Coverage Report

Created: 2020-06-30 13:58

/src/botan/src/lib/tls/tls_algos.cpp
Line
Count
Source (jump to first uncovered line)
1
/*
2
* (C) 2017 Jack Lloyd
3
*
4
* Botan is released under the Simplified BSD License (see license.txt)
5
*/
6
7
#include <botan/tls_algos.h>
8
#include <botan/exceptn.h>
9
10
namespace Botan {
11
12
namespace TLS {
13
14
std::string kdf_algo_to_string(KDF_Algo algo)
15
21.2k
   {
16
21.2k
   switch(algo)
17
21.2k
      {
18
7.22k
      case KDF_Algo::SHA_1:
19
7.22k
         return "SHA-1";
20
6.65k
      case KDF_Algo::SHA_256:
21
6.65k
         return "SHA-256";
22
7.39k
      case KDF_Algo::SHA_384:
23
7.39k
         return "SHA-384";
24
0
      }
25
0
26
0
   throw Invalid_State("kdf_algo_to_string unknown enum value");
27
0
   }
28
29
std::string kex_method_to_string(Kex_Algo method)
30
0
   {
31
0
   switch(method)
32
0
      {
33
0
      case Kex_Algo::STATIC_RSA:
34
0
         return "RSA";
35
0
      case Kex_Algo::DH:
36
0
         return "DH";
37
0
      case Kex_Algo::ECDH:
38
0
         return "ECDH";
39
0
      case Kex_Algo::CECPQ1:
40
0
         return "CECPQ1";
41
0
      case Kex_Algo::SRP_SHA:
42
0
         return "SRP_SHA";
43
0
      case Kex_Algo::PSK:
44
0
         return "PSK";
45
0
      case Kex_Algo::DHE_PSK:
46
0
         return "DHE_PSK";
47
0
      case Kex_Algo::ECDHE_PSK:
48
0
         return "ECDHE_PSK";
49
0
      }
50
0
51
0
   throw Invalid_State("kex_method_to_string unknown enum value");
52
0
   }
53
54
Kex_Algo kex_method_from_string(const std::string& str)
55
0
   {
56
0
   if(str == "RSA")
57
0
      return Kex_Algo::STATIC_RSA;
58
0
59
0
   if(str == "DH")
60
0
      return Kex_Algo::DH;
61
0
62
0
   if(str == "ECDH")
63
0
      return Kex_Algo::ECDH;
64
0
65
0
   if(str == "CECPQ1")
66
0
      return Kex_Algo::CECPQ1;
67
0
68
0
   if(str == "SRP_SHA")
69
0
      return Kex_Algo::SRP_SHA;
70
0
71
0
   if(str == "PSK")
72
0
      return Kex_Algo::PSK;
73
0
74
0
   if(str == "DHE_PSK")
75
0
      return Kex_Algo::DHE_PSK;
76
0
77
0
   if(str == "ECDHE_PSK")
78
0
      return Kex_Algo::ECDHE_PSK;
79
0
80
0
   throw Invalid_Argument("Unknown kex method " + str);
81
0
   }
82
83
std::string auth_method_to_string(Auth_Method method)
84
4.37k
   {
85
4.37k
   switch(method)
86
4.37k
      {
87
3.17k
      case Auth_Method::RSA:
88
3.17k
         return "RSA";
89
556
      case Auth_Method::DSA:
90
556
         return "DSA";
91
639
      case Auth_Method::ECDSA:
92
639
         return "ECDSA";
93
0
      case Auth_Method::IMPLICIT:
94
0
         return "IMPLICIT";
95
0
      case Auth_Method::ANONYMOUS:
96
0
         return "ANONYMOUS";
97
0
      }
98
0
99
0
    throw Invalid_State("auth_method_to_string unknown enum value");
100
0
   }
101
102
Auth_Method auth_method_from_string(const std::string& str)
103
0
   {
104
0
   if(str == "RSA")
105
0
      return Auth_Method::RSA;
106
0
   if(str == "DSA")
107
0
      return Auth_Method::DSA;
