello_done(), tls_new_server_key_exchange(), TLS_NEW_SESSION_TICKET, TLS_SERVER_HELLO, TLS_SERVER_HELLO_DONE, TLS_SERVER_KEY_EXCHANGE, tls_handshake_header::type, and tls_handshake_header::type_len.
Referenced by tls_new_record().
|
static |
Receive new unknown record.
| tls | TLS connection |
| iobuf | I/O buffer |
| rc | Return status code |
Definition at line 3374 of file tls.c.
References __unused, iob_len(), and iob_pull.
Referenced by tls_new_record().
|
static |
Receive new data record.
| tls | TLS connection |
| rx_data | List of received data buffers |
| rc | Return status code |
Definition at line 3389 of file tls.c.
References DBGC, ENOTCONN, io_buffer::list, list_del, list_first_entry, tls_connection::plainstream, rc, strerror(), tls_ready(), and xfer_deliver_iob().
Referenced by tls_new_record().
|
static |
Receive new record.
| tls | TLS connection |
| type | Record type |
| rx_data | List of received data buffers |
| rc | Return status code |
Definition at line 3421 of file tls.c.
References assert, DBGC, ENOMEM_RX_CONCAT, free_iob(), tls_rx::handshake, iob_concatenate(), iob_len(), list_add, NULL, rc, tls_connection::rx, tls_new_alert(), tls_new_change_cipher(), tls_new_data(), tls_new_handshake(), tls_new_unknown(), TLS_TYPE_ALERT, TLS_TYPE_CHANGE_CIPHER, TLS_TYPE_DATA, TLS_TYPE_HANDSHAKE, tmp, and type.
Referenced by tls_new_ciphertext().
|
static |
Initialise HMAC.
| cipherspec | Cipher specification |
| ctx | Context |
| authhdr | Authentication header |
Definition at line 3499 of file tls.c.
References ctx, tls_cipher_suite::digest, hmac_init(), hmac_update(), tls_cipher_suite::mac_len, tls_cipherspec::mac_secret, and tls_cipherspec::suite.
Referenced by tls_hmac(), and tls_hmac_list().
|
static |
Update HMAC.
Definition at line 3516 of file tls.c.
References ctx, data, tls_cipher_suite::digest, hmac_update(), len, and tls_cipherspec::suite.
Referenced by tls_hmac(), and tls_hmac_list().
|
static |
Finalise HMAC.
Definition at line 3530 of file tls.c.
References ctx, tls_cipher_suite::digest, hmac_final(), and tls_cipherspec::suite.
Referenced by tls_hmac(), and tls_hmac_list().
|
static |
Calculate HMAC.
| cipherspec | Cipher specification |
| authhdr | Authentication header |
| data | Data |
| len | Length of data |
| mac | HMAC to fill in |
Definition at line 3546 of file tls.c.
References ctx, data, tls_cipher_suite::digest, hmac_ctxsize(), len, tls_cipherspec::suite, tls_hmac_final(), tls_hmac_init(), and tls_hmac_update().
Referenced by tls_send_record().
|
static |
Calculate HMAC over list of I/O buffers.
| cipherspec | Cipher specification |
| authhdr | Authentication header |
| list | List of I/O buffers |
| mac | HMAC to fill in |
Definition at line 3565 of file tls.c.
References ctx, io_buffer::data, tls_cipher_suite::digest, hmac_ctxsize(), iob_len(), io_buffer::list, list_for_each_entry, tls_cipherspec::suite, tls_hmac_final(), tls_hmac_init(), and tls_hmac_update().
Referenced by tls_new_ciphertext().
|
static |
Calculate maximum additional length required for transmitted record(s).
| tls | TLS connection |
| len | I/O buffer payload length |
| reserve | Maximum additional length to reserve |
Definition at line 3587 of file tls.c.
References cipher_algorithm::authsize, cipher_algorithm::blocksize, tls_connection::channel, secure_pipe::cipher, tls_tx::cipherspec, count, is_block_cipher(), len, tls_cipher_suite::mac_len, tls_cipher_suite::record_iv_len, tls_cipherspec::suite, TLS_TX_BUFSIZE, secure_channel::tx, and tls_connection::tx.
