Coverage Report

Created: 2026-09-28 07:37

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/PcapPlusPlus/Packet++/header/SSLCommon.h
Line
Count
Source
1
#pragma once
2
3
#include <string>
4
#include <stdint.h>
5
6
#include "DeprecationUtils.h"
7
8
/// @file
9
/// See detailed explanation of the TLS/SSL protocol support in PcapPlusPlus in SSLLayer.h
10
11
/// @namespace pcpp
12
/// @brief The main namespace for the PcapPlusPlus lib
13
namespace pcpp
14
{
15
  /// @struct ssl_tls_record_layer
16
  /// The common part of all SSL/TLS messages
17
#pragma pack(push, 1)
18
  struct ssl_tls_record_layer
19
  {
20
    /// Message (record) type (one of ::SSLRecordType)
21
    uint8_t recordType;
22
    /// Message (record) version (one of SSLVersion::SSLVersionEnum)
23
    uint16_t recordVersion;
24
    /// Message (record) length in bytes
25
    uint16_t length;
26
  };
27
#pragma pack(pop)
28
  static_assert(sizeof(ssl_tls_record_layer) == 5, "ssl_tls_record_layer size is not 5 bytes");
29
30
  /// @struct ssl_tls_handshake_layer
31
  /// The common part of all SSL/TLS handshake message types
32
#pragma pack(push, 1)
33
  struct ssl_tls_handshake_layer
34
  {
35
    /// Type of the handshake message (one of ::SSLHandshakeType)
36
    uint8_t handshakeType;
37
    /// Length of the message. Length is 3-Byte long, This is the MSB byte
38
    uint8_t length1;
39
    /// Length of the message. Length is 3-Byte long, This is the 2 LSB bytes
40
    uint16_t length2;
41
  };
42
#pragma pack(pop)
43
  static_assert(sizeof(ssl_tls_handshake_layer) == 4, "ssl_tls_handshake_layer size is not 4 bytes");
44
45
  /// @struct ssl_tls_client_server_hello
46
  /// The common header part of client-hello and server-hello handshake messages
47
#pragma pack(push, 1)
48
  struct ssl_tls_client_server_hello : ssl_tls_handshake_layer
49
  {
50
    /// SSL/TLS handshake version (one of SSLVersion::SSLVersionEnum)
51
    uint16_t handshakeVersion;
52
    /// 32-bytes random number
53
    uint8_t random[32];
54
  };
55
#pragma pack(pop)
56
  static_assert(sizeof(ssl_tls_client_server_hello) == 38, "ssl_tls_client_server_hello size is not 38 bytes");
57
58
  /// @struct ssl_tls_change_cipher_spec
59
  /// SSL/TLS change-cipher-spec message structure
60
#pragma pack(push, 1)
61
  struct ssl_tls_change_cipher_spec
62
  {
63
    /// Unused byte
64
    uint8_t changeCipherSpec;
65
  };
66
#pragma pack(pop)
67
  static_assert(sizeof(ssl_tls_change_cipher_spec) == 1, "ssl_tls_change_cipher_spec size is not 1 byte");
68
69
  /// @struct ssl_tls_alert
70
  /// SSL/TLS alert message structure
71
#pragma pack(push, 1)
72
  struct ssl_tls_alert
73
  {
74
    /// Alert level (one of ::SSLAlertLevel)
75
    uint8_t alertLevel;
76
    /// Alert description (one of ::SSLAlertDescription)
77
    uint8_t alertDescription;
78
  };
79
#pragma pack(pop)
80
  static_assert(sizeof(ssl_tls_alert) == 2, "ssl_tls_alert size is not 2 bytes");
81
82
  /// SSL/TLS message types
83
  enum SSLRecordType
84
  {
85
    /// Change-cipher-spec message
86
    SSL_CHANGE_CIPHER_SPEC = 20,
87
    /// SSL alert message
88
    SSL_ALERT = 21,
89
    /// SSL handshake message
90
    SSL_HANDSHAKE = 22,
91
    /// SSL data message
92
    SSL_APPLICATION_DATA = 23
93
  };
94
95
  /// @class SSLVersion
96
  /// A wrapper class for SSL/TLS versions. The SSL/TLS version is typically represented by a 2-byte number,
97
  /// for example TLS 1.2 is represented by 0x0303.
