Coverage Report

Created: 2026-09-04 06:30

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wolfssl/wolfssl/internal.h
Line
Count
Source
1
/* internal.h
2
 *
3
 * Copyright (C) 2006-2026 wolfSSL Inc.
4
 *
5
 * This file is part of wolfSSL.
6
 *
7
 * wolfSSL is free software; you can redistribute it and/or modify
8
 * it under the terms of the GNU General Public License as published by
9
 * the Free Software Foundation; either version 3 of the License, or
10
 * (at your option) any later version.
11
 *
12
 * wolfSSL is distributed in the hope that it will be useful,
13
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
15
 * GNU General Public License for more details.
16
 *
17
 * You should have received a copy of the GNU General Public License
18
 * along with this program; if not, write to the Free Software
19
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335, USA
20
 */
21
22
23
24
#ifndef WOLFSSL_INT_H
25
#define WOLFSSL_INT_H
26
27
#include <wolfssl/wolfcrypt/types.h>
28
#include <wolfssl/ssl.h>
29
#include <wolfssl/wolfio.h>
30
#ifdef HAVE_CRL
31
    #include <wolfssl/crl.h>
32
#endif
33
#include <wolfssl/wolfcrypt/random.h>
34
#ifndef NO_DES3
35
    #include <wolfssl/wolfcrypt/des3.h>
36
#endif
37
#ifdef HAVE_CHACHA
38
    #include <wolfssl/wolfcrypt/chacha.h>
39
#endif
40
#ifndef NO_ASN
41
    #include <wolfssl/wolfcrypt/asn.h>
42
    #include <wolfssl/wolfcrypt/pkcs12.h>
43
#endif
44
#ifndef NO_MD5
45
    #include <wolfssl/wolfcrypt/md5.h>
46
#endif
47
#ifndef NO_SHA
48
    #include <wolfssl/wolfcrypt/sha.h>
49
#endif
50
#ifndef NO_AES
51
    #include <wolfssl/wolfcrypt/aes.h>
52
#endif
53
#ifdef HAVE_POLY1305
54
    #include <wolfssl/wolfcrypt/poly1305.h>
55
#endif
56
#if defined(HAVE_CHACHA) && defined(HAVE_POLY1305)
57
    /* Not OPENSSL_EXTRA-only: the TLS record layer calls the persistent-key
58
     * helpers wc_ChaCha20Poly1305_{Encrypt,Decrypt}_ex(), so this header has
59
     * to be visible whenever the ChaCha20-Poly1305 suites are built. */
60
    #include <wolfssl/wolfcrypt/chacha20_poly1305.h>
61
#endif
62
#ifdef HAVE_ARIA
63
    #include <wolfssl/wolfcrypt/port/aria/aria-crypt.h>
64
#endif
65
#ifdef HAVE_CAMELLIA
66
    #include <wolfssl/wolfcrypt/camellia.h>
67
#endif
68
#ifdef WOLFSSL_SM4
69
    #include <wolfssl/wolfcrypt/sm4.h>
70
#endif
71
#include <wolfssl/wolfcrypt/logging.h>
72
#ifndef NO_HMAC
73
    #include <wolfssl/wolfcrypt/hmac.h>
74
#endif
75
#ifndef NO_RC4
76
    #include <wolfssl/wolfcrypt/arc4.h>
77
#endif
78
#ifndef NO_SHA256
79
    #include <wolfssl/wolfcrypt/sha256.h>
80
#endif
81
#if defined(WOLFSSL_SHA384)
82
    #include <wolfssl/wolfcrypt/sha512.h>
83
#endif
84
#ifdef HAVE_OCSP
85
    #include <wolfssl/ocsp.h>
86
#endif
87
#ifdef WOLFSSL_QUIC
88
    #include <wolfssl/quic.h>
89
#endif
90
#ifdef WOLFSSL_SHA384
91
    #include <wolfssl/wolfcrypt/sha512.h>
92
#endif
93
#ifdef WOLFSSL_SHA512
94
    #include <wolfssl/wolfcrypt/sha512.h>
95
#endif
96
#ifdef WOLFSSL_SM3
97
    #include <wolfssl/wolfcrypt/sm3.h>
98
#endif
99
#ifdef HAVE_AESGCM
100
    #include <wolfssl/wolfcrypt/sha512.h>
101
#endif
102
#ifdef WOLFSSL_RIPEMD
103
    #include <wolfssl/wolfcrypt/ripemd.h>
104
#endif
105
#ifndef NO_RSA
106
    #include <wolfssl/wolfcrypt/rsa.h>
107
#endif
108
#ifdef HAVE_ECC
109
    #include <wolfssl/wolfcrypt/ecc.h>
110
#endif
111
#ifdef WOLFSSL_SM2
112
    #include <wolfssl/wolfcrypt/sm2.h>
113
#endif
114
#ifndef NO_DH
115
    #include <wolfssl/wolfcrypt/dh.h>
116
#endif
117
#ifdef HAVE_ED25519
118
    #include <wolfssl/wolfcrypt/ed25519.h>
119
#endif
120
#ifdef HAVE_CURVE25519
121
    #include <wolfssl/wolfcrypt/curve25519.h>
122
#endif
123
#ifdef HAVE_ED448
124
    #include <wolfssl/wolfcrypt/ed448.h>
125
#endif
126
#ifdef HAVE_CURVE448
127
    #include <wolfssl/wolfcrypt/curve448.h>
128
#endif
129
#ifdef HAVE_FALCON
130
    #include <wolfssl/wolfcrypt/falcon.h>
131
#endif
132
#ifdef WOLFSSL_HAVE_MLDSA
133
    #include <wolfssl/wolfcrypt/wc_mldsa.h>
134
#endif
135
#ifdef WOLFSSL_HAVE_SLHDSA
136
    #include <wolfssl/wolfcrypt/wc_slhdsa.h>
137
#endif
138
#ifdef HAVE_HKDF
139
    #include <wolfssl/wolfcrypt/kdf.h>
140
#endif
141
#ifndef WOLFSSL_NO_DEF_TICKET_ENC_CB
142
    #if defined(HAVE_CHACHA) && defined(HAVE_POLY1305) && \
143
        !defined(WOLFSSL_TICKET_ENC_AES128_GCM) && \
144
        !defined(WOLFSSL_TICKET_ENC_AES256_GCM)
145
        #include <wolfssl/wolfcrypt/chacha20_poly1305.h>
146
    #else
147
        #include <wolfssl/wolfcrypt/aes.h>
148
    #endif
149
#endif
150
151
#include <wolfssl/wolfcrypt/wc_encrypt.h>
152
#include <wolfssl/wolfcrypt/hash.h>
153
154
#if defined(WOLFSSL_CALLBACKS) || defined(OPENSSL_EXTRA)
155
    #include <wolfssl/callbacks.h>
156
#endif
157
#ifdef WOLFSSL_CALLBACKS
158
    #include <signal.h>
159
#endif
160
161
#ifdef WOLFSSL_APACHE_MYNEWT
162
    #if !defined(WOLFSSL_LWIP)
163
        void mynewt_ctx_clear(void *ctx);
164
        void* mynewt_ctx_new();
165
    #endif
166
#endif
167
168
#if !defined(WOLFCRYPT_ONLY) && !defined(INT_MAX)
169
    /* Needed for TLS/DTLS limit checking (Added in 91aad90c59 Jan 24, 2025) */
170
    #include <limits.h>
171
#endif
172
173
174
#ifdef HAVE_LIBZ
175
    #include "zlib.h"
176
#endif
177
178
#ifdef WOLFSSL_ASYNC_CRYPT
179
    #include <wolfssl/wolfcrypt/async.h>
180
#endif
181
182
#ifdef OPENSSL_EXTRA
183
    #ifdef WOLFCRYPT_HAVE_SRP
184
        #include <wolfssl/wolfcrypt/srp.h>
185
    #endif
186
#endif
187
188
#ifdef _MSC_VER
189
    /* 4996 warning to use MS extensions e.g., strcpy_s instead of strncpy */
190
    #pragma warning(disable: 4996)
191
#endif
192
193
#ifdef NO_SHA
194
    #define WC_SHA_DIGEST_SIZE 20
195
#endif
196
197
#ifdef NO_SHA256
198
    #define WC_SHA256_DIGEST_SIZE 32
199
#endif
200
201
#ifdef NO_MD5
202
    #define WC_MD5_DIGEST_SIZE 16
203
#endif
204
205
#ifdef WOLFSSL_IOTSAFE
206
    #include <wolfssl/wolfcrypt/port/iotsafe/iotsafe.h>
207
#endif
208
209
#if defined(WOLFSSL_RENESAS_TSIP_TLS)
210
    #include <wolfssl/wolfcrypt/port/Renesas/renesas_tsip_internal.h>
211
#endif
212
213
#include <wolfssl/wolfcrypt/hpke.h>
214
215
#if defined(WOLFSSL_SNIFFER) && defined(WOLFSSL_SNIFFER_KEYLOGFILE)
216
#include <wolfssl/sniffer.h>
217
#endif /* WOLFSSL_SNIFFER && WOLFSSL_SNIFFER_KEYLOGFILE */
218
219
#ifdef WOLFSSL_TEST_APPLE_NATIVE_CERT_VALIDATION
220
    #include <CoreFoundation/CoreFoundation.h>
221
#endif /* WOLFSSL_TEST_APPLE_NATIVE_CERT_VALIDATION */
222
223
#ifdef __cplusplus
224
    extern "C" {
225
#endif
226
227
/* ML-KEM client support requires generating a key pair (encapsulation key) and
228
 * decapsulating the server's ciphertext. */
229
#if defined(WOLFSSL_HAVE_MLKEM) && !defined(WOLFSSL_MLKEM_NO_MAKE_KEY) && \
230
     !defined(WOLFSSL_MLKEM_NO_DECAPSULATE)
231
    #define WOLFSSL_HAVE_MLKEM_CLIENT_SUPPORT
232
#endif
233
/* ML-KEM server support requires encapsulating to the client's key. */
234
#if defined(WOLFSSL_HAVE_MLKEM) && !defined(WOLFSSL_MLKEM_NO_ENCAPSULATE)
235
    #define WOLFSSL_HAVE_MLKEM_SERVER_SUPPORT
236
#endif
237
238
/* Define or comment out the cipher suites you'd like to be compiled in
239
   make sure to use at least one BUILD_SSL_xxx or BUILD_TLS_xxx is defined
240
241
   When adding cipher suites, add name to cipher_names, idx to cipher_name_idx
242
243
   Now that there is a maximum strength crypto build, the following BUILD_XXX
244
   flags need to be divided into two groups selected by WOLFSSL_MAX_STRENGTH.
245
   Those that do not use Perfect Forward Security and do not use AEAD ciphers
246
   need to be switched off. Allowed suites use (EC)DHE, AES-GCM|CCM, or
247
   CHACHA-POLY.
248
*/
249
250
/* Check that if WOLFSSL_MAX_STRENGTH is set that all the required options are
251
 * not turned off. */
252
#if defined(WOLFSSL_MAX_STRENGTH) && \
253
    ((!defined(HAVE_ECC) && (defined(NO_DH) || defined(NO_RSA))) || \
254
     (!defined(HAVE_AESGCM) && !defined(HAVE_AESCCM) && \
255
      (!defined(HAVE_POLY1305) || !defined(HAVE_CHACHA))) || \
256
     (defined(NO_SHA256) && !defined(WOLFSSL_SHA384)) || \
257
     !defined(NO_OLD_TLS))
258
259
    #error "You are trying to build max strength with requirements disabled."
260
#endif
261
262
#ifndef WOLFSSL_NO_TLS12
263
264
#ifndef WOLFSSL_MAX_STRENGTH
265
266
#ifdef WOLFSSL_AEAD_ONLY
267
    /* AES CBC ciphers are not allowed in AEAD only mode */
268
    #undef HAVE_AES_CBC
269
#endif
270
271
/* When adding new ciphersuites, make sure that they have appropriate
272
 * guards for WOLFSSL_HARDEN_TLS. */
273
#if defined(WOLFSSL_HARDEN_TLS) && \
274
    !defined(WOLFSSL_HARDEN_TLS_ALLOW_ALL_CIPHERSUITES)
275
/* Use a separate define (undef'ed later) to simplify macro logic. */
276
#define WSSL_HARDEN_TLS WOLFSSL_HARDEN_TLS
277
#define NO_TLS_DH
278
#endif
279
280
#ifndef WOLFSSL_AEAD_ONLY
281
    #if !defined(NO_RSA) && !defined(NO_RC4) && !defined(WSSL_HARDEN_TLS)
282
        /* MUST NOT negotiate RC4 cipher suites
283
         * https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
284
        #if defined(WOLFSSL_STATIC_RSA)
285
            #if !defined(NO_SHA)
286
                #define BUILD_SSL_RSA_WITH_RC4_128_SHA
287
            #endif
288
            #if !defined(NO_MD5)
289
                #define BUILD_SSL_RSA_WITH_RC4_128_MD5
290
            #endif
291
        #endif
292
    #endif
293
294
    #if !defined(NO_RSA) && !defined(NO_DES3) && !defined(NO_DES3_TLS_SUITES)
295
        #if !defined(NO_SHA)
296
            #if defined(WOLFSSL_STATIC_RSA)
297
                #define BUILD_SSL_RSA_WITH_3DES_EDE_CBC_SHA
298
            #endif
299
        #endif
300
    #endif
301
#endif /* !WOLFSSL_AEAD_ONLY */
302
303
    #if !defined(NO_RSA) && !defined(NO_AES) && !defined(NO_TLS)
304
        #if !defined(NO_SHA) && defined(HAVE_AES_CBC)
305
            #if defined(WOLFSSL_STATIC_RSA)
306
                #ifdef WOLFSSL_AES_128
307
                    #define BUILD_TLS_RSA_WITH_AES_128_CBC_SHA
308
                #endif
309
                #ifdef WOLFSSL_AES_256
310
                    #define BUILD_TLS_RSA_WITH_AES_256_CBC_SHA
311
                #endif
312
            #endif
313
        #endif
314
        #if defined(WOLFSSL_STATIC_RSA)
315
            #if !defined (NO_SHA256) && defined(HAVE_AES_CBC)
316
                #ifdef WOLFSSL_AES_128
317
                    #define BUILD_TLS_RSA_WITH_AES_128_CBC_SHA256
318
                #endif
319
                #ifdef WOLFSSL_AES_256
320
                    #define BUILD_TLS_RSA_WITH_AES_256_CBC_SHA256
321
                #endif
322
            #endif
323
            #if defined (HAVE_AESGCM)
324
                #ifdef WOLFSSL_AES_128
325
                    #define BUILD_TLS_RSA_WITH_AES_128_GCM_SHA256
326
                #endif
327
                #if defined (WOLFSSL_SHA384) && defined(WOLFSSL_AES_256)
328
                    #define BUILD_TLS_RSA_WITH_AES_256_GCM_SHA384
329
                #endif
330
            #endif
331
            #if defined (HAVE_AESCCM)
332
                #ifdef WOLFSSL_AES_128
333
                    #define BUILD_TLS_RSA_WITH_AES_128_CCM_8
334
                #endif
335
                #ifdef WOLFSSL_AES_256
336
                    #define BUILD_TLS_RSA_WITH_AES_256_CCM_8
337
                #endif
338
            #endif
339
        #endif
340
    #endif
341
342
    #if defined(HAVE_CAMELLIA) && !defined(NO_TLS) && !defined(NO_CAMELLIA_CBC)
343
        #ifndef NO_RSA
344
          #if defined(WOLFSSL_STATIC_RSA)
345
            #if !defined(NO_SHA)
346
                #define BUILD_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA
347
                #define BUILD_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA
348
            #endif
349
            #ifndef NO_SHA256
350
                #define BUILD_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256
351
                #define BUILD_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256
352
            #endif
353
          #endif
354
            #if !defined(NO_DH) && !defined(NO_TLS_DH)
355
              /* SHOULD NOT negotiate cipher suites based on ephemeral
356
               * finite-field Diffie-Hellman key agreement (i.e., "TLS_DHE_*"
357
               * suites). https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
358
              #if !defined(NO_SHA)
359
                #define BUILD_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA
360
                #define BUILD_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA
361
              #endif
362
                #ifndef NO_SHA256
363
                    #define BUILD_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256
364
                    #define BUILD_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256
365
                #endif
366
            #endif
367
        #endif
368
    #endif
369
370
#if defined(WOLFSSL_STATIC_PSK)
371
    #if !defined(NO_PSK) && !defined(NO_AES) && !defined(NO_TLS)
372
        #if !defined(NO_SHA)
373
            #ifdef WOLFSSL_AES_128
374
                #define BUILD_TLS_PSK_WITH_AES_128_CBC_SHA
375
            #endif
376
            #ifdef WOLFSSL_AES_256
377
                #define BUILD_TLS_PSK_WITH_AES_256_CBC_SHA
378
            #endif
379
        #endif
380
        #ifndef NO_SHA256
381
            #ifdef WOLFSSL_AES_128
382
                #ifdef HAVE_AES_CBC
383
                    #define BUILD_TLS_PSK_WITH_AES_128_CBC_SHA256
384
                #endif
385
                #ifdef HAVE_AESGCM
386
                    #define BUILD_TLS_PSK_WITH_AES_128_GCM_SHA256
387
                #endif
388
            #endif /* WOLFSSL_AES_128 */
389
            #ifdef HAVE_AESCCM
390
                #ifdef WOLFSSL_AES_128
391
                    #define BUILD_TLS_PSK_WITH_AES_128_CCM_8
392
                    #define BUILD_TLS_PSK_WITH_AES_128_CCM
393
                #endif
394
                #ifdef WOLFSSL_AES_256
395
                    #define BUILD_TLS_PSK_WITH_AES_256_CCM_8
396
                    #define BUILD_TLS_PSK_WITH_AES_256_CCM
397
                #endif
398
            #endif
399
        #endif
400
        #if defined(WOLFSSL_SHA384) && defined(WOLFSSL_AES_256)
401
            #ifdef HAVE_AES_CBC
402
                #define BUILD_TLS_PSK_WITH_AES_256_CBC_SHA384
403
            #endif
404
            #ifdef HAVE_AESGCM
405
                #define BUILD_TLS_PSK_WITH_AES_256_GCM_SHA384
406
            #endif
407
        #endif
408
    #endif
409
#endif
410
411
    #if !defined(NO_TLS) && defined(HAVE_NULL_CIPHER)
412
        #if !defined(NO_RSA)
413
            #if defined(WOLFSSL_STATIC_RSA)
414
                #ifndef NO_MD5
415
                    #define BUILD_TLS_RSA_WITH_NULL_MD5
416
                #endif
417
                #if !defined(NO_SHA)
418
                    #define BUILD_TLS_RSA_WITH_NULL_SHA
419
                #endif
420
                #ifndef NO_SHA256
421
                    #define BUILD_TLS_RSA_WITH_NULL_SHA256
422
                #endif
423
            #endif
424
        #endif
425
        #if !defined(NO_PSK) && defined(WOLFSSL_STATIC_PSK)
426
            #if !defined(NO_SHA)
427
                #define BUILD_TLS_PSK_WITH_NULL_SHA
428
            #endif
429
            #ifndef NO_SHA256
430
                #define BUILD_TLS_PSK_WITH_NULL_SHA256
431
            #endif
432
            #ifdef WOLFSSL_SHA384
433
                #define BUILD_TLS_PSK_WITH_NULL_SHA384
434
            #endif
435
        #endif
436
    #endif
437
438
    #if !defined(NO_DH) && !defined(NO_AES) && !defined(NO_TLS) && \
439
        !defined(NO_RSA) && !defined(NO_TLS_DH)
440
        /* SHOULD NOT negotiate cipher suites based on ephemeral
441
         * finite-field Diffie-Hellman key agreement (i.e., "TLS_DHE_*"
442
         * suites). https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
443
444
        #if !defined(NO_SHA)
445
            #if defined(WOLFSSL_AES_128) && defined(HAVE_AES_CBC)
446
                #define BUILD_TLS_DHE_RSA_WITH_AES_128_CBC_SHA
447
            #endif
448
            #if defined(WOLFSSL_AES_256) && defined(HAVE_AES_CBC)
449
                #define BUILD_TLS_DHE_RSA_WITH_AES_256_CBC_SHA
450
            #endif
451
            #if !defined(NO_DES3) && !defined(NO_DES3_TLS_SUITES)
452
                #define BUILD_TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA
453
            #endif
454
        #endif
455
        #if !defined(NO_SHA256) && defined(HAVE_AES_CBC)
456
            #ifdef WOLFSSL_AES_128
457
                #define BUILD_TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
458
            #endif
459
            #ifdef WOLFSSL_AES_256
460
                #define BUILD_TLS_DHE_RSA_WITH_AES_256_CBC_SHA256
461
            #endif
462
        #endif
463
    #endif
464
465
    #if defined(HAVE_ANON) && !defined(NO_TLS) && !defined(NO_DH) && \
466
        !defined(NO_AES)
467
        #if !defined(NO_SHA) && defined(HAVE_AES_CBC) && \
468
                defined(WOLFSSL_AES_128)
469
            #define BUILD_TLS_DH_anon_WITH_AES_128_CBC_SHA
470
        #endif
471
        #if defined(WOLFSSL_SHA384) && defined(HAVE_AESGCM) && \
472
                defined(WOLFSSL_AES_256)
473
            #define BUILD_TLS_DH_anon_WITH_AES_256_GCM_SHA384
474
        #endif
475
    #endif
476
477
    #if !defined(NO_DH) && !defined(NO_PSK) && !defined(NO_TLS) && \
478
        !defined(NO_TLS_DH)
479
        /* SHOULD NOT negotiate cipher suites based on ephemeral
480
         * finite-field Diffie-Hellman key agreement (i.e., "TLS_DHE_*"
481
         * suites). https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
482
        #ifndef NO_SHA256
483
            #if !defined(NO_AES) && defined(WOLFSSL_AES_128) && \
484
                                                           defined(HAVE_AES_CBC)
485
                #define BUILD_TLS_DHE_PSK_WITH_AES_128_CBC_SHA256
486
            #endif
487
            #ifdef HAVE_NULL_CIPHER
488
                #define BUILD_TLS_DHE_PSK_WITH_NULL_SHA256
489
            #endif
490
        #endif
491
        #ifdef WOLFSSL_SHA384
492
            #if !defined(NO_AES) && defined(WOLFSSL_AES_256) && \
493
                                                           defined(HAVE_AES_CBC)
494
                #define BUILD_TLS_DHE_PSK_WITH_AES_256_CBC_SHA384
495
            #endif
496
            #ifdef HAVE_NULL_CIPHER
497
                #define BUILD_TLS_DHE_PSK_WITH_NULL_SHA384
498
            #endif
499
        #endif
500
    #endif
501
502
    #if (defined(HAVE_ECC) || defined(HAVE_CURVE25519) || \
503
                                     defined(HAVE_CURVE448)) && !defined(NO_TLS)
504
        #if !defined(NO_AES)
505
            #if !defined(NO_SHA) && defined(HAVE_AES_CBC)
506
                #if !defined(NO_RSA)
507
                    #ifdef WOLFSSL_AES_128
508
                        #define BUILD_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
509
                    #endif
510
                    #ifdef WOLFSSL_AES_256
511
                        #define BUILD_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
512
                    #endif
513
                    #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
514
                        #ifdef WOLFSSL_AES_128
515
                            #define BUILD_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA
516
                        #endif
517
                        #ifdef WOLFSSL_AES_256
518
                            #define BUILD_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA
519
                        #endif
520
                    #endif
521
                #endif
522
523
                #if defined(HAVE_ECC) || \
524
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
525
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
526
                    #ifdef WOLFSSL_AES_128
527
                        #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
528
                    #endif
529
                    #ifdef WOLFSSL_AES_256
530
                        #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
531
                    #endif
532
                #endif
533
534
                #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
535
                    #ifdef WOLFSSL_AES_128
536
                        #define BUILD_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA
537
                    #endif
538
                    #ifdef WOLFSSL_AES_256
539
                        #define BUILD_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA
540
                    #endif
541
                #endif
542
            #endif /* NO_SHA */
543
            #if !defined(NO_SHA256) && defined(WOLFSSL_AES_128) && \
544
                                                           defined(HAVE_AES_CBC)
545
                #if !defined(NO_RSA)
546
                    #define BUILD_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
547
                    #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
548
                        #define BUILD_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256
549
                    #endif
550
                #endif
551
                #if defined(HAVE_ECC) || \
552
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
553
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
554
                    #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256
555
                #endif
556
                #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
557
                    #define BUILD_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256
558
                #endif
559
            #endif
560
561
            #if defined(WOLFSSL_SHA384) && defined(WOLFSSL_AES_256) && \
562
                                                           defined(HAVE_AES_CBC)
563
                #if !defined(NO_RSA)
564
                    #define BUILD_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
565
                    #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
566
                        #define BUILD_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384
567
                    #endif
568
                #endif
569
                #if defined(HAVE_ECC) || \
570
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
571
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
572
                    #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384
573
                #endif
574
                #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
575
                    #define BUILD_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384
576
                #endif
577
            #endif
578
579
            #if defined (HAVE_AESGCM)
580
                #if !defined(NO_RSA)
581
                    #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
582
                        #ifdef WOLFSSL_AES_128
583
                            #define BUILD_TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256
584
                        #endif
585
                    #endif
586
                    #if defined(WOLFSSL_SHA384)
587
                        #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
588
                            #ifdef WOLFSSL_AES_256
589
                                #define BUILD_TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384
590
                            #endif
591
                        #endif
592
                    #endif
593
                #endif
594
595
                #if defined(WOLFSSL_STATIC_DH) && defined(WOLFSSL_AES_128) && \
596
                                                               defined(HAVE_ECC)
597
                    #define BUILD_TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256
598
                #endif
599
600
                #if defined(WOLFSSL_SHA384)
601
                    #if defined(WOLFSSL_STATIC_DH) && \
602
                                   defined(WOLFSSL_AES_256) && defined(HAVE_ECC)
603
                        #define BUILD_TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384
604
                    #endif
605
                #endif
606
            #endif
607
        #endif /* NO_AES */
608
        #ifdef HAVE_ARIA
609
            #define BUILD_TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256
610
            #define BUILD_TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384
611
        #endif /* HAVE_ARIA */
612
        #if !defined(NO_RC4) && !defined(WSSL_HARDEN_TLS)
613
            /* MUST NOT negotiate RC4 cipher suites
614
             * https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
615
            #if !defined(NO_SHA)
616
                #if !defined(NO_RSA)
617
                    #ifndef WOLFSSL_AEAD_ONLY
618
                        #define BUILD_TLS_ECDHE_RSA_WITH_RC4_128_SHA
619
                    #endif
620
                    #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
621
                        #define BUILD_TLS_ECDH_RSA_WITH_RC4_128_SHA
622
                    #endif
623
                #endif
624
625
                #if defined(HAVE_ECC) || \
626
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
627
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
628
                    #ifndef WOLFSSL_AEAD_ONLY
629
                        #define BUILD_TLS_ECDHE_ECDSA_WITH_RC4_128_SHA
630
                    #endif
631
                #endif
632
                #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
633
                    #define BUILD_TLS_ECDH_ECDSA_WITH_RC4_128_SHA
634
                #endif
635
            #endif
636
        #endif
637
        #if !defined(NO_DES3) && !(defined(WSSL_HARDEN_TLS) && \
638
                                           WSSL_HARDEN_TLS > 112) && \
639
            !defined(NO_DES3_TLS_SUITES)
640
            /* 3DES offers only 112 bits of security.
641
             * Using guidance from section 5.6.1
642
             * https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf */
643
            #ifndef NO_SHA
644
                #if !defined(NO_RSA)
645
                    #define BUILD_TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA
646
                    #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
647
                        #define BUILD_TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA
648
                    #endif
649
                #endif
650
651
                #if defined(HAVE_ECC) || \
652
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
653
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
654
                    #define BUILD_TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA
655
                #endif
656
                #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
657
                    #define BUILD_TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA
658
                #endif
659
            #endif /* NO_SHA */
660
        #endif
661
        #if defined(HAVE_NULL_CIPHER)
662
            #if !defined(NO_SHA)
663
                #if defined(HAVE_ECC) || \
664
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
665
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
666
                    #define BUILD_TLS_ECDHE_ECDSA_WITH_NULL_SHA
667
                #endif
668
            #endif
669
            #if !defined(NO_PSK) && !defined(NO_SHA256)
670
                #define BUILD_TLS_ECDHE_PSK_WITH_NULL_SHA256
671
            #endif
672
        #endif
673
        #if !defined(NO_PSK) && !defined(NO_SHA256) && !defined(NO_AES) && \
674
            defined(WOLFSSL_AES_128) && defined(HAVE_AES_CBC)
675
            #define BUILD_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256
676
        #endif
677
        #if !defined(NO_PSK) && !defined(NO_SHA256) && !defined(NO_AES) && \
678
            defined(WOLFSSL_AES_128) && defined(HAVE_AESGCM)
679
            #define BUILD_TLS_ECDHE_PSK_WITH_AES_128_GCM_SHA256
680
        #endif
681
    #endif
682
    #if defined(HAVE_CHACHA) && defined(HAVE_POLY1305) && !defined(NO_SHA256)
683
        #if !defined(NO_OLD_POLY1305)
684
        #if defined(HAVE_ECC) || \
685
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
686
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
687
            #define BUILD_TLS_ECDHE_ECDSA_WITH_CHACHA20_OLD_POLY1305_SHA256
688
        #endif
689
        #if !defined(NO_RSA) && defined(HAVE_ECC)
690
            #define BUILD_TLS_ECDHE_RSA_WITH_CHACHA20_OLD_POLY1305_SHA256
691
        #endif
692
        #if !defined(NO_DH) && !defined(NO_RSA) && !defined(NO_TLS_DH)
693
            /* SHOULD NOT negotiate cipher suites based on ephemeral
694
             * finite-field Diffie-Hellman key agreement (i.e., "TLS_DHE_*"
695
             * suites). https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
696
            #define BUILD_TLS_DHE_RSA_WITH_CHACHA20_OLD_POLY1305_SHA256
697
        #endif
698
        #endif /* NO_OLD_POLY1305 */
699
        #if !defined(NO_PSK)
700
            #define BUILD_TLS_PSK_WITH_CHACHA20_POLY1305_SHA256
701
            #if defined(HAVE_ECC) || defined(HAVE_ED25519) || \
702
                                                             defined(HAVE_ED448)
703
                #define BUILD_TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256
704
            #endif
705
            #if !defined(NO_DH) && !defined(NO_TLS_DH)
706
                /* SHOULD NOT negotiate cipher suites based on ephemeral
707
                 * finite-field Diffie-Hellman key agreement (i.e., "TLS_DHE_*"
708
                 * suites). https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
709
                #define BUILD_TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256
710
            #endif
711
        #endif /* !NO_PSK */
712
    #endif
713
714
#endif /* !WOLFSSL_MAX_STRENGTH */
715
716
#if !defined(NO_DH) && !defined(NO_AES) && !defined(NO_TLS) && \
717
    !defined(NO_RSA) && defined(HAVE_AESGCM) && !defined(NO_TLS_DH)
718
    /* SHOULD NOT negotiate cipher suites based on ephemeral
719
     * finite-field Diffie-Hellman key agreement (i.e., "TLS_DHE_*"
720
     * suites). https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
721
722
    #if !defined(NO_SHA256) && defined(WOLFSSL_AES_128)
723
        #define BUILD_TLS_DHE_RSA_WITH_AES_128_GCM_SHA256
724
    #endif
725
726
    #if defined(WOLFSSL_SHA384) && defined(WOLFSSL_AES_256)
727
        #define BUILD_TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
728
    #endif
729
#endif
730
731
#if !defined(NO_DH) && !defined(NO_PSK) && !defined(NO_TLS) && \
732
    !defined(NO_TLS_DH)
733
    /* SHOULD NOT negotiate cipher suites based on ephemeral
734
     * finite-field Diffie-Hellman key agreement (i.e., "TLS_DHE_*"
735
     * suites). https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
736
    #ifndef NO_SHA256
737
        #if defined(HAVE_AESGCM) && defined(WOLFSSL_AES_128)
738
            #define BUILD_TLS_DHE_PSK_WITH_AES_128_GCM_SHA256
739
        #endif
740
        #ifdef HAVE_AESCCM
741
            #ifdef WOLFSSL_AES_128
742
                #define BUILD_TLS_DHE_PSK_WITH_AES_128_CCM
743
            #endif
744
            #ifdef WOLFSSL_AES_256
745
                #define BUILD_TLS_DHE_PSK_WITH_AES_256_CCM
746
            #endif
747
        #endif
748
    #endif
749
    #if defined(WOLFSSL_SHA384) && defined(HAVE_AESGCM) && \
750
        defined(WOLFSSL_AES_256)
751
        #define BUILD_TLS_DHE_PSK_WITH_AES_256_GCM_SHA384
752
    #endif
753
#endif
754
755
#if (defined(HAVE_ECC) || defined(HAVE_CURVE25519) || defined(HAVE_CURVE448)) \
756
                                         && !defined(NO_TLS) && !defined(NO_AES)
757
    #ifdef HAVE_AESGCM
758
        #if !defined(NO_SHA256) && defined(WOLFSSL_AES_128)
759
            #if defined(HAVE_ECC) || \
760
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
761
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
762
                #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
763
            #endif
764
            #ifndef NO_RSA
765
                #define BUILD_TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
766
            #endif
767
        #endif
768
        #if defined(WOLFSSL_SHA384) && defined(WOLFSSL_AES_256)
769
            #if defined(HAVE_ECC) || \
770
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
771
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
772
                #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
773
            #endif
774
            #ifndef NO_RSA
775
                #define BUILD_TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
776
            #endif
777
        #endif
778
    #endif
779
    #if defined(HAVE_AESCCM) && !defined(NO_SHA256)
780
        #if defined(HAVE_ECC) || \
781
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
782
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
783
            #ifdef WOLFSSL_AES_128
784
                #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CCM
785
                #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8
786
            #endif
787
            #ifdef WOLFSSL_AES_256
788
                #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8
789
            #endif
790
        #endif
791
    #endif
792
#endif
793
794
#if defined(HAVE_CHACHA) && defined(HAVE_POLY1305) && !defined(NO_SHA256)
795
    #if defined(HAVE_ECC) || defined(HAVE_CURVE25519) || defined(HAVE_CURVE448)
796
        #if defined(HAVE_ECC) || \
797
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
798
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
799
            #define BUILD_TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256
800
        #endif
801
        #ifndef NO_RSA
802
            #define BUILD_TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
803
        #endif
804
    #endif
805
    #if !defined(NO_DH) && !defined(NO_RSA) && !defined(NO_TLS_DH)
806
        /* SHOULD NOT negotiate cipher suites based on ephemeral
807
         * finite-field Diffie-Hellman key agreement (i.e., "TLS_DHE_*"
808
         * suites). https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
809
        #define BUILD_TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256
810
    #endif
811
#endif
812
813
    #if defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3)
814
        #ifdef WOLFSSL_SM4_CBC
815
            #define BUILD_TLS_ECDHE_ECDSA_WITH_SM4_CBC_SM3
816
        #endif
817
        #ifdef WOLFSSL_SM4_GCM
818
            #define BUILD_TLS_ECDHE_ECDSA_WITH_SM4_GCM_SM3
819
        #endif
820
        #ifdef WOLFSSL_SM4_CCM
821
            #define BUILD_TLS_ECDHE_ECDSA_WITH_SM4_CCM_SM3
822
        #endif
823
    #endif
824
#endif
825
826
#if defined(WOLFSSL_TLS13)
827
    #ifdef HAVE_AESGCM
828
        #if !defined(NO_SHA256) && defined(WOLFSSL_AES_128)
829
            #define BUILD_TLS_AES_128_GCM_SHA256
830
        #endif
831
        #if defined(WOLFSSL_SHA384) && defined(WOLFSSL_AES_256)
832
            #define BUILD_TLS_AES_256_GCM_SHA384
833
        #endif
834
    #endif
835
836
    #if defined(HAVE_CHACHA) && defined(HAVE_POLY1305)
837
        #ifndef NO_SHA256
838
            #define BUILD_TLS_CHACHA20_POLY1305_SHA256
839
        #endif
840
    #endif
841
842
    #ifdef HAVE_AESCCM
843
        #if !defined(NO_SHA256) && defined(WOLFSSL_AES_128)
844
            #define BUILD_TLS_AES_128_CCM_SHA256
845
            #define BUILD_TLS_AES_128_CCM_8_SHA256
846
        #endif
847
    #endif
848
    #ifdef HAVE_NULL_CIPHER
849
        #ifndef NO_SHA256
850
            #define BUILD_TLS_SHA256_SHA256
851
        #endif
852
        #ifdef WOLFSSL_SHA384
853
            #define BUILD_TLS_SHA384_SHA384
854
        #endif
855
    #endif
856
857
    #ifdef WOLFSSL_SM3
858
        #ifdef WOLFSSL_SM4_GCM
859
            #define BUILD_TLS_SM4_GCM_SM3
860
        #endif
861
862
        #ifdef WOLFSSL_SM4_CCM
863
            #define BUILD_TLS_SM4_CCM_SM3
864
        #endif
865
    #endif
866
#endif
867
868
#if !defined(WOLFCRYPT_ONLY) && defined(NO_PSK) && \
869
    (defined(NO_DH) || !defined(HAVE_ANON)) && \
870
    defined(NO_RSA) && !defined(HAVE_ECC) && \
871
    !defined(HAVE_ED25519) && !defined(HAVE_ED448) && \
872
    (!defined(WOLFSSL_TLS13) || \
873
     (!defined(HAVE_FALCON) && !defined(WOLFSSL_HAVE_MLDSA) && \
874
      !defined(WOLFSSL_HAVE_SLHDSA)))
875
   #error "No cipher suites available with this build"
876
#endif
877
878
#ifdef WOLFSSL_MULTICAST
879
    #if defined(HAVE_NULL_CIPHER) && !defined(NO_SHA256)
880
        #define BUILD_WDM_WITH_NULL_SHA256
881
    #endif
882
#endif
883
884
#if defined(BUILD_SSL_RSA_WITH_RC4_128_SHA) || \
885
    defined(BUILD_SSL_RSA_WITH_RC4_128_MD5)
886
    #define BUILD_ARC4
887
#endif
888
889
#if defined(BUILD_SSL_RSA_WITH_3DES_EDE_CBC_SHA)
890
    #define BUILD_DES3
891
#endif
892
893
#if defined(BUILD_TLS_RSA_WITH_AES_128_CBC_SHA) || \
894
    defined(BUILD_TLS_RSA_WITH_AES_256_CBC_SHA) || \
895
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256) || \
896
    defined(BUILD_TLS_DHE_PSK_WITH_AES_128_CBC_SHA256)
897
    #undef  BUILD_AES
898
    #define BUILD_AES
899
#endif
900
901
#if defined(BUILD_TLS_RSA_WITH_AES_128_GCM_SHA256) || \
902
    defined(BUILD_TLS_DHE_RSA_WITH_AES_128_GCM_SHA256) || \
903
    defined(BUILD_TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) || \
904
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256) || \
905
    defined(BUILD_TLS_PSK_WITH_AES_128_GCM_SHA256) || \
906
    defined(BUILD_TLS_DHE_PSK_WITH_AES_128_GCM_SHA256) || \
907
    defined(BUILD_TLS_RSA_WITH_AES_256_GCM_SHA384) || \
908
    defined(BUILD_TLS_DHE_RSA_WITH_AES_256_GCM_SHA384) || \
909
    defined(BUILD_TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) || \
910
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384) || \
911
    defined(BUILD_TLS_PSK_WITH_AES_256_GCM_SHA384) || \
912
    defined(BUILD_TLS_DHE_PSK_WITH_AES_256_GCM_SHA384) || \
913
    defined(BUILD_TLS_AES_128_GCM_SHA256) || \
914
    defined(BUILD_TLS_AES_256_GCM_SHA384)
915
    #define BUILD_AESGCM
916
#else
917
    /* No AES-GCM cipher suites available with build */
918
    #define NO_AESGCM_AEAD
919
#endif
920
921
#if defined(BUILD_TLS_RSA_WITH_AES_128_CCM_8) || \
922
    defined(BUILD_TLS_RSA_WITH_AES_256_CCM_8) || \
923
    defined(BUILD_TLS_PSK_WITH_AES_128_CCM_8) || \
924
    defined(BUILD_TLS_PSK_WITH_AES_128_CCM) || \
925
    defined(BUILD_TLS_PSK_WITH_AES_256_CCM_8) || \
926
    defined(BUILD_TLS_PSK_WITH_AES_256_CCM) || \
927
    defined(BUILD_TLS_DHE_PSK_WITH_AES_128_CCM) || \
928
    defined(BUILD_TLS_DHE_PSK_WITH_AES_256_CCM) || \
929
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CCM) || \
930
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8) || \
931
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8) || \
932
    defined(BUILD_TLS_AES_128_CCM_SHA256) || \
933
    defined(BUILD_TLS_AES_128_CCM_8_SHA256)
934
    #define BUILD_AESCCM
935
#else
936
    /* No AES-CCM cipher suites available with build */
937
    #define NO_AESCCM_AEAD
938
#endif
939
940
#if defined(BUILD_TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256) || \
941
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384)
942
    #define BUILD_ARIA
943
#endif
944
945
#if defined(BUILD_TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256) || \
946
    defined(BUILD_TLS_DHE_RSA_WITH_CHACHA20_OLD_POLY1305_SHA256) || \
947
    defined(BUILD_TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256) || \
948
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256) || \
949
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_CHACHA20_OLD_POLY1305_SHA256) || \
950
    defined(BUILD_TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256) || \
951
    defined(BUILD_TLS_ECDHE_RSA_WITH_CHACHA20_OLD_POLY1305_SHA256) || \
952
    defined(BUILD_TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256) || \
953
    defined(BUILD_TLS_PSK_WITH_CHACHA20_POLY1305_SHA256) || \
954
    defined(BUILD_TLS_CHACHA20_POLY1305_SHA256)
955
    /* Have an available ChaCha Poly cipher suite */
956
#else
957
    /* No ChaCha Poly cipher suites available with build */
958
    #define NO_CHAPOL_AEAD
959
#endif
960
961
#ifdef NO_DES3
962
    #define DES_BLOCK_SIZE 8
963
#else
964
    #undef  BUILD_DES3
965
    #define BUILD_DES3
966
#endif
967
968
#if defined(NO_AES) || !defined(HAVE_AES_DECRYPT)
969
    #undef WC_AES_BLOCK_SIZE
970
    #define WC_AES_BLOCK_SIZE 16
971
    #undef  BUILD_AES
972
#else
973
    #undef  BUILD_AES
974
    #define BUILD_AES
975
#endif
976
977
#if !defined(NO_RC4) && !defined(WSSL_HARDEN_TLS)
978
    /* MUST NOT negotiate RC4 cipher suites
979
     * https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
980
    #undef  BUILD_ARC4
981
    #define BUILD_ARC4
982
#endif
983
984
#ifdef HAVE_CHACHA
985
0
    #define CHACHA20_BLOCK_SIZE 16
986
#endif
987
988
#if defined(WOLFSSL_MAX_STRENGTH) || \
989
    (defined(HAVE_AESGCM) && !defined(NO_AESGCM_AEAD)) || \
990
     defined(HAVE_AESCCM) || \
991
     defined(HAVE_ARIA) || \
992
    (defined(HAVE_CHACHA) && defined(HAVE_POLY1305) && \
993
     !defined(NO_CHAPOL_AEAD)) || \
994
    defined(WOLFSSL_SM4_GCM) || defined(WOLFSSL_SM4_CCM) || \
995
    (defined(WOLFSSL_TLS13) && defined(HAVE_NULL_CIPHER))
996
997
    #define HAVE_AEAD
998
#endif
999
1000
#if defined(WOLFSSL_MAX_STRENGTH) || \
1001
    defined(HAVE_ECC) || !defined(NO_DH)
1002
1003
    #define HAVE_PFS
1004
#endif
1005
1006
#ifdef WSSL_HARDEN_TLS
1007
    #ifdef HAVE_NULL_CIPHER
1008
        #error "NULL ciphers not allowed https://www.rfc-editor.org/rfc/rfc9325#section-4.1"
1009
    #endif
1010
    #ifdef WOLFSSL_STATIC_RSA
1011
        #error "Static RSA ciphers not allowed https://www.rfc-editor.org/rfc/rfc9325#section-4.1"
1012
    #endif
1013
    #ifdef WOLFSSL_STATIC_DH
1014
        #error "Static DH ciphers not allowed https://www.rfc-editor.org/rfc/rfc9325#section-4.1"
1015
    #endif
1016
    #ifdef HAVE_ANON
1017
        #error "At least the server side has to be authenticated"
1018
    #endif
1019
#endif
1020
1021
#undef WSSL_HARDEN_TLS
1022
1023
/* CA Names feature */
1024
#if !defined(WOLFSSL_NO_CA_NAMES) && defined(OPENSSL_EXTRA)
1025
    #define SSL_CLIENT_CA_NAMES(ssl) ((ssl)->client_ca_names != NULL ? \
1026
        (ssl)->client_ca_names : \
1027
        (ssl)->ctx->client_ca_names)
1028
    #define SSL_CA_NAMES(ssl) ((ssl)->ca_names != NULL ? \
1029
        (ssl)->ca_names : \
1030
        (ssl)->ctx->ca_names)
1031
    /* On the server, client_ca_names has priority over ca_names if both are
1032
     * set. This mimics OpenSSL's API:
1033
     * https://docs.openssl.org/3.6/man3/SSL_CTX_set0_CA_list/ */
1034
    #define SSL_PRIORITY_CA_NAMES(ssl) \
1035
        (((ssl)->options.side == WOLFSSL_SERVER_END && \
1036
        SSL_CLIENT_CA_NAMES(ssl) != NULL) ? \
1037
            SSL_CLIENT_CA_NAMES(ssl) : \
1038
            SSL_CA_NAMES(ssl))
1039
#else
1040
    #undef  WOLFSSL_NO_CA_NAMES
1041
    #define WOLFSSL_NO_CA_NAMES
1042
#endif
1043
1044
1045
/* actual cipher values, 2nd byte */
1046
enum {
1047
    TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA = 0x16,
1048
    TLS_DHE_RSA_WITH_AES_256_CBC_SHA  = 0x39,
1049
    TLS_DHE_RSA_WITH_AES_128_CBC_SHA  = 0x33,
1050
    TLS_DH_anon_WITH_AES_128_CBC_SHA  = 0x34,
1051
    TLS_RSA_WITH_AES_256_CBC_SHA      = 0x35,
1052
    TLS_RSA_WITH_AES_128_CBC_SHA      = 0x2F,
1053
    TLS_RSA_WITH_NULL_MD5             = 0x01,
1054
    TLS_RSA_WITH_NULL_SHA             = 0x02,
1055
    TLS_PSK_WITH_AES_256_CBC_SHA      = 0x8d,
1056
    TLS_PSK_WITH_AES_128_CBC_SHA256   = 0xae,
1057
    TLS_PSK_WITH_AES_256_CBC_SHA384   = 0xaf,
1058
    TLS_PSK_WITH_AES_128_CBC_SHA      = 0x8c,
1059
    TLS_PSK_WITH_NULL_SHA256          = 0xb0,
1060
    TLS_PSK_WITH_NULL_SHA384          = 0xb1,
1061
    TLS_PSK_WITH_NULL_SHA             = 0x2c,
1062
    SSL_RSA_WITH_RC4_128_SHA          = 0x05,
1063
    SSL_RSA_WITH_RC4_128_MD5          = 0x04,
1064
    SSL_RSA_WITH_3DES_EDE_CBC_SHA     = 0x0A,
1065
1066
    /* ECC suites, first byte is 0xC0 (ECC_BYTE) */
1067
    TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA    = 0x14,
1068
    TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA    = 0x13,
1069
    TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA  = 0x0A,
1070
    TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA  = 0x09,
1071
    TLS_ECDHE_RSA_WITH_RC4_128_SHA        = 0x11,
1072
    TLS_ECDHE_ECDSA_WITH_RC4_128_SHA      = 0x07,
1073
    TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA   = 0x12,
1074
    TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA = 0x08,
1075
    TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256   = 0x27,
1076
    TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 = 0x23,
1077
    TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384   = 0x28,
1078
    TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 = 0x24,
1079
    TLS_ECDHE_ECDSA_WITH_NULL_SHA           = 0x06,
1080
    TLS_ECDHE_PSK_WITH_NULL_SHA256          = 0x3a,
1081
    TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256   = 0x37,
1082
1083
    /* static ECDH, first byte is 0xC0 (ECC_BYTE) */
1084
    TLS_ECDH_RSA_WITH_AES_256_CBC_SHA    = 0x0F,
1085
    TLS_ECDH_RSA_WITH_AES_128_CBC_SHA    = 0x0E,
1086
    TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA  = 0x05,
1087
    TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA  = 0x04,
1088
    TLS_ECDH_RSA_WITH_RC4_128_SHA        = 0x0C,
1089
    TLS_ECDH_ECDSA_WITH_RC4_128_SHA      = 0x02,
1090
    TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA   = 0x0D,
1091
    TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA = 0x03,
1092
    TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256   = 0x29,
1093
    TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256 = 0x25,
1094
    TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384   = 0x2A,
1095
    TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384 = 0x26,
1096
1097
    WDM_WITH_NULL_SHA256          = 0xFE, /* wolfSSL DTLS Multicast */
1098
1099
    /* SHA256 */
1100
    TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 = 0x6b,
1101
    TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 = 0x67,
1102
    TLS_RSA_WITH_AES_256_CBC_SHA256     = 0x3d,
1103
    TLS_RSA_WITH_AES_128_CBC_SHA256     = 0x3c,
1104
    TLS_RSA_WITH_NULL_SHA256            = 0x3b,
1105
    TLS_DHE_PSK_WITH_AES_128_CBC_SHA256 = 0xb2,
1106
    TLS_DHE_PSK_WITH_NULL_SHA256        = 0xb4,
1107
1108
    /* SHA384 */
1109
    TLS_DHE_PSK_WITH_AES_256_CBC_SHA384 = 0xb3,
1110
    TLS_DHE_PSK_WITH_NULL_SHA384        = 0xb5,
1111
1112
    /* AES-GCM */
1113
    TLS_RSA_WITH_AES_128_GCM_SHA256          = 0x9c,
1114
    TLS_RSA_WITH_AES_256_GCM_SHA384          = 0x9d,
1115
    TLS_DHE_RSA_WITH_AES_128_GCM_SHA256      = 0x9e,
1116
    TLS_DHE_RSA_WITH_AES_256_GCM_SHA384      = 0x9f,
1117
    TLS_DH_anon_WITH_AES_256_GCM_SHA384      = 0xa7,
1118
    TLS_PSK_WITH_AES_128_GCM_SHA256          = 0xa8,
1119
    TLS_PSK_WITH_AES_256_GCM_SHA384          = 0xa9,
1120
    TLS_DHE_PSK_WITH_AES_128_GCM_SHA256      = 0xaa,
1121
    TLS_DHE_PSK_WITH_AES_256_GCM_SHA384      = 0xab,
1122
1123
    /* ECC AES-GCM, first byte is 0xC0 (ECC_BYTE) */
1124
    TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256  = 0x2b,
1125
    TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384  = 0x2c,
1126
    TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256   = 0x2d,
1127
    TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384   = 0x2e,
1128
    TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256    = 0x2f,
1129
    TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384    = 0x30,
1130
    TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256     = 0x31,
1131
    TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384     = 0x32,
1132
1133
    /* AES-CCM, first byte is 0xC0 but isn't ECC,
1134
     * also, in some of the other AES-CCM suites
1135
     * there will be second byte number conflicts
1136
     * with non-ECC AES-GCM */
1137
    TLS_RSA_WITH_AES_128_CCM_8         = 0xa0,
1138
    TLS_RSA_WITH_AES_256_CCM_8         = 0xa1,
1139
    TLS_ECDHE_ECDSA_WITH_AES_128_CCM   = 0xac,
1140
    TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8 = 0xae,
1141
    TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8 = 0xaf,
1142
    TLS_PSK_WITH_AES_128_CCM           = 0xa4,
1143
    TLS_PSK_WITH_AES_256_CCM           = 0xa5,
1144
    TLS_PSK_WITH_AES_128_CCM_8         = 0xa8,
1145
    TLS_PSK_WITH_AES_256_CCM_8         = 0xa9,
1146
    TLS_DHE_PSK_WITH_AES_128_CCM       = 0xa6,
1147
    TLS_DHE_PSK_WITH_AES_256_CCM       = 0xa7,
1148
1149
    /* Camellia */
1150
    TLS_RSA_WITH_CAMELLIA_128_CBC_SHA        = 0x41,
1151
    TLS_RSA_WITH_CAMELLIA_256_CBC_SHA        = 0x84,
1152
    TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256     = 0xba,
1153
    TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256     = 0xc0,
1154
    TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA    = 0x45,
1155
    TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA    = 0x88,
1156
    TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 = 0xbe,
1157
    TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256 = 0xc4,
1158
1159
    /* chacha20-poly1305 suites first byte is 0xCC (CHACHA_BYTE) */
1160
    TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256   = 0xa8,
1161
    TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 = 0xa9,
1162
    TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256     = 0xaa,
1163
    TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256   = 0xac,
1164
    TLS_PSK_WITH_CHACHA20_POLY1305_SHA256         = 0xab,
1165
    TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256     = 0xad,
1166
1167
    /* chacha20-poly1305 earlier version of nonce and padding (CHACHA_BYTE) */
1168
    TLS_ECDHE_RSA_WITH_CHACHA20_OLD_POLY1305_SHA256   = 0x13,
1169
    TLS_ECDHE_ECDSA_WITH_CHACHA20_OLD_POLY1305_SHA256 = 0x14,
1170
    TLS_DHE_RSA_WITH_CHACHA20_OLD_POLY1305_SHA256     = 0x15,
1171
1172
    /* ECDHE_PSK RFC8442, first byte is 0xD0 (EDHE_PSK_BYTE) */
1173
    TLS_ECDHE_PSK_WITH_AES_128_GCM_SHA256    = 0x01,
1174
1175
    /* TLS v1.3 cipher suites */
1176
    TLS_AES_128_GCM_SHA256       = 0x01,
1177
    TLS_AES_256_GCM_SHA384       = 0x02,
1178
    TLS_CHACHA20_POLY1305_SHA256 = 0x03,
1179
    TLS_AES_128_CCM_SHA256       = 0x04,
1180
    TLS_AES_128_CCM_8_SHA256     = 0x05,
1181
1182
    /* TLS v1.3 Integrity only cipher suites - 0xC0 (ECC) first byte */
1183
    TLS_SHA256_SHA256            = 0xB4,
1184
    TLS_SHA384_SHA384            = 0xB5,
1185
1186
    /* ARIA-GCM, first byte is 0xC0 (ECC_BYTE)
1187
    * See: https://www.rfc-editor.org/rfc/rfc6209.html#section-5
1188
    */
1189
    TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256   = 0x5c,
1190
    TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384   = 0x5d,
1191
1192
    /* TLS v1.3 SM cipher suites - 0x00 (CIPHER_BYTE) is first byte */
1193
    TLS_SM4_GCM_SM3              = 0xC6,
1194
    TLS_SM4_CCM_SM3              = 0xC7,
1195
1196
    /* TLS v1.2 SM cipher suites - 0xE0 (SM_BYTE) is first byte */
1197
    TLS_ECDHE_ECDSA_WITH_SM4_CBC_SM3 = 0x11,
1198
    TLS_ECDHE_ECDSA_WITH_SM4_GCM_SM3 = 0x51,
1199
    TLS_ECDHE_ECDSA_WITH_SM4_CCM_SM3 = 0x52,
1200
1201
    /* Fallback SCSV (Signaling Cipher Suite Value) */
1202
    TLS_FALLBACK_SCSV                        = 0x56,
1203
    /* Renegotiation Indication Extension Special Suite */
1204
    TLS_EMPTY_RENEGOTIATION_INFO_SCSV        = 0xff
1205
};
1206
1207
1208
#ifndef WOLFSSL_SESSION_TIMEOUT
1209
0
    #define WOLFSSL_SESSION_TIMEOUT 500
1210
    /* default session resumption cache timeout in seconds */
1211
#endif
1212
1213
1214
#ifndef WOLFSSL_DTLS_WINDOW_WORDS
1215
    #define WOLFSSL_DTLS_WINDOW_WORDS 2
1216
#endif /* WOLFSSL_DTLS_WINDOW_WORDS */
1217
#define DTLS_WORD_BITS (sizeof(word32) * CHAR_BIT)
1218
#define DTLS_SEQ_BITS  (WOLFSSL_DTLS_WINDOW_WORDS * DTLS_WORD_BITS)
1219
#define DTLS_SEQ_SZ    (sizeof(word32) * WOLFSSL_DTLS_WINDOW_WORDS)
1220
1221
#ifndef WOLFSSL_MULTICAST
1222
    #define WOLFSSL_DTLS_PEERSEQ_SZ 1
1223
#else
1224
    #ifndef WOLFSSL_MULTICAST_PEERS
1225
        /* max allowed multicast group peers */
1226
        #define WOLFSSL_MULTICAST_PEERS 100
1227
    #endif
1228
    #define WOLFSSL_DTLS_PEERSEQ_SZ WOLFSSL_MULTICAST_PEERS
1229
#endif /* WOLFSSL_MULTICAST */
1230
1231
#ifndef WOLFSSL_MAX_MTU
1232
    /* 1500 - 100 bytes to account for UDP and IP headers */
1233
    #define WOLFSSL_MAX_MTU 1400
1234
#endif /* WOLFSSL_MAX_MTU */
1235
1236
#ifndef WOLFSSL_DTLS_MTU_ADDITIONAL_READ_BUFFER
1237
    #define WOLFSSL_DTLS_MTU_ADDITIONAL_READ_BUFFER 500
1238
#endif /* WOLFSSL_DTLS_MTU_ADDITIONAL_READ_BUFFER */
1239
1240
#ifndef WOLFSSL_DTLS_FRAG_POOL_SZ
1241
    #define WOLFSSL_DTLS_FRAG_POOL_SZ 10
1242
#endif
1243
1244
/* set minimum DH key size allowed */
1245
#ifndef WOLFSSL_MIN_DHKEY_BITS
1246
    #if defined(WOLFSSL_HARDEN_TLS) && !defined(WOLFSSL_HARDEN_TLS_NO_PKEY_CHECK)
1247
        /* Using guidance from section 5.6.1
1248
         * https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf */
1249
        #if WOLFSSL_HARDEN_TLS >= 128
1250
            #define WOLFSSL_MIN_DHKEY_BITS 3072
1251
        #elif WOLFSSL_HARDEN_TLS >= 112
1252
            #define WOLFSSL_MIN_DHKEY_BITS 2048
1253
        #endif
1254
    #else
1255
0
        #define WOLFSSL_MIN_DHKEY_BITS DH_MIN_SIZE
1256
    #endif
1257
#endif
1258
#if defined(WOLFSSL_HARDEN_TLS) && WOLFSSL_MIN_DHKEY_BITS < 2048 && \
1259
    !defined(WOLFSSL_HARDEN_TLS_NO_PKEY_CHECK)
1260
    /* Implementations MUST NOT negotiate cipher suites offering less than
1261
     * 112 bits of security.