108
0
   if(str == "ECDSA")
109
0
      return Auth_Method::ECDSA;
110
0
   if(str == "IMPLICIT")
111
0
      return Auth_Method::IMPLICIT;
112
0
   if(str == "ANONYMOUS" || str == "")
113
0
      return Auth_Method::ANONYMOUS;
114
0
115
0
   throw Invalid_Argument("Bad signature method " + str);
116
0
   }
117
118
bool group_param_is_dh(Group_Params group)
119
270k
   {
120
270k
   uint16_t group_id = static_cast<uint16_t>(group);
121
270k
   return (group_id >= 256 && group_id < 512);
122
270k
   }
123
124
Group_Params group_param_from_string(const std::string& group_name)
125
0
   {
126
0
   if(group_name == "secp256r1")
127
0
      return Group_Params::SECP256R1;
128
0
   if(group_name == "secp384r1")
129
0
      return Group_Params::SECP384R1;
130
0
   if(group_name == "secp521r1")
131
0
      return Group_Params::SECP521R1;
132
0
   if(group_name == "brainpool256r1")
133
0
      return Group_Params::BRAINPOOL256R1;
134
0
   if(group_name == "brainpool384r1")
135
0
      return Group_Params::BRAINPOOL384R1;
136
0
   if(group_name == "brainpool512r1")
137
0
      return Group_Params::BRAINPOOL512R1;
138
0
   if(group_name == "x25519")
139
0
      return Group_Params::X25519;
140
0
141
0
   if(group_name == "ffdhe/ietf/2048")
142
0
      return Group_Params::FFDHE_2048;
143
0
   if(group_name == "ffdhe/ietf/3072")
144
0
      return Group_Params::FFDHE_3072;
145
0
   if(group_name == "ffdhe/ietf/4096")
146
0
      return Group_Params::FFDHE_4096;
147
0
   if(group_name == "ffdhe/ietf/6144")
148
0
      return Group_Params::FFDHE_6144;
149
0
   if(group_name == "ffdhe/ietf/8192")
150
0
      return Group_Params::FFDHE_8192;
151
0
152
0
   return Group_Params::NONE; // unknown
153
0
   }
154
155
std::string group_param_to_string(Group_Params group)
156
23.6k
   {
157
23.6k
   switch(group)
158
23.6k
      {
159
2.35k
      case Group_Params::SECP256R1:
160
2.35k
         return "secp256r1";
161
1.86k
      case Group_Params::SECP384R1:
162
1.86k
         return "secp384r1";
163
10.3k
      case Group_Params::SECP521R1:
164
10.3k
         return "secp521r1";
165
621
      case Group_Params::BRAINPOOL256R1:
166
621
         return "brainpool256r1";
167
1.00k
      case Group_Params::BRAINPOOL384R1:
168
1.00k
         return "brainpool384r1";
169
1.78k
      case Group_Params::BRAINPOOL512R1:
170
1.78k
         return "brainpool512r1";
171
9
      case Group_Params::X25519:
172
9
         return "x25519";
173
0
174
3.92k
      case Group_Params::FFDHE_2048:
175
3.92k
         return "ffdhe/ietf/2048";
176
633
      case Group_Params::FFDHE_3072:
177
633
         return "ffdhe/ietf/3072";
178
615
      case Group_Params::FFDHE_4096:
179
615
         return "ffdhe/ietf/4096";
180
158
      case Group_Params::FFDHE_6144:
181
158
         return "ffdhe/ietf/6144";
182
308
      case Group_Params::FFDHE_8192:
183
308
         return "ffdhe/ietf/8192";
184
0
185
1
      default:
186
1
