53#define EINVAL_CHANGE_CIPHER __einfo_error ( EINFO_EINVAL_CHANGE_CIPHER )
54#define EINFO_EINVAL_CHANGE_CIPHER \
55 __einfo_uniqify ( EINFO_EINVAL, 0x01, \
56 "Invalid Change Cipher record" )
57#define EINVAL_ALERT __einfo_error ( EINFO_EINVAL_ALERT )
58#define EINFO_EINVAL_ALERT \
59 __einfo_uniqify ( EINFO_EINVAL, 0x02, \
60 "Invalid Alert record" )
61#define EINVAL_IV __einfo_error ( EINFO_EINVAL_IV )
62#define EINFO_EINVAL_IV \
63 __einfo_uniqify ( EINFO_EINVAL, 0x0a, \
64 "Invalid initialisation vector" )
65#define EINVAL_PADDING __einfo_error ( EINFO_EINVAL_PADDING )
66#define EINFO_EINVAL_PADDING \
67 __einfo_uniqify ( EINFO_EINVAL, 0x0b, \
68 "Invalid block padding" )
69#define EINVAL_RX_STATE __einfo_error ( EINFO_EINVAL_RX_STATE )
70#define EINFO_EINVAL_RX_STATE \
71 __einfo_uniqify ( EINFO_EINVAL, 0x0c, \
72 "Invalid receive state" )
73#define EINVAL_MAC __einfo_error ( EINFO_EINVAL_MAC )
74#define EINFO_EINVAL_MAC \
75 __einfo_uniqify ( EINFO_EINVAL, 0x0d, \
76 "Invalid MAC or authentication tag" )
77#define EINVAL_KEY_EXCHANGE __einfo_error ( EINFO_EINVAL_KEY_EXCHANGE )
78#define EINFO_EINVAL_KEY_EXCHANGE \
79 __einfo_uniqify ( EINFO_EINVAL, 0x0f, \
80 "Invalid exchanged key" )
81#define EINVAL_INNER __einfo_error ( EINFO_EINVAL_INNER )
82#define EINFO_EINVAL_INNER \
83 __einfo_uniqify ( EINFO_EINVAL, 0x10, \
84 "Invalid inner plaintext" )
85#define EINVAL_BLOCK __einfo_error ( EINFO_EINVAL_BLOCK )
86#define EINFO_EINVAL_BLOCK \
87 __einfo_uniqify ( EINFO_EINVAL, 0x11, \
88 "Invalid block cipher size" )
89#define EIO_ALERT __einfo_error ( EINFO_EIO_ALERT )
90#define EINFO_EIO_ALERT \
91 __einfo_uniqify ( EINFO_EIO, 0x01, \
92 "Unknown alert level" )
93#define ENOENT_CERT __einfo_error ( EINFO_ENOENT_CERT )
94#define EINFO_ENOENT_CERT \
95 __einfo_uniqify ( EINFO_ENOENT, 0x01, \
96 "Missing certificate" )
97#define ENOENT_KEY_EXCHANGE __einfo_error ( EINFO_ENOENT_KEY_EXCHANGE )
98#define EINFO_ENOENT_KEY_EXCHANGE \
99 __einfo_uniqify ( EINFO_ENOENT, 0x02, \
100 "No key exchange algorithm selected" )
101#define ENOMEM_CONTEXT __einfo_error ( EINFO_ENOMEM_CONTEXT )
102#define EINFO_ENOMEM_CONTEXT \
103 __einfo_uniqify ( EINFO_ENOMEM, 0x01, \
104 "Not enough space for crypto context" )
105#define ENOMEM_CERTIFICATE __einfo_error ( EINFO_ENOMEM_CERTIFICATE )
106#define EINFO_ENOMEM_CERTIFICATE \
107 __einfo_uniqify ( EINFO_ENOMEM, 0x02, \
108 "Not enough space for certificate" )
109#define ENOMEM_CHAIN __einfo_error ( EINFO_ENOMEM_CHAIN )
110#define EINFO_ENOMEM_CHAIN \
111 __einfo_uniqify ( EINFO_ENOMEM, 0x03, \
112 "Not enough space for certificate chain" )
113#define ENOMEM_TX_PLAINTEXT __einfo_error ( EINFO_ENOMEM_TX_PLAINTEXT )
114#define EINFO_ENOMEM_TX_PLAINTEXT \
115 __einfo_uniqify ( EINFO_ENOMEM, 0x04, \
116 "Not enough space for transmitted plaintext" )
117#define ENOMEM_TX_CIPHERTEXT __einfo_error ( EINFO_ENOMEM_TX_CIPHERTEXT )
118#define EINFO_ENOMEM_TX_CIPHERTEXT \
119 __einfo_uniqify ( EINFO_ENOMEM, 0x05, \
120 "Not enough space for transmitted ciphertext" )
121#define ENOMEM_RX_DATA __einfo_error ( EINFO_ENOMEM_RX_DATA )
122#define EINFO_ENOMEM_RX_DATA \
123 __einfo_uniqify ( EINFO_ENOMEM, 0x07, \
124 "Not enough space for received data" )
125#define ENOMEM_RX_CONCAT __einfo_error ( EINFO_ENOMEM_RX_CONCAT )
126#define EINFO_ENOMEM_RX_CONCAT \
127 __einfo_uniqify ( EINFO_ENOMEM, 0x08, \
128 "Not enough space to concatenate received data" )
129#define ENOTSUP_CIPHER __einfo_error ( EINFO_ENOTSUP_CIPHER )
130#define EINFO_ENOTSUP_CIPHER \
131 __einfo_uniqify ( EINFO_ENOTSUP, 0x01, \
132 "Unsupported cipher" )
133#define ENOTSUP_NULL __einfo_error ( EINFO_ENOTSUP_NULL )
134#define EINFO_ENOTSUP_NULL \
135 __einfo_uniqify ( EINFO_ENOTSUP, 0x02, \
136 "Refusing to use null cipher" )
137#define ENOTSUP_SIG_HASH __einfo_error ( EINFO_ENOTSUP_SIG_HASH )
138#define EINFO_ENOTSUP_SIG_HASH \
139 __einfo_uniqify ( EINFO_ENOTSUP, 0x03, \
140 "Unsupported signature and hash algorithm" )
141#define ENOTSUP_VERSION __einfo_error ( EINFO_ENOTSUP_VERSION )
142#define EINFO_ENOTSUP_VERSION \
143 __einfo_uniqify ( EINFO_ENOTSUP, 0x04, \
144 "Unsupported protocol version" )
145#define ENOTSUP_GROUP __einfo_error ( EINFO_ENOTSUP_GROUP )
146#define EINFO_ENOTSUP_GROUP \
147 __einfo_uniqify ( EINFO_ENOTSUP, 0x05, \
148 "Unsupported key exchange group" )
149#define EPERM_ALERT __einfo_error ( EINFO_EPERM_ALERT )
150#define EINFO_EPERM_ALERT \
151 __einfo_uniqify ( EINFO_EPERM, 0x01, \
152 "Received fatal alert" )
153#define EPERM_VERIFY __einfo_error ( EINFO_EPERM_VERIFY )
154#define EINFO_EPERM_VERIFY \
155 __einfo_uniqify ( EINFO_EPERM, 0x02, \
156 "Handshake verification failed" )
157#define EPERM_RENEG_INSECURE __einfo_error ( EINFO_EPERM_RENEG_INSECURE )
158#define EINFO_EPERM_RENEG_INSECURE \
159 __einfo_uniqify ( EINFO_EPERM, 0x04, \
160 "Secure renegotiation not supported" )
161#define EPERM_RENEG_VERIFY __einfo_error ( EINFO_EPERM_RENEG_VERIFY )
162#define EINFO_EPERM_RENEG_VERIFY \
163 __einfo_uniqify ( EINFO_EPERM, 0x05, \
164 "Secure renegotiation verification failed" )
165#define EPERM_KEY_EXCHANGE __einfo_error ( EINFO_EPERM_KEY_EXCHANGE )
166#define EINFO_EPERM_KEY_EXCHANGE \
167 __einfo_uniqify ( EINFO_EPERM, 0x06, \
168 "Unusable server public key" )
169#define EPERM_SAVE __einfo_error ( EINFO_EPERM_SAVE )
170#define EINFO_EPERM_SAVE \
171 __einfo_uniqify ( EINFO_EPERM, 0x07, \
172 "Pre-shared key was not established" )
173#define EPERM_DOWNGRADE __einfo_error ( EINFO_EPERM_DOWNGRADE )
174#define EINFO_EPERM_DOWNGRADE \
175 __einfo_uniqify ( EINFO_EPERM, 0x08, \
176 "Downgrade attack detected" )
177#define EPERM_SESSION_ID __einfo_error ( EINFO_EPERM_SESSION_ID )
178#define EINFO_EPERM_SESSION_ID \
179 __einfo_uniqify ( EINFO_EPERM, 0x09, \
180 "Session ID echo mismatch" )
181#define EPROTO_VERSION __einfo_error ( EINFO_EPROTO_VERSION )
182#define EINFO_EPROTO_VERSION \
183 __einfo_uniqify ( EINFO_EPROTO, 0x01, \
184 "Illegal protocol version upgrade" )
185#define EPROTO_CIPHER_CHANGE __einfo_error ( EINFO_EPROTO_CIPHER_CHANGE )
186#define EINFO_EPROTO_CIPHER_CHANGE \
187 __einfo_uniqify ( EINFO_EPROTO, 0x02, \
188 "Illegal cipher change" )
189#define EPROTO_VALIDATION __einfo_error ( EINFO_EPROTO_VALIDATION )
190#define EINFO_EPROTO_VALIDATION \
191 __einfo_uniqify ( EINFO_EPROTO, 0x04, \
192 "Certificate validation already in progress" )
193#define EPROTO_RETRY __einfo_error ( EINFO_EPROTO_RETRY )
194#define EINFO_EPROTO_RETRY \
195 __einfo_uniqify ( EINFO_EPROTO, 0x05, \
196 "Illegal retry request" )
210 0xcf, 0x21, 0xad, 0x74, 0xe5, 0x9a, 0x61, 0x11,
211 0xbe, 0x1d, 0x8c, 0x02, 0x1e, 0x65, 0xb8, 0x91,
212 0xc2, 0xa2, 0x11, 0x16, 0x7a, 0xbb, 0x8c, 0x5e,
213 0x07, 0x9e, 0x09, 0xe2, 0xc8, 0xa8, 0x33, 0x9c
221 unsigned int description );
225 const void *
data,
size_t len );
244#define TLS_NUM_VERSIONS ( TLS_VERSION_MAX - TLS_VERSION_MIN + 1 )
247#define TLS_LEGACY_VERSION_MAX \
248 ( ( TLS_VERSION_MAX <= TLS_VERSION_TLS_1_2 ) ? \
249 TLS_VERSION_MAX : TLS_VERSION_TLS_1_2 )
263 *(dst_bytes++) ^= *(src_bytes++);
513 static const char label[] =
"tls connection nonce";
533 .label =
"tls random nonce",
588 DBGC ( tls,
"TLS %p could not initialise key schedule: %s\n",
604 const void *
data,
size_t len ) {
627#define TLS_NUM_CIPHER_SUITES table_num_entries ( TLS_CIPHER_SUITES )
636 static char buf[ 7 ];
660 const char *exchange_name;
661 const char *pubkey_name;
662 const char *digest_name;
674 snprintf ( buf,
sizeof ( buf ),
"%s%s%s%s%s-%d-%s",
675 ( exchange_name ? exchange_name :
"" ),
676 ( exchange_name ?
