Coverage Report

Created: 2020-09-16 07:52

/src/botan/src/lib/tls/tls_algos.cpp
Line
Count
Source (jump to first uncovered line)
1
/*
2
* (C) 2017 Jack Lloyd
3
*
4
* Botan is released under the Simplified BSD License (see license.txt)
5
*/
6
7
#include <botan/tls_algos.h>
8
#include <botan/exceptn.h>
9
10
namespace Botan {
11
12
namespace TLS {
13
14
std::string kdf_algo_to_string(KDF_Algo algo)
15
23.5k
   {
16
23.5k
   switch(algo)
17
23.5k
      {
18
9.32k
      case KDF_Algo::SHA_1:
19
9.32k
         return "SHA-1";
20
6.17k
      case KDF_Algo::SHA_256:
21
6.17k
         return "SHA-256";
22
8.09k
      case KDF_Algo::SHA_384:
23
8.09k
         return "SHA-384";
24
0
      }
25
0
26
0
   throw Invalid_State("kdf_algo_to_string unknown enum value");
27
0
   }
28
29
std::string kex_method_to_string(Kex_Algo method)
30
0
   {
31
0
   switch(method)
32
0
      {
33
0
      case Kex_Algo::STATIC_RSA:
34
0
         return "RSA";
35
0
      case Kex_Algo::DH:
36
0
         return "DH";
37
0
      case Kex_Algo::ECDH:
38
0
         return "ECDH";
39
0
      case Kex_Algo::CECPQ1:
40
0
         return "CECPQ1";
41
0
      case Kex_Algo::SRP_SHA:
42
0
         return "SRP_SHA";
43
0
      case Kex_Algo::PSK:
44
0
         return "PSK";
45
0
      case Kex_Algo::DHE_PSK:
46
0
         return "DHE_PSK";
47
0
      case Kex_Algo::ECDHE_PSK:
48
0
         return "ECDHE_PSK";
49
0
      }
50
0
51
0
   throw Invalid_State("kex_method_to_string unknown enum value");
52
0
   }
53
54
Kex_Algo kex_method_from_string(const std::string& str)
55
0
   {
56
0
   if(str == "RSA")
57
0
      return Kex_Algo::STATIC_RSA;
58
0
59
0
   if(str == "DH")
60
0
      return Kex_Algo::DH;
61
0
62
0
   if(str == "ECDH")
63
0
      return Kex_Algo::ECDH;
64
0
65
0
   if(str == "CECPQ1")
66
0
      return Kex_Algo::CECPQ1;
67
0
68
0
   if(str == "SRP_SHA")
69
0
      return Kex_Algo::SRP_SHA;
70
0
71
0
   if(str == "PSK")
72
0
      return Kex_Algo::PSK;
73
0
74
0
   if(str == "DHE_PSK")
75
0
      return Kex_Algo::DHE_PSK;
76
0
77
0
   if(str == "ECDHE_PSK")
78
0
      return Kex_Algo::ECDHE_PSK;
79
0
80
0
   throw Invalid_Argument("Unknown kex method " + str);
81
0
   }
82
83
std::string auth_method_to_string(Auth_Method method)
84
4.33k
   {
85
4.33k
   switch(method)
86
4.33k
      {
87
3.08k
      case Auth_Method::RSA:
88
3.08k
         return "RSA";
89
699
      case Auth_Method::DSA:
90
699
         return "DSA";
91
551
      case Auth_Method::ECDSA:
92
551
         return "ECDSA";
93
0
      case Auth_Method::IMPLICIT:
94
0
         return "IMPLICIT";
95
0
      case Auth_Method::ANONYMOUS:
96
0
         return "ANONYMOUS";
97
0
      }
98
0
99
0
    throw Invalid_State("auth_method_to_string unknown enum value");
100
0
   }
101
102
Auth_Method auth_method_from_string(const std::string& str)
103
0
   {
104
0
   if(str == "RSA")
105
0
      return Auth_Method::RSA;
106
0
   if(str == "DSA")
107
0