1262
     * https://www.rfc-editor.org/rfc/rfc9325#section-4.1
1263
     * Using guidance from section 5.6.1
1264
     * https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf */
1265
    #error "For 112 bits of security DH needs at least 2048 bit keys"
1266
#endif
1267
#if (WOLFSSL_MIN_DHKEY_BITS % 8)
1268
    #error DH minimum bit size must be multiple of 8
1269
#endif
1270
#if (WOLFSSL_MIN_DHKEY_BITS > 16000)
1271
    #error DH minimum bit size must not be greater than 16000
1272
#endif
1273
#if (WOLFSSL_MIN_DHKEY_BITS < DH_MIN_SIZE)
1274
    /* The TLS-layer minimum must not be looser than the wolfCrypt DH primitive
1275
     * minimum (DH_MIN_SIZE), otherwise a key size accepted during negotiation
1276
     * is later rejected by wc_DhAgree with WC_KEY_SIZE_E. */
1277
    #error "WOLFSSL_MIN_DHKEY_BITS must be >= DH_MIN_SIZE"
1278
#endif
1279
0
#define MIN_DHKEY_SZ (WOLFSSL_MIN_DHKEY_BITS / 8)
1280
/* set maximum DH key size allowed */
1281
#ifndef WOLFSSL_MAX_DHKEY_BITS
1282
    #if (defined(USE_FAST_MATH) && defined(FP_MAX_BITS) && FP_MAX_BITS >= 16384)
1283
        #define WOLFSSL_MAX_DHKEY_BITS  (FP_MAX_BITS / 2)
1284
    #elif (defined(WOLFSSL_SP_MATH_ALL) || defined(WOLFSSL_SP_MATH)) && \
1285
           defined(SP_INT_BITS)
1286
        /* SP implementation supports numbers of SP_INT_BITS bits. */
1287
0
        #define WOLFSSL_MAX_DHKEY_BITS  WC_BITS_FULL_BYTES(SP_INT_BITS)
1288
    #else
1289
        #define WOLFSSL_MAX_DHKEY_BITS  4096
1290
    #endif
1291
#endif
1292
#if (WOLFSSL_MAX_DHKEY_BITS % 8)
1293
    #error DH maximum bit size must be multiple of 8
1294
#endif
1295
#if (WOLFSSL_MAX_DHKEY_BITS > 16384)
1296
    #error DH maximum bit size must not be greater than 16384
1297
#endif
1298
0
#define MAX_DHKEY_SZ (WOLFSSL_MAX_DHKEY_BITS / 8)
1299
1300
#ifndef NO_DH
1301
#if WOLFSSL_MAX_DHKEY_BITS < WOLFSSL_MIN_DHKEY_BITS
1302
#error "WOLFSSL_MAX_DHKEY_BITS has to be greater than WOLFSSL_MIN_DHKEY_BITS"
1303
#endif
1304
#endif /* NO_DH */
1305
1306
#ifndef MAX_PSK_KEY_LEN
1307
    #define MAX_PSK_KEY_LEN 64
1308
#endif
1309
1310
#ifndef MAX_EARLY_DATA_SZ
1311
    /* maximum early data size */
1312
    #define MAX_EARLY_DATA_SZ  4096
1313
#endif
1314
1315
/* Anti-replay eviction keys off the ticket's session ID. */
1316
#if defined(WOLFSSL_EARLY_DATA) && defined(HAVE_SESSION_TICKET) && \
1317
    !defined(WOLFSSL_TICKET_HAVE_ID)
1318
    #define WOLFSSL_TICKET_HAVE_ID
1319
#endif
1320
1321
1322
#if !defined(NO_RSA) || !defined(NO_DH) || defined(HAVE_ECC)
1323
    /* MySQL wants to be able to use 8192-bit numbers. */
1324
    #if defined(USE_FAST_MATH) && defined(FP_MAX_BITS)
1325
        /* Use the FP size up to 8192-bit and down to a min of 1024-bit. */
1326
        #if FP_MAX_BITS >= 16384
1327
            #define ENCRYPT_BASE_BITS  8192
1328
        #elif defined(HAVE_ECC)
1329
            #if FP_MAX_BITS > 2224
1330
                #define ENCRYPT_BASE_BITS  (FP_MAX_BITS / 2)
1331
            #else
1332
                /* 521-bit ASN.1 signature - 3 + 2 * (2 + 66) bytes. */
1333
                #define ENCRYPT_BASE_BITS  1112
1334
            #endif
1335
        #else
1336
            #if FP_MAX_BITS > 2048
1337
                #define ENCRYPT_BASE_BITS  (FP_MAX_BITS / 2)
1338
            #else
1339
                #define ENCRYPT_BASE_BITS  1024
1340
            #endif
1341
        #endif
1342
1343
        /* Check MySQL size requirements met. */
1344
        #if defined(WOLFSSL_MYSQL_COMPATIBLE) && ENCRYPT_BASE_BITS < 8192
1345
            #error "MySQL needs FP_MAX_BITS at least at 16384"
1346
        #endif
1347
1348
        #if !defined(NO_RSA) && defined(WC_MAX_RSA_BITS) && \
1349
            WC_MAX_RSA_BITS > ENCRYPT_BASE_BITS
1350
            #error "FP_MAX_BITS too small for WC_MAX_RSA_BITS"
1351
        #endif
1352
    #elif defined(WOLFSSL_SP_MATH_ALL) || defined(WOLFSSL_SP_MATH)
1353
        /* Use the SP size up to 8192-bit and down to a min of 1024-bit. */
1354
        #if SP_INT_BITS >= 8192
1355
            #define ENCRYPT_BASE_BITS  8192
1356
        #elif defined(HAVE_ECC)
1357
            #if SP_INT_BITS > 1112
1358
                #define ENCRYPT_BASE_BITS  SP_INT_BITS
1359
            #else
1360
                /* 521-bit ASN.1 signature - 3 + 2 * (2 + 66) bytes. */
1361
                #define ENCRYPT_BASE_BITS  1112
1362
            #endif
1363
        #else
1364
            #if SP_INT_BITS > 1024
1365
                #define ENCRYPT_BASE_BITS  SP_INT_BITS
1366
            #else
1367
                #define ENCRYPT_BASE_BITS  1024
1368
            #endif
1369
        #endif
1370
1371
        /* Check MySQL size requirements met. */
1372
        #if defined(WOLFSSL_MYSQL_COMPATIBLE) && ENCRYPT_BASE_BITS < 8192
1373
            #error "MySQL needs SP_INT_BITS at least at 8192"
1374
        #endif
1375
1376
        #if !defined(NO_RSA) && defined(WC_MAX_RSA_BITS) && \
1377
            WC_MAX_RSA_BITS > SP_INT_BITS
1378
            #error "SP_INT_BITS too small for WC_MAX_RSA_BITS"
1379
        #endif
1380
    #else
1381
        /* Integer/heap maths - support 4096-bit. */
1382
        #define ENCRYPT_BASE_BITS  4096
1383
    #endif
1384
#elif defined(HAVE_CURVE448)
1385
    #define ENCRYPT_BASE_BITS    (456 * 2)
1386
#elif defined(HAVE_CURVE25519)
1387
    #define ENCRYPT_BASE_BITS    (256 * 2)
1388
#else
1389
    /* No secret from public key operation but PSK key plus length used. */
1390
    #define ENCRYPT_BASE_BITS  ((MAX_PSK_KEY_LEN + 2) * 8)
1391
#endif
1392
1393
#ifdef WOLFSSL_DTLS_CID
1394
#ifndef DTLS_CID_MAX_SIZE
1395
/* DTLS parsing code copies the record header in a static buffer to decrypt
1396
 * the record. Increasing the CID max size does increase also this buffer,
1397
 * impacting on per-session runtime memory footprint. */
1398
#define DTLS_CID_MAX_SIZE 10
1399
#endif
1400
#else
1401
#undef DTLS_CID_MAX_SIZE
1402
#define DTLS_CID_MAX_SIZE 0
1403
#endif /* WOLFSSL_DTLS_CID */
1404
1405
#if DTLS_CID_MAX_SIZE > 255
1406
#error "Max size for DTLS CID is 255 bytes"
1407
#endif
1408
1409
/* Record Payload Protection Section 5
1410
 *   https://www.rfc-editor.org/rfc/rfc9146.html#section-5 */
1411
#define WOLFSSL_TLS_HMAC_CID_INNER_SZ                               \
1412
           (8 +                 /* seq_num_placeholder */           \
1413
            1 +                 /* tls12_cid */                     \
1414
            1 +                 /* cid_length */                    \
1415
            1 +                 /* tls12_cid */                     \
1416
            2 +                 /* DTLSCiphertext.version */        \
1417
            2 +                 /* epoch */                         \
1418
            6 +                 /* sequence_number */               \
1419
            DTLS_CID_MAX_SIZE + /* cid */                           \
1420
            2)                  /* length_of_DTLSInnerPlaintext */
1421
1422
#define WOLFSSL_TLS_AEAD_CID_AAD_SZ                                 \
1423
           (8 +                 /* seq_num_placeholder */           \
1424
            1 +                 /* tls12_cid */                     \
1425
            1 +                 /* cid_length */                    \
1426
            1 +                 /* tls12_cid */                     \
1427
            2 +                 /* DTLSCiphertext.version */        \
1428
            2 +                 /* epoch */                         \
1429
            6 +                 /* sequence_number */               \
1430
            DTLS_CID_MAX_SIZE + /* cid */                           \
1431
            2)                  /* length_of_DTLSInnerPlaintext */
1432
1433
#ifndef MAX_TICKET_AGE_DIFF
1434
/* maximum ticket age difference in seconds, 10 seconds */
1435
#define MAX_TICKET_AGE_DIFF     10
1436
#endif
1437
#ifndef TLS13_MAX_TICKET_AGE
1438
/* max ticket age in seconds, 7 days */
1439
#define TLS13_MAX_TICKET_AGE    (7*24*60*60)
1440
#endif
1441
1442
1443
/* Limit is 2^24.5
1444
 * https://www.rfc-editor.org/rfc/rfc8446#section-5.5
1445
 * Without the fraction is 23726566 (0x016A09E6) */
1446
0
#define AEAD_AES_LIMIT                           w64From32(0, 0x016A09E6)
1447
/* Limit is 2^23
1448
 * https://www.rfc-editor.org/rfc/rfc9147.html#name-integrity-limits */
1449
#define DTLS_AEAD_AES_CCM_LIMIT                  w64From32(0, 1 << 22)
1450
1451
/* Limit is 2^36
1452
 * https://www.rfc-editor.org/rfc/rfc9147.html#name-aead-limits */
1453
#define DTLS_AEAD_AES_GCM_CHACHA_FAIL_LIMIT      w64From32(1 << 3, 0)
1454
#define DTLS_AEAD_AES_GCM_CHACHA_FAIL_KU_LIMIT   w64From32(1 << 2, 0)
1455
/* Limit is 2^7
1456
 * https://www.rfc-editor.org/rfc/rfc9147.html#name-limits-for-aead_aes_128_ccm */
1457
#define DTLS_AEAD_AES_CCM_8_FAIL_LIMIT           w64From32(0, 1 << 6)
1458
#define DTLS_AEAD_AES_CCM_8_FAIL_KU_LIMIT        w64From32(0, 1 << 5)
1459
/* Limit is 2^23.5.
1460
 * https://www.rfc-editor.org/rfc/rfc9147.html#name-integrity-limits
1461
 * Without the fraction is 11863283 (0x00B504F3)
1462
 * Half of this value is    5931641 (0x005A8279) */
1463
#define DTLS_AEAD_AES_CCM_FAIL_LIMIT             w64From32(0, 0x00B504F3)
1464
#define DTLS_AEAD_AES_CCM_FAIL_KU_LIMIT          w64From32(0, 0x005A8279)
1465
1466
/* Limit is (2^22 - 1) full messages [2^36 - 31 octets]
1467
 * https://www.rfc-editor.org/rfc/rfc8998.html#name-aead_sm4_gcm
1468
 */
1469
#define AEAD_SM4_GCM_LIMIT                       w64From32(0, (1 << 22) - 1)
1470
/* Limit is (2^10 - 1) full messages [2^24 - 1 octets]
1471
 * https://www.rfc-editor.org/rfc/rfc8998.html#name-aead_sm4_ccm
1472
 */
1473
#define AEAD_SM4_CCM_LIMIT                       w64From32(0, (1 << 10) - 1)
1474
1475
#ifndef WOLFSSL_COOKIE_LEN
1476
/* Maximum size for a DTLS cookie */
1477
#define WOLFSSL_COOKIE_LEN 32
1478
#endif
1479
1480
#if WOLFSSL_COOKIE_LEN > 255
1481
#error "WOLFSSL_COOKIE_LEN must be <= 255 per RFC 6347 (opaque<0..2^8-1>)"
1482
#endif
1483
1484
#if defined(WOLFSSL_TLS13) || !defined(NO_PSK)
1485
1486
#define TLS13_TICKET_NONCE_MAX_SZ 255
1487
1488
#if (defined(HAVE_FIPS) &&                                                     \
1489
    !(defined(FIPS_VERSION_GE) && FIPS_VERSION_GE(5,3))) &&                    \
1490
    defined(TLS13_TICKET_NONCE_STATIC_SZ)
1491
#error "TLS13_TICKET_NONCE_STATIC_SZ is not supported in this FIPS version"
1492
#endif
1493
1494
#ifndef TLS13_TICKET_NONCE_STATIC_SZ
1495
#define TLS13_TICKET_NONCE_STATIC_SZ 8
1496
#endif
1497
1498
#if TLS13_TICKET_NONCE_STATIC_SZ > TLS13_TICKET_NONCE_MAX_SZ
1499
#error "Max size for ticket nonce is 255 bytes"
1500
#endif
1501
1502
#endif /* WOLFSSL_TLS13 || !NO_PSK */
1503
1504
#ifdef WOLFSSL_TLS13
1505
/* The length of the certificate verification label - client and server. */
1506
0
#define CERT_VFY_LABEL_SZ    34
1507
/* The number of prefix bytes for signature data. */
1508
0
#define SIGNING_DATA_PREFIX_SZ     64
1509
/* Maximum length of the signature data. */
1510
0
#define MAX_SIG_DATA_SZ            (SIGNING_DATA_PREFIX_SZ + \
1511
0
                                    CERT_VFY_LABEL_SZ      + \
1512
0
                                    WC_MAX_DIGEST_SIZE)
1513
#endif /* WOLFSSL_TLS13 */
1514
1515
enum Misc {
1516
    CIPHER_BYTE    = 0x00,         /* Default ciphers */
1517
    ECC_BYTE       = 0xC0,         /* ECC first cipher suite byte */
1518
    CHACHA_BYTE    = 0xCC,         /* ChaCha first cipher suite */
1519
    TLS13_BYTE     = 0x13,         /* TLS v1.3 first byte of cipher suite */
1520
    ECDHE_PSK_BYTE = 0xD0,         /* RFC 8442 */
1521
    SM_BYTE        = 0xE0,         /* SM first byte - private range */
1522
1523
    SEND_CERT       = 1,
1524
    SEND_BLANK_CERT = 2,
1525
1526
    DTLS_MAJOR      = 0xfe,     /* DTLS major version number */
1527
    DTLS_MINOR      = 0xff,     /* DTLS minor version number */
1528
    DTLS_BOGUS_MINOR = 0xfe,    /* DTLS 0xfe was skipped, see RFC6347 Sec. 1 */
1529
    DTLSv1_2_MINOR  = 0xfd,     /* DTLS minor version number */
1530
    DTLSv1_3_MINOR  = 0xfc,     /* DTLS minor version number */
1531
    SSLv3_MAJOR     = 3,        /* SSLv3 and TLSv1+  major version number */
1532
    SSLv3_MINOR     = 0,        /* TLSv1   minor version number */
1533
    TLSv1_MINOR     = 1,        /* TLSv1   minor version number */
1534
    TLSv1_1_MINOR   = 2,        /* TLSv1_1 minor version number */
1535
    TLSv1_2_MINOR   = 3,        /* TLSv1_2 minor version number */
1536
    TLSv1_3_MINOR   = 4,        /* TLSv1_3 minor version number */
1537
    TLS_DRAFT_MAJOR = 0x7f,     /* Draft TLS major version number */
1538
    OLD_HELLO_ID    = 0x01,     /* SSLv2 Client Hello Indicator */
1539
    INVALID_BYTE    = 0xff,     /* Used to initialize cipher specs values */
1540
    NO_COMPRESSION  =  0,
1541
    ZLIB_COMPRESSION = 221,     /* wolfSSL zlib compression */
1542
    HELLO_EXT_SIG_ALGO = 13,    /* ID for the sig_algo hello extension */
1543
    HELLO_EXT_EXTMS = 0x0017,   /* ID for the extended master secret ext */
1544
    SECRET_LEN      = WOLFSSL_MAX_MASTER_KEY_LENGTH,
1545
                                /* pre RSA and all master */
1546
#if !defined(WOLFSSL_TLS13) || defined(WOLFSSL_32BIT_MILLI_TIME)
1547
    TIMESTAMP_LEN   = 4,        /* timestamp size in ticket */
1548
#else
1549
    TIMESTAMP_LEN   = 8,        /* timestamp size in ticket */
1550
#endif
1551
#ifdef WOLFSSL_TLS13
1552
    AGEADD_LEN      = 4,        /* ageAdd size in ticket */
1553
    NAMEDGROUP_LEN  = 2,        /* namedGroup size in ticket */
1554
#ifdef WOLFSSL_EARLY_DATA
1555
    MAXEARLYDATASZ_LEN = 4,     /* maxEarlyDataSz size in ticket */
1556
#endif
1557
#endif
1558
#ifndef NO_PSK
1559
    ENCRYPT_LEN     = (ENCRYPT_BASE_BITS / 8) + MAX_PSK_KEY_LEN + 2,
1560
#else
1561
    ENCRYPT_LEN     = (ENCRYPT_BASE_BITS / 8),
1562
#endif
1563
    SIZEOF_SENDER   =  4,       /* clnt or srvr           */
1564
    FINISHED_SZ     = 36,       /* WC_MD5_DIGEST_SIZE + WC_SHA_DIGEST_SIZE */
1565
    MAX_PLAINTEXT_SZ   = (1 << 14),        /* Max plaintext sz   */
1566
    MAX_TLS_CIPHER_SZ  = (1 << 14) + 2048, /* Max TLS encrypted data sz */
1567
#ifdef WOLFSSL_TLS13
1568
    MAX_TLS13_PLAIN_SZ = (1 << 14) + 1,    /* Max unencrypted data sz */
1569
    MAX_TLS13_ENC_SZ   = (1 << 14) + 256,  /* Max encrypted data sz   */
1570
#endif
1571
    MAX_MSG_EXTRA   = 38 + WC_MAX_DIGEST_SIZE,
1572
                                /* max added to msg, mac + pad  from */
1573
                                /* RECORD_HEADER_SZ + BLOCK_SZ (pad) + Max
1574
                                   digest sz + BLOC_SZ (iv) + pad byte (1) */
1575
    MAX_COMP_EXTRA  = 1024,     /* max compression extra */
1576
    MAX_MTU         = WOLFSSL_MAX_MTU,     /* max expected MTU */
1577
    MAX_UDP_SIZE    = 8192 - 100, /* was MAX_MTU - 100 */
1578
    MAX_DH_SZ       = (MAX_DHKEY_SZ * 3) + 12, /* DH_P, DH_G and DH_Pub */
1579
                                /* 4096 p, pub, g + 2 byte size for each */
1580
    MAX_STR_VERSION = 8,        /* string rep of protocol version */
1581
1582
    PAD_MD5        = 48,       /* pad length for finished */
1583
    PAD_SHA        = 40,       /* pad length for finished */
1584
    MAX_PAD_SIZE   = 256,      /* maximum length of padding */
1585
1586
    LENGTH_SZ      =  2,       /* length field for HMAC, data only */
1587
    VERSION_SZ     =  2,       /* length of proctocol version */
1588
    SEQ_SZ         =  8,       /* 64 bit sequence number  */
1589
    ALERT_SIZE     =  2,       /* level + description     */
1590
    VERIFY_HEADER  =  2,       /* always use 2 bytes      */
1591
    EXTS_SZ        =  2,       /* always use 2 bytes      */
1592
    EXT_ID_SZ      =  2,       /* always use 2 bytes      */
1593
    MAX_DH_SIZE    = MAX_DHKEY_SZ+1,
1594
                               /* Max size plus possible leading 0 */
1595
    MIN_FFHDE_GROUP = 0x100,   /* Named group minimum for FFDHE parameters  */
1596
    MAX_FFHDE_GROUP = 0x1FF,   /* Named group maximum for FFDHE parameters  */
1597
    SESSION_HINT_SZ = 4,       /* session timeout hint */
1598
    SESSION_ADD_SZ = 4,        /* session age add */
1599
    TICKET_NONCE_LEN_SZ = 1,   /* Ticket nonce length size */
1600
    DEF_TICKET_NONCE_SZ = 1,   /* Default ticket nonce size */
1601
#if defined(WOLFSSL_TLS13) || !defined(NO_PSK)
1602
    MAX_TICKET_NONCE_STATIC_SZ = TLS13_TICKET_NONCE_STATIC_SZ,
1603
                               /* maximum ticket nonce static size */
1604
#endif /* WOLFSSL_TLS13 || !NO_PSK */
1605
    MAX_LIFETIME   = 604800,   /* maximum ticket lifetime */
1606
1607
    RAN_LEN      = 32,         /* random length           */
1608
    SEED_LEN     = RAN_LEN * 2, /* tls prf seed length    */
1609
    ID_LEN       = 32,         /* session id length       */
1610
    COOKIE_SECRET_SZ = 14,     /* dtls cookie secret size */
1611
    MAX_COOKIE_LEN = WOLFSSL_COOKIE_LEN, /* max dtls cookie size */
1612
    COOKIE_SZ    = 20,         /* use a 20 byte cookie    */
1613
    SUITE_LEN    =  2,         /* cipher suite sz length  */
1614
    ENUM_LEN     =  1,         /* always a byte           */
1615
    OPAQUE8_LEN  =  1,         /* 1 byte                  */
1616
    OPAQUE16_LEN =  2,         /* 2 bytes                 */
1617
    OPAQUE24_LEN =  3,         /* 3 bytes                 */
1618
    OPAQUE32_LEN =  4,         /* 4 bytes                 */
1619
    OPAQUE64_LEN =  8,         /* 8 bytes                 */
1620
    COMP_LEN     =  1,         /* compression length      */
1621
    CURVE_LEN    =  2,         /* ecc named curve length  */
1622
    KE_GROUP_LEN =  2,         /* key exchange group length */
1623
#if defined(NO_SHA) && !defined(NO_SHA256)
1624
    SERVER_ID_LEN = WC_SHA256_DIGEST_SIZE,
1625
#else
1626
    SERVER_ID_LEN = WC_SHA_DIGEST_SIZE,
1627
#endif
1628
1629
    HANDSHAKE_HEADER_SZ   = 4,  /* type + length(3)        */
1630
    DTLS13_HANDSHAKE_HEADER_SZ   = 12, /* sizeof(Dtls13HandshakeHeader) */
1631
    RECORD_HEADER_SZ      = 5,  /* type + version + len(2) */
1632
    CERT_HEADER_SZ        = 3,  /* always 3 bytes          */
1633
    REQ_HEADER_SZ         = 2,  /* cert request header sz  */
1634
    HINT_LEN_SZ           = 2,  /* length of hint size field */
1635
    TRUNCATED_HMAC_SZ     = 10, /* length of hmac w/ truncated hmac extension */
1636
    HELLO_EXT_SZ          = 4,  /* base length of a hello extension */
1637
    HELLO_EXT_TYPE_SZ     = 2,  /* length of a hello extension type */
1638
    HELLO_EXT_SZ_SZ       = 2,  /* length of a hello extension size */
1639
    HELLO_EXT_SIGALGO_SZ  = 2,  /* length of number of items in sigalgo list */
1640
1641
    DTLS_HANDSHAKE_HEADER_SZ = 12, /* normal + seq(2) + offset(3) + length(3) */
1642
    DTLS_RECORD_HEADER_SZ    = 13, /* normal + epoch(2) + seq_num(6) */
1643
    DTLS12_CID_OFFSET        = 11,
1644
    DTLS_UNIFIED_HEADER_MIN_SZ = 2,
1645
    /* flags + seq_number(2) + length(2) + CID */
1646
    DTLS_RECVD_RL_HEADER_MAX_SZ = 5 + DTLS_CID_MAX_SIZE,
1647
    DTLS_RECORD_HEADER_MAX_SZ = 13,
1648
    DTLS_HANDSHAKE_EXTRA     = 8,  /* diff from normal */
1649
    DTLS_RECORD_EXTRA        = 8,  /* diff from normal */
1650
    DTLS_HANDSHAKE_SEQ_SZ    = 2,  /* handshake header sequence number */
1651
    DTLS_HANDSHAKE_FRAG_SZ   = 3,  /* fragment offset and length are 24 bit */
1652
    DTLS_POOL_SZ             = 20, /* allowed number of list items in TX and
1653
                                    * RX pool */
1654
    DTLS_FRAG_POOL_SZ        = WOLFSSL_DTLS_FRAG_POOL_SZ,
1655
                                   /* allowed number of fragments per msg */
1656
    DTLS_EXPORT_PRO          = 165,/* wolfSSL protocol for serialized session */
1657
    DTLS_EXPORT_STATE_PRO    = 166,/* wolfSSL protocol for serialized state */
1658
    TLS_EXPORT_PRO           = 167,/* wolfSSL protocol for serialized TLS */
1659
    DTLS_EXPORT_OPT_SZ       = 66, /* number of bytes used from Options */
1660
    DTLS_EXPORT_OPT_SZ_5     = 62, /* number of bytes used from Options */
1661
    DTLS_EXPORT_OPT_SZ_4     = 61, /* number of bytes used from Options */
1662
    TLS_EXPORT_OPT_SZ        = 66, /* number of bytes used from Options */
1663
    TLS_EXPORT_OPT_SZ_5      = 66, /* number of bytes used from Options */
1664
    TLS_EXPORT_OPT_SZ_4      = 65, /* number of bytes used from Options */
1665
    DTLS_EXPORT_OPT_SZ_3     = 60, /* number of bytes used from Options */
1666
    DTLS_EXPORT_KEY_SZ       = 325 + (DTLS_SEQ_SZ * 2),
1667
                                   /* max number of bytes used from Keys */
1668
    DTLS_EXPORT_MIN_KEY_SZ   = 85 + (DTLS_SEQ_SZ * 2),
1669
                                   /* min number of bytes used from Keys */
1670
    WOLFSSL_EXPORT_TLS       = 1,
1671
    WOLFSSL_EXPORT_DTLS      = 0,
1672
#ifndef WOLFSSL_EXPORT_SPC_SZ
1673
    WOLFSSL_EXPORT_SPC_SZ    = 16, /* number of bytes used from CipherSpecs */
1674
#endif
1675
    WOLFSSL_EXPORT_LEN       = 2,  /* 2 bytes for length and protocol */
1676
    WOLFSSL_EXPORT_VERSION   = 6,  /* wolfSSL version for serialized session */
1677
1678
    /* older export versions supported */
1679
    WOLFSSL_EXPORT_VERSION_5 = 5,  /* version before DTLS Encrypt-Then-MAC */
1680
    WOLFSSL_EXPORT_VERSION_4 = 4,  /* 5.6.4 release and before */
1681
    WOLFSSL_EXPORT_VERSION_3 = 3,  /* wolfSSL version before TLS 1.3 addition */
1682
1683
    MAX_EXPORT_IP            = 46, /* max ip size IPv4 mapped IPv6 */
1684
    DTLS_MTU_ADDITIONAL_READ_BUFFER = WOLFSSL_DTLS_MTU_ADDITIONAL_READ_BUFFER,
1685
                                   /* Additional bytes to read so that
1686
                                    * we can work with a peer that has
1687
                                    * a slightly different MTU than us. */
1688
    MAX_EXPORT_BUFFER        = 514, /* max size of buffer for exporting */
1689
    MAX_EXPORT_STATE_BUFFER  = (DTLS_EXPORT_MIN_KEY_SZ) + (3 * WOLFSSL_EXPORT_LEN),
1690
                                    /* max size of buffer for exporting state */
1691
    FINISHED_LABEL_SZ   = 15,  /* TLS finished label size */
1692
    TLS_FINISHED_SZ     = 12,  /* TLS has a shorter size  */
1693
    TLS_FINISHED_SZ_MAX = WC_MAX_DIGEST_SIZE,
1694
                            /* longest message digest size is SHA512, 64 */
1695
    EXT_MASTER_LABEL_SZ = 22,  /* TLS extended master secret label sz */
1696
    MASTER_LABEL_SZ     = 13,  /* TLS master secret label sz */
1697
    KEY_LABEL_SZ        = 13,  /* TLS key block expansion sz */
1698
    PROTOCOL_LABEL_SZ   = 9,   /* Length of the protocol label */
1699
    MAX_LABEL_SZ        = 34,  /* Maximum length of a label */
1700
    MAX_REQUEST_SZ      = 256, /* Maximum cert req len (no auth yet */
1701
    SESSION_FLUSH_COUNT = 256, /* Flush session cache unless user turns off */
1702
    TLS_MAX_PAD_SZ      = 255, /* Max padding in TLS */
1703
    MAX_EXT_DATA_LEN    = 65535,
1704
                          /* Max extension data length <0..2^16-1> RFC 8446
1705
                           * Section 4.2 */
1706
    MAX_SV_EXT_LEN      = 255,
1707
                          /* Max supported_versions extension length
1708
                           * <2..254> RFC 8446 Section 4.2.1.*/
1709
1710
#if defined(HAVE_NULL_CIPHER) && defined(WOLFSSL_TLS13)
1711
    #if defined(WOLFSSL_SHA384) && WC_MAX_SYM_KEY_SIZE < 48
1712
        MAX_SYM_KEY_SIZE    = WC_SHA384_DIGEST_SIZE,
1713
    #elif !defined(NO_SHA256) && WC_MAX_SYM_KEY_SIZE < 32
1714
        MAX_SYM_KEY_SIZE    = WC_SHA256_DIGEST_SIZE,
1715
    #else
1716
        MAX_SYM_KEY_SIZE    = WC_MAX_SYM_KEY_SIZE,
1717
    #endif
1718
#else
1719
    MAX_SYM_KEY_SIZE    = WC_MAX_SYM_KEY_SIZE,
1720
#endif
1721
1722
#if defined(HAVE_SELFTEST) && \
1723
    (!defined(HAVE_SELFTEST_VERSION) || (HAVE_SELFTEST_VERSION < 2))
1724
    #ifndef WOLFSSL_AES_KEY_SIZE_ENUM
1725
    #define WOLFSSL_AES_KEY_SIZE_ENUM
1726
    AES_IV_SIZE         = 16,
1727
    AES_128_KEY_SIZE    = 16,
1728
    AES_192_KEY_SIZE    = 24,
1729
    AES_256_KEY_SIZE    = 32,
1730
    #endif
1731
#endif
1732
1733
    MAX_IV_SZ           = WC_AES_BLOCK_SIZE,
1734
1735
    AEAD_SEQ_OFFSET     = 4,   /* Auth Data: Sequence number */
1736
    AEAD_TYPE_OFFSET    = 8,   /* Auth Data: Type            */
1737
    AEAD_VMAJ_OFFSET    = 9,   /* Auth Data: Major Version   */
1738
    AEAD_VMIN_OFFSET    = 10,  /* Auth Data: Minor Version   */
1739
    AEAD_LEN_OFFSET     = 11,  /* Auth Data: Length          */
1740
    AEAD_AUTH_DATA_SZ   = 13,  /* Size of the data to authenticate */
1741
    AEAD_NONCE_SZ       = 12,
1742
    AESGCM_IMP_IV_SZ    = 4,   /* Size of GCM AEAD implicit IV */
1743
    AESCCM_IMP_IV_SZ    = 4,   /* Size of CCM AEAD implicit IV */
1744
    AESGCM_EXP_IV_SZ    = 8,   /* Size of GCM/CCM AEAD explicit IV */
1745
    AESGCM_NONCE_SZ     = AESGCM_EXP_IV_SZ + AESGCM_IMP_IV_SZ,
1746
    GCM_IMP_IV_SZ       = 4,   /* Size of GCM AEAD implicit IV */
1747
    CCM_IMP_IV_SZ       = 4,   /* Size of CCM AEAD implicit IV */
1748
    GCM_EXP_IV_SZ       = 8,   /* Size of GCM/CCM AEAD explicit IV */
1749
    GCM_NONCE_SZ        = GCM_EXP_IV_SZ + GCM_IMP_IV_SZ,
1750
1751
    CHACHA20_IMP_IV_SZ  = 12,  /* Size of ChaCha20 AEAD implicit IV */
1752
    CHACHA20_NONCE_SZ   = 12,  /* Size of ChacCha20 nonce           */
1753
    CHACHA20_OLD_OFFSET = 4,   /* Offset for seq # in old poly1305  */
1754
    CHACHA20_OFFSET     = 4,   /* Offset for seq # in poly1305  */
1755
1756
    /* For any new implicit/explicit IV size adjust AEAD_MAX_***_SZ */
1757
1758
    AES_GCM_AUTH_SZ     = 16, /* AES-GCM Auth Tag length    */
1759
    AES_CCM_16_AUTH_SZ  = 16, /* AES-CCM-16 Auth Tag length */
1760
    AES_CCM_8_AUTH_SZ   = 8,  /* AES-CCM-8 Auth Tag Length  */
1761
    AESCCM_NONCE_SZ     = 12,
1762
1763
    SM4_GCM_AUTH_SZ     = 16, /* SM4-GCM Auth Tag length    */
1764
    SM4_GCM_NONCE_SZ    = 12, /* SM4 GCM Nonce length       */
1765
    SM4_CCM_AUTH_SZ     = 16, /* SM4-CCM Auth Tag length    */
1766
    SM4_CCM_NONCE_SZ    = 12, /* SM4 CCM Nonce length       */
1767
1768
    CAMELLIA_128_KEY_SIZE = 16, /* for 128 bit */
1769
    CAMELLIA_192_KEY_SIZE = 24, /* for 192 bit */
1770
    CAMELLIA_256_KEY_SIZE = 32, /* for 256 bit */
1771
    CAMELLIA_IV_SIZE      = 16, /* always block size */
1772
1773
    CHACHA20_256_KEY_SIZE = 32,  /* for 256 bit             */
1774
    CHACHA20_128_KEY_SIZE = 16,  /* for 128 bit             */
1775
    CHACHA20_IV_SIZE      = 12,  /* 96 bits for iv          */
1776
1777
    POLY1305_AUTH_SZ    = 16,  /* 128 bits                */
1778
1779
    HMAC_NONCE_SZ       = 12,  /* Size of HMAC nonce */
1780
1781
    EVP_SALT_SIZE       =  8,  /* evp salt size 64 bits   */
1782
1783
#ifndef ECDHE_SIZE /* allow this to be overridden at compile-time */
1784
    ECDHE_SIZE          = 32,  /* ECDHE server size defaults to 256 bit */
1785
#endif
1786
    MAX_EXPORT_ECC_SZ   = 256, /* Export ANSI X9.62 max future size */
1787
    MAX_CURVE_NAME_SZ   = 20,  /* Maximum size of curve name string */
1788
1789
    NEW_SA_MAJOR        = 8,   /* Most significant byte used with new sig algos */
1790
    RSA_PSS_RSAE_SHA256_MINOR = 0x04,
1791
    RSA_PSS_RSAE_SHA384_MINOR = 0x05,
1792
    RSA_PSS_RSAE_SHA512_MINOR = 0x06,
1793
    RSA_PSS_PSS_SHA256_MINOR = 0x09,
1794
    RSA_PSS_PSS_SHA384_MINOR = 0x0A,
1795
    RSA_PSS_PSS_SHA512_MINOR = 0x0B,
1796
    ECDSA_BRAINPOOLP256R1TLS13_SHA256_MINOR = 0x1A,
1797
    ECDSA_BRAINPOOLP384R1TLS13_SHA384_MINOR = 0x1B,
1798
    ECDSA_BRAINPOOLP512R1TLS13_SHA512_MINOR = 0x1C,
1799
1800
    ED25519_SA_MAJOR    = 8,   /* Most significant byte for ED25519 */
1801
    ED25519_SA_MINOR    = 7,   /* Least significant byte for ED25519 */
1802
    ED448_SA_MAJOR      = 8,   /* Most significant byte for ED448 */
1803
    ED448_SA_MINOR      = 8,   /* Least significant byte for ED448 */
1804
    SM2_SA_MAJOR        = 7,   /* Most significant byte for SM2 with SM3 */
1805
    SM2_SA_MINOR        = 8,   /* Least significant byte for SM2 with SM3 */
1806
1807
    FALCON_SA_MAJOR     = 0xFE,/* Most significant byte used with falcon sig algs */
1808
    MLDSA_SA_MAJOR      = 0x09,/* Most significant byte used with ML-DSA sig algs */
1809
1810
    /* These values for falcon match what OQS has defined. */
1811
    FALCON_LEVEL1_SA_MAJOR = 0xFE,
1812
    FALCON_LEVEL1_SA_MINOR = 0xD7,
1813
    FALCON_LEVEL5_SA_MAJOR = 0xFE,
1814
    FALCON_LEVEL5_SA_MINOR = 0xDA,
1815
1816
    /* These values for ML-DSA correspond to what is proposed in the IETF. */
1817
    MLDSA_44_SA_MAJOR = 0x09,
1818
    MLDSA_44_SA_MINOR = 0x04,
1819
    MLDSA_65_SA_MAJOR = 0x09,
1820
    MLDSA_65_SA_MINOR = 0x05,
1821
    MLDSA_87_SA_MAJOR = 0x09,
1822
    MLDSA_87_SA_MINOR = 0x06,
1823
1824
    /* These values for SLH-DSA correspond to the code points assigned in
1825
     * draft-reddy-tls-slhdsa (0x0911-0x091C) and match what oqs-provider uses.
1826
     * The major byte (0x09) is shared with ML-DSA. */
1827
    SLHDSA_SA_MAJOR             = 0x09,
1828
    SLHDSA_SHA2_128S_SA_MINOR   = 0x11,
1829
    SLHDSA_SHA2_128F_SA_MINOR   = 0x12,
1830
    SLHDSA_SHA2_192S_SA_MINOR   = 0x13,
1831
    SLHDSA_SHA2_192F_SA_MINOR   = 0x14,
1832
    SLHDSA_SHA2_256S_SA_MINOR   = 0x15,
1833
    SLHDSA_SHA2_256F_SA_MINOR   = 0x16,
1834
    SLHDSA_SHAKE_128S_SA_MINOR  = 0x17,
1835
    SLHDSA_SHAKE_128F_SA_MINOR  = 0x18,
1836
    SLHDSA_SHAKE_192S_SA_MINOR  = 0x19,
1837
    SLHDSA_SHAKE_192F_SA_MINOR  = 0x1A,
1838
    SLHDSA_SHAKE_256S_SA_MINOR  = 0x1B,
1839
    SLHDSA_SHAKE_256F_SA_MINOR  = 0x1C,
1840
1841
    MIN_RSA_SHA512_PSS_BITS = 512 * 2 + 8 * 8, /* Min key size */
1842
    MIN_RSA_SHA384_PSS_BITS = 384 * 2 + 8 * 8, /* Min key size */
1843
1844
    CLIENT_HELLO_FIRST =  35,  /* Protocol + RAN_LEN + sizeof(id_len) */
1845
    MAX_SUITE_NAME     =  48,  /* maximum length of cipher suite string */
1846
1847
    DTLS_TIMEOUT_INIT       =  1, /* default timeout init for DTLS receive  */
1848
    DTLS_TIMEOUT_MAX        = 64, /* default max timeout for DTLS receive */
1849
    DTLS_TIMEOUT_MULTIPLIER =  2, /* default timeout multiplier for DTLS recv */
1850
1851
    NULL_TERM_LEN        =   1,  /* length of null '\0' termination character */
1852
    MIN_PSK_ID_LEN       =   6,  /* min length of identities */
1853
    MIN_PSK_BINDERS_LEN  =  33,  /* min length of binders */
1854
1855
#ifndef MAX_WOLFSSL_FILE_SIZE
1856
    MAX_WOLFSSL_FILE_SIZE = 1024UL * 1024UL * 4,  /* 4 mb file size alloc limit */
1857
#endif
1858
#if defined(WOLFSSL_SYS_CRYPTO_POLICY)
1859
    MAX_WOLFSSL_CRYPTO_POLICY_SIZE = 1024UL, /* Crypto-policy file is one line.
1860
                                              * It should not be large. */
1861
    MIN_WOLFSSL_SEC_LEVEL = 0,
1862
    MAX_WOLFSSL_SEC_LEVEL = 5,
1863
#endif /* WOLFSSL_SYS_CRYPTO_POLICY */
1864
1865
    CERT_MIN_SIZE      =  256, /* min PEM cert size with header/footer */
1866
1867
    NO_SNIFF           =   0,  /* not sniffing */
1868
    SNIFF              =   1,  /* currently sniffing */
1869
1870
    HASH_SIG_SIZE      =   2,  /* default SHA1 RSA */
1871
1872
    NO_COPY            =   0,  /* should we copy static buffer for write */
1873
    COPY               =   1,  /* should we copy static buffer for write */
1874
1875
    INVALID_PEER_ID    = 0xFFFF, /* Initialize value for peer ID. */
1876
1877
    PREV_ORDER         = -1,   /* Sequence number is in previous epoch. */
1878
    PEER_ORDER         = 1,    /* Peer sequence number for verify. */
1879
    CUR_ORDER          = 0,    /* Current sequence number. */
1880
    WRITE_PROTO        = 1,    /* writing a protocol message */
1881
    READ_PROTO         = 0     /* reading a protocol message */
1882
};
1883
1884
1885
/* Size of the data to authenticate */
1886
#if defined(WOLFSSL_DTLS) && defined(WOLFSSL_DTLS_CID)
1887
#define AEAD_AUTH_DATA_SZ WOLFSSL_TLS_AEAD_CID_AAD_SZ
1888
#else
1889
#define AEAD_AUTH_DATA_SZ 13
1890
#endif
1891
1892
#define WOLFSSL_NAMED_GROUP_IS_FFDHE(group) \
1893
0
    (WOLFSSL_FFDHE_START <= (group) && (group) <= WOLFSSL_FFDHE_END)
1894
#ifdef WOLFSSL_HAVE_MLKEM
1895
WOLFSSL_LOCAL int NamedGroupIsPqc(int group);
1896
WOLFSSL_LOCAL int NamedGroupIsPqcHybrid(int group);
1897
0
#define WOLFSSL_NAMED_GROUP_IS_PQC(group) NamedGroupIsPqc(group)
1898
0
#define WOLFSSL_NAMED_GROUP_IS_PQC_HYBRID(group) NamedGroupIsPqcHybrid(group)
1899
#else
1900
#define WOLFSSL_NAMED_GROUP_IS_PQC(group)        ((void)(group), 0)
1901
#define WOLFSSL_NAMED_GROUP_IS_PQC_HYBRID(group) ((void)(group), 0)
1902
#endif /* WOLFSSL_HAVE_MLKEM */
1903
1904
/* minimum Downgrade Minor version */
1905
#ifndef WOLFSSL_MIN_DOWNGRADE
1906
    #ifndef NO_OLD_TLS
1907
        #define WOLFSSL_MIN_DOWNGRADE TLSv1_MINOR
1908
    #else
1909
0
        #define WOLFSSL_MIN_DOWNGRADE TLSv1_2_MINOR
1910
    #endif
1911
#endif
1912
1913
/* minimum DTLS Downgrade Minor version */
1914
#ifndef WOLFSSL_MIN_DTLS_DOWNGRADE
1915
#define WOLFSSL_MIN_DTLS_DOWNGRADE DTLS_MINOR;
1916
#endif
1917
1918
/* Set max implicit IV size for AEAD cipher suites */
1919
#if defined(WOLFSSL_TLS13) && defined(HAVE_NULL_CIPHER) && defined(WOLFSSL_SHA384)
1920
    /* Integrity-only cipher suites use IV size equal to hash output size */
1921
    #define AEAD_MAX_IMP_SZ 48
1922
#elif defined(WOLFSSL_TLS13) && defined(HAVE_NULL_CIPHER) && !defined(NO_SHA256)
1923
    /* Integrity-only cipher suites use IV size equal to hash output size */
1924
    #define AEAD_MAX_IMP_SZ 32
1925
#else
1926
    #define AEAD_MAX_IMP_SZ 12
1927
#endif
1928
1929
/* Set max explicit IV size for AEAD cipher suites */
1930
0
#define AEAD_MAX_EXP_SZ 8
1931
1932
1933
#ifndef WOLFSSL_MAX_SUITE_SZ
1934
0
    #define WOLFSSL_MAX_SUITE_SZ 300
1935
    /* 150 suites for now! */
1936
#endif
1937
1938
/* number of items in the signature algo list */
1939
#ifndef WOLFSSL_MAX_SIGALGO
1940
#if (defined(WOLFSSL_LEANPSK) || defined(WOLFSSL_LEANTLS)) && \
1941
    !defined(HAVE_FALCON) && !defined(WOLFSSL_HAVE_MLDSA) && \
1942
    !defined(WOLFSSL_HAVE_SLHDSA)
1943
    /* Lean builds keep the list small to minimize the memory footprint, unless
1944
     * they are post-quantum builds: those want to inter-op with OQS's OpenSSL
1945
     * that sends a lot more sigalgs, so they fall through to the larger default.
1946
     */
1947
    #define WOLFSSL_MAX_SIGALGO 44
1948
#else
1949
0
    #define WOLFSSL_MAX_SIGALGO 128
1950
#endif
1951
#endif
1952
1953
1954
/* set minimum ECC key size allowed */
1955
#ifndef WOLFSSL_MIN_ECC_BITS
1956
    #ifdef WOLFSSL_MAX_STRENGTH
1957
        #define WOLFSSL_MIN_ECC_BITS  256
1958
    #else
1959
0
        #define WOLFSSL_MIN_ECC_BITS 224
1960
    #endif
1961
#endif /* WOLFSSL_MIN_ECC_BITS */
1962
#if (WOLFSSL_MIN_ECC_BITS % 8)
1963
    /* Some ECC keys are not divisible by 8 such as prime239v1 or sect131r1.
1964
       In these cases round down to the nearest value divisible by 8. The
1965
       restriction of being divisible by 8 is in place to match wc_ecc_size
1966
       function from wolfSSL.
1967
     */
1968
    #error ECC minimum bit size must be a multiple of 8
1969
#endif
1970
0
#define MIN_ECCKEY_SZ (WOLFSSL_MIN_ECC_BITS / 8)
1971
1972
#ifdef HAVE_FALCON
1973
#ifndef MIN_FALCONKEY_SZ
1974
    #define MIN_FALCONKEY_SZ    1281
1975
#endif
1976
#endif
1977
#ifdef WOLFSSL_HAVE_MLDSA
1978
#ifndef MIN_MLDSAKEY_SZ
1979
    #define MIN_MLDSAKEY_SZ    2528
1980
#endif
1981
#endif
1982
1983
/* set minimum RSA key size allowed */
1984
#ifndef WOLFSSL_MIN_RSA_BITS
1985
    #if defined(WOLFSSL_HARDEN_TLS) && !defined(WOLFSSL_HARDEN_TLS_NO_PKEY_CHECK)
1986
        /* Using guidance from section 5.6.1
1987
         * https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf */
1988
        #if WOLFSSL_HARDEN_TLS >= 128
1989
            #define WOLFSSL_MIN_RSA_BITS 3072
1990
        #elif WOLFSSL_HARDEN_TLS >= 112
1991
            #define WOLFSSL_MIN_RSA_BITS 2048
1992
        #endif
1993
    #elif defined(WOLFSSL_MAX_STRENGTH)
1994
        #define WOLFSSL_MIN_RSA_BITS 2048
1995
    #else
1996
0
        #define WOLFSSL_MIN_RSA_BITS 1024
1997
    #endif
1998
#endif /* WOLFSSL_MIN_RSA_BITS */
1999
#if defined(WOLFSSL_HARDEN_TLS) && WOLFSSL_MIN_RSA_BITS < 2048 && \
2000
    !defined(WOLFSSL_HARDEN_TLS_NO_PKEY_CHECK)
2001
    /* Implementations MUST NOT negotiate cipher suites offering less than
2002
     * 112 bits of security.
2003
     * https://www.rfc-editor.org/rfc/rfc9325#section-4.1
2004
     * Using guidance from section 5.6.1
2005
     * https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf */
2006
    #error "For 112 bits of security RSA needs at least 2048 bit keys"
2007
#endif
2008
#if (WOLFSSL_MIN_RSA_BITS % 8)
2009
    /* This is to account for the example case of a min size of 2050 bits but
2010
       still allows 2049 bit key. So we need the measurement to be in bytes. */
2011
    #error RSA minimum bit size must be a multiple of 8
2012
#endif
2013
0
#define MIN_RSAKEY_SZ (WOLFSSL_MIN_RSA_BITS / 8)
2014
2015
#ifdef SESSION_INDEX
2016
/* Shift values for making a session index */
2017
#define SESSIDX_ROW_SHIFT 4
2018
#define SESSIDX_IDX_MASK  0x0F
2019
#endif
2020
2021
/* Size of the static per-certificate slot in a cached session's chain. This is
2022
 * embedded by value MAX_CHAIN_DEPTH times in every WOLFSSL_SESSION, so it is
2023
 * deliberately not sized from a post-quantum signature: a certificate too
2024
 * large for a slot is simply not recorded in the chain. Use
2025
 * MAX_CERT_WIRE_SZ for anything bounding a certificate on the wire. */
2026
#ifndef MAX_X509_SIZE
2027
    /* 9 KB holds the largest ML-DSA certificate (ML-DSA-87: 4627 byte signature
2028
     * plus 2592 byte public key, ~7.6 KB in practice) and an ML-DSA-44 dual
2029
     * algorithm certificate, which carries a second key and signature. Not
2030
     * derived from the enabled parameter set: the slot holds any certificate in
2031
     * a peer's chain, so tying it to the local ML-DSA level would make a
2032
     * level-restricted build silently drop certificates a full build kept. */
2033
    #if defined(HAVE_FALCON) || defined(WOLFSSL_HAVE_MLDSA) || \
2034
        defined(WOLFSSL_HAVE_SLHDSA)
2035
        #define MAX_X509_SIZE   (9*1024) /* max static x509 buffer size; ML-DSA is big */
2036
    #elif defined(WOLFSSL_HAPROXY)
2037
        #define MAX_X509_SIZE   3072 /* max static x509 buffer size */
2038
    #else
2039
0
        #define MAX_X509_SIZE   2048 /* max static x509 buffer size */
2040
    #endif
2041
#endif
2042
2043
/* Largest single certificate that may appear in a handshake message. A
2044
 * post-quantum certificate's DER size is dominated by the issuer signature
2045
 * embedded in it, whose length depends on the parameter sets compiled in, plus
2046
 * headroom for the subject public key (largest is ML-DSA-87 at 2592 bytes) and
2047
 * the rest of the TBSCertificate. A leaf may be signed by a root of a larger
2048
 * parameter set, so the signature maximum is taken family-wide. */
2049
#ifndef MAX_CERT_WIRE_SZ
2050
    #if defined(WOLFSSL_HAVE_SLHDSA) && \
2051
        ((WC_SLHDSA_MAX_SIG_LEN + 4096) > MAX_X509_SIZE)
2052
        #define MAX_CERT_WIRE_SZ    (WC_SLHDSA_MAX_SIG_LEN + 4096)
2053
    #elif defined(WOLFSSL_HAVE_MLDSA) && \
2054
        ((MLDSA_MAX_SIG_SIZE + 4096) > MAX_X509_SIZE)
2055
        #define MAX_CERT_WIRE_SZ    (MLDSA_MAX_SIG_SIZE + 4096)
2056
    #else
2057
0
        #define MAX_CERT_WIRE_SZ    MAX_X509_SIZE
2058
    #endif
2059
#endif
2060
2061
/* max cert chain peer depth */
2062
#ifndef MAX_CHAIN_DEPTH
2063
0
    #define MAX_CHAIN_DEPTH 9
2064
#endif
2065
2066
#if defined(HAVE_CERTIFICATE_STATUS_REQUEST) || \
2067
                    defined(HAVE_CERTIFICATE_STATUS_REQUEST_V2)
2068
    #if !defined(HAVE_OCSP)
2069
        #error OCSP Stapling and Stapling V2 needs OCSP. Please define HAVE_OCSP.
