/src/PcapPlusPlus/Packet++/header/SSLCommon.h
Line | Count | Source |
1 | | #pragma once |
2 | | |
3 | | #include <string> |
4 | | #include <stdint.h> |
5 | | |
6 | | #include "DeprecationUtils.h" |
7 | | |
8 | | /// @file |
9 | | /// See detailed explanation of the TLS/SSL protocol support in PcapPlusPlus in SSLLayer.h |
10 | | |
11 | | /// @namespace pcpp |
12 | | /// @brief The main namespace for the PcapPlusPlus lib |
13 | | namespace pcpp |
14 | | { |
15 | | /// @struct ssl_tls_record_layer |
16 | | /// The common part of all SSL/TLS messages |
17 | | #pragma pack(push, 1) |
18 | | struct ssl_tls_record_layer |
19 | | { |
20 | | /// Message (record) type (one of ::SSLRecordType) |
21 | | uint8_t recordType; |
22 | | /// Message (record) version (one of SSLVersion::SSLVersionEnum) |
23 | | uint16_t recordVersion; |
24 | | /// Message (record) length in bytes |
25 | | uint16_t length; |
26 | | }; |
27 | | #pragma pack(pop) |
28 | | static_assert(sizeof(ssl_tls_record_layer) == 5, "ssl_tls_record_layer size is not 5 bytes"); |
29 | | |
30 | | /// @struct ssl_tls_handshake_layer |
31 | | /// The common part of all SSL/TLS handshake message types |
32 | | #pragma pack(push, 1) |
33 | | struct ssl_tls_handshake_layer |
34 | | { |
35 | | /// Type of the handshake message (one of ::SSLHandshakeType) |
36 | | uint8_t handshakeType; |
37 | | /// Length of the message. Length is 3-Byte long, This is the MSB byte |
38 | | uint8_t length1; |
39 | | /// Length of the message. Length is 3-Byte long, This is the 2 LSB bytes |
40 | | uint16_t length2; |
41 | | }; |
42 | | #pragma pack(pop) |
43 | | static_assert(sizeof(ssl_tls_handshake_layer) == 4, "ssl_tls_handshake_layer size is not 4 bytes"); |
44 | | |
45 | | /// @struct ssl_tls_client_server_hello |
46 | | /// The common header part of client-hello and server-hello handshake messages |
47 | | #pragma pack(push, 1) |
48 | | struct ssl_tls_client_server_hello : ssl_tls_handshake_layer |
49 | | { |
50 | | /// SSL/TLS handshake version (one of SSLVersion::SSLVersionEnum) |
51 | | uint16_t handshakeVersion; |
52 | | /// 32-bytes random number |
53 | | uint8_t random[32]; |
54 | | }; |
55 | | #pragma pack(pop) |
56 | | static_assert(sizeof(ssl_tls_client_server_hello) == 38, "ssl_tls_client_server_hello size is not 38 bytes"); |
57 | | |
58 | | /// @struct ssl_tls_change_cipher_spec |
59 | | /// SSL/TLS change-cipher-spec message structure |
60 | | #pragma pack(push, 1) |
61 | | struct ssl_tls_change_cipher_spec |
62 | | { |
63 | | /// Unused byte |
64 | | uint8_t changeCipherSpec; |
65 | | }; |
66 | | #pragma pack(pop) |
67 | | static_assert(sizeof(ssl_tls_change_cipher_spec) == 1, "ssl_tls_change_cipher_spec size is not 1 byte"); |
68 | | |
69 | | /// @struct ssl_tls_alert |
70 | | /// SSL/TLS alert message structure |
71 | | #pragma pack(push, 1) |
72 | | struct ssl_tls_alert |
73 | | { |
74 | | /// Alert level (one of ::SSLAlertLevel) |
75 | | uint8_t alertLevel; |