      return Auth_Method::DSA;
108
0
   if(str == "ECDSA")
109
0
      return Auth_Method::ECDSA;
110
0
   if(str == "IMPLICIT")
111
0
      return Auth_Method::IMPLICIT;
112
0
   if(str == "ANONYMOUS" || str == "")
113
0
      return Auth_Method::ANONYMOUS;
114
0
115
0
   throw Invalid_Argument("Bad signature method " + str);
116
0
   }
117
118
bool group_param_is_dh(Group_Params group)
119
278k
   {
120
278k
   uint16_t group_id = static_cast<uint16_t>(group);
121
278k
   return (group_id >= 256 && group_id < 512);
122
278k
   }
123
124
Group_Params group_param_from_string(const std::string& group_name)
125
0
   {
126
0
   if(group_name == "secp256r1")
127
0
      return Group_Params::SECP256R1;
128
0
   if(group_name == "secp384r1")
129
0
      return Group_Params::SECP384R1;
130
0
   if(group_name == "secp521r1")
131
0
      return Group_Params::SECP521R1;
132
0
   if(group_name == "brainpool256r1")
133
0
      return Group_Params::BRAINPOOL256R1;
134
0
   if(group_name == "brainpool384r1")
135
0
      return Group_Params::BRAINPOOL384R1;
136
0
   if(group_name == "brainpool512r1")
137
0
      return Group_Params::BRAINPOOL512R1;
138
0
   if(group_name == "x25519")
139
0
      return Group_Params::X25519;
140
0
141
0
   if(group_name == "ffdhe/ietf/2048")
142
0
      return Group_Params::FFDHE_2048;
143
0
   if(group_name == "ffdhe/ietf/3072")
144
0
      return Group_Params::FFDHE_3072;
145
0
   if(group_name == "ffdhe/ietf/4096")
146
0
      return Group_Params::FFDHE_4096;
147
0
   if(group_name == "ffdhe/ietf/6144")
148
0
      return Group_Params::FFDHE_6144;
149
0
   if(group_name == "ffdhe/ietf/8192")
150
0
      return Group_Params::FFDHE_8192;
151
0
152
0
   return Group_Params::NONE; // unknown
153
0
   }
154
155
std::string group_param_to_string(Group_Params group)
156
24.4k
   {
157
24.4k
   switch(group)
158
24.4k
      {
159
2.17k
      case Group_Params::SECP256R1:
160
2.17k
         return "secp256r1";
161
1.69k
      case Group_Params::SECP384R1:
162
1.69k
         return "secp384r1";
163
11.5k
      case Group_Params::SECP521R1:
164
11.5k
         return "secp521r1";
165
488
      case Group_Params::BRAINPOOL256R1:
166
488
         return "brainpool256r1";
167
1.28k
      case Group_Params::BRAINPOOL384R1:
168
1.28k
         return "brainpool384r1";
169
1.60k
      case Group_Params::BRAINPOOL512R1:
170
1.60k
         return "brainpool512r1";
171
11
      case Group_Params::X25519:
172
11
         return "x25519";
173
0
174
3.95k
      case Group_Params::FFDHE_2048:
175
3.95k
         return "ffdhe/ietf/2048";
176
593
      case Group_Params::FFDHE_3072:
177
593
         return "ffdhe/ietf/3072";
178
518
      case Group_Params::FFDHE_4096:
179
518
         return "ffdhe/ietf/4096";
180
169
      case Group_Params::FFDHE_6144:
181
169
         return "ffdhe/ietf/6144";
182
452
      case Group_Params::FFDHE_8192:
183
452
         return "ffdhe/ietf/8192";
184
0
185
