Coverage Report

Created: 2020-11-21 08:34

/src/botan/src/lib/tls/tls_algos.cpp
Line
Count
Source (jump to first uncovered line)
1
/*
2
* (C) 2017 Jack Lloyd
3
*
4
* Botan is released under the Simplified BSD License (see license.txt)
5
*/
6
7
#include <botan/tls_algos.h>
8
#include <botan/exceptn.h>
9
10
namespace Botan {
11
12
namespace TLS {
13
14
std::string kdf_algo_to_string(KDF_Algo algo)
15
24.6k
   {
16
24.6k
   switch(algo)
17
24.6k
      {
18
11.0k
      case KDF_Algo::SHA_1:
19
11.0k
         return "SHA-1";
20
5.44k
      case KDF_Algo::SHA_256:
21
5.44k
         return "SHA-256";
22
8.14k
      case KDF_Algo::SHA_384:
23
8.14k
         return "SHA-384";
24
0
      }
25
26
0
   throw Invalid_State("kdf_algo_to_string unknown enum value");
27
0
   }
28
29
std::string kex_method_to_string(Kex_Algo method)
30
0
   {
31
0
   switch(method)
32
0
      {
33
0
      case Kex_Algo::STATIC_RSA:
34
0
         return "RSA";
35
0
      case Kex_Algo::DH:
36
0
         return "DH";
37
0
      case Kex_Algo::ECDH:
38
0
         return "ECDH";
39
0
      case Kex_Algo::CECPQ1:
40
0
         return "CECPQ1";
41
0
      case Kex_Algo::SRP_SHA:
42
0
         return "SRP_SHA";
43
0
      case Kex_Algo::PSK:
44
0
         return "PSK";
45
0
      case Kex_Algo::DHE_PSK:
46
0
         return "DHE_PSK";
47
0
      case Kex_Algo::ECDHE_PSK:
48
0
         return "ECDHE_PSK";
49
0
      }
50
51
0
   throw Invalid_State("kex_method_to_string unknown enum value");
52
0
   }
53
54
Kex_Algo kex_method_from_string(const std::string& str)
55
0
   {
56
0
   if(str == "RSA")
57
0
      return Kex_Algo::STATIC_RSA;
58
59
0
   if(str == "DH")
60
0
      return Kex_Algo::DH;
61
62
0
   if(str == "ECDH")
63
0
      return Kex_Algo::ECDH;
64
65
0
   if(str == "CECPQ1")
66
0
      return Kex_Algo::CECPQ1;
67
68
0
   if(str == "SRP_SHA")
69
0
      return Kex_Algo::SRP_SHA;
70
71
0
   if(str == "PSK")
72
0
      return Kex_Algo::PSK;
73
74
0
   if(str == "DHE_PSK")
75
0
      return Kex_Algo::DHE_PSK;
76
77
0
   if(str == "ECDHE_PSK")
78
0
      return Kex_Algo::ECDHE_PSK;
79
80
0
   throw Invalid_Argument("Unknown kex method " + str);
81
0
   }
82
83
std::string auth_method_to_string(Auth_Method method)
84
4.28k
   {
85
4.28k
   switch(method)
86
4.28k
      {
87
2.91k
      case Auth_Method::RSA:
88
2.91k
         return "RSA";
89
869
      case Auth_Method::DSA:
90
869
         return "DSA";
91
504
      case Auth_Method::ECDSA:
92
504
         return "ECDSA";
93
0
      case Auth_Method::IMPLICIT:
94
0
         return "IMPLICIT";
95
0
      case Auth_Method::ANONYMOUS:
96
0
         return "ANONYMOUS";
97
0
      }
98
99
0
    throw Invalid_State("auth_method_to_string unknown enum value");
100
0
   }
101
102
Auth_Method auth_method_from_string(const std::string& str)
103
0
   {
104
0
   if(str == "RSA")
105
0
      return Auth_Method::RSA;
106
0
   if(str == "DSA")
107
0
      return Auth_Method::DSA;
108
0
   if(str == "ECDSA")
109
0
      return Auth_Method::ECDSA;
110
0
   if(str == "IMPLICIT")
111
0
      return Auth_Method::IMPLICIT;
112
0
   if(str == "ANONYMOUS" || str == "")
113
0
      return Auth_Method::ANONYMOUS;
114
115
0
   throw Invalid_Argument("Bad signature method " + str);
116
0
   }
117
118
bool group_param_is_dh(Group_Params group)
119
281k
   {
120
281k
   uint16_t group_id = static_cast<uint16_t>(group);
121
281k
   return (group_id >= 256 && group_id < 512);
122
281k
   }
123
124
Group_Params group_param_from_string(const std::string& group_name)
125
0
   {
126
0
   if(group_name == "secp256r1")
127
0
      return Group_Params::SECP256R1;
128
0