98
  /// This class wraps the numeric value and provides methods to convert it into an enum, string, etc.
99
  class SSLVersion
100
  {
101
  public:
102
    /// SSL/TLS versions enum
103
    enum SSLVersionEnum
104
    {
105
      /// SSL 3.0
106
      SSL3 = 0x0300,
107
      /// TLS 1.0
108
      TLS1_0 = 0x0301,
109
      /// TLS 1.1
110
      TLS1_1 = 0x0302,
111
      /// TLS 1.2
112
      TLS1_2 = 0x0303,
113
      /// TLS 1.3
114
      TLS1_3 = 0x0304,
115
      /// TLS 1.3 (draft 14)
116
      TLS1_3_D14 = 0x7f0e,
117
      /// TLS 1.3 (draft 15)
118
      TLS1_3_D15 = 0x7f0f,
119
      /// TLS 1.3 (draft 16)
120
      TLS1_3_D16 = 0x7f10,
121
      /// TLS 1.3 (draft 17)
122
      TLS1_3_D17 = 0x7f11,
123
      /// TLS 1.3 (draft 18)
124
      TLS1_3_D18 = 0x7f12,
125
      /// TLS 1.3 (draft 19)
126
      TLS1_3_D19 = 0x7f13,
127
      /// TLS 1.3 (draft 20)
128
      TLS1_3_D20 = 0x7f14,
129
      /// TLS 1.3 (draft 21)
130
      TLS1_3_D21 = 0x7f15,
131
      /// TLS 1.3 (draft 22)
132
      TLS1_3_D22 = 0x7f16,
133
      /// TLS 1.3 (draft 23)
134
      TLS1_3_D23 = 0x7f17,
135
      /// TLS 1.3 (draft 24)
136
      TLS1_3_D24 = 0x7f18,
137
      /// TLS 1.3 (draft 25)
138
      TLS1_3_D25 = 0x7f19,
139
      /// TLS 1.3 (draft 26)
140
      TLS1_3_D26 = 0x7f1a,
141
      /// TLS 1.3 (draft 27)
142
      TLS1_3_D27 = 0x7f1b,
143
      /// TLS 1.3 (draft 28)
144
      TLS1_3_D28 = 0x7f1c,
145
      /// TLS 1.3 (Facebook draft 23)
146
      TLS1_3_FBD23 = 0xfb17,
147
      /// TLS 1.3 (Facebook draft 26)
148
      TLS1_3_FBD26 = 0xfb1a,
149
      /// Unknown value
150
      Unknown = 0
151
    };
152
153
    /// A c'tor for this class.
154
    /// @param[in] sslVersionValue The numeric value representing this SSL/TLS version. For example:
155
    /// for TLS 1.2 this would be 0x0303.
156
    explicit SSLVersion(uint16_t sslVersionValue)
157
306k
    {
158
306k
      m_SSLVersionValue = sslVersionValue;
159
306k
    }
160
161
    /// @return An enum value of type SSLVersion::SSLVersionEnum representing the SSL/TLS version.
162
    /// If the numeric value is an invalid SSL/TLS version SSLVersion::Unknown will be returned.
163
    /// @param[in] countTlsDraftsAs1_3 A flag indicating whether to return the enum value SSLVersion::TLS1_3 for all
164
    /// TLS 1.3 drafts. If set to "true" all TLS 1.3 draft values (i.e 0x7f0e - 0x7f1c, 0xfb17, 0xfb1a) will return
165
    /// SSLVersion::TLS1_3, otherwise the corresponding enum values will be returned. The default value is "false".
