iPXE
tls.h File Reference

Transport Layer Security Protocol. More...

#include <stdint.h>
#include <ipxe/refcnt.h>
#include <ipxe/interface.h>
#include <ipxe/process.h>
#include <ipxe/crypto.h>
#include <ipxe/x509.h>
#include <ipxe/privkey.h>
#include <ipxe/pending.h>
#include <ipxe/iobuf.h>
#include <ipxe/tables.h>
#include <ipxe/channel.h>
#include <ipxe/tlskey.h>
#include <ipxe/tlsfmt.h>

Go to the source code of this file.

Data Structures

struct  tls_header
 A TLS header. More...
union  tls_handshake_header
 A TLS handshake header. More...
union  tls_server_random
 TLS server random data. More...
struct  tls_auth_header
 TLS authentication header. More...
struct  tls_key_exchange_parameters
 TLS key exchange parameters. More...
struct  tls_key_exchange_algorithm
 A TLS key exchange algorithm. More...
struct  tls_cipher_suite
 A TLS cipher suite. More...
struct  tls_named_group
 A TLS named group. More...
struct  tls_cipherspec
 A TLS cipher specification. More...
struct  tls_signature_hash_algorithm
 A TLS signature algorithm. More...
struct  tls_session_id
 A TLS session ID. More...
struct  tls_session
 A TLS session. More...
struct  tls_verify_data
 TLS verification data. More...
struct  tls_tx
 TLS transmit state. More...
struct  tls_rx
 TLS receive state. More...
struct  tls_client
 TLS client state. More...
struct  tls_server
 TLS server state. More...
struct  tls_connection
 A TLS connection. More...

Macros

#define TLS_HANDSHAKE_LEN(type_len)
 Get TLS handshake length.
#define TLS_SERVER_DOWNGRADE_MAGIC   "DOWNGRD"
 TLS server downgrade detection magic signature.
#define TLS_TYPE_CHANGE_CIPHER   20
 Change cipher content type.
#define TLS_CHANGE_CIPHER_SPEC   1
 Change cipher spec magic byte.
#define TLS_TYPE_ALERT   21
 Alert content type.
#define TLS_TYPE_HANDSHAKE   22
 Handshake content type.
#define TLS_TYPE_DATA   23
 Application data content type.
#define TLS_HELLO_REQUEST   0
#define TLS_CLIENT_HELLO   1
#define TLS_SERVER_HELLO   2
#define TLS_NEW_SESSION_TICKET   4
#define TLS_CERTIFICATE   11
#define TLS_SERVER_KEY_EXCHANGE   12
#define TLS_CERTIFICATE_REQUEST   13
#define TLS_SERVER_HELLO_DONE   14
#define TLS_CERTIFICATE_VERIFY   15
#define TLS_CLIENT_KEY_EXCHANGE   16
#define TLS_FINISHED   20
#define TLS_ALERT_WARNING   1
#define TLS_ALERT_FATAL   2
#define TLS_ALERT_CLOSE_NOTIFY   0
#define TLS_RSA_WITH_NULL_MD5   0x0001
#define TLS_RSA_WITH_NULL_SHA   0x0002
#define TLS_RSA_WITH_AES_128_CBC_SHA   0x002f
#define TLS_DHE_RSA_WITH_AES_128_CBC_SHA   0x0033
#define TLS_RSA_WITH_AES_256_CBC_SHA   0x0035
#define TLS_DHE_RSA_WITH_AES_256_CBC_SHA   0x0039
#define TLS_RSA_WITH_AES_128_CBC_SHA256   0x003c
#define TLS_RSA_WITH_AES_256_CBC_SHA256   0x003d
#define TLS_DHE_RSA_WITH_AES_128_CBC_SHA256   0x0067
#define TLS_DHE_RSA_WITH_AES_256_CBC_SHA256   0x006b
#define TLS_RSA_WITH_AES_128_GCM_SHA256   0x009c
#define TLS_RSA_WITH_AES_256_GCM_SHA384   0x009d
#define TLS_DHE_RSA_WITH_AES_128_GCM_SHA256   0x009e
#define TLS_DHE_RSA_WITH_AES_256_GCM_SHA384   0x009f
#define TLS_AES_128_GCM_SHA256   0x1301
#define TLS_AES_256_GCM_SHA384   0x1302
#define TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA   0xc009
#define TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA   0xc00a
#define TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA   0xc013
#define TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA   0xc014
#define TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256   0xc023
#define TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384   0xc024
#define TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256   0xc027
#define TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384   0xc028
#define TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256   0xc02b
#define TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   0xc02c
#define TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   0xc02f
#define TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   0xc030
#define TLS_RSA_SHA1_ALGORITHM   0x0201
#define TLS_RSA_SHA224_ALGORITHM   0x0301
#define TLS_ECDSA_SHA224_ALGORITHM   0x0303
#define TLS_RSA_SHA256_ALGORITHM   0x0401
#define TLS_ECDSA_SHA256_ALGORITHM   0x0403
#define TLS_RSA_SHA384_ALGORITHM   0x0501
#define TLS_ECDSA_SHA384_ALGORITHM   0x0503
#define TLS_RSA_SHA512_ALGORITHM   0x0601
#define TLS_ECDSA_SHA512_ALGORITHM   0x0603
#define TLS_RSA_PSS_RSAE_SHA256_ALGORITHM   0x0804
#define TLS_RSA_PSS_RSAE_SHA384_ALGORITHM   0x0805
#define TLS_RSA_PSS_RSAE_SHA512_ALGORITHM   0x0806
#define TLS_RSA_PSS_PSS_SHA256_ALGORITHM   0x0809
#define TLS_RSA_PSS_PSS_SHA384_ALGORITHM   0x080a
#define TLS_RSA_PSS_PSS_SHA512_ALGORITHM   0x080b
#define TLS_SERVER_NAME   0
#define TLS_SERVER_NAME_HOST_NAME   0
#define TLS_MAX_FRAGMENT_LENGTH   1
#define TLS_MAX_FRAGMENT_LENGTH_512   1
#define TLS_MAX_FRAGMENT_LENGTH_1024   2
#define TLS_MAX_FRAGMENT_LENGTH_2048   3
#define TLS_MAX_FRAGMENT_LENGTH_4096   4
#define TLS_NAMED_GROUP   10
#define TLS_NAMED_GROUP_SECP256R1   23
#define TLS_NAMED_GROUP_SECP384R1   24
#define TLS_NAMED_GROUP_X25519   29
#define TLS_NAMED_GROUP_FFDHE2048   256
#define TLS_NAMED_GROUP_FFDHE3072   257
#define TLS_NAMED_GROUP_FFDHE4096   258
#define TLS_SIGNATURE_ALGORITHMS   13
#define TLS_EXTENDED_MASTER_SECRET   23
#define TLS_RECORD_SIZE_LIMIT   28
#define TLS_SESSION_TICKET   35
#define TLS_SUPPORTED_VERSIONS   43
#define TLS_COOKIE   44
#define TLS_PSK_MODES   45
#define TLS_KEY_SHARE   51
#define TLS_RENEGOTIATION_INFO   0xff01
#define TLS_CIPHER_FL_SEQUENTIAL_IV   0x01
 Cipher XORs sequence number into the initialisation vector.
#define TLS_CIPHER_SUITES   __table ( struct tls_cipher_suite, "tls_cipher_suites" )
 TLS cipher suite table.
#define __tls_cipher_suite(pref)
 Declare a TLS cipher suite.
#define TLS_NAMED_CURVE_TYPE   3
 TLS named curve type.
#define TLS_NAMED_GROUPS   __table ( struct tls_named_group, "tls_named_groups" )
 TLS named group table.
#define __tls_named_group(pref)
 Declare a TLS named group.
#define __tls_anon_named_group   __tls_named_group ( 98 )
 Declare a TLS anonymous named group.
#define TLS_NUM_NAMED_GROUPS
 Number of non-anonymous TLS named groups.
#define TLS_SIG_HASH_ALGORITHMS
 TLS signature hash algorithm table.
#define __tls_sig_hash_algorithm   __table_entry ( TLS_SIG_HASH_ALGORITHMS, 01 )
 Declare a TLS signature hash algorithm.
#define TLS_MAX_FRAGMENT_LENGTH_VALUE   TLS_MAX_FRAGMENT_LENGTH_4096
 Advertised maximum fragment length.
#define TLS_TX_BUFSIZE   4096
 TX maximum fragment length.
#define TLS_RX_BUFSIZE   4096
 RX I/O buffer size.
#define TLS_RX_MIN_BUFSIZE   512
 Minimum RX I/O buffer size.
#define TLS_RX_ALIGN   16
 RX I/O buffer alignment.

