54#define TLS_HANDSHAKE_LEN( type_len ) ( ntohl (type_len) & 0xffffff )
72#define TLS_SERVER_DOWNGRADE_MAGIC "DOWNGRD"
75#define TLS_TYPE_CHANGE_CIPHER 20
78#define TLS_CHANGE_CIPHER_SPEC 1
81#define TLS_TYPE_ALERT 21
84#define TLS_TYPE_HANDSHAKE 22
87#define TLS_TYPE_DATA 23
90#define TLS_HELLO_REQUEST 0
91#define TLS_CLIENT_HELLO 1
92#define TLS_SERVER_HELLO 2
93#define TLS_NEW_SESSION_TICKET 4
94#define TLS_CERTIFICATE 11
95#define TLS_SERVER_KEY_EXCHANGE 12
96#define TLS_CERTIFICATE_REQUEST 13
97#define TLS_SERVER_HELLO_DONE 14
98#define TLS_CERTIFICATE_VERIFY 15
99#define TLS_CLIENT_KEY_EXCHANGE 16
100#define TLS_FINISHED 20
103#define TLS_ALERT_WARNING 1
104#define TLS_ALERT_FATAL 2
107#define TLS_ALERT_CLOSE_NOTIFY 0
110#define TLS_RSA_WITH_NULL_MD5 0x0001
111#define TLS_RSA_WITH_NULL_SHA 0x0002
112#define TLS_RSA_WITH_AES_128_CBC_SHA 0x002f
113#define TLS_DHE_RSA_WITH_AES_128_CBC_SHA 0x0033
114#define TLS_RSA_WITH_AES_256_CBC_SHA 0x0035
115#define TLS_DHE_RSA_WITH_AES_256_CBC_SHA 0x0039
116#define TLS_RSA_WITH_AES_128_CBC_SHA256 0x003c
117#define TLS_RSA_WITH_AES_256_CBC_SHA256 0x003d
118#define TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 0x0067
119#define TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 0x006b
120#define TLS_RSA_WITH_AES_128_GCM_SHA256 0x009c
121#define TLS_RSA_WITH_AES_256_GCM_SHA384 0x009d
122#define TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 0x009e
123#define TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 0x009f
124#define TLS_AES_128_GCM_SHA256 0x1301
125#define TLS_AES_256_GCM_SHA384 0x1302
126#define TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA 0xc009
127#define TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA 0xc00a
128#define TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 0xc013
129#define TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 0xc014
130#define TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 0xc023
131#define TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 0xc024
132#define TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 0xc027
133#define TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 0xc028
134#define TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 0xc02b
135#define TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 0xc02c
136#define TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 0xc02f
137#define TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 0xc030
140#define TLS_RSA_SHA1_ALGORITHM 0x0201
141#define TLS_RSA_SHA224_ALGORITHM 0x0301
142#define TLS_ECDSA_SHA224_ALGORITHM 0x0303
143#define TLS_RSA_SHA256_ALGORITHM 0x0401
144#define TLS_ECDSA_SHA256_ALGORITHM 0x0403
145#define TLS_RSA_SHA384_ALGORITHM 0x0501
146#define TLS_ECDSA_SHA384_ALGORITHM 0x0503
147#define TLS_RSA_SHA512_ALGORITHM 0x0601
148#define TLS_ECDSA_SHA512_ALGORITHM 0x0603
149#define TLS_RSA_PSS_RSAE_SHA256_ALGORITHM 0x0804
150#define TLS_RSA_PSS_RSAE_SHA384_ALGORITHM 0x0805
151#define TLS_RSA_PSS_RSAE_SHA512_ALGORITHM 0x0806
152#define TLS_RSA_PSS_PSS_SHA256_ALGORITHM 0x0809
153#define TLS_RSA_PSS_PSS_SHA384_ALGORITHM 0x080a
154#define TLS_RSA_PSS_PSS_SHA512_ALGORITHM 0x080b
157#define TLS_SERVER_NAME 0
158#define TLS_SERVER_NAME_HOST_NAME 0
161#define TLS_MAX_FRAGMENT_LENGTH 1
162#define TLS_MAX_FRAGMENT_LENGTH_512 1
163#define TLS_MAX_FRAGMENT_LENGTH_1024 2
164#define TLS_MAX_FRAGMENT_LENGTH_2048 3
165#define TLS_MAX_FRAGMENT_LENGTH_4096 4
168#define TLS_NAMED_GROUP 10