166
    SSLVersionEnum asEnum(bool countTlsDraftsAs1_3 = false);
167
168
    /// @return The numeric value of the SSL/TLs version
169
    uint16_t asUInt()
170
11.5k
    {
171
11.5k
      return m_SSLVersionValue;
172
11.5k
    }
173
174
    /// @return A string representation of the SSL/TLS version. For example: for TLS 1.2 the string "TLS 1.2" is
175
    /// returned. If the numeric value is an invalid SSL/TLS version the string "Unknown" will be returned.
176
    /// @param[in] countTlsDraftsAs1_3 A flag indicating whether to return the string value "TLS 1.3" for all
177
    /// TLS 1.3 drafts. If set to "true" all TLS 1.3 draft values (i.e 0x7f0e - 0x7f1c, 0xfb17, 0xfb1a) will return
178
    /// "TLS 1.3", otherwise the corresponding string values will be returned. The default value is "false".
179
    std::string toString(bool countTlsDraftsAs1_3 = false);
180
181
  private:
182
    uint16_t m_SSLVersionValue;
183
184
    // unimplemented empty c'tor
185
    SSLVersion();
186
  };
187
188
  /// SSL/TLS handshake message types
189
  enum SSLHandshakeType
190
  {
191
    /// Hello-request message type
192
    SSL_HELLO_REQUEST = 0,
193
    /// Client-hello message type
194
    SSL_CLIENT_HELLO = 1,
195
    /// Server-hello message type
196
    SSL_SERVER_HELLO = 2,
197
    /// New-session-ticket message type
198
    SSL_NEW_SESSION_TICKET = 4,
199
    /// End-of-early-data message type (TLS 1.3)
200
    SSL_END_OF_EARLY_DATE = 5,
201
    /// Encrypted-extensions message type (TLS 1.3)
202
    SSL_ENCRYPTED_EXTENSIONS = 8,
203
    /// Certificate message type
204
    SSL_CERTIFICATE = 11,
205
    /// Server-key-exchange message type
206
    SSL_SERVER_KEY_EXCHANGE = 12,
207
    /// Certificate-request message type
208
    SSL_CERTIFICATE_REQUEST = 13,
209
    /// Server-hello-done message type
210
    SSL_SERVER_DONE = 14,
211
    /// Certificate-verify message type
212
    SSL_CERTIFICATE_VERIFY = 15,
213
    /// Client-key-exchange message type
214
    SSL_CLIENT_KEY_EXCHANGE = 16,
215
    /// Finish message type
216
    SSL_FINISHED = 20,
217
    /// Key-update message type (TLS 1.3)
218
    SSL_KEY_UPDATE = 24,
219
    /// Unknown SSL handshake message
220
    SSL_HANDSHAKE_UNKNOWN = 255
221
  };
222
223
  /// SSL/TLS alert levels
224
  enum SSLAlertLevel
225
  {
226
    /// Warning level alert
227
    SSL_ALERT_LEVEL_WARNING = 1,
228
    /// Fatal level alert
229
    SSL_ALERT_LEVEL_FATAL = 2,
230
    /// For encrypted alerts the level is unknown so this type will be returned
231
    SSL_ALERT_LEVEL_ENCRYPTED = 255
232
  };
233
234
  /// SSL/TLS alert description types
235
  enum SSLAlertDescription
236
  {
237
    /// Close notify alert
238