Enumerations

enum  tls_rx_state { TLS_RX_HEADER = 0 , TLS_RX_DATA }
 TLS RX state machine state. More...
enum  tls_tx_pending {
  TLS_TX_CLIENT_HELLO = 0x0001 , TLS_TX_CERTIFICATE = 0x0002 , TLS_TX_CLIENT_KEY_EXCHANGE = 0x0004 , TLS_TX_CERTIFICATE_VERIFY = 0x0008 ,
  TLS_TX_CHANGE_CIPHER = 0x0010 , TLS_TX_FINISHED = 0x0020
}
 TLS TX pending flags. More...

Functions

 FILE_LICENCE (GPL2_OR_LATER_OR_UBDL)
 FILE_SECBOOT (PERMITTED)
int add_tls (struct interface *xfer, const char *name, struct x509_root *root, struct private_key *key)
 Add TLS on an interface.

Variables

struct exchange_algorithm tls_classic_pre_master_algorithm
 Classic pre-master secret key exchange algorithm.
struct tls_key_exchange_algorithm tls_null_exchange_algorithm
 Null key exchange algorithm.
struct tls_key_exchange_algorithm tls_pubkey_exchange_algorithm
 Public key exchange algorithm.
struct tls_key_exchange_algorithm tls_dhe_exchange_algorithm
 Ephemeral Diffie-Hellman key exchange algorithm.
struct tls_key_exchange_algorithm tls_ecdhe_exchange_algorithm
 Ephemeral Elliptic Curve Diffie-Hellman key exchange algorithm.

Detailed Description

Transport Layer Security Protocol.

Definition in file tls.h.

Macro Definition Documentation

◆ TLS_HANDSHAKE_LEN

#define TLS_HANDSHAKE_LEN ( type_len)
Value:
( ntohl (type_len) & 0xffffff )
#define ntohl(value)
Definition byteswap.h:135
uint16_t type_len
Type and length.
Definition lldp.h:1

Get TLS handshake length.

Definition at line 54 of file tls.h.

Referenced by tls_new_handshake().

◆ TLS_SERVER_DOWNGRADE_MAGIC

#define TLS_SERVER_DOWNGRADE_MAGIC   "DOWNGRD"

TLS server downgrade detection magic signature.

Definition at line 72 of file tls.h.

◆ TLS_TYPE_CHANGE_CIPHER

#define TLS_TYPE_CHANGE_CIPHER   20

Change cipher content type.

Definition at line 75 of file tls.h.

Referenced by tls_new_ciphertext(), tls_new_record(), and tls_send_change_cipher().

◆ TLS_CHANGE_CIPHER_SPEC

#define TLS_CHANGE_CIPHER_SPEC   1

Change cipher spec magic byte.

Definition at line 78 of file tls.h.

Referenced by tls_new_change_cipher(), and tls_send_change_cipher().

◆ TLS_TYPE_ALERT

#define TLS_TYPE_ALERT   21

Alert content type.

Definition at line 81 of file tls.h.

Referenced by tls_new_record(), and tls_send_alert().

