Coverage Report

Created: 2020-05-23 13:54

/src/botan/src/lib/tls/tls_algos.cpp
Line
Count
Source (jump to first uncovered line)
1
/*
2
* (C) 2017 Jack Lloyd
3
*
4
* Botan is released under the Simplified BSD License (see license.txt)
5
*/
6
7
#include <botan/tls_algos.h>
8
#include <botan/exceptn.h>
9
10
namespace Botan {
11
12
namespace TLS {
13
14
std::string kdf_algo_to_string(KDF_Algo algo)
15
18.9k
   {
16
18.9k
   switch(algo)
17
18.9k
      {
18
5.86k
      case KDF_Algo::SHA_1:
19
5.86k
         return "SHA-1";
20
5.84k
      case KDF_Algo::SHA_256:
21
5.84k
         return "SHA-256";
22
7.27k
      case KDF_Algo::SHA_384:
23
7.27k
         return "SHA-384";
24
0
      }
25
0
26
0
   throw Invalid_State("kdf_algo_to_string unknown enum value");
27
0
   }
28
29
std::string kex_method_to_string(Kex_Algo method)
30
0
   {
31
0
   switch(method)
32
0
      {
33
0
      case Kex_Algo::STATIC_RSA:
34
0
         return "RSA";
35
0
      case Kex_Algo::DH:
36
0
         return "DH";
37
0
      case Kex_Algo::ECDH:
38
0
         return "ECDH";
39
0
      case Kex_Algo::CECPQ1:
40
0
         return "CECPQ1";
41
0
      case Kex_Algo::SRP_SHA:
42
0
         return "SRP_SHA";
43
0
      case Kex_Algo::PSK:
44
0
         return "PSK";
45
0
      case Kex_Algo::DHE_PSK:
46
0
         return "DHE_PSK";
47
0
      case Kex_Algo::ECDHE_PSK:
48
0
         return "ECDHE_PSK";
49
0
      }
50
0
51
0
   throw Invalid_State("kex_method_to_string unknown enum value");
52
0
   }
53
54
Kex_Algo kex_method_from_string(const std::string& str)
55
0
   {
56
0
   if(str == "RSA")
57
0
      return Kex_Algo::STATIC_RSA;
58
0
59
0
   if(str == "DH")
60
0
      return Kex_Algo::DH;
61
0
62
0
   if(str == "ECDH")
63
0
      return Kex_Algo::ECDH;
64
0
65
0
   if(str == "CECPQ1")
66
0
      return Kex_Algo::CECPQ1;
67
0
68
0
   if(str == "SRP_SHA")
69
0
      return Kex_Algo::SRP_SHA;
70
0
71
0
   if(str == "PSK")
72
0
      return Kex_Algo::PSK;
73
0
74
0
   if(str == "DHE_PSK")
75
0
      return Kex_Algo::DHE_PSK;
76
0
77
0
   if(str == "ECDHE_PSK")
78
0
      return Kex_Algo::ECDHE_PSK;
79
0
80
0
   throw Invalid_Argument("Unknown kex method " + str);
81
0
   }
82
83
std::string auth_method_to_string(Auth_Method method)
84
3.79k
   {
85
3.79k
   switch(method)
86
3.79k
      {
87
2.62k
      case Auth_Method::RSA:
88
2.62k
         return "RSA";
89
580
      case Auth_Method::DSA:
90
580
         return "DSA";
91
590
      case Auth_Method::ECDSA:
92
590
         return "ECDSA";
93
0
      case Auth_Method::IMPLICIT:
94
0
         return "IMPLICIT";
95
0
      case Auth_Method::ANONYMOUS:
96
0
         return "ANONYMOUS";
97
0
      }
98
0
99
0
    throw Invalid_State("auth_method_to_string unknown enum value");
100
0
   }
101
102
Auth_Method auth_method_from_string(const std::string& str)
103
0
   {
104
0
   if(str == "RSA")
105
0
      return Auth_Method::RSA;
106
0
   if(str == "DSA")
107
0
      return Auth_Method::DSA;