2070
    #endif
2071
#endif
2072
2073
/* Max certificate extensions in TLS1.3 */
2074
#if defined(HAVE_CERTIFICATE_STATUS_REQUEST)
2075
    /* Number of extensions to set each OCSP response */
2076
    #define MAX_CERT_EXTENSIONS (1 + MAX_CHAIN_DEPTH)
2077
#else
2078
    /* Only empty extensions */
2079
0
    #define MAX_CERT_EXTENSIONS 1
2080
#endif
2081
2082
/* Chain depth assumed when sizing the certificate message. Deliberately not
2083
 * MAX_CHAIN_DEPTH: that bounds how deep a chain may be verified, while this
2084
 * sizes a buffer an unauthenticated peer can make us allocate. Only reduced
2085
 * when a post-quantum certificate has inflated the per-certificate size, where
2086
 * the full verification depth would reserve hundreds of kilobytes and chains
2087
 * that deep are not realistic. Classic builds keep the historical depth, since
2088
 * the resulting buffer is small either way. Raise it for a deployment that
2089
 * presents deeper chains of post-quantum certificates. */
2090
#ifndef MAX_CERT_MSG_DEPTH
2091
    /* Trim only once a single certificate is large enough that the full
2092
     * verification depth would reserve an unreasonable amount for an
2093
     * unauthenticated peer. The threshold sits above any classic or ML-DSA
2094
     * certificate, so those builds keep the historical depth, and the test is
2095
     * on the size itself rather than on which macro produced it, so raising
2096
     * MAX_X509_SIZE cannot disengage the trim. */
2097
    #if (MAX_CERT_WIRE_SZ > (16*1024)) && (MAX_CHAIN_DEPTH > 5)
2098
        #define MAX_CERT_MSG_DEPTH 5
2099
    #else
2100
0
        #define MAX_CERT_MSG_DEPTH MAX_CHAIN_DEPTH
2101
    #endif
2102
#endif
2103
2104
/* max size of a certificate message payload */
2105
/* assumes MAX_CERT_MSG_DEPTH certificates of MAX_CERT_WIRE_SZ each */
2106
#ifndef MAX_CERTIFICATE_SZ
2107
    #define MAX_CERTIFICATE_SZ \
2108
0
                (CERT_HEADER_SZ + \
2109
0
                (MAX_CERT_WIRE_SZ + CERT_HEADER_SZ) * MAX_CERT_MSG_DEPTH)
2110
#endif
2111
2112
/* max size of a handshake message, currently set to the certificate */
2113
#ifndef MAX_HANDSHAKE_SZ
2114
0
    #define MAX_HANDSHAKE_SZ MAX_CERTIFICATE_SZ
2115
#endif
2116
2117
#ifndef PREALLOC_SESSION_TICKET_LEN
2118
    #define PREALLOC_SESSION_TICKET_LEN 512
2119
#endif
2120
2121
#ifndef PREALLOC_SESSION_TICKET_NONCE_LEN
2122
    #define PREALLOC_SESSION_TICKET_NONCE_LEN 32
2123
#endif
2124
2125
#ifndef SESSION_TICKET_HINT_DEFAULT
2126
    #define SESSION_TICKET_HINT_DEFAULT 300
2127
#endif
2128
2129
#if !defined(WOLFSSL_NO_DEF_TICKET_ENC_CB) && !defined(NO_WOLFSSL_SERVER)
2130
    /* Check chosen encryption is available. */
2131
    #if !(defined(HAVE_CHACHA) && defined(HAVE_POLY1305)) && \
2132
        defined(WOLFSSL_TICKET_ENC_CHACHA20_POLY1305)
2133
        #error "ChaCha20-Poly1305 not available for default ticket encryption"
2134
    #endif
2135
    #if !defined(HAVE_AESGCM) && (defined(WOLFSSL_TICKET_ENC_AES128_GCM) || \
2136
        defined(WOLFSSL_TICKET_ENC_AES256_GCM))
2137
        #error "AES-GCM not available for default ticket encryption"
2138
    #endif
2139
2140
    #ifndef WOLFSSL_TICKET_KEY_LIFETIME
2141
        /* Default lifetime is 1 hour from issue of first ticket with key. */
2142
        #define WOLFSSL_TICKET_KEY_LIFETIME       (60 * 60)
2143
    #endif
2144
    #if WOLFSSL_TICKET_KEY_LIFETIME <= SESSION_TICKET_HINT_DEFAULT
2145
        #error "Ticket Key lifetime must be longer than ticket life hint."
2146
    #endif
2147
#endif
2148
2149
0
#define MAX_ENCRYPT_SZ ENCRYPT_LEN
2150
2151
#define WOLFSSL_ASSERT_EQ(x, y) wc_static_assert((x) == (y))
2152
#define WOLFSSL_ASSERT_GE(x, y) wc_static_assert((x) >= (y))
2153
2154
0
#define WOLFSSL_ASSERT_SIZEOF_GE(x, y) wc_static_assert(sizeof(x) >= sizeof(y))
2155
#define WOLFSSL_ASSERT_SIZEOF_EQ(x, y) wc_static_assert(sizeof(x) == sizeof(y))
2156
2157
/* states. Adding state before HANDSHAKE_DONE will break session importing */
2158
enum states {
2159
    NULL_STATE = 0,
2160
2161
    SERVER_HELLOVERIFYREQUEST_COMPLETE,
2162
    SERVER_HELLO_RETRY_REQUEST_COMPLETE,
2163
    SERVER_HELLO_COMPLETE,
2164
    SERVER_ENCRYPTED_EXTENSIONS_COMPLETE,
2165
    SERVER_CERT_COMPLETE,
2166
    SERVER_CERT_VERIFY_COMPLETE,
2167
    SERVER_KEYEXCHANGE_COMPLETE,
2168
    SERVER_HELLODONE_COMPLETE,
2169
    SERVER_CHANGECIPHERSPEC_COMPLETE,
2170
    SERVER_FINISHED_COMPLETE,
2171
2172
    CLIENT_HELLO_RETRY,
2173
    CLIENT_HELLO_COMPLETE,
2174
    CLIENT_KEYEXCHANGE_COMPLETE,
2175
    CLIENT_CHANGECIPHERSPEC_COMPLETE,
2176
    CLIENT_FINISHED_COMPLETE,
2177
2178
    HANDSHAKE_DONE,
2179
2180
#ifdef WOLFSSL_DTLS13
2181
    SERVER_FINISHED_ACKED,
2182
#endif /* WOLFSSL_DTLS13 */
2183
    WOLF_ENUM_DUMMY_LAST_ELEMENT(states)
2184
};
2185
2186
/* SSL Version */
2187
typedef struct ProtocolVersion {
2188
    byte major;
2189
    byte minor;
2190
} WOLFSSL_PACK ProtocolVersion;
2191
2192
2193
WOLFSSL_LOCAL ProtocolVersion MakeSSLv3(void);
2194
WOLFSSL_LOCAL ProtocolVersion MakeTLSv1(void);
2195
WOLFSSL_LOCAL ProtocolVersion MakeTLSv1_1(void);
2196
WOLFSSL_LOCAL ProtocolVersion MakeTLSv1_2(void);
2197
WOLFSSL_LOCAL ProtocolVersion MakeTLSv1_3(void);
2198
2199
#ifdef WOLFSSL_DTLS
2200
    WOLFSSL_LOCAL ProtocolVersion MakeDTLSv1(void);
2201
    WOLFSSL_LOCAL ProtocolVersion MakeDTLSv1_2(void);
2202
2203
#ifdef WOLFSSL_DTLS13
2204
    WOLFSSL_LOCAL ProtocolVersion MakeDTLSv1_3(void);
2205
#endif /* WOLFSSL_DTLS13 */
2206
2207
#endif
2208
#ifdef WOLFSSL_SESSION_EXPORT
2209
WOLFSSL_LOCAL int wolfSSL_session_export_internal(WOLFSSL* ssl, byte* buf,
2210
        word32* sz, int type);
2211
WOLFSSL_LOCAL int wolfSSL_session_import_internal(WOLFSSL* ssl, const byte* buf,
2212
        word32 sz, int type);
2213
#ifdef WOLFSSL_DTLS
2214
    WOLFSSL_LOCAL int wolfSSL_dtls_export_state_internal(WOLFSSL* ssl,
2215
                                                          byte* buf, word32 sz);
2216
    WOLFSSL_LOCAL int wolfSSL_dtls_import_state_internal(WOLFSSL* ssl,
2217
                                                    const byte* buf, word32 sz);
2218
    WOLFSSL_LOCAL int wolfSSL_send_session(WOLFSSL* ssl);
2219
#endif
2220
#endif
2221
2222
struct WOLFSSL_BY_DIR_HASH {
2223
    unsigned long hash_value;
2224
    int last_suffix;
2225
};
2226
2227
struct WOLFSSL_BY_DIR_entry {
2228
    char*   dir_name;
2229
    int     dir_type;
2230
    WOLF_STACK_OF(WOLFSSL_BY_DIR_HASH) *hashes;
2231
};
2232
2233
struct WOLFSSL_BY_DIR {
2234
    WOLF_STACK_OF(WOLFSSL_BY_DIR_entry) *dir_entry;
2235
    wolfSSL_Mutex    lock; /* dir list lock */
2236
};
2237
2238
/* wolfSSL method type */
2239
struct WOLFSSL_METHOD {
2240
    ProtocolVersion version;
2241
    byte            side;         /* connection side, server or client */
2242
    byte            downgrade;    /* whether to downgrade version, default no */
2243
};
2244
2245
/* wolfSSL buffer type - internal uses "buffer" type */
2246
typedef WOLFSSL_BUFFER_INFO buffer;
2247
2248
typedef struct Suites Suites;
2249
2250
/* Declare opaque struct for API to use */
2251
#ifndef WOLFSSL_CLIENT_SESSION_DEFINED
2252
    typedef struct ClientSession ClientSession;
2253
    #define WOLFSSL_CLIENT_SESSION_DEFINED
2254
#endif
2255
2256
/* defaults to client */
2257
WOLFSSL_LOCAL void InitSSL_Method(WOLFSSL_METHOD* method, ProtocolVersion pv);
2258
2259
WOLFSSL_LOCAL void InitSSL_CTX_Suites(WOLFSSL_CTX* ctx);
2260
WOLFSSL_LOCAL int InitSSL_Suites(WOLFSSL* ssl);
2261
WOLFSSL_LOCAL int InitSSL_Side(WOLFSSL* ssl, word16 side);
2262
2263
2264
#if defined(HAVE_CURVE25519) && !defined(WOLFSSL_X25519_NO_MASK_PEER)
2265
WOLFSSL_LOCAL const byte* MaskCurve25519PeerKey(const byte* pub, word32 pubSz,
2266
                                               byte maskBuf[CURVE25519_KEYSIZE]);
2267
#endif
2268
2269
WOLFSSL_LOCAL int DoHandShakeMsgType(WOLFSSL* ssl, byte* input,
2270
        word32* inOutIdx, byte type, word32 size, word32 totalSz);
2271
/* for sniffer */
2272
WOLFSSL_LOCAL int DoFinished(WOLFSSL* ssl, const byte* input, word32* inOutIdx,
2273
                            word32 size, word32 totalSz, int sniff);
2274
#ifdef WOLFSSL_TLS13
2275
WOLFSSL_LOCAL int DoTls13Finished(WOLFSSL* ssl, const byte* input, word32* inOutIdx,
2276
                           word32 size, word32 totalSz, int sniff);
2277
#endif
2278
#ifdef WOLFSSL_API_PREFIX_MAP
2279
    #define DoApplicationData wolfSSL_DoApplicationData
2280
#endif
2281
WOLFSSL_TEST_VIS int DoApplicationData(WOLFSSL* ssl, byte* input, word32* inOutIdx,
2282
                                    int sniff);
2283
/* TLS v1.3 needs these */
2284
WOLFSSL_LOCAL int  HandleTlsResumption(WOLFSSL* ssl, Suites* clSuites);
2285
#ifdef WOLFSSL_TLS13
2286
WOLFSSL_LOCAL byte SuiteMac(const byte* suite);
2287
#endif
2288
WOLFSSL_LOCAL int  DoClientHello(WOLFSSL* ssl, const byte* input, word32* inOutIdx,
2289
                             word32 helloSz);
2290
#ifdef WOLFSSL_TLS13
2291
WOLFSSL_LOCAL int DoTls13ClientHello(WOLFSSL* ssl, const byte* input,
2292
                                     word32* inOutIdx, word32 helloSz);
2293
#endif
2294
WOLFSSL_LOCAL int  DoServerHello(WOLFSSL* ssl, const byte* input, word32* inOutIdx,
2295
                      word32 helloSz);
2296
WOLFSSL_LOCAL int  CompleteServerHello(WOLFSSL *ssl);
2297
WOLFSSL_LOCAL int  CheckVersion(WOLFSSL *ssl, ProtocolVersion pv);
2298
WOLFSSL_LOCAL int  PickHashSigAlgo(WOLFSSL* ssl, const byte* hashSigAlgo,
2299
                                   word32 hashSigAlgoSz, int matchSuites);
2300
#if defined(WOLF_PRIVATE_KEY_ID) && !defined(NO_CHECK_PRIVATE_KEY)
2301
/* slhParam is the enum SlhDsaParam for DYNAMIC_TYPE_SLHDSA, whose parameter
2302
 * set cannot be derived from a device-side identifier. Pass -1 otherwise. */
2303
WOLFSSL_LOCAL int  CreateDevPrivateKey(void** pkey, byte* data, word32 length,
2304
                                       int hsType, int label, int id,
2305
                                       void* heap, int devId, int slhParam);
2306
#endif
2307
#ifdef WOLFSSL_BLIND_PRIVATE_KEY
2308
WOLFSSL_LOCAL int wolfssl_priv_der_blind(WC_RNG* rng, DerBuffer* key,
2309
    DerBuffer** mask);
2310
WOLFSSL_LOCAL void wolfssl_priv_der_blind_toggle(DerBuffer* key,
2311
    const DerBuffer* mask);
2312
WOLFSSL_LOCAL WARN_UNUSED_RESULT DerBuffer *wolfssl_priv_der_unblind(
2313
    const DerBuffer* key, const DerBuffer* mask);
2314
WOLFSSL_LOCAL void wolfssl_priv_der_unblind_free(DerBuffer* key);
2315
#endif
2316
WOLFSSL_LOCAL int  DecodePrivateKey(WOLFSSL *ssl, word32* sigLen);
2317
#ifdef WOLFSSL_DUAL_ALG_CERTS
2318
WOLFSSL_LOCAL int  DecodeAltPrivateKey(WOLFSSL *ssl, word32* sigLen);
2319
#endif
2320
#if defined(WOLF_PRIVATE_KEY_ID) || defined(HAVE_PK_CALLBACKS)
2321
WOLFSSL_LOCAL int GetPrivateKeySigSize(WOLFSSL* ssl);
2322
#ifndef NO_ASN
2323
    WOLFSSL_LOCAL int  InitSigPkCb(WOLFSSL* ssl, SignatureCtx* sigCtx);
2324
#endif
2325
#endif
2326
WOLFSSL_LOCAL int CreateSigData(WOLFSSL* ssl, byte* sigData, word16* sigDataSz,
2327
                                int check);
2328
WOLFSSL_LOCAL int CreateRSAEncodedSig(byte* sig, byte* sigData, int sigDataSz,
2329
                                      int sigAlgo, int hashAlgo);
2330
#ifdef WOLFSSL_ASYNC_IO
2331
WOLFSSL_LOCAL void FreeAsyncCtx(WOLFSSL* ssl, byte freeAsync);
2332
#endif
2333
WOLFSSL_LOCAL void FreeKeyExchange(WOLFSSL* ssl);
2334
WOLFSSL_LOCAL void FreeSuites(WOLFSSL* ssl);
2335
WOLFSSL_LOCAL int  ProcessPeerCerts(WOLFSSL* ssl, byte* input, word32* inOutIdx, word32 totalSz);
2336
#ifdef WOLFSSL_API_PREFIX_MAP
2337
    #define MatchDomainName wolfSSL_MatchDomainName
2338
#endif
2339
WOLFSSL_TEST_VIS int  MatchDomainName(const char* pattern, int len,
2340
                                      const char* str, word32 strLen,
2341
                                      unsigned int flags);
2342
#if !defined(NO_CERTS) && !defined(NO_ASN)
2343
WOLFSSL_LOCAL int  CheckForAltNames(DecodedCert* dCert, const char* domain,
2344
                                    word32 domainLen, int* checkCN,
2345
                                    unsigned int flags, byte isIP);
2346
WOLFSSL_LOCAL int  CheckIPAddr(DecodedCert* dCert, const char* ipasc,
2347
                               size_t ipascLen);
2348
WOLFSSL_LOCAL void CopyDecodedName(WOLFSSL_X509_NAME* name, DecodedCert* dCert, int nameType);
2349
#endif
2350
WOLFSSL_LOCAL int  SetupTicket(WOLFSSL* ssl);
2351
WOLFSSL_LOCAL int  CreateTicket(WOLFSSL* ssl);
2352
WOLFSSL_LOCAL int  DefTicketHintTooLarge(WOLFSSL* ssl);
2353
WOLFSSL_LOCAL int  HashRaw(WOLFSSL* ssl, const byte* data, int sz);
2354
WOLFSSL_LOCAL int  HashOutput(WOLFSSL* ssl, const byte* output, int sz,
2355
                              int ivSz);
2356
WOLFSSL_LOCAL int  HashInput(WOLFSSL* ssl, const byte* input, int sz);
2357
2358
#ifdef HAVE_SNI
2359
#ifndef NO_WOLFSSL_SERVER
2360
WOLFSSL_LOCAL int SNI_Callback(WOLFSSL* ssl);
2361
#endif
2362
#endif
2363
2364
#ifdef HAVE_ALPN
2365
WOLFSSL_LOCAL int ALPN_Select(WOLFSSL* ssl);
2366
#endif
2367
2368
WOLFSSL_LOCAL int ChachaAEADEncrypt(WOLFSSL* ssl, byte* out, const byte* input,
2369
                              word16 sz, byte type); /* needed by sniffer */
2370
WOLFSSL_LOCAL int ChachaAEADDecrypt(WOLFSSL* ssl, byte* plain, const byte* input,
2371
                              word16 sz); /* needed by sniffer */
2372
2373
#ifdef WOLFSSL_TLS13
2374
WOLFSSL_LOCAL int  DecryptTls13(WOLFSSL* ssl, byte* output, const byte* input,
2375
                                word16 sz, const byte* aad, word16 aadSz);
2376
WOLFSSL_LOCAL int  DoTls13HandShakeMsgType(WOLFSSL* ssl, byte* input,
2377
                                           word32* inOutIdx, byte type,
2378
                                           word32 size, word32 totalSz);
2379
WOLFSSL_LOCAL int  DoTls13HandShakeMsg(WOLFSSL* ssl, byte* input,
2380
                                       word32* inOutIdx, word32 totalSz);
2381
WOLFSSL_LOCAL int DoTls13ServerHello(WOLFSSL* ssl, const byte* input,
2382
                                     word32* inOutIdx, word32 helloSz,
2383
                                     byte* extMsgType);
2384
WOLFSSL_LOCAL int RestartHandshakeHash(WOLFSSL* ssl);
2385
2386
WOLFSSL_LOCAL int Tls13DeriveKey(WOLFSSL *ssl, byte *output, int outputLen,
2387
    const byte *secret, const byte *label, word32 labelLen, int hashAlgo,
2388
    int includeMsgs, int side);
2389
#endif
2390
int TimingPadVerify(WOLFSSL* ssl, const byte* input, int padLen, int macSz,
2391
                    int pLen, int content);
2392
2393
2394
enum {
2395
    FORCED_FREE = 1,
2396
    NO_FORCED_FREE = 0
2397
};
2398
2399
2400
/* only use compression extra if using compression */
2401
#ifdef HAVE_LIBZ
2402
    #define COMP_EXTRA MAX_COMP_EXTRA
2403
#else
2404
0
    #define COMP_EXTRA 0
2405
#endif
2406
2407
/* only the sniffer needs space in the buffer for extra MTU record(s) */
2408
#ifdef WOLFSSL_SNIFFER
2409
    #define MTU_EXTRA MAX_MTU * 3
2410
#else
2411
    #define MTU_EXTRA 0
2412
#endif
2413
2414
2415
/* embedded callbacks require large static buffers, make sure on */
2416
#ifdef WOLFSSL_CALLBACKS
2417
    #undef  LARGE_STATIC_BUFFERS
2418
    #define LARGE_STATIC_BUFFERS
2419
#endif
2420
2421
2422
/* determine maximum record size */
2423
0
#define MAX_RECORD_SIZE 16384  /* 2^14, max size by standard */
2424
2425
#ifdef RECORD_SIZE
2426
    /* user supplied value */
2427
    #if RECORD_SIZE < 128 || RECORD_SIZE > MAX_RECORD_SIZE
2428
        #error Invalid record size
2429
    #endif
2430
#else
2431
    /* give user option to use 16K static buffers */
2432
    #if defined(LARGE_STATIC_BUFFERS)
2433
        #define RECORD_SIZE     MAX_RECORD_SIZE
2434
    #else
2435
        #ifdef WOLFSSL_DTLS
2436
            #define RECORD_SIZE MAX_MTU
2437
        #else
2438
            #define RECORD_SIZE 128
2439
        #endif
2440
    #endif
2441
#endif
2442
2443
2444
/* user option to turn off 16K output option */
2445
/* if using small static buffers (default) and SSL_write tries to write data
2446
   larger than the record we have, dynamically get it, unless user says only
2447
   write in static buffer chunks  */
2448
#ifndef STATIC_CHUNKS_ONLY
2449
0
    #define OUTPUT_RECORD_SIZE MAX_RECORD_SIZE
2450
#else
2451
    #define OUTPUT_RECORD_SIZE RECORD_SIZE
2452
#endif
2453
2454
/* wolfSSL input buffer
2455
2456
   RFC 2246:
2457
2458
   length
2459
       The length (in bytes) of the following TLSPlaintext.fragment.
2460
       The length should not exceed 2^14.
2461
*/
2462
#ifdef STATIC_BUFFER_LEN
2463
    /* user supplied option */
2464
#elif defined(LARGE_STATIC_BUFFERS)
2465
    #define STATIC_BUFFER_LEN (RECORD_HEADER_SZ + RECORD_SIZE + COMP_EXTRA + \
2466
             MTU_EXTRA + MAX_MSG_EXTRA)
2467
#else
2468
    /* don't fragment memory from the record header */
2469
0
    #define STATIC_BUFFER_LEN RECORD_HEADER_SZ
2470
#endif
2471
2472
/* RECORD_HEADER_SZ is an enum constant, so the preprocessor can't check
2473
 * this bound. */
2474
wc_static_assert(STATIC_BUFFER_LEN >= RECORD_HEADER_SZ);
2475
2476
/* Default read-ahead window: when read-ahead is enabled the record header read
2477
 * requests up to a full record's worth of data in a single recv() so the body
2478
 * (and possibly following records) can be pulled in without a second syscall.
2479
 * Sized to one maximum TLS record (MAX_RECORD_SIZE, not the buffer-sizing
2480
 * RECORD_SIZE which may be small) so the whole record is captured. Defined
2481
 * unconditionally so the setters and CTX init can reference it as the default
2482
 * window even when read-ahead I/O is not built. */
2483
#ifndef WOLFSSL_READ_AHEAD_SZ
2484
#define WOLFSSL_READ_AHEAD_SZ (RECORD_HEADER_SZ + MAX_RECORD_SIZE + \
2485
         COMP_EXTRA + MTU_EXTRA + MAX_MSG_EXTRA)
2486
#endif
2487
2488
/* Upper bound for a caller-configured read-ahead window
2489
 * (wolfSSL_CTX/SSL_set_default_read_buffer_len()). The window feeds signed int
2490
 * arithmetic in GetInputData_ex(); bounding it well below INT_MAX ensures a
2491
 * large caller-supplied size can never overflow that arithmetic to a negative
2492
 * value (which would skip GrowInputBuffer() and drive an oversized recv()).
2493
 * 16 MB is far above any realistic coalescing window. Defined unconditionally
2494
 * so the setters can clamp even when read-ahead I/O is not built. */
2495
#ifndef WOLFSSL_MAX_READ_AHEAD_SZ
2496
#define WOLFSSL_MAX_READ_AHEAD_SZ (16 * 1024 * 1024)
2497
#endif
2498
2499
typedef struct {
2500
    ALIGN16 byte staticBuffer[STATIC_BUFFER_LEN];
2501
    byte*  buffer;       /* place holder for static or dynamic buffer */
2502
    word32 length;       /* total buffer length used */
2503
    word32 idx;          /* idx to part of length already consumed */
2504
    word32 bufferSize;   /* current buffer size */
2505
    byte   dynamicFlag;  /* dynamic memory currently in use */
2506
    byte   offset;       /* alignment offset attempt */
2507
} bufferStatic;
2508
2509
/* Cipher Suites holder */
2510
struct Suites {
2511
    word16 suiteSz;                 /* suite length in bytes        */
2512
    word16 hashSigAlgoSz;           /* SigAlgo extension length in bytes */
2513
    byte   suites[WOLFSSL_MAX_SUITE_SZ];
2514
    byte   hashSigAlgo[WOLFSSL_MAX_SIGALGO]; /* sig/algo to offer */
2515
    byte   setSuites:1;             /* user set suites from default */
2516
};
2517
2518
typedef struct CipherSuite {
2519
    byte   cipherSuite0;
2520
    byte   cipherSuite;
2521
    word32 ecdhCurveOID;
2522
    struct KeyShareEntry* clientKSE;
2523
#if defined(WOLFSSL_TLS13) && defined(HAVE_SUPPORTED_CURVES)
2524
    int    doHelloRetry;
2525
#endif
2526
} CipherSuite;
2527
2528
#ifdef WOLFSSL_API_PREFIX_MAP
2529
    #define InitSuitesHashSigAlgo wolfSSL_InitSuitesHashSigAlgo
2530
#endif
2531
WOLFSSL_TEST_VIS void InitSuitesHashSigAlgo(byte* hashSigAlgo, int have,
2532
                                       int tls1_2, int tls1_3, int keySz,
2533
                                       word16* len);
2534
WOLFSSL_LOCAL int AllocateCtxSuites(WOLFSSL_CTX* ctx);
2535
WOLFSSL_LOCAL int InitCtxSuitesWithMutex(WOLFSSL_CTX* ctx);
2536
WOLFSSL_LOCAL int AllocateSuites(WOLFSSL* ssl);
2537
WOLFSSL_LOCAL void InitSuites(Suites* suites, ProtocolVersion pv, int keySz,
2538
                              word16 haveRSA, word16 havePSK, word16 haveDH,
2539
                              word16 haveECDSAsig, word16 haveECC,
2540
                              word16 haveStaticRSA, word16 haveStaticECC,
2541
                              word16 haveAnon, word16 haveNull,
2542
                              word16 haveAES128, word16 haveSHA1,
2543
                              word16 haveRC4, int side);
2544
2545
void refineSuites(const Suites* sslSuites, const Suites* peerSuites,
2546
        Suites* outSuites, byte useClientOrder);
2547
void sslRefineSuites(WOLFSSL* ssl, Suites* peerSuites);
2548
2549
typedef struct TLSX TLSX;
2550
WOLFSSL_LOCAL int MatchSuite_ex(const WOLFSSL* ssl, Suites* peerSuites,
2551
                                CipherSuite* cs, TLSX* extensions);
2552
WOLFSSL_LOCAL int  MatchSuite(WOLFSSL* ssl, Suites* peerSuites);
2553
WOLFSSL_LOCAL int  SetCipherList_ex(const WOLFSSL_CTX* ctx, const WOLFSSL* ssl,
2554
        Suites* suites, const char* list);
2555
WOLFSSL_LOCAL int  SetCipherList(const WOLFSSL_CTX* ctx, Suites* suites,
2556
                                 const char* list);
2557
WOLFSSL_LOCAL int  SetCipherListFromBytes(WOLFSSL_CTX* ctx, Suites* suites,
2558
                                          const byte* list, const int listSz);
2559
WOLFSSL_LOCAL int  SetSuitesHashSigAlgo(Suites* suites, const char* list);
2560
2561
#ifndef PSK_TYPES_DEFINED
2562
    typedef unsigned int (*wc_psk_client_callback)(WOLFSSL*, const char*, char*,
2563
                          unsigned int, unsigned char*, unsigned int);
2564
    typedef unsigned int (*wc_psk_server_callback)(WOLFSSL*, const char*,
2565
                          unsigned char*, unsigned int);
2566
#ifdef WOLFSSL_TLS13
2567
    typedef unsigned int (*wc_psk_client_cs_callback)(WOLFSSL*, const char*,
2568
                          char*, unsigned int, unsigned char*, unsigned int,
2569
                          const char* cipherName);
2570
    typedef unsigned int (*wc_psk_client_tls13_callback)(WOLFSSL*, const char*,
2571
                          char*, unsigned int, unsigned char*, unsigned int,
2572
                          const char** cipherName);
2573
    typedef unsigned int (*wc_psk_server_tls13_callback)(WOLFSSL*, const char*,
2574
                          unsigned char*, unsigned int,
2575
                          const char** cipherName);
2576
#endif
2577
#endif /* PSK_TYPES_DEFINED */
2578
#if defined(WOLFSSL_DTLS) && defined(WOLFSSL_SESSION_EXPORT) && \
2579
   !defined(WOLFSSL_DTLS_EXPORT_TYPES)
2580
    typedef int (*wc_dtls_export)(WOLFSSL* ssl,
2581
2582
#define WOLFSSL_DTLS_EXPORT_TYPES
2583
#endif /* WOLFSSL_DTLS_EXPORT_TYPES */
2584
2585
2586
#if defined(OPENSSL_ALL) || defined(WOLFSSL_QT)
2587
#define MAX_DESCRIPTION_SZ 255
2588
#endif
2589
struct WOLFSSL_CIPHER {
2590
    byte cipherSuite0;
2591
    byte cipherSuite;
2592
    const WOLFSSL* ssl;
2593
#if defined(OPENSSL_ALL) || defined(WOLFSSL_QT)
2594
    char description[MAX_DESCRIPTION_SZ];
2595
    unsigned long offset;
2596
    unsigned int in_stack; /* TRUE if added to stack in wolfSSL_get_ciphers_compat */
2597
    int bits;
2598
#endif
2599
};
2600
2601
2602
#ifdef NO_ASN
2603
    /* no_asn won't have */
2604
    typedef struct CertStatus CertStatus;
2605
#endif
2606
2607
#ifndef HAVE_OCSP
2608
    typedef struct WOLFSSL_OCSP WOLFSSL_OCSP;
2609
#endif
2610
2611
/* wolfSSL OCSP controller */
2612
#ifdef HAVE_OCSP
2613
struct WOLFSSL_OCSP {
2614
    WOLFSSL_CERT_MANAGER* cm;            /* pointer back to cert manager */
2615
    OcspEntry*            ocspList;      /* OCSP response list */
2616
    wolfSSL_Mutex         ocspLock;      /* OCSP list lock */
2617
    int                   error;
2618
    int(*statusCb)(WOLFSSL*, void*);
2619
    void*                 statusCbArg;
2620
};
2621
#endif
2622
2623
typedef struct CRL_Entry CRL_Entry;
2624
2625
#if defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3)
2626
    #define CRL_DIGEST_SIZE WC_SM3_DIGEST_SIZE
2627
#elif defined(NO_SHA)
2628
    #define CRL_DIGEST_SIZE WC_SHA256_DIGEST_SIZE
2629
#else
2630
    #define CRL_DIGEST_SIZE WC_SHA_DIGEST_SIZE
2631
#endif
2632
2633
#ifdef NO_ASN
2634
    typedef struct RevokedCert RevokedCert;
2635
#endif
2636
#ifdef CRL_STATIC_REVOKED_LIST
2637
    #ifndef CRL_MAX_REVOKED_CERTS
2638
        #define CRL_MAX_REVOKED_CERTS 4
2639
    #elif CRL_MAX_REVOKED_CERTS > 22000
2640
        #error CRL_MAX_REVOKED_CERTS too big, max is 22000
2641
    #endif
2642
#endif
2643
2644
#ifdef HAVE_CRL
2645
/* Complete CRL */
2646
struct CRL_Entry {
2647
    byte*   toBeSigned;
2648
    byte*   signature;
2649
#ifdef WC_RSA_PSS
2650
    byte*   sigParams;   /* buffer with signature parameters */
2651
#endif
2652
#if defined(OPENSSL_EXTRA)
2653
    WOLFSSL_X509_NAME*    issuer;     /* X509_NAME type issuer */
2654
#endif
2655
    CRL_Entry* next;                      /* next entry */
2656
#ifdef CRL_STATIC_REVOKED_LIST
2657
    RevokedCert certs[CRL_MAX_REVOKED_CERTS];
2658
#else
2659
    RevokedCert* certs;             /* revoked cert list  */
2660
#endif
2661
    wolfSSL_Mutex verifyMutex;
2662
    /* DupCRL_Entry bulk copies the data after the `verifyMutex` member, so
2663
     * only self-contained value data belongs below it. Anything holding a
2664
     * pointer goes above, where DupCRL_Entry copies it explicitly. Using the
2665
     * mutex as the marker because clang-tidy doesn't like taking the sizeof a
2666
     * pointer. */
2667
    char    crlNumber[CRL_MAX_NUM_HEX_STR_SZ];    /* CRL number extension */
2668
    byte    issuerHash[CRL_DIGEST_SIZE];  /* issuer hash                 */
2669
    /* byte    crlHash[CRL_DIGEST_SIZE];      raw crl data hash           */
2670
    /* restore the hash here if needed for optimized comparisons */
2671
    byte    lastDate[MAX_DATE_SIZE]; /* last date updated  */
2672
    byte    nextDate[MAX_DATE_SIZE]; /* next update date   */
2673
    byte    lastDateFormat;          /* last date format */
2674
    byte    nextDateFormat;          /* next date format */
2675
#if defined(OPENSSL_EXTRA)
2676
    WOLFSSL_ASN1_TIME lastDateAsn1;  /* last date updated  */
2677
    WOLFSSL_ASN1_TIME nextDateAsn1;  /* next update date   */
2678
#endif
2679
    int     totalCerts;             /* number on list     */
2680
    int     version;                /* version of certificate */
2681
    int     verified;
2682
    word32  tbsSz;
2683
    word32  signatureSz;
2684
#ifdef WC_RSA_PSS
2685
    word32  sigParamsSz; /* length of signature parameters   */
2686
#endif
2687
    word32  signatureOID;
2688
#if !defined(NO_SKID) && !defined(NO_ASN)
2689
    byte    extAuthKeyId[KEYID_SIZE];
2690
    byte    extAuthKeyIdSet:1;  /* Auth key identifier set indicator */
2691
#endif
2692
    byte    crlNumberSet:1;     /* CRL number set indicator */
2693
};
2694
2695
2696
#ifdef HAVE_CRL_MONITOR
2697
typedef struct CRL_Monitor CRL_Monitor;
2698
2699
/* CRL directory monitor */
2700
struct CRL_Monitor {
2701
    char* path;      /* full dir path, if valid pointer we're using */
2702
    int   type;      /* PEM or ASN1 type */
2703
};
2704
2705
2706
#if defined(HAVE_CRL) && defined(NO_FILESYSTEM)
2707
    #undef HAVE_CRL_MONITOR
2708
#endif
2709
2710
/* PEM and DER possible */
2711
#define WOLFSSL_CRL_MONITORS_LEN (2)
2712
2713
#if defined(__MACH__) || defined(__FreeBSD__) || defined(__linux__)
2714
typedef int    wolfSSL_CRL_mfd_t; /* monitor fd, -1 if no init yet */
2715
/* mfd for bsd is kqueue fd, eventfd for linux */
2716
#define WOLFSSL_CRL_MFD_INIT_VAL (-1)
2717
#elif defined(_MSC_VER)
2718
typedef HANDLE wolfSSL_CRL_mfd_t; /* monitor fd, INVALID_HANDLE_VALUE if
2719
                                   * no init yet */
2720
#define WOLFSSL_CRL_MFD_INIT_VAL (INVALID_HANDLE_VALUE)
2721
#endif
2722
#endif
2723
2724
/* wolfSSL CRL controller */
2725
struct WOLFSSL_CRL {
2726
    WOLFSSL_CERT_MANAGER* cm;            /* pointer back to cert manager */
2727
    CRL_Entry*            crlList;       /* our CRL list */
2728
#ifdef HAVE_CRL_IO
2729
    CbCrlIO               crlIOCb;
2730
#endif
2731
    wolfSSL_RwLock        crlLock;       /* CRL list lock */
2732
#ifdef HAVE_CRL_MONITOR
2733
    CRL_Monitor           monitors[WOLFSSL_CRL_MONITORS_LEN];
2734
    COND_TYPE             cond;          /* condition to signal setup */
2735
    THREAD_TYPE           tid;           /* monitoring thread */
2736
    wolfSSL_CRL_mfd_t     mfd;
2737
    int                   setup;         /* thread is setup predicate */
2738
#endif
2739
#ifdef OPENSSL_ALL
2740
    wolfSSL_Ref           ref;
2741
#endif
2742
#if defined(OPENSSL_EXTRA)
2743
    WOLFSSL_STACK*        revokedStack;  /* cached STACK_OF(X509_REVOKED) */
2744
#endif
2745
    void*                 heap;          /* heap hint for dynamic memory */
2746
};
2747
#endif
2748
2749
2750
#ifdef NO_ASN
2751
    typedef struct Signer Signer;
2752
#ifdef WOLFSSL_TRUST_PEER_CERT
2753
    typedef struct TrustedPeerCert TrustedPeerCert;
2754
#endif
2755
#endif
2756
2757
2758
#ifndef CA_TABLE_SIZE
2759
0
    #define CA_TABLE_SIZE 11
2760
#endif
2761
#ifdef WOLFSSL_TRUST_PEER_CERT
2762
    #define TP_TABLE_SIZE 11
2763
#endif
2764
2765
/* wolfSSL Certificate Manager */
2766
struct WOLFSSL_CERT_MANAGER {
2767
    Signer*         caTable[CA_TABLE_SIZE]; /* the CA signer table */
2768
    void*           heap;                /* heap helper */
2769
#ifdef WOLFSSL_TRUST_PEER_CERT
2770
    TrustedPeerCert* tpTable[TP_TABLE_SIZE]; /* table of trusted peer certs */
2771
    wolfSSL_Mutex   tpLock;                  /* trusted peer list lock */
2772
#endif
2773
    WOLFSSL_CRL*    crl;                 /* CRL checker */
2774
    WOLFSSL_OCSP*   ocsp;                /* OCSP checker */
2775
#if !defined(NO_WOLFSSL_SERVER) && (defined(HAVE_CERTIFICATE_STATUS_REQUEST) \
2776
                               ||  defined(HAVE_CERTIFICATE_STATUS_REQUEST_V2))
2777
    WOLFSSL_OCSP*   ocsp_stapling;       /* OCSP checker for OCSP stapling */
2778
#endif
2779
    char*           ocspOverrideURL;     /* use this responder */
2780
    void*           ocspIOCtx;           /* I/O callback CTX */
2781
#ifndef NO_WOLFSSL_CM_VERIFY
2782
    VerifyCallback  verifyCallback;      /* Verify callback */
2783
#endif
2784
    CallbackCACache caCacheCallback;       /* CA cache addition callback */
2785
    CbMissingCRL    cbMissingCRL;          /* notify thru cb of missing crl */
2786
    crlErrorCb      crlCb;                 /* Allow user to override error */
2787
    void*           crlCbCtx;
2788
    CbOCSPIO        ocspIOCb;              /* I/O callback for OCSP lookup */
2789
    CbOCSPRespFree  ocspRespFreeCb;        /* Frees OCSP Response from IO Cb */
2790
    wolfSSL_Mutex   caLock;                /* CA list lock */
2791
    byte            crlEnabled:1;          /* is CRL on ? */
2792
    byte            crlCheckAll:1;         /* always leaf, but all ? */
2793
    byte            ocspEnabled:1;         /* is OCSP on ? */
2794
    byte            ocspCheckAll:1;        /* always leaf, but all ? */
2795
    byte            ocspFailIfNotSupported:1; /* refuse a cert that advertises
2796
                                              * no OCSP responder ? */
2797
    byte            ocspSendNonce:1;       /* send the OCSP nonce ? */
2798
    byte            ocspUseOverrideURL:1;  /* ignore cert responder, override */
2799
    byte            ocspStaplingEnabled:1; /* is OCSP Stapling on ? */
2800
#if defined(HAVE_CERTIFICATE_STATUS_REQUEST) \
2801
||  defined(HAVE_CERTIFICATE_STATUS_REQUEST_V2)
2802
    byte            ocspMustStaple:1;      /* server must respond with staple */
2803
#endif
2804
    /* Tracks which resources were successfully initialized so that
2805
     * DoCertManagerFree can dispose of them safely even when construction
2806
     * fails partway through. */
2807
    WC_BITFIELD     caLockInit:1;          /* caLock has been initialized */
2808
#ifdef WOLFSSL_TRUST_PEER_CERT
2809
    WC_BITFIELD     tpLockInit:1;          /* tpLock has been initialized */
2810
#endif
2811
    WC_BITFIELD     refInit:1;             /* ref has been initialized */
2812
2813
#ifndef NO_RSA
2814
    short           minRsaKeySz;         /* minimum allowed RSA key size */
2815
#endif
2816
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || defined(HAVE_ED448)
2817
    short           minEccKeySz;         /* minimum allowed ECC key size */
2818
#endif
2819
#if defined(OPENSSL_EXTRA) || defined(WOLFSSL_WPAS_SMALL)
2820
    WOLFSSL_X509_STORE  *x509_store_p;  /* a pointer back to CTX x509 store  */
2821
                                        /* CTX has ownership and free this   */
2822
                                        /* with CTX free.                    */
2823
#endif
2824
    wolfSSL_Ref     ref;
2825
#ifdef HAVE_FALCON
2826
    short           minFalconKeySz;     /* minimum allowed Falcon key size */
2827
#endif
2828
#ifdef WOLFSSL_HAVE_MLDSA
2829
    short           minMlDsaKeySz;      /* minimum allowed ML-DSA key size */
2830
#endif
2831
#ifdef WC_ASN_UNKNOWN_EXT_CB
2832
    wc_UnknownExtCallback unknownExtCallback;
2833
#if defined(HAVE_CRL)
2834
    wc_UnknownExtCallback   crlUnknownExtCallback;
2835
    wc_UnknownExtCallbackEx crlUnknownExtCallbackEx;
2836
    void*                   crlUnknownExtCallbackExCtx;
2837
#endif
2838
#endif
2839
#ifdef HAVE_CRL_UPDATE_CB
2840
    CbUpdateCRL    cbUpdateCRL; /* notify thru cb that crl has updated */
2841
#endif
2842
};
2843
2844
WOLFSSL_LOCAL int CM_SaveCertCache(WOLFSSL_CERT_MANAGER* cm,
2845
                                   const char* fname);
2846
WOLFSSL_LOCAL int CM_RestoreCertCache(WOLFSSL_CERT_MANAGER* cm,
2847
                                      const char* fname);
2848
WOLFSSL_LOCAL int CM_MemSaveCertCache(WOLFSSL_CERT_MANAGER* cm, void* mem,
2849
                                      int sz, int* used);
2850
WOLFSSL_LOCAL int CM_MemRestoreCertCache(WOLFSSL_CERT_MANAGER* cm,
2851
                                         const void* mem, int sz);
2852
WOLFSSL_LOCAL int CM_GetCertCacheMemSize(WOLFSSL_CERT_MANAGER* cm);
2853
WOLFSSL_LOCAL int CM_VerifyBuffer_ex(WOLFSSL_CERT_MANAGER* cm, const byte* buff,
2854
                                     long sz, int format, int prev_err);
2855
2856
2857
#ifndef NO_CERTS
2858
#if !defined(NO_WOLFSSL_CLIENT) || !defined(WOLFSSL_NO_CLIENT_AUTH)
2859
typedef struct ProcPeerCertArgs {
2860
    buffer*      certs;
2861
#ifdef WOLFSSL_TLS13
2862
    buffer*      exts; /* extensions */
2863
#endif
2864
#ifndef NO_ASN
2865
    DecodedCert* dCert;
2866
#endif
2867
    word32 idx;
2868
    word32 begin;
2869
    int    totalCerts; /* number of certs in certs buffer */
2870
    int    count;
2871
    int    certIdx;
2872
    int    lastErr;
2873
    int    leafVerifyErr;
2874
#ifdef WOLFSSL_TLS13
2875
    byte   ctxSz;
2876
#endif
2877
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
2878
    char   untrustedDepth;
2879
#endif
2880
    word16 fatal:1;
2881
    word16 verifyErr:1;
2882
    word16 dCertInit:1;
2883
#ifdef WOLFSSL_TRUST_PEER_CERT
2884
    word16 haveTrustPeer:1; /* was cert verified by loaded trusted peer cert */
2885
#endif
2886
} ProcPeerCertArgs;
2887
WOLFSSL_LOCAL int DoVerifyCallback(WOLFSSL_CERT_MANAGER* cm, WOLFSSL* ssl,
2888
        int cert_err, ProcPeerCertArgs* args);
2889
WOLFSSL_LOCAL void DoCrlCallback(WOLFSSL_CERT_MANAGER* cm, WOLFSSL* ssl,
2890
        ProcPeerCertArgs* args, int* outRet);
2891
2892
WOLFSSL_LOCAL int SetupStoreCtxCallback(WOLFSSL_X509_STORE_CTX** store_pt,
2893
        WOLFSSL* ssl, WOLFSSL_CERT_MANAGER* cm, ProcPeerCertArgs* args,
2894
        int cert_err, void* heap, int* x509Free);
2895
WOLFSSL_LOCAL void CleanupStoreCtxCallback(WOLFSSL_X509_STORE_CTX* store,
2896
        WOLFSSL* ssl, void* heap, int x509Free);
2897
#endif /* !defined(NO_WOLFSSL_CLIENT) || !defined(WOLFSSL_NO_CLIENT_AUTH) */
2898
WOLFSSL_LOCAL int X509StoreLoadCertBuffer(WOLFSSL_X509_STORE *str,
2899
                                        byte *buf, word32 bufLen, int type);
2900
WOLFSSL_LOCAL int X509StorePushCertsToCM(WOLFSSL_X509_STORE* store);
2901
#endif /* !defined NO_CERTS */
2902
2903
/* wolfSSL Sock Addr */
2904
struct WOLFSSL_SOCKADDR {
2905
    unsigned int sz; /* sockaddr size */
2906
    unsigned int bufSz; /* size of allocated buffer */
2907
    void*        sa; /* pointer to the sockaddr_in or sockaddr_in6 */
2908
};
2909
2910
#ifdef WOLFSSL_DTLS
2911
typedef struct WOLFSSL_DTLS_CTX {
2912
#ifdef WOLFSSL_RW_THREADED
2913
    /* Protect peer access after the handshake */
2914
    wolfSSL_RwLock peerLock;
2915
#endif
2916
    WOLFSSL_SOCKADDR peer;
2917
#ifdef WOLFSSL_DTLS_CID
2918
    WOLFSSL_SOCKADDR pendingPeer; /* When using CID's, we don't want to update
2919
                                   * the peer's address until we successfully
2920
                                   * de-protect the record. */
2921
#endif
2922
    int rfd;
2923
    int wfd;
2924
    WolfSSLRecvFrom recvfrom;
2925
    WolfSSLSento sendto;
2926
    byte userSet:1;
2927
    byte connected:1; /* When set indicates rfd and wfd sockets are
2928
                       * connected (connect() and bind() both called).