"-" :
"" ),
677 ( pubkey_name ? pubkey_name :
"" ),
678 ( pubkey_name ?
"-" :
"" ),
679 cipher->
name, ( suite->
key_len * 8 ), digest_name );
696 if ( suite->
code == cipher_suite )
718 memset ( verify, 0,
sizeof ( *verify ) );
721 total = ( verify_len * 2 );
725 verify->
len = verify_len;
746 unsigned int cipher_suite ) {
753 DBGC ( tls,
"TLS %p does not support protocol version %s\n",
758 DBGC ( tls,
"TLS %p refusing illegal upgrade to protocol "
766 DBGC ( tls,
"TLS %p does not support cipher suite %#04x\n",
767 tls,
ntohs ( cipher_suite ) );
774 DBGC ( tls,
"TLS %p cannot use broken cipher suite %#04x\n",
775 tls,
ntohs ( cipher_suite ) );
787 DBGC ( tls,
"TLS %p refusing to change to %s %s\n",
798 DBGC ( tls,
"TLS %p using protocol version %s\n",
826 DBGC ( tls,
"TLS %p selected cipher suite %s\n",
875 DBGC ( tls,
"TLS %p could not generate %s %s traffic secret: "
907 DBGC ( tls,
"TLS %p refusing to use null %s cipher\n",
915 dynamic =
zalloc ( total );
917 DBGC ( tls,
"TLS %p could not allocate %zd bytes for crypto "
918 "context\n", tls, total );
931 cipherspec->
suite = suite;
945 DBGC ( tls,
"TLS %p could not generate %s %s keys: %s\n",
955 DBGC ( tls,
"TLS %p could not set %s cipher: %s\n",
960 DBGC ( tls,
"TLS %p activated %s cipher %s\n",
1008#define TLS_NUM_SIG_HASH_ALGORITHMS \
1009 table_num_entries ( TLS_SIG_HASH_ALGORITHMS )
1072 if (
group->code && (
group->code == named_group ) )
1114 DBGC ( tls,
"TLS %p received unexpected ServerKeyExchange:\n", tls );
1127 .group = &tls_null_named_group,
1129 .map = tls_client_key_exchange_pubkey_map,
1140 .group = &tls_pubkey_named_group,
1142 .map = tls_client_key_exchange_pubkey_map,
1162 cursor, &dhe ) ) != 0 ) {
1163 DBGC ( tls,
"TLS %p could not parse ServerKeyExchange: %s\n",
1171 DBGC ( tls,
"TLS %p unsupported %zd-bit group:\n",
1188 .group = &tls_null_named_group,
1190 .map = tls_client_key_exchange_dhe_map,
1211 cursor, &ecdhe ) ) != 0 ) {
1212 DBGC ( tls,
"TLS %p could not parse ServerKeyExchange: %s\n",
1219 DBGC ( tls,
"TLS %p unsupported curve type %d\n",
1226 DBGC ( tls,
"TLS %p unsupported named group %d\n",
1243 .group = &tls_null_named_group,
1245 .map = tls_client_key_exchange_ecdhe_map,
1295 if (
pubsize != public->len ) {
1296 DBGC ( tls,
"TLS %p wrong public %s key size (%zd bytes)\n",
1297 tls, exchange->
name, public->len );
1303 public->data ) ) != 0 ) {
1304 DBGC ( tls,
"TLS %p could not share public %s key: %s\n",
1340 DBGC ( tls,
"TLS %p overlength partner %s key:\n",
1341 tls, exchange->
name );
1350 if ( pad_len && ( ! strip ) ) {
1351 DBGC ( tls,
"TLS %p underlength partner %s key:\n",
1352 tls, exchange->
name );
1361 DBGC ( tls,
"TLS %p could not agree shared %s key: %s\n",
1393 DBGC ( tls,
"TLS %p has no server certificate chain\n", tls );
1398 DBGC ( tls,
"TLS %p has no server certificate\n", tls );
1405 builder ) ) != 0 ) {
1406 DBGC ( tls,
"TLS %p could not encrypt %s key: %s\n",
1436 DBGC ( tls,
"TLS %p cannot use %s public key\n",
1440 DBGC ( tls,
"TLS %p signing with %s-%s\n",
1445 NULL, 0, tbshash ) ) != 0 ) {
1446 DBGC ( tls,
"TLS %p could not generate signable digest: %s\n",
1454 DBGC ( tls,
"TLS %p could not sign: %s\n",
1485 DBGC ( tls,
"TLS %p cannot use %s public key\n",
1489 DBGC ( tls,
"TLS %p verifying with %s-%s\n",
1495 tbshash ) ) != 0 ) {
1496 DBGC ( tls,
"TLS %p could not generate signable digest: %s\n",
1503 digest, tbshash,
sig ) ) != 0 ) {
1504 DBGC ( tls,
"TLS %p failed signature verification: %s\n",
1543 const void *shared,
int *accumulated ) {
1557 while ( shared_len && ( ! *( (
const uint8_t * ) shared ) ) ) {
1561 assert ( shared_len > 0 );
1563 DBGC ( tls,
"TLS %p shared (pre-master) secret:\n", tls );
1564 DBGC_HDA ( tls, 0, shared, shared_len );
1568 DBGC ( tls,
"TLS %p could not apply shared secret: %s\n",
1600 DBGC ( tls,
"TLS %p cannot save pre-shared key before "
1601 "channel is established\n", tls );
1607 &session->
psk ) ) != 0 ) {
1608 DBGC ( tls,
"TLS %p could not save key material: %s\n",
1633 &session->
psk ) ) != 0 ) {
1634 DBGC ( tls,
"TLS %p could not load key material: %s\n",
1651 const void *auth,
size_t len ) {
1658 DBGC ( tls,
"TLS %p invalid authenticator value:\n", tls );
1666 DBGC ( tls,
"TLS %p could not generate server verification: "
1673 DBGC ( tls,
"TLS %p incorrect authenticator value:\n", tls );
1732 DBGC ( tls,
"TLS %p joining %s session %s:\n", tls,
1734 "stateful" ),
name );
1748 name_copy = ( ( (
void * ) session ) +
sizeof ( *session ) );
1750 session->
name = name_copy;
1759 DBGC ( tls,
"TLS %p created session %s:\n", tls,
name );
1791 DBGC ( tls,
"TLS %p could not save: %s\n",
1799 DBGC ( tls,
"TLS %p %s session %s:\n",
1800 tls, ( tls->
new_id.
len ?
"saved stateful" :
"reset" ),
name );
1809 DBGC ( tls,
"TLS %p saved stateless session %s:\n",
1828 DBGC ( tls,
"TLS %p resuming %s session %s\n",
1829 tls, ( session->
ticket.
len ?