    SSL_ALERT_CLOSE_NOTIFY = 0,
239
    /// Unexpected message alert
240
    SSL_ALERT_UNEXPECTED_MESSAGE = 10,
241
    /// Bad record MAC alert
242
    SSL_ALERT_BAD_RECORD_MAC = 20,
243
    /// Decryption failed alert
244
    SSL_ALERT_DECRYPTION_FAILED = 21,
245
    ///
246
    SSL_ALERT_RECORD_OVERFLOW = 22,
247
    /// Decompression failure alert
248
    SSL_ALERT_DECOMPRESSION_FAILURE = 30,
249
    /// Handshake failure alert
250
    SSL_ALERT_HANDSHAKE_FAILURE = 40,
251
    /// No certificate alert
252
    SSL_ALERT_NO_CERTIFICATE = 41,
253
    /// Bad certificate alert
254
    SSL_ALERT_BAD_CERTIFICATE = 42,
255
    /// Unsupported certificate
256
    SSL_ALERT_UNSUPPORTED_CERTIFICATE = 43,
257
    /// Certificate revoked alert
258
    SSL_ALERT_CERTIFICATE_REVOKED = 44,
259
    /// Certificate expired alert
260
    SSL_ALERT_CERTIFICATE_EXPIRED = 45,
261
    /// Certificate unknown alert
262
    SSL_ALERT_CERTIFICATE_UNKNOWN = 46,
263
    /// Illegal parameter alert
264
    SSL_ALERT_ILLEGAL_PARAMETER = 47,
265
    /// Unknown CA alert
266
    SSL_ALERT_UNKNOWN_CA = 48,
267
    /// Access denied alert
268
    SSL_ALERT_ACCESS_DENIED = 49,
269
    /// Decode error alert
270
    SSL_ALERT_DECODE_ERROR = 50,
271
    /// Decrypt error alert
272
    SSL_ALERT_DECRYPT_ERROR = 51,
273
    /// Export restriction alert
274
    SSL_ALERT_EXPORT_RESTRICTION = 60,
275
    /// Protocol version alert
276
    SSL_ALERT_PROTOCOL_VERSION = 70,
277
    /// Insufficient security alert
278
    SSL_ALERT_INSUFFICIENT_SECURITY = 71,
279
    /// Internal error alert
280
    SSL_ALERT_INTERNAL_ERROR = 80,
281
    /// User cancelled alert
282
    SSL_ALERT_USER_CANCELLED = 90,
283
    /// No negotiation alert
284
    SSL_ALERT_NO_RENEGOTIATION = 100,
285
    /// Unsupported extension alert
286
    SSL_ALERT_UNSUPPORTED_EXTENSION = 110,
287
    /// Encrtpyed alert (cannot determine its type)
288
    SSL_ALERT_ENCRYPTED = 255
289
  };
290
291
  /// SSL/TLS key exchange algorithms
292
  enum SSLKeyExchangeAlgorithm
293
  {
294
    /// Null value
295
    SSL_KEYX_NULL,
296
    /// RSA (Rivest-Shamir-Adleman)
297
    SSL_KEYX_RSA,
298
    /// Diffie-Hellman
299
    SSL_KEYX_DH,
300
    /// Diffie-Hellman ephemeral
301
    SSL_KEYX_DHE,
302
    /// Elliptic curve Diffie�Hellman
303
    SSL_KEYX_ECDH,
304
    /// Elliptic curve Diffie�Hellman ephemeral
305
    SSL_KEYX_ECDHE,
306
    /// Fortezza Crypto Card
307
    SSL_KEYX_FORTEZZA,
308
    /// Kerberos 5
309
    SSL_KEYX_KRB5,
310
    ///  Pre-Shared Key
311
    SSL_KEYX_PSK,
312
    /// GOST
313
    SSL_KEYX_GOST,
314
    /// Secure Remote Password
315
    SSL_KEYX_SRP,
316
    /// PCT
317
    SSL_KEYX_PCT,
318