2929
                       * This means that sendto and recvfrom do not need to
2930
                       * specify and store the peer address. */
2931
    byte rfdIsDGram:1; /* whether rfd is a SOCK_DGRAM socket; probed with
2932
                        * getsockopt(SO_TYPE) where rfd is assigned to keep
2933
                        * the syscall out of the I/O callbacks. */
2934
    byte wfdIsDGram:1; /* as rfdIsDGram, for wfd; rfd and wfd may be
2935
                        * different sockets of different types. */
2936
#ifdef WOLFSSL_DTLS_CID
2937
    byte processingPendingRecord:1;
2938
#endif
2939
} WOLFSSL_DTLS_CTX;
2940
#endif
2941
2942
2943
typedef struct WOLFSSL_DTLS_PEERSEQ {
2944
    word32 window[WOLFSSL_DTLS_WINDOW_WORDS];
2945
                        /* Sliding window for current epoch    */
2946
    word16 nextEpoch;   /* Expected epoch in next record       */
2947
    word16 nextSeq_hi;  /* Expected sequence in next record    */
2948
    word32 nextSeq_lo;
2949
2950
    word32 prevWindow[WOLFSSL_DTLS_WINDOW_WORDS];
2951
                        /* Sliding window for old epoch        */
2952
    word32 prevSeq_lo;
2953
    word16 prevSeq_hi;  /* Next sequence in allowed old epoch  */
2954
2955
#ifdef WOLFSSL_MULTICAST
2956
    word16 peerId;
2957
    word32 highwaterMark;
2958
#endif
2959
} WOLFSSL_DTLS_PEERSEQ;
2960
2961
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
2962
struct WOLFSSL_BIO {
2963
    WOLFSSL_BUF_MEM* mem_buf;
2964
    WOLFSSL_BIO_METHOD* method;
2965
    WOLFSSL_BIO* prev;          /* previous in chain */
2966
    WOLFSSL_BIO* next;          /* next in chain */
2967
    WOLFSSL_BIO* pair;          /* BIO paired with */
2968
    void*        heap;          /* user heap hint */
2969
    union {
2970
        byte*    mem_buf_data;
2971
#ifndef WOLFCRYPT_ONLY
2972
        WOLFSSL* ssl;
2973
        WOLFSSL_EVP_MD_CTX* md_ctx;
2974
#endif
2975
#ifndef NO_FILESYSTEM
2976
        XFILE    fh;
2977
#endif
2978
    } ptr;
2979
    void*        usrCtx;        /* user set pointer */
2980
    char*        ip;            /* IP address for wolfIO_TcpConnect */
2981
    word16       port;          /* Port for wolfIO_TcpConnect */
2982
    char*        infoArg;       /* BIO callback argument */
2983
    wolf_bio_info_cb infoCb;    /* BIO callback */
2984
    int          wrSz;          /* write buffer size (mem) */
2985
    int          wrSzReset;     /* First buffer size (mem) - read ONLY data */
2986
    int          wrIdx;         /* current index for write buffer */
2987
    int          rdIdx;         /* current read index */
2988
    int          readRq;        /* read request */
2989
    union {
2990
        SOCKET_T fd;
2991
        size_t   length;
2992
    } num;
2993
    int          eof;           /* eof flag */
2994
    int          flags;
2995
    int          type;          /* method type */
2996
    byte         init:1;        /* bio has been initialized */
2997
    byte         shutdown:1;    /* close flag */
2998
    byte         connected:1;   /* connected state, for datagram BIOs -- as for
2999
                                 * struct WOLFSSL_DTLS_CTX, when set, sendto and
3000
                                 * recvfrom leave the peer_addr unchanged. */
3001
#ifdef WOLFSSL_HAVE_BIO_ADDR
3002
    union WOLFSSL_BIO_ADDR peer_addr; /* for datagram BIOs, the socket address stored
3003
                                       * with BIO_CTRL_DGRAM_CONNECT,
3004
                                       * BIO_CTRL_DGRAM_SET_CONNECTED, or
3005
                                       * BIO_CTRL_DGRAM_SET_PEER, or stored when a
3006
                                       * packet was received on an unconnected BIO. */
3007
#endif
3008
3009
#if defined(WORD64_AVAILABLE) && !defined(WOLFSSL_BIO_NO_FLOW_STATS)
3010
    #define WOLFSSL_BIO_HAVE_FLOW_STATS
3011
    word64       bytes_read;
3012
    word64       bytes_written;
3013
#endif
3014
3015
#ifdef HAVE_EX_DATA
3016
    WOLFSSL_CRYPTO_EX_DATA ex_data;
3017
#endif
3018
#if defined(OPENSSL_ALL) || defined(OPENSSL_EXTRA)
3019
    wolfSSL_Ref  ref;
3020
#endif
3021
};
3022
#endif /* OPENSSL_EXTRA || OPENSSL_EXTRA_X509_SMALL */
3023
3024
#if defined(WOLFSSL_HAVE_BIO_ADDR) && defined(OPENSSL_EXTRA)
3025
WOLFSSL_LOCAL socklen_t wolfSSL_BIO_ADDR_size(const WOLFSSL_BIO_ADDR *addr);
3026
#endif
3027
3028
#if defined(WOLFSSL_TLS13) && defined(HAVE_NULL_CIPHER) && defined(WOLFSSL_SHA384)
3029
    /* Integrity-only cipher suites use IV size equal to hash output size */
3030
    #define MAX_WRITE_IV_SZ 48
3031
#elif defined(WOLFSSL_TLS13) && defined(HAVE_NULL_CIPHER) && !defined(NO_SHA256)
3032
    /* Integrity-only cipher suites use IV size equal to hash output size */
3033
    #define MAX_WRITE_IV_SZ 32
3034
#else
3035
    #define MAX_WRITE_IV_SZ 16 /* max size of client/server write_IV */
3036
#endif
3037
3038
/* keys and secrets
3039
 * keep as a constant size (no additional ifdefs) for session export */
3040
typedef struct Keys {
3041
#if !defined(WOLFSSL_AEAD_ONLY) || defined(WOLFSSL_TLS13)
3042
    byte client_write_MAC_secret[WC_MAX_DIGEST_SIZE];   /* max sizes */
3043
    byte server_write_MAC_secret[WC_MAX_DIGEST_SIZE];
3044
#endif
3045
    byte client_write_key[MAX_SYM_KEY_SIZE];         /* max sizes */
3046
    byte server_write_key[MAX_SYM_KEY_SIZE];
3047
    byte client_write_IV[MAX_WRITE_IV_SZ];               /* max sizes */
3048
    byte server_write_IV[MAX_WRITE_IV_SZ];
3049
#if defined(HAVE_AEAD) || defined(WOLFSSL_SESSION_EXPORT)
3050
    byte aead_exp_IV[AEAD_MAX_EXP_SZ];
3051
    byte aead_enc_imp_IV[AEAD_MAX_IMP_SZ];
3052
    byte aead_dec_imp_IV[AEAD_MAX_IMP_SZ];
3053
#endif
3054
3055
#ifdef WOLFSSL_DTLS13
3056
    byte client_sn_key[MAX_SYM_KEY_SIZE];
3057
    byte server_sn_key[MAX_SYM_KEY_SIZE];
3058
#endif /* WOLFSSL_DTLS13 */
3059
3060
    word32 peer_sequence_number_hi;
3061
    word32 peer_sequence_number_lo;
3062
    word32 sequence_number_hi;
3063
    word32 sequence_number_lo;
3064
3065
#ifdef WOLFSSL_DTLS
3066
    word16 curEpoch;    /* Received epoch in current record    */
3067
    word16 curSeq_hi;   /* Received sequence in current record */
3068
    word32 curSeq_lo;
3069
3070
#ifdef WOLFSSL_DTLS13
3071
    w64wrapper curEpoch64;    /* Received epoch in current record    */
3072
    w64wrapper curSeq;
3073
#endif /* WOLFSSL_DTLS13 */
3074
3075
#ifdef WOLFSSL_MULTICAST
3076
    byte   curPeerId;   /* Received peer group ID in current record */
3077
#endif
3078
    WOLFSSL_DTLS_PEERSEQ peerSeq[WOLFSSL_DTLS_PEERSEQ_SZ];
3079
3080
    word16 dtls_peer_handshake_number;
3081
    word16 dtls_expected_peer_handshake_number;
3082
3083
    word16 dtls_epoch;                          /* Current epoch    */
3084
    word16 dtls_sequence_number_hi;             /* Current epoch */
3085
    word32 dtls_sequence_number_lo;
3086
    word16 dtls_prev_sequence_number_hi;        /* Previous epoch */
3087
    word32 dtls_prev_sequence_number_lo;
3088
    word16 dtls_handshake_number;               /* Current tx handshake seq */
3089
#endif
3090
3091
    word32 encryptSz;             /* last size of encrypted data   */
3092
    word32 padSz;                 /* how much to advance after decrypt part */
3093
    byte   encryptionOn;          /* true after change cipher spec */
3094
    byte   decryptedCur;          /* only decrypt current record once */
3095
#ifdef WOLFSSL_TLS13
3096
    byte   updateResponseReq;     /* KeyUpdate response from peer required. */
3097
    byte   keyUpdateRespond;      /* KeyUpdate is to be responded to. */
3098
    w64wrapper keyUpdateCount;    /* Sending key updates performed (RFC 9846). */
3099
#endif
3100
#ifdef WOLFSSL_RENESAS_TSIP_TLS
3101
3102
    tsip_hmac_sha_key_index_t tsip_client_write_MAC_secret;
3103
    tsip_hmac_sha_key_index_t tsip_server_write_MAC_secret;
3104
3105
#endif
3106
#ifdef WOLFSSL_RENESAS_FSPSM_TLS
3107
    FSPSM_HMAC_WKEY fspsm_client_write_MAC_secret;
3108
    FSPSM_HMAC_WKEY fspsm_server_write_MAC_secret;
3109
#endif
3110
} Keys;
3111
3112
/* RFC 9846 Section 4.7.3: a TLS 1.3 sender MUST NOT allow its number of key
3113
 * updates to exceed 2^48-1. Receivers MUST NOT enforce this. Expressed as the
3114
 * high and low 32-bit halves of a w64wrapper. */
3115
0
#define TLS13_KEY_UPDATE_MAX_HI32 0x0000FFFFU
3116
0
#define TLS13_KEY_UPDATE_MAX_LO32 0xFFFFFFFFU
3117
3118
/* Forward declare opaque pointer to make available for func def */
3119
typedef struct Options Options;
3120
3121
3122
/** TLS Extensions - RFC 6066 */
3123
#ifdef HAVE_TLS_EXTENSIONS
3124
3125
0
#define TLSXT_SERVER_NAME                0x0000 /* a.k.a. SNI  */
3126
0
#define TLSXT_MAX_FRAGMENT_LENGTH        0x0001
3127
0
#define TLSXT_TRUSTED_CA_KEYS            0x0003
3128
0
#define TLSXT_TRUNCATED_HMAC             0x0004
3129
0
#define TLSXT_STATUS_REQUEST             0x0005 /* a.k.a. OCSP stapling   */
3130
0
#define TLSXT_SUPPORTED_GROUPS           0x000a /* a.k.a. Supported Curves */
3131
0
#define TLSXT_EC_POINT_FORMATS           0x000b
3132
0
#define TLSXT_SIGNATURE_ALGORITHMS       0x000d /* HELLO_EXT_SIG_ALGO */
3133
0
#define TLSXT_USE_SRTP                   0x000e /* 14 */
3134
0
#define TLSXT_APPLICATION_LAYER_PROTOCOL 0x0010 /* a.k.a. ALPN */
3135
0
#define TLSXT_STATUS_REQUEST_V2          0x0011 /* a.k.a. OCSP stapling v2 */
3136
0
#define TLSXT_CLIENT_CERTIFICATE         0x0013 /* RFC8446 */
3137
0
#define TLSXT_SERVER_CERTIFICATE         0x0014 /* RFC8446 */
3138
0
#define TLSXT_ENCRYPT_THEN_MAC           0x0016 /* RFC 7366 */
3139
#define TLSXT_EXTENDED_MASTER_SECRET     0x0017 /* HELLO_EXT_EXTMS */
3140
0
#define TLSXT_CERT_WITH_EXTERN_PSK       0x0021 /* RFC 9973 */
3141
0
#define TLSXT_SESSION_TICKET             0x0023
3142
0
#define TLSXT_PRE_SHARED_KEY             0x0029
3143
0
#define TLSXT_EARLY_DATA                 0x002a
3144
#define TLSXT_SUPPORTED_VERSIONS         0x002b
3145
0
#define TLSXT_COOKIE                     0x002c
3146
0
#define TLSXT_PSK_KEY_EXCHANGE_MODES     0x002d
3147
0
#define TLSXT_CERTIFICATE_AUTHORITIES    0x002f
3148
0
#define TLSXT_POST_HANDSHAKE_AUTH        0x0031
3149
0
#define TLSXT_SIGNATURE_ALGORITHMS_CERT  0x0032
3150
0
#define TLSXT_KEY_SHARE                  0x0033
3151
0
#define TLSXT_CONNECTION_ID              0x0036
3152
#define TLSXT_KEY_QUIC_TP_PARAMS         0x0039 /* RFC 9001, ch. 8.2 */
3153
0
#define TLSXT_ECH                        0xfe0d /* RFC 9849 */
3154
#define TLSXT_ECH_OUTER_EXTENSIONS       0xfd00 /* RFC 9849 */
3155
/* The 0xFF section is experimental/custom/personal use */
3156
#define TLSXT_CKS                        0xff92 /* X9.146 */
3157
0
#define TLSXT_RENEGOTIATION_INFO         0xff01
3158
0
#define TLSXT_KEY_QUIC_TP_PARAMS_DRAFT   0xffa5 /* from */
3159
                                                /* draft-ietf-quic-tls-27 */
3160
3161
typedef enum {
3162
#ifdef HAVE_SNI
3163
    TLSX_SERVER_NAME                = TLSXT_SERVER_NAME,
3164
#endif
3165
    TLSX_MAX_FRAGMENT_LENGTH        = TLSXT_MAX_FRAGMENT_LENGTH,
3166
    TLSX_TRUSTED_CA_KEYS            = TLSXT_TRUSTED_CA_KEYS,
3167
    TLSX_TRUNCATED_HMAC             = TLSXT_TRUNCATED_HMAC,
3168
    TLSX_STATUS_REQUEST             = TLSXT_STATUS_REQUEST,
3169
    TLSX_SUPPORTED_GROUPS           = TLSXT_SUPPORTED_GROUPS,
3170
    TLSX_EC_POINT_FORMATS           = TLSXT_EC_POINT_FORMATS,
3171
#if !defined(NO_CERTS) && !defined(WOLFSSL_NO_SIGALG)
3172
    TLSX_SIGNATURE_ALGORITHMS       = TLSXT_SIGNATURE_ALGORITHMS,
3173
#endif
3174
#ifdef WOLFSSL_SRTP
3175
    TLSX_USE_SRTP                   = TLSXT_USE_SRTP,
3176
#endif
3177
    TLSX_APPLICATION_LAYER_PROTOCOL = TLSXT_APPLICATION_LAYER_PROTOCOL,
3178
    TLSX_STATUS_REQUEST_V2          = TLSXT_STATUS_REQUEST_V2,
3179
#ifdef HAVE_RPK
3180
    TLSX_CLIENT_CERTIFICATE_TYPE    = TLSXT_CLIENT_CERTIFICATE,
3181
    TLSX_SERVER_CERTIFICATE_TYPE    = TLSXT_SERVER_CERTIFICATE,
3182
#endif
3183
#if defined(HAVE_ENCRYPT_THEN_MAC) && !defined(WOLFSSL_AEAD_ONLY)
3184
    TLSX_ENCRYPT_THEN_MAC           = TLSXT_ENCRYPT_THEN_MAC,
3185
#endif
3186
    TLSX_EXTENDED_MASTER_SECRET     = TLSXT_EXTENDED_MASTER_SECRET,
3187
    TLSX_SESSION_TICKET             = TLSXT_SESSION_TICKET,
3188
#ifdef WOLFSSL_TLS13
3189
    #ifdef WOLFSSL_EARLY_DATA
3190
    TLSX_EARLY_DATA                 = TLSXT_EARLY_DATA,
3191
    #endif
3192
    TLSX_SUPPORTED_VERSIONS         = TLSXT_SUPPORTED_VERSIONS,
3193
    TLSX_COOKIE                     = TLSXT_COOKIE,
3194
    #if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
3195
    TLSX_PSK_KEY_EXCHANGE_MODES     = TLSXT_PSK_KEY_EXCHANGE_MODES,
3196
    #if defined(WOLFSSL_CERT_WITH_EXTERN_PSK)
3197
    TLSX_CERT_WITH_EXTERN_PSK       = TLSXT_CERT_WITH_EXTERN_PSK,
3198
    #endif
3199
    #endif
3200
    #if !defined(NO_CERTS) && !defined(WOLFSSL_NO_CA_NAMES)
3201
    TLSX_CERTIFICATE_AUTHORITIES    = TLSXT_CERTIFICATE_AUTHORITIES,
3202
    #endif
3203
    #ifdef WOLFSSL_POST_HANDSHAKE_AUTH
3204
    TLSX_POST_HANDSHAKE_AUTH        = TLSXT_POST_HANDSHAKE_AUTH,
3205
    #endif
3206
    #if !defined(NO_CERTS) && !defined(WOLFSSL_NO_SIGALG)
3207
    TLSX_SIGNATURE_ALGORITHMS_CERT  = TLSXT_SIGNATURE_ALGORITHMS_CERT,
3208
    #endif
3209
    #ifdef WOLFSSL_QUIC
3210
    TLSX_KEY_QUIC_TP_PARAMS         = TLSXT_KEY_QUIC_TP_PARAMS,
3211
    #endif
3212
    #ifdef HAVE_ECH
3213
    TLSX_ECH                        = TLSXT_ECH,
3214
    #endif
3215
#endif
3216
#if defined(WOLFSSL_DTLS_CID)
3217
    TLSX_CONNECTION_ID              = TLSXT_CONNECTION_ID,
3218
#endif /* defined(WOLFSSL_DTLS_CID) */
3219
#if defined(WOLFSSL_TLS13) || !defined(WOLFSSL_NO_TLS12) || !defined(NO_OLD_TLS)
3220
    #if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
3221
    TLSX_PRE_SHARED_KEY             = TLSXT_PRE_SHARED_KEY,
3222
    #endif
3223
    TLSX_KEY_SHARE                  = TLSXT_KEY_SHARE,
3224
#endif
3225
#if defined(WOLFSSL_TLS13) && defined(WOLFSSL_DUAL_ALG_CERTS)
3226
    TLSX_CKS                        = TLSXT_CKS,
3227
#endif
3228
#ifdef WOLFSSL_QUIC
3229
    TLSX_KEY_QUIC_TP_PARAMS_DRAFT   = TLSXT_KEY_QUIC_TP_PARAMS_DRAFT,
3230
#endif
3231
    TLSX_RENEGOTIATION_INFO         = TLSXT_RENEGOTIATION_INFO
3232
} TLSX_Type;
3233
3234
/* TLS Certificate type defined RFC7250
3235
 * https://www.iana.org/assignments/tls-extensiontype-values/tls-extensiontype-values.xhtml#tls-extensiontype-values-3
3236
 */
3237
#if defined(HAVE_RPK)
3238
/* WOLFSSL_MAX_RPK_PINS (default 4) is defined in the public header
3239
 * wolfssl/ssl.h, which this header includes, so applications can see and
3240
 * override it. The pin table is stored inline in RpkConfig (see below),
3241
 * costing WOLFSSL_MAX_RPK_PINS * WC_SHA256_DIGEST_SIZE bytes per WOLFSSL_CTX and
3242
 * WOLFSSL. Out-of-band RPK pinning needs SHA-256 (pins are stored as digests);
3243
 * under NO_SHA256 there is no in-library pinning and trust must be expressed
3244
 * through a verify callback instead. */
3245
3246
typedef struct RpkConfig {
3247
    /* user's preference */
3248
    byte preferred_ClientCertTypeCnt;
3249
    byte preferred_ClientCertTypes[MAX_CLIENT_CERT_TYPE_CNT];
3250
    byte preferred_ServerCertTypeCnt;
3251
    byte preferred_ServerCertTypes[MAX_CLIENT_CERT_TYPE_CNT];
3252
    /* reflect to client_certificate_type extension in xxxHello */
3253
#ifndef NO_SHA256
3254
    /* SHA-256 digests of the DER SubjectPublicKeyInfo(s) the peer is expected
3255
     * to present as a Raw Public Key (RFC 7250), pinned out of band via
3256
     * wolfSSL_set_expected_rpk()/wolfSSL_CTX_set_expected_rpk(). A received RPK
3257
     * whose SPKI digest matches one of these is treated as authenticated.
3258
     * Stored inline (not a pointer) so the by-value RpkConfig copy from CTX to
3259
     * SSL needs no deep-copy or free handling. */
3260
    byte expectedRpkCnt;
3261
    byte expectedRpk[WOLFSSL_MAX_RPK_PINS][WC_SHA256_DIGEST_SIZE];
3262
#endif /* !NO_SHA256 */
3263
} RpkConfig;
3264
3265
typedef struct RpkState {
3266
    byte sending_ClientCertTypeCnt;
3267
    byte sending_ClientCertTypes[MAX_CLIENT_CERT_TYPE_CNT];
3268
    /* reflect to server_certificate_type extension in xxxHello */
3269
    byte sending_ServerCertTypeCnt;
3270
    byte sending_ServerCertTypes[MAX_SERVER_CERT_TYPE_CNT];
3271
    /* client_certificate_type extension in received yyyHello  */
3272
    byte received_ClientCertTypeCnt;
3273
    byte received_ClientCertTypes[MAX_CLIENT_CERT_TYPE_CNT];
3274
    /* server_certificate_type extension in received yyyHello  */
3275
    byte received_ServerCertTypeCnt;
3276
    byte received_ServerCertTypes[MAX_SERVER_CERT_TYPE_CNT];
3277
    /* set if Raw-public-key cert is loaded as own certificate */
3278
    int  isRPKLoaded;
3279
} RpkState;
3280
#endif /* HAVE_RPK */
3281
3282
#if defined(WOLFSSL_TLS13) && defined(HAVE_ECH)
3283
#define ECH_ACCEPT_CONFIRMATION_SZ 8
3284
#define ECH_PADDING_TO_32(length) (31 - (((length) - 1) % 32))
3285
3286
typedef enum {
3287
    ECH_TYPE_OUTER = 0,
3288
    ECH_TYPE_INNER = 1
3289
} EchType;
3290
3291
typedef enum {
3292
    ECH_WRITE_GREASE,
3293
    ECH_WRITE_REAL,
3294
    ECH_WRITE_RETRY_CONFIGS,
3295
    ECH_WRITE_NONE,
3296
    ECH_PARSED_INTERNAL,
3297
} EchState;
3298
3299
typedef struct EchCipherSuite {
3300
    word16 kdfId;
3301
    word16 aeadId;
3302
} EchCipherSuite;
3303
3304
typedef struct WOLFSSL_EchConfig {
3305
    byte* raw;
3306
    char* publicName;
3307
    void* receiverPrivkey;
3308
    struct WOLFSSL_EchConfig* next;
3309
    EchCipherSuite* cipherSuites;
3310
    word32 rawLen;
3311
    word16 kemId;
3312
    byte configId;
3313
    byte numCipherSuites;
3314
    byte receiverPubkey[HPKE_Npk_MAX];
3315
    byte maxNameLen;
3316
} WOLFSSL_EchConfig;
3317
3318
typedef struct WOLFSSL_ECH {
3319
    Hpke* hpke;
3320
    HpkeBaseContext* hpkeContext;
3321
    const byte* aad;
3322
    void* ephemeralKey;
3323
    WOLFSSL_EchConfig* echConfig;
3324
    byte* innerClientHello;
3325
    byte* outerClientPayload;
3326
    /* the 'public' extensions (i.e., the public SNI would be stored here) */
3327
    TLSX* extensions;
3328
    byte* confBuf;
3329
    EchCipherSuite cipherSuite;
3330
    word32 aadLen;
3331
    word32 innerClientHelloLen;
3332
    word16 paddingLen;
3333
    word16 kemId;
3334
    word16 encLen;
3335
    EchState state;
3336
    byte type;
3337
    byte configId;
3338
    byte enc[HPKE_Npk_MAX];
3339
    byte innerCount;
3340
    byte writeEncoded;
3341
} WOLFSSL_ECH;
3342
3343
WOLFSSL_LOCAL int EchConfigGetSupportedCipherSuite(WOLFSSL_EchConfig* config);
3344
3345
WOLFSSL_LOCAL int TLSX_FinalizeEch(WOLFSSL* ssl, WOLFSSL_ECH* ech, byte* aad,
3346
    word32 aadLen);
3347
3348
WOLFSSL_LOCAL int TLSX_EchReplaceExtensions(WOLFSSL* ssl, byte accepted);
3349
3350
#ifdef WOLFSSL_API_PREFIX_MAP
3351
    #define TLSX_EchSwapExtensions wolfSSL_TLSX_EchSwapExtensions
3352
#endif
3353
WOLFSSL_TEST_VIS int TLSX_EchSwapExtensions(TLSX** sslExts, TLSX** echExts,
3354
    word16* appended);
3355
3356
#ifdef WOLFSSL_API_PREFIX_MAP
3357
    #define TLSX_ServerECH_Use wolfSSL_TLSX_ServerECH_Use
3358
#endif
3359
WOLFSSL_TEST_VIS int TLSX_ServerECH_Use(TLSX** extensions, void* heap,
3360
    WOLFSSL_EchConfig* configs);
3361
3362
WOLFSSL_LOCAL int SetEchConfigsEx(WOLFSSL_EchConfig** outputConfigs, void* heap,
3363
    const byte* echConfigs, word32 echConfigsLen);
3364
3365
WOLFSSL_LOCAL int GetEchConfig(WOLFSSL_EchConfig* config, byte* output,
3366
    word32* outputLen);
3367
3368
WOLFSSL_LOCAL int GetEchConfigsEx(WOLFSSL_EchConfig* configs,
3369
    byte* output, word32* outputLen);
3370
3371
WOLFSSL_LOCAL void FreeEchConfigs(WOLFSSL_EchConfig* configs, void* heap);
3372
3373
WOLFSSL_LOCAL int SetRetryConfigs(WOLFSSL* ssl, const byte* echConfigs,
3374
    word32 echConfigsLen);
3375
#endif
3376
3377
struct TLSX {
3378
    TLSX_Type    type; /* Extension Type  */
3379
    void*        data; /* Extension Data  */
3380
    word32       val;  /* Extension Value */
3381
    byte         resp; /* IsResponse Flag */
3382
    struct TLSX* next; /* List Behavior   */
3383
};
3384
3385
#if defined(HAVE_TLS_EXTENSIONS) && defined(OPENSSL_EXTRA)
3386
/* OpenSSL-compatible custom (application-defined) TLS extension.
3387
 * Registered on a WOLFSSL_CTX via wolfSSL_CTX_add_client_custom_ext(). These
3388
 * extensions are not part of the TLSX framework but are processed in parallel
3389
 * for unknown extension types. Currently the client side for TLS 1.2 and below
3390
 * is supported, mirroring SSL_CTX_add_client_custom_ext(). */
3391
typedef struct WOLFSSL_CustomExt {
3392
    word16                      ext_type;  /* extension type on the wire     */
3393
    wolfSSL_custom_ext_add_cb   add_cb;    /* build outgoing extension data  */
3394
    wolfSSL_custom_ext_free_cb  free_cb;   /* free data produced by add_cb   */
3395
    wolfSSL_custom_ext_parse_cb parse_cb;  /* parse incoming extension data  */
3396
    void*                       add_arg;   /* opaque arg for add_cb/free_cb  */
3397
    void*                       parse_arg; /* opaque arg for parse_cb        */
3398
    struct WOLFSSL_CustomExt*   next;      /* list behaviour                 */
3399
} WOLFSSL_CustomExt;
3400
3401
WOLFSSL_LOCAL void TLSX_CustomExt_FreeAll(WOLFSSL_CustomExt* list, void* heap);
3402
#ifdef WOLFSSL_API_PREFIX_MAP
3403
    #define TLSX_CustomExt_BuildRequest wolfSSL_TLSX_CustomExt_BuildRequest
3404
#endif
3405
WOLFSSL_TEST_VIS int TLSX_CustomExt_BuildRequest(WOLFSSL* ssl, word16* pSz);
3406
WOLFSSL_LOCAL int  TLSX_CustomExt_Parse(WOLFSSL* ssl, byte msgType, word16 type,
3407
        const byte* input, word16 size, int* found);
3408
#endif /* HAVE_TLS_EXTENSIONS && OPENSSL_EXTRA */
3409
3410
#ifdef WOLFSSL_API_PREFIX_MAP
3411
    #define TLSX_Find wolfSSL_TLSX_Find
3412
#endif
3413
WOLFSSL_TEST_VIS TLSX* TLSX_Find(TLSX* list, TLSX_Type type);
3414
WOLFSSL_LOCAL void  TLSX_Remove(TLSX** list, TLSX_Type type, void* heap);
3415
WOLFSSL_LOCAL void  TLSX_FreeAll(TLSX* list, void* heap);
3416
WOLFSSL_LOCAL int   TLSX_SupportExtensions(WOLFSSL* ssl);
3417
WOLFSSL_LOCAL int   TLSX_PopulateExtensions(WOLFSSL* ssl, byte isRequest);
3418
3419
#if defined(WOLFSSL_TLS13) || !defined(NO_WOLFSSL_CLIENT)
3420
#ifdef WOLFSSL_API_PREFIX_MAP
3421
    #define TLSX_GetRequestSize wolfSSL_TLSX_GetRequestSize
3422
    #define TLSX_WriteRequest   wolfSSL_TLSX_WriteRequest
3423
#endif
3424
WOLFSSL_TEST_VIS int   TLSX_GetRequestSize(WOLFSSL* ssl, byte msgType,
3425
                                         word32* pLength);
3426
WOLFSSL_TEST_VIS int   TLSX_WriteRequest(WOLFSSL* ssl, byte* output,
3427
                                       byte msgType, word32* pOffset);
3428
#endif
3429
3430
#if defined(WOLFSSL_TLS13) || !defined(NO_WOLFSSL_SERVER)
3431
/* TLS 1.3 Certificate messages have extensions. */
3432
WOLFSSL_LOCAL int   TLSX_GetResponseSize(WOLFSSL* ssl, byte msgType,
3433
                                          word16* pLength);
3434
WOLFSSL_LOCAL int   TLSX_WriteResponse(WOLFSSL *ssl, byte* output, byte msgType,
3435
                                        word16* pOffset);
3436
#endif
3437
3438
WOLFSSL_LOCAL int   TLSX_ParseVersion(WOLFSSL* ssl, const byte* input,
3439
                                      word16 length, byte msgType, int* found);
3440
WOLFSSL_LOCAL int TLSX_SupportedVersions_Parse(const WOLFSSL* ssl,
3441
        const byte* input, word16 length, byte msgType, ProtocolVersion* pv,
3442
        Options* opts, TLSX** exts);
3443
#ifdef WOLFSSL_API_PREFIX_MAP
3444
    #define TLSX_Parse wolfSSL_TLSX_Parse
3445
#endif
3446
WOLFSSL_TEST_VIS int TLSX_Parse(WOLFSSL* ssl, const byte* input, word16 length,
3447
                               byte msgType, Suites *suites);
3448
WOLFSSL_LOCAL int TLSX_Push(TLSX** list, TLSX_Type type,
3449
                            const void* data, void* heap);
3450
WOLFSSL_LOCAL int TLSX_Append(TLSX** list, TLSX_Type type,
3451
                            const void* data, void* heap);
3452
3453
#elif defined(HAVE_SNI)                           \
3454
   || defined(HAVE_MAX_FRAGMENT)                  \
3455
   || defined(HAVE_TRUSTED_CA)                    \
3456
   || defined(HAVE_TRUNCATED_HMAC)                \
3457
   || defined(HAVE_CERTIFICATE_STATUS_REQUEST)    \
3458
   || defined(HAVE_CERTIFICATE_STATUS_REQUEST_V2) \
3459
   || defined(HAVE_SUPPORTED_CURVES)              \
3460
   || defined(HAVE_ALPN)                          \
3461
   || defined(HAVE_SESSION_TICKET)                \
3462
   || defined(HAVE_SECURE_RENEGOTIATION)          \
3463
   || defined(HAVE_SERVER_RENEGOTIATION_INFO)
3464
3465
#ifndef NO_TLS
3466
#error Using TLS extensions requires HAVE_TLS_EXTENSIONS to be defined.
3467
#endif
3468
#endif /* HAVE_TLS_EXTENSIONS */
3469
3470
/** Server Name Indication - RFC 6066 (session 3) */
3471
#ifdef HAVE_SNI
3472
3473
typedef struct SNI {
3474
    byte                       type;    /* SNI Type         */
3475
    union { char* host_name; } data;    /* SNI Data         */
3476
    struct SNI*                next;    /* List Behavior    */
3477
    byte                       status;  /* Matching result  */
3478
#ifndef NO_WOLFSSL_SERVER
3479
    byte                       options; /* Behavior options */
3480
#endif
3481
} SNI;
3482
3483
WOLFSSL_LOCAL int TLSX_UseSNI(TLSX** extensions, byte type, const void* data,
3484
                                                       word16 size, void* heap);
3485
WOLFSSL_LOCAL byte TLSX_SNI_Status(TLSX* extensions, byte type);
3486
#ifdef WOLFSSL_API_PREFIX_MAP
3487
    #define TLSX_SNI_GetRequest wolfSSL_TLSX_SNI_GetRequest
3488
#endif
3489
WOLFSSL_TEST_VIS word16 TLSX_SNI_GetRequest(TLSX* extensions, byte type,
3490
                                                void** data, byte ignoreStatus);
3491
#ifdef WOLFSSL_API_PREFIX_MAP
3492
    #define TLSX_SNI_GetSize wolfSSL_TLSX_SNI_GetSize
3493
#endif
3494
WOLFSSL_TEST_VIS word16 TLSX_SNI_GetSize(SNI* list);
3495
3496
#ifndef NO_WOLFSSL_SERVER
3497
WOLFSSL_LOCAL void   TLSX_SNI_SetOptions(TLSX* extensions, byte type,
3498
                                                                  byte options);
3499
WOLFSSL_LOCAL int    TLSX_SNI_GetFromBuffer(const byte* clientHello,
3500
                         word32 helloSz, byte type, byte* sni, word32* inOutSz);
3501
#endif
3502
3503
#endif /* HAVE_SNI */
3504
3505
/* Trusted CA Key Indication - RFC 6066 (section 6) */
3506
#ifdef HAVE_TRUSTED_CA
3507
3508
typedef struct TCA {
3509
    byte                       type;    /* TCA Type            */
3510
    byte*                      id;      /* TCA identifier      */
3511
    word16                     idSz;    /* TCA identifier size */
3512
    struct TCA*                next;    /* List Behavior       */
3513
} TCA;
3514
3515
WOLFSSL_LOCAL int TLSX_UseTrustedCA(TLSX** extensions, byte type,
3516
                    const byte* id, word16 idSz, void* heap);
3517
3518
#endif /* HAVE_TRUSTED_CA */
3519
3520
/* Application-Layer Protocol Negotiation - RFC 7301 */
3521
#ifdef HAVE_ALPN
3522
typedef struct ALPN {
3523
    char*        protocol_name; /* ALPN protocol name */
3524
    struct ALPN* next;          /* List Behavior      */
3525
    byte         options;       /* Behavior options */
3526
    byte         negotiated;    /* ALPN protocol negotiated or not */
3527
} ALPN;
3528
3529
WOLFSSL_LOCAL int TLSX_ALPN_GetRequest(TLSX* extensions,
3530
                                       void** data, word16 *dataSz);
3531
3532
WOLFSSL_LOCAL int TLSX_UseALPN(TLSX** extensions, const void* data,
3533
                               word16 size, byte options, void* heap);
3534
3535
WOLFSSL_LOCAL int TLSX_ALPN_SetOptions(TLSX** extensions, byte option);
3536
3537
#endif /* HAVE_ALPN */
3538
3539
/** Maximum Fragment Length Negotiation - RFC 6066 (session 4) */
3540
#ifdef HAVE_MAX_FRAGMENT
3541
3542
WOLFSSL_LOCAL int TLSX_UseMaxFragment(TLSX** extensions, byte mfl, void* heap);
3543
3544
#endif /* HAVE_MAX_FRAGMENT */
3545
3546
/** Truncated HMAC - RFC 6066 (session 7) */
3547
#ifdef HAVE_TRUNCATED_HMAC
3548
3549
WOLFSSL_LOCAL int TLSX_UseTruncatedHMAC(TLSX** extensions, void* heap);
3550
3551
#endif /* HAVE_TRUNCATED_HMAC */
3552
3553
/** Certificate Status Request - RFC 6066 (session 8) */
3554
#ifdef HAVE_CERTIFICATE_STATUS_REQUEST
3555
3556
typedef struct {
3557
    byte status_type;
3558
    byte options;
3559
    WOLFSSL* ssl;
3560
    union {
3561
        OcspRequest ocsp[MAX_CERT_EXTENSIONS];
3562
    } request;
3563
    word16 requests;
3564
#ifdef WOLFSSL_TLS13
3565
    buffer responses[MAX_CERT_EXTENSIONS];
3566
#endif
3567
} CertificateStatusRequest;
3568
3569
WOLFSSL_LOCAL int   TLSX_UseCertificateStatusRequest(TLSX** extensions,
3570
           byte status_type, byte options, WOLFSSL* ssl, void* heap, int devId);
3571
#ifndef NO_CERTS
3572
WOLFSSL_LOCAL int   TLSX_CSR_InitRequest(TLSX* extensions, DecodedCert* cert,
3573
                                                                    void* heap);
3574
WOLFSSL_LOCAL int   TLSX_CSR_InitRequest_ex(TLSX* extensions, DecodedCert* cert,
3575
                                            void* heap, int idx);
3576
#endif
3577
WOLFSSL_LOCAL void* TLSX_CSR_GetRequest(TLSX* extensions);
3578
WOLFSSL_LOCAL int   TLSX_CSR_ForceRequest(WOLFSSL* ssl);
3579
WOLFSSL_LOCAL word16 TLSX_CSR_GetSize_ex(CertificateStatusRequest* csr,
3580
                                        byte isRequest,
3581
                                        int idx);
3582
WOLFSSL_LOCAL int TLSX_CSR_Write_ex(CertificateStatusRequest* csr, byte* output,
3583
                          byte isRequest, int idx);
3584
WOLFSSL_LOCAL void* TLSX_CSR_GetRequest_ex(TLSX* extensions, int idx);
3585
3586
WOLFSSL_LOCAL int TLSX_CSR_SetResponseWithStatusCB(WOLFSSL *ssl);
3587
WOLFSSL_LOCAL int ProcessChainOCSPRequest(WOLFSSL* ssl);
3588
3589
#endif
3590
#if defined(HAVE_CERTIFICATE_STATUS_REQUEST) || \
3591
    defined(HAVE_CERTIFICATE_STATUS_REQUEST_V2)
3592
WOLFSSL_LOCAL int CreateOcspRequest(WOLFSSL* ssl, OcspRequest* request,
3593
                             DecodedCert* cert, byte* certData, word32 length);
3594
#endif
3595
/** Certificate Status Request v2 - RFC 6961 */
3596
#ifdef HAVE_CERTIFICATE_STATUS_REQUEST_V2
3597
3598
typedef struct CSRIv2 {
3599
    byte status_type;
3600
    byte options;
3601
    word16 requests;
3602
    union {
3603
        OcspRequest ocsp[1 + MAX_CHAIN_DEPTH];
3604
    } request;
3605
    struct CSRIv2* next;
3606
    Signer *pendingSigners;
3607
} CertificateStatusRequestItemV2;
3608
3609
WOLFSSL_LOCAL int   TLSX_UseCertificateStatusRequestV2(TLSX** extensions,
3610
                         byte status_type, byte options, void* heap, int devId);
3611
#ifndef NO_CERTS
3612
WOLFSSL_LOCAL int TLSX_CSR2_IsMulti(TLSX *extensions);
3613
WOLFSSL_LOCAL int TLSX_CSR2_AddPendingSigner(TLSX *extensions, Signer *s);
3614
WOLFSSL_LOCAL Signer* TLSX_CSR2_GetPendingSigners(TLSX *extensions);
3615
WOLFSSL_LOCAL int TLSX_CSR2_ClearPendingCA(WOLFSSL *ssl);
3616
WOLFSSL_LOCAL int TLSX_CSR2_MergePendingCA(WOLFSSL* ssl);
3617
WOLFSSL_LOCAL int   TLSX_CSR2_InitRequests(TLSX* extensions, DecodedCert* cert,
3618
                                                       byte isPeer, void* heap);
3619
#endif
3620
WOLFSSL_LOCAL void* TLSX_CSR2_GetRequest(TLSX* extensions, byte status_type,
3621
                                                                    byte idx);
3622
WOLFSSL_LOCAL int   TLSX_CSR2_ForceRequest(WOLFSSL* ssl);
3623
3624
#endif
3625
3626
#if defined(WOLFSSL_PUBLIC_ASN) && defined(HAVE_PK_CALLBACKS)
3627
/* Internal callback guarded by WOLFSSL_TEST_VIS because of DecodedCert. */
3628
typedef int (*CallbackProcessPeerCert)(WOLFSSL* ssl, DecodedCert* p_cert);
3629
WOLFSSL_TEST_VIS void wolfSSL_CTX_SetProcessPeerCertCb(WOLFSSL_CTX* ctx,
3630
       CallbackProcessPeerCert cb);
3631
#endif /* DecodedCert && HAVE_PK_CALLBACKS */
3632
3633
#if !defined(NO_CERTS) && !defined(WOLFSSL_NO_SIGALG)
3634
typedef struct SignatureAlgorithms {
3635
    /* Not const since it is modified in TLSX_SignatureAlgorithms_MapPss */
3636
    WOLFSSL*    ssl;
3637
    word16      hashSigAlgoSz; /* SigAlgo extension length in bytes */
3638
    /* Ignore "nonstandard extension used : zero-sized array in struct/union"
3639
     * MSVC warning */
3640
    #ifdef _MSC_VER
3641
    #pragma warning(disable: 4200)
3642
    #endif
3643
    /* sig/algo to offer */
3644
    byte        hashSigAlgo[WC_FLEXIBLE_ARRAY_SIZE];
3645
} SignatureAlgorithms;
3646
3647
WOLFSSL_LOCAL SignatureAlgorithms* TLSX_SignatureAlgorithms_New(
3648
        WOLFSSL* ssl, word16 hashSigAlgoSz, void* heap);
3649
WOLFSSL_LOCAL void TLSX_SignatureAlgorithms_FreeAll(SignatureAlgorithms* sa,
3650
                                                    void* heap);
3651
#endif
3652
3653
/** Supported Elliptic Curves - RFC 4492 (session 4) */
3654
#ifdef HAVE_SUPPORTED_CURVES
3655
3656
typedef struct SupportedCurve {
3657
    word16 name;                 /* Curve Names */
3658
    struct SupportedCurve* next; /* List Behavior */
3659
} SupportedCurve;
3660
3661
typedef struct PointFormat {
3662
    byte format;                /* PointFormat */
3663
    struct PointFormat* next;   /* List Behavior */
3664
} PointFormat;
3665
3666
WOLFSSL_LOCAL int TLSX_SupportedCurve_Copy(TLSX* src, TLSX** dst, void* heap);
3667
WOLFSSL_LOCAL int TLSX_UseSupportedCurve(TLSX** extensions, word16 name,
3668
                                                          void* heap, int side);
3669
3670
#ifdef WOLFSSL_API_PREFIX_MAP
3671
    #define TLSX_UsePointFormat wolfSSL_TLSX_UsePointFormat
3672
#endif
3673
/* WOLFSSL_TEST_VIS so the API tests can seed a client's ec_point_formats
3674
 * extension (the point-format negotiation has no public API). */
3675
WOLFSSL_TEST_VIS int TLSX_UsePointFormat(TLSX** extensions, byte point,
3676
                                                                    void* heap);
3677
WOLFSSL_LOCAL int TLSX_IsGroupSupported(int namedGroup, int side);
3678
3679
#ifndef NO_WOLFSSL_SERVER
3680
WOLFSSL_LOCAL int TLSX_ValidateSupportedCurves(const WOLFSSL* ssl, byte first,
3681
                                               byte second, word32* ecdhCurveOID);
3682
WOLFSSL_LOCAL int TLSX_SupportedCurve_CheckPriority(WOLFSSL* ssl);
3683
WOLFSSL_LOCAL int TLSX_SupportedFFDHE_Set(WOLFSSL* ssl);
3684
#endif
3685
WOLFSSL_LOCAL int TLSX_SupportedCurve_IsSupported(WOLFSSL* ssl, word16 name);
3686
WOLFSSL_LOCAL int TLSX_SupportedCurve_Preferred(WOLFSSL* ssl,
3687
                                                            int checkSupported);
3688
WOLFSSL_LOCAL int TLSX_SupportedCurve_Parse(const WOLFSSL* ssl,
3689
        const byte* input, word16 length, byte isRequest, TLSX** extensions);
3690
3691
#endif /* HAVE_SUPPORTED_CURVES */
3692
3693
/** Renegotiation Indication - RFC 5746 */
3694
#if defined(HAVE_SECURE_RENEGOTIATION) \
3695
 || defined(HAVE_SERVER_RENEGOTIATION_INFO)
3696
3697
enum key_cache_state {
3698
    SCR_CACHE_NULL   = 0,       /* empty / begin state */
3699
    SCR_CACHE_NEEDED,           /* need to cache keys */
3700
    SCR_CACHE_COPY,             /* we have a cached copy */
3701
    SCR_CACHE_PARTIAL,          /* partial restore to real keys */
3702
    SCR_CACHE_COMPLETE          /* complete restore to real keys */
3703
};
3704
3705
/* Additional Connection State according to rfc5746 section 3.1 */
3706
typedef struct SecureRenegotiation {
3707
   /* Single-bit flags grouped together so they pack into one storage unit. */
3708
   WC_BITFIELD          enabled:1;  /* secure_renegotiation flag in rfc */
3709
   WC_BITFIELD          verifySet:1;
3710
   WC_BITFIELD          startScr:1; /* server requested client to start scr */
3711
   WC_BITFIELD          renegInfoSeen:1; /* renegotiation_info ext seen this
3712
                                          * handshake (RFC 5746 3.7) */
3713
   WC_BITFIELD          subject_hash_set:1; /* if peer cert hash is set */
3714
#ifdef HAVE_SECURE_RENEGOTIATION
3715
   WC_BITFIELD          advertiseOnly:1; /* extension advertised for the RFC
3716
                                          * 5746 initial-handshake check only;
3717
                                          * refuse peer-initiated renegotiation */
3718
#endif
3719
   enum key_cache_state cache_status;  /* track key cache state */
3720
   byte                 client_verify_data[TLS_FINISHED_SZ];  /* cached */
3721
   byte                 server_verify_data[TLS_FINISHED_SZ];  /* cached */
3722
   byte                 subject_hash[KEYID_SIZE];  /* peer cert hash */
3723
   Keys                 tmp_keys;  /* can't overwrite real keys yet */
3724
} SecureRenegotiation;
3725
3726
WOLFSSL_LOCAL int TLSX_UseSecureRenegotiation(TLSX** extensions, void* heap);
3727
3728
#ifdef HAVE_SERVER_RENEGOTIATION_INFO
3729
WOLFSSL_LOCAL int TLSX_AddEmptyRenegotiationInfo(TLSX** extensions, void* heap);
3730
#endif
3731
3732
WOLFSSL_LOCAL int SetupClientSecureRenegotiation(WOLFSSL* ssl);
3733
3734
#endif /* HAVE_SECURE_RENEGOTIATION */
3735
3736
#ifdef HAVE_SESSION_TICKET
3737
/* Max peer cert size for ticket: 2KB is reasonable for most RSA/ECC certs */
3738
#ifndef MAX_TICKET_PEER_CERT_SZ
3739
#define MAX_TICKET_PEER_CERT_SZ 2048
3740
#endif
3741
#if defined(HAVE_SNI) || defined(HAVE_ALPN)
3742
/* Hash algorithm used for SNI/ALPN binding in session tickets.