Referenced by tls_alloc_iob(), and tls_send_record().
|
static |
Verify block padding.
| tls | TLS connection |
| iobuf | Last received I/O buffer |
Definition at line 3854 of file tls.c.
References io_buffer::data, DBGC, DBGC_HD, EINVAL_PADDING, iob_len(), len, pad, and io_buffer::tail.
Referenced by tls_new_ciphertext().
|
static |
Extract inner plaintext.
| tls | TLS connection |
| type | Record type |
| rx_data | List of received data buffers |
| type | Inner plaintext record type, or negative error |
Definition at line 3889 of file tls.c.
References data, io_buffer::data, DBGC, EINVAL_INNER, iob_len(), iob_unput, len, io_buffer::list, list_for_each_entry_reverse, TLS_TYPE_DATA, and type.
Referenced by tls_new_ciphertext().
|
static |
Receive new ciphertext record.
| tls | TLS connection |
| tlshdr | Record header |
| rx_data | List of received data buffers |
| rc | Return status code |
Definition at line 3930 of file tls.c.
References __attribute__, assert, cipher_algorithm::authsize, cipher_algorithm::blocksize, tls_connection::channel, secure_pipe::cipher, tls_cipher_suite::cipher, cipher_auth(), cipher_decrypt, cipher_setiv(), tls_rx::cipherspec, tls_tx::cipherspec, cpu_to_be64, secure_pipe::ctx, io_buffer::data, tls_rx::data, DBGC, DBGC2, DBGC2_HD, DBGC_HD, tls_cipher_suite::digest, digest_algorithm::digestsize, EINVAL_BLOCK, EINVAL_IV, EINVAL_MAC, first, fixed, tls_cipherspec::fixed_iv, tls_cipher_suite::fixed_iv_len, tls_cipher_suite::flags, tls_auth_header::header, htons, iob_len(), iob_pull, iob_unput, is_auth_cipher(), is_block_cipher(), iv, len, tls_header::length, io_buffer::list, list_empty, list_first_entry, list_for_each_entry, list_last_entry, mac, tls_cipher_suite::mac_len, memcmp(), memcpy(), memset(), ntohs, NULL, rc, tls_cipher_suite::record_iv_len, secure_channel::rx, tls_connection::rx, tls_auth_header::seq, tls_cipherspec::seq, strerror(), tls_cipherspec::suite, io_buffer::tail, TLS_CIPHER_FL_SEQUENTIAL_IV, tls_extract_inner(), tls_has_inner(), tls_hmac_list(), tls_new_record(), tls_pending_cipher(), TLS_RX_BUFSIZE, TLS_TYPE_CHANGE_CIPHER, tls_verify_padding(), tls_version(), TLS_VERSION_TLS_1_3, tls_xor(), tls_connection::tx, tls_header::type, type, and tls_header::version.
Referenced by tls_newdata_process_data().
|
static |
Check flow control window.
| tls | TLS connection |
| len | Length of window |
Definition at line 4137 of file tls.c.
References tls_connection::cipherstream, tls_ready(), and xfer_window().
|
static |
Deliver datagram as raw data.
| tls | TLS connection |
| iobuf | I/O buffer |
| meta | Data transfer metadata |
| rc | Return status code |
Definition at line 4154 of file tls.c.
References __unused, done, ENOTCONN, free_iob(), iob_disown, meta, rc, tls_ready(), tls_send_record(), and TLS_TYPE_DATA.
|
static |
Report job progress.
| tls | TLS connection |
| progress | Progress report to fill in |
| ongoing_rc | Ongoing job status code (if known) |
Definition at line 4182 of file tls.c.
References tls_connection::cipherstream, is_pending(), job_progress(), tls_connection::server, tls_server::validation, and tls_server::validator.
|
static |
Handle received TLS header.
| tls | TLS connection |
| rc | Returned status code |
Definition at line 4222 of file tls.c.