◆ TLS_TYPE_HANDSHAKE

#define TLS_TYPE_HANDSHAKE   22

Handshake content type.

Definition at line 84 of file tls.h.

Referenced by tls_new_record(), tls_send_handshake(), and tls_send_record().

◆ TLS_TYPE_DATA

#define TLS_TYPE_DATA   23

Application data content type.

Definition at line 87 of file tls.h.

Referenced by tls_extract_inner(), tls_new_record(), tls_plainstream_deliver(), and tls_send_record().

◆ TLS_HELLO_REQUEST

#define TLS_HELLO_REQUEST   0

Definition at line 90 of file tls.h.

Referenced by tls_new_handshake().

◆ TLS_CLIENT_HELLO

#define TLS_CLIENT_HELLO   1

Definition at line 91 of file tls.h.

Referenced by tls_client_hello().

◆ TLS_SERVER_HELLO

#define TLS_SERVER_HELLO   2

Definition at line 92 of file tls.h.

Referenced by tls_new_handshake().

◆ TLS_NEW_SESSION_TICKET

#define TLS_NEW_SESSION_TICKET   4

Definition at line 93 of file tls.h.

Referenced by tls_new_handshake().

◆ TLS_CERTIFICATE

#define TLS_CERTIFICATE   11

Definition at line 94 of file tls.h.

Referenced by tls_new_handshake(), and tls_send_certificate().

◆ TLS_SERVER_KEY_EXCHANGE

#define TLS_SERVER_KEY_EXCHANGE   12

Definition at line 95 of file tls.h.

Referenced by tls_new_handshake().

◆ TLS_CERTIFICATE_REQUEST

#define TLS_CERTIFICATE_REQUEST   13

Definition at line 96 of file tls.h.

Referenced by tls_new_handshake().

◆ TLS_SERVER_HELLO_DONE

#define TLS_SERVER_HELLO_DONE   14

Definition at line 97 of file tls.h.

Referenced by tls_new_handshake().

◆ TLS_CERTIFICATE_VERIFY

#define TLS_CERTIFICATE_VERIFY   15

Definition at line 98 of file tls.h.

Referenced by tls_new_handshake(), and tls_send_certificate_verify().

◆ TLS_CLIENT_KEY_EXCHANGE

#define TLS_CLIENT_KEY_EXCHANGE   16

Definition at line 99 of file tls.h.

Referenced by tls_send_client_key_exchange().

◆ TLS_FINISHED

#define TLS_FINISHED   20

Definition at line 100 of file tls.h.

Referenced by tls_new_handshake(), and tls_send_finished().

◆ TLS_ALERT_WARNING

#define TLS_ALERT_WARNING   1

Definition at line 103 of file tls.h.

Referenced by tls_close_alert(), and tls_new_alert().

◆ TLS_ALERT_FATAL

#define TLS_ALERT_FATAL   2

Definition at line 104 of file tls.h.

Referenced by tls_new_alert().

◆ TLS_ALERT_CLOSE_NOTIFY

#define TLS_ALERT_CLOSE_NOTIFY   0

Definition at line 107 of file tls.h.

Referenced by tls_close_alert(), and tls_new_alert().

◆ TLS_RSA_WITH_NULL_MD5

#define TLS_RSA_WITH_NULL_MD5   0x0001

Definition at line 110 of file tls.h.

◆ TLS_RSA_WITH_NULL_SHA

#define TLS_RSA_WITH_NULL_SHA   0x0002

Definition at line 111 of file tls.h.

◆ TLS_RSA_WITH_AES_128_CBC_SHA

#define TLS_RSA_WITH_AES_128_CBC_SHA   0x002f

Definition at line 112 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_DHE_RSA_WITH_AES_128_CBC_SHA

#define TLS_DHE_RSA_WITH_AES_128_CBC_SHA   0x0033

Definition at line 113 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_RSA_WITH_AES_256_CBC_SHA

#define TLS_RSA_WITH_AES_256_CBC_SHA   0x0035

Definition at line 114 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_DHE_RSA_WITH_AES_256_CBC_SHA

#define TLS_DHE_RSA_WITH_AES_256_CBC_SHA   0x0039

Definition at line 115 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_RSA_WITH_AES_128_CBC_SHA256

#define TLS_RSA_WITH_AES_128_CBC_SHA256   0x003c

Definition at line 116 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_RSA_WITH_AES_256_CBC_SHA256

#define TLS_RSA_WITH_AES_256_CBC_SHA256   0x003d

Definition at line 117 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_DHE_RSA_WITH_AES_128_CBC_SHA256

#define TLS_DHE_RSA_WITH_AES_128_CBC_SHA256   0x0067

Definition at line 118 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_DHE_RSA_WITH_AES_256_CBC_SHA256

#define TLS_DHE_RSA_WITH_AES_256_CBC_SHA256   0x006b

Definition at line 119 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_RSA_WITH_AES_128_GCM_SHA256

#define TLS_RSA_WITH_AES_128_GCM_SHA256   0x009c

Definition at line 120 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_RSA_WITH_AES_256_GCM_SHA384

#define TLS_RSA_WITH_AES_256_GCM_SHA384   0x009d

Definition at line 121 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_DHE_RSA_WITH_AES_128_GCM_SHA256

#define TLS_DHE_RSA_WITH_AES_128_GCM_SHA256   0x009e

Definition at line 122 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_DHE_RSA_WITH_AES_256_GCM_SHA384

#define TLS_DHE_RSA_WITH_AES_256_GCM_SHA384   0x009f

Definition at line 123 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_AES_128_GCM_SHA256

#define TLS_AES_128_GCM_SHA256   0x1301

Definition at line 124 of file tls.h.

Referenced by __tls_cipher_suite(), and tlsfmt_test_exec().