         return "";
187
23.6k
      }
188
23.6k
   }
189
190
191
std::string hash_function_of_scheme(Signature_Scheme scheme)
192
92.8k
   {
193
92.8k
   switch(scheme)
194
92.8k
      {
195
19.0k
      case Signature_Scheme::DSA_SHA1:
196
19.0k
      case Signature_Scheme::ECDSA_SHA1:
197
19.0k
      case Signature_Scheme::RSA_PKCS1_SHA1:
198
19.0k
         return "SHA-1";
199
19.0k
200
24.7k
      case Signature_Scheme::DSA_SHA256:
201
24.7k
      case Signature_Scheme::ECDSA_SHA256:
202
24.7k
      case Signature_Scheme::RSA_PKCS1_SHA256:
203
24.7k
      case Signature_Scheme::RSA_PSS_SHA256:
204
24.7k
         return "SHA-256";
205
24.7k
206
24.7k
      case Signature_Scheme::DSA_SHA384:
207
24.7k
      case Signature_Scheme::ECDSA_SHA384:
208
24.7k
      case Signature_Scheme::RSA_PKCS1_SHA384:
209
24.7k
      case Signature_Scheme::RSA_PSS_SHA384:
210
24.7k
         return "SHA-384";
211
24.7k
212
24.7k
      case Signature_Scheme::DSA_SHA512:
213
24.3k
      case Signature_Scheme::ECDSA_SHA512:
214
24.3k
      case Signature_Scheme::RSA_PKCS1_SHA512:
215
24.3k
      case Signature_Scheme::RSA_PSS_SHA512:
216
24.3k
         return "SHA-512";
217
24.3k
218
24.3k
      case Signature_Scheme::EDDSA_25519:
219
0
      case Signature_Scheme::EDDSA_448:
220
0
         return "Pure";
221
0
222
0
      case Signature_Scheme::NONE:
223
0
         return "";
224
0
      }
225
0
226
0
   throw Invalid_State("hash_function_of_scheme: Unknown signature algorithm enum");
227
0
   }
228
229
const std::vector<Signature_Scheme>& all_signature_schemes()
230
5.88k
   {
231
5.88k
   /*
232
5.88k
   * This is ordered in some approximate order of preference
233
5.88k
   */
234
5.88k
   static const std::vector<Signature_Scheme> all_schemes = {
235
5.88k
      //Signature_Scheme::EDDSA_448,
236
5.88k
      //Signature_Scheme::EDDSA_25519,
237
5.88k
238
5.88k
      Signature_Scheme::RSA_PSS_SHA384,
239
5.88k
      Signature_Scheme::RSA_PSS_SHA256,
240
5.88k
      Signature_Scheme::RSA_PSS_SHA512,
241
5.88k
242
5.88k
      Signature_Scheme::RSA_PKCS1_SHA384,
243
5.88k
      Signature_Scheme::RSA_PKCS1_SHA512,
244
5.88k
      Signature_Scheme::RSA_PKCS1_SHA256,
245
5.88k
246
5.88k
      Signature_Scheme::ECDSA_SHA384,
247
5.88k
      Signature_Scheme::ECDSA_SHA512,
248
5.88k
      Signature_Scheme::ECDSA_SHA256,
249
5.88k
250
5.88k
      Signature_Scheme::DSA_SHA384,
251
5.88k
      Signature_Scheme::DSA_SHA512,
252
5.88k
      Signature_Scheme::DSA_SHA256,
253
5.88k
254
5.88k
      Signature_Scheme::RSA_PKCS1_SHA1,
255
5.88k
      Signature_Scheme::ECDSA_SHA1,
256
5.88k
      Signature_Scheme::DSA_SHA1,
257
5.88k
   };
258
5.88k
259
5.88k
   return all_schemes;
260
5.88k
   }
261
262
bool signature_scheme_is_known(Signature_Scheme scheme)
263
98.7k
   {
264
98.7k
   switch(scheme)
265
98.7k
      {
266
93.6k
      case Signature_Scheme::RSA_PKCS1_SHA1:
267
93.6k
      case Signature_Scheme::RSA_PKCS1_SHA256:
268