76 | | /// Alert description (one of ::SSLAlertDescription) |
77 | | uint8_t alertDescription; |
78 | | }; |
79 | | #pragma pack(pop) |
80 | | static_assert(sizeof(ssl_tls_alert) == 2, "ssl_tls_alert size is not 2 bytes"); |
81 | | |
82 | | /// SSL/TLS message types |
83 | | enum SSLRecordType |
84 | | { |
85 | | /// Change-cipher-spec message |
86 | | SSL_CHANGE_CIPHER_SPEC = 20, |
87 | | /// SSL alert message |
88 | | SSL_ALERT = 21, |
89 | | /// SSL handshake message |
90 | | SSL_HANDSHAKE = 22, |
91 | | /// SSL data message |
92 | | SSL_APPLICATION_DATA = 23 |
93 | | }; |
94 | | |
95 | | /// @class SSLVersion |
96 | | /// A wrapper class for SSL/TLS versions. The SSL/TLS version is typically represented by a 2-byte number, |
97 | | /// for example TLS 1.2 is represented by 0x0303. |
98 | | /// This class wraps the numeric value and provides methods to convert it into an enum, string, etc. |
99 | | class SSLVersion |
100 | | { |
101 | | public: |
102 | | /// SSL/TLS versions enum |
103 | | enum SSLVersionEnum |
104 | | { |
105 | | /// SSL 3.0 |
106 | | SSL3 = 0x0300, |
107 | | /// TLS 1.0 |
108 | | TLS1_0 = 0x0301, |
109 | | /// TLS 1.1 |
110 | | TLS1_1 = 0x0302, |
111 | | /// TLS 1.2 |
112 | | TLS1_2 = 0x0303, |
113 | | /// TLS 1.3 |
114 | | TLS1_3 = 0x0304, |
115 | | /// TLS 1.3 (draft 14) |
116 | | TLS1_3_D14 = 0x7f0e, |
117 | | /// TLS 1.3 (draft 15) |
118 | | TLS1_3_D15 = 0x7f0f, |
119 | | /// TLS 1.3 (draft 16) |
120 | | TLS1_3_D16 = 0x7f10, |
121 | | /// TLS 1.3 (draft 17) |
122 | | TLS1_3_D17 = 0x7f11, |
123 | | /// TLS 1.3 (draft 18) |
124 | | TLS1_3_D18 = 0x7f12, |
125 | | /// TLS 1.3 (draft 19) |
126 | | TLS1_3_D19 = 0x7f13, |
127 | | /// TLS 1.3 (draft 20) |
128 | | TLS1_3_D20 = 0x7f14, |
129 | | /// TLS 1.3 (draft 21) |
130 | | TLS1_3_D21 = 0x7f15, |
131 | | /// TLS 1.3 (draft 22) |
132 | | TLS1_3_D22 = 0x7f16, |
133 | | /// TLS 1.3 (draft 23) |
134 | | TLS1_3_D23 = 0x7f17, |
135 | | /// TLS 1.3 (draft 24) |
136 | | TLS1_3_D24 = 0x7f18, |
137 | | /// TLS 1.3 (draft 25) |
138 | | TLS1_3_D25 = 0x7f19, |
139 | | /// TLS 1.3 (draft 26) |
140 | | TLS1_3_D26 = 0x7f1a, |
141 | | /// TLS 1.3 (draft 27) |
142 | | TLS1_3_D27 = 0x7f1b, |
143 | | /// TLS 1.3 (draft 28) |
144 | | TLS1_3_D28 = 0x7f1c, |
145 | | /// TLS 1.3 (Facebook draft 23) |
146 | | TLS1_3_FBD23 = 0xfb17, |
147 | | /// TLS 1.3 (Facebook draft 26) |
148 | | TLS1_3_FBD26 = 0xfb1a, |
149 | | /// Unknown value |
150 | | Unknown = 0 |
151 | | }; |
152 | | |
153 | | /// A c'tor for this class. |
154 | | /// @param[in] sslVersionValue The numeric value representing this SSL/TLS version. For example: |
155 | | /// for TLS 1.2 this would be 0x0303. |
156 | | explicit SSLVersion(uint16_t sslVersionValue) |
157 | 306k | { |
158 | 306k | m_SSLVersionValue = sslVersionValue; |
159 | 306k | } |
160 | | |
161 | | /// @return An enum value of type SSLVersion::SSLVersionEnum representing the SSL/TLS version. |
162 | | /// If the numeric value is an invalid SSL/TLS version SSLVersion::Unknown will be returned. |