1
      default:
186
1
         return "";
187
24.4k
      }
188
24.4k
   }
189
190
191
std::string hash_function_of_scheme(Signature_Scheme scheme)
192
98.7k
   {
193
98.7k
   switch(scheme)
194
98.7k
      {
195
20.3k
      case Signature_Scheme::DSA_SHA1:
196
20.3k
      case Signature_Scheme::ECDSA_SHA1:
197
20.3k
      case Signature_Scheme::RSA_PKCS1_SHA1:
198
20.3k
         return "SHA-1";
199
20.3k
200
26.2k
      case Signature_Scheme::DSA_SHA256:
201
26.2k
      case Signature_Scheme::ECDSA_SHA256:
202
26.2k
      case Signature_Scheme::RSA_PKCS1_SHA256:
203
26.2k
      case Signature_Scheme::RSA_PSS_SHA256:
204
26.2k
         return "SHA-256";
205
26.2k
206
26.2k
      case Signature_Scheme::DSA_SHA384:
207
26.2k
      case Signature_Scheme::ECDSA_SHA384:
208
26.2k
      case Signature_Scheme::RSA_PKCS1_SHA384:
209
26.2k
      case Signature_Scheme::RSA_PSS_SHA384:
210
26.2k
         return "SHA-384";
211
26.2k
212
25.9k
      case Signature_Scheme::DSA_SHA512:
213
25.9k
      case Signature_Scheme::ECDSA_SHA512:
214
25.9k
      case Signature_Scheme::RSA_PKCS1_SHA512:
215
25.9k
      case Signature_Scheme::RSA_PSS_SHA512:
216
25.9k
         return "SHA-512";
217
25.9k
218
0
      case Signature_Scheme::EDDSA_25519:
219
0
      case Signature_Scheme::EDDSA_448:
220
0
         return "Pure";
221
0
222
0
      case Signature_Scheme::NONE:
223
0
         return "";
224
0
      }
225
0
226
0
   throw Invalid_State("hash_function_of_scheme: Unknown signature algorithm enum");
227
0
   }
228
229
const std::vector<Signature_Scheme>& all_signature_schemes()
230
6.33k
   {
231
   /*
232
   * This is ordered in some approximate order of preference
233
   */
234
6.33k
   static const std::vector<Signature_Scheme> all_schemes = {
235
      //Signature_Scheme::EDDSA_448,
236
      //Signature_Scheme::EDDSA_25519,
237
6.33k
238
6.33k
      Signature_Scheme::RSA_PSS_SHA384,
239
6.33k
      Signature_Scheme::RSA_PSS_SHA256,
240
6.33k
      Signature_Scheme::RSA_PSS_SHA512,
241
6.33k
242
6.33k
      Signature_Scheme::RSA_PKCS1_SHA384,
243
6.33k
      Signature_Scheme::RSA_PKCS1_SHA512,
244
6.33k
      Signature_Scheme::RSA_PKCS1_SHA256,
245
6.33k
246
6.33k
      Signature_Scheme::ECDSA_SHA384,
247
6.33k
      Signature_Scheme::ECDSA_SHA512,
248
6.33k
      Signature_Scheme::ECDSA_SHA256,
249
6.33k
250
6.33k
      Signature_Scheme::DSA_SHA384,
251
6.33k
      Signature_Scheme::DSA_SHA512,
252
6.33k
      Signature_Scheme::DSA_SHA256,
253
6.33k
254
6.33k
      Signature_Scheme::RSA_PKCS1_SHA1,
255
6.33k
      Signature_Scheme::ECDSA_SHA1,
256
6.33k
      Signature_Scheme::DSA_SHA1,
257
6.33k
   };
258
6.33k
259
6.33k
   return all_schemes;
260
6.33k
   }
261
262
bool signature_scheme_is_known(Signature_Scheme scheme)
263
104k
   {
264
104k
   switch(scheme)
265
104k
      {
266
99.5k
      case Signature_Scheme::RSA_PKCS1_SHA1:
267
99.5k
      case Signature_Scheme::RSA_PKCS1_SHA256:
268