93.6k
      case Signature_Scheme::RSA_PKCS1_SHA384:
269
93.6k
      case Signature_Scheme::RSA_PKCS1_SHA512:
270
93.6k
      case Signature_Scheme::RSA_PSS_SHA256:
271
93.6k
      case Signature_Scheme::RSA_PSS_SHA384:
272
93.6k
      case Signature_Scheme::RSA_PSS_SHA512:
273
93.6k
274
93.6k
      case Signature_Scheme::DSA_SHA1:
275
93.6k
      case Signature_Scheme::DSA_SHA256:
276
93.6k
      case Signature_Scheme::DSA_SHA384:
277
93.6k
      case Signature_Scheme::DSA_SHA512:
278
93.6k
279
93.6k
      case Signature_Scheme::ECDSA_SHA1:
280
93.6k
      case Signature_Scheme::ECDSA_SHA256:
281
93.6k
      case Signature_Scheme::ECDSA_SHA384:
282
93.6k
      case Signature_Scheme::ECDSA_SHA512:
283
93.6k
         return true;
284
93.6k
285
93.6k
      default:
286
5.03k
         return false;
287
98.7k
      }
288
98.7k
289
98.7k
   }
290
291
std::string signature_algorithm_of_scheme(Signature_Scheme scheme)
292
92.2k
   {
293
92.2k
   switch(scheme)
294
92.2k
      {
295
43.7k
      case Signature_Scheme::RSA_PKCS1_SHA1:
296
43.7k
      case Signature_Scheme::RSA_PKCS1_SHA256:
297
43.7k
      case Signature_Scheme::RSA_PKCS1_SHA384:
298
43.7k
      case Signature_Scheme::RSA_PKCS1_SHA512:
299
43.7k
      case Signature_Scheme::RSA_PSS_SHA256:
300
43.7k
      case Signature_Scheme::RSA_PSS_SHA384:
301
43.7k
      case Signature_Scheme::RSA_PSS_SHA512:
302
43.7k
         return "RSA";
303
43.7k
304
43.7k
      case Signature_Scheme::DSA_SHA1:
305
24.2k
      case Signature_Scheme::DSA_SHA256:
306
24.2k
      case Signature_Scheme::DSA_SHA384:
307
24.2k
      case Signature_Scheme::DSA_SHA512:
308
24.2k
         return "DSA";
309
24.2k
310
24.2k
      case Signature_Scheme::ECDSA_SHA1:
311
24.2k
      case Signature_Scheme::ECDSA_SHA256:
312
24.2k
      case Signature_Scheme::ECDSA_SHA384:
313
24.2k
      case Signature_Scheme::ECDSA_SHA512:
314
24.2k
         return "ECDSA";
315
24.2k
316
24.2k
      case Signature_Scheme::EDDSA_25519:
317
1
         return "Ed25519";
318
24.2k
319
24.2k
      case Signature_Scheme::EDDSA_448:
320
1
         return "Ed448";
321
24.2k
322
24.2k
      case Signature_Scheme::NONE:
323
0
         return "";
324
60
      }
325
60
326
60
   throw Invalid_State("signature_algorithm_of_scheme: Unknown signature algorithm enum");
327
60
   }
328
329
std::string sig_scheme_to_string(Signature_Scheme scheme)
330
0
   {
331
0
   switch(scheme)
332
0
      {
333
0
      case Signature_Scheme::RSA_PKCS1_SHA1:
334
0
         return "RSA_PKCS1_SHA1";
335
0
      case Signature_Scheme::RSA_PKCS1_SHA256:
336
0
         return "RSA_PKCS1_SHA256";
337
0
      case Signature_Scheme::RSA_PKCS1_SHA384:
338
0
         return "RSA_PKCS1_SHA384";
339
0
      case Signature_Scheme::RSA_PKCS1_SHA512:
340
0
         return "RSA_PKCS1_SHA512";
341
0
342
0
      case Signature_Scheme::DSA_SHA1:
343
0
         return "DSA_SHA1";
344
0
      case Signature_Scheme::DSA_SHA256:
345
0