163 | | /// @param[in] countTlsDraftsAs1_3 A flag indicating whether to return the enum value SSLVersion::TLS1_3 for all |
164 | | /// TLS 1.3 drafts. If set to "true" all TLS 1.3 draft values (i.e 0x7f0e - 0x7f1c, 0xfb17, 0xfb1a) will return |
165 | | /// SSLVersion::TLS1_3, otherwise the corresponding enum values will be returned. The default value is "false". |
166 | | SSLVersionEnum asEnum(bool countTlsDraftsAs1_3 = false); |
167 | | |
168 | | /// @return The numeric value of the SSL/TLs version |
169 | | uint16_t asUInt() |
170 | 11.5k | { |
171 | 11.5k | return m_SSLVersionValue; |
172 | 11.5k | } |
173 | | |
174 | | /// @return A string representation of the SSL/TLS version. For example: for TLS 1.2 the string "TLS 1.2" is |
175 | | /// returned. If the numeric value is an invalid SSL/TLS version the string "Unknown" will be returned. |
176 | | /// @param[in] countTlsDraftsAs1_3 A flag indicating whether to return the string value "TLS 1.3" for all |
177 | | /// TLS 1.3 drafts. If set to "true" all TLS 1.3 draft values (i.e 0x7f0e - 0x7f1c, 0xfb17, 0xfb1a) will return |
178 | | /// "TLS 1.3", otherwise the corresponding string values will be returned. The default value is "false". |
179 | | std::string toString(bool countTlsDraftsAs1_3 = false); |
180 | | |
181 | | private: |
182 | | uint16_t m_SSLVersionValue; |
183 | | |
184 | | // unimplemented empty c'tor |
185 | | SSLVersion(); |
186 | | }; |
187 | | |
188 | | /// SSL/TLS handshake message types |
189 | | enum SSLHandshakeType |
190 | | { |
191 | | /// Hello-request message type |
192 | | SSL_HELLO_REQUEST = 0, |
193 | | /// Client-hello message type |
194 | | SSL_CLIENT_HELLO = 1, |
195 | | /// Server-hello message type |
196 | | SSL_SERVER_HELLO = 2, |
197 | | /// New-session-ticket message type |
198 | | SSL_NEW_SESSION_TICKET = 4, |
199 | | /// End-of-early-data message type (TLS 1.3) |
200 | | SSL_END_OF_EARLY_DATE = 5, |
201 | | /// Encrypted-extensions message type (TLS 1.3) |
202 | | SSL_ENCRYPTED_EXTENSIONS = 8, |
203 | | /// Certificate message type |
204 | | SSL_CERTIFICATE = 11, |
205 | | /// Server-key-exchange message type |
206 | | SSL_SERVER_KEY_EXCHANGE = 12, |
207 | | /// Certificate-request message type |
208 | | SSL_CERTIFICATE_REQUEST = 13, |
209 | | /// Server-hello-done message type |
210 | | SSL_SERVER_DONE = 14, |
211 | | /// Certificate-verify message type |
212 | | SSL_CERTIFICATE_VERIFY = 15, |
213 | | /// Client-key-exchange message type |
214 | | SSL_CLIENT_KEY_EXCHANGE = 16, |
215 | | /// Finish message type |
216 | | SSL_FINISHED = 20, |
217 | | /// Key-update message type (TLS 1.3) |
218 | | SSL_KEY_UPDATE = 24, |
219 | | /// Unknown SSL handshake message |
220 | | SSL_HANDSHAKE_UNKNOWN = 255 |
221 | | }; |
222 | | |
223 | | /// SSL/TLS alert levels |
224 | | enum SSLAlertLevel |
225 | | { |
226 | | /// Warning level alert |
227 | | SSL_ALERT_LEVEL_WARNING = 1, |