169#define TLS_NAMED_GROUP_SECP256R1 23
170#define TLS_NAMED_GROUP_SECP384R1 24
171#define TLS_NAMED_GROUP_X25519 29
172#define TLS_NAMED_GROUP_FFDHE2048 256
173#define TLS_NAMED_GROUP_FFDHE3072 257
174#define TLS_NAMED_GROUP_FFDHE4096 258
177#define TLS_SIGNATURE_ALGORITHMS 13
180#define TLS_EXTENDED_MASTER_SECRET 23
183#define TLS_RECORD_SIZE_LIMIT 28
186#define TLS_SESSION_TICKET 35
189#define TLS_SUPPORTED_VERSIONS 43
195#define TLS_PSK_MODES 45
198#define TLS_KEY_SHARE 51
201#define TLS_RENEGOTIATION_INFO 0xff01
294#define TLS_CIPHER_FL_SEQUENTIAL_IV 0x01
297#define TLS_CIPHER_SUITES \
298 __table ( struct tls_cipher_suite, "tls_cipher_suites" )
301#define __tls_cipher_suite( pref ) \
302 __table_entry ( TLS_CIPHER_SUITES, pref )
305#define TLS_NAMED_CURVE_TYPE 3
316#define TLS_NAMED_GROUPS \
317 __table ( struct tls_named_group, "tls_named_groups" )
320#define __tls_named_group( pref ) \
321 __table_entry ( TLS_NAMED_GROUPS, pref )
324#define __tls_anon_named_group __tls_named_group ( 98 )
327#define TLS_NUM_NAMED_GROUPS \
329 ( __table_entries ( TLS_NAMED_GROUPS, 97 ) \
330 - table_start ( TLS_NAMED_GROUPS ) ) )
372#define TLS_SIG_HASH_ALGORITHMS \
373 __table ( struct tls_signature_hash_algorithm, \
374 "tls_sig_hash_algorithms" )
377#define __tls_sig_hash_algorithm \
378 __table_entry ( TLS_SIG_HASH_ALGORITHMS, 01 )
528#define TLS_MAX_FRAGMENT_LENGTH_VALUE TLS_MAX_FRAGMENT_LENGTH_4096
536#define TLS_TX_BUFSIZE 4096
546#define TLS_RX_BUFSIZE 4096
554#define TLS_RX_MIN_BUFSIZE 512
557#define TLS_RX_ALIGN 16
union @162305117151260234136356364136041353210355154177 key
unsigned long long uint64_t
Secure channel abstraction.
#define FILE_LICENCE(_licence)
Declare a particular licence as applying to a file.
#define FILE_SECBOOT(_status)
Declare a file's UEFI Secure Boot permission status.
struct stp_switch root
Root switch.
An ASN.1 OID-identified algorithm.
A message digest algorithm.
A key exchange algorithm.
A doubly-linked list entry (or list head).
A secure channel transmit or receive pipe.
A pre-shared bound peer identity.
uint8_t fixed_iv_len
Fixed initialisation vector length.
struct cipher_algorithm * cipher
Bulk encryption cipher algorithm.
struct pubkey_algorithm * pubkey
Public-key encryption algorithm.
uint8_t key_len
Key length.
uint8_t verify_len
Verification data length.
uint8_t mac_len
MAC length.
uint8_t record_iv_len
Record initialisation vector length.
struct digest_algorithm * digest
MAC digest algorithm.
struct tls_key_exchange_algorithm * exchange
Key exchange algorithm.
uint16_t code
Numeric code (in network-endian order).
struct digest_algorithm * handshake
Handshake digest algorithm (for TLSv1.2 and above).
A TLS cipher specification.
void * fixed_iv
Fixed initialisation vector.
uint64_t seq
Sequence number.
void * cipher_key
Cipher key.
const struct tls_endpoint * writer
Writer endpoint.
const struct tls_phase * pending
Pending traffic phase change.
struct tls_cipher_suite * suite
Cipher suite.
void * dynamic
Dynamically-allocated storage.
struct secure_pipe * pipe
Secure pipe.
void * mac_secret
MAC secret.
struct private_key * key
Private key.
struct x509_chain * chain
Certificate chain (if any).
struct pending_operation negotiation
Security negotiation pending operation.
struct tls_named_group * group
Key exchange named group.
struct interface cipherstream
Ciphertext stream.
struct tls_session * session
Session.
struct tls_server server
Server state.