"stateless" :
"stateful" ),
1834 DBGC ( tls,
"TLS %p could not resume: %s\n",
1909 DBGC ( tls,
"TLS %p could not establish channel: %s\n",
1941 unsigned int type ) {
1951 handshake =
iob_put ( iobuf,
sizeof ( *handshake ) );
2046 memset ( &s, 0,
sizeof ( s ) );
2050 name->name.data = ( (
void * ) session->
name );
2067 ext->groups.len = 0;
2070 ext->ems.data = empty;
2073 ext->frag.len =
sizeof ( *frag );
2090 ext->ticket.data = empty;
2096 if ( !
key->public.len )
2104 hello->compression.len =
sizeof ( *compression );
2106 &cursor ) ) != 0 ) {
2107 DBGC ( tls,
"TLS %p could not size ClientHello: %s\n",
2144 if (
ext->groups.len ) {
2156 frag =
ext->frag.data;
2167 &
key->public ) ) != 0 ) {
2173 if ( (
rc = action ( tls,
iob_disown ( iobuf ) ) ) != 0 )
2217 memset ( &s, 0,
sizeof ( s ) );
2222 DBGC ( tls,
"TLS %p has no client certificate chain\n", tls );
2230 DBGC ( tls,
"TLS %p sending client certificate %s\n",
2234 entry, &cursor ) ) != 0 ) {
2235 DBGC ( tls,
"TLS %p could not size CertificateEntry: "
2242 &cursor ) ) != 0 ) {
2243 DBGC ( tls,
"TLS %p could not size Certificate: %s\n",
2310 &cursor ) ) != 0 ) {
2311 DBGC ( tls,
"TLS %p could not size ClientKeyExchange: %s\n",
2337 DBGC ( tls,
"TLS %p could not generate master secret: %s\n",
2373 DBGC ( tls,
"TLS %p has no client certificate chain\n", tls );
2379 DBGC ( tls,
"TLS %p has no client certificate\n", tls );
2392 DBGC ( tls,
"TLS %p could not identify (%s,%s) "
2393 "signature and hash algorithm\n", tls,
2403 memset ( sig_hash, 0,
sizeof ( *sig_hash ) );
2404 sig_hash->
pubkey = pubkey;
2418 &dsig, &cursor ) ) != 0 ) {
2419 DBGC ( tls,
"TLS %p could not size DigitallySigned: %s\n",
2457 static const struct {
2467 sizeof ( change_cipher ) ) ) != 0 ) {
2494 cursor.
len = verify_len;
2503 verify_len ) ) != 0 ) {
2504 DBGC ( tls,
"TLS %p could not generate client verification: "
2560 unsigned int description ) {
2566 .description = description,
2589 if ( (
sizeof ( *change_cipher ) !=
len ) ||
2591 DBGC ( tls,
"TLS %p received invalid Change Cipher\n", tls );
2595 iob_pull ( iobuf,
sizeof ( *change_cipher ) );
2622 DBGC ( tls,
"TLS %p received overlength Alert\n", tls );
2629 switch (
alert->level ) {
2631 switch (
alert->description ) {
2633 DBGC ( tls,
"TLS %p closed by notification\n", tls );
2637 DBGC ( tls,
"TLS %p received warning alert %d\n",
2638 tls,
alert->description );
2643 DBGC ( tls,
"TLS %p received fatal alert %d\n",
2644 tls,
alert->description );
2647 DBGC ( tls,
"TLS %p received unknown alert level %d"
2648 "(alert %d)\n", tls,
alert->level,
alert->description );
2668 DBGC ( tls,
"TLS %p could not parse HelloRequest: %s\n",
2675 DBGC ( tls,
"TLS %p ignoring Hello Request\n", tls );
2681 DBGC ( tls,
"TLS %p refusing to renegotiate insecurely\n",
2718 DBGC ( tls,
"TLS %p could not parse ServerHello: %s\n",
2727 &
hello.ext.reneg, &reneg ) ) != 0 ) {
2728 DBGC ( tls,
"TLS %p could not parse RenegotiationInfo: %s\n",
2735 &
hello.ext.supver, &supver ) ) != 0 ) {
2736 DBGC ( tls,
"TLS %p could not parse SupportedVersion: %s\n",
2743 sizeof ( *
random ) ) == 0 );
2744 key_map = ( retry ? tls_key_share_hello_retry_request_map :
2745 tls_key_share_server_hello_map );
2747 &
hello.ext.key,
key.desc ) ) != 0 ) {
2748 DBGC ( tls,
"TLS %p could not parse KeyShare%s: %s\n",
2749 tls, ( retry ?
"HelloRetryRequest" :
"ServerHello" ),
2756 DBGC ( tls,
"TLS %p refusing repeated retry request\n", tls );
2768 verify_len ) != 0 ) ) {
2769 DBGC ( tls,
"TLS %p server failed secure "
2770 "renegotiation\n", tls );
2778 DBGC ( tls,
"TLS %p server provided non-empty initial "
2779 "renegotiation\n", tls );
2788 suite =
hello.b->suite;
2796 sizeof (
random->downgrade.magic ) ) == 0 ) &&
2799 DBGC ( tls,
"TLS %p detected downgrade attack:\n", tls );
2801 sizeof (
random->downgrade ) );
2809 if (
hello.session_id.len &&
2810 (
hello.session_id.len == session->
id.
len ) &&
2812 hello.session_id.len ) == 0 ) ) {
2824 DBGC ( tls,
"TLS %p session ID mismatch\n", tls );
2826 hello.session_id.len );
2831 if (
hello.session_id.len &&
2835 hello.session_id.len );
2843 DBGC ( tls,
"TLS %p unsupported named group %d\n",
2851 if ( ( ! retry ) &&
key.hello.public.data &&
2853 &
key.hello.public ) ) != 0 ) ) {
2866 DBGC ( tls,
"TLS %p retrying hello\n", tls );
2892 cursor, &
ticket ) ) != 0 ) {
2893 DBGC ( tls,
"TLS %p could not parse NewSessionTicket: %s\n",
2900 DBGC ( tls,
"TLS %p ignoring unsupported New Session Ticket\n",
2933 goto err_alloc_chain;
2938 &certificate ) ) != 0 ) {
2939 DBGC ( tls,
"TLS %p could not parse Certificate: %s\n",
2941 goto err_certificate;
2945 for ( cursor = &certificate.
list ; cursor->
len ;
2946 cursor = &entry.
next ) {
2950 cursor, &entry ) ) != 0 ) {
2951 DBGC ( tls,
"TLS %p could not parse CertificateEntry: "
2960 DBGC ( tls,
"TLS %p could not append certificate: "
2996 cursor, &dsig ) ) != 0 ) {
2997 DBGC ( tls,
"TLS %p could not parse DigitallySigned: %s\n",
3004 DBGC ( tls,
"TLS %p has no server certificate chain\n", tls );
3009 DBGC ( tls,
"TLS %p has no server certificate\n", tls );
3020 DBGC ( tls,
"TLS %p unsupported signature hash "
3030 memset ( sig_hash, 0,
sizeof ( *sig_hash ) );
3082 DBGC ( tls,
"TLS %p using named group %s-%s\n",
3138 DBGC ( tls,
"TLS %p selected client certificate %s\n",
3148 goto err_auto_append;
3152 DBGC ( tls,
"TLS %p could not find certificate corresponding "
3153 "to private key\n", tls );
3181 DBGC ( tls,
"TLS %p could not parse ServerHelloDone: %s\n",
3206 cursor->
len ) ) != 0 ) {
3207 DBGC ( tls,
"TLS %p could not confirm peer identity: %s\n",
3220 DBGC ( tls,
"TLS %p could not generate master secret: "
3292 while ( ( remaining =
iob_len ( iobuf ) ) ) {
3296 DBGC ( tls,
"TLS %p cipher change mid-record\n", tls );
3301 if ( remaining <
sizeof ( *handshake ) ) {
3305 handshake = iobuf->
data;
3306 cursor.
data = ( iobuf->
data +
sizeof ( *handshake ) );
3308 len = ( cursor.
len +
sizeof ( *handshake ) );
3309 if ( remaining <
len ) {
3315 switch ( handshake->
type ) {
3344 DBGC ( tls,
"TLS %p ignoring handshake type %d\n",
3345 tls, handshake->
type );
3351 if ( handler && ( (
rc = handler ( tls, &cursor ) ) != 0 ) )
3404 DBGC ( tls,
"TLS %p could not deliver data: "
3447 DBGC ( tls,
"TLS %p unknown record type %d\n", tls,
type );
3454 list_add ( &(*iobuf)->list, rx_data );
3457 DBGC ( tls,
"TLS %p could not concatenate non-data record "
3458 "type %d\n", tls,
type );
3460 goto err_concatenate;
3464 if ( (
rc = handler ( tls, *iobuf ) ) != 0 )
3517 const void *
data,
size_t len ) {
3548 const void *
data,
size_t len,
void *hmac ) {
3603 sizeof ( *inner_type ) + suite->
mac_len +
3608 return (
count * each );
3659 const void *plaintext;
3660 const void *encrypt;
3673 plaintext = iobuf->
data;
3708 memset (
iv.record, 0, sizeof (
iv.record ) );
3709 assert (
sizeof (
iv ) >=
sizeof ( authhdr.
seq ) );
3711 -
sizeof ( authhdr.
seq ) ),
3712 &authhdr.