228 | | /// Fatal level alert |
229 | | SSL_ALERT_LEVEL_FATAL = 2, |
230 | | /// For encrypted alerts the level is unknown so this type will be returned |
231 | | SSL_ALERT_LEVEL_ENCRYPTED = 255 |
232 | | }; |
233 | | |
234 | | /// SSL/TLS alert description types |
235 | | enum SSLAlertDescription |
236 | | { |
237 | | /// Close notify alert |
238 | | SSL_ALERT_CLOSE_NOTIFY = 0, |
239 | | /// Unexpected message alert |
240 | | SSL_ALERT_UNEXPECTED_MESSAGE = 10, |
241 | | /// Bad record MAC alert |
242 | | SSL_ALERT_BAD_RECORD_MAC = 20, |
243 | | /// Decryption failed alert |
244 | | SSL_ALERT_DECRYPTION_FAILED = 21, |
245 | | /// |
246 | | SSL_ALERT_RECORD_OVERFLOW = 22, |
247 | | /// Decompression failure alert |
248 | | SSL_ALERT_DECOMPRESSION_FAILURE = 30, |
249 | | /// Handshake failure alert |
250 | | SSL_ALERT_HANDSHAKE_FAILURE = 40, |
251 | | /// No certificate alert |
252 | | SSL_ALERT_NO_CERTIFICATE = 41, |
253 | | /// Bad certificate alert |
254 | | SSL_ALERT_BAD_CERTIFICATE = 42, |
255 | | /// Unsupported certificate |
256 | | SSL_ALERT_UNSUPPORTED_CERTIFICATE = 43, |
257 | | /// Certificate revoked alert |
258 | | SSL_ALERT_CERTIFICATE_REVOKED = 44, |
259 | | /// Certificate expired alert |
260 | | SSL_ALERT_CERTIFICATE_EXPIRED = 45, |
261 | | /// Certificate unknown alert |
262 | | SSL_ALERT_CERTIFICATE_UNKNOWN = 46, |
263 | | /// Illegal parameter alert |
264 | | SSL_ALERT_ILLEGAL_PARAMETER = 47, |
265 | | /// Unknown CA alert |
266 | | SSL_ALERT_UNKNOWN_CA = 48, |
267 | | /// Access denied alert |
268 | | SSL_ALERT_ACCESS_DENIED = 49, |
269 | | /// Decode error alert |
270 | | SSL_ALERT_DECODE_ERROR = 50, |
271 | | /// Decrypt error alert |
272 | | SSL_ALERT_DECRYPT_ERROR = 51, |
273 | | /// Export restriction alert |
274 | | SSL_ALERT_EXPORT_RESTRICTION = 60, |
275 | | /// Protocol version alert |
276 | | SSL_ALERT_PROTOCOL_VERSION = 70, |
277 | | /// Insufficient security alert |
278 | | SSL_ALERT_INSUFFICIENT_SECURITY = 71, |
279 | | /// Internal error alert |
280 | | SSL_ALERT_INTERNAL_ERROR = 80, |
281 | | /// User cancelled alert |
282 | | SSL_ALERT_USER_CANCELLED = 90, |
283 | | /// No negotiation alert |
284 | | SSL_ALERT_NO_RENEGOTIATION = 100, |
285 | | /// Unsupported extension alert |
286 | | SSL_ALERT_UNSUPPORTED_EXTENSION = 110, |
287 | | /// Encrtpyed alert (cannot determine its type) |
288 | | SSL_ALERT_ENCRYPTED = 255 |
289 | | }; |
290 | | |
291 | | /// SSL/TLS key exchange algorithms |
292 | | enum SSLKeyExchangeAlgorithm |
293 | | { |
294 | | /// Null value |
295 | | SSL_KEYX_NULL, |
296 | | /// RSA (Rivest-Shamir-Adleman) |
297 | | SSL_KEYX_RSA, |
298 | | /// Diffie-Hellman |
299 | | SSL_KEYX_DH, |
300 | | /// Diffie-Hellman ephemeral |
301 | | SSL_KEYX_DHE, |
302 | | /// Elliptic curve Diffie�Hellman |
303 | | SSL_KEYX_ECDH, |
304 | | /// Elliptic curve Diffie�Hellman ephemeral |
305 | | SSL_KEYX_ECDHE, |
306 | | /// Fortezza Crypto Card |
307 | | SSL_KEYX_FORTEZZA, |
308 | | /// Kerberos 5 |