◆ TLS_AES_256_GCM_SHA384

#define TLS_AES_256_GCM_SHA384   0x1302

Definition at line 125 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA

#define TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA   0xc009

Definition at line 126 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA

#define TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA   0xc00a

Definition at line 127 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA

#define TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA   0xc013

Definition at line 128 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA

#define TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA   0xc014

Definition at line 129 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256

#define TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256   0xc023

Definition at line 130 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384

#define TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384   0xc024

Definition at line 131 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

#define TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256   0xc027

Definition at line 132 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384

#define TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384   0xc028

Definition at line 133 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256

#define TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256   0xc02b

Definition at line 134 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384

#define TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   0xc02c

Definition at line 135 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

#define TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   0xc02f

Definition at line 136 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

#define TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   0xc030

Definition at line 137 of file tls.h.

Referenced by __tls_cipher_suite().

◆ TLS_RSA_SHA1_ALGORITHM

#define TLS_RSA_SHA1_ALGORITHM   0x0201

Definition at line 140 of file tls.h.

Referenced by tlsfmt_test_exec().

◆ TLS_RSA_SHA224_ALGORITHM

#define TLS_RSA_SHA224_ALGORITHM   0x0301

Definition at line 141 of file tls.h.

◆ TLS_ECDSA_SHA224_ALGORITHM

#define TLS_ECDSA_SHA224_ALGORITHM   0x0303

Definition at line 142 of file tls.h.

◆ TLS_RSA_SHA256_ALGORITHM

#define TLS_RSA_SHA256_ALGORITHM   0x0401

Definition at line 143 of file tls.h.

◆ TLS_ECDSA_SHA256_ALGORITHM

#define TLS_ECDSA_SHA256_ALGORITHM   0x0403

Definition at line 144 of file tls.h.

◆ TLS_RSA_SHA384_ALGORITHM

#define TLS_RSA_SHA384_ALGORITHM   0x0501

Definition at line 145 of file tls.h.

◆ TLS_ECDSA_SHA384_ALGORITHM

#define TLS_ECDSA_SHA384_ALGORITHM   0x0503

Definition at line 146 of file tls.h.

◆ TLS_RSA_SHA512_ALGORITHM

#define TLS_RSA_SHA512_ALGORITHM   0x0601

Definition at line 147 of file tls.h.

◆ TLS_ECDSA_SHA512_ALGORITHM

#define TLS_ECDSA_SHA512_ALGORITHM   0x0603

Definition at line 148 of file tls.h.

◆ TLS_RSA_PSS_RSAE_SHA256_ALGORITHM

#define TLS_RSA_PSS_RSAE_SHA256_ALGORITHM   0x0804

Definition at line 149 of file tls.h.

◆ TLS_RSA_PSS_RSAE_SHA384_ALGORITHM

#define TLS_RSA_PSS_RSAE_SHA384_ALGORITHM   0x0805

Definition at line 150 of file tls.h.

◆ TLS_RSA_PSS_RSAE_SHA512_ALGORITHM

#define TLS_RSA_PSS_RSAE_SHA512_ALGORITHM   0x0806

Definition at line 151 of file tls.h.

◆ TLS_RSA_PSS_PSS_SHA256_ALGORITHM

#define TLS_RSA_PSS_PSS_SHA256_ALGORITHM   0x0809

Definition at line 152 of file tls.h.

◆ TLS_RSA_PSS_PSS_SHA384_ALGORITHM

#define TLS_RSA_PSS_PSS_SHA384_ALGORITHM   0x080a

Definition at line 153 of file tls.h.

◆ TLS_RSA_PSS_PSS_SHA512_ALGORITHM

#define TLS_RSA_PSS_PSS_SHA512_ALGORITHM   0x080b

Definition at line 154 of file tls.h.

◆ TLS_SERVER_NAME

#define TLS_SERVER_NAME   0

Definition at line 157 of file tls.h.

Referenced by TLS_DESCR_MAPPING().

◆ TLS_SERVER_NAME_HOST_NAME

#define TLS_SERVER_NAME_HOST_NAME   0

Definition at line 158 of file tls.h.

◆ TLS_MAX_FRAGMENT_LENGTH

#define TLS_MAX_FRAGMENT_LENGTH   1

Definition at line 161 of file tls.h.

Referenced by TLS_DESCR_MAPPING().

◆ TLS_MAX_FRAGMENT_LENGTH_512

#define TLS_MAX_FRAGMENT_LENGTH_512   1

Definition at line 162 of file tls.h.

◆ TLS_MAX_FRAGMENT_LENGTH_1024

#define TLS_MAX_FRAGMENT_LENGTH_1024   2

Definition at line 163 of file tls.h.

◆ TLS_MAX_FRAGMENT_LENGTH_2048

#define TLS_MAX_FRAGMENT_LENGTH_2048   3

Definition at line 164 of file tls.h.

◆ TLS_MAX_FRAGMENT_LENGTH_4096

#define TLS_MAX_FRAGMENT_LENGTH_4096   4

Definition at line 165 of file tls.h.

◆ TLS_NAMED_GROUP

#define TLS_NAMED_GROUP   10

Definition at line 168 of file tls.h.

Referenced by TLS_DESCR_MAPPING().

◆ TLS_NAMED_GROUP_SECP256R1

#define TLS_NAMED_GROUP_SECP256R1   23

Definition at line 169 of file tls.h.

Referenced by __tls_named_group().

◆ TLS_NAMED_GROUP_SECP384R1

#define TLS_NAMED_GROUP_SECP384R1   24

Definition at line 170 of file tls.h.

Referenced by __tls_named_group().

◆ TLS_NAMED_GROUP_X25519

#define TLS_NAMED_GROUP_X25519   29

Definition at line 171 of file tls.h.

Referenced by __tls_named_group(), and tlsfmt_test_exec().

◆ TLS_NAMED_GROUP_FFDHE2048

#define TLS_NAMED_GROUP_FFDHE2048   256

Definition at line 172 of file tls.h.

Referenced by __tls_named_group().