References cipher_algorithm::alignsize, alloc_iob_raw(), assert, tls_connection::channel, secure_pipe::cipher, tls_rx::cipherspec, tls_rx::data, data_len, DBGC, ENOMEM_RX_DATA, free_iob(), tls_rx::header, iob_reserve, iob_tailroom(), tls_header::length, io_buffer::list, list_add_tail, list_del, list_empty, list_for_each_entry_safe, ntohs, rc, tls_cipher_suite::record_iv_len, secure_channel::rx, tls_connection::rx, tls_rx::state, tls_cipherspec::suite, TLS_RX_ALIGN, TLS_RX_BUFSIZE, TLS_RX_DATA, TLS_RX_MIN_BUFSIZE, and tmp.
Referenced by tls_cipherstream_deliver().
|
static |
Handle received TLS data payload.
| tls | TLS connection |
| rc | Returned status code |
Definition at line 4308 of file tls.c.
References assert, tls_rx::data, tls_rx::header, iob_tailroom(), iob_unput, tls_rx::iobuf, io_buffer::list, list_add_tail, list_del, list_empty, list_first_entry, rc, tls_connection::rx, tls_rx::state, tls_new_ciphertext(), and TLS_RX_HEADER.
Referenced by tls_cipherstream_deliver().
|
static |
Check flow control window.
| tls | TLS connection |
| len | Length of window |
Definition at line 4341 of file tls.c.
References tls_connection::plainstream, tls_ready(), and xfer_window().
|
static |
Receive new ciphertext.
| tls | TLS connection |
| iobuf | I/O buffer |
| meta | Data transfer metadat |
| rc | Return status code |
Definition at line 4358 of file tls.c.
References __unused, assert, io_buffer::data, tls_rx::data, dest, done, EINVAL_RX_STATE, free_iob(), iob_len(), iob_pull, iob_put, iob_tailroom(), tls_rx::iobuf, io_buffer::list, list_first_entry, memcpy(), NULL, rc, tls_connection::rx, tls_rx::state, tls_close_alert(), tls_newdata_process_data(), tls_newdata_process_header(), TLS_RX_DATA, and TLS_RX_HEADER.
|
static |
Handle certificate validation completion.
| tls | TLS connection |
| rc | Reason for completion |
Definition at line 4465 of file tls.c.
References tls_client::chain, tls_connection::client, DBGC, intf_restart(), x509_chain::links, list_empty, tls_tx::pending, pending_put(), rc, tls_connection::server, strerror(), tls_close_alert(), TLS_TX_CERTIFICATE, TLS_TX_CERTIFICATE_VERIFY, TLS_TX_CHANGE_CIPHER, TLS_TX_CLIENT_KEY_EXCHANGE, TLS_TX_FINISHED, tls_tx_resume(), tls_version(), TLS_VERSION_TLS_1_3, tls_connection::tx, tls_server::validation, and tls_server::validator.
|
static |
TLS TX state machine.
| tls | TLS connection |
Definition at line 4523 of file tls.c.
References tls_connection::cipherstream, tls_session::conn, DBGC, is_pending(), tls_connection::list, list_for_each_entry, tls_server::negotiation, tls_tx::pending, tls_connection::plainstream, rc, tls_connection::server, tls_connection::session, strerror(), tls_close_alert(), tls_send_certificate(), tls_send_certificate_verify(), tls_send_change_cipher(), tls_send_client_hello(), tls_send_client_key_exchange(), tls_send_finished(), TLS_TX_CERTIFICATE, TLS_TX_CERTIFICATE_VERIFY, TLS_TX_CHANGE_CIPHER, TLS_TX_CLIENT_HELLO, TLS_TX_CLIENT_KEY_EXCHANGE, TLS_TX_FINISHED, tls_tx_resume(), tls_connection::tx, xfer_window(), and xfer_window_changed().
| int add_tls | ( | struct interface * | xfer, |
| const char * | name, | ||
| struct x509_root * | root, | ||
| struct private_key * | key ) |
Add TLS on an interface.
| xfer | Data transfer interface |
| name | Host name |
| root | Root of trust (or NULL to use default) |
| key | Private key (or NULL to use default) |
| rc | Return status code |
Definition at line 4628 of file tls.c.