seq, sizeof ( authhdr.
seq ) );
3717 sizeof (
iv ) ) ) != 0 ) {
3718 DBGC ( tls,
"TLS %p could not set TX IV: %s\n",
3724 encrypt_len = record_len;
3726 encrypt_len +=
sizeof ( inner_type );
3727 encrypt_len += suite->
mac_len;
3729 pad_len = ( ( ( cipher->
blocksize - 1 ) &
3730 -( encrypt_len + 1 ) ) + 1 );
3734 encrypt_len += pad_len;
3737 tlshdr =
iob_put ( iobuf,
sizeof ( *tlshdr ) );
3740 tlshdr->
length =
htons (
sizeof (
iv.record ) + encrypt_len +
3745 tls_hmac ( cipherspec, &authhdr, plaintext,
3753 sizeof ( authhdr.
header ) );
3756 NULL, sizeof ( authhdr ) );
3762 sizeof (
iv.record ) );
3765 ciphertext =
iob_put ( iobuf, record_len );
3766 assert ( ciphertext <= plaintext );
3767 if ( encrypt_len > record_len ) {
3768 memmove ( ciphertext, plaintext, record_len );
3769 encrypt = ciphertext;
3771 encrypt = plaintext;
3777 &inner_type,
sizeof ( inner_type ) );
3789 DBGC2 ( tls,
"Sending plaintext data:\n" );
3790 DBGC2_HDA ( tls, 0, encrypt, encrypt_len );
3797 plaintext += record_len;
3805 DBGC ( tls,
"TLS %p could not deliver ciphertext: %s\n",
3829 const void *
data,
size_t len ) {
3862 padding = ( iobuf->
tail - 1 );
3866 DBGC ( tls,
"TLS %p received underlength padding\n", tls );
3870 for ( i = 0 ; i <
pad ; i++ ) {
3871 if ( *(--padding) !=
pad ) {
3872 DBGC ( tls,
"TLS %p received bad padding\n", tls );
3897 DBGC ( tls,
"TLS %p invalid outer type %d\n", tls,
type );
3915 DBGC ( tls,
"TLS %p missing inner type\n", tls );
3989 DBGC ( tls,
"TLS %p received underlength IV\n", tls );
3995 memset (
iv.record, 0, sizeof (
iv.record ) );
3996 assert (
sizeof (
iv ) >=
sizeof ( authhdr.
seq ) );
3998 sizeof ( authhdr.
seq ) ), &authhdr.
seq,
3999 sizeof ( authhdr.
seq ) );
4003 len -=
sizeof (
iv.record );
4007 DBGC ( tls,
"TLS %p received underlength authentication tag\n",
4019 DBGC ( tls,
"TLS %p invalid received length %zd\n",
4026 sizeof (
iv ) ) ) != 0 ) {
4027 DBGC ( tls,
"TLS %p could not set RX IV: %s\n",
4040 NULL, sizeof ( authhdr ) );
4049 check_len +=
iob_len ( iobuf );
4056 if ( pad_len < 0 ) {
4066 DBGC ( tls,
"TLS %p received underlength MAC\n", tls );
4075 DBGC2 ( tls,
"Received plaintext data:\n" );
4079 check_len +=
iob_len ( iobuf );
4086 tls_hmac_list ( cipherspec, &authhdr, rx_data, verify_mac );
4093 DBGC ( tls,
"TLS %p failed MAC verification\n", tls );
4099 DBGC ( tls,
"TLS %p failed authentication tag verification\n",
4239 reserve = ( ( -iv_len ) & ( cipher->
alignsize - 1 ) );
4240 remaining += reserve;
4250 frag_len = remaining;
4253 remaining -= frag_len;
4255 frag_len += remaining;
4262 DBGC ( tls,
"TLS %p could not allocate %zd of %zd "
4263 "bytes for receive buffer\n", tls,
4286 }
while ( remaining );
4442 DBGC ( tls,
"TLS %p refusing to restart validation\n", tls );
4450 DBGC ( tls,
"TLS %p could not start certificate validation: "
4475 DBGC ( tls,
"TLS %p certificate validation failed: %s\n",
4479 DBGC ( tls,
"TLS %p certificate validation succeeded\n", tls );
4546 DBGC ( tls,
"TLS %p could not send Client Hello: %s\n",
4554 DBGC ( tls,
"TLS %p could not send Certificate: %s\n",
4562 DBGC ( tls,
"TLS %p could not send Client Key "
4570 DBGC ( tls,
"TLS %p could not send Certificate "
4578 DBGC ( tls,
"TLS %p could not send Change Cipher: "
4586 DBGC ( tls,
"TLS %p could not send Finished: %s\n",
4634 tls =
malloc (
sizeof ( *tls ) );
4639 memset ( tls, 0,
sizeof ( *tls ) );
#define NULL
NULL pointer (VOID *).
struct golan_eq_context ctx
union @162305117151260234136356364136041353210355154177 key
typeof(acpi_finder=acpi_find)
ACPI table finder.
u32 link
Link to next descriptor.
struct arbelprm_rc_send_wqe rc
unsigned long long uint64_t
if(len >=6 *4) __asm__ __volatile__("movsl" if(len >=5 *4) __asm__ __volatile__("movsl" if(len >=4 *4) __asm__ __volatile__("movsl" if(len >=3 *4) __asm__ __volatile__("movsl" if(len >=2 *4) __asm__ __volatile__("movsl" if(len >=1 *4) __asm__ __volatile__("movsl" if((len % 4) >=2) __asm__ __volatile__("movsw" if((len % 2) >=1) __asm__ __volatile__("movsb" retur dest)
#define assert(condition)
Assert a condition at run-time.
u32 version
Driver version.
struct bofm_section_header done
struct x509_chain certstore
Certificate store.
int channel_set_cipher(struct secure_channel *channel, struct secure_pipe *pipe, struct cipher_algorithm *cipher, const void *key, size_t len)
Set cipher algorithm and key.
void channel_reopen(struct secure_channel *channel)
Reopen secure channel.
int channel_bind_encrypt(struct secure_channel *channel, struct x509_certificate *identity, struct exchange_algorithm *exchange, struct pubkey_algorithm *pubkey, struct asn1_builder *ciphertext)
Bind peer identity via shared secret encryption.
void channel_ephemeral(struct secure_channel *channel, const void *info, size_t info_len, void *out, size_t len)
Generate ephemeral secret.
void channel_unkey(struct secure_channel *channel)
Clear shared secret.
int channel_key_agree(struct secure_channel *channel, struct exchange_algorithm *exchange, const void *partner)
Agree shared secret.
int channel_open(struct secure_channel *channel)
Open secure channel.
void channel_close(struct secure_channel *channel)
Close secure channel.
void channel_clear_cipher(struct secure_pipe *pipe)
Clear cipher algorithm.
int channel_bind_verify(struct secure_channel *channel, struct x509_certificate *identity, struct pubkey_algorithm *pubkey, struct digest_algorithm *digest, const void *value, const struct asn1_cursor *signature)
Bind peer identity via ephemeral public key signature verification.
int channel_establish(struct secure_channel *channel, const char *name, struct x509_root *root)
Establish channel as trusted for application data.
int channel_save(struct secure_channel *channel, struct secure_preshared_identity *psid)
Save a pre-shared key.
int channel_confirm(struct secure_channel *channel, const void *auth, size_t len)
Confirm peer identity.
int channel_key_share(struct secure_channel *channel, struct exchange_algorithm *exchange, void *public)
Share public key.
void channel_ephemeral_label(struct secure_channel *channel, const char *label, void *out, size_t len)
Generate labelled ephemeral secret.
int channel_load(struct secure_channel *channel, struct secure_preshared_identity *psid)
Load a pre-shared key.
static void channel_init(struct secure_channel *channel, struct secure_channel_operations *op)
Initialise secure channel.
static void channel_clear_preshared(struct secure_preshared_identity *psid)
Clear pre-shared bound peer identity.
static int channel_is_established(struct secure_channel *channel)
Check if secure channel has been established.
Cryptographic configuration.
#define TLS_VERSION_MAX
Maximum TLS version.
#define TLS_VERSION_MIN
Minimum TLS version.
struct cipher_algorithm cipher_null
struct exchange_algorithm exchange_null
struct pubkey_algorithm pubkey_null
struct digest_algorithm digest_null
uint32_t next
Next descriptor address.
struct eltorito_descriptor_fixed fixed
Fixed portion.
uint16_t ext
Extended status.
uint32_t type
Operating system type.
uint8_t data[48]
Additional event data.
uint16_t spec
ENA specification version.
uint8_t meta
Metadata flags.
uint16_t group
Type of event.
uint8_t mac[ETH_ALEN]
MAC address.
struct eth_slow_lacp_entity_tlv partner
Partner information.
int ffdhe_has_params(struct exchange_algorithm *exchange, const void *dh_p, size_t dh_p_len, const void *dh_g, size_t dh_g_len)
Check group parameters.
Finite Field Diffie-Hellman Ephemeral key exchange.
static int is_ffdhe(struct exchange_algorithm *exchange)
Check if key exchange algorithm is a finite field DHE group.
#define __unused
Declare a variable or data structure as unused.
static unsigned int count
Number of entries.