108
0
   if(str == "ECDSA")
109
0
      return Auth_Method::ECDSA;
110
0
   if(str == "IMPLICIT")
111
0
      return Auth_Method::IMPLICIT;
112
0
   if(str == "ANONYMOUS" || str == "")
113
0
      return Auth_Method::ANONYMOUS;
114
0
115
0
   throw Invalid_Argument("Bad signature method " + str);
116
0
   }
117
118
bool group_param_is_dh(Group_Params group)
119
250k
   {
120
250k
   uint16_t group_id = static_cast<uint16_t>(group);
121
250k
   return (group_id >= 256 && group_id < 512);
122
250k
   }
123
124
Group_Params group_param_from_string(const std::string& group_name)
125
0
   {
126
0
   if(group_name == "secp256r1")
127
0
      return Group_Params::SECP256R1;
128
0
   if(group_name == "secp384r1")
129
0
      return Group_Params::SECP384R1;
130
0
   if(group_name == "secp521r1")
131
0
      return Group_Params::SECP521R1;
132
0
   if(group_name == "brainpool256r1")
133
0
      return Group_Params::BRAINPOOL256R1;
134
0
   if(group_name == "brainpool384r1")
135
0
      return Group_Params::BRAINPOOL384R1;
136
0
   if(group_name == "brainpool512r1")
137
0
      return Group_Params::BRAINPOOL512R1;
138
0
   if(group_name == "x25519")
139
0
      return Group_Params::X25519;
140
0
141
0
   if(group_name == "ffdhe/ietf/2048")
142
0
      return Group_Params::FFDHE_2048;
143
0
   if(group_name == "ffdhe/ietf/3072")
144
0
      return Group_Params::FFDHE_3072;
145
0
   if(group_name == "ffdhe/ietf/4096")
146
0
      return Group_Params::FFDHE_4096;
147
0
   if(group_name == "ffdhe/ietf/6144")
148
0
      return Group_Params::FFDHE_6144;
149
0
   if(group_name == "ffdhe/ietf/8192")
150
0
      return Group_Params::FFDHE_8192;
151
0
152
0
   return Group_Params::NONE; // unknown
153
0
   }
154
155
std::string group_param_to_string(Group_Params group)
156
21.8k
   {
157
21.8k
   switch(group)
158
21.8k
      {
159
2.09k
      case Group_Params::SECP256R1:
160
2.09k
         return "secp256r1";
161
1.75k
      case Group_Params::SECP384R1:
162
1.75k
         return "secp384r1";
163
9.34k
      case Group_Params::SECP521R1:
164
9.34k
         return "secp521r1";
165
753
      case Group_Params::BRAINPOOL256R1:
166
753
         return "brainpool256r1";
167
659
      case Group_Params::BRAINPOOL384R1:
168
659
         return "brainpool384r1";
169
1.34k
      case Group_Params::BRAINPOOL512R1:
170
1.34k
         return "brainpool512r1";
171
9
      case Group_Params::X25519:
172
9
         return "x25519";
173
0
174
4.14k
      case Group_Params::FFDHE_2048:
175
4.14k
         return "ffdhe/ietf/2048";
176
713
      case Group_Params::FFDHE_3072:
177
713
         return "ffdhe/ietf/3072";
178
646
      case Group_Params::FFDHE_4096:
179
646
         return "ffdhe/ietf/4096";
180
154
      case Group_Params::FFDHE_6144:
181
154
         return "ffdhe/ietf/6144";
182
218
      case Group_Params::FFDHE_8192:
183
218
         return "ffdhe/ietf/8192";
184
0
185
1
      default:
186
1