99.5k
      case Signature_Scheme::RSA_PKCS1_SHA384:
269
99.5k
      case Signature_Scheme::RSA_PKCS1_SHA512:
270
99.5k
      case Signature_Scheme::RSA_PSS_SHA256:
271
99.5k
      case Signature_Scheme::RSA_PSS_SHA384:
272
99.5k
      case Signature_Scheme::RSA_PSS_SHA512:
273
99.5k
274
99.5k
      case Signature_Scheme::DSA_SHA1:
275
99.5k
      case Signature_Scheme::DSA_SHA256:
276
99.5k
      case Signature_Scheme::DSA_SHA384:
277
99.5k
      case Signature_Scheme::DSA_SHA512:
278
99.5k
279
99.5k
      case Signature_Scheme::ECDSA_SHA1:
280
99.5k
      case Signature_Scheme::ECDSA_SHA256:
281
99.5k
      case Signature_Scheme::ECDSA_SHA384:
282
99.5k
      case Signature_Scheme::ECDSA_SHA512:
283
99.5k
         return true;
284
99.5k
285
5.14k
      default:
286
5.14k
         return false;
287
104k
      }
288
104k
289
104k
   }
290
291
std::string signature_algorithm_of_scheme(Signature_Scheme scheme)
292
98.5k
   {
293
98.5k
   switch(scheme)
294
98.5k
      {
295
46.7k
      case Signature_Scheme::RSA_PKCS1_SHA1:
296
46.7k
      case Signature_Scheme::RSA_PKCS1_SHA256:
297
46.7k
      case Signature_Scheme::RSA_PKCS1_SHA384:
298
46.7k
      case Signature_Scheme::RSA_PKCS1_SHA512:
299
46.7k
      case Signature_Scheme::RSA_PSS_SHA256:
300
46.7k
      case Signature_Scheme::RSA_PSS_SHA384:
301
46.7k
      case Signature_Scheme::RSA_PSS_SHA512:
302
46.7k
         return "RSA";
303
46.7k
304
25.8k
      case Signature_Scheme::DSA_SHA1:
305
25.8k
      case Signature_Scheme::DSA_SHA256:
306
25.8k
      case Signature_Scheme::DSA_SHA384:
307
25.8k
      case Signature_Scheme::DSA_SHA512:
308
25.8k
         return "DSA";
309
25.8k
310
25.9k
      case Signature_Scheme::ECDSA_SHA1:
311
25.9k
      case Signature_Scheme::ECDSA_SHA256:
312
25.9k
      case Signature_Scheme::ECDSA_SHA384:
313
25.9k
      case Signature_Scheme::ECDSA_SHA512:
314
25.9k
         return "ECDSA";
315
25.9k
316
1
      case Signature_Scheme::EDDSA_25519:
317
1
         return "Ed25519";
318
25.9k
319
1
      case Signature_Scheme::EDDSA_448:
320
1
         return "Ed448";
321
25.9k
322
0
      case Signature_Scheme::NONE:
323
0
         return "";
324
53
      }
325
53
326
53
   throw Invalid_State("signature_algorithm_of_scheme: Unknown signature algorithm enum");
327
53
   }
328
329
std::string sig_scheme_to_string(Signature_Scheme scheme)
330
0
   {
331
0
   switch(scheme)
332
0
      {
333
0
      case Signature_Scheme::RSA_PKCS1_SHA1:
334
0
         return "RSA_PKCS1_SHA1";
335
0
      case Signature_Scheme::RSA_PKCS1_SHA256:
336
0
         return "RSA_PKCS1_SHA256";
337
0
      case Signature_Scheme::RSA_PKCS1_SHA384:
338
0
         return "RSA_PKCS1_SHA384";
339
0
      case Signature_Scheme::RSA_PKCS1_SHA512:
340
0
         return "RSA_PKCS1_SHA512";
341
0
342
0
      case Signature_Scheme::DSA_SHA1:
343
0
         return "DSA_SHA1";
344
0
      case Signature_Scheme::DSA_SHA256:
345
0
