|
iPXE
|
Transport Layer Security Protocol. More...
#include <stdint.h>#include <ipxe/refcnt.h>#include <ipxe/interface.h>#include <ipxe/process.h>#include <ipxe/crypto.h>#include <ipxe/x509.h>#include <ipxe/privkey.h>#include <ipxe/pending.h>#include <ipxe/iobuf.h>#include <ipxe/tables.h>#include <ipxe/channel.h>#include <ipxe/tlskey.h>#include <ipxe/tlsfmt.h>Go to the source code of this file.
Data Structures | |
| struct | tls_header |
| A TLS header. More... | |
| union | tls_handshake_header |
| A TLS handshake header. More... | |
| union | tls_server_random |
| TLS server random data. More... | |
| struct | tls_auth_header |
| TLS authentication header. More... | |
| struct | tls_key_exchange_parameters |
| TLS key exchange parameters. More... | |
| struct | tls_key_exchange_algorithm |
| A TLS key exchange algorithm. More... | |
| struct | tls_cipher_suite |
| A TLS cipher suite. More... | |
| struct | tls_named_group |
| A TLS named group. More... | |
| struct | tls_cipherspec |
| A TLS cipher specification. More... | |
| struct | tls_signature_hash_algorithm |
| A TLS signature algorithm. More... | |
| struct | tls_session_id |
| A TLS session ID. More... | |
| struct | tls_session |
| A TLS session. More... | |
| struct | tls_verify_data |
| TLS verification data. More... | |
| struct | tls_tx |
| TLS transmit state. More... | |
| struct | tls_rx |
| TLS receive state. More... | |
| struct | tls_client |
| TLS client state. More... | |
| struct | tls_server |
| TLS server state. More... | |
| struct | tls_connection |
| A TLS connection. More... | |
Enumerations | |
| enum | tls_rx_state { TLS_RX_HEADER = 0 , TLS_RX_DATA } |
| TLS RX state machine state. More... | |
| enum | tls_tx_pending { TLS_TX_CLIENT_HELLO = 0x0001 , TLS_TX_CERTIFICATE = 0x0002 , TLS_TX_CLIENT_KEY_EXCHANGE = 0x0004 , TLS_TX_CERTIFICATE_VERIFY = 0x0008 , TLS_TX_CHANGE_CIPHER = 0x0010 , TLS_TX_FINISHED = 0x0020 } |
| TLS TX pending flags. More... | |
Functions | |
| FILE_LICENCE (GPL2_OR_LATER_OR_UBDL) | |
| FILE_SECBOOT (PERMITTED) | |
| int | add_tls (struct interface *xfer, const char *name, struct x509_root *root, struct private_key *key) |
| Add TLS on an interface. | |
Variables | |
| struct exchange_algorithm | tls_classic_pre_master_algorithm |
| Classic pre-master secret key exchange algorithm. | |
| struct tls_key_exchange_algorithm | tls_null_exchange_algorithm |
| Null key exchange algorithm. | |
| struct tls_key_exchange_algorithm | tls_pubkey_exchange_algorithm |
| Public key exchange algorithm. | |
| struct tls_key_exchange_algorithm | tls_dhe_exchange_algorithm |
| Ephemeral Diffie-Hellman key exchange algorithm. | |
| struct tls_key_exchange_algorithm | tls_ecdhe_exchange_algorithm |
| Ephemeral Elliptic Curve Diffie-Hellman key exchange algorithm. | |
Transport Layer Security Protocol.
Definition in file tls.h.
| #define TLS_HANDSHAKE_LEN | ( | type_len | ) |
Get TLS handshake length.
Definition at line 54 of file tls.h.
Referenced by tls_new_handshake().
| #define TLS_SERVER_DOWNGRADE_MAGIC "DOWNGRD" |
| #define TLS_TYPE_CHANGE_CIPHER 20 |
Change cipher content type.
Definition at line 75 of file tls.h.