3743
 * Pick the best available at compile time. */
3744
#ifndef TICKET_BINDING_HASH_TYPE
3745
    #if !defined(NO_SHA256)
3746
        #define TICKET_BINDING_HASH_TYPE WC_HASH_TYPE_SHA256
3747
        #define TICKET_BINDING_HASH_SZ   WC_SHA256_DIGEST_SIZE
3748
    #elif defined(WOLFSSL_SHA384)
3749
        #define TICKET_BINDING_HASH_TYPE WC_HASH_TYPE_SHA384
3750
        #define TICKET_BINDING_HASH_SZ   WC_SHA384_DIGEST_SIZE
3751
    #elif !defined(NO_SHA)
3752
        #define TICKET_BINDING_HASH_TYPE WC_HASH_TYPE_SHA
3753
        #define TICKET_BINDING_HASH_SZ   WC_SHA_DIGEST_SIZE
3754
    #else
3755
        #error "No hash algorithm available for ticket binding"
3756
    #endif
3757
#endif
3758
#endif
3759
3760
/* Our ticket format. All members need to be a byte or array of byte to
3761
 * avoid alignment issues */
3762
typedef struct InternalTicket {
3763
    ProtocolVersion pv;                    /* version when ticket created */
3764
    byte            suite[SUITE_LEN];      /* cipher suite when created */
3765
    byte            msecret[SECRET_LEN];   /* master secret */
3766
    byte            timestamp[TIMESTAMP_LEN];          /* born on */
3767
    byte            haveEMS;               /* have extended master secret */
3768
#ifdef WOLFSSL_TLS13
3769
    byte            ageAdd[AGEADD_LEN];    /* Obfuscation of age */
3770
    byte            namedGroup[NAMEDGROUP_LEN]; /* Named group used */
3771
    byte            ticketNonceLen;
3772
    byte            ticketNonce[MAX_TICKET_NONCE_STATIC_SZ];
3773
#ifdef WOLFSSL_EARLY_DATA
3774
    byte            maxEarlyDataSz[MAXEARLYDATASZ_LEN]; /* Max size of
3775
                                                         * early data */
3776
#endif
3777
#endif
3778
#ifdef WOLFSSL_TICKET_HAVE_ID
3779
    byte            id[ID_LEN];
3780
#endif
3781
#ifdef HAVE_SNI
3782
    byte            sniHash[TICKET_BINDING_HASH_SZ]; /* digest of server name
3783
                                                      * at ticket issue */
3784
#endif
3785
#ifdef HAVE_ALPN
3786
    byte            alpnHash[TICKET_BINDING_HASH_SZ]; /* digest of negotiated
3787
                                                       * ALPN at issue */
3788
#endif
3789
#ifdef OPENSSL_EXTRA
3790
    byte            sessionCtxSz;          /* sessionCtx length        */
3791
    byte            sessionCtx[ID_LEN];    /* app specific context id */
3792
#endif /* OPENSSL_EXTRA */
3793
#if defined(OPENSSL_ALL) && defined(KEEP_PEER_CERT) && \
3794
    !defined(NO_CERT_IN_TICKET)
3795
    byte            peerCertLen[OPAQUE16_LEN]; /* peer cert length */
3796
    byte            peerCert[]; /* peer certificate DER - variable length */
3797
#endif
3798
} InternalTicket;
3799
3800
/* Base size of InternalTicket without the variable-length peerCert field */
3801
#define WOLFSSL_INTERNAL_TICKET_BASE_SZ  (sizeof(InternalTicket))
3802
3803
/* Minimum internal ticket length (no peer cert) */
3804
#ifndef WOLFSSL_TICKET_ENC_CBC_HMAC
3805
    #define WOLFSSL_INTERNAL_TICKET_LEN     WOLFSSL_INTERNAL_TICKET_BASE_SZ
3806
#else
3807
    #define WOLFSSL_INTERNAL_TICKET_LEN     \
3808
        (((WOLFSSL_INTERNAL_TICKET_BASE_SZ + 15) / 16) * 16)
3809
#endif
3810
3811
/* Maximum internal ticket length (with max peer cert) */
3812
#if defined(OPENSSL_ALL) && defined(KEEP_PEER_CERT) && \
3813
    !defined(NO_CERT_IN_TICKET)
3814
    #define WOLFSSL_INTERNAL_TICKET_MAX_SZ  \
3815
        (WOLFSSL_INTERNAL_TICKET_BASE_SZ + MAX_TICKET_PEER_CERT_SZ)
3816
#else
3817
    #define WOLFSSL_INTERNAL_TICKET_MAX_SZ  WOLFSSL_INTERNAL_TICKET_BASE_SZ
3818
#endif
3819
3820
#ifndef WOLFSSL_TICKET_EXTRA_PADDING_SZ
3821
#define WOLFSSL_TICKET_EXTRA_PADDING_SZ 32
3822
#endif
3823
3824
/* Maximum encrypted ticket size */
3825
#define WOLFSSL_TICKET_ENC_SZ \
3826
    (WOLFSSL_INTERNAL_TICKET_MAX_SZ + WOLFSSL_TICKET_EXTRA_PADDING_SZ)
3827
3828
/* RFC 5077 defines this for session tickets. All members need to be a byte or
3829
 * array of byte to avoid alignment issues */
3830
typedef struct ExternalTicket {
3831
    byte key_name[WOLFSSL_TICKET_NAME_SZ];     /* key context name - 16 */
3832
    byte iv[WOLFSSL_TICKET_IV_SZ];             /* this ticket's iv - 16 */
3833
    byte enc_len[OPAQUE16_LEN];                /* encrypted length - 2 */
3834
    byte enc_ticket[WC_FLEXIBLE_ARRAY_SIZE];   /* encrypted ticket - var length
3835
                                                * + total mac - 32 */
3836
} ExternalTicket;
3837
3838
/* Fixed portion of external ticket (key_name + iv + enc_len) */
3839
#define WOLFSSL_TICKET_FIXED_SZ  \
3840
    (WOLFSSL_TICKET_NAME_SZ + WOLFSSL_TICKET_IV_SZ + OPAQUE16_LEN + \
3841
        WOLFSSL_TICKET_MAC_SZ)
3842
3843
/* Maximum session ticket length */
3844
#define SESSION_TICKET_LEN  \
3845
    ((int)(WOLFSSL_TICKET_FIXED_SZ + WOLFSSL_TICKET_ENC_SZ))
3846
3847
typedef struct SessionTicket {
3848
    word32 lifetime;
3849
#ifdef WOLFSSL_TLS13
3850
    word64 seen;
3851
    word32 ageAdd;
3852
#endif
3853
    byte*  data;
3854
    word16 size;
3855
} SessionTicket;
3856
3857
#if !defined(WOLFSSL_NO_DEF_TICKET_ENC_CB) && !defined(NO_WOLFSSL_SERVER)
3858
3859
/* Data passed to default SessionTicket enc/dec callback. */
3860
typedef struct TicketEncCbCtx {
3861
    /* Name for this context. */
3862
    byte name[WOLFSSL_TICKET_NAME_SZ];
3863
    /* Current keys - current and next. */
3864
    byte key[2][WOLFSSL_TICKET_KEY_SZ];
3865
    /* Expirary date of keys. */
3866
    word32 expirary[2];
3867
    /* Random number generator to use for generating name, keys and IV. */
3868
    WC_RNG rng;
3869
#ifndef SINGLE_THREADED
3870
    /* Mutex for access to changing keys. */
3871
    wolfSSL_Mutex mutex;
3872
#endif
3873
    /* Pointer back to SSL_CTX. */
3874
    WOLFSSL_CTX* ctx;
3875
} TicketEncCbCtx;
3876
3877
#endif /* !WOLFSSL_NO_DEF_TICKET_ENC_CB && !NO_WOLFSSL_SERVER */
3878
3879
#ifdef WOLFSSL_API_PREFIX_MAP
3880
    #define TLSX_UseSessionTicket     wolfSSL_TLSX_UseSessionTicket
3881
    #define TLSX_SessionTicket_Create wolfSSL_TLSX_SessionTicket_Create
3882
    #define TLSX_SessionTicket_Free   wolfSSL_TLSX_SessionTicket_Free
3883
#endif
3884
WOLFSSL_TEST_VIS int  TLSX_UseSessionTicket(TLSX** extensions,
3885
                                             SessionTicket* ticket, void* heap);
3886
WOLFSSL_TEST_VIS SessionTicket* TLSX_SessionTicket_Create(word32 lifetime,
3887
                                           byte* data, word16 size, void* heap);
3888
WOLFSSL_TEST_VIS void TLSX_SessionTicket_Free(SessionTicket* ticket, void* heap);
3889
3890
#endif /* HAVE_SESSION_TICKET */
3891
3892
#ifndef MAX_PSK_ID_LEN
3893
    /* max psk identity/hint supported */
3894
    #if defined(WOLFSSL_TLS13)
3895
        #ifdef SESSION_TICKET_LEN
3896
            #define MAX_PSK_ID_LEN SESSION_TICKET_LEN
3897
        #else
3898
            /* Previous value. Use as fallback for when tickets are disabled. */
3899
            #define MAX_PSK_ID_LEN 1536
3900
        #endif
3901
    #else
3902
        #define MAX_PSK_ID_LEN 128
3903
    #endif
3904
#endif
3905
3906
#if defined(HAVE_ENCRYPT_THEN_MAC) && !defined(WOLFSSL_AEAD_ONLY)
3907
int TLSX_EncryptThenMac_Respond(WOLFSSL* ssl);
3908
#endif
3909
3910
#ifdef WOLFSSL_TLS13
3911
3912
/* Cookie support is mandatory per RFC 8446 9.2 */
3913
#if !defined(NO_WOLFSSL_CLIENT) || defined(WOLFSSL_SEND_HRR_COOKIE)
3914
    #define WOLFSSL_TLS13_COOKIE
3915
#endif
3916
3917
/* Largest cookie a client stores from a HelloRetryRequest to echo back in the
3918
 * second ClientHello. RFC 8446 4.2.2 allows up to 2^16-1 bytes, but the cookie
3919
 * sits inside an extension body of that same size, so its own two byte length
3920
 * prefix leaves 65533. */
3921
#ifndef WOLFSSL_MAX_TLS13_COOKIE_SZ
3922
0
    #define WOLFSSL_MAX_TLS13_COOKIE_SZ 4096
3923
#endif
3924
#if WOLFSSL_MAX_TLS13_COOKIE_SZ > 65533
3925
    #error "WOLFSSL_MAX_TLS13_COOKIE_SZ must be <= 65533"
3926
#endif
3927
3928
/* Cookie extension information - cookie data. */
3929
typedef struct Cookie {
3930
    word16 len;
3931
    /* Ignore "nonstandard extension used : zero-sized array in struct/union"
3932
     * MSVC warning */
3933
    #ifdef _MSC_VER
3934
    #pragma warning(disable: 4200)
3935
    #endif
3936
    byte   data[WC_FLEXIBLE_ARRAY_SIZE];
3937
} Cookie;
3938
3939
WOLFSSL_LOCAL int TLSX_Cookie_Use(const WOLFSSL* ssl, const byte* data,
3940
        word16 len, byte* mac, byte macSz, int resp, TLSX** exts);
3941
WOLFSSL_LOCAL int TlsCheckCookie(const WOLFSSL* ssl, const byte* cookie,
3942
                                 word16 cookieSz);
3943
3944
3945
/* Key Share - TLS v1.3 Specification */
3946
3947
/* The KeyShare extension information - entry in a linked list. */
3948
typedef struct KeyShareEntry {
3949
    word16                group;     /* NamedGroup                        */
3950
    byte*                 ke;        /* Key exchange data                 */
3951
    word32                keLen;     /* Key exchange data length          */
3952
    void*                 key;       /* Key struct                        */
3953
    word32                keyLen;    /* Key size (bytes)                  */
3954
    byte*                 pubKey;    /* Public key                        */
3955
    word32                pubKeyLen; /* Public key length                 */
3956
#if !defined(NO_DH) || defined(WOLFSSL_HAVE_MLKEM)
3957
    byte*                 privKey;   /* Private key                       */
3958
    word32                privKeyLen;/* Private key length - PQC only     */
3959
#endif
3960
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
3961
    word16                session;   /* NamedGroup that was in session    */
3962
    word16                derived;   /* preMaster has been derived        */
3963
#endif
3964
#ifdef WOLFSSL_ASYNC_CRYPT
3965
    int                   lastRet;
3966
#endif
3967
    struct KeyShareEntry* next;      /* List pointer             */
3968
} KeyShareEntry;
3969
3970
WOLFSSL_LOCAL int TLSX_KeyShare_Use(const WOLFSSL* ssl, word16 group,
3971
        word16 len, byte* data, KeyShareEntry **kse, TLSX** extensions);
3972
WOLFSSL_LOCAL int TLSX_KeyShare_Empty(WOLFSSL* ssl);
3973
WOLFSSL_LOCAL int TLSX_KeyShare_SetSupported(const WOLFSSL* ssl,
3974
        TLSX** extensions);
3975
WOLFSSL_LOCAL int TLSX_KeyShare_GenKey(WOLFSSL *ssl, KeyShareEntry *kse);
3976
WOLFSSL_LOCAL int TLSX_KeyShare_Choose(const WOLFSSL *ssl, TLSX* extensions,
3977
        byte cipherSuite0, byte cipherSuite, KeyShareEntry** kse,
3978
        byte* searched);
3979
WOLFSSL_LOCAL int TLSX_KeyShare_Setup(WOLFSSL *ssl, KeyShareEntry* clientKSE);
3980
WOLFSSL_LOCAL int TLSX_KeyShare_Establish(WOLFSSL* ssl, int* doHelloRetry);
3981
WOLFSSL_LOCAL int TLSX_KeyShare_DeriveSecret(WOLFSSL* sclientKSEclientKSEsl);
3982
WOLFSSL_LOCAL int TLSX_KeyShare_Parse(WOLFSSL* ssl, const byte* input,
3983
        word16 length, byte msgType);
3984
WOLFSSL_LOCAL int TLSX_KeyShare_Parse_ClientHello(const WOLFSSL* ssl,
3985
        const byte* input, word16 length, TLSX** extensions);
3986
WOLFSSL_LOCAL int TLSX_KeyShare_HandlePqcHybridKeyServer(WOLFSSL* ssl,
3987
        KeyShareEntry* keyShareEntry, byte* data, word16 len);
3988
#ifdef WOLFSSL_DUAL_ALG_CERTS
3989
#ifdef WOLFSSL_API_PREFIX_MAP
3990
    #define TLSX_CKS_Parse wolfSSL_TLSX_CKS_Parse
3991
#endif
3992
WOLFSSL_TEST_VIS int TLSX_CKS_Parse(WOLFSSL* ssl, byte* input,
3993
                                 word16 length, TLSX** extensions);
3994
WOLFSSL_LOCAL int TLSX_CKS_Set(WOLFSSL* ssl, TLSX** extensions);
3995
#endif
3996
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
3997
3998
enum PskDecryptReturn {
3999
    PSK_DECRYPT_NONE = 0,
4000
    PSK_DECRYPT_OK,
4001
    PSK_DECRYPT_CREATE,
4002
    PSK_DECRYPT_FAIL
4003
};
4004
4005
#ifdef HAVE_SESSION_TICKET
4006
typedef struct psk_sess_free_cb_ctx {
4007
    word32 row;
4008
#ifdef HAVE_EXT_CACHE
4009
    int extCache;
4010
    int freeSess;
4011
#endif
4012
} psk_sess_free_cb_ctx;
4013
typedef void (psk_sess_free_cb)(const WOLFSSL* ssl, const WOLFSSL_SESSION* sess,
4014
        psk_sess_free_cb_ctx* freeCtx);
4015
#endif
4016
4017
/* The PreSharedKey extension information - entry in a linked list. */
4018
typedef struct PreSharedKey {
4019
    word16               identityLen;             /* Length of identity */
4020
    byte*                identity;                /* PSK identity       */
4021
    word32               ticketAge;               /* Age of the ticket  */
4022
    byte                 cipherSuite0;            /* Cipher Suite       */
4023
    byte                 cipherSuite;             /* Cipher Suite       */
4024
    word32               binderLen;               /* Length of HMAC     */
4025
    byte                 binder[WC_MAX_DIGEST_SIZE]; /* HMAC of handshake */
4026
    byte                 hmac;                    /* HMAC algorithm     */
4027
#ifdef HAVE_SESSION_TICKET
4028
    InternalTicket*      it;                      /* ptr to ticket      */
4029
    const WOLFSSL_SESSION* sess; /* ptr to session either from external cache or
4030
                                  * into SessionCache. Work around so that we
4031
                                  * don't call into the cache more than once */
4032
    psk_sess_free_cb* sess_free_cb;               /* callback to free sess */
4033
    psk_sess_free_cb_ctx sess_free_cb_ctx;        /* info for sess_free_cb */
4034
#endif
4035
    byte                 resumption:1;            /* Resumption PSK     */
4036
    byte                 chosen:1;                /* Server's choice    */
4037
    byte                 decryptRet:3;            /* Ticket decrypt return */
4038
    struct PreSharedKey* next;                    /* List pointer       */
4039
} PreSharedKey;
4040
4041
WOLFSSL_LOCAL int TLSX_PreSharedKey_WriteBinders(PreSharedKey* list,
4042
                                                 byte* output, byte msgType,
4043
                                                 word16* pSz);
4044
WOLFSSL_LOCAL int TLSX_PreSharedKey_GetSizeBinders(PreSharedKey* list,
4045
                                                   byte msgType, word16* pSz);
4046
WOLFSSL_LOCAL int TLSX_PreSharedKey_Use(TLSX** extensions, const byte* identity,
4047
                                        word16 len, word32 age, byte hmac,
4048
                                        byte cipherSuite0, byte cipherSuite,
4049
                                        byte resumption,
4050
                                        PreSharedKey **preSharedKey,
4051
                                        void* heap);
4052
WOLFSSL_LOCAL int TLSX_PreSharedKey_Parse_ClientHello(TLSX** extensions,
4053
                                  const byte* input, word16 length, void* heap);
4054
#if defined(WOLFSSL_CERT_WITH_EXTERN_PSK) && defined(WOLFSSL_TLS13)
4055
WOLFSSL_LOCAL int TLSX_CertWithExternPsk_Use(WOLFSSL* ssl);
4056
#endif
4057
4058
/* The possible Pre-Shared Key key exchange modes. */
4059
enum PskKeyExchangeMode {
4060
    PSK_KE,
4061
    PSK_DHE_KE
4062
};
4063
4064
/* User can define this. */
4065
#ifndef WOLFSSL_DEF_PSK_CIPHER
4066
#define WOLFSSL_DEF_PSK_CIPHER    TLS_AES_128_GCM_SHA256
4067
#endif
4068
4069
WOLFSSL_LOCAL int TLSX_PskKeyModes_Use(WOLFSSL* ssl, byte modes);
4070
WOLFSSL_LOCAL int TLSX_PskKeyModes_Parse_Modes(const byte* input, word16 length,
4071
                                              byte msgType, byte* modes);
4072
4073
#ifdef WOLFSSL_EARLY_DATA
4074
WOLFSSL_LOCAL int TLSX_EarlyData_Use(WOLFSSL* ssl, word32 max, int is_response);
4075
#endif
4076
#endif /* HAVE_SESSION_TICKET || !NO_PSK */
4077
4078
4079
/* The types of keys to derive for. */
4080
enum DeriveKeyType {
4081
    no_key,
4082
    early_data_key,
4083
    handshake_key,
4084
    traffic_key,
4085
    update_traffic_key
4086
};
4087
4088
WOLFSSL_LOCAL int DeriveEarlySecret(WOLFSSL* ssl);
4089
WOLFSSL_LOCAL int DeriveHandshakeSecret(WOLFSSL* ssl);
4090
#ifdef WOLFSSL_API_PREFIX_MAP
4091
    #define DeriveTls13Keys wolfSSL_DeriveTls13Keys
4092
#endif
4093
WOLFSSL_TEST_VIS int DeriveTls13Keys(WOLFSSL* ssl, int secret, int side, int store);
4094
WOLFSSL_LOCAL int DeriveMasterSecret(WOLFSSL* ssl);
4095
WOLFSSL_LOCAL int DeriveResumptionPSK(WOLFSSL* ssl, byte* nonce, byte nonceLen, byte* secret);
4096
WOLFSSL_LOCAL int DeriveResumptionSecret(WOLFSSL* ssl, byte* key);
4097
4098
WOLFSSL_LOCAL int Tls13_Exporter(WOLFSSL* ssl, unsigned char *out, size_t outLen,
4099
        const char *label, size_t labelLen,
4100
        const unsigned char *context, size_t contextLen);
4101
4102
/* The key update request values for KeyUpdate message. */
4103
enum KeyUpdateRequest {
4104
    update_not_requested,
4105
    update_requested
4106
};
4107
#endif /* WOLFSSL_TLS13 */
4108
4109
#ifdef WOLFSSL_DTLS_CID
4110
WOLFSSL_LOCAL void TLSX_ConnectionID_Free(byte* ext, void* heap);
4111
WOLFSSL_LOCAL word16 TLSX_ConnectionID_Write(byte* ext, byte* output);
4112
WOLFSSL_LOCAL word16 TLSX_ConnectionID_GetSize(byte* ext);
4113
WOLFSSL_LOCAL int TLSX_ConnectionID_Use(WOLFSSL* ssl);
4114
WOLFSSL_LOCAL int TLSX_ConnectionID_Parse(WOLFSSL* ssl, const byte* input,
4115
    word16 length, byte isRequest);
4116
WOLFSSL_LOCAL void DtlsCIDOnExtensionsParsed(WOLFSSL* ssl);
4117
WOLFSSL_LOCAL byte DtlsCIDCheck(WOLFSSL* ssl, const byte* input,
4118
    word16 inputSize);
4119
WOLFSSL_LOCAL int DtlsCidReplaceTx(WOLFSSL* ssl, const byte* cid, byte size);
4120
WOLFSSL_LOCAL int Dtls13UnifiedHeaderCIDPresent(byte flags);
4121
#endif /* WOLFSSL_DTLS_CID */
4122
WOLFSSL_LOCAL byte DtlsGetCidTxSize(WOLFSSL* ssl);
4123
WOLFSSL_LOCAL byte DtlsGetCidRxSize(WOLFSSL* ssl);
4124
4125
#ifdef OPENSSL_EXTRA
4126
enum SetCBIO {
4127
    WOLFSSL_CBIO_NONE = 0,
4128
    WOLFSSL_CBIO_RECV = 0x1,
4129
    WOLFSSL_CBIO_SEND = 0x2,
4130
};
4131
#endif
4132
4133
#ifdef WOLFSSL_STATIC_EPHEMERAL
4134
/* contains static ephemeral keys */
4135
typedef struct {
4136
#ifndef NO_DH
4137
    DerBuffer* dhKey;
4138
#endif
4139
#ifdef HAVE_ECC
4140
    DerBuffer* ecKey;
4141
#endif
4142
#ifdef HAVE_CURVE25519
4143
    DerBuffer* x25519Key;
4144
#endif
4145
#ifdef HAVE_CURVE448
4146
    DerBuffer* x448Key;
4147
#endif
4148
} StaticKeyExchangeInfo_t;
4149
#endif /* WOLFSSL_STATIC_EPHEMERAL */
4150
4151
4152
/* wolfSSL context type */
4153
struct WOLFSSL_CTX {
4154
    WOLFSSL_METHOD* method;
4155
#ifdef SINGLE_THREADED
4156
    WC_RNG*         rng;          /* to be shared with WOLFSSL w/o locking */
4157
#endif
4158
    wolfSSL_RefWithMutex ref;
4159
    int         err;              /* error code in case of mutex not created */
4160
#ifndef NO_DH
4161
    buffer      serverDH_P;
4162
    buffer      serverDH_G;
4163
#endif
4164
#ifndef NO_CERTS
4165
    DerBuffer*  certificate;
4166
    DerBuffer*  certChain;
4167
    int         certChainCnt;
4168
                 /* chain after self, in DER, with leading size for each cert */
4169
    #ifndef WOLFSSL_NO_CA_NAMES
4170
    WOLF_STACK_OF(WOLFSSL_X509_NAME)* client_ca_names;
4171
    WOLF_STACK_OF(WOLFSSL_X509_NAME)* ca_names;
4172
    #endif
4173
    #ifdef OPENSSL_EXTRA
4174
    WOLF_STACK_OF(WOLFSSL_X509)* x509Chain;
4175
    #endif
4176
#ifdef WOLFSSL_CERT_SETUP_CB
4177
#ifdef OPENSSL_EXTRA
4178
    client_cert_cb CBClientCert;  /* client certificate callback */
4179
#endif
4180
    CertSetupCallback  certSetupCb;
4181
    void*              certSetupCbArg;
4182
#endif
4183
    DerBuffer*  privateKey;
4184
#ifdef WOLFSSL_BLIND_PRIVATE_KEY
4185
    DerBuffer*  privateKeyMask;             /* Mask of private key DER. */
4186
#endif
4187
    byte        privateKeyType;
4188
    byte        privateKeyId:1;
4189
    byte        privateKeyLabel:1;
4190
    int         privateKeySz;
4191
    int         privateKeyDevId;
4192
4193
#ifdef WOLFSSL_DUAL_ALG_CERTS
4194
    DerBuffer*  altPrivateKey;
4195
#ifdef WOLFSSL_BLIND_PRIVATE_KEY
4196
    DerBuffer*  altPrivateKeyMask;          /* Mask of alt private key DER. */
4197
#endif
4198
    byte        altPrivateKeyType;
4199
    byte        altPrivateKeyId:1;
4200
    byte        altPrivateKeyLabel:1;
4201
    int         altPrivateKeySz;
4202
    int         altPrivateKeyDevId;
4203
#endif /* WOLFSSL_DUAL_ALG_CERTS */
4204
#ifdef OPENSSL_ALL
4205
    /* note it is the privateKeyPKey pointer that is volatile, not the object it
4206
     * points to:
4207
     */
4208
    WOLFSSL_EVP_PKEY* volatile privateKeyPKey;
4209
#endif
4210
    WOLFSSL_CERT_MANAGER* cm;      /* our cert manager, ctx owns SSL will use */
4211
#endif
4212
#ifdef KEEP_OUR_CERT
4213
    WOLFSSL_X509*    ourCert;     /* keep alive a X509 struct of cert */
4214
    int              ownOurCert;  /* Dispose of certificate if we own */
4215
#endif
4216
    Suites*     suites;           /* make dynamic, user may not need/set */
4217
    void*       heap;             /* for user memory overrides */
4218
    byte        verifyDepth;
4219
    byte        verifyPeer:1;
4220
    byte        verifyNone:1;
4221
    byte        failNoCert:1;
4222
    byte        failNoCertxPSK:1; /* fail if no cert with the exception of PSK*/
4223
    byte        failNoPSK:1;      /* fail if no PSK is negotiated */
4224
    byte        sessionCacheOff:1;
4225
    byte        sessionCacheFlushOff:1;
4226
#ifdef HAVE_EXT_CACHE
4227
    byte        internalCacheOff:1;
4228
    byte        internalCacheLookupOff:1;
4229
#endif
4230
    byte        sendVerify:2;     /* for client side (can not be single bit) */
4231
    byte        haveRSA:1;        /* RSA available */
4232
    byte        haveECC:1;        /* ECC available */
4233
    byte        haveDH:1;         /* server DH params set by user */
4234
    byte        haveECDSAsig:1;   /* server cert signed w/ ECDSA */
4235
    byte        haveFalconSig:1;  /* server cert signed w/ Falcon */
4236
    byte        haveMlDsaSig:1;   /* server cert signed w/ ML-DSA */
4237
    byte        haveSlhDsaSig:1;  /* server cert signed w/ SLH-DSA */
4238
    byte        haveStaticECC:1;  /* static server ECC private key */
4239
    byte        partialWrite:1;   /* only one msg per write call */
4240
    byte        autoRetry:1;      /* retry read/write on a WANT_{READ|WRITE} */
4241
    byte        quietShutdown:1;  /* don't send close notify */
4242
    byte        groupMessages:1;  /* group handshake messages before sending */
4243
    byte        minDowngrade;     /* minimum downgrade version */
4244
    byte        haveEMS:1;        /* have extended master secret extension */
4245
    byte        useClientOrder:1; /* Use client's cipher preference order */
4246
#if defined(HAVE_SESSION_TICKET)
4247
    byte        noTicketTls12:1;  /* TLS 1.2 server won't send ticket */
4248
#endif
4249
#ifdef WOLFSSL_TLS13
4250
    #if defined(HAVE_SESSION_TICKET) && !defined(NO_WOLFSSL_SERVER)
4251
    unsigned int maxTicketTls13;  /* maximum number of tickets to send */
4252
    #endif
4253
    byte        noTicketTls13:1;  /* TLS 1.3 Server won't create new Ticket */
4254
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
4255
    byte        noPskDheKe:1;     /* Don't use (EC)DHE with PSK */
4256
#ifdef HAVE_SUPPORTED_CURVES
4257
    byte        onlyPskDheKe:1;   /* Only use (EC)DHE with PSK */
4258
#endif
4259
#if defined(WOLFSSL_CERT_WITH_EXTERN_PSK)
4260
    byte        certWithExternPsk:1; /* Use tls_cert_with_extern_psk extension */
4261
#endif
4262
#endif
4263
#endif /* WOLFSSL_TLS13 */
4264
    byte        mutualAuth:1;     /* Mutual authentication required */
4265
#if defined(WOLFSSL_TLS13) && defined(WOLFSSL_POST_HANDSHAKE_AUTH)
4266
    byte        postHandshakeAuth:1;  /* Post-handshake auth supported. */
4267
    byte        verifyPostHandshake:1; /* Only send client cert req post
4268
                                        * handshake, not also during */
4269
#endif
4270
#ifndef NO_DH
4271
    #if !defined(WOLFSSL_OLD_PRIME_CHECK) && !defined(HAVE_FIPS) && \
4272
        !defined(HAVE_SELFTEST)
4273
    byte        dhKeyTested:1;   /* Set when key has been tested. */
4274
    #endif
4275
#endif
4276
#if defined(HAVE_SECURE_RENEGOTIATION) || defined(HAVE_SERVER_RENEGOTIATION_INFO)
4277
    byte        useSecureReneg:1; /* when set will set WOLFSSL objects generated to enable */
4278
#endif
4279
#if !defined(NO_WOLFSSL_CLIENT) && !defined(WOLFSSL_NO_TLS12) && \
4280
    defined(HAVE_SERVER_RENEGOTIATION_INFO) && \
4281
    !defined(WOLFSSL_HARDEN_TLS_NO_SCR_CHECK)
4282
    byte        scr_check_enabled:1; /* require server renegotiation_info on the
4283
                                      * initial handshake (RFC 5746/9325);
4284
                                      * inherited by WOLFSSL objects */
4285
#endif
4286
#ifdef HAVE_ENCRYPT_THEN_MAC
4287
    byte        disallowEncThenMac:1;  /* Don't do Encrypt-Then-MAC */
4288
#endif
4289
#ifdef WOLFSSL_STATIC_MEMORY
4290
    byte        onHeapHint:1; /* whether the ctx/method is put on heap hint */
4291
#endif
4292
#if defined(WOLFSSL_STATIC_EPHEMERAL) && !defined(SINGLE_THREADED)
4293
    byte        staticKELockInit:1;
4294
#endif
4295
#if defined(WOLFSSL_DTLS) && defined(WOLFSSL_SCTP)
4296
    byte        dtlsSctp:1;         /* DTLS-over-SCTP mode */
4297
#endif
4298
#if defined(WOLFSSL_TLS13) && defined(HAVE_ECH)
4299
    byte        disableECH:1;
4300
    byte        enableEchTrialDecrypt:1;  /* Trial decryption of the
4301
                                             inner hello */
4302
#endif
4303
    word16      minProto:1; /* sets min to min available */
4304
    word16      maxProto:1; /* sets max to max available */
4305
#if defined(HAVE_RPK)
4306
    RpkConfig   rpkConfig;
4307
    RpkState    rpkState;
4308
#endif /* HAVE_RPK */
4309
#ifdef WOLFSSL_SRTP
4310
    word16      dtlsSrtpProfiles;  /* DTLS-with-SRTP mode
4311
                                    * (list of selected profiles - up to 16) */
4312
#endif
4313
#if defined(WOLFSSL_DTLS) && defined(WOLFSSL_MULTICAST)
4314
    byte        haveMcast;        /* multicast requested */
4315
    byte        mcastID;          /* multicast group ID */
4316
#endif
4317
#if defined(WOLFSSL_DTLS) && \
4318
    (defined(WOLFSSL_SCTP) || defined(WOLFSSL_DTLS_MTU))
4319
    word16      dtlsMtuSz;        /* DTLS MTU size */
4320
#endif
4321
#ifndef NO_DH
4322
    word16      minDhKeySz;       /* minimum DH key size */
4323
    word16      maxDhKeySz;       /* maximum DH key size */
4324
#endif
4325
#ifndef NO_RSA
4326
    short       minRsaKeySz;      /* minimum RSA key size */
4327
#ifdef WC_RSA_PSS
4328
    word8       useRsaPss;        /* cert supports RSA-PSS */
4329
#endif
4330
#endif
4331
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || defined(HAVE_ED448)
4332
    short       minEccKeySz;      /* minimum ECC key size */
4333
#endif
4334
#ifdef HAVE_FALCON
4335
    short       minFalconKeySz;   /* minimum Falcon key size */
4336
#endif
4337
#ifdef WOLFSSL_HAVE_MLDSA
4338
    short       minMlDsaKeySz;    /* minimum ML-DSA key size */
4339
#endif
4340
    unsigned long     mask;             /* store SSL_OP_ flags */
4341
#if defined(OPENSSL_EXTRA) || defined(HAVE_CURL)
4342
    word32            disabledCurves;   /* curves disabled by user */
4343
#endif
4344
#ifdef WOLFSSL_SESSION_ID_CTX
4345
    byte              sessionCtx[ID_LEN]; /* app session context ID */
4346
    byte              sessionCtxSz;
4347
#endif
4348
#ifdef OPENSSL_EXTRA
4349
    const unsigned char *alpn_cli_protos;/* ALPN client protocol list */
4350
    unsigned int         alpn_cli_protos_len;
4351
    byte              cbioFlag;  /* WOLFSSL_CBIO_RECV/SEND: CBIORecv/Send is set */
4352
    CallbackInfoState* CBIS;      /* used to get info about SSL state */
4353
    WOLFSSL_X509_VERIFY_PARAM* param;    /* verification parameters*/
4354
#endif
4355
#ifdef WOLFSSL_WOLFSENTRY_HOOKS
4356
    NetworkFilterCallback_t AcceptFilter;
4357
    void *AcceptFilter_arg;
4358
    NetworkFilterCallback_t ConnectFilter;
4359
    void *ConnectFilter_arg;
4360
#endif /* WOLFSSL_WOLFSENTRY_HOOKS */
4361
    CallbackIORecv CBIORecv;
4362
    CallbackIOSend CBIOSend;
4363
#ifdef WOLFSSL_DTLS
4364
    CallbackGenCookie CBIOCookie;       /* gen cookie callback */
4365
#endif /* WOLFSSL_DTLS */
4366
#ifdef WOLFSSL_SESSION_EXPORT
4367
#ifdef WOLFSSL_DTLS
4368
    wc_dtls_export  dtls_export;        /* export function for DTLS session */
4369
#endif
4370
    CallbackGetPeer CBGetPeer;
4371
    CallbackSetPeer CBSetPeer;
4372
#endif
4373
    VerifyCallback  verifyCallback;     /* cert verification callback */
4374
    void*           verifyCbCtx;        /* cert verify callback user ctx*/
4375
#ifdef OPENSSL_ALL
4376
    CertVerifyCallback verifyCertCb;
4377
    void*              verifyCertCbArg;
4378
#endif /* OPENSSL_ALL */
4379
#ifdef OPENSSL_EXTRA
4380
    SSL_Msg_Cb      protoMsgCb;         /* inspect protocol message callback */
4381
    void*           protoMsgCtx;        /* user set context with msg callback */
4382
#endif
4383
    word32          timeout;            /* session timeout */
4384
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || defined(HAVE_CURVE25519) || \
4385
    defined(HAVE_ED448)
4386
    word32          ecdhCurveOID;       /* curve Ecc_Sum */
4387
#endif
4388
#ifdef HAVE_ECC
4389
    word16          eccTempKeySz;       /* in octets 20 - 66 */
4390
#endif
4391
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || defined(HAVE_ED448) || \
4392
    defined(HAVE_FALCON) || defined(WOLFSSL_HAVE_MLDSA) || \
4393
    defined(WOLFSSL_HAVE_SLHDSA)
4394
    word32          pkCurveOID;         /* curve Ecc_Sum */
4395
#endif
4396
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
4397
    byte        havePSK;                /* psk key set by user */
4398
    wc_psk_client_callback client_psk_cb;  /* client callback */
4399
    wc_psk_server_callback server_psk_cb;  /* server callback */
4400
#ifdef WOLFSSL_TLS13
4401
    wc_psk_client_cs_callback    client_psk_cs_cb;     /* client callback */
4402
    wc_psk_client_tls13_callback client_psk_tls13_cb;  /* client callback */
4403
    wc_psk_server_tls13_callback server_psk_tls13_cb;  /* server callback */
4404
#endif
4405
    void*       psk_ctx;
4406
    char        server_hint[MAX_PSK_ID_LEN + NULL_TERM_LEN];
4407
#endif /* HAVE_SESSION_TICKET || !NO_PSK */
4408
#ifdef WOLFSSL_TLS13
4409
    word16          group[WOLFSSL_MAX_GROUP_COUNT];
4410
    byte            numGroups;
4411
#endif
4412
#ifdef WOLFSSL_EARLY_DATA
4413
    word32          maxEarlyDataSz;
4414
#if defined(WOLFSSL_TLS13) && defined(HAVE_SESSION_TICKET) && !defined(NO_TLS)
4415
    /* RFC 8446 Section 8.2: reject 0-RTT for tickets minted before this
4416
     * context was created. */
4417
#ifdef WOLFSSL_32BIT_MILLI_TIME
4418
    word32          ticketStartTime;    /* Ctx creation time (ms) */
4419
#else
4420
    sword64         ticketStartTime;    /* Ctx creation time (ms) */
4421
#endif
4422
    byte            noFreshStartCheck:1; /* Skip the fresh start check */
4423
#endif
4424
#endif
4425
#ifdef HAVE_ANON
4426
    byte        useAnon;               /* User wants to allow Anon suites */
4427
#endif /* HAVE_ANON */
4428
#ifdef WOLFSSL_ENCRYPTED_KEYS
4429
    wc_pem_password_cb* passwd_cb;
4430
    void*               passwd_userdata;
4431
#endif
4432
#ifdef WOLFSSL_LOCAL_X509_STORE
4433
    WOLFSSL_X509_STORE x509_store; /* points to ctx->cm */
4434
    WOLFSSL_X509_STORE* x509_store_pt; /* take ownership of external store */
4435
#endif
4436
#if defined(OPENSSL_EXTRA) || defined(HAVE_WEBSERVER) || \
4437
    defined(WOLFSSL_WPAS_SMALL) || defined(WOLFSSL_TLS_READ_AHEAD)
4438
    byte            readAhead;
4439
#endif
4440
#if defined(OPENSSL_EXTRA) || defined(WOLFSSL_TLS_READ_AHEAD)
4441
    /* Read-ahead coalescing buffer size. 0 = use one record (default). See
4442
     * wolfSSL_CTX_set_default_read_buffer_len(). */
4443
    word32          readAheadSz;
4444
#endif
4445
#if defined(OPENSSL_EXTRA) || defined(HAVE_WEBSERVER) || defined(WOLFSSL_WPAS_SMALL)
4446
    void*           userPRFArg; /* passed to prf callback */
4447
#endif
4448
#ifdef HAVE_EX_DATA
4449
    WOLFSSL_CRYPTO_EX_DATA ex_data;
4450
#endif
4451
#if defined(HAVE_ALPN) && (defined(OPENSSL_ALL) || defined(WOLFSSL_NGINX) || \
4452
    defined(WOLFSSL_HAPROXY) || defined(HAVE_LIGHTY) || defined(WOLFSSL_QUIC))
4453
    CallbackALPNSelect alpnSelect;
4454
    void*              alpnSelectArg;
4455
#endif
4456
#ifdef HAVE_SNI
4457
    CallbackSniRecv sniRecvCb;
4458
    void*           sniRecvCbArg;
4459
#endif
4460
#if defined(WOLFSSL_MULTICAST) && defined(WOLFSSL_DTLS)
4461
    CallbackMcastHighwater mcastHwCb; /* Sequence number highwater callback */
4462
    word32      mcastFirstSeq;    /* first trigger level */
4463
    word32      mcastSecondSeq;   /* second trigger level */
4464
    word32      mcastMaxSeq;      /* max level */
4465
#endif
4466
#ifdef HAVE_OCSP
4467
    WOLFSSL_OCSP      ocsp;
4468
#endif
4469
    int             devId;              /* async device id to use */
4470
#ifdef HAVE_TLS_EXTENSIONS
4471
    TLSX* extensions;                  /* RFC 6066 TLS Extensions data */
4472
    #ifdef OPENSSL_EXTRA
4473
        WOLFSSL_CustomExt* customExt;  /* App-defined custom TLS extensions */
4474
    #endif
4475
    #ifndef NO_WOLFSSL_SERVER
4476
        #if defined(HAVE_CERTIFICATE_STATUS_REQUEST) \
4477
         || defined(HAVE_CERTIFICATE_STATUS_REQUEST_V2)
4478
            OcspRequest* certOcspRequest;
4479
            ocspVerifyStatusCb ocspStatusVerifyCb;
4480
            void* ocspStatusVerifyCbArg;
4481
        #endif
4482
        #if defined(HAVE_CERTIFICATE_STATUS_REQUEST_V2)
4483
            OcspRequest* chainOcspRequest[MAX_CHAIN_DEPTH];
4484
        #endif
4485
    #endif
4486
    #if defined(HAVE_SESSION_TICKET) && !defined(NO_WOLFSSL_SERVER)
4487
        SessionTicketEncCb ticketEncCb;   /* enc/dec session ticket Cb */
4488
        void*              ticketEncCtx;  /* session encrypt context */
4489
        #if defined(OPENSSL_ALL) || defined(WOLFSSL_NGINX) || defined(WOLFSSL_HAPROXY) \
4490
          || defined(OPENSSL_EXTRA) || defined(HAVE_LIGHTY)
4491
        ticketCompatCb     ticketEncWrapCb; /* callback for OpenSSL ticket key callback */
4492
        #endif
4493
        int                ticketHint;    /* ticket hint in seconds */
4494
        #ifndef WOLFSSL_NO_DEF_TICKET_ENC_CB
4495
            TicketEncCbCtx ticketKeyCtx;
4496
        #endif
4497
    #endif
4498
    #endif
4499
    #ifdef HAVE_SUPPORTED_CURVES
4500
        byte userCurves;                  /* indicates user called wolfSSL_CTX_UseSupportedCurve */
4501
    #endif
4502
#ifdef ATOMIC_USER
4503
    CallbackMacEncrypt    MacEncryptCb;    /* Atomic User Mac/Encrypt Cb */
4504
    CallbackDecryptVerify DecryptVerifyCb; /* Atomic User Decrypt/Verify Cb */
4505
    #ifdef HAVE_ENCRYPT_THEN_MAC
4506
        CallbackEncryptMac    EncryptMacCb;    /* Atomic User Mac/Enc Cb */
4507
        CallbackVerifyDecrypt VerifyDecryptCb; /* Atomic User Dec/Verify Cb */
4508
    #endif
4509
#endif
4510
#ifdef HAVE_PK_CALLBACKS
4511
    #ifdef HAVE_ECC
4512
        CallbackEccKeyGen EccKeyGenCb;  /* User EccKeyGen Callback Handler */
4513
        CallbackEccSign   EccSignCb;    /* User EccSign   Callback handler */
4514
        void*             EccSignCtx;   /* Ecc Sign       Callback Context */
4515
        CallbackEccVerify EccVerifyCb;  /* User EccVerify Callback handler */
4516
        CallbackEccSharedSecret EccSharedSecretCb; /* User EccVerify Callback handler */
4517
    #endif /* HAVE_ECC */
4518
    #ifdef HAVE_HKDF
4519
        CallbackHKDFExtract HkdfExtractCb; /* User hkdf Extract Callback handler */
4520
    #endif
4521
    #ifdef HAVE_ED25519
4522
        /* User Ed25519Sign   Callback handler */
4523
        CallbackEd25519Sign   Ed25519SignCb;
4524
        /* User Ed25519Verify Callback handler */
4525
        CallbackEd25519Verify Ed25519VerifyCb;
4526
    #endif
4527
    #ifdef HAVE_CURVE25519
4528
        /* User X25519 KeyGen Callback Handler */
4529
        CallbackX25519KeyGen X25519KeyGenCb;
4530
        /* User X25519 SharedSecret Callback handler */
4531
        CallbackX25519SharedSecret X25519SharedSecretCb;
4532
    #endif
4533
    #ifdef HAVE_ED448
4534
        /* User Ed448Sign   Callback handler */
4535
        CallbackEd448Sign   Ed448SignCb;
4536
        /* User Ed448Verify Callback handler */
4537
        CallbackEd448Verify Ed448VerifyCb;
4538
    #endif
4539
    #ifdef HAVE_CURVE448
4540
        /* User X448 KeyGen Callback Handler */
4541
        CallbackX448KeyGen X448KeyGenCb;
4542
        /* User X448 SharedSecret Callback handler */
4543
        CallbackX448SharedSecret X448SharedSecretCb;
4544
    #endif
4545
    #ifndef NO_DH
4546
        /* User DH KeyGen Callback handler*/
4547
        CallbackDhGenerateKeyPair DhGenerateKeyPairCb;
4548
        /* User DH Agree Callback handler */
4549
        CallbackDhAgree DhAgreeCb;
4550
    #endif
4551
    #ifndef NO_RSA
4552
        /* User RsaSign Callback handler (priv key) */
4553
        CallbackRsaSign   RsaSignCb;
4554
        /* User RsaVerify Callback handler (pub key) */
4555
        CallbackRsaVerify RsaVerifyCb;
4556
        /* User VerifyRsaSign Callback handler (priv key) */
4557
        CallbackRsaVerify RsaSignCheckCb;
4558
        #ifdef WC_RSA_PSS
4559
            /* User RsaSign (priv key) */
4560
            CallbackRsaPssSign   RsaPssSignCb;
4561
            /* User RsaVerify (pub key) */
4562
            CallbackRsaPssVerify RsaPssVerifyCb;
4563
            /* User VerifyRsaSign (priv key) */
4564
            CallbackRsaPssVerify RsaPssSignCheckCb;
4565
        #endif
4566
        CallbackRsaEnc    RsaEncCb;     /* User Rsa Public Encrypt  handler */
4567
        CallbackRsaDec    RsaDecCb;     /* User Rsa Private Decrypt handler */
4568
    #endif /* NO_RSA */
4569
4570
    /* User generate pre-master handler */
4571
    CallbackGenPreMaster        GenPreMasterCb;
4572
    /* User generate master secret handler */
4573
    CallbackGenMasterSecret     GenMasterCb;
4574
    /* User generate Extended master secret handler */
4575
    CallbackGenExtMasterSecret  GenExtMasterCb;
4576
    /* User generate session key handler */
4577
    CallbackGenSessionKey       GenSessionKeyCb;
4578
    /* User setting encrypt keys handler */
4579
    CallbackEncryptKeys         EncryptKeysCb;
4580
    /* User Tls finished handler */
4581
    CallbackTlsFinished         TlsFinishedCb;
4582
#if !defined(WOLFSSL_NO_TLS12) && !defined(WOLFSSL_AEAD_ONLY)
4583
    /* User Verify mac handler */
4584
    CallbackVerifyMac           VerifyMacCb;
4585
#endif
4586
#if defined(WOLFSSL_PUBLIC_ASN)
4587
    /* User handler to process a certificate */
4588
    CallbackProcessPeerCert ProcessPeerCertCb;
4589
#endif
4590
    /* User handler to process the server's key exchange public key */
4591
    CallbackProcessServerSigKex ProcessServerSigKexCb;
4592
    /* User handler to process the TLS record */
4593
    CallbackPerformTlsRecordProcessing PerformTlsRecordProcessingCb;
4594
    /* User handler to do HKDF expansions */
4595
    CallbackHKDFExpandLabel HKDFExpandLabelCb;
4596
4597
#endif /* HAVE_PK_CALLBACKS */
4598
#ifdef HAVE_WOLF_EVENT
4599
    WOLF_EVENT_QUEUE event_queue;
4600
#endif /* HAVE_WOLF_EVENT */
4601
#ifdef HAVE_EXT_CACHE
4602
    WOLFSSL_SESSION*(*get_sess_cb)(WOLFSSL*, const unsigned char*, int, int*);
4603
    int (*new_sess_cb)(WOLFSSL*, WOLFSSL_SESSION*);
4604
#endif
4605
#if defined(HAVE_EXT_CACHE) || defined(HAVE_EX_DATA)
4606
    Rem_Sess_Cb rem_sess_cb;
4607
#endif
4608
#if defined(OPENSSL_EXTRA) && defined(WOLFCRYPT_HAVE_SRP) && !defined(NO_SHA256)
4609
    Srp*  srp;  /* TLS Secure Remote Password Protocol*/
4610
    byte* srp_password;
4611
#endif
4612
#if defined(OPENSSL_EXTRA) && defined(HAVE_SECRET_CALLBACK)
4613
    wolfSSL_CTX_keylog_cb_func keyLogCb;
4614
#endif /* OPENSSL_EXTRA && HAVE_SECRET_CALLBACK */
4615
#ifdef WOLFSSL_STATIC_EPHEMERAL
4616
    StaticKeyExchangeInfo_t staticKE;
4617
    #ifndef SINGLE_THREADED
4618
    wolfSSL_Mutex staticKELock;
4619
    #endif
4620
#endif
4621
#ifdef WOLFSSL_QUIC
4622
    struct {
4623
        const WOLFSSL_QUIC_METHOD *method;
4624
    } quic;
4625
#endif
4626
#if defined(WOLFSSL_TLS13) && defined(HAVE_ECH)
4627
    WOLFSSL_EchConfig* echConfigs;
4628
#endif
4629
#if defined(__APPLE__) && defined(WOLFSSL_SYS_CA_CERTS)
4630
    byte doAppleNativeCertValidationFlag:1;
4631
#endif /* defined(__APPLE__) && defined(WOLFSSL_SYS_CA_CERTS) */
4632
#ifdef WOLFSSL_DUAL_ALG_CERTS
4633
    byte *sigSpec;
4634
    word16 sigSpecSz;
4635
#endif
4636
#if defined(WOLFSSL_SYS_CRYPTO_POLICY)
4637
    int secLevel; /* The security level of system-wide crypto policy. */
4638
#endif /* WOLFSSL_SYS_CRYPTO_POLICY */
4639
4640
#ifdef WOLFSSL_TEST_APPLE_NATIVE_CERT_VALIDATION
4641
    CFMutableArrayRef testTrustedCAs;
4642
#endif /* WOLFSSL_TEST_APPLE_NATIVE_CERT_VALIDATION */
4643
};
4644
4645
WOLFSSL_LOCAL
4646
int InitSSL_Ctx(WOLFSSL_CTX* ctx, WOLFSSL_METHOD* method, void* heap);
4647
WOLFSSL_LOCAL
4648
void FreeSSL_Ctx(WOLFSSL_CTX* ctx);
4649
WOLFSSL_LOCAL
4650
void SSL_CtxResourceFree(WOLFSSL_CTX* ctx);
4651
4652
#ifdef HAVE_EX_DATA_CLEANUP_HOOKS
4653
    #ifndef HAVE_EX_DATA
4654
        #error "HAVE_EX_DATA_CLEANUP_HOOKS requires HAVE_EX_DATA to be defined"
4655
    #endif
4656
void wolfSSL_CRYPTO_cleanup_ex_data(WOLFSSL_CRYPTO_EX_DATA* ex_data);
4657
#endif
4658
4659
WOLFSSL_LOCAL
4660
int DeriveTlsKeys(WOLFSSL* ssl);
4661
WOLFSSL_LOCAL
4662
int ProcessOldClientHello(WOLFSSL* ssl, const byte* input, word32* inOutIdx,
4663
                          word32 inSz, word16 sz);
4664
4665
#ifndef NO_CERTS
4666
    WOLFSSL_LOCAL int AddSigner(WOLFSSL_CERT_MANAGER* cm, Signer *s);
4667
    WOLFSSL_LOCAL
4668
    int AddCA(WOLFSSL_CERT_MANAGER* cm, DerBuffer** pDer, int type, int verify);
4669
    WOLFSSL_LOCAL int RemoveCA(WOLFSSL_CERT_MANAGER* cm, byte* hash, int type);
4670
    WOLFSSL_LOCAL int SetCAType(WOLFSSL_CERT_MANAGER* cm, byte* hash, int type);
4671
    WOLFSSL_LOCAL
4672
    int AlreadySigner(WOLFSSL_CERT_MANAGER* cm, byte* hash);
4673
#ifdef WOLFSSL_TRUST_PEER_CERT
4674
    WOLFSSL_LOCAL
4675
    int AddTrustedPeer(WOLFSSL_CERT_MANAGER* cm, DerBuffer** pDer, int verify);
4676
    WOLFSSL_LOCAL
4677
    int AlreadyTrustedPeer(WOLFSSL_CERT_MANAGER* cm, DecodedCert* cert);
4678
#endif
4679
#endif
4680
4681
#ifdef WOLFSSL_TEST_APPLE_NATIVE_CERT_VALIDATION
4682
    WOLFSSL_API
4683
    int wolfSSL_TestAppleNativeCertValidation_AppendCA(WOLFSSL_CTX* ctx,
4684
                                                    const byte* derCert,
4685
                                                    int derLen);
4686
#endif /* WOLFSSL_TEST_APPLE_NATIVE_CERT_VALIDATION */
4687
4688
/* All cipher suite related info
4689
 * Keep as a constant size (no ifdefs) for session export */
4690
typedef struct CipherSpecs {
4691
    word16 key_size;
4692
    word16 iv_size;
4693
    word16 block_size;
4694
    word16 aead_mac_size;
4695
    byte bulk_cipher_algorithm;
4696
    byte cipher_type;               /* block, stream, or aead */
4697
    byte mac_algorithm;
4698
    byte kea;                       /* key exchange algo */
4699
    byte sig_algo;
4700
    byte hash_size;
4701
    byte pad_size;
4702
    byte static_ecdh;
4703
} CipherSpecs;
4704
4705
4706
void InitCipherSpecs(CipherSpecs* cs);
4707
4708
4709
/* Supported Key Exchange Protocols */
4710
enum KeyExchangeAlgorithm {
4711
    no_kea,
4712
    rsa_kea,
4713
    diffie_hellman_kea,
4714
    fortezza_kea,
4715
    psk_kea,
4716
    dhe_psk_kea,
4717
    ecdhe_psk_kea,
4718
    ecc_diffie_hellman_kea,
4719
    ecc_static_diffie_hellman_kea,      /* for verify suite only */
4720
    any_kea
4721
};
4722
4723
/* Used with InitSuitesHashSigAlgo */
4724
0
#define SIG_ECDSA       0x01
4725
0
#define SIG_RSA         0x02
4726
0
#define SIG_SM2         0x04
4727
0
#define SIG_FALCON      0x08
4728
0
#define SIG_MLDSA       0x10
4729
#define SIG_ANON        0x20
4730
0
#define SIG_SLHDSA      0x40
4731
/* SIG_ANON is omitted by default */
4732
0
#define SIG_ALL         (SIG_ECDSA | SIG_RSA | SIG_SM2 | SIG_FALCON | \
4733
0
                         SIG_MLDSA | SIG_SLHDSA)
4734
4735
/* Supported Authentication Schemes */
4736
enum SignatureAlgorithm {
4737
    anonymous_sa_algo            = 0,
4738
    rsa_sa_algo                  = 1,
4739
    dsa_sa_algo                  = 2,
4740
    ecc_dsa_sa_algo              = 3,
4741
    rsa_pss_sa_algo              = 8,
4742
    ed25519_sa_algo              = 9,
4743
    rsa_pss_pss_algo             = 10,
4744
    ed448_sa_algo                = 11,
4745
    falcon_level1_sa_algo        = 12,
4746
    falcon_level5_sa_algo        = 13,
4747
    mldsa_44_sa_algo             = 14,
4748
    mldsa_65_sa_algo             = 15,
4749
    mldsa_87_sa_algo             = 16,
4750
    sm2_sa_algo                  = 17,
4751
    any_sa_algo                  = 18,
4752
    ecc_brainpool_sa_algo        = 19,
4753
    slhdsa_sha2_128s_sa_algo     = 20,
4754
    slhdsa_sha2_128f_sa_algo     = 21,
4755
    slhdsa_sha2_192s_sa_algo     = 22,
4756
    slhdsa_sha2_192f_sa_algo     = 23,
4757
    slhdsa_sha2_256s_sa_algo     = 24,
4758
    slhdsa_sha2_256f_sa_algo     = 25,
4759
    slhdsa_shake_128s_sa_algo    = 26,
4760
    slhdsa_shake_128f_sa_algo    = 27,
4761
    slhdsa_shake_192s_sa_algo    = 28,
4762
    slhdsa_shake_192f_sa_algo    = 29,
4763
    slhdsa_shake_256s_sa_algo    = 30,
4764
    slhdsa_shake_256f_sa_algo    = 31,
4765
    invalid_sa_algo              = 255
4766
};
4767
4768
#define PSS_RSAE_TO_PSS_PSS(macAlgo) \
4769
0
    ((macAlgo) + (pss_sha256 - sha256_mac))
4770
4771
#define PSS_PSS_HASH_TO_MAC(macAlgo) \
4772
0
    ((macAlgo) - (pss_sha256 - sha256_mac))
4773
4774
enum SigAlgRsaPss {
4775
    pss_sha256  = 0x09,
4776
    pss_sha384  = 0x0a,
4777
    pss_sha512  = 0x0b
4778
};
4779
4780
#ifdef WOLFSSL_SM2
4781
    /* Default SM2 signature ID. */
4782
    #define TLS12_SM2_SIG_ID        ((byte*)"1234567812345678")
4783
    /* Length of default SM2 signature ID. */
4784
    #define TLS12_SM2_SIG_ID_SZ     16
4785
4786
    /* https://www.rfc-editor.org/rfc/rfc8998.html#name-sm2-signature-scheme */
4787
    /* ID to use when signing/verifying TLS v1.3 data. */
4788
    #define TLS13_SM2_SIG_ID        ((byte*)"TLSv1.3+GM+Cipher+Suite")
4789
    /* Length of ID to use when signing/verifying TLS v1.3 data. */
4790
    #define TLS13_SM2_SIG_ID_SZ     23
4791
#endif
4792
4793
/* Supported ECC Curve Types */
4794
enum EccCurves {
4795
    named_curve = 3
4796
};
4797
4798
4799
/* Valid client certificate request types from page 27 */
4800
enum ClientCertificateType {
4801
    rsa_sign            = 1,
4802
    dss_sign            = 2,
4803
    rsa_fixed_dh        = 3,
4804
    dss_fixed_dh        = 4,
4805
    rsa_ephemeral_dh    = 5,
4806
    dss_ephemeral_dh    = 6,
4807
    fortezza_kea_cert   = 20,
4808
    ecdsa_sign          = 64,
4809
    rsa_fixed_ecdh      = 65,
4810
    ecdsa_fixed_ecdh    = 66,
4811
    falcon_sign         = 67,
4812
    mldsa_sign          = 68
4813
};
4814
4815
/* Maximum number of ClientCertificateType bytes the server emits in a
4816
 * CertificateRequest. Currently rsa_sign and ecdsa_sign. */
4817
#define MAX_CERT_REQ_CERT_TYPE_CNT 2
4818
4819
4820
#ifndef WOLFSSL_AEAD_ONLY
4821
enum CipherType { stream, block, aead };
4822
#else
4823
enum CipherType { aead };
4824
#endif
4825
4826
4827
#if defined(BUILD_AES) || defined(BUILD_AESGCM) || defined(HAVE_ARIA) || \
4828
        (defined(HAVE_CHACHA) && defined(HAVE_POLY1305)) || defined(WOLFSSL_TLS13)
4829
    #define CIPHER_NONCE
4830
#endif
4831
4832
#if defined(WOLFSSL_DTLS) && defined(HAVE_SECURE_RENEGOTIATION)
4833
enum CipherSrc {
4834
    KEYS_NOT_SET = 0,
4835
    KEYS,     /* keys from ssl->keys are loaded */
4836
    SCR       /* keys from ssl->secure_renegotiation->tmp_keys are loaded */
4837
};
4838
#endif
4839
4840
#ifdef WOLFSSL_CIPHER_TEXT_CHECK
4841
    #ifndef WOLFSSL_CIPHER_CHECK_SZ
4842
        /* 64-bits to confirm encrypt operation worked */
4843
        #define WOLFSSL_CIPHER_CHECK_SZ 8
4844
    #endif
4845
#endif
4846
4847
/* cipher for now */
4848
typedef struct Ciphers {
4849
#ifdef BUILD_ARC4
4850
    Arc4*   arc4;
4851
#endif
4852
#ifdef BUILD_DES3
4853
    Des3*   des3;
4854
#endif
4855
#if defined(BUILD_AES) || defined(BUILD_AESGCM)
4856
    Aes*    aes;
4857
#endif
4858
#if (defined(BUILD_AESGCM) || defined(HAVE_AESCCM)) && !defined(WOLFSSL_NO_TLS12)
4859
    byte* additional;
4860
#endif
4861
#ifdef HAVE_ARIA
4862
    wc_Aria* aria;
4863
#endif
4864
#ifdef CIPHER_NONCE
4865
    byte* nonce;
4866
#endif
4867
#ifdef HAVE_CAMELLIA
4868
    wc_Camellia* cam;
4869
#endif
4870
#ifdef HAVE_CHACHA
4871
    ChaCha*   chacha;
4872
#endif
4873
#ifdef WOLFSSL_SM4
4874
    wc_Sm4*   sm4;
4875
#endif
4876
#if defined(WOLFSSL_TLS13) && defined(HAVE_NULL_CIPHER) && !defined(NO_HMAC)
4877
    Hmac* hmac;
4878
#endif
4879
#ifdef WOLFSSL_CIPHER_TEXT_CHECK
4880
    word32 sanityCheck[WOLFSSL_CIPHER_CHECK_SZ/sizeof(word32)];
4881
#endif
4882
    byte    state;
4883
    byte    setup;       /* have we set it up flag for detection */
4884
#if defined(WOLFSSL_DTLS) && defined(HAVE_SECURE_RENEGOTIATION)
4885
    enum CipherSrc src;  /* DTLS uses this to determine which keys
4886
                          * are currently loaded */
4887
#endif
4888
} Ciphers;
4889
4890
#ifdef WOLFSSL_DTLS13
4891
typedef struct RecordNumberCiphers {
4892
#if defined(BUILD_AES) || defined(BUILD_AESGCM)
4893
        Aes *aes;
4894
#endif /*  BUILD_AES || BUILD_AESGCM */
4895
#ifdef HAVE_CHACHA
4896
        ChaCha *chacha;
4897
#endif
4898
} RecordNumberCiphers;
4899
#endif /* WOLFSSL_DTLS13 */
4900
4901
#ifdef HAVE_ONE_TIME_AUTH
4902
/* Ciphers for one time authentication such as poly1305 */
4903
typedef struct OneTimeAuth {
4904
#ifdef HAVE_POLY1305
4905
    Poly1305* poly1305;
4906
#endif
4907
    byte    setup;      /* flag for if a cipher has been set */
4908
4909
} OneTimeAuth;
4910
#endif
4911
4912
4913
WOLFSSL_LOCAL void InitCiphers(WOLFSSL* ssl);
4914
WOLFSSL_LOCAL void FreeCiphers(WOLFSSL* ssl);
4915
4916
4917
/* hashes type */
4918
typedef struct Hashes {
4919
    #if !defined(NO_MD5) && !defined(NO_OLD_TLS)
4920
        byte md5[WC_MD5_DIGEST_SIZE];
4921
    #endif
4922
    #if !defined(NO_SHA) && (!defined(NO_OLD_TLS) || \
4923
                              defined(WOLFSSL_ALLOW_TLS_SHA1))
4924
        byte sha[WC_SHA_DIGEST_SIZE];
4925
    #endif
4926
    #ifndef NO_SHA256
4927
        byte sha256[WC_SHA256_DIGEST_SIZE];
4928
    #endif
4929
    #ifdef WOLFSSL_SHA384
4930
        byte sha384[WC_SHA384_DIGEST_SIZE];
4931
    #endif
4932
    #ifdef WOLFSSL_SHA512
4933
        byte sha512[WC_SHA512_DIGEST_SIZE];
4934
    #endif
4935
    #ifdef WOLFSSL_SM3
4936
        byte sm3[WC_SM3_DIGEST_SIZE];
4937
    #endif
4938
} Hashes;
4939
4940
WOLFSSL_LOCAL int BuildCertHashes(const WOLFSSL* ssl, Hashes* hashes);
4941
4942
#ifdef WOLFSSL_TLS13
4943
typedef union Digest {
4944
#ifndef NO_SHA256
4945
    wc_Sha256 sha256;
4946
#endif
4947
#ifdef WOLFSSL_SHA384
4948
    wc_Sha384 sha384;
4949
#endif
4950
#ifdef WOLFSSL_SHA512
4951
    wc_Sha512 sha512;
4952
#endif
4953
#ifdef WOLFSSL_SM3
4954
    wc_Sm3    sm3;
4955
#endif
4956
} Digest;
4957
#endif
4958
4959
/* Static x509 buffer */
4960
typedef struct x509_buffer {
4961
    int  length;                  /* actual size */
4962
    byte buffer[MAX_X509_SIZE];   /* max static cert size */
4963
} x509_buffer;
4964
4965
4966
/* wolfSSL X509_CHAIN, for no dynamic memory SESSION_CACHE */
4967
struct WOLFSSL_X509_CHAIN {
4968
    int         count;                    /* total number in chain */
4969
    x509_buffer certs[MAX_CHAIN_DEPTH];   /* only allow max depth 4 for now */
4970
};
4971
4972
typedef enum WOLFSSL_SESSION_TYPE {
4973
    WOLFSSL_SESSION_TYPE_UNKNOWN,
4974
    WOLFSSL_SESSION_TYPE_SSL,    /* in ssl->session */
4975
    WOLFSSL_SESSION_TYPE_CACHE,  /* pointer to internal cache */
4976
    WOLFSSL_SESSION_TYPE_HEAP    /* allocated from heap SESSION_new */
4977
} WOLFSSL_SESSION_TYPE;
4978
4979
#ifdef WOLFSSL_QUIC
4980
typedef struct QuicRecord QuicRecord;
4981
typedef struct QuicRecord {
4982
    struct QuicRecord *next;
4983
    uint8_t *data;
4984
    word32 capacity;
4985
    word32 len;
4986
    word32 start;
4987
    word32 end;
4988
    WOLFSSL_ENCRYPTION_LEVEL level;
4989
    word32 rec_hdr_remain;
4990
} QuicEncData;
4991
4992
typedef struct QuicTransportParam QuicTransportParam;
4993
struct QuicTransportParam {
4994
    const uint8_t *data;
4995
    word16 len;
4996
};
4997
4998
WOLFSSL_LOCAL const QuicTransportParam *QuicTransportParam_new(const uint8_t *data, size_t len, void *heap);
4999
WOLFSSL_LOCAL const QuicTransportParam *QuicTransportParam_dup(const QuicTransportParam *tp, void *heap);
5000
WOLFSSL_LOCAL void QuicTransportParam_free(const QuicTransportParam *tp, void *heap);
5001
WOLFSSL_LOCAL int TLSX_QuicTP_Use(WOLFSSL* ssl, TLSX_Type ext_type, int is_response);
5002
WOLFSSL_LOCAL int wolfSSL_quic_add_transport_extensions(WOLFSSL *ssl, int msg_type);
5003
5004
#define QTP_FREE     QuicTransportParam_free
5005
5006
#endif /* WOLFSSL_QUIC */
5007
5008
/** Session Ticket - RFC 5077 (session 3.2) */
5009
#if defined(WOLFSSL_TLS13) && (defined(HAVE_SESSION_TICKET) || !defined(NO_PSK))
5010
/* Ticket nonce - for deriving PSK.
5011
   Length allowed to be: 1..255. Only support
5012
 * TLS13_TICKET_NONCE_STATIC_SZ length bytes.