    /// Unknown algorithm
319
    SSL_KEYX_Unknown
320
  };
321
322
  /// SSL/TLS authentication algorithms
323
  enum SSLAuthenticationAlgorithm
324
  {
325
    /// Null value
326
    SSL_AUTH_NULL,
327
    /// RSA (Rivest-Shamir-Adleman)
328
    SSL_AUTH_RSA,
329
    /// Digital Signature Standard
330
    SSL_AUTH_DSS,
331
    /// Anonymous
332
    SSL_AUTH_anon,
333
    /// Diffie-Hellman based key-exchange protocol
334
    SSL_AUTH_KEA,
335
    /// Kerberos 5
336
    SSL_AUTH_KRB5,
337
    /// Pre-Shared Key
338
    SSL_AUTH_PSK,
339
    /// Elliptic Curve Digital Signature Algorithm
340
    SSL_AUTH_ECDSA,
341
    /// GOST
342
    SSL_AUTH_GOST,
343
    /// SHA-1 (Secure Hash Algorithm)
344
    SSL_AUTH_SHA,
345
    /// PCT
346
    SSL_AUTH_PCT,
347
    /// Diffie-Hellman ephemeral
348
    SSL_AUTH_DHE,
349
    /// Unknown algorithm
350
    SSL_AUTH_Unknown
351
  };
352
353
  /// SSL/TLS symmetric encryption algorithms
354
  enum SSLSymmetricEncryptionAlgorithm
355
  {
356
    /// Null value
357
    SSL_SYM_NULL,
358
    /// RC4_40
359
    SSL_SYM_RC4_40,
360
    /// RC4_128
361
    SSL_SYM_RC4_128,
362
    /// RC2_CBC_40
363
    SSL_SYM_RC2_CBC_40,
364
    /// IDEA_CBC
365
    SSL_SYM_IDEA_CBC,
366
    /// DES40_CBC
367
    SSL_SYM_DES40_CBC,
368
    /// DES_CBC
369
    SSL_SYM_DES_CBC,
370
    /// 3DES_EDE_CBC
371
    SSL_SYM_3DES_EDE_CBC,
372
    /// FORTEZZA_CBC
373
    SSL_SYM_FORTEZZA_CBC,
374
    /// DES_CBC_40
375
    SSL_SYM_DES_CBC_40,
376
    /// AES_128_CBC
377
    SSL_SYM_AES_128_CBC,
378
    /// AES_256_CBC
379
    SSL_SYM_AES_256_CBC,
380
    /// CAMELLIA_128_CBC
381
    SSL_SYM_CAMELLIA_128_CBC,
382
    /// CAMELLIA_128_GCM
383
    SSL_SYM_CAMELLIA_128_GCM,
384
    /// CAMELLIA_256_GCM
385
    SSL_SYM_CAMELLIA_256_GCM,
386
    /// RC4_56
387
    SSL_SYM_RC4_56,
388
    /// RC2_CBC_56
389
    SSL_SYM_RC2_CBC_56,
390
    /// GOST28147
391
    SSL_SYM_GOST28147,
392
    /// CAMELLIA_256_CBC
393
    SSL_SYM_CAMELLIA_256_CBC,
394
    /// SEED_CBC
395
    SSL_SYM_SEED_CBC,
396
    /// AES_128
397
    SSL_SYM_AES_128,
398
    /// AES_256
399
    SSL_SYM_AES_256,
400
    /// SSL_SYM_AES_128_GCM
401
    SSL_SYM_AES_128_GCM,
402
    /// AES_256_GCM
403
    SSL_SYM_AES_256_GCM,
404
    /// RC4_128_EXPORT40
405
    SSL_SYM_RC4_128_EXPORT40,
406
    /// RC2_CBC_128_CBC
407
    SSL_SYM_RC2_CBC_128_CBC,
408
    /// IDEA_128_CBC
409
    SSL_SYM_IDEA_128_CBC,
410
    /// DES_64_CBC
411
    SSL_SYM_DES_64_CBC,
412
    /// DES_192_EDE3_CBC
413
    SSL_SYM_DES_192_EDE3_CBC,
414
    /// RC4_64
415
    SSL_SYM_RC4_64,
416
    /// ARIA_128_CBC
417
    SSL_SYM_ARIA_128_CBC,
418
    /// ARIA_256_CBC
419
    SSL_SYM_ARIA_256_CBC,
420
    /// ARIA_128_GCM
421