         return "DSA_SHA256";
346
0
      case Signature_Scheme::DSA_SHA384:
347
0
         return "DSA_SHA384";
348
0
      case Signature_Scheme::DSA_SHA512:
349
0
         return "DSA_SHA512";
350
0
351
0
      case Signature_Scheme::ECDSA_SHA1:
352
0
         return "ECDSA_SHA1";
353
0
      case Signature_Scheme::ECDSA_SHA256:
354
0
         return "ECDSA_SHA256";
355
0
      case Signature_Scheme::ECDSA_SHA384:
356
0
         return "ECDSA_SHA384";
357
0
      case Signature_Scheme::ECDSA_SHA512:
358
0
         return "ECDSA_SHA512";
359
0
360
0
      case Signature_Scheme::RSA_PSS_SHA256:
361
0
         return "RSA_PSS_SHA256";
362
0
      case Signature_Scheme::RSA_PSS_SHA384:
363
0
         return "RSA_PSS_SHA384";
364
0
      case Signature_Scheme::RSA_PSS_SHA512:
365
0
         return "RSA_PSS_SHA512";
366
0
367
0
      case Signature_Scheme::EDDSA_25519:
368
0
         return "EDDSA_25519";
369
0
      case Signature_Scheme::EDDSA_448:
370
0
         return "EDDSA_448";
371
0
372
0
      case Signature_Scheme::NONE:
373
0
         return "";
374
0
      }
375
0
376
0
   throw Invalid_State("sig_scheme_to_string: Unknown signature algorithm enum");
377
0
   }
378
379
std::string padding_string_for_scheme(Signature_Scheme scheme)
380
295
   {
381
295
   switch(scheme)
382
295
      {
383
0
      case Signature_Scheme::RSA_PKCS1_SHA1:
384
0
         return "EMSA_PKCS1(SHA-1)";
385
1
      case Signature_Scheme::RSA_PKCS1_SHA256:
386
1
         return "EMSA_PKCS1(SHA-256)";
387
1
      case Signature_Scheme::RSA_PKCS1_SHA384:
388
1
         return "EMSA_PKCS1(SHA-384)";
389
11
      case Signature_Scheme::RSA_PKCS1_SHA512:
390
11
         return "EMSA_PKCS1(SHA-512)";
391
0
392
0
      case Signature_Scheme::DSA_SHA1:
393
0
      case Signature_Scheme::ECDSA_SHA1:
394
0
         return "EMSA1(SHA-1)";
395
175
      case Signature_Scheme::DSA_SHA256:
396
175
      case Signature_Scheme::ECDSA_SHA256:
397
175
         return "EMSA1(SHA-256)";
398
175
      case Signature_Scheme::DSA_SHA384:
399
58
      case Signature_Scheme::ECDSA_SHA384:
400
58
         return "EMSA1(SHA-384)";
401
58
      case Signature_Scheme::DSA_SHA512:
402
30
      case Signature_Scheme::ECDSA_SHA512:
403
30
         return "EMSA1(SHA-512)";
404
30
405
30
      case Signature_Scheme::RSA_PSS_SHA256:
406
6
         return "PSSR(SHA-256,MGF1,32)";
407
30
      case Signature_Scheme::RSA_PSS_SHA384:
408
11
         return "PSSR(SHA-384,MGF1,48)";
409
30
      case Signature_Scheme::RSA_PSS_SHA512:
410
2
         return "PSSR(SHA-512,MGF1,64)";
411
30
412
30
      case Signature_Scheme::EDDSA_25519:
413
0
         return "Pure";
414
30
      case Signature_Scheme::EDDSA_448:
415
0
         return "Pure";
416
30
417
30
      case Signature_Scheme::NONE:
418
0
         return "";
419
0
      }
420
0
421
0
   throw Invalid_State("padding_string_for_scheme: Unknown signature algorithm enum");
422
0
   }
423
424
}
425
426
}