   if(group_name == "secp384r1")
129
0
      return Group_Params::SECP384R1;
130
0
   if(group_name == "secp521r1")
131
0
      return Group_Params::SECP521R1;
132
0
   if(group_name == "brainpool256r1")
133
0
      return Group_Params::BRAINPOOL256R1;
134
0
   if(group_name == "brainpool384r1")
135
0
      return Group_Params::BRAINPOOL384R1;
136
0
   if(group_name == "brainpool512r1")
137
0
      return Group_Params::BRAINPOOL512R1;
138
0
   if(group_name == "x25519")
139
0
      return Group_Params::X25519;
140
141
0
   if(group_name == "ffdhe/ietf/2048")
142
0
      return Group_Params::FFDHE_2048;
143
0
   if(group_name == "ffdhe/ietf/3072")
144
0
      return Group_Params::FFDHE_3072;
145
0
   if(group_name == "ffdhe/ietf/4096")
146
0
      return Group_Params::FFDHE_4096;
147
0
   if(group_name == "ffdhe/ietf/6144")
148
0
      return Group_Params::FFDHE_6144;
149
0
   if(group_name == "ffdhe/ietf/8192")
150
0
      return Group_Params::FFDHE_8192;
151
152
0
   return Group_Params::NONE; // unknown
153
0
   }
154
155
std::string group_param_to_string(Group_Params group)
156
24.9k
   {
157
24.9k
   switch(group)
158
24.9k
      {
159
1.66k
      case Group_Params::SECP256R1:
160
1.66k
         return "secp256r1";
161
1.62k
      case Group_Params::SECP384R1:
162
1.62k
         return "secp384r1";
163
11.9k
      case Group_Params::SECP521R1:
164
11.9k
         return "secp521r1";
165
575
      case Group_Params::BRAINPOOL256R1:
166
575
         return "brainpool256r1";
167
1.37k
      case Group_Params::BRAINPOOL384R1:
168
1.37k
         return "brainpool384r1";
169
1.42k
      case Group_Params::BRAINPOOL512R1:
170
1.42k
         return "brainpool512r1";
171
12
      case Group_Params::X25519:
172
12
         return "x25519";
173
174
4.43k
      case Group_Params::FFDHE_2048:
175
4.43k
         return "ffdhe/ietf/2048";
176
540
      case Group_Params::FFDHE_3072:
177
540
         return "ffdhe/ietf/3072";
178
332
      case Group_Params::FFDHE_4096:
179
332
         return "ffdhe/ietf/4096";
180
447
      case Group_Params::FFDHE_6144:
181
447
         return "ffdhe/ietf/6144";
182
543
      case Group_Params::FFDHE_8192:
183
543
         return "ffdhe/ietf/8192";
184
185
1
      default:
186
1
         return "";
187
24.9k
      }
188
24.9k
   }
189
190
191
std::string hash_function_of_scheme(Signature_Scheme scheme)
192
95.9k
   {
193
95.9k
   switch(scheme)
194
95.9k
      {
195
19.6k
      case Signature_Scheme::DSA_SHA1:
196
19.6k
      case Signature_Scheme::ECDSA_SHA1:
197
19.6k
      case Signature_Scheme::RSA_PKCS1_SHA1:
198
19.6k
         return "SHA-1";
199
200
25.5k
      case Signature_Scheme::DSA_SHA256:
201
25.5k
      case Signature_Scheme::ECDSA_SHA256:
202
25.5k
      case Signature_Scheme::RSA_PKCS1_SHA256:
203
25.5k
      case Signature_Scheme::RSA_PSS_SHA256:
204
25.5k
         return "SHA-256";
205
206
25.4k
      case Signature_Scheme::DSA_SHA384:
207
25.4k
      case Signature_Scheme::ECDSA_SHA384:
208
25.4k
      case Signature_Scheme::RSA_PKCS1_SHA384:
209
25.4k
      case Signature_Scheme::RSA_PSS_SHA384:
210
25.4k
         return "SHA-384";
211
212
25.2k
      case Signature_Scheme::DSA_SHA512:
213
25.2k
      case Signature_Scheme::ECDSA_SHA512:
214
25.2k
      case Signature_Scheme::RSA_PKCS1_SHA512:
215
25.2k
      case Signature_Scheme::RSA_PSS_SHA512:
216
25.2k
         return "SHA-512";
217
218
0
      case Signature_Scheme::EDDSA_25519:
219
0
      case Signature_Scheme::EDDSA_448:
220
0
         return "Pure";
221
222
0
      case Signature_Scheme::NONE:
223
0
         return "";
224
0
      }
225
226
0