◆ TLS_NAMED_GROUP_FFDHE3072

#define TLS_NAMED_GROUP_FFDHE3072   257

Definition at line 173 of file tls.h.

Referenced by __tls_named_group().

◆ TLS_NAMED_GROUP_FFDHE4096

#define TLS_NAMED_GROUP_FFDHE4096   258

Definition at line 174 of file tls.h.

Referenced by __tls_named_group().

◆ TLS_SIGNATURE_ALGORITHMS

#define TLS_SIGNATURE_ALGORITHMS   13

Definition at line 177 of file tls.h.

Referenced by TLS_DESCR_MAPPING().

◆ TLS_EXTENDED_MASTER_SECRET

#define TLS_EXTENDED_MASTER_SECRET   23

Definition at line 180 of file tls.h.

Referenced by TLS_DESCR_MAPPING(), and TLS_DESCR_MAPPING().

◆ TLS_RECORD_SIZE_LIMIT

#define TLS_RECORD_SIZE_LIMIT   28

Definition at line 183 of file tls.h.

Referenced by TLS_DESCR_MAPPING().

◆ TLS_SESSION_TICKET

#define TLS_SESSION_TICKET   35

Definition at line 186 of file tls.h.

Referenced by TLS_DESCR_MAPPING().

◆ TLS_SUPPORTED_VERSIONS

#define TLS_SUPPORTED_VERSIONS   43

Definition at line 189 of file tls.h.

Referenced by TLS_DESCR_MAPPING(), TLS_DESCR_MAPPING(), and tlsfmt_test_exec().

◆ TLS_COOKIE

#define TLS_COOKIE   44

Definition at line 192 of file tls.h.

Referenced by TLS_DESCR_MAPPING(), and TLS_DESCR_MAPPING().

◆ TLS_PSK_MODES

#define TLS_PSK_MODES   45

Definition at line 195 of file tls.h.

Referenced by TLS_DESCR_MAPPING().

◆ TLS_KEY_SHARE

#define TLS_KEY_SHARE   51

Definition at line 198 of file tls.h.

Referenced by TLS_DESCR_MAPPING(), TLS_DESCR_MAPPING(), and tlsfmt_test_exec().

◆ TLS_RENEGOTIATION_INFO

#define TLS_RENEGOTIATION_INFO   0xff01

Definition at line 201 of file tls.h.

Referenced by TLS_DESCR_MAPPING(), TLS_DESCR_MAPPING(), and tlsfmt_test_exec().

◆ TLS_CIPHER_FL_SEQUENTIAL_IV

#define TLS_CIPHER_FL_SEQUENTIAL_IV   0x01

◆ TLS_CIPHER_SUITES

#define TLS_CIPHER_SUITES   __table ( struct tls_cipher_suite, "tls_cipher_suites" )

TLS cipher suite table.

Definition at line 297 of file tls.h.

297#define TLS_CIPHER_SUITES \
298 __table ( struct tls_cipher_suite, "tls_cipher_suites" )

Referenced by tls_client_hello(), and tls_find_cipher_suite().

◆ __tls_cipher_suite

#define __tls_cipher_suite ( pref)
Value:
#define __table_entry(table, idx)
Declare a linker table entry.
Definition tables.h:239
#define TLS_CIPHER_SUITES
TLS cipher suite table.
Definition tls.h:297

Declare a TLS cipher suite.

Definition at line 301 of file tls.h.

301#define __tls_cipher_suite( pref ) \
302 __table_entry ( TLS_CIPHER_SUITES, pref )

Referenced by __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), and __tls_cipher_suite().

◆ TLS_NAMED_CURVE_TYPE

#define TLS_NAMED_CURVE_TYPE   3

TLS named curve type.

Definition at line 305 of file tls.h.

Referenced by tls_parse_ecdhe(), and tlsfmt_test_exec().

◆ TLS_NAMED_GROUPS

#define TLS_NAMED_GROUPS   __table ( struct tls_named_group, "tls_named_groups" )

TLS named group table.

Definition at line 316 of file tls.h.

316#define TLS_NAMED_GROUPS \
317 __table ( struct tls_named_group, "tls_named_groups" )

Referenced by add_tls(), tls_client_hello(), tls_find_named_group(), and tls_find_param_group().

◆ __tls_named_group

#define __tls_named_group ( pref)
Value:
#define TLS_NAMED_GROUPS
TLS named group table.
Definition tls.h:316

Declare a TLS named group.

Definition at line 320 of file tls.h.

320#define __tls_named_group( pref ) \
321 __table_entry ( TLS_NAMED_GROUPS, pref )

Referenced by __tls_named_group(), __tls_named_group(), and __tls_named_group().

◆ __tls_anon_named_group

struct tls_named_group tls_pubkey_named_group __tls_anon_named_group   __tls_named_group ( 98 )

Declare a TLS anonymous named group.

Public key named group.

Definition at line 324 of file tls.h.

◆ TLS_NUM_NAMED_GROUPS

#define TLS_NUM_NAMED_GROUPS
Value:
( ( unsigned int ) \
#define __table_entries(table, idx)
Get start of linker table entries.
Definition tables.h:250
#define table_start(table)
Get start of linker table.
Definition tables.h:283

Number of non-anonymous TLS named groups.

Definition at line 327 of file tls.h.

327#define TLS_NUM_NAMED_GROUPS \
328 ( ( unsigned int ) \
329 ( __table_entries ( TLS_NAMED_GROUPS, 97 ) \
330 - table_start ( TLS_NAMED_GROUPS ) ) )

Referenced by tls_client_hello().

◆ TLS_SIG_HASH_ALGORITHMS

#define TLS_SIG_HASH_ALGORITHMS
Value:
"tls_sig_hash_algorithms" )
A TLS signature algorithm.
Definition tls.h:356
#define __table(type, name)
Declare a linker table.
Definition tables.h:180

TLS signature hash algorithm table.