#define FILE_LICENCE(_licence)
Declare a particular licence as applying to a file.
#define REQUIRE_OBJECT(object)
Require an object.
#define ENOMEM
Not enough space.
#define ENOTCONN
The socket is not connected.
#define FILE_SECBOOT(_status)
Declare a file's UEFI Secure Boot permission status.
#define REQUIRING_SYMBOL(symbol)
Specify the file's requiring symbol.
void hmac_init(struct digest_algorithm *digest, void *ctx, const void *secret, size_t len)
Initialise HMAC.
void hmac_final(struct digest_algorithm *digest, void *ctx, void *hmac)
Finalise HMAC.
Keyed-Hashing for Message Authentication.
static void hmac_update(struct digest_algorithm *digest, void *ctx, const void *data, size_t len)
Update HMAC.
static size_t hmac_ctxsize(struct digest_algorithm *digest)
Calculate HMAC context size.
u8 request[0]
List of IEs requested.
#define cpu_to_be64(value)
static int is_block_cipher(struct cipher_algorithm *cipher)
static int cipher_setiv(struct cipher_algorithm *cipher, void *ctx, const void *iv, size_t ivlen)
static int is_key_transport(struct exchange_algorithm *exchange)
#define cipher_decrypt(cipher, ctx, src, dst, len)
static int is_auth_cipher(struct cipher_algorithm *cipher)
static int pubkey_sign(struct pubkey_algorithm *pubkey, const struct asn1_cursor *key, struct digest_algorithm *digest, const void *value, struct asn1_builder *signature)
#define cipher_encrypt(cipher, ctx, src, dst, len)
static void cipher_auth(struct cipher_algorithm *cipher, void *ctx, void *auth)
uint32_t pending
Pending events.
void * memcpy(void *dest, const void *src, size_t len) __nonnull
void * memset(void *dest, int character, size_t len) __nonnull
void * memmove(void *dest, const void *src, size_t len) __nonnull
void intf_close(struct interface *intf, int rc)
Close an object interface.
void intf_shutdown(struct interface *intf, int rc)
Shut down an object interface.
void intf_insert(struct interface *intf, struct interface *upper, struct interface *lower)
Insert a filter interface.
void intf_restart(struct interface *intf, int rc)
Shut down and restart an object interface.
#define INTF_DESC(object_type, intf, operations)
Define an object interface descriptor.
#define INTF_DESC_PASSTHRU(object_type, intf, operations, passthru)
Define an object interface descriptor with pass-through interface.
static void intf_init(struct interface *intf, struct interface_descriptor *desc, struct refcnt *refcnt)
Initialise an object interface.
#define INTF_OP(op_type, object_type, op_func)
Define an object interface operation.
void free_iob(struct io_buffer *iobuf)
Free I/O buffer.
struct io_buffer * alloc_iob_raw(size_t len, size_t align, size_t offset)
Allocate I/O buffer with specified alignment and offset.
struct io_buffer * iob_concatenate(struct list_head *list)
Concatenate I/O buffers into a single buffer.
#define iob_push(iobuf, len)
static void iob_populate(struct io_buffer *iobuf, void *data, size_t len, size_t max_len)
Create a temporary I/O buffer.
#define iob_put(iobuf, len)
#define iob_disown(iobuf)
Disown an I/O buffer.
static size_t iob_len(struct io_buffer *iobuf)
Calculate length of data in an I/O buffer.
#define iob_reserve(iobuf, len)
#define iob_pull(iobuf, len)
#define iob_unput(iobuf, len)
static size_t iob_tailroom(struct io_buffer *iobuf)
Calculate available space at end of an I/O buffer.
static __always_inline int struct dma_mapping * map
int job_progress(struct interface *intf, struct job_progress *progress)
Get job progress.
#define list_first_entry(list, type, member)
Get the container of the first entry in a list.
#define list_last_entry(list, type, member)
Get the container of the last entry in a list.
#define list_for_each_entry_safe(pos, tmp, head, member)
Iterate over entries in a list, safe against deletion of the current entry.
#define list_add_tail(new, head)
Add a new entry to the tail of a list.
#define list_for_each_entry(pos, head, member)
Iterate over entries in a list.
#define list_del(list)
Delete an entry from a list.
#define INIT_LIST_HEAD(list)
Initialise a list head.
#define list_empty(list)
Test whether a list is empty.
#define LIST_HEAD(list)
Declare a static list head.
#define list_for_each_entry_reverse(pos, head, member)
Iterate over entries in a list in reverse order.
#define list_add(new, head)
Add a new entry to the head of a list.
void * zalloc(size_t size)
Allocate cleared memory.
void * malloc(size_t size)
Allocate memory.
void zfree(void *ptr)
Clear and free memory.
struct digest_algorithm md5_sha1_algorithm
Hybrid MD5+SHA1 digest algorithm.
Hybrid MD5+SHA1 hash as used by TLSv1.1 and earlier.
void alert(unsigned int row, const char *fmt,...)
Show alert message.
uint32_t channel
RNDIS channel.
static uint16_t struct vmbus_xfer_pages_operations * op
Data transfer interface opening.
static char key_map[][128]
uint32_t first
First block in range.
void pending_put(struct pending_operation *pending)
Mark an operation as no longer pending.
void pending_get(struct pending_operation *pending)
Mark an operation as pending.
static int is_pending(struct pending_operation *pending)
Check if an operation is pending.
static struct asn1_cursor * privkey_cursor(struct private_key *key)
Get private key ASN.1 cursor.
static void privkey_put(struct private_key *key)
Drop reference to private key.
static struct private_key * privkey_get(struct private_key *key)
Get reference to private key.
void process_del(struct process *process)
Remove process from process list.
void process_add(struct process *process)
Add process to process list.
#define PROC_DESC_ONCE(object_type, process, _step)
Define a process descriptor for a process that runs only once.
static void process_init_stopped(struct process *process, struct process_descriptor *desc, struct refcnt *refcnt)
Initialise process without adding to process list.
long int random(void)
Generate a pseudo-random number between 0 and 2147483647L or 2147483562?
#define ref_get(refcnt)
Get additional reference to object.
#define ref_put(refcnt)
Drop reference to object.
#define ref_init(refcnt, free)
Initialise a reference counter.
struct x509_root root_certificates
Root certificates.
struct digest_algorithm sha1_algorithm
#define container_of(ptr, type, field)
Get containing structure.
struct stp_switch root
Root switch.
uint16_t hello
Hello time.
char * strerror(int errno)
Retrieve string representation of error number.
int strcmp(const char *first, const char *second)
Compare strings.
int memcmp(const void *first, const void *second, size_t len)
Compare memory regions.
char * strcpy(char *dest, const char *src)
Copy string.
size_t strlen(const char *src)
Get length of string.
struct pubkey_algorithm * pubkey
Public-key algorithm (if applicable).
size_t len
Length of data.
const void * data
Start of data.
size_t len
Length of data.
const char * name
Algorithm name.
size_t blocksize
Block size.
size_t authsize
Authentication tag size.
size_t alignsize
Alignment size.
A message digest algorithm.
size_t digestsize
Digest size.
const char * name
Algorithm name.
A key exchange algorithm.
size_t sharedsize
Shared secret size.
size_t pubsize
Public key size.
const char * name
Algorithm name.
An object interface descriptor.
An object interface operation.
void * data
Start of data.
struct list_head list
List of which this buffer is a member.
A doubly-linked list entry (or list head).
const char * name
Algorithm name.
Secure channel operations.
struct secure_pipe tx
Transmit pipe.
struct secure_pipe rx
Receive pipe.
A secure channel transmit or receive pipe.
void * ctx
Cipher context.
struct cipher_algorithm * cipher
Cipher algorithm.
A pre-shared bound peer identity.
CertificateEntry descriptor.
struct tls_cursor next
Next certificate.
struct tls_cursor cert
Certificate data.
struct tls_cursor list
Certificate list.
uint8_t fixed_iv_len
Fixed initialisation vector length.
struct cipher_algorithm * cipher
Bulk encryption cipher algorithm.
struct pubkey_algorithm * pubkey
Public-key encryption algorithm.
uint8_t key_len
Key length.
uint8_t verify_len
Verification data length.
uint8_t mac_len
MAC length.
uint8_t record_iv_len
Record initialisation vector length.
struct digest_algorithm * digest
MAC digest algorithm.
struct tls_key_exchange_algorithm * exchange
Key exchange algorithm.
uint16_t code
Numeric code (in network-endian order).
struct digest_algorithm * handshake
Handshake digest algorithm (for TLSv1.2 and above).