References tls_connection::channel, channel_close(), channel_init(), channel_open(), tls_rx::cipherspec, tls_tx::cipherspec, tls_connection::cipherstream, tls_connection::client, tls_session::conn, tls_rx::data, ENOMEM, free_tls(), tls_connection::group, tls_rx::header, INIT_LIST_HEAD, intf_init(), intf_insert(), iob_populate(), tls_rx::iobuf, key, tls_client::key, tls_connection::legacy_version, tls_connection::list, list_add_tail, malloc(), memset(), name, tls_cipherspec::pipe, tls_connection::plainstream, privkey_get(), tls_tx::process, process_init_stopped(), rc, ref_init, ref_put, tls_connection::refcnt, root, tls_server::root, root_certificates, secure_channel::rx, tls_connection::rx, tls_connection::server, tls_connection::session, tls_cipherspec::suite, tls_connection::suite, table_start, tls_channel_ops, tls_cipher_suite_null, tls_cipherstream_desc, tls_clear_digest(), TLS_LEGACY_VERSION_MAX, TLS_NAMED_GROUPS, tls_plainstream_desc, tls_process_desc, tls_restart(), tls_validator_desc, TLS_VERSION_MAX, secure_channel::tx, tls_connection::tx, tls_server::validator, tls_connection::version, tls_cipherspec::writer, and x509_root_get().
Referenced by apply_syslogs_settings(), https_filter(), ipair_rx_session(), and REQUIRING_SYMBOL().
| REQUIRE_OBJECT | ( | config_crypto | ) |
| struct pubkey_algorithm rsa_algorithm |
Definition at line 199 of file tls.c.
Referenced by __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), icert_cert(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), PUBKEY_TEST(), REQUIRING_SYMBOL(), tls_send_certificate_verify(), and tls_verify_signature().
|
static |
ServerHello downgrade magic value.
Definition at line 205 of file tls.c.
Referenced by tls_new_server_hello().
|
static |
HelloRetryRequest magic value.
Definition at line 208 of file tls.c.
Referenced by tls_new_server_hello().
| struct tls_cipher_suite tls_cipher_suite_null |
Null cipher suite.
Definition at line 618 of file tls.c.
Referenced by add_tls(), tls_change_cipher(), tls_clear_cipher(), tls_new_server_hello(), tls_restart(), and tls_select_cipher().
| struct tls_named_group tls_pubkey_named_group __tls_anon_named_group |
| struct tls_key_exchange_algorithm tls_null_exchange_algorithm |
Null key exchange algorithm.
Definition at line 1125 of file tls.c.
Referenced by __tls_cipher_suite(), __tls_cipher_suite(), and tls_cipher_name().
| struct tls_key_exchange_algorithm tls_pubkey_exchange_algorithm |
Public key exchange algorithm.
Definition at line 1138 of file tls.c.
Referenced by __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), and tls_cipher_name().
| struct tls_key_exchange_algorithm tls_dhe_exchange_algorithm |
Ephemeral Diffie-Hellman key exchange algorithm.
Definition at line 1186 of file tls.c.
Referenced by __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), and __tls_cipher_suite().
| struct tls_key_exchange_algorithm tls_ecdhe_exchange_algorithm |
Ephemeral Elliptic Curve Diffie-Hellman key exchange algorithm.
Definition at line 1241 of file tls.c.
Referenced by __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), and __tls_cipher_suite().
|
static |
Secure channel operations.
Definition at line 1681 of file tls.c.
Referenced by add_tls().
|
static |
TLS plaintext stream interface operations.
|
static |
TLS plaintext stream interface descriptor.
Definition at line 4205 of file tls.c.
Referenced by add_tls().
|
static |
TLS ciphertext stream interface operations.
Definition at line 4409 of file tls.c.
|
static |
TLS ciphertext stream interface descriptor.
Definition at line 4420 of file tls.c.
Referenced by add_tls().
|
static |
TLS certificate validator interface operations.
|
static |
TLS certificate validator interface descriptor.
Definition at line 4507 of file tls.c.
Referenced by add_tls().
|
static |
TLS TX process descriptor.
Definition at line 4609 of file tls.c.
Referenced by add_tls().