Note that the default (TLSv1.1 and earlier) algorithm using MD5+SHA1 is never explicitly specified.

Definition at line 372 of file tls.h.

372#define TLS_SIG_HASH_ALGORITHMS \
373 __table ( struct tls_signature_hash_algorithm, \
374 "tls_sig_hash_algorithms" )

Referenced by tls_client_hello(), tls_find_signature_hash(), and tls_signature_hash_algorithm().

◆ __tls_sig_hash_algorithm

struct tls_signature_hash_algorithm tls_rsa_pss_pss_sha512 __tls_sig_hash_algorithm   __table_entry ( TLS_SIG_HASH_ALGORITHMS, 01 )

Declare a TLS signature hash algorithm.

RSA-PSS with RSASSA-PSS OID and SHA-512 signature hash algorithm.

RSA-PSS with rsaEncryption OID and SHA-512 signature hash algorithm.

RSA-PSS with RSASSA-PSS OID and SHA-384 signature hash algorithm.

RSA-PSS with rsaEncryption OID and SHA-384 signature hash algorithm.

RSA-PSS with RSASSA-PSS OID and SHA-256 signature hash algorithm.

RSA-PSS with rsaEncryption OID and SHA-256 signature hash algorithm.

Definition at line 377 of file tls.h.

377#define __tls_sig_hash_algorithm \
378 __table_entry ( TLS_SIG_HASH_ALGORITHMS, 01 )

◆ TLS_MAX_FRAGMENT_LENGTH_VALUE

#define TLS_MAX_FRAGMENT_LENGTH_VALUE   TLS_MAX_FRAGMENT_LENGTH_4096

Advertised maximum fragment length.

Definition at line 528 of file tls.h.

Referenced by tls_client_hello().

◆ TLS_TX_BUFSIZE

#define TLS_TX_BUFSIZE   4096

TX maximum fragment length.

TLS requires us to limit our transmitted records to the maximum fragment length that we attempt to negotiate, even if the server does not respect this choice.

Definition at line 536 of file tls.h.

Referenced by tls_iob_reserved(), and tls_send_record().

◆ TLS_RX_BUFSIZE

#define TLS_RX_BUFSIZE   4096

RX I/O buffer size.

The maximum fragment length extension is optional, and many common implementations (including OpenSSL) do not support it. We must therefore be prepared to receive records of up to 16kB in length. The chance of an allocation of this size failing is non-negligible, so we must split received data into smaller allocations.

Definition at line 546 of file tls.h.

Referenced by tls_new_ciphertext(), and tls_newdata_process_header().

◆ TLS_RX_MIN_BUFSIZE

#define TLS_RX_MIN_BUFSIZE   512

Minimum RX I/O buffer size.

To simplify manipulations, we ensure that no RX I/O buffer is smaller than this size. This allows us to assume that the MAC and padding are entirely contained within the final I/O buffer.

Definition at line 554 of file tls.h.

Referenced by tls_newdata_process_header().

◆ TLS_RX_ALIGN

#define TLS_RX_ALIGN   16

RX I/O buffer alignment.

Definition at line 557 of file tls.h.

Referenced by tls_newdata_process_header().

Enumeration Type Documentation

◆ tls_rx_state

TLS RX state machine state.

Enumerator
TLS_RX_HEADER 
TLS_RX_DATA 

Definition at line 212 of file tls.h.

212 {
213 TLS_RX_HEADER = 0,
215};
@ TLS_RX_HEADER
Definition tls.h:213
@ TLS_RX_DATA
Definition tls.h:214

◆ tls_tx_pending

TLS TX pending flags.

Enumerator
TLS_TX_CLIENT_HELLO 
TLS_TX_CERTIFICATE 
TLS_TX_CLIENT_KEY_EXCHANGE 
TLS_TX_CERTIFICATE_VERIFY 
TLS_TX_CHANGE_CIPHER 
TLS_TX_FINISHED 

Definition at line 218 of file tls.h.

218 {
219 TLS_TX_CLIENT_HELLO = 0x0001,
220 TLS_TX_CERTIFICATE = 0x0002,
223 TLS_TX_CHANGE_CIPHER = 0x0010,
224 TLS_TX_FINISHED = 0x0020,
225};
@ TLS_TX_FINISHED
Definition tls.h:224
@ TLS_TX_CLIENT_KEY_EXCHANGE
Definition tls.h:221
@ TLS_TX_CLIENT_HELLO
Definition tls.h:219
@ TLS_TX_CHANGE_CIPHER
Definition tls.h:223
@ TLS_TX_CERTIFICATE_VERIFY
Definition tls.h:222
@ TLS_TX_CERTIFICATE
Definition tls.h:220

Function Documentation

◆ FILE_LICENCE()

FILE_LICENCE ( GPL2_OR_LATER_OR_UBDL )

◆ FILE_SECBOOT()

FILE_SECBOOT ( PERMITTED )

◆ add_tls()

int add_tls ( struct interface * xfer,
const char * name,
struct x509_root * root,
struct private_key * key )
extern

Add TLS on an interface.

Parameters
xferData transfer interface
nameHost name
rootRoot of trust (or NULL to use default)
keyPrivate key (or NULL to use default)
Return values
rcReturn status code

Definition at line 4628 of file tls.c.