Referenced by tls_new_ciphertext(), tls_new_record(), and tls_send_change_cipher().
| #define TLS_CHANGE_CIPHER_SPEC 1 |
Change cipher spec magic byte.
Definition at line 78 of file tls.h.
Referenced by tls_new_change_cipher(), and tls_send_change_cipher().
| #define TLS_TYPE_ALERT 21 |
Alert content type.
Definition at line 81 of file tls.h.
Referenced by tls_new_record(), and tls_send_alert().
| #define TLS_TYPE_HANDSHAKE 22 |
Handshake content type.
Definition at line 84 of file tls.h.
Referenced by tls_new_record(), tls_send_handshake(), and tls_send_record().
| #define TLS_TYPE_DATA 23 |
Application data content type.
Definition at line 87 of file tls.h.
Referenced by tls_extract_inner(), tls_new_record(), tls_plainstream_deliver(), and tls_send_record().
| #define TLS_HELLO_REQUEST 0 |
Definition at line 90 of file tls.h.
Referenced by tls_new_handshake().
| #define TLS_CLIENT_HELLO 1 |
Definition at line 91 of file tls.h.
Referenced by tls_client_hello().
| #define TLS_SERVER_HELLO 2 |
Definition at line 92 of file tls.h.
Referenced by tls_new_handshake().
| #define TLS_NEW_SESSION_TICKET 4 |
Definition at line 93 of file tls.h.
Referenced by tls_new_handshake().
| #define TLS_CERTIFICATE 11 |
Definition at line 94 of file tls.h.
Referenced by tls_new_handshake(), and tls_send_certificate().
| #define TLS_SERVER_KEY_EXCHANGE 12 |
Definition at line 95 of file tls.h.
Referenced by tls_new_handshake().
| #define TLS_CERTIFICATE_REQUEST 13 |
Definition at line 96 of file tls.h.
Referenced by tls_new_handshake().
| #define TLS_SERVER_HELLO_DONE 14 |
Definition at line 97 of file tls.h.
Referenced by tls_new_handshake().
| #define TLS_CERTIFICATE_VERIFY 15 |
Definition at line 98 of file tls.h.
Referenced by tls_new_handshake(), and tls_send_certificate_verify().
| #define TLS_CLIENT_KEY_EXCHANGE 16 |
Definition at line 99 of file tls.h.
Referenced by tls_send_client_key_exchange().
| #define TLS_FINISHED 20 |
Definition at line 100 of file tls.h.
Referenced by tls_new_handshake(), and tls_send_finished().
| #define TLS_ALERT_WARNING 1 |
Definition at line 103 of file tls.h.
Referenced by tls_close_alert(), and tls_new_alert().
| #define TLS_ALERT_FATAL 2 |
Definition at line 104 of file tls.h.
Referenced by tls_new_alert().
| #define TLS_ALERT_CLOSE_NOTIFY 0 |
Definition at line 107 of file tls.h.
Referenced by tls_close_alert(), and tls_new_alert().
| #define TLS_RSA_WITH_AES_128_CBC_SHA 0x002f |
Definition at line 112 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_DHE_RSA_WITH_AES_128_CBC_SHA 0x0033 |
Definition at line 113 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_RSA_WITH_AES_256_CBC_SHA 0x0035 |
Definition at line 114 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_DHE_RSA_WITH_AES_256_CBC_SHA 0x0039 |
Definition at line 115 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_RSA_WITH_AES_128_CBC_SHA256 0x003c |
Definition at line 116 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_RSA_WITH_AES_256_CBC_SHA256 0x003d |
Definition at line 117 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 0x0067 |
Definition at line 118 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 0x006b |
Definition at line 119 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_RSA_WITH_AES_128_GCM_SHA256 0x009c |
Definition at line 120 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_RSA_WITH_AES_256_GCM_SHA384 0x009d |
Definition at line 121 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 0x009e |
Definition at line 122 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 0x009f |
Definition at line 123 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_AES_128_GCM_SHA256 0x1301 |
Definition at line 124 of file tls.h.