         return "";
187
21.8k
      }
188
21.8k
   }
189
190
191
std::string hash_function_of_scheme(Signature_Scheme scheme)
192
84.4k
   {
193
84.4k
   switch(scheme)
194
84.4k
      {
195
17.4k
      case Signature_Scheme::DSA_SHA1:
196
17.4k
      case Signature_Scheme::ECDSA_SHA1:
197
17.4k
      case Signature_Scheme::RSA_PKCS1_SHA1:
198
17.4k
         return "SHA-1";
199
17.4k
200
22.4k
      case Signature_Scheme::DSA_SHA256:
201
22.4k
      case Signature_Scheme::ECDSA_SHA256:
202
22.4k
      case Signature_Scheme::RSA_PKCS1_SHA256:
203
22.4k
      case Signature_Scheme::RSA_PSS_SHA256:
204
22.4k
         return "SHA-256";
205
22.4k
206
22.4k
      case Signature_Scheme::DSA_SHA384:
207
22.4k
      case Signature_Scheme::ECDSA_SHA384:
208
22.4k
      case Signature_Scheme::RSA_PKCS1_SHA384:
209
22.4k
      case Signature_Scheme::RSA_PSS_SHA384:
210
22.4k
         return "SHA-384";
211
22.4k
212
22.4k
      case Signature_Scheme::DSA_SHA512:
213
22.1k
      case Signature_Scheme::ECDSA_SHA512:
214
22.1k
      case Signature_Scheme::RSA_PKCS1_SHA512:
215
22.1k
      case Signature_Scheme::RSA_PSS_SHA512:
216
22.1k
         return "SHA-512";
217
22.1k
218
22.1k
      case Signature_Scheme::EDDSA_25519:
219
0
      case Signature_Scheme::EDDSA_448:
220
0
         return "Pure";
221
0
222
0
      case Signature_Scheme::NONE:
223
0
         return "";
224
0
      }
225
0
226
0
   throw Invalid_State("hash_function_of_scheme: Unknown signature algorithm enum");
227
0
   }
228
229
const std::vector<Signature_Scheme>& all_signature_schemes()
230
5.39k
   {
231
5.39k
   /*
232
5.39k
   * This is ordered in some approximate order of preference
233
5.39k
   */
234
5.39k
   static const std::vector<Signature_Scheme> all_schemes = {
235
5.39k
      //Signature_Scheme::EDDSA_448,
236
5.39k
      //Signature_Scheme::EDDSA_25519,
237
5.39k
238
5.39k
      Signature_Scheme::RSA_PSS_SHA384,
239
5.39k
      Signature_Scheme::RSA_PSS_SHA256,
240
5.39k
      Signature_Scheme::RSA_PSS_SHA512,
241
5.39k
242
5.39k
      Signature_Scheme::RSA_PKCS1_SHA384,
243
5.39k
      Signature_Scheme::RSA_PKCS1_SHA512,
244
5.39k
      Signature_Scheme::RSA_PKCS1_SHA256,
245
5.39k
246
5.39k
      Signature_Scheme::ECDSA_SHA384,
247
5.39k
      Signature_Scheme::ECDSA_SHA512,
248
5.39k
      Signature_Scheme::ECDSA_SHA256,
249
5.39k
250
5.39k
      Signature_Scheme::DSA_SHA384,
251
5.39k
      Signature_Scheme::DSA_SHA512,
252
5.39k
      Signature_Scheme::DSA_SHA256,
253
5.39k
254
5.39k
      Signature_Scheme::RSA_PKCS1_SHA1,
255
5.39k
      Signature_Scheme::ECDSA_SHA1,
256
5.39k
      Signature_Scheme::DSA_SHA1,
257
5.39k
   };
258
5.39k
259
5.39k
   return all_schemes;
260
5.39k
   }
261
262
bool signature_scheme_is_known(Signature_Scheme scheme)
263
89.5k
   {
264
89.5k
   switch(scheme)
265
89.5k
      {
266
84.9k
      case Signature_Scheme::RSA_PKCS1_SHA1:
267
84.9k
      case Signature_Scheme::RSA_PKCS1_SHA256:
268