4629 {
4630 struct tls_connection *tls;
4631 int rc;
4632
4633 /* Allocate and initialise TLS structure */
4634 tls = malloc ( sizeof ( *tls ) );
4635 if ( ! tls ) {
4636 rc = -ENOMEM;
4637 goto err_alloc;
4638 }
4639 memset ( tls, 0, sizeof ( *tls ) );
4640 ref_init ( &tls->refcnt, free_tls );
4641 INIT_LIST_HEAD ( &tls->list );
4646 &tls->refcnt );
4647 tls->client.key = privkey_get ( key ? key : &private_key );
4649 tls->version = TLS_VERSION_MAX;
4654 tls_clear_digest ( tls );
4657 tls->tx.cipherspec.pipe = &tls->channel.tx;
4660 tls->rx.cipherspec.pipe = &tls->channel.rx;
4661 iob_populate ( &tls->rx.iobuf, &tls->rx.header, 0,
4662 sizeof ( tls->rx.header ) );
4663 INIT_LIST_HEAD ( &tls->rx.data );
4664
4665 /* Open secure channel */
4666 if ( ( rc = channel_open ( &tls->channel ) ) != 0 )
4667 goto err_channel;
4668
4669 /* Find or create session */
4670 if ( ( rc = tls_session ( tls, name ) ) != 0 )
4671 goto err_session;
4672 list_add_tail ( &tls->list, &tls->session->conn );
4673
4674 /* Start negotiation */
4675 tls_restart ( tls );
4676
4677 /* Attach to parent interface, mortalise self, and return */
4678 intf_insert ( xfer, &tls->plainstream, &tls->cipherstream );
4679 ref_put ( &tls->refcnt );
4680 return 0;
4681
4682 err_session:
4683 channel_close ( &tls->channel );
4684 err_channel:
4685 ref_put ( &tls->refcnt );
4686 err_alloc:
4687 return rc;
4688}
union @162305117151260234136356364136041353210355154177 key
struct arbelprm_rc_send_wqe rc
Definition arbel.h:3
const char * name
Definition ath9k_hw.c:1986
int channel_open(struct secure_channel *channel)
Open secure channel.
Definition channel.c:1205
void channel_close(struct secure_channel *channel)
Close secure channel.
Definition channel.c:1301
static void channel_init(struct secure_channel *channel, struct secure_channel_operations *op)
Initialise secure channel.
Definition channel.h:256
#define TLS_VERSION_MAX
Maximum TLS version.
Definition crypto.h:17
#define ENOMEM
Not enough space.
Definition errno.h:578
void * memset(void *dest, int character, size_t len) __nonnull
void intf_insert(struct interface *intf, struct interface *upper, struct interface *lower)
Insert a filter interface.
Definition interface.c:402
static void intf_init(struct interface *intf, struct interface_descriptor *desc, struct refcnt *refcnt)
Initialise an object interface.
Definition interface.h:204
static void iob_populate(struct io_buffer *iobuf, void *data, size_t len, size_t max_len)
Create a temporary I/O buffer.
Definition iobuf.h:255
#define list_add_tail(new, head)
Add a new entry to the tail of a list.
Definition list.h:94
#define INIT_LIST_HEAD(list)
Initialise a list head.
Definition list.h:46
void * malloc(size_t size)
Allocate memory.
Definition malloc.c:677
static struct private_key * privkey_get(struct private_key *key)
Get reference to private key.
Definition privkey.h:31
static void process_init_stopped(struct process *process, struct process_descriptor *desc, struct refcnt *refcnt)
Initialise process without adding to process list.
Definition process.h:146
#define ref_put(refcnt)
Drop reference to object.
Definition refcnt.h:107
#define ref_init(refcnt, free)
Initialise a reference counter.
Definition refcnt.h:65
struct x509_root root_certificates
Root certificates.
Definition rootcert.c:79
struct stp_switch root
Root switch.
Definition stp.h:15
A private key.
Definition privkey.h:17
struct secure_pipe tx
Transmit pipe.
Definition channel.h:82
struct secure_pipe rx
Receive pipe.
Definition channel.h:84
const struct tls_endpoint * writer
Writer endpoint.
Definition tls.h:337
struct tls_cipher_suite * suite
Cipher suite.
Definition tls.h:335
struct secure_pipe * pipe
Secure pipe.
Definition tls.h:339
TLS client state.
Definition tls.h:454
struct private_key * key
Private key.
Definition tls.h:456
A TLS connection.
Definition tls.h:478
struct tls_named_group * group
Key exchange named group.
Definition tls.h:503
struct interface cipherstream
Ciphertext stream.
Definition tls.h:494
struct tls_session * session
Session.
Definition tls.h:483
struct tls_server server
Server state.
Definition tls.h:524
struct tls_rx rx
Receive state.
Definition tls.h:520
struct secure_channel channel
Secure channel.
Definition tls.h:514
struct interface plainstream
Plaintext stream.
Definition tls.h:492
struct tls_tx tx
Transmit state.
Definition tls.h:518
struct tls_cipher_suite * suite
Cipher suite.
Definition tls.h:501
struct list_head list
List of connections within the same session.
Definition tls.h:485
struct tls_client client
Client state.
Definition tls.h:522
uint16_t version
Protocol version.
Definition tls.h:497
uint16_t legacy_version
Legacy protocol version.
Definition tls.h:499
struct refcnt refcnt
Reference counter.
Definition tls.h:480
struct list_head data
List of received data buffers.
Definition tls.h:448
struct io_buffer iobuf
Current received record header (static I/O buffer).
Definition tls.h:446
struct tls_cipherspec cipherspec
Cipher specification.
Definition tls.h:440
struct tls_header header
Current received record header.
Definition tls.h:444
TLS server state.
Definition tls.h:464
struct interface validator
Certificate validator.
Definition tls.h:470
struct x509_root * root
Root of trust.
Definition tls.h:466
A TLS session.
Definition tls.h:389
struct list_head conn
List of connections.
Definition tls.h:412
struct tls_cipherspec cipherspec
Cipher specification.
Definition tls.h:430
struct process process
Transmit process.
Definition tls.h:434
static struct interface_descriptor tls_cipherstream_desc
TLS ciphertext stream interface descriptor.
Definition tls.c:4420
static void tls_clear_digest(struct tls_connection *tls)
Clear key schedule digest algorithm.
Definition tls.c:549
static struct secure_channel_operations tls_channel_ops
Secure channel operations.
Definition tls.c:1681
static struct interface_descriptor tls_validator_desc
TLS certificate validator interface descriptor.
Definition tls.c:4507
static struct interface_descriptor tls_plainstream_desc
TLS plaintext stream interface descriptor.
Definition tls.c:4205
static void free_tls(struct refcnt *refcnt)
Free TLS connection.
Definition tls.c:412
static void tls_restart(struct tls_connection *tls)
Restart negotiation.
Definition tls.c:1875
struct tls_cipher_suite tls_cipher_suite_null
Null cipher suite.
Definition tls.c:618
static struct process_descriptor tls_process_desc
TLS TX process descriptor.
Definition tls.c:4609
#define TLS_LEGACY_VERSION_MAX
Maximum pre-TLSv1.3 version.
Definition tls.c:247
static struct x509_root * x509_root_get(struct x509_root *root)
Get reference to X.509 root certificate list.
Definition x509.h:393