Referenced by __tls_cipher_suite(), and tlsfmt_test_exec().
| #define TLS_AES_256_GCM_SHA384 0x1302 |
Definition at line 125 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA 0xc009 |
Definition at line 126 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA 0xc00a |
Definition at line 127 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 0xc013 |
Definition at line 128 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 0xc014 |
Definition at line 129 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 0xc023 |
Definition at line 130 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 0xc024 |
Definition at line 131 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 0xc027 |
Definition at line 132 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 0xc028 |
Definition at line 133 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 0xc02b |
Definition at line 134 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 0xc02c |
Definition at line 135 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 0xc02f |
Definition at line 136 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 0xc030 |
Definition at line 137 of file tls.h.
Referenced by __tls_cipher_suite().
| #define TLS_RSA_SHA1_ALGORITHM 0x0201 |
Definition at line 140 of file tls.h.
Referenced by tlsfmt_test_exec().
| #define TLS_SERVER_NAME 0 |
Definition at line 157 of file tls.h.
Referenced by TLS_DESCR_MAPPING().
| #define TLS_MAX_FRAGMENT_LENGTH 1 |
Definition at line 161 of file tls.h.
Referenced by TLS_DESCR_MAPPING().
| #define TLS_NAMED_GROUP 10 |
Definition at line 168 of file tls.h.
Referenced by TLS_DESCR_MAPPING().
| #define TLS_NAMED_GROUP_SECP256R1 23 |
Definition at line 169 of file tls.h.
Referenced by __tls_named_group().
| #define TLS_NAMED_GROUP_SECP384R1 24 |
Definition at line 170 of file tls.h.
Referenced by __tls_named_group().
| #define TLS_NAMED_GROUP_X25519 29 |
Definition at line 171 of file tls.h.
Referenced by __tls_named_group(), and tlsfmt_test_exec().
| #define TLS_NAMED_GROUP_FFDHE2048 256 |
Definition at line 172 of file tls.h.
Referenced by __tls_named_group().
| #define TLS_NAMED_GROUP_FFDHE3072 257 |
Definition at line 173 of file tls.h.
Referenced by __tls_named_group().
| #define TLS_NAMED_GROUP_FFDHE4096 258 |
Definition at line 174 of file tls.h.
Referenced by __tls_named_group().
| #define TLS_SIGNATURE_ALGORITHMS 13 |
Definition at line 177 of file tls.h.
Referenced by TLS_DESCR_MAPPING().
| #define TLS_EXTENDED_MASTER_SECRET 23 |
Definition at line 180 of file tls.h.
Referenced by TLS_DESCR_MAPPING(), and TLS_DESCR_MAPPING().
| #define TLS_RECORD_SIZE_LIMIT 28 |
Definition at line 183 of file tls.h.
Referenced by TLS_DESCR_MAPPING().
| #define TLS_SESSION_TICKET 35 |
Definition at line 186 of file tls.h.
Referenced by TLS_DESCR_MAPPING().
| #define TLS_SUPPORTED_VERSIONS 43 |
Definition at line 189 of file tls.h.
Referenced by TLS_DESCR_MAPPING(), TLS_DESCR_MAPPING(), and tlsfmt_test_exec().
| #define TLS_COOKIE 44 |
Definition at line 192 of file tls.h.
Referenced by TLS_DESCR_MAPPING(), and TLS_DESCR_MAPPING().
| #define TLS_PSK_MODES 45 |
Definition at line 195 of file tls.h.
Referenced by TLS_DESCR_MAPPING().
| #define TLS_KEY_SHARE 51 |
Definition at line 198 of file tls.h.
Referenced by TLS_DESCR_MAPPING(), TLS_DESCR_MAPPING(), and tlsfmt_test_exec().
| #define TLS_RENEGOTIATION_INFO 0xff01 |
Definition at line 201 of file tls.h.