5013
 */
5014
typedef struct TicketNonce {
5015
    byte len;
5016
#if defined(WOLFSSL_TICKET_NONCE_MALLOC) &&                                    \
5017
    (!defined(HAVE_FIPS) || (defined(FIPS_VERSION_GE) && FIPS_VERSION_GE(5,3)))
5018
    byte *data;
5019
    byte dataStatic[MAX_TICKET_NONCE_STATIC_SZ];
5020
#else
5021
    byte data[MAX_TICKET_NONCE_STATIC_SZ];
5022
#endif /* WOLFSSL_TICKET_NONCE_MALLOC  && FIPS_VERSION_GE(5,3) */
5023
} TicketNonce;
5024
#endif
5025
5026
/* wolfSSL session type */
5027
struct WOLFSSL_SESSION {
5028
    /* WARNING Do not add fields here. They will be ignored in
5029
     *         wolfSSL_DupSession. */
5030
    WOLFSSL_SESSION_TYPE type;
5031
#ifndef NO_SESSION_CACHE
5032
    int                cacheRow;          /* row in session cache     */
5033
#endif
5034
    wolfSSL_Ref        ref;
5035
    byte               altSessionID[ID_LEN];
5036
    byte               haveAltSessionID:1;
5037
#ifdef HAVE_EX_DATA
5038
    byte               ownExData:1;
5039
#endif
5040
#if defined(HAVE_EXT_CACHE) || defined(HAVE_EX_DATA)
5041
    Rem_Sess_Cb        rem_sess_cb;
5042
#endif
5043
    void*              heap;
5044
    /* WARNING The above fields (up to and including the heap) are not copied
5045
     *         in wolfSSL_DupSession. Place new fields after the heap
5046
     *         member */
5047
5048
    byte               side;              /* Either WOLFSSL_CLIENT_END or
5049
                                                    WOLFSSL_SERVER_END */
5050
5051
    word32             bornOn;            /* create time in seconds   */
5052
    word32             timeout;           /* timeout in seconds       */
5053
5054
    byte               sessionID[ID_LEN]; /* id for protocol or bogus
5055
                                           * ID for TLS 1.3           */
5056
    byte               sessionIDSz;
5057
5058
    byte               masterSecret[SECRET_LEN]; /* stored secret     */
5059
    word16             haveEMS;           /* ext master secret flag   */
5060
#if defined(SESSION_CERTS) && defined(OPENSSL_EXTRA)
5061
    WOLFSSL_X509*      peer;              /* peer cert */
5062
#endif
5063
    ProtocolVersion    version;           /* which version was used   */
5064
#if defined(SESSION_CERTS) || !defined(NO_RESUME_SUITE_CHECK) || \
5065
                        (defined(WOLFSSL_TLS13) && defined(HAVE_SESSION_TICKET))
5066
    byte               cipherSuite0;      /* first byte, normally 0   */
5067
    byte               cipherSuite;       /* 2nd byte, actual suite   */
5068
#endif
5069
#ifndef NO_CLIENT_CACHE
5070
    word16             idLen;             /* serverID length          */
5071
    byte               serverID[SERVER_ID_LEN]; /* for easier client lookup */
5072
#endif
5073
#ifdef WOLFSSL_SESSION_ID_CTX
5074
    byte               sessionCtxSz;      /* sessionCtx length        */
5075
    byte               sessionCtx[ID_LEN]; /* app specific context id */
5076
#endif /* WOLFSSL_SESSION_ID_CTX */
5077
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
5078
    byte               peerVerifyRet;     /* cert verify error */
5079
#endif
5080
#ifdef WOLFSSL_TLS13
5081
    word16             namedGroup;
5082
#endif
5083
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
5084
#ifdef WOLFSSL_TLS13
5085
#ifdef WOLFSSL_32BIT_MILLI_TIME
5086
    word32             ticketSeen;        /* Time ticket seen (ms) */
5087
#else
5088
    sword64            ticketSeen;        /* Time ticket seen (ms) */
5089
#endif
5090
    word32             ticketAdd;         /* Added by client */
5091
    TicketNonce        ticketNonce;       /* Nonce used to derive PSK */
5092
#endif
5093
#ifdef WOLFSSL_EARLY_DATA
5094
    word32             maxEarlyDataSz;
5095
#endif
5096
#endif
5097
#ifdef HAVE_SESSION_TICKET
5098
    byte               staticTicket[SESSION_TICKET_LEN];
5099
    byte*              ticket;
5100
    word16             ticketLen;
5101
    word16             ticketLenAlloc;    /* is dynamic */
5102
#ifdef HAVE_SNI
5103
    byte               sniHash[TICKET_BINDING_HASH_SZ];  /* SNI at issue */
5104
#endif
5105
#ifdef HAVE_ALPN
5106
    byte               alpnHash[TICKET_BINDING_HASH_SZ]; /* ALPN at issue */
5107
#endif
5108
#endif
5109
5110
#ifdef SESSION_CERTS
5111
    WOLFSSL_X509_CHAIN chain;             /* peer cert chain, static  */
5112
    #ifdef WOLFSSL_ALT_CERT_CHAINS
5113
    WOLFSSL_X509_CHAIN altChain;          /* peer alt cert chain, static */
5114
    #endif
5115
#endif
5116
#ifdef HAVE_EX_DATA
5117
    WOLFSSL_CRYPTO_EX_DATA ex_data;
5118
#endif
5119
#ifdef HAVE_MAX_FRAGMENT
5120
    byte               mfl; /* max fragment length negotiated i.e.
5121
                             * WOLFSSL_MFL_2_8  (6) */
5122
#endif
5123
    byte               isSetup:1;
5124
};
5125
5126
#if defined(WOLFSSL_TLS13) && defined(HAVE_SESSION_TICKET) &&                  \
5127
        defined(WOLFSSL_TICKET_NONCE_MALLOC) &&                                \
5128
    (!defined(HAVE_FIPS) || (defined(FIPS_VERSION_GE) && FIPS_VERSION_GE(5,3)))
5129
WOLFSSL_LOCAL int SessionTicketNoncePopulate(WOLFSSL_SESSION *session,
5130
    const byte* nonce, byte len);
5131
#endif /* WOLFSSL_TLS13 &&  */
5132
5133
WOLFSSL_LOCAL int wolfSSL_RAND_Init(void);
5134
5135
WOLFSSL_LOCAL WOLFSSL_SESSION* wolfSSL_NewSession(void* heap);
5136
WOLFSSL_LOCAL WOLFSSL_SESSION* wolfSSL_GetSession(
5137
    WOLFSSL* ssl, byte* masterSecret, byte restoreSessionCerts);
5138
WOLFSSL_LOCAL void SetupSession(WOLFSSL* ssl);
5139
WOLFSSL_LOCAL void AddSession(WOLFSSL* ssl);
5140
#ifdef WOLFSSL_API_PREFIX_MAP
5141
    #define AddSessionToCache wolfSSL_AddSessionToCache
5142
#endif
5143
WOLFSSL_TEST_VIS int AddSessionToCache(WOLFSSL_CTX* ctx,
5144
    WOLFSSL_SESSION* addSession, const byte* id, byte idSz, int* sessionIndex,
5145
    int side, word16 useTicket, ClientSession** clientCacheEntry);
5146
#ifndef NO_CLIENT_CACHE
5147
WOLFSSL_LOCAL ClientSession* AddSessionToClientCache(int side, int row, int idx,
5148
                      byte* serverID, word16 idLen, const byte* sessionID,
5149
                      word16 useTicket);
5150
#endif
5151
WOLFSSL_LOCAL
5152
WOLFSSL_SESSION* ClientSessionToSession(const WOLFSSL_SESSION* session);
5153
WOLFSSL_LOCAL void TlsSessionCacheUnlockRow(word32 row);
5154
WOLFSSL_LOCAL int TlsSessionCacheGetAndRdLock(const byte *id,
5155
    const WOLFSSL_SESSION **sess, word32 *lockedRow, byte side);
5156
WOLFSSL_LOCAL int TlsSessionCacheGetAndWrLock(const byte *id,
5157
    WOLFSSL_SESSION **sess, word32 *lockedRow, byte side);
5158
WOLFSSL_LOCAL void EvictSessionFromCache(WOLFSSL_SESSION* session);
5159
WOLFSSL_TEST_VIS int wolfSSL_GetSessionFromCache(WOLFSSL* ssl, WOLFSSL_SESSION* output);
5160
WOLFSSL_LOCAL int wolfSSL_SetSession(WOLFSSL* ssl, WOLFSSL_SESSION* session);
5161
WOLFSSL_LOCAL void wolfSSL_FreeSession(WOLFSSL_CTX* ctx,
5162
        WOLFSSL_SESSION* session);
5163
WOLFSSL_LOCAL int wolfSSL_DupSession(const WOLFSSL_SESSION* input,
5164
        WOLFSSL_SESSION* output, int avoidSysCalls);
5165
5166
5167
typedef int (*hmacfp) (WOLFSSL*, byte*, const byte*, word32, int, int, int, int);
5168
5169
#ifndef NO_CLIENT_CACHE
5170
    WOLFSSL_LOCAL WOLFSSL_SESSION* wolfSSL_GetSessionClient(
5171
        WOLFSSL* ssl, const byte* id, int len);
5172
#endif
5173
5174
/* client connect state for nonblocking restart */
5175
enum ConnectState {
5176
    CONNECT_BEGIN = 0,
5177
    CLIENT_HELLO_SENT,
5178
    HELLO_AGAIN,               /* HELLO_AGAIN s for DTLS case */
5179
    HELLO_AGAIN_REPLY,
5180
    FIRST_REPLY_DONE,
5181
    FIRST_REPLY_FIRST,
5182
    FIRST_REPLY_SECOND,
5183
    FIRST_REPLY_THIRD,
5184
    FIRST_REPLY_FOURTH,
5185
    FINISHED_DONE,
5186
    SECOND_REPLY_DONE,
5187
5188
#ifdef WOLFSSL_DTLS13
5189
    WAIT_FINISHED_ACK
5190
#endif /* WOLFSSL_DTLS13 */
5191
5192
};
5193
5194
5195
/* server accept state for nonblocking restart */
5196
enum AcceptState {
5197
    ACCEPT_BEGIN = 0,
5198
    ACCEPT_BEGIN_RENEG,
5199
    ACCEPT_CLIENT_HELLO_DONE,
5200
    ACCEPT_HELLO_RETRY_REQUEST_DONE,
5201
    ACCEPT_FIRST_REPLY_DONE,
5202
    SERVER_HELLO_SENT,
5203
    CERT_SENT,
5204
    CERT_VERIFY_SENT,
5205
    CERT_STATUS_SENT,
5206
    KEY_EXCHANGE_SENT,
5207
    CERT_REQ_SENT,
5208
    SERVER_HELLO_DONE,
5209
    ACCEPT_SECOND_REPLY_DONE,
5210
    TICKET_SENT,
5211
    CHANGE_CIPHER_SENT,
5212
    ACCEPT_FINISHED_DONE,
5213
    ACCEPT_THIRD_REPLY_DONE
5214
};
5215
5216
/* TLS 1.3 server accept state for nonblocking restart */
5217
enum AcceptStateTls13 {
5218
    TLS13_ACCEPT_BEGIN = 0,
5219
    TLS13_ACCEPT_BEGIN_RENEG,
5220
    TLS13_ACCEPT_CLIENT_HELLO_DONE,
5221
    TLS13_ACCEPT_HELLO_RETRY_REQUEST_DONE,
5222
    TLS13_ACCEPT_FIRST_REPLY_DONE,
5223
    TLS13_ACCEPT_SECOND_REPLY_DONE,
5224
    TLS13_SERVER_HELLO_SENT,
5225
    TLS13_ACCEPT_THIRD_REPLY_DONE,
5226
    TLS13_SERVER_EXTENSIONS_SENT,
5227
    TLS13_CERT_REQ_SENT,
5228
    TLS13_CERT_SENT,
5229
    TLS13_CERT_VERIFY_SENT,
5230
    TLS13_ACCEPT_FINISHED_SENT,
5231
    TLS13_PRE_TICKET_SENT,
5232
    TLS13_ACCEPT_FINISHED_DONE,
5233
    TLS13_TICKET_SENT
5234
};
5235
5236
#ifdef WOLFSSL_THREADED_CRYPT
5237
5238
#include <pthread.h>
5239
5240
typedef struct ThreadCrypt {
5241
    Ciphers encrypt;
5242
    bufferStatic buffer;
5243
    unsigned char nonce[AESGCM_NONCE_SZ];
5244
    unsigned char additional[AEAD_AUTH_DATA_SZ];
5245
    int init;
5246
    int offset;
5247
    int cryptLen;
5248
    int done;
5249
    int avail;
5250
    int stop;
5251
    WOLFSSL_THREAD_SIGNAL signal;
5252
    void*                 signalCtx;
5253
} ThreadCrypt;
5254
5255
#endif
5256
5257
/* Streamed TLS 1.3 CertificateVerify send. When the CertificateVerify body
5258
 * (the signature) does not fit in a single record - a post-quantum signature
5259
 * such as SLH-DSA or ML-DSA, or any signature under a small
5260
 * max_fragment_length - it is generated once into a connection-level buffer and
5261
 * emitted one record at a time, so the output buffer never has to hold the
5262
 * whole signature. The assembled body must be held at the connection level
5263
 * (not on the stack) because these signatures are randomized: a non-blocking
5264
 * WANT_WRITE can return control mid-send, and the records already sent are
5265
 * bound into the transcript, so the resumed send must continue emitting the
5266
 * exact same signature - it cannot be regenerated. This is algorithm-neutral;
5267
 * it applies to any signature scheme whose CertificateVerify can exceed a
5268
 * record. It is not used with WOLFSSL_ASYNC_CRYPT, whose record-AEAD pends are
5269
 * handled by the existing in-place fragmented path. */
5270
#if defined(WOLFSSL_TLS13) && !defined(WOLFSSL_ASYNC_CRYPT) && \
5271
    (defined(WOLFSSL_HAVE_SLHDSA) || defined(WOLFSSL_HAVE_MLDSA) || \
5272
     defined(HAVE_FALCON))
5273
    #define WOLFSSL_TLS13_STREAM_CERT_VERIFY
5274
#endif
5275
5276
/* buffers for struct WOLFSSL */
5277
typedef struct Buffers {
5278
    bufferStatic    inputBuffer;
5279
    bufferStatic    outputBuffer;
5280
#ifdef WOLFSSL_THREADED_CRYPT
5281
    ThreadCrypt     encrypt[WOLFSSL_THREADED_CRYPT_CNT];
5282
#endif
5283
    buffer          domainName;            /* for client check */
5284
    buffer          ipasc;                 /* for client IP SAN check */
5285
    buffer          clearOutputBuffer;
5286
    buffer          sig;                   /* signature data */
5287
    buffer          digest;                /* digest data */
5288
    word32          prevSent;              /* previous plain text bytes sent
5289
                                              when got WANT_WRITE            */
5290
    word32          plainSz;               /* plain text bytes in buffer to send
5291
                                              when got WANT_WRITE            */
5292
    byte            weOwnCert;             /* SSL own cert flag */
5293
    byte            weOwnCertChain;        /* SSL own cert chain flag */
5294
    byte            weOwnKey;              /* SSL own key flag */
5295
#ifdef WOLFSSL_DUAL_ALG_CERTS
5296
    byte            weOwnAltKey;           /* SSL own alt key flag */
5297
#endif
5298
    byte            weOwnDH;               /* SSL own dh (p,g)  flag */
5299
#ifndef NO_DH
5300
    buffer          serverDH_P;            /* WOLFSSL_CTX owns, unless we own */
5301
    buffer          serverDH_G;            /* WOLFSSL_CTX owns, unless we own */
5302
    buffer          serverDH_Pub;
5303
    buffer          serverDH_Priv;
5304
    DhKey*          serverDH_Key;
5305
#endif
5306
#ifndef NO_CERTS
5307
    DerBuffer*      certificate;           /* WOLFSSL_CTX owns, unless we own */
5308
    DerBuffer*      key;                   /* WOLFSSL_CTX owns, unless we own */
5309
#ifdef WOLFSSL_BLIND_PRIVATE_KEY
5310
    DerBuffer*      keyMask;               /* Mask of private key DER. */
5311
#endif
5312
    byte            keyType;               /* Type of key */
5313
    byte            keyId:1;               /* Key data is an id not data */
5314
    byte            keyLabel:1;            /* Key data is a label not data */
5315
    int             keySz;                 /* Size of RSA key */
5316
    int             keyDevId;              /* Device Id for key */
5317
#ifdef WOLFSSL_DUAL_ALG_CERTS
5318
    DerBuffer*      altKey;                /* WOLFSSL_CTX owns, unless we own */
5319
#ifdef WOLFSSL_BLIND_PRIVATE_KEY
5320
    DerBuffer*      altKeyMask;            /* Mask of alt private key DER. */
5321
#endif
5322
    byte            altKeyType;            /* Type of alt key */
5323
    byte            altKeyId:1;            /* Key data is an id not data */
5324
    byte            altKeyLabel:1;         /* Key data is a label not data */
5325
    int             altKeySz;              /* Size of alt key */
5326
    int             altKeyDevId;           /* Device Id for alt key */
5327
#endif
5328
    DerBuffer*      certChain;             /* WOLFSSL_CTX owns, unless we own */
5329
                 /* chain after self, in DER, with leading size for each cert */
5330
    int             certChainCnt;
5331
#ifdef WOLFSSL_TLS13
5332
    DerBuffer*      certExts[MAX_CERT_EXTENSIONS];
5333
#endif
5334
#endif
5335
#ifdef WOLFSSL_SEND_HRR_COOKIE
5336
    buffer          tls13CookieSecret;     /* HRR cookie secret */
5337
    /* Secondary HRR cookie secret, used only when verifying a cookie if the
5338
     * primary secret fails.  Lets a stateless DTLS 1.3 server keep accepting
5339
     * cookies issued under the secret it had before an application-driven
5340
     * rotation.  DTLS only - never used to issue cookies. */
5341
    buffer          tls13CookieSecretSecondary;
5342
#endif
5343
#ifdef WOLFSSL_DTLS
5344
    WOLFSSL_DTLS_CTX dtlsCtx;              /* DTLS connection context */
5345
    #ifndef NO_WOLFSSL_SERVER
5346
        buffer       dtlsCookieSecret;     /* DTLS cookie secret */
5347
        /* Secondary DTLS 1.2 cookie secret, used only when verifying a
5348
         * received HelloVerifyRequest cookie if the primary secret fails.
5349
         * Lets a stateless server keep accepting cookies issued under the
5350
         * secret it had before an application-driven rotation.  Never used to
5351
         * issue cookies. */
5352
        buffer       dtlsCookieSecretSecondary;
5353
    #endif /* NO_WOLFSSL_SERVER */
5354
#endif
5355
#ifdef HAVE_PK_CALLBACKS
5356
    #ifdef HAVE_ECC
5357
        buffer peerEccDsaKey;              /* we own for Ecc Verify Callbacks */
5358
    #endif /* HAVE_ECC */
5359
    #ifdef HAVE_ED25519
5360
        buffer peerEd25519Key;             /* for Ed25519 Verify Callbacks */
5361
    #endif /* HAVE_ED25519 */
5362
    #ifdef HAVE_ED448
5363
        buffer peerEd448Key;             /* for Ed448 Verify Callbacks */
5364
    #endif /* HAVE_ED448 */
5365
    #ifndef NO_RSA
5366
        buffer peerRsaKey;                 /* we own for Rsa Verify Callbacks */
5367
    #endif /* NO_RSA */
5368
#endif /* HAVE_PK_CALLBACKS */
5369
#ifdef WOLFSSL_TLS13_STREAM_CERT_VERIFY
5370
    /* Assembled TLS 1.3 CertificateVerify body (sig-alg | length | signature)
5371
     * held across records while it is streamed, so a non-blocking WANT_WRITE
5372
     * can resume the send without recomputing the signature. NULL when idle;
5373
     * freed by wolfSSL_ResourceFree. See WOLFSSL_TLS13_STREAM_CERT_VERIFY. */
5374
    buffer          certVerifyMsg;
5375
#endif
5376
} Buffers;
5377
5378
/* sub-states for send/do key share (key exchange) */
5379
enum asyncState {
5380
    TLS_ASYNC_BEGIN = 0,
5381
    TLS_ASYNC_BUILD,
5382
    TLS_ASYNC_DO,
5383
    TLS_ASYNC_VERIFY,
5384
    TLS_ASYNC_FINALIZE,
5385
    TLS_ASYNC_END
5386
};
5387
5388
/* sub-states for build message */
5389
enum buildMsgState {
5390
    BUILD_MSG_BEGIN = 0,
5391
    BUILD_MSG_SIZE,
5392
    BUILD_MSG_HASH,
5393
    BUILD_MSG_VERIFY_MAC,
5394
    BUILD_MSG_ENCRYPT,
5395
    BUILD_MSG_ENCRYPTED_VERIFY_MAC
5396
};
5397
5398
/* sub-states for cipher operations */
5399
enum cipherState {
5400
    CIPHER_STATE_BEGIN = 0,
5401
    CIPHER_STATE_DO,
5402
    CIPHER_STATE_END
5403
};
5404
5405
struct Options {
5406
#ifndef NO_PSK
5407
    wc_psk_client_callback client_psk_cb;
5408
    wc_psk_server_callback server_psk_cb;
5409
#ifdef OPENSSL_EXTRA
5410
    wc_psk_use_session_cb_func session_psk_cb;
5411
#endif
5412
#ifdef WOLFSSL_TLS13
5413
    wc_psk_client_cs_callback    client_psk_cs_cb;     /* client callback */
5414
    wc_psk_client_tls13_callback client_psk_tls13_cb;  /* client callback */
5415
    wc_psk_server_tls13_callback server_psk_tls13_cb;  /* server callback */
5416
#endif
5417
    void*             psk_ctx;
5418
#endif /* NO_PSK */
5419
    unsigned long     mask; /* store SSL_OP_ flags */
5420
#if defined(OPENSSL_EXTRA) || defined(HAVE_WEBSERVER) || defined(WOLFSSL_WPAS_SMALL)
5421
    word16            minProto:1; /* sets min to min available */
5422
    word16            maxProto:1; /* sets max to max available */
5423
#endif
5424
#if defined(HAVE_SESSION_TICKET) && defined(WOLFSSL_TLS13)
5425
    unsigned int      maxTicketTls13;  /* maximum number of tickets to send */
5426
    unsigned int      ticketsSent;     /* keep track of the total sent */
5427
#endif
5428
5429
    /* on/off or small bit flags, optimize layout */
5430
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
5431
    word16            havePSK:1;            /* psk key set by user */
5432
#endif /* HAVE_SESSION_TICKET || !NO_PSK */
5433
    word16            sendVerify:2;     /* false = 0, true = 1, sendBlank = 2 */
5434
    word16            sessionCacheOff:1;
5435
    word16            sessionCacheFlushOff:1;
5436
#ifdef HAVE_EXT_CACHE
5437
    word16            internalCacheOff:1;
5438
    word16            internalCacheLookupOff:1;
5439
#endif
5440
    word16            side:2;             /* client, server or neither end */
5441
    word16            verifyPeer:1;
5442
    word16            verifyNone:1;
5443
    word16            failNoCert:1;
5444
    word16            failNoCertxPSK:1;   /* fail for no cert except with PSK */
5445
    word16            failNoPSK:1;        /* fail if no PSK is negotiated */
5446
    word16            downgrade:1;        /* allow downgrade of versions */
5447
    word16            resuming:1;
5448
#ifdef HAVE_SECURE_RENEGOTIATION
5449
    word16            resumed:1;          /* resuming may be reset on SCR */
5450
#endif
5451
    word16            isPSK:1;
5452
    word16            haveSessionId:1;    /* server may not send */
5453
    word16            tls:1;              /* using TLS ? */
5454
    word16            tls1_1:1;           /* using TLSv1.1+ ? */
5455
    word16            tls1_3:1;           /* using TLSv1.3+ ? */
5456
    word16            dtls:1;             /* using datagrams ? */
5457
#ifdef WOLFSSL_DTLS
5458
    word16            dtlsStateful:1;     /* allow stateful processing ? */
5459
#endif
5460
    word16            connReset:1;        /* has the peer reset */
5461
    word16            isClosed:1;         /* if we consider conn closed */
5462
    word16            closeNotify:1;      /* we've received a close notify */
5463
    word16            sentNotify:1;       /* we've sent a close notify */
5464
    word16            usingCompression:1; /* are we using compression */
5465
    word16            haveRSA:1;          /* RSA available */
5466
    word16            haveECC:1;          /* ECC available */
5467
    word16            haveDH:1;           /* server DH params set by user */
5468
    word16            haveECDSAsig:1;     /* server ECDSA signed cert */
5469
    word16            haveStaticECC:1;    /* static server ECC private key */
5470
    word16            haveFalconSig:1;    /* server Falcon signed cert */
5471
    word16            haveMlDsaSig:1;     /* server ML-DSA signed cert */
5472
    word16            haveSlhDsaSig:1;    /* server SLH-DSA signed cert */
5473
    word16            havePeerCert:1;     /* do we have peer's cert */
5474
    word16            havePeerVerify:1;   /* and peer's cert verify */
5475
    word16            usingPSK_cipher:1;  /* are using psk as cipher */
5476
    word16            usingAnon_cipher:1; /* are we using an anon cipher */
5477
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
5478
    word16            noPskDheKe:1;       /* Don't use (EC)DHE with PSK */
5479
#ifdef HAVE_SUPPORTED_CURVES
5480
    word16            onlyPskDheKe:1;     /* Only use (EC)DHE with PSK */
5481
#endif
5482
#if defined(WOLFSSL_CERT_WITH_EXTERN_PSK)
5483
    word16            certWithExternPsk:1; /* Cert auth with external PSK */
5484
#endif
5485
#endif
5486
    word16            partialWrite:1;     /* only one msg per write call */
5487
    word16            quietShutdown:1;    /* don't send close notify */
5488
    word16            certOnly:1;         /* stop once we get cert */
5489
    word16            groupMessages:1;    /* group handshake messages */
5490
    word16            saveArrays:1;       /* save array Memory for user get keys
5491
                                           or psk */
5492
    word16            weOwnRng:1;         /* will be true unless CTX owns */
5493
    word16            dontFreeDigest:1;   /* when true, we used SetDigest */
5494
    word16            haveEMS:1;          /* using extended master secret */
5495
#ifdef HAVE_POLY1305
5496
    word16            oldPoly:1;        /* set when to use old rfc way of poly*/
5497
#endif
5498
    word16            useAnon:1;       /* User wants to allow Anon suites */
5499
#ifdef HAVE_SESSION_TICKET
5500
    word16            createTicket:1;     /* Server to create new Ticket */
5501
    word16            useTicket:1;        /* Use Ticket not session cache */
5502
    word16            rejectTicket:1;     /* Callback rejected ticket */
5503
    word16            noTicketTls12:1;    /* TLS 1.2 server won't send ticket */
5504
#ifdef WOLFSSL_TLS13
5505
    word16            noTicketTls13:1;    /* Server won't create new Ticket */
5506
#ifdef WOLFSSL_EARLY_DATA
5507
    word16            ticketPredatesCtx:1; /* PSK ticket minted before ctx */
5508
#endif
5509
#endif
5510
#endif
5511
#ifdef WOLFSSL_DTLS
5512
#ifdef HAVE_SECURE_RENEGOTIATION
5513
    word16            dtlsDoSCR:1;        /* Enough packets were dropped. We
5514
                                           * need to re-key. */
5515
#endif
5516
    word16            dtlsUseNonblock:1;  /* are we using nonblocking socket */
5517
    word16            dtlsHsRetain:1;     /* DTLS retaining HS data */
5518
#ifdef WOLFSSL_SCTP
5519
    word16            dtlsSctp:1;         /* DTLS-over-SCTP mode */
5520
#endif
5521
#endif /* WOLFSSL_DTLS */
5522
#if defined(HAVE_TLS_EXTENSIONS) && defined(HAVE_SUPPORTED_CURVES)
5523
    word16            userCurves:1;       /* indicates user called wolfSSL_UseSupportedCurve */
5524
    word16            peerNoUncompPF:1;   /* peer sent ec_point_formats without
5525
                                           * the uncompressed (0) format */
5526
#endif
5527
    word16            keepResources:1;    /* Keep resources after handshake */
5528
    word16            useClientOrder:1;   /* Use client's cipher order */
5529
    word16            mutualAuth:1;       /* Mutual authentication is required */
5530
    word16            peerAuthGood:1;     /* Any required peer auth done */
5531
#if defined(WOLFSSL_TLS13) && (defined(HAVE_SESSION_TICKET) || !defined(NO_PSK))
5532
    word16            pskNegotiated:1;    /* Session Ticket/PSK negotiated. */
5533
#endif
5534
#if defined(WOLFSSL_TLS13) && defined(WOLFSSL_POST_HANDSHAKE_AUTH)
5535
    word16            postHandshakeAuth:1;/* Client send post_handshake_auth
5536
                                           * extension */
5537
    word16            verifyPostHandshake:1; /* Only send client cert req post
5538
                                              * handshake, not also during */
5539
#endif
5540
#if defined(WOLFSSL_TLS13) && !defined(NO_WOLFSSL_SERVER)
5541
    word16            sendCookie:1;       /* Server creates a Cookie in HRR */
5542
#endif
5543
#ifdef WOLFSSL_ALT_CERT_CHAINS
5544
    word16            usingAltCertChain:1;/* Alternate cert chain was used */
5545
#endif
5546
#if defined(WOLFSSL_TLS13) && defined(WOLFSSL_TLS13_MIDDLEBOX_COMPAT)
5547
    word16            sentChangeCipher:1; /* Change Cipher Spec sent */
5548
#endif
5549
#if !defined(WOLFSSL_NO_CLIENT_AUTH) && \
5550
               ((defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3)) || \
5551
                (defined(HAVE_ED25519) && !defined(NO_ED25519_CLIENT_AUTH)) || \
5552
                (defined(HAVE_ED448) && !defined(NO_ED448_CLIENT_AUTH)))
5553
    word16            cacheMessages:1;    /* Cache messages for sign/verify */
5554
#endif
5555
#ifndef NO_DH
5556
    #if !defined(WOLFSSL_OLD_PRIME_CHECK) && \
5557
        !defined(HAVE_FIPS) && !defined(HAVE_SELFTEST)
5558
        word16        dhDoKeyTest:1;      /* Need to do the DH Key prime test */
5559
        word16        dhKeyTested:1;      /* Set when key has been tested. */
5560
    #endif
5561
#endif
5562
#ifdef HAVE_ENCRYPT_THEN_MAC
5563
    word16            disallowEncThenMac:1;   /* Don't do Encrypt-Then-MAC */
5564
    word16            encThenMac:1;           /* Doing Encrypt-Then-MAC */
5565
    word16            startedETMRead:1;       /* Doing Encrypt-Then-MAC read */
5566
    word16            startedETMWrite:1;      /* Doing Encrypt-Then-MAC write */
5567
#endif
5568
#ifdef WOLFSSL_ASYNC_CRYPT
5569
    word16            buildArgsSet:1;         /* buildArgs are set and need to
5570
                                               * be free'd */
5571
#endif
5572
#ifdef WOLFSSL_DTLS13
5573
    word16            dtls13SendMoreAcks:1;  /* Send more acks during the
5574
                                              * handshake process */
5575
#ifdef WOLFSSL_DTLS13_NO_HRR_ON_RESUME
5576
    word16            dtls13NoHrrOnResume:1;
5577
#endif
5578
#ifdef WOLFSSL_DTLS_CH_FRAG
5579
    word16            dtls13ChFrag:1;
5580
#endif
5581
#endif
5582
#ifdef WOLFSSL_TLS13
5583
    word16            tls13MiddleBoxCompat:1; /* TLSv1.3 middlebox compatibility */
5584
#endif
5585
#ifdef WOLFSSL_DTLS_CID
5586
    word16            useDtlsCID:1;
5587
#endif /* WOLFSSL_DTLS_CID */
5588
#if defined(WOLFSSL_TLS13) && defined(HAVE_ECH)
5589
    word16            echAccepted:1;
5590
    word16            disableECH:1;             /* Did the user disable ech */
5591
    word16            echProcessingInner:1;     /* Processing the inner hello */
5592
    word16            echRetryConfigsAccepted:1;
5593
    word16            enableEchTrialDecrypt:1;  /* Trial decryption of the
5594
                                                   inner hello */
5595
#endif
5596
#ifdef WOLFSSL_SEND_HRR_COOKIE
5597
    word16            cookieGood:1;
5598
#endif
5599
#ifdef WOLFSSL_TLS13
5600
#ifdef WOLFSSL_TLS13_COOKIE
5601
    word16            hrrSentCookie:1;    /* HRR sent with cookie */
5602
#endif
5603
    word16            hrrSentKeyShare:1;  /* HRR sent with key share */
5604
    word16            shSentKeyShare:1;   /* SH sent with key share */
5605
#endif
5606
    word16            returnOnGoodCh:1;
5607
    word16            disableRead:1;
5608
#if defined(WOLFSSL_ASYNC_CRYPT) && defined(WOLFSSL_ASYNC_CERT_YIELD)
5609
    /* Opt-in (WOLFSSL_ASYNC_CERT_YIELD): set when we deliberately returned
5610
     * WC_PENDING_E between peer certificate verifies so a cooperative scheduler
5611
     * can run. Lives in (zero-initialized, persistent) ssl->options so the
5612
     * fresh-entry vs. resume decision in ProcessPeerCerts is reliable; the
5613
     * transient ProcPeerCertArgs scratch buffer is not zeroed on alloc. */
5614
    word16            certYieldPending:1;
5615
#endif
5616
5617
#ifdef WOLFSSL_EARLY_DATA
5618
    word16            clientInEarlyData:1; /* Client is in wolfSSL_read_early_data */
5619
#endif
5620
#if defined(WOLFSSL_TLS13) && !defined(NO_CERTS) && !defined(WOLFSSL_NO_SIGALG)
5621
    word16            peerSha1CertOk:1;   /* Peer advertised a SHA-1 signature
5622
                                           * scheme for certificates */
5623
#endif
5624
#ifdef WOLFSSL_DTLS
5625
    byte              haveMcast;          /* using multicast ? */
5626
#endif
5627
    byte              buildingMsg;        /* If set then we need to re-enter the
5628
                                           * handshake logic. */
5629
    byte              seenUnifiedHdr;     /* received msg with unified header */
5630
    byte              shutdownDone;       /* we've completed a shutdown */
5631
    byte              sendKeyUpdate;      /* Key Update to write */
5632
#if defined(HAVE_RPK)
5633
    RpkConfig         rpkConfig;
5634
    RpkState          rpkState;
5635
#endif /* HAVE_RPK */
5636
5637
    /* need full byte values for this section */
5638
    byte            processReply;           /* nonblocking resume */
5639
    byte            cipherSuite0;           /* first byte, normally 0 */
5640
    byte            cipherSuite;            /* second byte, actual suite */
5641
#ifdef WOLFSSL_TLS13
5642
    byte            hrrCipherSuite0;        /* first byte, normally 0 */
5643
    byte            hrrCipherSuite;         /* second byte, actual suite */
5644
#endif
5645
    byte            hashAlgo;               /* selected hash algorithm */
5646
    byte            sigAlgo;                /* selected sig algorithm */
5647
    byte            peerHashAlgo;           /* peer's chosen hash algo */
5648
    byte            peerSigAlgo;            /* peer's chosen sig algo */
5649
    byte            serverState;
5650
    byte            clientState;
5651
    byte            handShakeState;
5652
    byte            handShakeDone;      /* at least one handshake complete */
5653
    byte            minDowngrade;       /* minimum downgrade version */
5654
    byte            connectState;       /* nonblocking resume */
5655
    byte            acceptState;        /* nonblocking resume */
5656
    byte            asyncState;         /* sub-state for enum asyncState */
5657
    byte            buildMsgState;      /* sub-state for enum buildMsgState */
5658
    byte            alertCount;         /* detect warning dos attempt */
5659
    byte            emptyRecordCount;   /* detect empty record dos attempt */
5660
#ifdef WOLFSSL_MULTICAST
5661
    word16          mcastID;            /* Multicast group ID */
5662
#endif
5663
#ifndef NO_DH
5664
    word16          minDhKeySz;         /* minimum DH key size */
5665
    word16          maxDhKeySz;         /* minimum DH key size */
5666
    word16          dhKeySz;            /* actual DH key size */
5667
#endif
5668
#ifndef NO_RSA
5669
    short           minRsaKeySz;      /* minimum RSA key size */
5670
#endif
5671
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || defined(HAVE_ED448)
5672
    short           minEccKeySz;      /* minimum ECC key size */
5673
#endif
5674
#if defined(HAVE_FALCON)
5675
    short           minFalconKeySz;   /* minimum Falcon key size */
5676
#endif
5677
#if defined(WOLFSSL_HAVE_MLDSA)
5678
    short           minMlDsaKeySz;    /* minimum ML-DSA key size */
5679
#endif
5680
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
5681
    byte            verifyDepth;      /* maximum verification depth */
5682
#endif
5683
#ifdef WOLFSSL_EARLY_DATA
5684
    word16          pskIdIndex;
5685
    word32          maxEarlyDataSz;
5686
#endif
5687
#ifdef WOLFSSL_TLS13
5688
    byte            oldMinor;          /* client preferred version < TLS 1.3 */
5689
#endif
5690
};
5691
5692
typedef struct Arrays {
5693
    byte*           preMasterSecret;
5694
    word32          preMasterSz;        /* differs for DH, actual size */
5695
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
5696
    word32          psk_keySz;          /* actual size */
5697
    char            client_identity[MAX_PSK_ID_LEN + NULL_TERM_LEN];
5698
    char            server_hint[MAX_PSK_ID_LEN + NULL_TERM_LEN];
5699
    byte            psk_key[MAX_PSK_KEY_LEN];
5700
#endif
5701
    byte            clientRandom[RAN_LEN];
5702
#if defined(WOLFSSL_TLS13) && defined(HAVE_ECH)
5703
    byte            clientRandomInner[RAN_LEN];
5704
#endif
5705
    byte            serverRandom[RAN_LEN];
5706
    byte            sessionID[ID_LEN];
5707
    byte            sessionIDSz;
5708
#ifdef WOLFSSL_TLS13
5709
    byte            secret[SECRET_LEN];
5710
#endif
5711
#ifdef HAVE_KEYING_MATERIAL
5712
    byte            exporterSecret[WC_MAX_DIGEST_SIZE];
5713
#endif
5714
    byte            masterSecret[SECRET_LEN];
5715
#if defined(WOLFSSL_RENESAS_TSIP_TLS) && \
5716
   !defined(NO_WOLFSSL_RENESAS_TSIP_TLS_SESSION)
5717
    byte            tsip_masterSecret[TSIP_TLS_MASTERSECRET_SIZE];
5718
#endif
5719
#if defined(WOLFSSL_RENESAS_FSPSM_TLS)
5720
    byte            fspsm_masterSecret[FSPSM_TLS_MASTERSECRET_SIZE];
5721
#endif
5722
#ifdef WOLFSSL_DTLS
5723
    byte            cookie[MAX_COOKIE_LEN];
5724
    byte            cookieSz;
5725
#endif
5726
} Arrays;
5727
5728
#ifndef ASN_NAME_MAX
5729
    #ifndef NO_ASN
5730
        /* use value from asn.h */
5731
0
        #define ASN_NAME_MAX WC_ASN_NAME_MAX
5732
    #else
5733
        /* calculate for WOLFSSL_X509 */
5734
        #if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL) || \
5735
            defined(WOLFSSL_CERT_EXT)
5736
            #define ASN_NAME_MAX 330
5737
        #else
5738
            #define ASN_NAME_MAX 256
5739
        #endif
5740
    #endif
5741
#endif
5742
5743
typedef enum {
5744
    STACK_TYPE_X509               = 0,
5745
    STACK_TYPE_GEN_NAME           = 1,
5746
    STACK_TYPE_BIO                = 2,
5747
    STACK_TYPE_OBJ                = 3,
5748
    STACK_TYPE_STRING             = 4,
5749
    STACK_TYPE_CIPHER             = 5,
5750
    STACK_TYPE_ACCESS_DESCRIPTION = 6,
5751
    STACK_TYPE_X509_EXT           = 7,
5752
    STACK_TYPE_NULL               = 8,
5753
    STACK_TYPE_X509_NAME          = 9,
5754
    STACK_TYPE_CONF_VALUE         = 10,
5755
    STACK_TYPE_X509_INFO          = 11,
5756
    STACK_TYPE_BY_DIR_entry       = 12,
5757
    STACK_TYPE_BY_DIR_hash        = 13,
5758
    STACK_TYPE_X509_OBJ           = 14,
5759
    STACK_TYPE_DIST_POINT         = 15,
5760
    STACK_TYPE_X509_CRL           = 16,
5761
    STACK_TYPE_X509_NAME_ENTRY    = 17,
5762
    STACK_TYPE_X509_REQ_ATTR      = 18,
5763
    STACK_TYPE_GENERAL_SUBTREE    = 19,
5764
    STACK_TYPE_X509_REVOKED       = 20
5765
} WOLF_STACK_TYPE;
5766
5767
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
5768
5769
struct WOLFSSL_STACK {
5770
    unsigned long num; /* number of nodes in stack
5771
                        * (safety measure for freeing and shortcut for count) */
5772
    #if defined(OPENSSL_ALL)
5773
    wolf_sk_hash_cb hash_fn;
5774
    unsigned long hash;
5775
    #endif
5776
5777
    union {
5778
        WOLFSSL_X509*          x509;
5779
        WOLFSSL_X509_NAME*     name;
5780
        WOLFSSL_X509_NAME_ENTRY* name_entry;
5781
        WOLFSSL_X509_INFO*     info;
5782
        WOLFSSL_BIO*           bio;
5783
        WOLFSSL_ASN1_OBJECT*   obj;
5784
        WOLFSSL_CIPHER         cipher;
5785
        WOLFSSL_ACCESS_DESCRIPTION* access;
5786
        WOLFSSL_X509_EXTENSION* ext;
5787
#ifdef OPENSSL_EXTRA
5788
        WOLFSSL_CONF_VALUE*    conf;
5789
#endif
5790
        void*                  generic;
5791
        char*                  string;
5792
        WOLFSSL_GENERAL_NAME*  gn;
5793
        WOLFSSL_GENERAL_SUBTREE* subtree;
5794
        WOLFSSL_BY_DIR_entry*  dir_entry;
5795
        WOLFSSL_BY_DIR_HASH*   dir_hash;
5796
        WOLFSSL_X509_OBJECT*   x509_obj;
5797
        WOLFSSL_DIST_POINT*    dp;
5798
        WOLFSSL_X509_CRL*      crl;
5799
        WOLFSSL_X509_REVOKED*  revoked;
5800
    } data;
5801
    void* heap; /* memory heap hint */
5802
    WOLFSSL_STACK* next;
5803
    WOLF_STACK_TYPE type;     /* Identifies type of stack. */
5804
};
5805
5806
#endif /* OPENSSL_EXTRA || OPENSSL_EXTRA_X509_SMALL */
5807
5808
struct WOLFSSL_X509_NAME {
5809
    char  *name;
5810
    int   dynamicName;
5811
    int   sz;
5812
    char  staticName[ASN_NAME_MAX];
5813
#if (defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)) && \
5814
    !defined(NO_ASN)
5815
    DecodedName fullName;
5816
    int   entrySz; /* number of entries */
5817
    WOLFSSL_X509_NAME_ENTRY entry[MAX_NAME_ENTRIES]; /* all entries i.e. CN */
5818
    WOLFSSL_X509*           x509;   /* x509 that struct belongs to */
5819
#endif /* OPENSSL_EXTRA */
5820
#ifndef WOLFSSL_NO_CA_NAMES
5821
    byte  raw[ASN_NAME_MAX];
5822
    int   rawLen;
5823
5824
    WOLF_STACK_OF(WOLFSSL_X509_NAME_ENTRY)* entries;
5825
#endif
5826
    void* heap;
5827
};
5828
5829
#ifndef EXTERNAL_SERIAL_SIZE
5830
    #define EXTERNAL_SERIAL_SIZE 32
5831
#endif
5832
5833
#ifdef NO_ASN
5834
    typedef struct DNS_entry DNS_entry;
5835
    #ifndef IGNORE_NAME_CONSTRAINTS
5836
        typedef struct Base_entry Base_entry;
5837
    #endif
5838
#endif
5839
5840
#ifndef WOLFSSL_AIA_ENTRY_DEFINED
5841
#ifndef WOLFSSL_MAX_AIA_ENTRIES
5842
    #define WOLFSSL_MAX_AIA_ENTRIES 8
5843
#endif
5844
5845
#define WOLFSSL_AIA_ENTRY_DEFINED
5846
typedef struct WOLFSSL_AIA_ENTRY {
5847
    word32      method; /* AIA method OID sum (e.g., AIA_OCSP_OID). */
5848
    const byte* uri;    /* Pointer into cert DER for the URI. */
5849
    word32      uriSz;  /* Length of URI data. */
5850
} WOLFSSL_AIA_ENTRY;
5851
#endif /* WOLFSSL_AIA_ENTRY_DEFINED */
5852
5853
struct WOLFSSL_X509 {
5854
    int              version;
5855
    int              serialSz;
5856
#ifdef WOLFSSL_SEP
5857
    int              deviceTypeSz;
5858
    int              hwTypeSz;
5859
    byte             deviceType[EXTERNAL_SERIAL_SIZE];
5860
    byte             hwType[EXTERNAL_SERIAL_SIZE];
5861
    int              hwSerialNumSz;
5862
    byte             hwSerialNum[EXTERNAL_SERIAL_SIZE];
5863
    byte             certPolicySet;
5864
    byte             certPolicyCrit;
5865
#endif /* WOLFSSL_SEP */
5866
#if defined(WOLFSSL_QT) || defined(OPENSSL_ALL) || defined(OPENSSL_EXTRA)
5867
    WOLFSSL_STACK* ext_sk; /* Store X509_EXTENSIONS from wolfSSL_X509_get_ext */
5868
    WOLFSSL_STACK* ext_sk_full; /* Store X509_EXTENSIONS from wolfSSL_X509_get0_extensions */
5869
    WOLFSSL_STACK* ext_d2i;/* Store d2i extensions from wolfSSL_X509_get_ext_d2i */
5870
#endif /* WOLFSSL_QT || OPENSSL_ALL */
5871
#if defined(OPENSSL_EXTRA) || defined(WOLFSSL_WPAS_SMALL)
5872
    WOLFSSL_ASN1_INTEGER* serialNumber; /* Stores SN from wolfSSL_X509_get_serialNumber */
5873
#endif
5874
    WOLFSSL_ASN1_TIME notBefore;
5875
    WOLFSSL_ASN1_TIME notAfter;
5876
    buffer           sig;
5877
    int              sigOID;
5878
    DNS_entry*       altNames;                       /* alt names list */
5879
#ifndef IGNORE_NAME_CONSTRAINTS
5880
    Base_entry*      permittedNames;                 /* name constraints */
5881
    Base_entry*      excludedNames;
5882
    byte             nameConstraintCrit:1;
5883
#endif
5884
    buffer           pubKey;
5885
    int              pubKeyOID;
5886
    DNS_entry*       altNamesNext;                   /* hint for retrieval */
5887
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || defined(HAVE_ED448) || \
5888
    defined(HAVE_FALCON) || defined(WOLFSSL_HAVE_MLDSA) || \
5889
    defined(WOLFSSL_HAVE_SLHDSA)
5890
    word32       pkCurveOID;
5891
#endif
5892
#ifndef NO_CERTS
5893
    DerBuffer*   derCert;                            /* may need  */
5894
#endif
5895
    void*            heap;                           /* heap hint */
5896
    byte             dynamicMemory;                  /* dynamic memory flag */
5897
    byte             isCa:1;
5898
#ifdef WOLFSSL_CERT_EXT
5899
    char             certPolicies[MAX_CERTPOL_NB][MAX_CERTPOL_SZ];
5900
    int              certPoliciesNb;
5901
#endif /* WOLFSSL_CERT_EXT */
5902
#if defined(OPENSSL_EXTRA_X509_SMALL) || defined(OPENSSL_EXTRA)
5903
    wolfSSL_Ref      ref;
5904
#endif
5905
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
5906
#ifdef HAVE_EX_DATA
5907
    WOLFSSL_CRYPTO_EX_DATA ex_data;
5908
#endif
5909
    byte*            authKeyId; /* Points into authKeyIdSrc */
5910
    byte*            authKeyIdSrc;
5911
    byte*            subjKeyId;
5912
    WOLFSSL_ASN1_STRING* subjKeyIdStr;
5913
    byte*            extKeyUsageSrc;
5914
#ifdef OPENSSL_ALL
5915
    byte*            subjAltNameSrc;
5916
#endif
5917
    byte*            rawCRLInfo;
5918
    byte*            CRLInfo;
5919
    byte*            authInfo;
5920
#ifdef WOLFSSL_ASN_CA_ISSUER
5921
    byte*            authInfoCaIssuer;
5922
    int              authInfoCaIssuerSz;
5923
#endif
5924
    WOLFSSL_AIA_ENTRY authInfoList[WOLFSSL_MAX_AIA_ENTRIES];
5925
    byte             authInfoListSz:7;
5926
    byte             authInfoListOverflow:1;
5927
    word32           pathLength;
5928
    word16           keyUsage;
5929
    int              rawCRLInfoSz;
5930
    int              CRLInfoSz;
5931
    int              authInfoSz;
5932
    word32           authKeyIdSz;
5933
    word32           authKeyIdSrcSz;
5934
    word32           subjKeyIdSz;
5935
    byte             extKeyUsage;
5936
    word32           extKeyUsageSz;
5937
    word32           extKeyUsageCount;
5938
#ifndef IGNORE_NETSCAPE_CERT_TYPE
5939
    byte             nsCertType;
5940
#endif
5941
#ifdef OPENSSL_ALL
5942
    word32           subjAltNameSz;
5943
#endif
5944
5945
    byte             CRLdistSet:1;
5946
    byte             CRLdistCrit:1;
5947
    byte             authInfoSet:1;
5948
    byte             authInfoCrit:1;
5949
    byte             keyUsageSet:1;
5950
    byte             keyUsageCrit:1;
5951
    byte             extKeyUsageCrit:1;
5952
    byte             subjKeyIdSet:1;
5953
    byte             pathLengthSet:1;
5954
5955
    byte             subjKeyIdCrit:1;
5956
    byte             basicConstSet:1;
5957
    byte             basicConstCrit:1;
5958
    byte             basicConstPlSet:1;
5959
    byte             subjAltNameSet:1;
5960
    byte             subjAltNameCrit:1;
5961
    byte             authKeyIdSet:1;
5962
    byte             authKeyIdCrit:1;
5963
    byte             issuerSet:1;
5964
#ifdef WOLFSSL_CUSTOM_OID
5965
    CertExtension    custom_exts[NUM_CUSTOM_EXT];
5966
    int              customExtCount;
5967
#endif /* WOLFSSL_CUSTOM_OID */
5968
#endif /* OPENSSL_EXTRA || OPENSSL_EXTRA_X509_SMALL */
5969
#ifdef WOLFSSL_CERT_REQ
5970
    byte             isCSR:1;
5971
#endif
5972
    byte             serial[EXTERNAL_SERIAL_SIZE];
5973
    char             subjectCN[ASN_NAME_MAX];        /* common name short cut */
5974
#if defined(WOLFSSL_CERT_REQ) || defined(WOLFSSL_CERT_GEN)
5975
#if defined(OPENSSL_ALL) || defined(OPENSSL_EXTRA)
5976
    /* stack of CSR attributes */
5977
    WOLF_STACK_OF(WOLFSSL_X509_ATRIBUTE)* reqAttributes;
5978
#endif
5979
    #if defined(WOLFSSL_CERT_REQ)
5980
    char             challengePw[CTC_NAME_SIZE]; /* for REQ certs */
5981
    char             contentType[CTC_NAME_SIZE];
5982
    #endif
5983
#endif /* WOLFSSL_CERT_REQ || WOLFSSL_CERT_GEN */
5984
    WOLFSSL_X509_NAME issuer;
5985
    WOLFSSL_X509_NAME subject;
5986
#if defined(OPENSSL_ALL) || defined(OPENSSL_EXTRA) || \
5987
    defined(OPENSSL_EXTRA_X509_SMALL) || defined(WOLFSSL_APACHE_HTTPD) || \
5988
    defined(WOLFSSL_HAPROXY) || defined(WOLFSSL_WPAS)
5989
    WOLFSSL_X509_ALGOR algor;
5990
    WOLFSSL_X509_PUBKEY key;
5991
#endif
5992
#if defined(OPENSSL_EXTRA_X509_SMALL) || defined(OPENSSL_EXTRA) || \
5993
    defined(OPENSSL_ALL) || defined(KEEP_OUR_CERT) || \
5994
    defined(KEEP_PEER_CERT) || defined(SESSION_CERTS)
5995
    byte            notBeforeData[CTC_DATE_SIZE];
5996
    byte            notAfterData[CTC_DATE_SIZE];
5997
#endif
5998
#ifdef WOLFSSL_DUAL_ALG_CERTS
5999
    /* Subject Alternative Public Key Info */
6000
    byte *sapkiDer;
6001
    int sapkiLen;
6002
    /* Alternative Signature Algorithm */
6003
    byte *altSigAlgDer;
6004
    int altSigAlgLen;
6005
    /* Alternative Signature Value */
6006
    byte *altSigValDer;
6007
    int altSigValLen;
6008
6009
    byte sapkiCrit:1;
6010
    byte altSigAlgCrit:1;
6011
    byte altSigValCrit:1;
6012
#endif /* WOLFSSL_DUAL_ALG_CERTS */
6013
};
6014
6015
#if defined(WOLFSSL_ACERT)
6016
struct WOLFSSL_X509_ACERT {
6017
    int               version;
6018
    int               serialSz;