A TLS cipher specification.
void * fixed_iv
Fixed initialisation vector.
uint64_t seq
Sequence number.
void * cipher_key
Cipher key.
const struct tls_endpoint * writer
Writer endpoint.
const struct tls_phase * pending
Pending traffic phase change.
struct tls_cipher_suite * suite
Cipher suite.
void * dynamic
Dynamically-allocated storage.
struct secure_pipe * pipe
Secure pipe.
void * mac_secret
MAC secret.
struct private_key * key
Private key.
struct x509_chain * chain
Certificate chain (if any).
struct pending_operation negotiation
Security negotiation pending operation.
struct tls_named_group * group
Key exchange named group.
struct interface cipherstream
Ciphertext stream.
struct tls_session * session
Session.
struct tls_server server
Server state.
struct tls_key_schedule key
Key schedule.
struct tls_rx rx
Receive state.
struct tls_verify_data verify
Verification data.
struct secure_channel channel
Secure channel.
struct interface plainstream
Plaintext stream.
struct tls_tx tx
Transmit state.
struct tls_cursor cookie
Cookie.
struct tls_cipher_suite * suite
Cipher suite.
int extended_master_secret
Extended master secret flag.
struct list_head list
List of connections within the same session.
struct tls_client client
Client state.
struct tls_cursor new_ticket
New session ticket (if any).
uint16_t version
Protocol version.
uint16_t legacy_version
Legacy protocol version.
struct tls_session_id new_id
New session ID (if any).
struct refcnt refcnt
Reference counter.
int secure_renegotiation
Secure renegotiation flag.
A TLS variable-length data cursor.
size_t len
Length of data.
DigitallySigned descriptor.
uint16_t * sig_hash
Signature and hash algorithm.
struct tls_cursor sig
Signature.
const char name[7]
Name (for key expansion labels).
A TLS key exchange algorithm.
const char * name
Algorithm name.
struct tls_named_group * group
Default named group.
int(* parse)(struct tls_connection *tls, const struct tls_cursor *cursor, struct tls_key_exchange_parameters *kex)
Parse key exchange parameters from Server Key Exchange record.
const uint8_t * map
ClientKeyExchange descriptor mapping.
TLS key exchange parameters.
size_t len
Length of parameters (excluding trailing signature).
struct tls_named_group * group
Named group.
struct tls_cursor partner
Partner key.
TLS key schedule operations.
struct digest_algorithm * digest
Digest algorithm.
KeyShareClientHello descriptor.
struct tls_cursor list
Key share list.
KeyShareEntry descriptor.
NamedGroupList descriptor.
struct tls_cursor list
Named group list.
uint16_t code
Numeric code (in network-endian order).
struct exchange_algorithm * exchange
Key exchange algorithm.
NewSessionTicket descriptor.
struct tls_cursor ticket
Ticket.
TLS client or server random bytes.
RenegotiationInfo descriptor.
struct tls_cursor verify
Verification data from previous Finished.
struct list_head data
List of received data buffers.
struct io_buffer iobuf
Current received record header (static I/O buffer).
struct tls_cipherspec cipherspec
Cipher specification.
struct io_buffer * handshake
Received handshake fragment (if any).
enum tls_rx_state state
State machine current state.
struct tls_header header
Current received record header.
ServerHelloDone descriptor.
ServerKeyExchange descriptor (for DHE).
struct tls_cursor dsig
Signature.
struct tls_cursor dh_ys
Public key.
struct tls_cursor dh_g
Generator.
struct tls_cursor dh_p
Prime modulus.
ServerKeyExchange descriptor (for ECDHE).
struct tls_server_key_exchange_ecdhe::@335121145353041211061272202142307345103264367317 * curve
Curve parameters.
uint16_t group
Named group.
struct tls_cursor dsig
Signature.
struct tls_cursor point
Curve point.
ServerNameList descriptor.
struct tls_cursor list
Server name list.
struct pending_operation validation
Certificate validation pending operation.
struct interface validator
Certificate validator.
struct x509_root * root
Root of trust.
struct pending_operation negotiation
Security negotiation pending operation.
struct x509_chain * chain
Certificate chain (if any).
struct private_key * key
Private key.
struct tls_cursor ticket
Session ticket.
const char * name
Server name.
struct secure_preshared_identity psid
Bound peer identity.
struct x509_root * root
Root of trust.
struct tls_preshared_key psk
Pre-shared key.
struct list_head conn
List of connections.
struct refcnt refcnt
Reference counter.
struct tls_session_id id
Session ID.
struct list_head list
List of sessions.
A TLS signature algorithm.
struct asn1_algorithm * algorithm
Required certificate OID-identified algorithm, if any.
struct pubkey_algorithm * pubkey
Public-key algorithm.
uint16_t code
Numeric code (in network-endian order).
struct digest_algorithm * digest
Digest algorithm.
SignatureSchemeList descriptor.
struct tls_cursor list
Supported signature algorithm list.
SupportedVersions descriptor (in ServerHello).
uint16_t * selected
Selected version.
SupportedVersions descriptor (in ClientHello).
struct tls_cursor list
Supported version list.
struct tls_cipherspec cipherspec
Cipher specification.
unsigned int pending
Pending transmissions.
struct process process
Transmit process.
void * dynamic
Dynamically allocated storage.
void * client
Client verification data.
size_t len
Length of each verification data.
void * server
Server verification data.
struct x509_subject subject
Subject.
struct asn1_cursor raw
Raw certificate.
struct list_head links
List of links.
A link in an X.509 certificate chain.
struct asn1_algorithm * algorithm
Public key algorithm.
An X.509 root certificate list.
struct x509_public_key public_key
Public key information.
#define table_start(table)
Get start of linker table.
#define for_each_table_entry(pointer, table)
Iterate through all entries within a linker table.
static int tls_copy(const struct tls_cursor *src, struct tls_cursor *dst)
Duplicate content of a TLS cursor.
static struct io_buffer * tls_alloc_iob(struct tls_connection *tls, size_t len)
Allocate I/O buffer for transmitted record(s).
#define EINVAL_CHANGE_CIPHER
static struct interface_descriptor tls_cipherstream_desc
TLS ciphertext stream interface descriptor.
static void tls_hmac_init(struct tls_cipherspec *cipherspec, void *ctx, struct tls_auth_header *authhdr)
Initialise HMAC.
static int tls_has_inner(struct tls_connection *tls, struct cipher_algorithm *cipher)
Check if TLS inner plaintext is in use.
static int tls_new_ciphertext(struct tls_connection *tls, struct tls_header *tlshdr, struct list_head *rx_data)
Receive new ciphertext record.
static int tls_progress(struct tls_connection *tls, struct job_progress *progress)
Report job progress.
static const char * tls_pipe_name(struct tls_connection *tls, struct secure_pipe *pipe)
Get pipe name (for debugging).
static void tls_validator_done(struct tls_connection *tls, int rc)
Handle certificate validation completion.
static int tls_key_share(struct tls_connection *tls, struct tls_named_group *group, struct tls_cursor *public)
Share public key.
static int tls_resume(struct tls_connection *tls)
Resume session.
static int tls_verify_signature(struct tls_connection *tls, const struct tls_cursor *cursor, const struct tls_cursor *params)
Verify a signature record.
static int tls_new_certificate_verify(struct tls_connection *tls, const struct tls_cursor *cursor)
Receive new Certificate Verify handshake record.
static int tls_select_cipher(struct tls_connection *tls, unsigned int version, unsigned int cipher_suite)
Select protocol version and cipher suite.
#define EINVAL_KEY_EXCHANGE
static struct io_buffer * tls_alloc_handshake(struct tls_connection *tls, struct tls_cursor *cursor, unsigned int type)
Allocate Handshake record.
static int tls_send_alert(struct tls_connection *tls, unsigned int level, unsigned int description)
Transmit Alert record.
static int tls_parse_dhe(struct tls_connection *tls, const struct tls_cursor *cursor, struct tls_key_exchange_parameters *kex)
Parse key exchange parameters from DHE Server Key Exchange record.
static int tls_set_digest(struct tls_connection *tls, struct digest_algorithm *digest)
Set key schedule digest algorithm.
static const uint8_t tls_downgrade_magic[7]
ServerHello downgrade magic value.
static int tls_replay_handshake(struct tls_connection *tls, struct io_buffer *iobuf)
Add Handshake record to transcript digest (without transmitting).
static int tls_send_certificate(struct tls_connection *tls)
Transmit Certificate record.
static void tls_tx_resume(struct tls_connection *tls)
Resume TX state machine.
static struct interface_operation tls_validator_ops[]
TLS certificate validator interface operations.
static void free_tls_session(struct refcnt *refcnt)
Free TLS session.
static int tls_new_change_cipher(struct tls_connection *tls, struct io_buffer *iobuf)
Receive new Change Cipher record.
static void tls_clear_digest(struct tls_connection *tls)
Clear key schedule digest algorithm.
static void tls_tx_step(struct tls_connection *tls)
TLS TX state machine.
static int tls_newdata_process_data(struct tls_connection *tls)
Handle received TLS data payload.