84.9k
      case Signature_Scheme::RSA_PKCS1_SHA384:
269
84.9k
      case Signature_Scheme::RSA_PKCS1_SHA512:
270
84.9k
      case Signature_Scheme::RSA_PSS_SHA256:
271
84.9k
      case Signature_Scheme::RSA_PSS_SHA384:
272
84.9k
      case Signature_Scheme::RSA_PSS_SHA512:
273
84.9k
274
84.9k
      case Signature_Scheme::DSA_SHA1:
275
84.9k
      case Signature_Scheme::DSA_SHA256:
276
84.9k
      case Signature_Scheme::DSA_SHA384:
277
84.9k
      case Signature_Scheme::DSA_SHA512:
278
84.9k
279
84.9k
      case Signature_Scheme::ECDSA_SHA1:
280
84.9k
      case Signature_Scheme::ECDSA_SHA256:
281
84.9k
      case Signature_Scheme::ECDSA_SHA384:
282
84.9k
      case Signature_Scheme::ECDSA_SHA512:
283
84.9k
         return true;
284
84.9k
285
84.9k
      default:
286
4.67k
         return false;
287
89.5k
      }
288
89.5k
289
89.5k
   }
290
291
std::string signature_algorithm_of_scheme(Signature_Scheme scheme)
292
83.9k
   {
293
83.9k
   switch(scheme)
294
83.9k
      {
295
39.9k
      case Signature_Scheme::RSA_PKCS1_SHA1:
296
39.9k
      case Signature_Scheme::RSA_PKCS1_SHA256:
297
39.9k
      case Signature_Scheme::RSA_PKCS1_SHA384:
298
39.9k
      case Signature_Scheme::RSA_PKCS1_SHA512:
299
39.9k
      case Signature_Scheme::RSA_PSS_SHA256:
300
39.9k
      case Signature_Scheme::RSA_PSS_SHA384:
301
39.9k
      case Signature_Scheme::RSA_PSS_SHA512:
302
39.9k
         return "RSA";
303
39.9k
304
39.9k
      case Signature_Scheme::DSA_SHA1:
305
21.8k
      case Signature_Scheme::DSA_SHA256:
306
21.8k
      case Signature_Scheme::DSA_SHA384:
307
21.8k
      case Signature_Scheme::DSA_SHA512:
308
21.8k
         return "DSA";
309
21.8k
310
22.0k
      case Signature_Scheme::ECDSA_SHA1:
311
22.0k
      case Signature_Scheme::ECDSA_SHA256:
312
22.0k
      case Signature_Scheme::ECDSA_SHA384:
313
22.0k
      case Signature_Scheme::ECDSA_SHA512:
314
22.0k
         return "ECDSA";
315
22.0k
316
22.0k
      case Signature_Scheme::EDDSA_25519:
317
1
         return "Ed25519";
318
22.0k
319
22.0k
      case Signature_Scheme::EDDSA_448:
320
1
         return "Ed448";
321
22.0k
322
22.0k
      case Signature_Scheme::NONE:
323
0
         return "";
324
46
      }
325
46
326
46
   throw Invalid_State("signature_algorithm_of_scheme: Unknown signature algorithm enum");
327
46
   }
328
329
std::string sig_scheme_to_string(Signature_Scheme scheme)
330
0
   {
331
0
   switch(scheme)
332
0
      {
333
0
      case Signature_Scheme::RSA_PKCS1_SHA1:
334
0
         return "RSA_PKCS1_SHA1";
335
0
      case Signature_Scheme::RSA_PKCS1_SHA256:
336
0
         return "RSA_PKCS1_SHA256";
337
0
      case Signature_Scheme::RSA_PKCS1_SHA384:
338
0
         return "RSA_PKCS1_SHA384";
339
0
      case Signature_Scheme::RSA_PKCS1_SHA512:
340
0
         return "RSA_PKCS1_SHA512";
341
0
342
0
      case Signature_Scheme::DSA_SHA1:
343
0
         return "DSA_SHA1";
344
0
      case Signature_Scheme::DSA_SHA256:
345
0