6019
    byte              serial[EXTERNAL_SERIAL_SIZE];
6020
    WOLFSSL_ASN1_TIME notBefore;
6021
    WOLFSSL_ASN1_TIME notAfter;
6022
    buffer            sig;
6023
    int               sigOID;
6024
#ifndef NO_CERTS
6025
    DerBuffer *       derCert;
6026
#endif
6027
    void *            heap;
6028
    int               dynamic; /* whether struct was dynamically allocated */
6029
    /* copy of raw Attributes field from */
6030
    byte              holderSerial[EXTERNAL_SERIAL_SIZE];
6031
    int               holderSerialSz;
6032
    DNS_entry *       holderEntityName;  /* Holder entityName from ACERT */
6033
    DNS_entry *       holderIssuerName;  /* issuerName from ACERT */
6034
    DNS_entry *       AttCertIssuerName; /* AttCertIssuer name from ACERT */
6035
    byte *            rawAttr;
6036
    word32            rawAttrLen;
6037
};
6038
#endif /* WOLFSSL_ACERT */
6039
6040
/* record layer header for PlainText, Compressed, and CipherText */
6041
typedef struct RecordLayerHeader {
6042
    byte            type;
6043
    byte            pvMajor;
6044
    byte            pvMinor;
6045
    byte            length[2];
6046
} RecordLayerHeader;
6047
6048
6049
/* record layer header for DTLS PlainText, Compressed, and CipherText */
6050
typedef struct DtlsRecordLayerHeader {
6051
    byte            type;
6052
    byte            pvMajor;
6053
    byte            pvMinor;
6054
    byte            sequence_number[8];   /* per record */
6055
    byte            length[2];
6056
} DtlsRecordLayerHeader;
6057
6058
typedef struct DtlsFragBucket {
6059
    /* m stands for meta */
6060
    union {
6061
        struct {
6062
            struct DtlsFragBucket* next;
6063
            word32 offset;
6064
            word32 sz;
6065
        } m;
6066
        /* Make sure we have at least DTLS_HANDSHAKE_HEADER_SZ bytes before the
6067
         * buf so that we can reconstruct the header in the allocated
6068
         * DtlsFragBucket buffer. */
6069
        byte padding[DTLS_HANDSHAKE_HEADER_SZ];
6070
    } m;
6071
/* Ignore "nonstandard extension used : zero-sized array in struct/union"
6072
 * MSVC warning */
6073
#ifdef _MSC_VER
6074
#pragma warning(disable: 4200)
6075
#endif
6076
    byte buf[WC_FLEXIBLE_ARRAY_SIZE];
6077
} DtlsFragBucket;
6078
6079
typedef struct DtlsMsg {
6080
    struct DtlsMsg* next;
6081
    byte*           raw;
6082
    byte*           fullMsg;   /* for TX fullMsg == raw. For RX this points to
6083
                                * the start of the message after headers. */
6084
    DtlsFragBucket* fragBucketList;
6085
    word32          bytesReceived;
6086
    word16          epoch;     /* Epoch that this message belongs to */
6087
    word32          seq;       /* Handshake sequence number    */
6088
    word32          sz;        /* Length of whole message      */
6089
    byte            type;
6090
    byte            fragBucketListCount;
6091
    byte            ready:1;
6092
    byte            encrypted:1;
6093
} DtlsMsg;
6094
6095
6096
#ifdef HAVE_NETX
6097
6098
    /* NETX I/O Callback default */
6099
    typedef struct NetX_Ctx {
6100
        NX_TCP_SOCKET* nxTcpSocket; /* send/recv tcp socket handle */
6101
        NX_PACKET*     nxPacket;    /* incoming packet handle for short reads */
6102
        ULONG          nxOffset;    /* offset already read from nxPacket */
6103
        ULONG          nxWait;      /* wait option flag */
6104
/* WOLFSSL_NETX_DUO: requires ThreadX NetX Duo (NXD_ADDRESS, nxd_udp_socket_send) */
6105
#if defined(WOLFSSL_DTLS) && defined(WOLFSSL_NETX_DUO)
6106
        NX_UDP_SOCKET* nxUdpSocket; /* send/recv udp socket handle */
6107
        NXD_ADDRESS    nxdIp;       /* destination IP address for udp send */
6108
        USHORT         nxPort;      /* destination port for udp send */
6109
#endif /* WOLFSSL_DTLS && WOLFSSL_NETX_DUO */
6110
    } NetX_Ctx;
6111
6112
#endif
6113
6114
/* Handshake messages received from peer (plus change cipher */
6115
typedef struct MsgsReceived {
6116
    word16 got_hello_request:1;
6117
    word16 got_client_hello:2;
6118
    word16 got_server_hello:1;
6119
    word16 got_hello_verify_request:1;
6120
    word16 got_session_ticket:1;
6121
    word16 got_end_of_early_data:1;
6122
    word16 got_hello_retry_request:1;
6123
    word16 got_encrypted_extensions:1;
6124
    word16 got_certificate:1;
6125
    word16 got_certificate_status:1;
6126
    word16 got_server_key_exchange:1;
6127
    word16 got_certificate_request:1;
6128
    word16 got_server_hello_done:1;
6129
    word16 got_certificate_verify:1;
6130
    word16 got_client_key_exchange:1;
6131
    word16 got_finished:1;
6132
    word16 got_key_update:1;
6133
    word16 got_change_cipher:1;
6134
} MsgsReceived;
6135
6136
6137
/* Handshake hashes */
6138
typedef struct HS_Hashes {
6139
    Hashes          verifyHashes;
6140
    Hashes          certHashes;         /* for cert verify */
6141
#if !defined(NO_SHA) && (!defined(NO_OLD_TLS) || \
6142
                          defined(WOLFSSL_ALLOW_TLS_SHA1))
6143
    wc_Sha          hashSha;            /* sha hash of handshake msgs */
6144
#endif
6145
#if !defined(NO_MD5) && !defined(NO_OLD_TLS)
6146
    wc_Md5          hashMd5;            /* md5 hash of handshake msgs */
6147
#endif
6148
#ifndef NO_SHA256
6149
    wc_Sha256       hashSha256;         /* sha256 hash of handshake msgs */
6150
#endif
6151
#ifdef WOLFSSL_SHA384
6152
    wc_Sha384       hashSha384;         /* sha384 hash of handshake msgs */
6153
#endif
6154
#ifdef WOLFSSL_SHA512
6155
    wc_Sha512       hashSha512;         /* sha512 hash of handshake msgs */
6156
#endif
6157
#ifdef WOLFSSL_SM3
6158
    wc_Sm3          hashSm3;            /* sm3 hash of handshake msgs */
6159
#endif
6160
#if (defined(HAVE_ED25519) || defined(HAVE_ED448) || \
6161
     (defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3))) && \
6162
    !defined(WOLFSSL_NO_CLIENT_AUTH)
6163
    byte*           messages;           /* handshake messages */
6164
    int             length;             /* length of handshake messages' data */
6165
    int             prevLen;            /* length of messages but last */
6166
#endif
6167
} HS_Hashes;
6168
6169
6170
#ifndef WOLFSSL_NO_TLS12
6171
/* Persistable BuildMessage arguments */
6172
typedef struct BuildMsgArgs {
6173
    word32 digestSz;
6174
    word32 sz;
6175
    word32 pad;
6176
    word32 idx;
6177
    word32 headerSz;
6178
    word16 size;
6179
    word32 ivSz;      /* TLSv1.1  IV */
6180
    byte   type;
6181
    byte*  iv;
6182
    ALIGN16 byte staticIvBuffer[MAX_IV_SZ];
6183
} BuildMsgArgs;
6184
#endif
6185
6186
#ifdef WOLFSSL_ASYNC_IO
6187
    #define MAX_ASYNC_ARGS 24
6188
    typedef void (*FreeArgsCb)(struct WOLFSSL* ssl, void* pArgs);
6189
6190
    struct WOLFSSL_ASYNC {
6191
#if defined(WOLFSSL_ASYNC_CRYPT) && !defined(WOLFSSL_NO_TLS12)
6192
        BuildMsgArgs  buildArgs; /* holder for current BuildMessage args */
6193
#endif
6194
        FreeArgsCb    freeArgs; /* function pointer to cleanup args */
6195
#ifdef WC_NO_PTR_INT_CAST
6196
        max_align_t args[MAX_ASYNC_ARGS * sizeof(word32) / sizeof(max_align_t)]; /* holder for current args */
6197
#else
6198
        word32        args[MAX_ASYNC_ARGS]; /* holder for current args */
6199
#endif
6200
    };
6201
#endif
6202
6203
#ifdef HAVE_WRITE_DUP
6204
6205
    #define WRITE_DUP_SIDE 1
6206
    #define READ_DUP_SIDE 2
6207
6208
    typedef struct WriteDup {
6209
        wolfSSL_Mutex   dupMutex;       /* field access mutex */
6210
        int             dupCount;       /* reference count */
6211
        int             dupErr;         /* under dupMutex, pass to other side */
6212
#ifdef WOLFSSL_DTLS13
6213
        struct Dtls13RecordNumber* sendAckList; /* ownership transferred */
6214
        /* Key update ACK tracking: write side stores the (epoch, seq) of its
6215
         * in-flight KeyUpdate; read side sets keyUpdateAcked when the ACK for
6216
         * that exact record arrives.  Both epoch and seq are checked to avoid
6217
         * false positives from data records in the same epoch. */
6218
        w64wrapper keyUpdateEpoch;     /* epoch of the KeyUpdate */
6219
        w64wrapper keyUpdateSeq;       /* seq num of the KeyUpdate */
6220
#endif /* WOLFSSL_DTLS13 */
6221
#ifdef WOLFSSL_TLS13
6222
#ifdef WOLFSSL_POST_HANDSHAKE_AUTH
6223
        /* Post-handshake certificate request delegation: the read side received
6224
         * a CertificateRequest but cannot write; it saves state here and the
6225
         * write side sends Certificate+CertificateVerify+Finished. */
6226
        struct HS_Hashes* postHandshakeHashState;    /* transcript at CR time */
6227
        struct CertReqCtx* postHandshakeCertReqCtx; /* context from CR */
6228
        byte postHandshakeSendVerify;    /* ssl->options.sendVerify */
6229
        byte postHandshakeSigAlgo;       /* ssl->options.sigAlgo */
6230
        byte postHandshakeHashAlgo;      /* ssl->options.hashAlgo */
6231
#if !defined(NO_CERTS) && !defined(WOLFSSL_NO_SIGALG)
6232
        byte postHandshakeSha1CertOk;    /* ssl->options.peerSha1CertOk */
6233
#endif
6234
        /* After the write side sends the PHA response, it stores its updated
6235
         * transcript here so the read side can resume from it on the next
6236
         * CertificateRequest (keeps client/server transcript in sync). */
6237
        struct HS_Hashes* postHandshakeSyncedHashState;
6238
#endif /* WOLFSSL_POST_HANDSHAKE_AUTH */
6239
#endif /* WOLFSSL_TLS13 */
6240
6241
        /* Flags */
6242
#ifdef WOLFSSL_DTLS13
6243
        WC_BITFIELD keyUpdateWaiting:1; /* write side has an unACKed KeyUpdate */
6244
        WC_BITFIELD keyUpdateAcked:1;   /* read side confirmed the ACK arrived */
6245
        /* DTLS 1.3: read side cannot write, so it passes ACK work to the
6246
         * write side. */
6247
        WC_BITFIELD sendAcks:1;
6248
#endif /* WOLFSSL_DTLS13 */
6249
#ifdef WOLFSSL_TLS13
6250
        /* TLS 1.3 (and DTLS 1.3): read side received a KeyUpdate(update_requested)
6251
         * but cannot send the response; write side handles it. */
6252
        WC_BITFIELD keyUpdateRespond:1; /* write side must send a KeyUpdate response */
6253
#ifdef WOLFSSL_POST_HANDSHAKE_AUTH
6254
        WC_BITFIELD postHandshakeAuthPending:1; /* write side must respond */
6255
#endif /* WOLFSSL_POST_HANDSHAKE_AUTH */
6256
#endif /* WOLFSSL_TLS13 */
6257
    } WriteDup;
6258
6259
    WOLFSSL_LOCAL void FreeWriteDup(WOLFSSL* ssl);
6260
    WOLFSSL_LOCAL int  NotifyWriteSide(WOLFSSL* ssl, int err);
6261
#endif /* HAVE_WRITE_DUP */
6262
6263
#if defined(WOLFSSL_TLS13) && defined(WOLFSSL_POST_HANDSHAKE_AUTH)
6264
typedef struct CertReqCtx CertReqCtx;
6265
6266
struct CertReqCtx {
6267
    CertReqCtx* next;
6268
    byte        len;
6269
    byte        ctx;
6270
};
6271
#endif
6272
6273
#ifdef WOLFSSL_EARLY_DATA
6274
typedef enum EarlyDataState {
6275
    no_early_data,
6276
    early_data_ext,
6277
    expecting_early_data,
6278
    process_early_data,
6279
    done_early_data
6280
} EarlyDataState;
6281
#endif
6282
6283
#ifdef WOLFSSL_DTLS13
6284
6285
/* size of the mask used to encrypt/decrypt Record Number  */
6286
#define DTLS13_RN_MASK_SIZE 16
6287
6288
typedef struct Dtls13UnifiedHdrInfo {
6289
    word16 recordLength;
6290
    byte seqLo;
6291
    byte seqHi;
6292
    byte seqHiPresent:1;
6293
    byte epochBits;
6294
} Dtls13UnifiedHdrInfo;
6295
6296
enum  {
6297
    DTLS13_EPOCH_EARLYDATA = 1,
6298
    DTLS13_EPOCH_HANDSHAKE = 2,
6299
    DTLS13_EPOCH_TRAFFIC0 = 3
6300
};
6301
6302
/* Sender-side DTLS 1.3 epoch ceiling: we MUST NOT advance our own epoch past
6303
 * 2^48-1 (RFC 9147 Section 4.2.1). This gates only the sending epoch; receivers
6304
 * MUST NOT enforce it on the peer epoch (RFC 9147 Section 8). Expressed as the
6305
 * high/low 32-bit halves of a w64wrapper. */
6306
#define DTLS13_EPOCH_MAX_HI32 0x0000FFFFU
6307
#define DTLS13_EPOCH_MAX_LO32 0xFFFFFFFFU
6308
6309
/* 64-bit epoch + 64-bit sequence number */
6310
#define DTLS13_RN_SIZE (OPAQUE64_LEN + OPAQUE64_LEN)
6311
/* Maximum number of ACK records allowed in an ACK message */
6312
#ifndef DTLS13_ACK_MAX_RECORDS
6313
#define DTLS13_ACK_MAX_RECORDS 128
6314
#endif
6315
/* WOLFSSL_MAX_16BIT / DTLS13_RN_SIZE (0xffff / (OPAQUE64_LEN + OPAQUE64_LEN))
6316
 * Literals are used because OPAQUE64_LEN is an enum value, invisible to the
6317
 * preprocessor. */
6318
#if DTLS13_ACK_MAX_RECORDS > 0xffff / 16
6319
#error "DTLS13_ACK_MAX_RECORDS exceeds the maximum encodable in the word16 length field"
6320
#endif
6321
6322
6323
typedef struct Dtls13Epoch {
6324
    w64wrapper epochNumber;
6325
6326
    w64wrapper nextSeqNumber;
6327
    w64wrapper nextPeerSeqNumber;
6328
6329
#ifndef WOLFSSL_TLS13_IGNORE_AEAD_LIMITS
6330
    w64wrapper dropCount; /* Amount of records that failed decryption */
6331
#endif
6332
6333
    word32 window[WOLFSSL_DTLS_WINDOW_WORDS];
6334
6335
    /* key material for the epoch */
6336
    byte client_write_key[MAX_SYM_KEY_SIZE];
6337
    byte server_write_key[MAX_SYM_KEY_SIZE];
6338
    byte client_write_IV[MAX_WRITE_IV_SZ];
6339
    byte server_write_IV[MAX_WRITE_IV_SZ];
6340
6341
    byte aead_exp_IV[AEAD_MAX_EXP_SZ];
6342
    byte aead_enc_imp_IV[AEAD_MAX_IMP_SZ];
6343
    byte aead_dec_imp_IV[AEAD_MAX_IMP_SZ];
6344
6345
    byte client_sn_key[MAX_SYM_KEY_SIZE];
6346
    byte server_sn_key[MAX_SYM_KEY_SIZE];
6347
6348
    byte isValid;
6349
    byte side;
6350
} Dtls13Epoch;
6351
6352
#ifndef DTLS13_EPOCH_SIZE
6353
#define DTLS13_EPOCH_SIZE 4
6354
#endif
6355
6356
/* our epoch, peer epoch, peer epoch - 1 and a free slot for a new epoch */
6357
#if DTLS13_EPOCH_SIZE < 4
6358
#error "DTLS13_EPOCH_SIZE must be at least 4"
6359
#endif
6360
6361
#ifndef DTLS13_RETRANS_RN_SIZE
6362
#define DTLS13_RETRANS_RN_SIZE 3
6363
#endif
6364
6365
enum Dtls13RtxFsmState {
6366
    DTLS13_RTX_FSM_PREPARING = 0,
6367
    DTLS13_RTX_FSM_SENDING,
6368
    DTLS13_RTX_FSM_WAITING,
6369
    DTLS13_RTX_FSM_FINISHED
6370
};
6371
6372
typedef struct Dtls13RtxRecord {
6373
    struct Dtls13RtxRecord *next;
6374
    word16 length;
6375
    byte *data;
6376
    w64wrapper epoch;
6377
    w64wrapper seq[DTLS13_RETRANS_RN_SIZE];
6378
    byte rnIdx;
6379
    byte handshakeType;
6380
} Dtls13RtxRecord;
6381
6382
typedef struct Dtls13RecordNumber {
6383
    struct Dtls13RecordNumber *next;
6384
    w64wrapper epoch;
6385
    w64wrapper seq;
6386
} Dtls13RecordNumber;
6387
6388
typedef struct Dtls13Rtx {
6389
#ifdef WOLFSSL_RW_THREADED
6390
    wolfSSL_Mutex mutex;
6391
#endif
6392
    enum Dtls13RtxFsmState state; /* Unused? */
6393
    Dtls13RtxRecord *rtxRecords;
6394
    Dtls13RtxRecord **rtxRecordTailPtr;
6395
    Dtls13RecordNumber *seenRecords;
6396
    word16 seenRecordsCount;
6397
#ifdef WOLFSSL_32BIT_MILLI_TIME
6398
    word32 lastRtx;
6399
#else
6400
    sword64 lastRtx;
6401
#endif
6402
    byte triggeredRtxs; /* Unused? */
6403
    byte sendAcks;
6404
    byte retransmit;
6405
} Dtls13Rtx;
6406
6407
#endif /* WOLFSSL_DTLS13 */
6408
6409
#ifdef WOLFSSL_DTLS_CID
6410
typedef struct ConnectionID {
6411
    byte length;
6412
/* Ignore "nonstandard extension used : zero-sized array in struct/union"
6413
 * MSVC warning */
6414
#ifdef _MSC_VER
6415
#pragma warning(disable: 4200)
6416
#endif
6417
    byte id[];
6418
} ConnectionID;
6419
6420
typedef struct CIDInfo {
6421
    ConnectionID* tx;
6422
    ConnectionID* rx;
6423
    byte negotiated : 1;
6424
} CIDInfo;
6425
6426
/* ConnectionIdUsage of the NewConnectionId message (RFC 9147 Section 9) */
6427
enum ConnectionIdUsage {
6428
    cid_immediate = 0,
6429
    cid_spare     = 1
6430
};
6431
#endif /* WOLFSSL_DTLS_CID */
6432
6433
/* The idea is to reuse the context suites object whenever possible to save
6434
 * space. */
6435
#define WOLFSSL_SUITES(ssl) \
6436
0
    ((const Suites*) ((ssl)->suites != NULL ? \
6437
0
        (ssl)->suites : \
6438
0
        (ssl)->ctx->suites))
6439
6440
/* wolfSSL ssl type */
6441
struct WOLFSSL {
6442
    WOLFSSL_CTX*    ctx;
6443
#if defined(WOLFSSL_HAPROXY)
6444
    WOLFSSL_CTX*    initial_ctx; /* preserve session key materials */
6445
#endif
6446
    Suites*         suites; /* Only need during handshake. Can be NULL when
6447
                             * reusing the context's object. When WOLFSSL
6448
                             * object needs separate instance of suites use
6449
                             * AllocateSuites(). */
6450
    Suites*         clSuites;
6451
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_ALL) || \
6452
    defined(WOLFSSL_NGINX) || defined(WOLFSSL_HAPROXY)
6453
    WOLF_STACK_OF(WOLFSSL_CIPHER)* suitesStack; /* stack of available cipher
6454
                                                 * suites */
6455
    WOLF_STACK_OF(WOLFSSL_CIPHER)* clSuitesStack; /* stack of client cipher
6456
                                                   * suites */
6457
#endif
6458
    Arrays*         arrays;
6459
    /* Buffer used to reassemble a handshake message that is fragmented across
6460
     * multiple records. Kept in WOLFSSL (not Arrays) so that post-handshake
6461
     * messages (e.g. a TLS 1.3 NewSessionTicket) can still be defragmented
6462
     * after the handshake arrays have been released by FreeArrays(). */
6463
    byte*           pendingMsg;         /* defrag buffer */
6464
    word32          pendingMsgSz;       /* defrag buffer size */
6465
    word32          pendingMsgOffset;   /* current offset into defrag buffer */
6466
    byte            pendingMsgType;     /* defrag buffer message type */
6467
#ifdef WOLFSSL_TLS13
6468
    byte            clientSecret[SECRET_LEN];
6469
    byte            serverSecret[SECRET_LEN];
6470
#endif
6471
    HS_Hashes*      hsHashes;
6472
#if defined(WOLFSSL_TLS13) && defined(HAVE_ECH)
6473
    HS_Hashes*      hsHashesEch;
6474
#endif
6475
    void*           IOCB_ReadCtx;
6476
    void*           IOCB_WriteCtx;
6477
    WC_RNG*         rng;
6478
    void*           verifyCbCtx;        /* cert verify callback user ctx*/
6479
    VerifyCallback  verifyCallback;     /* cert verification callback */
6480
    void*           heap;               /* for user overrides */
6481
#ifdef HAVE_WRITE_DUP
6482
    WriteDup*       dupWrite;           /* valid pointer indicates ON */
6483
             /* side that decrements dupCount to zero frees overall structure */
6484
    byte            dupSide;            /* write side or read side */
6485
#endif
6486
#ifdef OPENSSL_EXTRA
6487
    byte              cbioFlag;         /* WOLFSSL_CBIO_RECV/SEND:
6488
                                         * CBIORecv/Send is set */
6489
#endif
6490
#ifdef WOLFSSL_WOLFSENTRY_HOOKS
6491
    NetworkFilterCallback_t AcceptFilter;
6492
    void *AcceptFilter_arg;
6493
    NetworkFilterCallback_t ConnectFilter;
6494
    void *ConnectFilter_arg;
6495
#endif /* WOLFSSL_WOLFSENTRY_HOOKS */
6496
    CallbackIORecv  CBIORecv;
6497
    CallbackIOSend  CBIOSend;
6498
#ifdef WOLFSSL_STATIC_MEMORY
6499
    WOLFSSL_HEAP_HINT heap_hint;
6500
#endif
6501
#if defined(WOLFSSL_DTLS) && !defined(NO_WOLFSSL_SERVER)
6502
    ClientHelloGoodCb chGoodCb;        /* notify user we parsed a verified
6503
                                        * ClientHello that passed basic tests */
6504
    void*             chGoodCtx;       /* user ClientHello cb context  */
6505
#endif
6506
#ifndef NO_HANDSHAKE_DONE_CB
6507
    HandShakeDoneCb hsDoneCb;          /* notify user handshake done */
6508
    void*           hsDoneCtx;         /* user handshake cb context  */
6509
#endif
6510
#ifdef WOLFSSL_ASYNC_IO
6511
#ifdef WOLFSSL_ASYNC_CRYPT
6512
    WC_ASYNC_DEV* asyncDev;
6513
#endif
6514
    /* Message building context should be stored here for functions that expect
6515
     * to encounter encryption blocking or fragment the message. */
6516
    struct WOLFSSL_ASYNC* async;
6517
#endif
6518
    void*           hsKey;              /* Handshake key (RsaKey or ecc_key)
6519
                                         * allocated from heap */
6520
    word32          hsType;             /* Type of Handshake key (hsKey) */
6521
    WOLFSSL_CIPHER  cipher;
6522
#ifdef WOLFSSL_DUAL_ALG_CERTS
6523
    void*           hsAltKey;           /* Handshake key (ML-DSA, falcon)
6524
                                         * allocated from heap */
6525
    word32          hsAltType;          /* Type of Handshake key (hsAltKey) */
6526
#endif
6527
#ifndef WOLFSSL_AEAD_ONLY
6528
    hmacfp          hmac;
6529
#endif
6530
    Ciphers         encrypt;
6531
    Ciphers         decrypt;
6532
    Buffers         buffers;
6533
    WOLFSSL_SESSION* session;
6534
#ifndef NO_CLIENT_CACHE
6535
    ClientSession*  clientSession;
6536
#endif
6537
    WOLFSSL_ALERT_HISTORY alert_history;
6538
    WOLFSSL_ALERT   pendingAlert;
6539
    int             error;
6540
    int             rfd;                /* read  file descriptor */
6541
    int             wfd;                /* write file descriptor */
6542
    int             rflags;             /* user read  flags */
6543
    int             wflags;             /* user write flags */
6544
    word32          timeout;            /* session timeout */
6545
    word32          fragOffset;         /* fragment offset */
6546
    word16          curSize;
6547
    word32          curStartIdx;
6548
    byte            verifyDepth;
6549
    RecordLayerHeader curRL;
6550
    MsgsReceived    msgsReceived;       /* peer messages received */
6551
    ProtocolVersion version;            /* negotiated version */
6552
    ProtocolVersion chVersion;          /* client hello version */
6553
    CipherSpecs     specs;
6554
    Keys            keys;
6555
    Options         options;
6556
#ifdef WOLFSSL_SESSION_ID_CTX
6557
    byte             sessionCtx[ID_LEN]; /* app session context ID */
6558
    byte             sessionCtxSz;       /* size of sessionCtx stored */
6559
#endif
6560
#ifdef OPENSSL_EXTRA
6561
    CallbackInfoState* CBIS;             /* used to get info about SSL state */
6562
    int              cbmode;             /* read or write on info callback */
6563
    int              cbtype;             /* event type in info callback */
6564
    WOLFSSL_BIO*     biord;              /* socket bio read  to free/close */
6565
    WOLFSSL_BIO*     biowr;              /* socket bio write to free/close */
6566
    WOLFSSL_X509_VERIFY_PARAM* param;    /* verification parameters*/
6567
#endif
6568
#if defined(OPENSSL_EXTRA) || defined(HAVE_CURL)
6569
    word32            disabledCurves;   /* curves disabled by user */
6570
#endif
6571
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL) || \
6572
    defined(OPENSSL_ALL)
6573
    unsigned long    peerVerifyRet;
6574
#endif
6575
#if defined(OPENSSL_EXTRA) || defined(WOLFSSL_TLS_READ_AHEAD)
6576
    byte             readAhead;
6577
    /* Read-ahead coalescing buffer size; 0 = one record (default). */
6578
    word32           readAheadSz;
6579
#endif
6580
#ifdef OPENSSL_EXTRA
6581
#ifdef HAVE_PK_CALLBACKS
6582
    void*            loggingCtx;         /* logging callback argument */
6583
#endif
6584
#endif /* OPENSSL_EXTRA */
6585
#ifndef NO_RSA
6586
    RsaKey*         peerRsaKey;
6587
#if defined(WOLFSSL_RENESAS_TSIP_TLS) || defined(WOLFSSL_RENESAS_FSPSM_TLS)
6588
    void*           RenesasUserCtx;
6589
    byte*           peerSceTsipEncRsaKeyIndex;
6590
#endif
6591
    byte            peerRsaKeyPresent;
6592
#ifdef WC_RSA_PSS
6593
    word8           useRsaPss;           /* cert supports RSA-PSS */
6594
#endif
6595
#endif
6596
#if defined(WOLFSSL_TLS13) || defined(HAVE_FFDHE)
6597
    word16          namedGroup;
6598
#endif
6599
#ifdef WOLFSSL_TLS13
6600
    word16          group[WOLFSSL_MAX_GROUP_COUNT];
6601
    byte            numGroups;
6602
#endif
6603
    word16          pssAlgo;
6604
#ifdef WOLFSSL_TLS13
6605
    word16          certHashSigAlgoSz;  /* SigAlgoCert ext length in bytes */
6606
    byte            certHashSigAlgo[WOLFSSL_MAX_SIGALGO]; /* cert sig/algo to
6607
                                                           * offer */
6608
#endif
6609
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || defined(HAVE_ED448)
6610
    int             eccVerifyRes;
6611
#endif
6612
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || defined(HAVE_CURVE25519) || \
6613
    defined(HAVE_ED448) || defined(HAVE_CURVE448)
6614
    word32          ecdhCurveOID;            /* curve Ecc_Sum     */
6615
    ecc_key*        eccTempKey;              /* private ECDHE key */
6616
    byte            eccTempKeyPresent;       /* also holds type */
6617
    byte            peerEccKeyPresent;
6618
#endif
6619
#ifdef HAVE_ECC
6620
    ecc_key*        peerEccKey;              /* peer's  ECDHE key */
6621
    ecc_key*        peerEccDsaKey;           /* peer's  ECDSA key */
6622
    word16          eccTempKeySz;            /* in octets 20 - 66 */
6623
    byte            peerEccDsaKeyPresent;
6624
#endif
6625
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || \
6626
    defined(HAVE_CURVE448) || defined(HAVE_ED448) || \
6627
    defined(HAVE_FALCON) || defined(WOLFSSL_HAVE_MLDSA) || \
6628
    defined(WOLFSSL_HAVE_SLHDSA)
6629
    word32          pkCurveOID;              /* curve Ecc_Sum     */
6630
#endif
6631
#ifdef HAVE_ED25519
6632
    ed25519_key*    peerEd25519Key;
6633
    byte            peerEd25519KeyPresent;
6634
#endif
6635
#ifdef HAVE_CURVE25519
6636
    curve25519_key* peerX25519Key;
6637
    byte            peerX25519KeyPresent;
6638
#endif
6639
#ifdef HAVE_ED448
6640
    ed448_key*      peerEd448Key;
6641
    byte            peerEd448KeyPresent;
6642
#endif
6643
#ifdef HAVE_CURVE448
6644
    curve448_key*   peerX448Key;
6645
    byte            peerX448KeyPresent;
6646
#endif
6647
#ifdef HAVE_FALCON
6648
    falcon_key*     peerFalconKey;
6649
    byte            peerFalconKeyPresent;
6650
#endif
6651
#ifdef WOLFSSL_HAVE_MLDSA
6652
    wc_MlDsaKey*    peerMlDsaKey;
6653
    byte            peerMlDsaKeyPresent;
6654
#endif
6655
#ifdef WOLFSSL_HAVE_SLHDSA
6656
    SlhDsaKey*      peerSlhDsaKey;
6657
    byte            peerSlhDsaKeyPresent;
6658
#endif
6659
#ifdef HAVE_LIBZ
6660
    z_stream        c_stream;           /* compression   stream */
6661
    z_stream        d_stream;           /* decompression stream */
6662
    byte            didStreamInit;      /* for stream init and end */
6663
#endif
6664
#ifdef WOLFSSL_DTLS
6665
    int             dtls_timeout_init;  /* starting timeout value */
6666
    int             dtls_timeout_max;   /* maximum timeout value */
6667
    int             dtls_timeout;       /* current timeout value, changes */
6668
#ifndef NO_ASN_TIME
6669
    word32          dtls_start_timeout;
6670
#endif /* !NO_ASN_TIME */
6671
    word32          dtls_tx_msg_list_sz;
6672
    word32          dtls_rx_msg_list_sz;
6673
    DtlsMsg*        dtls_tx_msg_list;
6674
    DtlsMsg*        dtls_tx_msg;
6675
    DtlsMsg*        dtls_rx_msg_list;
6676
    void*           IOCB_CookieCtx;     /* gen cookie ctx */
6677
#ifdef WOLFSSL_SESSION_EXPORT
6678
    wc_dtls_export  dtls_export;        /* export function for session */
6679
#endif
6680
#if defined(WOLFSSL_SCTP) || defined(WOLFSSL_DTLS_MTU)
6681
    word16          dtlsMtuSz;
6682
#endif /* WOLFSSL_SCTP || WOLFSSL_DTLS_MTU */
6683
#ifdef WOLFSSL_MULTICAST
6684
    void*           mcastHwCbCtx;       /* Multicast highwater callback ctx */
6685
#endif /* WOLFSSL_MULTICAST */
6686
#ifdef WOLFSSL_DTLS_DROP_STATS
6687
    word32 macDropCount;
6688
    word32 replayDropCount;
6689
#endif /* WOLFSSL_DTLS_DROP_STATS */
6690
#ifdef WOLFSSL_SRTP
6691
    word16         dtlsSrtpProfiles;   /* DTLS-with-SRTP profiles list
6692
                                        * (selected profiles - up to 16) */
6693
    word16         dtlsSrtpId;         /* DTLS-with-SRTP profile ID selected */
6694
#endif
6695
#ifdef WOLFSSL_DTLS13
6696
    RecordNumberCiphers dtlsRecordNumberEncrypt;
6697
    RecordNumberCiphers dtlsRecordNumberDecrypt;
6698
    Dtls13Epoch dtls13Epochs[DTLS13_EPOCH_SIZE];
6699
    Dtls13Epoch *dtls13EncryptEpoch;
6700
    Dtls13Epoch *dtls13DecryptEpoch;
6701
    w64wrapper dtls13Epoch;
6702
    w64wrapper dtls13PeerEpoch;
6703
    w64wrapper dtls13InvalidateBefore;
6704
    byte dtls13CurRL[DTLS_RECVD_RL_HEADER_MAX_SZ];
6705
    word16 dtls13CurRlLength;
6706
6707
    /* used to store the message if it needs to be fragmented */
6708
    buffer dtls13FragmentsBuffer;
6709
    byte dtls13SendingFragments:1;
6710
    byte dtls13SendingAckOrRtx;
6711
    byte dtls13FastTimeout:1;
6712
#ifdef HAVE_WRITE_DUP
6713
    byte dtls13KeyUpdateAcked:1;
6714
#endif
6715
    byte dtls13WaitKeyUpdateAck;
6716
    byte dtls13DoKeyUpdate;
6717
    word32 dtls13MessageLength;
6718
    word32 dtls13FragOffset;
6719
    byte dtls13FragHandshakeType;
6720
    Dtls13Rtx dtls13Rtx;
6721
    byte *dtls13ClientHello;
6722
    word16 dtls13ClientHelloSz;
6723
6724
#endif /* WOLFSSL_DTLS13 */
6725
#ifdef WOLFSSL_DTLS_CID
6726
    CIDInfo *dtlsCidInfo;
6727
#endif /* WOLFSSL_DTLS_CID */
6728
6729
#endif /* WOLFSSL_DTLS */
6730
#ifdef WOLFSSL_CALLBACKS
6731
    TimeoutInfo     timeoutInfo;        /* info saved during handshake */
6732
    HandShakeInfo   handShakeInfo;      /* info saved during handshake */
6733
#endif
6734
#ifdef OPENSSL_EXTRA
6735
    SSL_Msg_Cb      protoMsgCb;         /* inspect protocol message callback */
6736
    void*           protoMsgCtx;        /* user set context with msg callback */
6737
#endif
6738
#if defined(WOLFSSL_CALLBACKS) || defined(OPENSSL_EXTRA)
6739
    byte            hsInfoOn;           /* track handshake info        */
6740
    byte            toInfoOn;           /* track timeout   info        */
6741
#endif
6742
#ifdef HAVE_FUZZER
6743
    CallbackFuzzer  fuzzerCb;           /* for testing with using fuzzer */
6744
    void*           fuzzerCtx;          /* user defined pointer */
6745
#endif
6746
#if defined(WOLFSSL_TLS13) && defined(WOLFSSL_POST_HANDSHAKE_AUTH)
6747
    CertReqCtx*     certReqCtx;
6748
#endif
6749
#ifdef WOLFSSL_LOCAL_X509_STORE
6750
    WOLFSSL_X509_STORE* x509_store_pt; /* take ownership of external store */
6751
#endif
6752
#ifdef KEEP_PEER_CERT
6753
    /* TODO put this on the heap so we can properly use the
6754
     * reference counter and not have to duplicate it. */
6755
    WOLFSSL_X509     peerCert;           /* X509 peer cert */
6756
#endif
6757
#ifdef KEEP_OUR_CERT
6758
    WOLFSSL_X509*    ourCert;            /* keep alive a X509 struct of cert.
6759
                                            points to ctx if not owned (owned
6760
                                            flag found in buffers.weOwnCert) */
6761
#endif
6762
    byte             keepCert;           /* keep certificate after handshake */
6763
#ifdef HAVE_EX_DATA
6764
    WOLFSSL_CRYPTO_EX_DATA ex_data; /* external data, for Fortress */
6765
#endif
6766
    int              devId;             /* async device id to use */
6767
#ifdef HAVE_ONE_TIME_AUTH
6768
    OneTimeAuth     auth;
6769
#endif
6770
#ifdef HAVE_TLS_EXTENSIONS
6771
    TLSX* extensions;                  /* RFC 6066 TLS Extensions data */
6772
    #ifdef OPENSSL_EXTRA
6773
        /* Pre-built wire bytes for app-defined custom extensions in the
6774
         * ClientHello. Produced in TLSX_GetRequestSize and consumed (then
6775
         * freed) in TLSX_WriteRequest. See WOLFSSL_CustomExt. */
6776
        byte*   customExtData;
6777
        word16  customExtSz;
6778
        /* Custom extension types actually emitted in the ClientHello, so an
6779
         * unsolicited type echoed by the server can be rejected. Rebuilt with
6780
         * customExtData; persists until the connection is freed. */
6781
        word16* customExtSent;
6782
        word16  customExtSentCnt;
6783
    #endif
6784
    #ifdef HAVE_MAX_FRAGMENT
6785
        word16 max_fragment;
6786
    #endif
6787
    #ifdef HAVE_TRUNCATED_HMAC
6788
        byte truncated_hmac;
6789
    #endif
6790
    #ifdef HAVE_CERTIFICATE_STATUS_REQUEST
6791
        byte status_request;
6792
    #endif
6793
    #ifdef HAVE_CERTIFICATE_STATUS_REQUEST_V2
6794
        byte status_request_v2;
6795
    #endif
6796
    #if defined(HAVE_SECURE_RENEGOTIATION) \
6797
        || defined(HAVE_SERVER_RENEGOTIATION_INFO)
6798
        int                  secure_rene_count;    /* how many times */
6799
        SecureRenegotiation* secure_renegotiation; /* valid pointer indicates */
6800
    #endif                                         /* user turned on */
6801
    #ifdef HAVE_ALPN
6802
        byte *alpn_peer_requested; /* the ALPN bytes requested by peer, sequence
6803
                                    * of length byte + chars */
6804
        word16 alpn_peer_requested_length; /* number of bytes total */
6805
        #if defined(OPENSSL_ALL) || defined(WOLFSSL_NGINX)  || \
6806
            defined(WOLFSSL_HAPROXY) || defined(WOLFSSL_QUIC)
6807
            CallbackALPNSelect alpnSelect;
6808
            void*              alpnSelectArg;
6809
        #endif
6810
    #endif                         /* of accepted protocols */
6811
    #if !defined(NO_WOLFSSL_CLIENT) && defined(HAVE_SESSION_TICKET)
6812
        CallbackSessionTicket session_ticket_cb;
6813
        void*                 session_ticket_ctx;
6814
        byte                  expect_session_ticket;
6815
    #endif
6816
        word16 hrr_keyshare_group;
6817
#endif /* HAVE_TLS_EXTENSIONS */
6818
#ifdef HAVE_OCSP
6819
        void*       ocspIOCtx;
6820
        byte ocspProducedDate[MAX_DATE_SIZE];
6821
        int ocspProducedDateFormat;
6822
        buffer      ocspCsrResp[1 + MAX_CHAIN_DEPTH];
6823
    #if defined(OPENSSL_ALL) || defined(WOLFSSL_NGINX) || defined(WOLFSSL_HAPROXY)
6824
        char*   url;
6825
    #endif
6826
#if defined(WOLFSSL_TLS13) && defined(HAVE_CERTIFICATE_STATUS_REQUEST)
6827
            word32 response_idx;
6828
#endif
6829
#endif
6830
#ifdef HAVE_NETX
6831
    NetX_Ctx        nxCtx;             /* NetX IO Context */
6832
#endif
6833
#if defined(WOLFSSL_APACHE_MYNEWT) && !defined(WOLFSSL_LWIP)
6834
    void*           mnCtx;             /* mynewt mn_socket IO Context */
6835
#endif /* defined(WOLFSSL_APACHE_MYNEWT) && !defined(WOLFSSL_LWIP) */
6836
#ifdef WOLFSSL_GNRC
6837
    struct gnrc_wolfssl_ctx *gnrcCtx;  /* Riot-OS GNRC UDP/IP context */
6838
#endif
6839
#ifdef SESSION_INDEX
6840
    int sessionIndex;                  /* Session's location in the cache. */
6841
#endif
6842
#ifdef ATOMIC_USER
6843
    void*    MacEncryptCtx;    /* Atomic User Mac/Encrypt Callback Context */
6844
    void*    DecryptVerifyCtx; /* Atomic User Decrypt/Verify Callback Context */
6845
    #ifdef HAVE_ENCRYPT_THEN_MAC
6846
        void*    EncryptMacCtx;    /* Atomic User Encrypt/Mac Callback Ctx */
6847
        void*    VerifyDecryptCtx; /* Atomic User Verify/Decrypt Callback Ctx */
6848
    #endif
6849
#endif
6850
#ifdef HAVE_PK_CALLBACKS
6851
    #ifdef HAVE_ECC
6852
        void* EccKeyGenCtx;          /* EccKeyGen  Callback Context */
6853
        void* EccSignCtx;            /* Ecc Sign   Callback Context */
6854
        void* EccVerifyCtx;          /* Ecc Verify Callback Context */
6855
        void* EccSharedSecretCtx;    /* Ecc Pms    Callback Context */
6856
    #endif /* HAVE_ECC */
6857
    #ifdef HAVE_HKDF
6858
        void* HkdfExtractCtx;       /* Hkdf extract callback context */
6859
    #endif
6860
    #ifdef HAVE_ED25519
6861
        void* Ed25519SignCtx;        /* ED25519 Sign   Callback Context */
6862
        void* Ed25519VerifyCtx;      /* ED25519 Verify Callback Context */
6863
    #endif
6864
    #ifdef HAVE_CURVE25519
6865
        void* X25519KeyGenCtx;       /* X25519 KeyGen Callback Context */
6866
        void* X25519SharedSecretCtx; /* X25519 Pms    Callback Context */
6867
    #endif
6868
    #ifdef HAVE_ED448
6869
        void* Ed448SignCtx;          /* ED448 Sign   Callback Context */
6870
        void* Ed448VerifyCtx;        /* ED448 Verify Callback Context */
6871
    #endif
6872
    #ifdef HAVE_CURVE448
6873
        void* X448KeyGenCtx;         /* X448 KeyGen Callback Context */
6874
        void* X448SharedSecretCtx;   /* X448 Pms    Callback Context */
6875
    #endif
6876
    #ifndef NO_DH
6877
        void* DhAgreeCtx; /* DH Pms Callback Context */
6878
    #endif /* !NO_DH */
6879
    #ifndef NO_RSA
6880
        void* RsaSignCtx;     /* Rsa Sign   Callback Context */
6881
        void* RsaVerifyCtx;   /* Rsa Verify Callback Context */
6882
        #ifdef WC_RSA_PSS
6883
            void* RsaPssSignCtx;     /* Rsa PSS Sign   Callback Context */
6884
            void* RsaPssVerifyCtx;   /* Rsa PSS Verify Callback Context */
6885
        #endif
6886
        void* RsaEncCtx;      /* Rsa Public  Encrypt   Callback Context */
6887
        void* RsaDecCtx;      /* Rsa Private Decrypt   Callback Context */
6888
    #endif /* NO_RSA */
6889
    void* GenPreMasterCtx;   /* Generate Premaster Callback Context */
6890
    void* GenMasterCtx;      /* Generate Master Callback Context */
6891
    void* GenExtMasterCtx;   /* Generate Extended Master Callback Context */
6892
    void* GenSessionKeyCtx;  /* Generate Session Key Callback Context */
6893
    void* EncryptKeysCtx;    /* Set Encrypt keys Callback Context */
6894
    void* TlsFinishedCtx;    /* Generate Tls Finished Callback Context */
6895
    void* VerifyMacCtx;      /* Verify mac Callback Context */
6896
#endif /* HAVE_PK_CALLBACKS */
6897
#ifdef HAVE_SECRET_CALLBACK
6898
        SessionSecretCb sessionSecretCb;
6899
        void*           sessionSecretCtx;
6900
        TicketParseCb   ticketParseCb;
6901
        void*           ticketParseCtx;
6902
        TlsSecretCb     tlsSecretCb;
6903
        void*           tlsSecretCtx;
6904
    #ifdef WOLFSSL_TLS13
6905
        Tls13SecretCb   tls13SecretCb;
6906
        void*           tls13SecretCtx;
6907
    #endif
6908
    #ifdef OPENSSL_EXTRA
6909
        SessionSecretCb keyLogCb;
6910
    #ifdef WOLFSSL_TLS13
6911
        Tls13SecretCb   tls13KeyLogCb;
6912
    #endif
6913
    #endif
6914
#endif /* HAVE_SECRET_CALLBACK */
6915
#ifdef WOLFSSL_JNI
6916
        void* jObjectRef;     /* reference to WolfSSLSession in JNI wrapper */
6917
#endif /* WOLFSSL_JNI */
6918
#ifdef WOLFSSL_EARLY_DATA
6919
    EarlyDataState earlyData;
6920
    word32 earlyDataSz;
6921
    byte earlyDataStatus;
6922
#endif
6923
#if defined(OPENSSL_EXTRA)
6924
    WOLFSSL_STACK* supportedCiphers; /* Used in wolfSSL_get_ciphers_compat */
6925
    WOLFSSL_STACK* peerCertChain;    /* Used in wolfSSL_get_peer_cert_chain */
6926
    WOLFSSL_STACK* verifiedChain;    /* peer cert chain to CA */
6927
#ifdef KEEP_OUR_CERT
6928
    WOLFSSL_STACK* ourCertChain;    /* Used in wolfSSL_add1_chain_cert */
6929
#endif
6930
#endif
6931
#ifdef WOLFSSL_STATIC_EPHEMERAL
6932
    StaticKeyExchangeInfo_t staticKE;
6933
#endif
6934
#ifdef WOLFSSL_MAXQ10XX_TLS
6935
    maxq_ssl_t maxq_ctx;
6936
#endif
6937
#ifdef WOLFSSL_HAVE_TLS_UNIQUE
6938
    /* Added in libest port: allow applications to get the 'tls-unique' Channel
6939
     * Binding Type (https://tools.ietf.org/html/rfc5929#section-3). This is
6940
     * used in the EST protocol to bind an enrollment to a TLS session through
6941
     * 'proof-of-possession' (https://tools.ietf.org/html/rfc7030#section-3.4
6942
     * and https://tools.ietf.org/html/rfc7030#section-3.5). */
6943
    byte clientFinished[TLS_FINISHED_SZ_MAX];
6944
    byte serverFinished[TLS_FINISHED_SZ_MAX];
6945
    byte clientFinished_len;
6946
    byte serverFinished_len;
6947
#endif
6948
#ifndef WOLFSSL_NO_CA_NAMES
6949
    WOLF_STACK_OF(WOLFSSL_X509_NAME)* client_ca_names; /* Used in *_set/get_client_CA_list
6950
                                                          (server only) */
6951
    WOLF_STACK_OF(WOLFSSL_X509_NAME)* ca_names;        /* Used in *_set0/get0_CA_list */
6952
    WOLF_STACK_OF(WOLFSSL_X509_NAME)* peer_ca_names;   /* Used in *_get0_peer_CA_list
6953
                                                          and (client only)
6954
                                                          wolfSSL_get_client_CA_list */
6955
#endif
6956
#if defined(WOLFSSL_IOTSAFE) && defined(HAVE_PK_CALLBACKS)
6957
    IOTSAFE iotsafe;
6958
#endif
6959
#ifdef WOLFSSL_LWIP_NATIVE
6960
    WOLFSSL_LWIP_NATIVE_STATE      lwipCtx; /* LwIP native socket IO Context */
6961
#endif
6962
#ifdef WOLFSSL_QUIC
6963
    struct {
6964
        const WOLFSSL_QUIC_METHOD* method;
6965
        WOLFSSL_ENCRYPTION_LEVEL enc_level_read;
6966
        WOLFSSL_ENCRYPTION_LEVEL enc_level_read_next;
6967
        WOLFSSL_ENCRYPTION_LEVEL enc_level_latest_recvd;
6968
        WOLFSSL_ENCRYPTION_LEVEL enc_level_write;
6969
        WOLFSSL_ENCRYPTION_LEVEL enc_level_write_next;
6970
        int transport_version;
6971
        const QuicTransportParam* transport_local;
6972
        const QuicTransportParam* transport_peer;
6973
        const QuicTransportParam* transport_peer_draft;
6974
        QuicRecord* input_head;          /* we own, data for handshake */
6975
        QuicRecord* input_tail;          /* points to last element for append */
6976
        QuicRecord* scratch;             /* we own, record construction */
6977
        enum wolfssl_encryption_level_t output_rec_level;
6978
                                         /* encryption level of current output record */
6979
        word32 output_rec_remain;        /* how many bytes of output TLS record
6980
                                          * content have not been handled yet by quic */
6981
    } quic;
6982
#endif /* WOLFSSL_QUIC */
6983
#if defined(WOLFSSL_TLS13) && defined(HAVE_ECH)
6984
    WOLFSSL_EchConfig* echConfigs;
6985
    WOLFSSL_EchConfig* echRetryConfigs;
6986
#endif
6987
#if defined(WOLFSSL_TLS13) && defined(HAVE_ECH) && defined(WOLFSSL_TEST_ECH)
6988
    /* Test-only hook: called on the client before ECH encryption, after the
6989
     * inner ClientHello body is fully constructed. The callback may modify
6990
     * innerCh in-place (length stays the same). */
6991
    int (*echInnerHelloCb)(byte* innerCh, word32 innerChLen);
6992
#endif
6993
6994
#if defined(WOLFSSL_SNIFFER) && defined(WOLFSSL_SNIFFER_KEYLOGFILE)
6995
    SSLSnifferSecretCb snifferSecretCb;
6996
#endif /* WOLFSSL_SNIFFER && WOLFSSL_SNIFFER_KEYLOGFILE */
6997
#ifdef WOLFSSL_DUAL_ALG_CERTS
6998
    byte *sigSpec;         /* This pointer never owns the memory. */
6999
    word16 sigSpecSz;
7000
    byte *peerSigSpec;     /* This pointer always owns the memory. */
7001
    word16 peerSigSpecSz;
7002
#endif
7003
#if defined(WOLFSSL_SYS_CRYPTO_POLICY)
7004
    int secLevel; /* The security level of system-wide crypto policy. */
7005
#endif /* WOLFSSL_SYS_CRYPTO_POLICY */
7006
#if !defined(NO_WOLFSSL_CLIENT) && !defined(WOLFSSL_NO_TLS12) && \
7007
    defined(HAVE_SERVER_RENEGOTIATION_INFO) && \
7008
    !defined(WOLFSSL_HARDEN_TLS_NO_SCR_CHECK)
7009
    WC_BITFIELD          scr_check_enabled:1;  /* enable/disable SCR check */
7010
#endif
7011
#ifdef HAVE_WRITE_DUP
7012
#ifdef WOLFSSL_TLS13
7013
#ifdef WOLFSSL_POST_HANDSHAKE_AUTH
7014
    WC_BITFIELD postHandshakeAuthPending:1;
7015
#endif
7016
#endif
7017
#endif
7018
    /* Cached BuildMessage(sizeOnly) overhead (recordSz - payloadSz) for AEAD
7019
     * ciphers; 0 means uncached and is never a valid AEAD overhead. EtM does
7020
     * not apply to AEAD. */
7021
    word32 recordSzOverhead;
7022
};
7023
7024
#if defined(WOLFSSL_SYS_CRYPTO_POLICY)
7025
#define WOLFSSL_SECLEVEL_STR "@SECLEVEL="
7026
struct SystemCryptoPolicy {
7027
    int    enabled;
7028
    int    secLevel;
7029
    char   str[MAX_WOLFSSL_CRYPTO_POLICY_SIZE + 1]; /* + 1 for null term */
7030
};
7031
#endif /* WOLFSSL_SYS_CRYPTO_POLICY */
7032
7033
/*
7034
 * wolfSSL_PEM_read_bio_X509 pushes an ASN_NO_PEM_HEADER error
7035
 * to the error queue on file end. This should not be left
7036
 * for the caller to find so we clear the last error.
7037
 */
7038
#if defined(OPENSSL_EXTRA) && defined(WOLFSSL_HAVE_ERROR_QUEUE)
7039
#define CLEAR_ASN_NO_PEM_HEADER_ERROR(err)                                     \
7040
do {                                                                           \
7041
    (err) = wolfSSL_ERR_peek_last_error();                                     \
7042
    if (wolfSSL_ERR_GET_LIB(err) == WOLFSSL_ERR_LIB_PEM &&                     \
7043
        wolfSSL_ERR_GET_REASON(err) ==                                         \
7044
            -WC_NO_ERR_TRACE(WOLFSSL_PEM_R_NO_START_LINE_E)) {                 \
7045
        unsigned long peekErr;                                                 \
7046
        do {                                                                   \
7047
            wc_RemoveErrorNode(-1);                                            \
7048
            peekErr = wolfSSL_ERR_peek_last_error();                           \
7049
        } while (wolfSSL_ERR_GET_LIB(peekErr) == WOLFSSL_ERR_LIB_PEM &&        \
7050
                 wolfSSL_ERR_GET_REASON(peekErr) ==                            \
7051
                 -WC_NO_ERR_TRACE(WOLFSSL_PEM_R_NO_START_LINE_E));             \
7052
    }                                                                          \
7053
} while(0)
7054
#else
7055
0
#define CLEAR_ASN_NO_PEM_HEADER_ERROR(err) (void)(err);
7056
#endif
7057
7058
/*
7059
 * The SSL object may have its own certificate store. The below macros simplify
7060
 * logic for choosing which WOLFSSL_CERT_MANAGER and WOLFSSL_X509_STORE to use.
7061
 * Always use SSL specific objects when available and revert to CTX otherwise.