#define EPERM_KEY_EXCHANGE
static int tls_send_finished(struct tls_connection *tls)
Transmit Finished record.
static int tls_new_session_ticket(struct tls_connection *tls, const struct tls_cursor *cursor)
Receive New Session Ticket handshake record.
static int tls_channel_save(struct secure_channel *channel, struct secure_preshared_identity *psid)
Save a pre-shared key for future resumption of the key schedule.
static int tls_validator_start(struct tls_connection *tls)
Start certificate validation.
static struct interface_operation tls_cipherstream_ops[]
TLS ciphertext stream interface operations.
static struct secure_channel_operations tls_channel_ops
Secure channel operations.
static int tls_send_record(struct tls_connection *tls, unsigned int type, struct io_buffer *iobuf)
Send plaintext record(s).
struct pubkey_algorithm rsa_algorithm
static int tls_send_client_hello(struct tls_connection *tls)
Transmit Client Hello record.
static int tls_hash_verify(struct tls_connection *tls, struct tls_signature_hash_algorithm *sig_hash, struct x509_certificate *cert, const struct tls_cursor *params, const struct asn1_cursor *sig)
Verify signature over parameters used to construct shared secret.
static int tls_save(struct tls_connection *tls)
Save session for future resumption.
static struct tls_cipher_suite * tls_find_cipher_suite(unsigned int cipher_suite)
Identify cipher suite.
static struct interface_descriptor tls_validator_desc
TLS certificate validator interface descriptor.
static int tls_cipherstream_deliver(struct tls_connection *tls, struct io_buffer *iobuf, struct xfer_metadata *xfer __unused)
Receive new ciphertext.
static void tls_hmac_final(struct tls_cipherspec *cipherspec, void *ctx, void *hmac)
Finalise HMAC.
static void tls_set_session_id(struct tls_connection *tls)
Set a random session ID.
static int tls_new_hello_request(struct tls_connection *tls, const struct tls_cursor *cursor)
Receive new Hello Request handshake record.
static const char * tls_cipher_name(struct tls_cipher_suite *suite)
Get cipher suite name (for debugging).
#define ENOMEM_TX_PLAINTEXT
static const char * tls_version_name(unsigned int version)
Get protocol version name (for debugging).
static int tls_new_finished(struct tls_connection *tls, const struct tls_cursor *cursor)
Receive new Finished handshake record.
static int tls_new_certificate_request(struct tls_connection *tls, const struct tls_cursor *cursor __unused)
Receive new Certificate Request handshake record.
#define TLS_NUM_CIPHER_SUITES
Number of supported cipher suites.
static int tls_newdata_process_header(struct tls_connection *tls)
Handle received TLS header.
static int tls_new_server_key_exchange(struct tls_connection *tls, const struct tls_cursor *cursor)
Receive new Server Key Exchange handshake record.
#define EPROTO_CIPHER_CHANGE
static int tls_send_client_key_exchange(struct tls_connection *tls)
Transmit Client Key Exchange record.
#define TLS_NUM_VERSIONS
Number of supported TLS versions.
static int tls_prep_cipher(struct tls_connection *tls, struct tls_cipherspec *cipherspec, const struct tls_phase *phase)
Prepare cipher specification for a new traffic phase.
static int tls_version(struct tls_connection *tls, unsigned int version)
Check for TLS version.
static void tls_random(struct tls_connection *tls, void *nonce, size_t len)
Generate random nonce.
static int tls_ready(struct tls_connection *tls)
Determine if TLS connection is ready for application data.
static struct interface_descriptor tls_plainstream_desc
TLS plaintext stream interface descriptor.
static int tls_plainstream_deliver(struct tls_connection *tls, struct io_buffer *iobuf, struct xfer_metadata *meta __unused)
Deliver datagram as raw data.
struct tls_key_exchange_algorithm tls_null_exchange_algorithm
Null key exchange algorithm.
static void tls_nonce(struct tls_connection *tls, struct tls_random *nonce)
Generate deterministic connection nonce.
static int tls_session(struct tls_connection *tls, const char *name)
Find or create session for TLS connection.
static void free_tls(struct refcnt *refcnt)
Free TLS connection.
static int tls_new_certificate(struct tls_connection *tls, const struct tls_cursor *cursor)
Receive new Certificate handshake record.
static void tls_add_handshake(struct tls_connection *tls, const void *data, size_t len)
Add handshake record to transcript digest.
static int tls_establish(struct tls_connection *tls)
Establish secure channel.
static void tls_restart(struct tls_connection *tls)
Restart negotiation.
struct tls_cipher_suite tls_cipher_suite_null
Null cipher suite.
static int tls_channel_load(struct secure_channel *channel, struct secure_preshared_identity *psid)
Load a pre-shared key and resume the key schedule.
struct tls_key_exchange_algorithm tls_pubkey_exchange_algorithm
Public key exchange algorithm.
static size_t tls_plainstream_window(struct tls_connection *tls)
Check flow control window.
static void tls_hmac_list(struct tls_cipherspec *cipherspec, struct tls_auth_header *authhdr, struct list_head *list, void *hmac)
Calculate HMAC over list of I/O buffers.
static int tls_send_change_cipher(struct tls_connection *tls)
Transmit Change Cipher record.
static int tls_extract_inner(struct tls_connection *tls, int type, struct list_head *rx_data)
Extract inner plaintext.
struct tls_key_exchange_algorithm tls_ecdhe_exchange_algorithm
Ephemeral Elliptic Curve Diffie-Hellman key exchange algorithm.
static int tls_key_agree(struct tls_connection *tls, struct tls_named_group *group, const struct tls_cursor *partner)
Agree shared secret.
static struct tls_named_group * tls_find_named_group(unsigned int named_group)
Identify named key exchange group.
static size_t tls_cipherstream_window(struct tls_connection *tls)
Check flow control window.
static int tls_new_server_hello_done(struct tls_connection *tls, const struct tls_cursor *cursor)
Receive new Server Hello Done handshake record.
static int tls_send_plaintext(struct tls_connection *tls, unsigned int type, const void *data, size_t len)
Send plaintext record.
static void tls_hmac(struct tls_cipherspec *cipherspec, struct tls_auth_header *authhdr, const void *data, size_t len, void *hmac)
Calculate HMAC.
static void tls_channel_reset(struct secure_channel *channel)
Reset the key schedule.
static int tls_new_server_hello(struct tls_connection *tls, const struct tls_cursor *cursor)
Receive new Server Hello handshake record.
static void tls_hmac_update(struct tls_cipherspec *cipherspec, void *ctx, const void *data, size_t len)
Update HMAC.
static int tls_channel_verify(struct secure_channel *channel, const void *auth, size_t len)
Verify authenticator value.
static int tls_hash_sign(struct tls_connection *tls, struct tls_signature_hash_algorithm *sig_hash, struct x509_certificate *cert, struct asn1_builder *sig)
Create signature over parameters used to construct shared secret.
static int tls_client_hello(struct tls_connection *tls, int(*action)(struct tls_connection *tls, struct io_buffer *iobuf))
Digest or transmit Client Hello record.
#define EPERM_RENEG_INSECURE
static int tls_parse_ecdhe(struct tls_connection *tls, const struct tls_cursor *cursor, struct tls_key_exchange_parameters *kex)
Parse key exchange parameters from ECDHE Server Key Exchange record.
static int tls_send_certificate_verify(struct tls_connection *tls)
Transmit Certificate Verify record.
static void tls_close_alert(struct tls_connection *tls, int rc)
Send closure alert and finish with TLS connection.
static int tls_keysize_is_variable(struct tls_connection *tls, struct exchange_algorithm *exchange)
Check if key exchange keys have a variable size.
static void tls_close(struct tls_connection *tls, int rc)
Finish with TLS connection.
static int tls_verify_padding(struct tls_connection *tls, struct io_buffer *iobuf)
Verify block padding.
static struct process_descriptor tls_process_desc
TLS TX process descriptor.
#define EPERM_RENEG_VERIFY
#define TLS_LEGACY_VERSION_MAX
Maximum pre-TLSv1.3 version.
static int tls_new_unknown(struct tls_connection *tls __unused, struct io_buffer *iobuf)
Receive new unknown record.
struct tls_key_exchange_algorithm tls_dhe_exchange_algorithm
Ephemeral Diffie-Hellman key exchange algorithm.
static int tls_new_data(struct tls_connection *tls, struct list_head *rx_data)
Receive new data record.
#define TLS_NUM_SIG_HASH_ALGORITHMS
Number of supported signature and hash algorithms.
static int tls_parse_null(struct tls_connection *tls, const struct tls_cursor *cursor, struct tls_key_exchange_parameters *kex __unused)
Parse key exchange parameters from unexpected Server Key Exchange record.
static struct tls_named_group * tls_find_param_group(const struct tls_cursor *dh_p, const struct tls_cursor *dh_g)
Identify named key exchange group by Diffie-Hellman parameters.
static int tls_new_handshake(struct tls_connection *tls, struct io_buffer *iobuf)
Receive new Handshake record.
static size_t tls_iob_reserved(struct tls_connection *tls, size_t len)
Calculate maximum additional length required for transmitted record(s).
static struct tls_signature_hash_algorithm * tls_signature_hash_algorithm(struct pubkey_algorithm *pubkey, struct digest_algorithm *digest)
Find TLS signature and hash algorithm.
static int tls_pending_cipher(struct tls_connection *tls, struct tls_cipherspec *cipherspec)
Apply pending traffic phase change (if any).
static struct interface_operation tls_plainstream_ops[]
TLS plaintext stream interface operations.
static const struct tls_random tls_hrr_magic
HelloRetryRequest magic value.
static int tls_change_cipher(struct tls_connection *tls, struct tls_cipherspec *cipherspec, const struct tls_phase *phase)
Change cipher specification.
static int tls_key_encrypt(struct tls_connection *tls, struct tls_named_group *group, struct asn1_builder *builder)
Encrypt (and implicitly bind) shared secret.
static int tls_channel_apply(struct secure_channel *channel, struct exchange_algorithm *exchange, const void *shared, int *accumulated)
Apply a new shared secret to key schedule.
static void tls_xor(void *dst, const void *src, size_t len)
XOR data block.
static int tls_new_record(struct tls_connection *tls, unsigned int type, struct list_head *rx_data)
Receive new record.