References tls_connection::channel, channel_close(), channel_init(), channel_open(), tls_rx::cipherspec, tls_tx::cipherspec, tls_connection::cipherstream, tls_connection::client, tls_session::conn, tls_rx::data, ENOMEM, free_tls(), tls_connection::group, tls_rx::header, INIT_LIST_HEAD, intf_init(), intf_insert(), iob_populate(), tls_rx::iobuf, key, tls_client::key, tls_connection::legacy_version, tls_connection::list, list_add_tail, malloc(), memset(), name, tls_cipherspec::pipe, tls_connection::plainstream, privkey_get(), tls_tx::process, process_init_stopped(), rc, ref_init, ref_put, tls_connection::refcnt, root, tls_server::root, root_certificates, secure_channel::rx, tls_connection::rx, tls_connection::server, tls_connection::session, tls_cipherspec::suite, tls_connection::suite, table_start, tls_channel_ops, tls_cipher_suite_null, tls_cipherstream_desc, tls_clear_digest(), TLS_LEGACY_VERSION_MAX, TLS_NAMED_GROUPS, tls_plainstream_desc, tls_process_desc, tls_restart(), tls_validator_desc, TLS_VERSION_MAX, secure_channel::tx, tls_connection::tx, tls_server::validator, tls_connection::version, tls_cipherspec::writer, and x509_root_get().

Referenced by apply_syslogs_settings(), https_filter(), ipair_rx_session(), and REQUIRING_SYMBOL().

Variable Documentation

◆ tls_classic_pre_master_algorithm

struct exchange_algorithm tls_classic_pre_master_algorithm
extern

Classic pre-master secret key exchange algorithm.

Definition at line 101 of file tlsclassic.c.

101 {
102 .name = "classic pre-master",
103 .privsize = sizeof ( struct tls_classic_pre_master_private ),
104 .pubsize = 0,
105 .sharedsize = sizeof ( struct tls_classic_pre_master_shared ),
106 .share = exchange_null_share,
108};
int exchange_null_share(struct exchange_algorithm *exchange __unused, const void *private __unused, void *public __unused)
A classic pre-master private key.
Definition tlsclassic.c:62
A classic pre-master shared secret.
Definition tlsclassic.c:68
static int tls_classic_pre_master_agree(struct exchange_algorithm *exchange __unused, const void *private, const void *partner __unused, void *shared)
Agree classic pre-master secret.
Definition tlsclassic.c:85

◆ tls_null_exchange_algorithm

struct tls_key_exchange_algorithm tls_null_exchange_algorithm
extern

Null key exchange algorithm.

Definition at line 1125 of file tls.c.

1125 {
1126 .name = "null",
1127 .group = &tls_null_named_group,
1128 .parse = tls_parse_null,
1129 .map = tls_client_key_exchange_pubkey_map,
1130};
static int tls_parse_null(struct tls_connection *tls, const struct tls_cursor *cursor, struct tls_key_exchange_parameters *kex __unused)
Parse key exchange parameters from unexpected Server Key Exchange record.
Definition tls.c:1111

Referenced by __tls_cipher_suite(), __tls_cipher_suite(), and tls_cipher_name().

◆ tls_pubkey_exchange_algorithm

struct tls_key_exchange_algorithm tls_pubkey_exchange_algorithm
extern

Public key exchange algorithm.

Definition at line 1138 of file tls.c.

1138 {
1139 .name = "pubkey",
1140 .group = &tls_pubkey_named_group,
1141 .parse = tls_parse_null,
1142 .map = tls_client_key_exchange_pubkey_map,
1143};

Referenced by __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), and tls_cipher_name().

◆ tls_dhe_exchange_algorithm

struct tls_key_exchange_algorithm tls_dhe_exchange_algorithm
extern

Ephemeral Diffie-Hellman key exchange algorithm.

Definition at line 1186 of file tls.c.

1186 {
1187 .name = "dhe",
1188 .group = &tls_null_named_group,
1189 .parse = tls_parse_dhe,
1190 .map = tls_client_key_exchange_dhe_map,
1191};
static int tls_parse_dhe(struct tls_connection *tls, const struct tls_cursor *cursor, struct tls_key_exchange_parameters *kex)
Parse key exchange parameters from DHE Server Key Exchange record.
Definition tls.c:1153

Referenced by __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), and __tls_cipher_suite().

◆ tls_ecdhe_exchange_algorithm

struct tls_key_exchange_algorithm tls_ecdhe_exchange_algorithm
extern

Ephemeral Elliptic Curve Diffie-Hellman key exchange algorithm.

Definition at line 1241 of file tls.c.

1241 {
1242 .name = "ecdhe",
1243 .group = &tls_null_named_group,
1244 .parse = tls_parse_ecdhe,
1245 .map = tls_client_key_exchange_ecdhe_map,
1246};
static int tls_parse_ecdhe(struct tls_connection *tls, const struct tls_cursor *cursor, struct tls_key_exchange_parameters *kex)
Parse key exchange parameters from ECDHE Server Key Exchange record.
Definition tls.c:1202

Referenced by __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), __tls_cipher_suite(), and __tls_cipher_suite().