Referenced by TLS_DESCR_MAPPING(), TLS_DESCR_MAPPING(), and tlsfmt_test_exec().
| #define TLS_CIPHER_FL_SEQUENTIAL_IV 0x01 |
Cipher XORs sequence number into the initialisation vector.
Definition at line 294 of file tls.h.
Referenced by __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), tls_new_ciphertext(), and tls_send_record().
| #define TLS_CIPHER_SUITES __table ( struct tls_cipher_suite, "tls_cipher_suites" ) |
TLS cipher suite table.
Definition at line 297 of file tls.h.
Referenced by tls_client_hello(), and tls_find_cipher_suite().
| #define __tls_cipher_suite | ( | pref | ) |
Declare a TLS cipher suite.
Definition at line 301 of file tls.h.
Referenced by __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), and __tls_cipher_suite().
| #define TLS_NAMED_CURVE_TYPE 3 |
TLS named curve type.
Definition at line 305 of file tls.h.
Referenced by tls_parse_ecdhe(), and tlsfmt_test_exec().
| #define TLS_NAMED_GROUPS __table ( struct tls_named_group, "tls_named_groups" ) |
TLS named group table.
Definition at line 316 of file tls.h.
Referenced by add_tls(), tls_client_hello(), tls_find_named_group(), and tls_find_param_group().
| #define __tls_named_group | ( | pref | ) |
Declare a TLS named group.
Definition at line 320 of file tls.h.
Referenced by __tls_named_group(), __tls_named_group(), and __tls_named_group().
| struct tls_named_group tls_pubkey_named_group __tls_anon_named_group __tls_named_group ( 98 ) |
| #define TLS_NUM_NAMED_GROUPS |
Number of non-anonymous TLS named groups.
Definition at line 327 of file tls.h.
Referenced by tls_client_hello().
| #define TLS_SIG_HASH_ALGORITHMS |
TLS signature hash algorithm table.
Note that the default (TLSv1.1 and earlier) algorithm using MD5+SHA1 is never explicitly specified.
Definition at line 372 of file tls.h.
Referenced by tls_client_hello(), tls_find_signature_hash(), and tls_signature_hash_algorithm().
| struct tls_signature_hash_algorithm tls_rsa_pss_pss_sha512 __tls_sig_hash_algorithm __table_entry ( TLS_SIG_HASH_ALGORITHMS, 01 ) |
Declare a TLS signature hash algorithm.
RSA-PSS with RSASSA-PSS OID and SHA-512 signature hash algorithm.
RSA-PSS with rsaEncryption OID and SHA-512 signature hash algorithm.
RSA-PSS with RSASSA-PSS OID and SHA-384 signature hash algorithm.
RSA-PSS with rsaEncryption OID and SHA-384 signature hash algorithm.
RSA-PSS with RSASSA-PSS OID and SHA-256 signature hash algorithm.
RSA-PSS with rsaEncryption OID and SHA-256 signature hash algorithm.
Definition at line 377 of file tls.h.
| #define TLS_MAX_FRAGMENT_LENGTH_VALUE TLS_MAX_FRAGMENT_LENGTH_4096 |
Advertised maximum fragment length.
Definition at line 528 of file tls.h.
Referenced by tls_client_hello().
| #define TLS_TX_BUFSIZE 4096 |
TX maximum fragment length.
TLS requires us to limit our transmitted records to the maximum fragment length that we attempt to negotiate, even if the server does not respect this choice.
Definition at line 536 of file tls.h.
Referenced by tls_iob_reserved(), and tls_send_record().
| #define TLS_RX_BUFSIZE 4096 |
RX I/O buffer size.
The maximum fragment length extension is optional, and many common implementations (including OpenSSL) do not support it. We must therefore be prepared to receive records of up to 16kB in length. The chance of an allocation of this size failing is non-negligible, so we must split received data into smaller allocations.
Definition at line 546 of file tls.h.