309 | | SSL_KEYX_KRB5, |
310 | | /// Pre-Shared Key |
311 | | SSL_KEYX_PSK, |
312 | | /// GOST |
313 | | SSL_KEYX_GOST, |
314 | | /// Secure Remote Password |
315 | | SSL_KEYX_SRP, |
316 | | /// PCT |
317 | | SSL_KEYX_PCT, |
318 | | /// Unknown algorithm |
319 | | SSL_KEYX_Unknown |
320 | | }; |
321 | | |
322 | | /// SSL/TLS authentication algorithms |
323 | | enum SSLAuthenticationAlgorithm |
324 | | { |
325 | | /// Null value |
326 | | SSL_AUTH_NULL, |
327 | | /// RSA (Rivest-Shamir-Adleman) |
328 | | SSL_AUTH_RSA, |
329 | | /// Digital Signature Standard |
330 | | SSL_AUTH_DSS, |
331 | | /// Anonymous |
332 | | SSL_AUTH_anon, |
333 | | /// Diffie-Hellman based key-exchange protocol |
334 | | SSL_AUTH_KEA, |
335 | | /// Kerberos 5 |
336 | | SSL_AUTH_KRB5, |
337 | | /// Pre-Shared Key |
338 | | SSL_AUTH_PSK, |
339 | | /// Elliptic Curve Digital Signature Algorithm |
340 | | SSL_AUTH_ECDSA, |
341 | | /// GOST |
342 | | SSL_AUTH_GOST, |
343 | | /// SHA-1 (Secure Hash Algorithm) |
344 | | SSL_AUTH_SHA, |
345 | | /// PCT |
346 | | SSL_AUTH_PCT, |
347 | | /// Diffie-Hellman ephemeral |
348 | | SSL_AUTH_DHE, |
349 | | /// Unknown algorithm |
350 | | SSL_AUTH_Unknown |
351 | | }; |
352 | | |
353 | | /// SSL/TLS symmetric encryption algorithms |
354 | | enum SSLSymmetricEncryptionAlgorithm |
355 | | { |
356 | | /// Null value |
357 | | SSL_SYM_NULL, |
358 | | /// RC4_40 |
359 | | SSL_SYM_RC4_40, |
360 | | /// RC4_128 |
361 | | SSL_SYM_RC4_128, |
362 | | /// RC2_CBC_40 |
363 | | SSL_SYM_RC2_CBC_40, |
364 | | /// IDEA_CBC |
365 | | SSL_SYM_IDEA_CBC, |
366 | | /// DES40_CBC |
367 | | SSL_SYM_DES40_CBC, |
368 | | /// DES_CBC |
369 | | SSL_SYM_DES_CBC, |
370 | | /// 3DES_EDE_CBC |
371 | | SSL_SYM_3DES_EDE_CBC, |
372 | | /// FORTEZZA_CBC |
373 | | SSL_SYM_FORTEZZA_CBC, |
374 | | /// DES_CBC_40 |
375 | | SSL_SYM_DES_CBC_40, |
376 | | /// AES_128_CBC |
377 | | SSL_SYM_AES_128_CBC, |
378 | | /// AES_256_CBC |
379 | | SSL_SYM_AES_256_CBC, |
380 | | /// CAMELLIA_128_CBC |
381 | | SSL_SYM_CAMELLIA_128_CBC, |
382 | | /// CAMELLIA_128_GCM |
383 | | SSL_SYM_CAMELLIA_128_GCM, |
384 | | /// CAMELLIA_256_GCM |
385 | | SSL_SYM_CAMELLIA_256_GCM, |
386 | | /// RC4_56 |
387 | | SSL_SYM_RC4_56, |
388 | | /// RC2_CBC_56 |
389 | | SSL_SYM_RC2_CBC_56, |
390 | | /// GOST28147 |
391 | | SSL_SYM_GOST28147, |
392 | | /// CAMELLIA_256_CBC |
393 | | SSL_SYM_CAMELLIA_256_CBC, |
394 | | /// SEED_CBC |
395 | | SSL_SYM_SEED_CBC, |
396 | | /// AES_128 |
397 | | SSL_SYM_AES_128, |
398 | | /// AES_256 |
399 | | SSL_SYM_AES_256, |
400 | | /// SSL_SYM_AES_128_GCM |
401 | | SSL_SYM_AES_128_GCM, |
402 | | /// AES_256_GCM |
403 | | SSL_SYM_AES_256_GCM, |
404 | | /// RC4_128_EXPORT40 |
405 | | SSL_SYM_RC4_128_EXPORT40, |
406 | | /// RC2_CBC_128_CBC |
407 | | SSL_SYM_RC2_CBC_128_CBC, |
408 | | /// IDEA_128_CBC |
409 | | SSL_SYM_IDEA_128_CBC, |
410 | | /// DES_64_CBC |
411 | | SSL_SYM_DES_64_CBC, |
412 | | /// DES_192_EDE3_CBC |
413 | | SSL_SYM_DES_192_EDE3_CBC, |