struct tls_key_schedule key
Key schedule.
struct tls_rx rx
Receive state.
struct tls_verify_data verify
Verification data.
struct secure_channel channel
Secure channel.
struct interface plainstream
Plaintext stream.
struct tls_tx tx
Transmit state.
struct tls_cursor cookie
Cookie.
struct tls_cipher_suite * suite
Cipher suite.
int extended_master_secret
Extended master secret flag.
struct list_head list
List of connections within the same session.
struct tls_client client
Client state.
struct tls_cursor new_ticket
New session ticket (if any).
uint16_t version
Protocol version.
uint16_t legacy_version
Legacy protocol version.
struct tls_session_id new_id
New session ID (if any).
struct refcnt refcnt
Reference counter.
int secure_renegotiation
Secure renegotiation flag.
A TLS variable-length data cursor.
A TLS key exchange algorithm.
const char * name
Algorithm name.
struct tls_named_group * group
Default named group.
int(* parse)(struct tls_connection *tls, const struct tls_cursor *cursor, struct tls_key_exchange_parameters *kex)
Parse key exchange parameters from Server Key Exchange record.
const uint8_t * map
ClientKeyExchange descriptor mapping.
TLS key exchange parameters.
size_t len
Length of parameters (excluding trailing signature).
struct tls_named_group * group
Named group.
struct tls_cursor partner
Partner key.
uint16_t code
Numeric code (in network-endian order).
struct exchange_algorithm * exchange
Key exchange algorithm.
struct list_head data
List of received data buffers.
struct io_buffer iobuf
Current received record header (static I/O buffer).
struct tls_cipherspec cipherspec
Cipher specification.
struct io_buffer * handshake
Received handshake fragment (if any).
enum tls_rx_state state
State machine current state.
struct tls_header header
Current received record header.
struct pending_operation validation
Certificate validation pending operation.
struct interface validator
Certificate validator.
struct x509_root * root
Root of trust.
struct pending_operation negotiation
Security negotiation pending operation.
struct x509_chain * chain
Certificate chain (if any).
struct private_key * key
Private key.
struct tls_cursor ticket
Session ticket.
const char * name
Server name.
struct secure_preshared_identity psid
Bound peer identity.
struct x509_root * root
Root of trust.
struct tls_preshared_key psk
Pre-shared key.
struct list_head conn
List of connections.
struct refcnt refcnt
Reference counter.
struct tls_session_id id
Session ID.
struct list_head list
List of sessions.
A TLS signature algorithm.
struct asn1_algorithm * algorithm
Required certificate OID-identified algorithm, if any.
struct pubkey_algorithm * pubkey
Public-key algorithm.
uint16_t code
Numeric code (in network-endian order).
struct digest_algorithm * digest
Digest algorithm.
struct tls_cipherspec cipherspec
Cipher specification.
unsigned int pending
Pending transmissions.
struct process process
Transmit process.
void * dynamic
Dynamically allocated storage.
void * client
Client verification data.
size_t len
Length of each verification data.
void * server
Server verification data.
An X.509 certificate chain.
An X.509 root certificate list.
struct tls_key_exchange_algorithm tls_null_exchange_algorithm
Null key exchange algorithm.
struct tls_key_exchange_algorithm tls_pubkey_exchange_algorithm
Public key exchange algorithm.
struct tls_key_exchange_algorithm tls_ecdhe_exchange_algorithm
Ephemeral Elliptic Curve Diffie-Hellman key exchange algorithm.
struct tls_key_exchange_algorithm tls_dhe_exchange_algorithm
Ephemeral Diffie-Hellman key exchange algorithm.
tls_rx_state
TLS RX state machine state.
tls_tx_pending
TLS TX pending flags.
@ TLS_TX_CLIENT_KEY_EXCHANGE
@ TLS_TX_CERTIFICATE_VERIFY
int add_tls(struct interface *xfer, const char *name, struct x509_root *root, struct private_key *key)
Add TLS on an interface.
struct exchange_algorithm tls_classic_pre_master_algorithm
Classic pre-master secret key exchange algorithm.
uint32_t type_len
Type and length.
uint8_t magic[7]
Magic signature.
struct tls_server_random::@277065305262320303277017256323141213323144155004 downgrade
Version downgrade detection.
uint8_t version
Negotiated version (as a delta from TLSv1.1).
uint8_t random[32]
Random bytes.
uint8_t unused[24]
Unused.