    SSL_SYM_ARIA_128_GCM,
422
    /// ARIA_256_GCM
423
    SSL_SYM_ARIA_256_GCM,
424
    /// CHACHA20_POLY1305
425
    SSL_SYM_CHACHA20_POLY1305,
426
    /// AES_128_CCM
427
    SSL_SYM_AES_128_CCM,
428
    /// AES_128_CCM_8
429
    SSL_SYM_AES_128_CCM_8,
430
    /// Unknown algorithm
431
    SSL_SYM_Unknown
432
  };
433
  /// Deprecated typo, use SSLSymmetricEncryptionAlgorithm instead
434
  using SSLSymetricEncryptionAlgorithm PCPP_DEPRECATED("Use SSLSymmetricEncryptionAlgorithm instead") =
435
      SSLSymmetricEncryptionAlgorithm;
436
437
  /// SSL/TLS hashing algorithms
438
  enum SSLHashingAlgorithm
439
  {
440
    /// Null value
441
    SSL_HASH_NULL,
442
    /// Message-Digest Algorithm
443
    SSL_HASH_MD5,
444
    /// SHA-1 (Secure Hash Algorithm)
445
    SSL_HASH_SHA,
446
    /// SHA-256 (Secure Hash Algorithm)
447
    SSL_HASH_SHA256,
448
    /// GOST 28147
449
    SSL_HASH_GOST28147,
450
    ///  GOST R 34.11
451
    SSL_HASH_GOSTR3411,
452
    /// SHA-384 (Secure Hash Algorithm)
453
    SSL_HASH_SHA384,
454
    /// CCM mode (Counter with CBC-MAC)
455
    SSL_HASH_CCM,
456
    /// CCM mode (Counter with CBC-MAC)
457
    SSL_HASH_CCM_8,
458
    /// Unknown algorithm
459
    SSL_HASH_Unknown
460
  };
461
462
  /// SSL/TLS extension types
463
  enum SSLExtensionType
464
  {
465
    /// Server Name Indication extension
466
    SSL_EXT_SERVER_NAME = 0,
467
    /// Maximum Fragment Length Negotiation extension
468
    SSL_EXT_MAX_FRAGMENT_LENGTH = 1,
469
    /// Client Certificate URLs extension
470
    SSL_EXT_CLIENT_CERTIFICATE_URL = 2,
471
    /// Trusted CA Indication extension
472
    SSL_EXT_TRUSTED_CA_KEYS = 3,
473
    /// Truncated HMAC extension
474
    SSL_EXT_TRUNCATED_HMAC = 4,
475
    /// Certificate Status Request extension
476
    SSL_EXT_STATUS_REQUEST = 5,
477
    /// TLS User Mapping extension
478
    SSL_EXT_USER_MAPPING = 6,
479
    /// Client Authorization  extension
480
    SSL_EXT_CLIENT_AUTHZ = 7,
481
    /// Server Authorization extension
482
    SSL_EXT_SERVER_AUTHZ = 8,
483
    /// Certificate Type extension
484
    SSL_EXT_CERT_TYPE = 9,
485
    /// Supported Groups extension (renamed from "elliptic curves")
486
    SSL_EXT_SUPPORTED_GROUPS = 10,
487
    /// Elliptic Curves Point Format extension
488
    SSL_EXT_EC_POINT_FORMATS = 11,
489
    /// Secure Remote Password extension
490
    SSL_EXT_SRP = 12,
491
    /// Signature Algorithms extension
492
    SSL_EXT_SIGNATURE_ALGORITHMS = 13,
493
    /// Use Secure Real-time Transport Protocol extension
494
    SSL_EXT_USE_SRTP = 14,
495
    /// TLS Heartbit extension
496
    SSL_EXT_HEARTBEAT = 15,
497
    /// Application Layer Protocol Negotiation (ALPN) extension
498