         return "DSA_SHA256";
346
0
      case Signature_Scheme::DSA_SHA384:
347
0
         return "DSA_SHA384";
348
0
      case Signature_Scheme::DSA_SHA512:
349
0
         return "DSA_SHA512";
350
0
351
0
      case Signature_Scheme::ECDSA_SHA1:
352
0
         return "ECDSA_SHA1";
353
0
      case Signature_Scheme::ECDSA_SHA256:
354
0
         return "ECDSA_SHA256";
355
0
      case Signature_Scheme::ECDSA_SHA384:
356
0
         return "ECDSA_SHA384";
357
0
      case Signature_Scheme::ECDSA_SHA512:
358
0
         return "ECDSA_SHA512";
359
0
360
0
      case Signature_Scheme::RSA_PSS_SHA256:
361
0
         return "RSA_PSS_SHA256";
362
0
      case Signature_Scheme::RSA_PSS_SHA384:
363
0
         return "RSA_PSS_SHA384";
364
0
      case Signature_Scheme::RSA_PSS_SHA512:
365
0
         return "RSA_PSS_SHA512";
366
0
367
0
      case Signature_Scheme::EDDSA_25519:
368
0
         return "EDDSA_25519";
369
0
      case Signature_Scheme::EDDSA_448:
370
0
         return "EDDSA_448";
371
0
372
0
      case Signature_Scheme::NONE:
373
0
         return "";
374
0
      }
375
0
376
0
   throw Invalid_State("sig_scheme_to_string: Unknown signature algorithm enum");
377
0
   }
378
379
std::string padding_string_for_scheme(Signature_Scheme scheme)
380
208
   {
381
208
   switch(scheme)
382
208
      {
383
0
      case Signature_Scheme::RSA_PKCS1_SHA1:
384
0
         return "EMSA_PKCS1(SHA-1)";
385
1
      case Signature_Scheme::RSA_PKCS1_SHA256:
386
1
         return "EMSA_PKCS1(SHA-256)";
387
1
      case Signature_Scheme::RSA_PKCS1_SHA384:
388
1
         return "EMSA_PKCS1(SHA-384)";
389
13
      case Signature_Scheme::RSA_PKCS1_SHA512:
390
13
         return "EMSA_PKCS1(SHA-512)";
391
0
392
0
      case Signature_Scheme::DSA_SHA1:
393
0
      case Signature_Scheme::ECDSA_SHA1:
394
0
         return "EMSA1(SHA-1)";
395
120
      case Signature_Scheme::DSA_SHA256:
396
120
      case Signature_Scheme::ECDSA_SHA256:
397
120
         return "EMSA1(SHA-256)";
398
120
      case Signature_Scheme::DSA_SHA384:
399
39
      case Signature_Scheme::ECDSA_SHA384:
400
39
         return "EMSA1(SHA-384)";
401
39
      case Signature_Scheme::DSA_SHA512:
402
16
      case Signature_Scheme::ECDSA_SHA512:
403
16
         return "EMSA1(SHA-512)";
404
16
405
16
      case Signature_Scheme::RSA_PSS_SHA256:
406
6
         return "PSSR(SHA-256,MGF1,32)";
407
16
      case Signature_Scheme::RSA_PSS_SHA384:
408
10
         return "PSSR(SHA-384,MGF1,48)";
409
16
      case Signature_Scheme::RSA_PSS_SHA512:
410
2
         return "PSSR(SHA-512,MGF1,64)";
411
16
412
16
      case Signature_Scheme::EDDSA_25519:
413
0
         return "Pure";
414
16
      case Signature_Scheme::EDDSA_448:
415
0
         return "Pure";
416
16
417
16
      case Signature_Scheme::NONE:
418
0
         return "";
419
0
      }
420
0
421
0
   throw Invalid_State("padding_string_for_scheme: Unknown signature algorithm enum");
422
0
   }
423
424
}
425
426
}