   throw Invalid_State("hash_function_of_scheme: Unknown signature algorithm enum");
227
0
   }
228
229
const std::vector<Signature_Scheme>& all_signature_schemes()
230
6.17k
   {
231
   /*
232
   * This is ordered in some approximate order of preference
233
   */
234
6.17k
   static const std::vector<Signature_Scheme> all_schemes = {
235
      //Signature_Scheme::EDDSA_448,
236
      //Signature_Scheme::EDDSA_25519,
237
238
6.17k
      Signature_Scheme::RSA_PSS_SHA384,
239
6.17k
      Signature_Scheme::RSA_PSS_SHA256,
240
6.17k
      Signature_Scheme::RSA_PSS_SHA512,
241
242
6.17k
      Signature_Scheme::RSA_PKCS1_SHA384,
243
6.17k
      Signature_Scheme::RSA_PKCS1_SHA512,
244
6.17k
      Signature_Scheme::RSA_PKCS1_SHA256,
245
246
6.17k
      Signature_Scheme::ECDSA_SHA384,
247
6.17k
      Signature_Scheme::ECDSA_SHA512,
248
6.17k
      Signature_Scheme::ECDSA_SHA256,
249
250
6.17k
      Signature_Scheme::DSA_SHA384,
251
6.17k
      Signature_Scheme::DSA_SHA512,
252
6.17k
      Signature_Scheme::DSA_SHA256,
253
254
6.17k
      Signature_Scheme::RSA_PKCS1_SHA1,
255
6.17k
      Signature_Scheme::ECDSA_SHA1,
256
6.17k
      Signature_Scheme::DSA_SHA1,
257
6.17k
   };
258
259
6.17k
   return all_schemes;
260
6.17k
   }
261
262
bool signature_scheme_is_known(Signature_Scheme scheme)
263
101k
   {
264
101k
   switch(scheme)
265
101k
      {
266
96.7k
      case Signature_Scheme::RSA_PKCS1_SHA1:
267
96.7k
      case Signature_Scheme::RSA_PKCS1_SHA256:
268
96.7k
      case Signature_Scheme::RSA_PKCS1_SHA384:
269
96.7k
      case Signature_Scheme::RSA_PKCS1_SHA512:
270
96.7k
      case Signature_Scheme::RSA_PSS_SHA256:
271
96.7k
      case Signature_Scheme::RSA_PSS_SHA384:
272
96.7k
      case Signature_Scheme::RSA_PSS_SHA512:
273
274
96.7k
      case Signature_Scheme::DSA_SHA1:
275
96.7k
      case Signature_Scheme::DSA_SHA256:
276
96.7k
      case Signature_Scheme::DSA_SHA384:
277
96.7k
      case Signature_Scheme::DSA_SHA512:
278
279
96.7k
      case Signature_Scheme::ECDSA_SHA1:
280
96.7k
      case Signature_Scheme::ECDSA_SHA256:
281
96.7k
      case Signature_Scheme::ECDSA_SHA384:
282
96.7k
      case Signature_Scheme::ECDSA_SHA512:
283
96.7k
         return true;
284
285
4.68k
      default:
286
4.68k
         return false;
287
101k
      }
288
289
101k
   }
290
291
std::string signature_algorithm_of_scheme(Signature_Scheme scheme)
292
95.8k
   {
293
95.8k
   switch(scheme)
294
95.8k
      {
295
45.2k
      case Signature_Scheme::RSA_PKCS1_SHA1:
296
45.2k
      case Signature_Scheme::RSA_PKCS1_SHA256:
297
45.2k
      case Signature_Scheme::RSA_PKCS1_SHA384:
298
45.2k
      case Signature_Scheme::RSA_PKCS1_SHA512:
299
45.2k
      case Signature_Scheme::RSA_PSS_SHA256:
300
45.2k
      case Signature_Scheme::RSA_PSS_SHA384:
301
45.2k
      case Signature_Scheme::RSA_PSS_SHA512:
302
45.2k
         return "RSA";
303
304
25.3k
      case Signature_Scheme::DSA_SHA1:
305
25.3k
      case Signature_Scheme::DSA_SHA256:
306
25.3k
      case Signature_Scheme::DSA_SHA384:
307
25.3k
      case Signature_Scheme::DSA_SHA512:
308
25.3k
         return "DSA";
309
310
25.1k
      case Signature_Scheme::ECDSA_SHA1:
311
25.1k
      case Signature_Scheme::ECDSA_SHA256:
312
25.1k
      case Signature_Scheme::ECDSA_SHA384:
313
25.1k
      case Signature_Scheme::ECDSA_SHA512:
314
25.1k
         return "ECDSA";
315
316
1
      case Signature_Scheme::EDDSA_25519:
317
1
         return "Ed25519";
318
319
1
      case Signature_Scheme::EDDSA_448:
320
1
         return "Ed448";
321
322
0
      case Signature_Scheme::NONE:
323
0
         return "";
324
36
      }
325
326
36