414 | | /// RC4_64 |
415 | | SSL_SYM_RC4_64, |
416 | | /// ARIA_128_CBC |
417 | | SSL_SYM_ARIA_128_CBC, |
418 | | /// ARIA_256_CBC |
419 | | SSL_SYM_ARIA_256_CBC, |
420 | | /// ARIA_128_GCM |
421 | | SSL_SYM_ARIA_128_GCM, |
422 | | /// ARIA_256_GCM |
423 | | SSL_SYM_ARIA_256_GCM, |
424 | | /// CHACHA20_POLY1305 |
425 | | SSL_SYM_CHACHA20_POLY1305, |
426 | | /// AES_128_CCM |
427 | | SSL_SYM_AES_128_CCM, |
428 | | /// AES_128_CCM_8 |
429 | | SSL_SYM_AES_128_CCM_8, |
430 | | /// Unknown algorithm |
431 | | SSL_SYM_Unknown |
432 | | }; |
433 | | /// Deprecated typo, use SSLSymmetricEncryptionAlgorithm instead |
434 | | using SSLSymetricEncryptionAlgorithm PCPP_DEPRECATED("Use SSLSymmetricEncryptionAlgorithm instead") = |
435 | | SSLSymmetricEncryptionAlgorithm; |
436 | | |
437 | | /// SSL/TLS hashing algorithms |
438 | | enum SSLHashingAlgorithm |
439 | | { |
440 | | /// Null value |
441 | | SSL_HASH_NULL, |
442 | | /// Message-Digest Algorithm |
443 | | SSL_HASH_MD5, |
444 | | /// SHA-1 (Secure Hash Algorithm) |
445 | | SSL_HASH_SHA, |
446 | | /// SHA-256 (Secure Hash Algorithm) |
447 | | SSL_HASH_SHA256, |
448 | | /// GOST 28147 |
449 | | SSL_HASH_GOST28147, |
450 | | /// GOST R 34.11 |
451 | | SSL_HASH_GOSTR3411, |
452 | | /// SHA-384 (Secure Hash Algorithm) |
453 | | SSL_HASH_SHA384, |
454 | | /// CCM mode (Counter with CBC-MAC) |
455 | | SSL_HASH_CCM, |
456 | | /// CCM mode (Counter with CBC-MAC) |
457 | | SSL_HASH_CCM_8, |
458 | | /// Unknown algorithm |
459 | | SSL_HASH_Unknown |
460 | | }; |
461 | | |
462 | | /// SSL/TLS extension types |
463 | | enum SSLExtensionType |
464 | | { |
465 | | /// Server Name Indication extension |
466 | | SSL_EXT_SERVER_NAME = 0, |
467 | | /// Maximum Fragment Length Negotiation extension |
468 | | SSL_EXT_MAX_FRAGMENT_LENGTH = 1, |
469 | | /// Client Certificate URLs extension |
470 | | SSL_EXT_CLIENT_CERTIFICATE_URL = 2, |
471 | | /// Trusted CA Indication extension |
472 | | SSL_EXT_TRUSTED_CA_KEYS = 3, |
473 | | /// Truncated HMAC extension |
474 | | SSL_EXT_TRUNCATED_HMAC = 4, |
475 | | /// Certificate Status Request extension |
476 | | SSL_EXT_STATUS_REQUEST = 5, |
477 | | /// TLS User Mapping extension |
478 | | SSL_EXT_USER_MAPPING = 6, |
479 | | /// Client Authorization extension |
480 | | SSL_EXT_CLIENT_AUTHZ = 7, |
481 | | /// Server Authorization extension |
482 | | SSL_EXT_SERVER_AUTHZ = 8, |
483 | | /// Certificate Type extension |
484 | | SSL_EXT_CERT_TYPE = 9, |
485 | | /// Supported Groups extension (renamed from "elliptic curves") |
486 | | SSL_EXT_SUPPORTED_GROUPS = 10, |
487 | | /// Elliptic Curves Point Format extension |
488 | | SSL_EXT_EC_POINT_FORMATS = 11, |
489 | | /// Secure Remote Password extension |
490 | | SSL_EXT_SRP = 12, |
491 | | /// Signature Algorithms extension |
492 | | SSL_EXT_SIGNATURE_ALGORITHMS = 13, |
493 | | /// Use Secure Real-time Transport Protocol extension |
494 | | SSL_EXT_USE_SRTP = 14, |
495 | | /// TLS Heartbit extension |