    SSL_EXT_APPLICATION_LAYER_PROTOCOL_NEGOTIATION = 16,
499
    /// Status Request extension
500
    SSL_EXT_STATUS_REQUEST_V2 = 17,
501
    /// Signed Certificate Timestamp extension
502
    SSL_EXT_SIGNED_CERTIFICATE_TIMESTAMP = 18,
503
    /// Client Certificate Type extension
504
    SSL_EXT_CLIENT_CERTIFICATE_TYPE = 19,
505
    /// Server Certificate Type extension
506
    SSL_EXT_SERVER_CERTIFICATE_TYPE = 20,
507
    /// ClientHello Padding extension
508
    SSL_EXT_PADDING = 21,
509
    /// Encrypt-then-MAC extension
510
    SSL_EXT_ENCRYPT_THEN_MAC = 22,
511
    /// Extended Master Secret extension
512
    SSL_EXT_EXTENDED_MASTER_SECRET = 23,
513
    /// Token Binding extension
514
    SSL_EXT_TOKEN_BINDING = 24,
515
    /// SessionTicket TLS extension
516
    SSL_EXT_SESSIONTICKET_TLS = 35,
517
    /// Pre-shared key (PSK) extension (TLS 1.3)
518
    SSL_EXT_PRE_SHARED_KEY = 41,
519
    /// Early data extension (TLS 1.3)
520
    SSL_EXT_EARLY_DATA = 42,
521
    /// Supported versions extension (TLS 1.3)
522
    SSL_EXT_SUPPORTED_VERSIONS = 43,
523
    /// Cookie extension (TLS 1.3)
524
    SSL_EXT_COOKIE = 44,
525
    /// Pre-Shared Key Exchange Modes extension (TLS 1.3)
526
    SSL_EXT_PSK_KEY_EXCHANGE_MODES = 45,
527
    /// Certificate authorities extension (TLS 1.3)
528
    SSL_EXT_CERTIFICATE_AUTHORITIES = 47,
529
    /// Old filters extension (TLS 1.3)
530
    SSL_EXT_OLD_FILTERS = 48,
531
    /// Post handshake auth extension (TLS 1.3)
532
    SSL_EXT_POST_HANDSHAKE_AUTH = 49,
533
    /// Signature algorithm cert extension (TLS 1.3)
534
    SSL_EXT_SIGNATURE_ALGORITHM_CERT = 50,
535
    /// Key share extension (TLS 1.3)
536
    SSL_EXT_KEY_SHARE = 51,
537
    /// Renegotiation Indication extension
538
    SSL_EXT_RENEGOTIATION_INFO = 65281,
539
    /// Unknown extension
540
    SSL_EXT_Unknown
541
  };
542
543
  /// SSL/TLS client certificate types
544
  enum SSLClientCertificateType
545
  {
546
    /// RSA_SIGN
547
    SSL_CCT_RSA_SIGN = 1,
548
    /// DSS_SIGN
549
    SSL_CCT_DSS_SIGN = 2,
550
    /// RSA_FIXED_DH
551
    SSL_CCT_RSA_FIXED_DH = 3,
552
    /// DSS_FIXED_DH
553
    SSL_CCT_DSS_FIXED_DH = 4,
554
    /// RSA_EPHEMERAL_DH_RESERVED
555
    SSL_CCT_RSA_EPHEMERAL_DH_RESERVED = 5,
556
    /// DSS_EPHEMERAL_DH_RESERVED
557
    SSL_CCT_DSS_EPHEMERAL_DH_RESERVED = 6,
558
    /// FORTEZZA_DMS_RESERVED
559
    SSL_CCT_FORTEZZA_DMS_RESERVED = 20,
560
    /// ECDSA_SIGN
561
    SSL_CCT_ECDSA_SIGN = 64,
562
    /// FIXED_ECDH
563
    SSL_CCT_RSA_FIXED_ECDH = 65,
564
    /// ECDSA_FIXED_ECDH
565
    SSL_CCT_ECDSA_FIXED_ECDH = 66,
566
    /// Unknown client certificate type
567
    SSL_CCT_UNKNOWN
568
  };
569
}  // namespace pcpp