         return "DSA_SHA256";
346
0
      case Signature_Scheme::DSA_SHA384:
347
0
         return "DSA_SHA384";
348
0
      case Signature_Scheme::DSA_SHA512:
349
0
         return "DSA_SHA512";
350
0
351
0
      case Signature_Scheme::ECDSA_SHA1:
352
0
         return "ECDSA_SHA1";
353
0
      case Signature_Scheme::ECDSA_SHA256:
354
0
         return "ECDSA_SHA256";
355
0
      case Signature_Scheme::ECDSA_SHA384:
356
0
         return "ECDSA_SHA384";
357
0
      case Signature_Scheme::ECDSA_SHA512:
358
0
         return "ECDSA_SHA512";
359
0
360
0
      case Signature_Scheme::RSA_PSS_SHA256:
361
0
         return "RSA_PSS_SHA256";
362
0
      case Signature_Scheme::RSA_PSS_SHA384:
363
0
         return "RSA_PSS_SHA384";
364
0
      case Signature_Scheme::RSA_PSS_SHA512:
365
0
         return "RSA_PSS_SHA512";
366
0
367
0
      case Signature_Scheme::EDDSA_25519:
368
0
         return "EDDSA_25519";
369
0
      case Signature_Scheme::EDDSA_448:
370
0
         return "EDDSA_448";
371
0
372
0
      case Signature_Scheme::NONE:
373
0
         return "";
374
0
      }
375
0
376
0
   throw Invalid_State("sig_scheme_to_string: Unknown signature algorithm enum");
377
0
   }
378
379
std::string padding_string_for_scheme(Signature_Scheme scheme)
380
216
   {
381
216
   switch(scheme)
382
216
      {
383
0
      case Signature_Scheme::RSA_PKCS1_SHA1:
384
0
         return "EMSA_PKCS1(SHA-1)";
385
1
      case Signature_Scheme::RSA_PKCS1_SHA256:
386
1
         return "EMSA_PKCS1(SHA-256)";
387
1
      case Signature_Scheme::RSA_PKCS1_SHA384:
388
1
         return "EMSA_PKCS1(SHA-384)";
389
10
      case Signature_Scheme::RSA_PKCS1_SHA512:
390
10
         return "EMSA_PKCS1(SHA-512)";
391
0
392
0
      case Signature_Scheme::DSA_SHA1:
393
0
      case Signature_Scheme::ECDSA_SHA1:
394
0
         return "EMSA1(SHA-1)";
395
109
      case Signature_Scheme::DSA_SHA256:
396
109
      case Signature_Scheme::ECDSA_SHA256:
397
109
         return "EMSA1(SHA-256)";
398
43
      case Signature_Scheme::DSA_SHA384:
399
43
      case Signature_Scheme::ECDSA_SHA384:
400
43
         return "EMSA1(SHA-384)";
401
28
      case Signature_Scheme::DSA_SHA512:
402
28
      case Signature_Scheme::ECDSA_SHA512:
403
28
         return "EMSA1(SHA-512)";
404
28
405
8
      case Signature_Scheme::RSA_PSS_SHA256:
406
8
         return "PSSR(SHA-256,MGF1,32)";
407
7
      case Signature_Scheme::RSA_PSS_SHA384:
408
7
         return "PSSR(SHA-384,MGF1,48)";
409
9
      case Signature_Scheme::RSA_PSS_SHA512:
410
9
         return "PSSR(SHA-512,MGF1,64)";
411
28
412
0
      case Signature_Scheme::EDDSA_25519:
413
0
         return "Pure";
414
0
      case Signature_Scheme::EDDSA_448:
415
0
         return "Pure";
416
28
417
0
      case Signature_Scheme::NONE:
418
0
         return "";
419
0
      }
420
0
421
0
   throw Invalid_State("padding_string_for_scheme: Unknown signature algorithm enum");
422
0
   }
423
424
}
425
426
}