Referenced by tls_new_ciphertext(), and tls_newdata_process_header().
| #define TLS_RX_MIN_BUFSIZE 512 |
Minimum RX I/O buffer size.
To simplify manipulations, we ensure that no RX I/O buffer is smaller than this size. This allows us to assume that the MAC and padding are entirely contained within the final I/O buffer.
Definition at line 554 of file tls.h.
Referenced by tls_newdata_process_header().
| #define TLS_RX_ALIGN 16 |
RX I/O buffer alignment.
Definition at line 557 of file tls.h.
Referenced by tls_newdata_process_header().
| enum tls_rx_state |
TLS RX state machine state.
| Enumerator | |
|---|---|
| TLS_RX_HEADER | |
| TLS_RX_DATA | |
| enum tls_tx_pending |
TLS TX pending flags.
| Enumerator | |
|---|---|
| TLS_TX_CLIENT_HELLO | |
| TLS_TX_CERTIFICATE | |
| TLS_TX_CLIENT_KEY_EXCHANGE | |
| TLS_TX_CERTIFICATE_VERIFY | |
| TLS_TX_CHANGE_CIPHER | |
| TLS_TX_FINISHED | |
Definition at line 218 of file tls.h.
| FILE_LICENCE | ( | GPL2_OR_LATER_OR_UBDL | ) |
| FILE_SECBOOT | ( | PERMITTED | ) |
|
extern |
Add TLS on an interface.
| xfer | Data transfer interface |
| name | Host name |
| root | Root of trust (or NULL to use default) |
| key | Private key (or NULL to use default) |
| rc | Return status code |
Definition at line 4628 of file tls.c.
References tls_connection::channel, channel_close(), channel_init(), channel_open(), tls_rx::cipherspec, tls_tx::cipherspec, tls_connection::cipherstream, tls_connection::client, tls_session::conn, tls_rx::data, ENOMEM, free_tls(), tls_connection::group, tls_rx::header, INIT_LIST_HEAD, intf_init(), intf_insert(), iob_populate(), tls_rx::iobuf, key, tls_client::key, tls_connection::legacy_version, tls_connection::list, list_add_tail, malloc(), memset(), name, tls_cipherspec::pipe, tls_connection::plainstream, privkey_get(), tls_tx::process, process_init_stopped(), rc, ref_init, ref_put, tls_connection::refcnt, root, tls_server::root, root_certificates, secure_channel::rx, tls_connection::rx, tls_connection::server, tls_connection::session, tls_cipherspec::suite, tls_connection::suite, table_start, tls_channel_ops, tls_cipher_suite_null, tls_cipherstream_desc, tls_clear_digest(), TLS_LEGACY_VERSION_MAX, TLS_NAMED_GROUPS, tls_plainstream_desc, tls_process_desc, tls_restart(), tls_validator_desc, TLS_VERSION_MAX, secure_channel::tx, tls_connection::tx, tls_server::validator, tls_connection::version, tls_cipherspec::writer, and x509_root_get().
Referenced by apply_syslogs_settings(), https_filter(), ipair_rx_session(), and REQUIRING_SYMBOL().
|
extern |
Classic pre-master secret key exchange algorithm.
Definition at line 101 of file tlsclassic.c.
|
extern |
Null key exchange algorithm.
Definition at line 1125 of file tls.c.
Referenced by __tls_cipher_suite(), __tls_cipher_suite(), and tls_cipher_name().
|
extern |
Public key exchange algorithm.
Definition at line 1138 of file tls.c.
Referenced by __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), and tls_cipher_name().
|
extern |
Ephemeral Diffie-Hellman key exchange algorithm.
Definition at line 1186 of file tls.c.
Referenced by __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), and __tls_cipher_suite().
|
extern |
Ephemeral Elliptic Curve Diffie-Hellman key exchange algorithm.
Definition at line 1241 of file tls.c.
Referenced by __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), and __tls_cipher_suite().