   throw Invalid_State("signature_algorithm_of_scheme: Unknown signature algorithm enum");
327
36
   }
328
329
std::string sig_scheme_to_string(Signature_Scheme scheme)
330
0
   {
331
0
   switch(scheme)
332
0
      {
333
0
      case Signature_Scheme::RSA_PKCS1_SHA1:
334
0
         return "RSA_PKCS1_SHA1";
335
0
      case Signature_Scheme::RSA_PKCS1_SHA256:
336
0
         return "RSA_PKCS1_SHA256";
337
0
      case Signature_Scheme::RSA_PKCS1_SHA384:
338
0
         return "RSA_PKCS1_SHA384";
339
0
      case Signature_Scheme::RSA_PKCS1_SHA512:
340
0
         return "RSA_PKCS1_SHA512";
341
342
0
      case Signature_Scheme::DSA_SHA1:
343
0
         return "DSA_SHA1";
344
0
      case Signature_Scheme::DSA_SHA256:
345
0
         return "DSA_SHA256";
346
0
      case Signature_Scheme::DSA_SHA384:
347
0
         return "DSA_SHA384";
348
0
      case Signature_Scheme::DSA_SHA512:
349
0
         return "DSA_SHA512";
350
351
0
      case Signature_Scheme::ECDSA_SHA1:
352
0
         return "ECDSA_SHA1";
353
0
      case Signature_Scheme::ECDSA_SHA256:
354
0
         return "ECDSA_SHA256";
355
0
      case Signature_Scheme::ECDSA_SHA384:
356
0
         return "ECDSA_SHA384";
357
0
      case Signature_Scheme::ECDSA_SHA512:
358
0
         return "ECDSA_SHA512";
359
360
0
      case Signature_Scheme::RSA_PSS_SHA256:
361
0
         return "RSA_PSS_SHA256";
362
0
      case Signature_Scheme::RSA_PSS_SHA384:
363
0
         return "RSA_PSS_SHA384";
364
0
      case Signature_Scheme::RSA_PSS_SHA512:
365
0
         return "RSA_PSS_SHA512";
366
367
0
      case Signature_Scheme::EDDSA_25519:
368
0
         return "EDDSA_25519";
369
0
      case Signature_Scheme::EDDSA_448:
370
0
         return "EDDSA_448";
371
372
0
      case Signature_Scheme::NONE:
373
0
         return "";
374
0
      }
375
376
0
   throw Invalid_State("sig_scheme_to_string: Unknown signature algorithm enum");
377
0
   }
378
379
std::string padding_string_for_scheme(Signature_Scheme scheme)
380
197
   {
381
197
   switch(scheme)
382
197
      {
383
0
      case Signature_Scheme::RSA_PKCS1_SHA1:
384
0
         return "EMSA_PKCS1(SHA-1)";
385
2
      case Signature_Scheme::RSA_PKCS1_SHA256:
386
2
         return "EMSA_PKCS1(SHA-256)";
387
1
      case Signature_Scheme::RSA_PKCS1_SHA384:
388
1
         return "EMSA_PKCS1(SHA-384)";
389
9
      case Signature_Scheme::RSA_PKCS1_SHA512:
390
9
         return "EMSA_PKCS1(SHA-512)";
391
392
0
      case Signature_Scheme::DSA_SHA1:
393
0
      case Signature_Scheme::ECDSA_SHA1:
394
0
         return "EMSA1(SHA-1)";
395
104
      case Signature_Scheme::DSA_SHA256:
396
104
      case Signature_Scheme::ECDSA_SHA256:
397
104
         return "EMSA1(SHA-256)";
398
29
      case Signature_Scheme::DSA_SHA384:
399
29
      case Signature_Scheme::ECDSA_SHA384:
400
29
         return "EMSA1(SHA-384)";
401
29
      case Signature_Scheme::DSA_SHA512:
402
29
      case Signature_Scheme::ECDSA_SHA512:
403
29
         return "EMSA1(SHA-512)";
404
405
12
      case Signature_Scheme::RSA_PSS_SHA256:
406
12
         return "PSSR(SHA-256,MGF1,32)";
407
6
      case Signature_Scheme::RSA_PSS_SHA384:
408
6
         return "PSSR(SHA-384,MGF1,48)";
409
5
      case Signature_Scheme::RSA_PSS_SHA512:
410
5
         return "PSSR(SHA-512,MGF1,64)";
411
412
0
      case Signature_Scheme::EDDSA_25519:
413
0
         return "Pure";
414
0
      case Signature_Scheme::EDDSA_448:
415
0
         return "Pure";
416
417
0
      case Signature_Scheme::NONE:
418
0
         return "";
419
0
      }
420
421
0
   throw Invalid_State("padding_string_for_scheme: Unknown signature algorithm enum");
422
0
   }
423
424
}
425
426
}