496 | | SSL_EXT_HEARTBEAT = 15, |
497 | | /// Application Layer Protocol Negotiation (ALPN) extension |
498 | | SSL_EXT_APPLICATION_LAYER_PROTOCOL_NEGOTIATION = 16, |
499 | | /// Status Request extension |
500 | | SSL_EXT_STATUS_REQUEST_V2 = 17, |
501 | | /// Signed Certificate Timestamp extension |
502 | | SSL_EXT_SIGNED_CERTIFICATE_TIMESTAMP = 18, |
503 | | /// Client Certificate Type extension |
504 | | SSL_EXT_CLIENT_CERTIFICATE_TYPE = 19, |
505 | | /// Server Certificate Type extension |
506 | | SSL_EXT_SERVER_CERTIFICATE_TYPE = 20, |
507 | | /// ClientHello Padding extension |
508 | | SSL_EXT_PADDING = 21, |
509 | | /// Encrypt-then-MAC extension |
510 | | SSL_EXT_ENCRYPT_THEN_MAC = 22, |
511 | | /// Extended Master Secret extension |
512 | | SSL_EXT_EXTENDED_MASTER_SECRET = 23, |
513 | | /// Token Binding extension |
514 | | SSL_EXT_TOKEN_BINDING = 24, |
515 | | /// SessionTicket TLS extension |
516 | | SSL_EXT_SESSIONTICKET_TLS = 35, |
517 | | /// Pre-shared key (PSK) extension (TLS 1.3) |
518 | | SSL_EXT_PRE_SHARED_KEY = 41, |
519 | | /// Early data extension (TLS 1.3) |
520 | | SSL_EXT_EARLY_DATA = 42, |
521 | | /// Supported versions extension (TLS 1.3) |
522 | | SSL_EXT_SUPPORTED_VERSIONS = 43, |
523 | | /// Cookie extension (TLS 1.3) |
524 | | SSL_EXT_COOKIE = 44, |
525 | | /// Pre-Shared Key Exchange Modes extension (TLS 1.3) |
526 | | SSL_EXT_PSK_KEY_EXCHANGE_MODES = 45, |
527 | | /// Certificate authorities extension (TLS 1.3) |
528 | | SSL_EXT_CERTIFICATE_AUTHORITIES = 47, |
529 | | /// Old filters extension (TLS 1.3) |
530 | | SSL_EXT_OLD_FILTERS = 48, |
531 | | /// Post handshake auth extension (TLS 1.3) |
532 | | SSL_EXT_POST_HANDSHAKE_AUTH = 49, |
533 | | /// Signature algorithm cert extension (TLS 1.3) |
534 | | SSL_EXT_SIGNATURE_ALGORITHM_CERT = 50, |
535 | | /// Key share extension (TLS 1.3) |
536 | | SSL_EXT_KEY_SHARE = 51, |
537 | | /// Renegotiation Indication extension |
538 | | SSL_EXT_RENEGOTIATION_INFO = 65281, |
539 | | /// Unknown extension |
540 | | SSL_EXT_Unknown |
541 | | }; |
542 | | |
543 | | /// SSL/TLS client certificate types |
544 | | enum SSLClientCertificateType |
545 | | { |
546 | | /// RSA_SIGN |
547 | | SSL_CCT_RSA_SIGN = 1, |
548 | | /// DSS_SIGN |
549 | | SSL_CCT_DSS_SIGN = 2, |
550 | | /// RSA_FIXED_DH |
551 | | SSL_CCT_RSA_FIXED_DH = 3, |
552 | | /// DSS_FIXED_DH |
553 | | SSL_CCT_DSS_FIXED_DH = 4, |
554 | | /// RSA_EPHEMERAL_DH_RESERVED |
555 | | SSL_CCT_RSA_EPHEMERAL_DH_RESERVED = 5, |
556 | | /// DSS_EPHEMERAL_DH_RESERVED |
557 | | SSL_CCT_DSS_EPHEMERAL_DH_RESERVED = 6, |
558 | | /// FORTEZZA_DMS_RESERVED |
559 | | SSL_CCT_FORTEZZA_DMS_RESERVED = 20, |
560 | | /// ECDSA_SIGN |
561 | | SSL_CCT_ECDSA_SIGN = 64, |
562 | | /// FIXED_ECDH |
563 | | SSL_CCT_RSA_FIXED_ECDH = 65, |
564 | | /// ECDSA_FIXED_ECDH |
565 | | SSL_CCT_ECDSA_FIXED_ECDH = 66, |
566 | | /// Unknown client certificate type |
567 | | SSL_CCT_UNKNOWN |
568 | | }; |
569 | | } // namespace pcpp |