#define EPROTO_VALIDATION
static void tls_clear_cipher(struct tls_connection *tls, struct tls_cipherspec *cipherspec)
static int tls_set_verify_len(struct tls_connection *tls, size_t verify_len)
Set verification data length.
static int tls_new_alert(struct tls_connection *tls, struct io_buffer *iobuf)
Receive new Alert record.
static void tls_tx_resume_all(struct tls_session *session)
Resume TX state machine for all connections within a session.
static struct tls_signature_hash_algorithm * tls_find_signature_hash(unsigned int code)
Find TLS signature and hash algorithm.
static int tls_send_handshake(struct tls_connection *tls, struct io_buffer *iobuf)
Transmit Handshake record.
int add_tls(struct interface *xfer, const char *name, struct x509_root *root, struct private_key *key)
Add TLS on an interface.
Transport Layer Security Protocol.
#define TLS_SERVER_KEY_EXCHANGE
#define TLS_TYPE_ALERT
Alert content type.
#define TLS_TX_BUFSIZE
TX maximum fragment length.
#define TLS_NEW_SESSION_TICKET
#define TLS_HANDSHAKE_LEN(type_len)
Get TLS handshake length.
#define TLS_CLIENT_KEY_EXCHANGE
#define TLS_NUM_NAMED_GROUPS
Number of non-anonymous TLS named groups.
#define TLS_CHANGE_CIPHER_SPEC
Change cipher spec magic byte.
#define TLS_CIPHER_SUITES
TLS cipher suite table.
#define __tls_anon_named_group
Declare a TLS anonymous named group.
#define TLS_RX_MIN_BUFSIZE
Minimum RX I/O buffer size.
#define TLS_MAX_FRAGMENT_LENGTH_VALUE
Advertised maximum fragment length.
#define TLS_CERTIFICATE_VERIFY
#define TLS_ALERT_CLOSE_NOTIFY
#define TLS_HELLO_REQUEST
#define TLS_RX_ALIGN
RX I/O buffer alignment.
#define TLS_TYPE_HANDSHAKE
Handshake content type.
#define TLS_TYPE_DATA
Application data content type.
#define TLS_CIPHER_FL_SEQUENTIAL_IV
Cipher XORs sequence number into the initialisation vector.
#define TLS_ALERT_WARNING
#define TLS_CERTIFICATE_REQUEST
@ TLS_TX_CLIENT_KEY_EXCHANGE
@ TLS_TX_CERTIFICATE_VERIFY
#define TLS_TYPE_CHANGE_CIPHER
Change cipher content type.
#define TLS_SIG_HASH_ALGORITHMS
TLS signature hash algorithm table.
#define TLS_SERVER_HELLO_DONE
#define TLS_RX_BUFSIZE
RX I/O buffer size.
#define TLS_NAMED_CURVE_TYPE
TLS named curve type.
#define TLS_SERVER_DOWNGRADE_MAGIC
TLS server downgrade detection magic signature.
#define TLS_NAMED_GROUPS
TLS named group table.
struct exchange_algorithm tls_classic_pre_master_algorithm
Classic pre-master secret key exchange algorithm.
int tls_build_map(const uint8_t *map, unsigned int version, union tls_ptr_len *desc, struct tls_cursor *cursor)
Build TLS data structure.
int tls_size_map(const uint8_t *map, unsigned int version, union tls_ptr_len *desc, struct tls_cursor *cursor)
Calculate length of TLS data structure.
int tls_parse_opt_map(const uint8_t *map, unsigned int version, const struct tls_cursor *cursor, union tls_ptr_len *desc)
Parse optional TLS data structure.
#define tls_build(type, version, desc, cursor)
Build TLS data structure.
static const struct asn1_cursor * tls_asn1(const struct tls_cursor *cursor)
Get ASN.1 cursor from TLS cursor.
#define TLS_VERSION_TLS_1_2
TLS version 1.2.
#define tls_parse_opt(type, version, cursor, desc)
Parse optional TLS data structure.
#define tls_parse(type, version, cursor, desc)
Parse TLS data structure.
#define TLS_VERSION_TLS_1_3
TLS version 1.3.
#define TLS_VERSION_TLS_1_1
TLS version 1.1.
#define tls_size(type, version, desc, cursor)
Calculate length of TLS data structure.
int tlskey_save(struct tls_key_schedule *tlskey, const void *nonce, size_t nonce_len, struct tls_preshared_key *psk)
Save pre-shared key.
int tlskey_master(struct tls_key_schedule *tlskey, int ems)
Generate master secret.
int tlskey_cipher(struct tls_key_schedule *tlskey, const struct tls_endpoint *writer, void *key, size_t key_len, void *iv, size_t iv_len, void *mac, size_t mac_len)
Generate cipher key material.
int tlskey_load(struct tls_key_schedule *tlskey, int ems, const struct tls_preshared_key *psk)
Load pre-shared key.
void tlskey_stop(struct tls_key_schedule *tlskey)
Stop key schedule.
void tlskey_reset(struct tls_key_schedule *tlskey)
Reset key schedule.
const struct tls_phase tls_handshake
Handshake traffic phase.
int tlskey_start(struct tls_key_schedule *tlskey, const struct tls_key_schedule_operations *op, struct digest_algorithm *digest, const struct tls_random *nonce)
Start key schedule.
int tlskey_tbshash(struct tls_key_schedule *tlskey, const struct tls_endpoint *end, struct digest_algorithm *digest, const void *data, size_t len, void *tbs)
Generate signable digest value.
int tlskey_apply(struct tls_key_schedule *tlskey, const void *shared, size_t shared_len)
Apply a new shared secret.
const struct tls_key_schedule_operations tlskey_hash
TLS key schedule based on P_Hash().
int tlskey_traffic(struct tls_key_schedule *tlskey, const struct tls_endpoint *writer, const struct tls_phase *phase)
Generate traffic secret.
void tlskey_message(struct tls_key_schedule *tlskey)
Replace running transcript digest with a message hash of itself.
const struct tls_key_schedule_operations tlskey_md5_sha1
TLS key schedule based on P_MD5()+P_SHA1().
int tlskey_verify(struct tls_key_schedule *tlskey, const struct tls_endpoint *end, void *verify, size_t verify_len)
Generate verification data.
void tlskey_digest(struct tls_key_schedule *tlskey, const void *data, size_t len)
Add handshake to running transcript digest.
const struct tls_phase tls_application
Application traffic phase.
const struct tls_key_schedule_operations tlskey_hkdf
TLS key schedule based on HKDF.
static int tlskey_is_accumulating(struct tls_key_schedule *tlskey)
Check if key schedule accumulates shared secrets.
uint32_t data_len
Microcode data size (or 0 to indicate 2000 bytes).
ClientKeyExchange descriptor (unified).
struct tls_cursor cursor
ClientKeyExchange descriptor (common format).
union tls_ptr_len desc[0]
Raw pointer/length array.
uint32_t type_len
Type and length.
KeyShareServerHello/KeyShareHelloRetryRequest combined descriptor.
int create_validator(struct interface *job, struct x509_chain *chain, struct x509_root *root)
Instantiate a certificate validator.
int snprintf(char *buf, size_t size, const char *fmt,...)
Write a formatted string to a buffer.
u8 iv[16]
Initialization vector.
u8 tx[WPA_TKIP_MIC_KEY_LEN]
MIC key for packets to the AP.
int x509_auto_append(struct x509_chain *chain, struct x509_chain *store)
Append X.509 certificates to X.509 certificate chain.
struct x509_chain * x509_alloc_chain(void)
Allocate X.509 certificate chain.
const char * x509_name(struct x509_certificate *cert)
Get X.509 certificate display name.
struct x509_certificate * x509_find_key(struct x509_chain *store, struct private_key *key)
Identify X.509 certificate by corresponding public key.
int x509_append_raw(struct x509_chain *chain, const void *data, size_t len)
Append X.509 certificate to X.509 certificate chain.
int x509_append(struct x509_chain *chain, struct x509_certificate *cert)
Append X.509 certificate to X.509 certificate chain.
static struct x509_certificate * x509_first(struct x509_chain *chain)
Get first certificate in X.509 certificate chain.
static struct x509_root * x509_root_get(struct x509_root *root)
Get reference to X.509 root certificate list.
static void x509_root_put(struct x509_root *root)
Drop reference to X.509 root certificate list.
static void x509_chain_put(struct x509_chain *chain)
Drop reference to X.509 certificate chain.
size_t xfer_window(struct interface *intf)
Check flow control window.
int xfer_deliver(struct interface *intf, struct io_buffer *iobuf, struct xfer_metadata *meta)
Deliver datagram.
struct io_buffer * xfer_alloc_iob(struct interface *intf, size_t len)
Allocate I/O buffer.
void xfer_window_changed(struct interface *intf)
Report change of flow control window.
int xfer_deliver_iob(struct interface *intf, struct io_buffer *iobuf)
Deliver datagram as I/O buffer without metadata.
Data transfer interfaces.