7062
 */
7063
#ifdef WOLFSSL_LOCAL_X509_STORE
7064
#define SSL_CM(ssl) ((ssl)->x509_store_pt ? (ssl)->x509_store_pt->cm : \
7065
                     ((ssl)->ctx->x509_store_pt ? (ssl)->ctx->x509_store_pt->cm : \
7066
                                            (ssl)->ctx->cm))
7067
#define SSL_STORE(ssl) ((ssl)->x509_store_pt ? (ssl)->x509_store_pt : \
7068
                  ((ssl)->ctx->x509_store_pt ? (ssl)->ctx->x509_store_pt : \
7069
                                            &(ssl)->ctx->x509_store))
7070
#define CTX_STORE(ctx) ((ctx)->x509_store_pt ? (ctx)->x509_store_pt : \
7071
                                            &(ctx)->x509_store)
7072
#else
7073
0
#define SSL_CM(ssl) (ssl)->ctx->cm
7074
#endif
7075
/* Issue warning when we are modifying the overall context CM */
7076
#define SSL_CM_WARNING(ssl) \
7077
0
    do {                                                             \
7078
0
        if (SSL_CM( (ssl) ) == (ssl)->ctx->cm) {                     \
7079
0
            WOLFSSL_MSG("Modifying SSL_CTX CM not SSL specific CM"); \
7080
0
        }                                                            \
7081
0
    } while (0)
7082
7083
WOLFSSL_LOCAL int  SetSSL_CTX(WOLFSSL* ssl, WOLFSSL_CTX* ctx, int writeDup);
7084
WOLFSSL_LOCAL int  InitSSL(WOLFSSL* ssl, WOLFSSL_CTX* ctx, int writeDup);
7085
WOLFSSL_LOCAL int  ReinitSSL(WOLFSSL* ssl, WOLFSSL_CTX* ctx, int writeDup);
7086
WOLFSSL_LOCAL void FreeSSL(WOLFSSL* ssl, void* heap);
7087
WOLFSSL_TEST_VIS   void wolfSSL_ResourceFree(WOLFSSL* ssl);   /* Micrium uses */
7088
#ifndef OPENSSL_COEXIST
7089
#define SSL_ResourceFree wolfSSL_ResourceFree
7090
#endif
7091
7092
7093
#ifndef NO_CERTS
7094
7095
    WOLFSSL_LOCAL int ProcessBuffer(WOLFSSL_CTX* ctx, const unsigned char* buff,
7096
                                    long sz, int format, int type, WOLFSSL* ssl,
7097
                                    long* used, int userChain, int verify,
7098
                                    const char *source_name);
7099
    WOLFSSL_LOCAL int ProcessFile(WOLFSSL_CTX* ctx, const char* fname, int format,
7100
                                 int type, WOLFSSL* ssl, int userChain,
7101
                                WOLFSSL_CRL* crl, int verify);
7102
7103
    #ifndef NO_ASN
7104
    WOLFSSL_LOCAL int CheckHostName(DecodedCert* dCert, const char *domainName,
7105
                                    size_t domainNameLen, unsigned int flags,
7106
                                    byte isIP);
7107
    #endif
7108
#endif
7109
7110
7111
#if defined(WOLFSSL_CALLBACKS) || defined(OPENSSL_EXTRA)
7112
    WOLFSSL_LOCAL void InitHandShakeInfo(HandShakeInfo* info, WOLFSSL* ssl);
7113
    WOLFSSL_LOCAL void FinishHandShakeInfo(HandShakeInfo* info);
7114
    WOLFSSL_LOCAL void AddPacketName(WOLFSSL* ssl, const char* name);
7115
7116
    WOLFSSL_LOCAL void InitTimeoutInfo(TimeoutInfo* info);
7117
    WOLFSSL_LOCAL void FreeTimeoutInfo(TimeoutInfo* info, void* heap);
7118
    WOLFSSL_LOCAL int AddPacketInfo(WOLFSSL* ssl, const char* name, int type,
7119
                             const byte* data, int sz, int written, int lateRL,
7120
                             void* heap);
7121
    WOLFSSL_LOCAL void AddLateName(const char* name, TimeoutInfo* info);
7122
    WOLFSSL_LOCAL void AddLateRecordHeader(const RecordLayerHeader* rl,
7123
                                           TimeoutInfo* info);
7124
#endif
7125
7126
7127
/* Record Layer Header identifier from page 12 */
7128
enum ContentType {
7129
    no_type            = 0,
7130
    change_cipher_spec = 20,
7131
    alert              = 21,
7132
    handshake          = 22,
7133
    application_data   = 23,
7134
    dtls12_cid         = 25,
7135
#ifdef WOLFSSL_DTLS13
7136
    ack                = 26,
7137
#endif /* WOLFSSL_DTLS13 */
7138
    WOLF_ENUM_DUMMY_LAST_ELEMENT(ContentType)
7139
};
7140
7141
7142
/* handshake header, same for each message type, pgs 20/21 */
7143
typedef struct HandShakeHeader {
7144
    byte            type;
7145
    word24          length;
7146
} HandShakeHeader;
7147
7148
7149
/* DTLS handshake header, same for each message type */
7150
typedef struct DtlsHandShakeHeader {
7151
    byte            type;
7152
    word24          length;
7153
    byte            message_seq[2];    /* start at 0, retransmit gets same # */
7154
    word24          fragment_offset;   /* bytes in previous fragments */
7155
    word24          fragment_length;   /* length of this fragment */
7156
} DtlsHandShakeHeader;
7157
7158
7159
enum HandShakeType {
7160
    hello_request        =   0,
7161
    client_hello         =   1,
7162
    server_hello         =   2,
7163
    hello_verify_request =   3,    /* DTLS addition */
7164
    session_ticket       =   4,
7165
    end_of_early_data    =   5,
7166
    hello_retry_request  =   6,
7167
    encrypted_extensions =   8,
7168
    request_connection_id =  9,    /* DTLS v1.3 addition (RFC 9147) */
7169
    new_connection_id    =  10,    /* DTLS v1.3 addition (RFC 9147) */
7170
    certificate          =  11,
7171
    server_key_exchange  =  12,
7172
    certificate_request  =  13,
7173
    server_hello_done    =  14,
7174
    certificate_verify   =  15,
7175
    client_key_exchange  =  16,
7176
    finished             =  20,
7177
    certificate_status   =  22,
7178
    key_update           =  24,
7179
    change_cipher_hs     =  55,    /* simulate unique handshake type for sanity
7180
                                      checks.  record layer change_cipher
7181
                                      conflicts with handshake finished */
7182
    message_hash         = 254,    /* synthetic message type for TLS v1.3 */
7183
    no_shake             = 255     /* used to initialize the DtlsMsg record */
7184
};
7185
7186
enum ProvisionSide {
7187
    PROVISION_CLIENT = 1,
7188
    PROVISION_SERVER = 2,
7189
    PROVISION_CLIENT_SERVER = 3
7190
};
7191
7192
/* cipher requirements */
7193
enum {
7194
    REQUIRES_RSA,
7195
    REQUIRES_DHE,
7196
    REQUIRES_ECC,
7197
    REQUIRES_ECC_STATIC,
7198
    REQUIRES_PSK,
7199
    REQUIRES_RSA_SIG,
7200
    REQUIRES_AEAD
7201
};
7202
7203
static const byte kTlsClientStr[SIZEOF_SENDER+1] = { 0x43, 0x4C, 0x4E, 0x54, 0x00 }; /* CLNT */
7204
static const byte kTlsServerStr[SIZEOF_SENDER+1] = { 0x53, 0x52, 0x56, 0x52, 0x00 }; /* SRVR */
7205
7206
static const byte kTlsClientFinStr[FINISHED_LABEL_SZ + 1] = "client finished";
7207
static const byte kTlsServerFinStr[FINISHED_LABEL_SZ + 1] = "server finished";
7208
7209
#if defined(OPENSSL_EXTRA) || defined(WOLFSSL_WPAS_SMALL) || defined(HAVE_CURL)
7210
typedef struct {
7211
    int name_len;
7212
    const char *name;
7213
    int nid;
7214
    word16 curve;
7215
} WOLF_EC_NIST_NAME;
7216
extern const WOLF_EC_NIST_NAME kNistCurves[];
7217
WOLFSSL_LOCAL int set_curves_list(WOLFSSL* ssl, WOLFSSL_CTX *ctx,
7218
        const char* names, byte curves_only);
7219
#endif /* OPENSSL_EXTRA || WOLFSSL_WPAS_SMALL || HAVE_CURL */
7220
7221
/* internal functions */
7222
WOLFSSL_LOCAL int SendChangeCipher(WOLFSSL* ssl);
7223
WOLFSSL_LOCAL int SendTicket(WOLFSSL* ssl);
7224
#ifdef HAVE_SESSION_TICKET
7225
WOLFSSL_LOCAL int DoDecryptTicket(const WOLFSSL* ssl, const byte* input,
7226
        word32 len, InternalTicket **it);
7227
/* Return 0 when check successful. <0 on failure. */
7228
WOLFSSL_LOCAL void DoClientTicketFinalize(WOLFSSL* ssl, InternalTicket* it,
7229
                                          const WOLFSSL_SESSION* sess);
7230
7231
#ifdef WOLFSSL_TLS13
7232
WOLFSSL_LOCAL int DoClientTicketCheck(const WOLFSSL* ssl,
7233
        const PreSharedKey* psk, sword64 timeout, const byte* suite);
7234
WOLFSSL_LOCAL void CleanupClientTickets(PreSharedKey* psk);
7235
WOLFSSL_LOCAL int DoClientTicket_ex(const WOLFSSL* ssl, PreSharedKey* psk,
7236
                                    int retainSess);
7237
#endif
7238
7239
WOLFSSL_LOCAL int DoClientTicket(WOLFSSL* ssl, const byte* input, word32 len);
7240
/* TicketSniHash, TicketAlpnHash, and VerifyTicketBinding are defined in
7241
 * internal.c only when !NO_WOLFSSL_SERVER && !NO_TLS - gate the
7242
 * declarations to match so client-only or no-TLS builds don't compile in
7243
 * call sites that would fail to link. */
7244
#if !defined(NO_WOLFSSL_SERVER) && !defined(NO_TLS)
7245
#ifdef HAVE_SNI
7246
WOLFSSL_LOCAL int TicketSniHash(WOLFSSL* ssl, byte* dst);
7247
#endif
7248
#ifdef HAVE_ALPN
7249
WOLFSSL_LOCAL int TicketAlpnHash(WOLFSSL* ssl, byte* dst);
7250
#endif
7251
#if defined(HAVE_SNI) || defined(HAVE_ALPN)
7252
WOLFSSL_LOCAL int VerifyTicketBinding(WOLFSSL* ssl);
7253
#endif
7254
#endif /* !NO_WOLFSSL_SERVER && !NO_TLS */
7255
#endif /* HAVE_SESSION_TICKET */
7256
WOLFSSL_LOCAL int SendData(WOLFSSL* ssl, const void* data, size_t sz);
7257
#ifdef WOLFSSL_THREADED_CRYPT
7258
WOLFSSL_LOCAL int SendAsyncData(WOLFSSL* ssl);
7259
#endif
7260
#ifdef WOLFSSL_TLS13
7261
WOLFSSL_LOCAL int SendTls13ServerHello(WOLFSSL* ssl, byte extMsgType);
7262
#endif
7263
WOLFSSL_LOCAL int SendCertificate(WOLFSSL* ssl);
7264
WOLFSSL_LOCAL int SendCertificateRequest(WOLFSSL* ssl);
7265
#if defined(HAVE_CERTIFICATE_STATUS_REQUEST) \
7266
 || defined(HAVE_CERTIFICATE_STATUS_REQUEST_V2)
7267
WOLFSSL_LOCAL int CreateOcspResponse(WOLFSSL* ssl, OcspRequest** ocspRequest,
7268
                       buffer* response, byte* ctxOwnsRequest);
7269
#endif
7270
#if defined(HAVE_SECURE_RENEGOTIATION) && \
7271
    !defined(NO_WOLFSSL_SERVER)
7272
WOLFSSL_LOCAL int SendHelloRequest(WOLFSSL* ssl);
7273
#endif
7274
WOLFSSL_LOCAL int SendCertificateStatus(WOLFSSL* ssl);
7275
WOLFSSL_LOCAL int SendServerKeyExchange(WOLFSSL* ssl);
7276
WOLFSSL_LOCAL int SendBuffered(WOLFSSL* ssl);
7277
WOLFSSL_LOCAL int ReceiveData(WOLFSSL* ssl, byte* output, size_t sz, int peek);
7278
WOLFSSL_LOCAL int SendFinished(WOLFSSL* ssl);
7279
WOLFSSL_LOCAL int RetrySendAlert(WOLFSSL* ssl);
7280
WOLFSSL_LOCAL int SendAlert(WOLFSSL* ssl, int severity, int type);
7281
WOLFSSL_LOCAL int SendFatalAlertOnly(WOLFSSL *ssl, int error);
7282
WOLFSSL_LOCAL int ProcessReply(WOLFSSL* ssl);
7283
WOLFSSL_LOCAL int ProcessReplyEx(WOLFSSL* ssl, int allowSocketErr);
7284
7285
WOLFSSL_LOCAL const char* AlertTypeToString(int type);
7286
7287
WOLFSSL_LOCAL int SetCipherSpecs(WOLFSSL* ssl);
7288
WOLFSSL_LOCAL int GetCipherSpec(word16 side, byte cipherSuite0,
7289
        byte cipherSuite, CipherSpecs* specs, Options* opts);
7290
WOLFSSL_LOCAL int MakeMasterSecret(WOLFSSL* ssl);
7291
7292
WOLFSSL_LOCAL int DeriveKeys(WOLFSSL* ssl);
7293
WOLFSSL_LOCAL int StoreKeys(WOLFSSL* ssl, const byte* keyData, int side);
7294
7295
WOLFSSL_LOCAL int IsTLS(const WOLFSSL* ssl);
7296
WOLFSSL_LOCAL int IsTLS_ex(const ProtocolVersion pv);
7297
WOLFSSL_LOCAL int IsAtLeastTLSv1_2(const WOLFSSL* ssl);
7298
WOLFSSL_LOCAL int IsAtLeastTLSv1_3(const ProtocolVersion pv);
7299
WOLFSSL_LOCAL int IsEncryptionOn(const WOLFSSL* ssl, int isSend);
7300
WOLFSSL_LOCAL int TLSv1_3_Capable(WOLFSSL* ssl);
7301
7302
WOLFSSL_LOCAL void FreeHandshakeResources(WOLFSSL* ssl);
7303
WOLFSSL_LOCAL void ShrinkInputBuffer(WOLFSSL* ssl, int forcedFree);
7304
WOLFSSL_LOCAL void ShrinkOutputBuffer(WOLFSSL* ssl);
7305
WOLFSSL_LOCAL byte* GetOutputBuffer(WOLFSSL* ssl);
7306
7307
WOLFSSL_LOCAL int CipherRequires(byte first, byte second, int requirement);
7308
WOLFSSL_LOCAL int VerifyClientSuite(word16 havePSK, byte cipherSuite0,
7309
                                    byte cipherSuite);
7310
7311
WOLFSSL_LOCAL int SetTicket(WOLFSSL* ssl, const byte* ticket, word32 length);
7312
WOLFSSL_TEST_VIS int wolfssl_local_GetRecordSize(WOLFSSL *ssl, int payloadSz,
7313
        int isEncrypted);
7314
WOLFSSL_LOCAL int wolfssl_local_GetMaxPlaintextSize(WOLFSSL *ssl);
7315
WOLFSSL_LOCAL int wolfSSL_GetMaxFragSize(WOLFSSL* ssl);
7316
7317
#if defined(WOLFSSL_IOTSAFE) && defined(HAVE_PK_CALLBACKS)
7318
WOLFSSL_LOCAL IOTSAFE *wolfSSL_get_iotsafe_ctx(WOLFSSL *ssl);
7319
WOLFSSL_LOCAL int wolfSSL_set_iotsafe_ctx(WOLFSSL *ssl, IOTSAFE *iotsafe);
7320
#endif
7321
7322
#if (defined(OPENSSL_EXTRA) || defined(WOLFSSL_WPAS_SMALL)) && defined(HAVE_ECC)
7323
WOLFSSL_LOCAL int SetECKeyInternal(WOLFSSL_EC_KEY* eckey);
7324
WOLFSSL_LOCAL int SetECKeyExternal(WOLFSSL_EC_KEY* eckey);
7325
#endif
7326
7327
#if defined(OPENSSL_EXTRA) || defined(HAVE_CURL)
7328
WOLFSSL_LOCAL int wolfSSL_curve_is_disabled(const WOLFSSL* ssl,
7329
                                            word16 curve_id);
7330
#else
7331
static WC_INLINE int wolfSSL_curve_is_disabled(const WOLFSSL* ssl,
7332
                                               word16 curve_id)
7333
0
{
7334
0
    (void)ssl;
7335
0
    (void)curve_id;
7336
0
    return 0;
7337
0
}
Unexecuted instantiation: wolfio.c:wolfSSL_curve_is_disabled
Unexecuted instantiation: ssl.c:wolfSSL_curve_is_disabled
Unexecuted instantiation: tls.c:wolfSSL_curve_is_disabled
Unexecuted instantiation: tls13.c:wolfSSL_curve_is_disabled
Unexecuted instantiation: asn.c:wolfSSL_curve_is_disabled
Unexecuted instantiation: internal.c:wolfSSL_curve_is_disabled
Unexecuted instantiation: keys.c:wolfSSL_curve_is_disabled
7338
#endif
7339
7340
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
7341
WOLFSSL_LOCAL WC_RNG* WOLFSSL_RSA_GetRNG(WOLFSSL_RSA *rsa, WC_RNG **tmpRNG,
7342
                                         int *initTmpRng);
7343
#endif /* OPENSSL_EXTRA || OPENSSL_EXTRA_X509_SMALL */
7344
7345
    #ifndef NO_RSA
7346
        #ifdef WC_RSA_PSS
7347
            WOLFSSL_LOCAL int CheckRsaPssPadding(const byte* plain, word32 plainSz,
7348
                byte* out, word32 sigSz, enum wc_HashType hashType);
7349
            WOLFSSL_LOCAL int ConvertHashPss(int hashAlgo,
7350
                enum wc_HashType* hashType, int* mgf);
7351
        #endif
7352
        WOLFSSL_LOCAL int VerifyRsaSign(WOLFSSL* ssl, byte* verifySig,
7353
            word32 sigSz, const byte* plain, word32 plainSz, int sigAlgo,
7354
            int hashAlgo, RsaKey* key, DerBuffer* keyBufInfo);
7355
        WOLFSSL_LOCAL int RsaSign(WOLFSSL* ssl, const byte* in, word32 inSz,
7356
            byte* out, word32* outSz, int sigAlgo, int hashAlgo, RsaKey* key,
7357
            DerBuffer* keyBufInfo);
7358
        WOLFSSL_LOCAL int RsaVerify(WOLFSSL* ssl, byte* in, word32 inSz,
7359
            byte** out, int sigAlgo, int hashAlgo, RsaKey* key,
7360
            buffer* keyBufInfo);
7361
        WOLFSSL_LOCAL int RsaDec(WOLFSSL* ssl, byte* in, word32 inSz, byte** out,
7362
            word32* outSz, RsaKey* key, DerBuffer* keyBufInfo);
7363
        WOLFSSL_LOCAL int RsaEnc(WOLFSSL* ssl, const byte* in, word32 inSz, byte* out,
7364
            word32* outSz, RsaKey* key, buffer* keyBufInfo);
7365
    #endif /* !NO_RSA */
7366
7367
    #ifdef HAVE_ECC
7368
        WOLFSSL_LOCAL int EccSign(WOLFSSL* ssl, const byte* in, word32 inSz,
7369
            byte* out, word32* outSz, ecc_key* key, DerBuffer* keyBufInfo);
7370
        WOLFSSL_LOCAL int EccVerify(WOLFSSL* ssl, const byte* in, word32 inSz,
7371
            const byte* out, word32 outSz, ecc_key* key, buffer* keyBufInfo);
7372
        WOLFSSL_LOCAL int EccSharedSecret(WOLFSSL* ssl, ecc_key* priv_key,
7373
            ecc_key* pub_key, byte* pubKeyDer, word32* pubKeySz, byte* out,
7374
            word32* outlen, int side);
7375
    #endif /* HAVE_ECC */
7376
    #if defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3)
7377
        WOLFSSL_LOCAL int Sm2wSm3Sign(WOLFSSL* ssl, const byte* id, word32 idSz,
7378
            const byte* in, word32 inSz, byte* out, word32* outSz, ecc_key* key,
7379
            DerBuffer* keyBufInfo);
7380
        WOLFSSL_LOCAL int Sm2wSm3Verify(WOLFSSL* ssl, const byte* id,
7381
            word32 idSz, const byte* in, word32 inSz, const byte* out,
7382
            word32 outSz, ecc_key* key, buffer* keyBufInfo);
7383
    #endif /* WOLFSSL_SM2 && WOLFSSL_SM3 */
7384
    #ifdef HAVE_ED25519
7385
        WOLFSSL_LOCAL int Ed25519CheckPubKey(WOLFSSL* ssl);
7386
        WOLFSSL_LOCAL int Ed25519Sign(WOLFSSL* ssl, const byte* in, word32 inSz,
7387
            byte* out, word32* outSz, ed25519_key* key, DerBuffer* keyBufInfo);
7388
        WOLFSSL_LOCAL int Ed25519Verify(WOLFSSL* ssl, const byte* in,
7389
            word32 inSz, const byte* msg, word32 msgSz, ed25519_key* key,
7390
            buffer* keyBufInfo);
7391
    #endif /* HAVE_ED25519 */
7392
    #ifdef HAVE_ED448
7393
        WOLFSSL_LOCAL int Ed448CheckPubKey(WOLFSSL* ssl);
7394
        WOLFSSL_LOCAL int Ed448Sign(WOLFSSL* ssl, const byte* in, word32 inSz,
7395
            byte* out, word32* outSz, ed448_key* key, DerBuffer* keyBufInfo);
7396
        WOLFSSL_LOCAL int Ed448Verify(WOLFSSL* ssl, const byte* in,
7397
            word32 inSz, const byte* msg, word32 msgSz, ed448_key* key,
7398
            buffer* keyBufInfo);
7399
    #endif /* HAVE_ED448 */
7400
7401
#ifndef NO_CERTS
7402
    #ifdef WOLFSSL_TRUST_PEER_CERT
7403
7404
        /* options for searching hash table for a matching trusted peer cert */
7405
        #define WC_MATCH_SKID 0
7406
        #define WC_MATCH_NAME 1
7407
7408
        WOLFSSL_LOCAL TrustedPeerCert* GetTrustedPeer(void* vp, DecodedCert* cert);
7409
        WOLFSSL_LOCAL int MatchTrustedPeer(TrustedPeerCert* tp,
7410
                                                             DecodedCert* cert);
7411
    #endif
7412
7413
7414
    #ifndef GetCA
7415
        WOLFSSL_LOCAL Signer* GetCA(void* vp, byte* hash);
7416
    #endif
7417
    #if defined(WOLFSSL_AKID_NAME) && !defined(WC_SYM_RELOC_TABLES)
7418
        /* note WOLFSSL_API_PREFIX_MAPping is in asn.h, and if
7419
         * WC_SYM_RELOC_TABLES, the prototype is in the port layer
7420
         * (e.g. linuxkm_wc_port.h), to allow shimming.
7421
         */
7422
        WOLFSSL_TEST_VIS Signer* GetCAByAKID(void* vp, const byte* issuer,
7423
                word32 issuerSz, const byte* serial, word32 serialSz);
7424
    #endif
7425
    #if defined(HAVE_OCSP) && !defined(GetCAByKeyHash)
7426
        WOLFSSL_LOCAL Signer* GetCAByKeyHash(void* vp, const byte* keyHash);
7427
    #endif
7428
    #if !defined(NO_SKID) && !defined(GetCAByName)
7429
        WOLFSSL_LOCAL Signer* GetCAByName(void* vp, byte* hash);
7430
    #endif
7431
#endif /* !NO_CERTS */
7432
WOLFSSL_LOCAL int  BuildTlsHandshakeHash(WOLFSSL* ssl, byte* hash,
7433
                                   word32* hashLen);
7434
WOLFSSL_LOCAL int  BuildTlsFinished(WOLFSSL* ssl, Hashes* hashes,
7435
                                   const byte* sender);
7436
WOLFSSL_LOCAL void FreeArrays(WOLFSSL* ssl, int keep);
7437
WOLFSSL_LOCAL  int CheckAvailableSize(WOLFSSL *ssl, int size);
7438
WOLFSSL_LOCAL  int GrowInputBuffer(WOLFSSL* ssl, int size, int usedLength);
7439
WOLFSSL_LOCAL  int MsgCheckEncryption(WOLFSSL* ssl, byte type, byte encrypted);
7440
WOLFSSL_LOCAL  int EarlySanityCheckMsgReceived(WOLFSSL* ssl, byte type,
7441
        word32 msgSz);
7442
WOLFSSL_LOCAL int GetHandshakeHeader(WOLFSSL* ssl, const byte* input,
7443
        word32* inOutIdx, byte* type, word32* size, word32 totalSz);
7444
#if !defined(NO_WOLFSSL_CLIENT) || !defined(WOLFSSL_NO_CLIENT_AUTH)
7445
WOLFSSL_LOCAL void DoCertFatalAlert(WOLFSSL* ssl, int ret);
7446
#endif
7447
#ifndef NO_TLS
7448
    WOLFSSL_LOCAL int  MakeTlsMasterSecret(WOLFSSL* ssl);
7449
#ifndef WOLFSSL_AEAD_ONLY
7450
    WOLFSSL_LOCAL int  TLS_hmac(WOLFSSL* ssl, byte* digest, const byte* in,
7451
                                word32 sz, int padSz, int content, int verify, int epochOrder);
7452
#endif
7453
#endif
7454
7455
WOLFSSL_LOCAL int cipherExtraData(WOLFSSL* ssl);
7456
WOLFSSL_LOCAL word32 MacSize(const WOLFSSL* ssl);
7457
7458
#ifndef NO_WOLFSSL_CLIENT
7459
    WOLFSSL_LOCAL int HaveUniqueSessionObj(WOLFSSL* ssl);
7460
    WOLFSSL_LOCAL int SendClientHello(WOLFSSL* ssl);
7461
    WOLFSSL_LOCAL int DoHelloVerifyRequest(WOLFSSL* ssl, const byte* input, word32* inOutIdx,
7462
        word32 size);
7463
    #ifdef WOLFSSL_TLS13
7464
    WOLFSSL_LOCAL int SendTls13ClientHello(WOLFSSL* ssl);
7465
    #endif
7466
    WOLFSSL_LOCAL int SendClientKeyExchange(WOLFSSL* ssl);
7467
    WOLFSSL_LOCAL int SendCertificateVerify(WOLFSSL* ssl);
7468
#endif /* NO_WOLFSSL_CLIENT */
7469
7470
#ifndef NO_WOLFSSL_SERVER
7471
    WOLFSSL_LOCAL int SendServerHello(WOLFSSL* ssl);
7472
    WOLFSSL_LOCAL int SendServerHelloDone(WOLFSSL* ssl);
7473
#endif /* NO_WOLFSSL_SERVER */
7474
7475
#ifdef WOLFSSL_TLS13
7476
    WOLFSSL_LOCAL int SendTls13KeyUpdate(WOLFSSL* ssl);
7477
WOLFSSL_LOCAL int Tls13KeyUpdateLimitReached(WOLFSSL* ssl);
7478
#endif
7479
7480
#ifdef WOLFSSL_DTLS
7481
    #ifdef WOLFSSL_API_PREFIX_MAP
7482
        #define DtlsMsgListDelete wolfSSL_DtlsMsgListDelete
7483
        #define DtlsMsgFind wolfSSL_DtlsMsgFind
7484
        #define DtlsMsgStore wolfSSL_DtlsMsgStore
7485
    #endif /* WOLFSSL_API_PREFIX_MAP */
7486
    WOLFSSL_LOCAL DtlsMsg* DtlsMsgNew(word32 sz, byte tx, void* heap);
7487
    WOLFSSL_LOCAL void DtlsMsgDelete(DtlsMsg* item, void* heap);
7488
    WOLFSSL_TEST_VIS void DtlsMsgListDelete(DtlsMsg* head, void* heap);
7489
    WOLFSSL_LOCAL void DtlsTxMsgListClean(WOLFSSL* ssl);
7490
    WOLFSSL_LOCAL int  DtlsMsgSet(DtlsMsg* msg, word32 seq, word16 epoch,
7491
                                  const byte* data, byte type,
7492
                                  word32 fragOffset, word32 fragSz, void* heap,
7493
                                  word32 totalLen, byte encrypted);
7494
    WOLFSSL_TEST_VIS DtlsMsg* DtlsMsgFind(DtlsMsg* head, word16 epoch, word32 seq);
7495
7496
    WOLFSSL_TEST_VIS void DtlsMsgStore(WOLFSSL* ssl, word16 epoch, word32 seq,
7497
                                    const byte* data, word32 dataSz, byte type,
7498
                                    word32 fragOffset, word32 fragSz,
7499
                                    void* heap);
7500
    WOLFSSL_LOCAL DtlsMsg* DtlsMsgInsert(DtlsMsg* head, DtlsMsg* item);
7501
7502
    WOLFSSL_LOCAL int  DtlsMsgPoolSave(WOLFSSL* ssl, const byte* data,
7503
                                       word32 dataSz, enum HandShakeType type);
7504
    WOLFSSL_LOCAL int  DtlsMsgPoolTimeout(WOLFSSL* ssl);
7505
    WOLFSSL_LOCAL int  VerifyForDtlsMsgPoolSend(WOLFSSL* ssl, byte type,
7506
                                                word32 fragOffset);
7507
    WOLFSSL_LOCAL int  VerifyForTxDtlsMsgDelete(WOLFSSL* ssl, DtlsMsg* item);
7508
    WOLFSSL_LOCAL void DtlsMsgPoolReset(WOLFSSL* ssl);
7509
    WOLFSSL_LOCAL int  wolfssl_local_SockAddrSet(WOLFSSL_SOCKADDR* sockAddr,
7510
                                                 void* peer,
7511
                                                 unsigned int peerSz,
7512
                                                 void* heap);
7513
    WOLFSSL_LOCAL int  DtlsMsgPoolSend(WOLFSSL* ssl, int sendOnlyFirstPacket);
7514
    WOLFSSL_LOCAL void DtlsMsgDestroyFragBucket(DtlsFragBucket* fragBucket, void* heap);
7515
    WOLFSSL_LOCAL int GetDtlsHandShakeHeader(WOLFSSL *ssl, const byte *input,
7516
        word32 *inOutIdx, byte *type, word32 *size, word32 *fragOffset,
7517
        word32 *fragSz, word32 totalSz);
7518
    WOLFSSL_LOCAL int DtlsMsgDrain(WOLFSSL *ssl);
7519
    WOLFSSL_LOCAL int SendHelloVerifyRequest(WOLFSSL* ssl,
7520
        const byte* cookie, byte cookieSz);
7521
7522
#if !defined(NO_WOLFSSL_SERVER)
7523
    WOLFSSL_LOCAL int DoClientHelloStateless(WOLFSSL* ssl,
7524
            const byte* input, word32 helloSz, byte isFirstCHFrag, byte* tls13);
7525
#endif /* !defined(NO_WOLFSSL_SERVER) */
7526
#if !defined(WOLFCRYPT_ONLY) && !defined(WOLFSSL_NO_SOCK) && \
7527
    (defined(USE_WOLFSSL_IO) || defined(WOLFSSL_USER_IO))
7528
    WOLFSSL_LOCAL int sockAddrEqual(SOCKADDR_S *a, XSOCKLENT aLen,
7529
                                    SOCKADDR_S *b, XSOCKLENT bLen);
7530
#endif
7531
#endif /* WOLFSSL_DTLS */
7532
7533
#if defined(HAVE_SECURE_RENEGOTIATION) && defined(WOLFSSL_DTLS)
7534
    WOLFSSL_LOCAL int DtlsSCRKeysSet(WOLFSSL* ssl);
7535
    WOLFSSL_LOCAL int IsDtlsMsgSCRKeys(WOLFSSL* ssl);
7536
    WOLFSSL_LOCAL int DtlsUseSCRKeys(WOLFSSL* ssl);
7537
    WOLFSSL_LOCAL int DtlsCheckOrder(WOLFSSL* ssl, int order);
7538
#endif
7539
    WOLFSSL_LOCAL int IsSCR(WOLFSSL* ssl);
7540
    WOLFSSL_LOCAL int IsDtlsNotSctpMode(WOLFSSL* ssl);
7541
    WOLFSSL_LOCAL int IsDtlsNotSrtpMode(WOLFSSL* ssl);
7542
7543
    WOLFSSL_LOCAL void WriteSEQ(WOLFSSL* ssl, int verifyOrder, byte* out);
7544
7545
#if defined(WOLFSSL_TLS13) && (defined(HAVE_SESSION_TICKET) || \
7546
        !defined(NO_PSK) || defined(WOLFSSL_DTLS13))
7547
#ifdef WOLFSSL_32BIT_MILLI_TIME
7548
    WOLFSSL_LOCAL word32 TimeNowInMilliseconds(void);
7549
#else
7550
    WOLFSSL_LOCAL sword64 TimeNowInMilliseconds(void);
7551
#endif
7552
7553
#endif
7554
WOLFSSL_LOCAL word32  LowResTimer(void);
7555
7556
WOLFSSL_LOCAL int FindSuiteSSL(const WOLFSSL* ssl, byte* suite);
7557
WOLFSSL_LOCAL int FindSuite(const Suites* suites, byte first, byte second);
7558
7559
WOLFSSL_LOCAL void DecodeSigAlg(const byte* input, byte* hashAlgo,
7560
        byte* hsType);
7561
#ifdef WOLFSSL_HAVE_SLHDSA
7562
WOLFSSL_LOCAL byte SlhDsaSigMinorToType(byte minor);
7563
WOLFSSL_LOCAL int SlhDsaTypeToParam(byte hsType);
7564
WOLFSSL_LOCAL int IsSlhDsaSigAlgo(byte hsType);
7565
WOLFSSL_LOCAL byte SlhDsaParamToType(int param);
7566
#endif
7567
WOLFSSL_LOCAL enum wc_HashType HashAlgoToType(int hashAlgo);
7568
7569
#ifndef NO_CERTS
7570
    WOLFSSL_LOCAL void InitX509Name(WOLFSSL_X509_NAME* name, int dynamicFlag,
7571
                                    void* heap);
7572
    WOLFSSL_LOCAL void FreeX509Name(WOLFSSL_X509_NAME* name);
7573
    WOLFSSL_LOCAL void InitX509(WOLFSSL_X509* x509, int dynamicFlag,
7574
                                void* heap);
7575
    WOLFSSL_LOCAL void FreeX509(WOLFSSL_X509* x509);
7576
    WOLFSSL_LOCAL void ReinitX509(WOLFSSL_X509* x509);
7577
    #ifndef NO_ASN
7578
    WOLFSSL_LOCAL int  CopyDecodedToX509(WOLFSSL_X509* x509,
7579
                                         DecodedCert* dCert);
7580
    #endif
7581
#endif
7582
7583
#if defined(WOLFSSL_ACERT)
7584
    WOLFSSL_LOCAL int  CopyDecodedAcertToX509(WOLFSSL_X509_ACERT* x509,
7585
                                              DecodedAcert* dAcert);
7586
#endif /* WOLFSSL_ACERT */
7587
7588
7589
#ifndef MAX_CIPHER_NAME
7590
#define MAX_CIPHER_NAME 50
7591
#endif
7592
7593
#ifdef WOLFSSL_NAMES_STATIC
7594
typedef char cipher_name[MAX_CIPHER_NAME];
7595
#else
7596
typedef const char* cipher_name;
7597
#endif
7598
7599
typedef struct CipherSuiteInfo {
7600
    cipher_name name;
7601
#ifndef NO_ERROR_STRINGS
7602
    cipher_name name_iana;
7603
#endif
7604
    byte cipherSuite0;
7605
    byte cipherSuite;
7606
#if defined(OPENSSL_EXTRA) || defined(WOLFSSL_QT) || \
7607
    defined(WOLFSSL_HAPROXY) || defined(WOLFSSL_NGINX)
7608
    byte minor;
7609
    byte major;
7610
#endif
7611
    byte flags;
7612
} CipherSuiteInfo;
7613
7614
#ifdef WOLFSSL_API_PREFIX_MAP
7615
    #define GetCipherNames wolfSSL_GetCipherNames
7616
    #define GetCipherNamesSize wolfSSL_GetCipherNamesSize
7617
#endif
7618
WOLFSSL_TEST_VIS const CipherSuiteInfo* GetCipherNames(void);
7619
WOLFSSL_TEST_VIS int GetCipherNamesSize(void);
7620
WOLFSSL_LOCAL const char* GetCipherNameInternal(const byte cipherSuite0, const byte cipherSuite);
7621
#if defined(OPENSSL_ALL) || defined(WOLFSSL_QT)
7622
/* used in wolfSSL_sk_CIPHER_description */
7623
#define MAX_SEGMENTS    5
7624
#define MAX_SEGMENT_SZ 20
7625
WOLFSSL_LOCAL int wolfSSL_sk_CIPHER_description(WOLFSSL_CIPHER* cipher);
7626
WOLFSSL_LOCAL const char* GetCipherSegment(const WOLFSSL_CIPHER* cipher,
7627
                                           char n[][MAX_SEGMENT_SZ]);
7628
WOLFSSL_LOCAL const char* GetCipherProtocol(byte minor);
7629
WOLFSSL_LOCAL const char* GetCipherKeaStr(char n[][MAX_SEGMENT_SZ]);
7630
WOLFSSL_LOCAL const char* GetCipherAuthStr(char n[][MAX_SEGMENT_SZ]);
7631
WOLFSSL_LOCAL const char* GetCipherEncStr(char n[][MAX_SEGMENT_SZ]);
7632
WOLFSSL_LOCAL const char* GetCipherMacStr(char n[][MAX_SEGMENT_SZ]);
7633
WOLFSSL_LOCAL int SetCipherBits(const char* enc);
7634
WOLFSSL_LOCAL int IsCipherAEAD(char n[][MAX_SEGMENT_SZ]);
7635
#endif
7636
WOLFSSL_LOCAL const char* GetCipherNameIana(const byte cipherSuite0, const byte cipherSuite);
7637
WOLFSSL_LOCAL const char* wolfSSL_get_cipher_name_internal(WOLFSSL* ssl);
7638
WOLFSSL_LOCAL const char* wolfSSL_get_cipher_name_iana(WOLFSSL* ssl);
7639
WOLFSSL_LOCAL int GetCipherSuiteFromName(const char* name, byte* cipherSuite0,
7640
                       byte* cipherSuite, byte* major, byte* minor, int* flags);
7641
7642
7643
enum encrypt_side {
7644
    ENCRYPT_SIDE_ONLY = 1,
7645
    DECRYPT_SIDE_ONLY,
7646
    ENCRYPT_AND_DECRYPT_SIDE
7647
};
7648
7649
WOLFSSL_LOCAL int SetKeys(Ciphers* enc, Ciphers* dec, Keys* keys,
7650
    CipherSpecs* specs, int side, void* heap, int devId, WC_RNG* rng,
7651
    int tls13);
7652
WOLFSSL_LOCAL int SetKeysSide(WOLFSSL* ssl, enum encrypt_side side);
7653
7654
/* Set*Internal and Set*External functions */
7655
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
7656
WOLFSSL_LOCAL int SetDsaInternal(WOLFSSL_DSA* dsa);
7657
WOLFSSL_LOCAL int SetDsaExternal(WOLFSSL_DSA* dsa);
7658
WOLFSSL_LOCAL int SetRsaExternal(WOLFSSL_RSA* rsa);
7659
WOLFSSL_LOCAL int SetRsaInternal(WOLFSSL_RSA* rsa);
7660
7661
typedef enum elem_set {
7662
    ELEMENT_P   = 0x01,
7663
    ELEMENT_Q   = 0x02,
7664
    ELEMENT_G   = 0x04,
7665
    ELEMENT_PUB = 0x08,
7666
    ELEMENT_PRV = 0x10,
7667
} Element_Set;
7668
WOLFSSL_LOCAL int SetDhExternal_ex(WOLFSSL_DH *dh, int elm );
7669
WOLFSSL_LOCAL int SetDhInternal(WOLFSSL_DH* dh);
7670
WOLFSSL_LOCAL int SetDhExternal(WOLFSSL_DH *dh);
7671
#endif /* OPENSSL_EXTRA || OPENSSL_EXTRA_X509_SMALL */
7672
7673
#if !defined(NO_DH) && (!defined(NO_CERTS) || !defined(NO_PSK))
7674
    WOLFSSL_LOCAL int DhGenKeyPair(WOLFSSL* ssl, DhKey* dhKey,
7675
        byte* priv, word32* privSz,
7676
        byte* pub, word32* pubSz);
7677
    WOLFSSL_LOCAL int DhAgree(WOLFSSL* ssl, DhKey* dhKey,
7678
        const byte* priv, word32 privSz,
7679
        const byte* otherPub, word32 otherPubSz,
7680
        byte* agree, word32* agreeSz,
7681
        const byte* prime, word32 primeSz);
7682
#endif /* !NO_DH */
7683
7684
#ifdef HAVE_ECC
7685
    WOLFSSL_LOCAL int EccMakeKey(WOLFSSL* ssl, ecc_key* key, ecc_key* peer);
7686
    WOLFSSL_LOCAL word16 GetCurveByOID(int oidSum);
7687
#endif
7688
7689
WOLFSSL_LOCAL int InitHandshakeHashes(WOLFSSL* ssl);
7690
WOLFSSL_LOCAL void Free_HS_Hashes(HS_Hashes* hsHashes, void* heap);
7691
WOLFSSL_LOCAL void FreeHandshakeHashes(WOLFSSL* ssl);
7692
WOLFSSL_LOCAL int InitHandshakeHashesAndCopy(WOLFSSL* ssl, HS_Hashes* source,
7693
    HS_Hashes** destination);
7694
7695
7696
#ifndef WOLFSSL_NO_TLS12
7697
WOLFSSL_LOCAL void FreeBuildMsgArgs(WOLFSSL* ssl, BuildMsgArgs* args);
7698
#endif
7699
#ifdef WOLFSSL_API_PREFIX_MAP
7700
    #define BuildMessage wolfSSL_BuildMessage
7701
#endif
7702
WOLFSSL_TEST_VIS int BuildMessage(WOLFSSL* ssl, byte* output, int outSz,
7703
                        const byte* input, int inSz, int type, int hashOutput,
7704
                        int sizeOnly, int asyncOkay, int epochOrder);
7705
7706
#ifdef WOLFSSL_TLS13
7707
#ifdef WOLFSSL_API_PREFIX_MAP
7708
    #define BuildTls13Message wolfSSL_BuildTls13Message
7709
#endif
7710
WOLFSSL_TEST_VIS int BuildTls13Message(WOLFSSL* ssl, byte* output, int outSz, const byte* input,
7711
               int inSz, int type, int hashOutput, int sizeOnly, int asyncOkay);
7712
WOLFSSL_LOCAL int Tls13UpdateKeys(WOLFSSL* ssl);
7713
#endif
7714
7715
WOLFSSL_LOCAL int AllocKey(WOLFSSL* ssl, int type, void** pKey);
7716
WOLFSSL_LOCAL void FreeKey(WOLFSSL* ssl, int type, void** pKey);
7717
7718
#ifdef WOLFSSL_ASYNC_CRYPT
7719
    WOLFSSL_LOCAL int wolfSSL_AsyncInit(WOLFSSL* ssl, WC_ASYNC_DEV* asyncDev, word32 flags);
7720
    WOLFSSL_LOCAL int wolfSSL_AsyncPop(WOLFSSL* ssl, byte* state);
7721
    WOLFSSL_LOCAL int wolfSSL_AsyncPush(WOLFSSL* ssl, WC_ASYNC_DEV* asyncDev);
7722
#endif
7723
7724
#if defined(OPENSSL_ALL) && defined(WOLFSSL_CERT_GEN) && \
7725
    (defined(WOLFSSL_CERT_REQ) || defined(WOLFSSL_CERT_EXT)) && \
7726
    !defined(NO_FILESYSTEM) && !defined(NO_WOLFSSL_DIR)
7727
WOLFSSL_LOCAL int LoadCertByIssuer(WOLFSSL_X509_STORE* store,
7728
                                           X509_NAME* issuer, int Type);
7729
#endif
7730
#if defined(OPENSSL_ALL) && !defined(NO_FILESYSTEM) && !defined(NO_WOLFSSL_DIR)
7731
WOLFSSL_LOCAL WOLFSSL_BY_DIR_HASH* wolfSSL_BY_DIR_HASH_new(void);
7732
WOLFSSL_LOCAL void wolfSSL_BY_DIR_HASH_free(WOLFSSL_BY_DIR_HASH* dir_hash);
7733
WOLFSSL_LOCAL WOLFSSL_STACK* wolfSSL_sk_BY_DIR_HASH_new_null(void);
7734
WOLFSSL_LOCAL int wolfSSL_sk_BY_DIR_HASH_find(
7735
   WOLF_STACK_OF(WOLFSSL_BY_DIR_HASH)* sk, const WOLFSSL_BY_DIR_HASH* toFind);
7736
WOLFSSL_LOCAL int wolfSSL_sk_BY_DIR_HASH_num(const WOLF_STACK_OF(WOLFSSL_BY_DIR_HASH) *sk);
7737
WOLFSSL_LOCAL WOLFSSL_BY_DIR_HASH* wolfSSL_sk_BY_DIR_HASH_value(
7738
                        const WOLF_STACK_OF(WOLFSSL_BY_DIR_HASH) *sk, int i);
7739
WOLFSSL_LOCAL WOLFSSL_BY_DIR_HASH* wolfSSL_sk_BY_DIR_HASH_pop(
7740
                                WOLF_STACK_OF(WOLFSSL_BY_DIR_HASH)* sk);
7741
WOLFSSL_LOCAL void wolfSSL_sk_BY_DIR_HASH_pop_free(WOLF_STACK_OF(WOLFSSL_BY_DIR_HASH)* sk,
7742
    void (*f) (WOLFSSL_BY_DIR_HASH*));
7743
WOLFSSL_LOCAL void wolfSSL_sk_BY_DIR_HASH_free(WOLF_STACK_OF(WOLFSSL_BY_DIR_HASH) *sk);
7744
WOLFSSL_LOCAL int wolfSSL_sk_BY_DIR_HASH_push(WOLF_STACK_OF(WOLFSSL_BY_DIR_HASH)* sk,
7745
                                               WOLFSSL_BY_DIR_HASH* in);
7746
/* WOLFSSL_BY_DIR_entry stuff */
7747
WOLFSSL_LOCAL WOLFSSL_BY_DIR_entry* wolfSSL_BY_DIR_entry_new(void);
7748
WOLFSSL_LOCAL void wolfSSL_BY_DIR_entry_free(WOLFSSL_BY_DIR_entry* entry);
7749
WOLFSSL_LOCAL WOLFSSL_STACK* wolfSSL_sk_BY_DIR_entry_new_null(void);
7750
WOLFSSL_LOCAL int wolfSSL_sk_BY_DIR_entry_num(const WOLF_STACK_OF(WOLFSSL_BY_DIR_entry) *sk);
7751
WOLFSSL_LOCAL WOLFSSL_BY_DIR_entry* wolfSSL_sk_BY_DIR_entry_value(
7752
                        const WOLF_STACK_OF(WOLFSSL_BY_DIR_entry) *sk, int i);
7753
WOLFSSL_LOCAL WOLFSSL_BY_DIR_entry* wolfSSL_sk_BY_DIR_entry_pop(
7754
                                WOLF_STACK_OF(WOLFSSL_BY_DIR_entry)* sk);
7755
WOLFSSL_LOCAL void wolfSSL_sk_BY_DIR_entry_pop_free(WOLF_STACK_OF(wolfSSL_BY_DIR_entry)* sk,
7756
    void (*f) (WOLFSSL_BY_DIR_entry*));
7757
WOLFSSL_LOCAL void wolfSSL_sk_BY_DIR_entry_free(WOLF_STACK_OF(wolfSSL_BY_DIR_entry) *sk);
7758
WOLFSSL_LOCAL int wolfSSL_sk_BY_DIR_entry_push(WOLF_STACK_OF(wolfSSL_BY_DIR_entry)* sk,
7759
                                               WOLFSSL_BY_DIR_entry* in);
7760
#endif /* OPENSSL_ALL && !NO_FILESYSTEM && !NO_WOLFSSL_DIR */
7761
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
7762
WOLFSSL_LOCAL int oid2nid(word32 oid, int grp);
7763
WOLFSSL_LOCAL word32 nid2oid(int nid, int grp);
7764
WOLFSSL_LOCAL void wolfssl_object_info_slice_init(void);
7765
#endif
7766
7767
#ifdef WOLFSSL_DTLS
7768
WOLFSSL_TEST_VIS int wolfSSL_DtlsUpdateWindow(word16 cur_hi, word32 cur_lo,
7769
        word16* next_hi, word32* next_lo, word32 *window);
7770
WOLFSSL_LOCAL int DtlsUpdateWindow(WOLFSSL* ssl);
7771
WOLFSSL_LOCAL void DtlsResetState(WOLFSSL *ssl);
7772
WOLFSSL_LOCAL int DtlsIgnoreError(int err);
7773
WOLFSSL_LOCAL void DtlsSetSeqNumForReply(WOLFSSL* ssl);
7774
#endif
7775
7776
#ifdef WOLFSSL_DTLS13
7777
    #ifdef WOLFSSL_API_PREFIX_MAP
7778
        #define Dtls13GetEpoch wolfSSL_Dtls13GetEpoch
7779
        #define Dtls13NewEpoch wolfSSL_Dtls13NewEpoch
7780
        #define Dtls13CheckEpoch wolfSSL_Dtls13CheckEpoch
7781
        #define Dtls13HandshakeRecv wolfSSL_Dtls13HandshakeRecv
7782
        #define Dtls13WriteAckMessage wolfSSL_Dtls13WriteAckMessage
7783
        #define Dtls13RtxAddAck wolfSSL_Dtls13RtxAddAck
7784
        #define Dtls13DoScheduledWork wolfSSL_Dtls13DoScheduledWork
7785
    #endif
7786
7787
WOLFSSL_TEST_VIS struct Dtls13Epoch* Dtls13GetEpoch(WOLFSSL* ssl,
7788
    w64wrapper epochNumber);
7789
WOLFSSL_LOCAL void Dtls13SetOlderEpochSide(WOLFSSL* ssl, w64wrapper epochNumber,
7790
    int side);
7791
WOLFSSL_TEST_VIS int Dtls13NewEpoch(WOLFSSL* ssl, w64wrapper epochNumber,
7792
    int side);
7793
WOLFSSL_LOCAL int Dtls13SetEpochKeys(WOLFSSL* ssl, w64wrapper epochNumber,
7794
    enum encrypt_side side);
7795
WOLFSSL_LOCAL int Dtls13GetSeq(WOLFSSL* ssl, int order, word32* seq,
7796
    byte increment);
7797
WOLFSSL_LOCAL void Dtls13RtxRemoveRecord(WOLFSSL* ssl, w64wrapper epoch,
7798
    w64wrapper seq);
7799
WOLFSSL_TEST_VIS int Dtls13DoScheduledWork(WOLFSSL* ssl);
7800
WOLFSSL_LOCAL int Dtls13DeriveSnKeys(WOLFSSL* ssl, int provision);
7801
WOLFSSL_LOCAL int Dtls13SetRecordNumberKeys(WOLFSSL* ssl,
7802
    enum encrypt_side side);
7803
7804
WOLFSSL_LOCAL int Dtls13AddHeaders(byte* output, word32 length,
7805
    enum HandShakeType hs_type, WOLFSSL* ssl);
7806
WOLFSSL_LOCAL word16 Dtls13GetHeadersLength(WOLFSSL *ssl,
7807
    enum HandShakeType type);
7808
WOLFSSL_LOCAL word16 Dtls13GetRlHeaderLength(WOLFSSL *ssl, byte is_encrypted);
7809
WOLFSSL_LOCAL int Dtls13RlAddCiphertextHeader(WOLFSSL* ssl, byte* out,
7810
    word16 length);
7811
WOLFSSL_LOCAL int Dtls13RlAddPlaintextHeader(WOLFSSL* ssl, byte* out,
7812
    enum ContentType content_type, word16 length);
7813
WOLFSSL_LOCAL int Dtls13MinimumRecordLength(WOLFSSL* ssl);
7814
WOLFSSL_LOCAL int Dtls13EncryptRecordNumber(WOLFSSL* ssl, byte* hdr,
7815
    word16 recordLength);
7816
WOLFSSL_LOCAL int Dtls13IsUnifiedHeader(byte header_flags);
7817
WOLFSSL_LOCAL int Dtls13GetUnifiedHeaderSize(WOLFSSL* ssl, const byte input,
7818
    word16* size);
7819
WOLFSSL_LOCAL int Dtls13ParseUnifiedRecordLayer(WOLFSSL* ssl, const byte* input,
7820
    word16 input_size, Dtls13UnifiedHdrInfo* hdrInfo);
7821
WOLFSSL_LOCAL int Dtls13HandshakeSend(WOLFSSL* ssl, byte* output,
7822
    word16 output_size, word16 length, enum HandShakeType handshake_type,
7823
    int hash_output);
7824
WOLFSSL_LOCAL int Dtls13RecordRecvd(WOLFSSL* ssl);
7825
WOLFSSL_TEST_VIS int Dtls13CheckEpoch(WOLFSSL* ssl, enum HandShakeType type);
7826
WOLFSSL_TEST_VIS int Dtls13HandshakeRecv(WOLFSSL* ssl, byte* input,
7827
    word32* inOutIdx, word32 totalSz);
7828
WOLFSSL_LOCAL int Dtls13HandshakeAddHeader(WOLFSSL* ssl, byte* output,
7829
    enum HandShakeType msg_type, word32 length);
7830
#define EE_MASK (0x3)
7831
WOLFSSL_LOCAL int Dtls13FragmentsContinue(WOLFSSL* ssl);
7832
WOLFSSL_LOCAL int DoDtls13KeyUpdateAck(WOLFSSL* ssl);
7833
#ifdef WOLFSSL_DTLS_CID
7834
WOLFSSL_LOCAL int DoDtls13RequestConnectionId(WOLFSSL* ssl, const byte* input,
7835
    word32* inOutIdx, word32 size);
7836
WOLFSSL_LOCAL int DoDtls13NewConnectionId(WOLFSSL* ssl, const byte* input,
7837
    word32* inOutIdx, word32 size);
7838
#endif /* WOLFSSL_DTLS_CID */
7839
WOLFSSL_LOCAL int DoDtls13Ack(WOLFSSL* ssl, const byte* input, word32 inputSize,
7840
    word32* processedSize);
7841
WOLFSSL_LOCAL int Dtls13ReconstructEpochNumber(WOLFSSL* ssl, byte epochBits,
7842
    w64wrapper* epoch);
7843
WOLFSSL_LOCAL int Dtls13ReconstructSeqNumber(WOLFSSL* ssl,
7844
    Dtls13UnifiedHdrInfo* hdrInfo, w64wrapper* out);
7845
WOLFSSL_TEST_VIS int Dtls13WriteAckMessage(WOLFSSL* ssl,
7846
    Dtls13RecordNumber* recordNumberList, word16 recordsCount, word32* length);
7847
WOLFSSL_LOCAL int SendDtls13Ack(WOLFSSL* ssl);
7848
WOLFSSL_TEST_VIS int Dtls13RtxAddAck(WOLFSSL* ssl, w64wrapper epoch, w64wrapper seq);
7849
WOLFSSL_LOCAL int Dtls13RtxProcessingCertificate(WOLFSSL* ssl, byte* input,
7850
    word32 inputSize);
7851
WOLFSSL_LOCAL int Dtls13HashHandshake(WOLFSSL* ssl, const byte* input,
7852
    word16 length);
7853
WOLFSSL_LOCAL int Dtls13HashClientHello(const WOLFSSL* ssl, byte* hash,
7854
        int* hashSz, const byte* body, word32 length, CipherSpecs* specs);
7855
WOLFSSL_LOCAL void Dtls13FreeFsmResources(WOLFSSL* ssl);
7856
WOLFSSL_LOCAL void Dtls13RtxFlushBuffered(WOLFSSL* ssl,
7857
        byte keepNewSessionTicket);
7858
WOLFSSL_LOCAL int Dtls13RtxTimeout(WOLFSSL* ssl);
7859
WOLFSSL_LOCAL int Dtls13ProcessBufferedMessages(WOLFSSL* ssl);
7860
WOLFSSL_LOCAL int Dtls13CheckAEADFailLimit(WOLFSSL* ssl);
7861
WOLFSSL_LOCAL int Dtls13UpdateWindowRecordRecvd(WOLFSSL* ssl);
7862
#endif /* WOLFSSL_DTLS13 */
7863
7864
#ifdef WOLFSSL_STATIC_EPHEMERAL
7865
WOLFSSL_LOCAL int wolfSSL_StaticEphemeralKeyLoad(WOLFSSL* ssl, int keyAlgo, void* keyPtr);
7866
#endif
7867
7868
#ifndef NO_CERTS
7869
#if defined(OPENSSL_ALL) || defined(OPENSSL_EXTRA) || \
7870
    defined(OPENSSL_EXTRA_X509_SMALL)
7871
WOLFSSL_LOCAL int wolfSSL_ASN1_STRING_canon(WOLFSSL_ASN1_STRING* asn_out,
7872
    const WOLFSSL_ASN1_STRING* asn_in);
7873
#endif
7874
#ifdef OPENSSL_EXTRA
7875
WOLFSSL_LOCAL int GetX509Error(int e);
7876
#endif
7877
#endif
7878
7879
#ifdef HAVE_EX_DATA_CRYPTO
7880
typedef struct CRYPTO_EX_cb_ctx {
7881
    long ctx_l;
7882
    void *ctx_ptr;
7883
    WOLFSSL_CRYPTO_EX_new* new_func;
7884
    WOLFSSL_CRYPTO_EX_free* free_func;
7885
    WOLFSSL_CRYPTO_EX_dup* dup_func;
7886
    struct CRYPTO_EX_cb_ctx* next;
7887
} CRYPTO_EX_cb_ctx;
7888
7889
WOLFSSL_TEST_VIS extern CRYPTO_EX_cb_ctx* crypto_ex_cb_ctx_session;
7890
#ifdef WOLFSSL_API_PREFIX_MAP
7891
    #define crypto_ex_cb_free wolfSSL_crypto_ex_cb_free
7892
#endif
7893
WOLFSSL_TEST_VIS void crypto_ex_cb_free(CRYPTO_EX_cb_ctx* cb_ctx);
7894
WOLFSSL_LOCAL void crypto_ex_cb_setup_new_data(void *new_obj,
7895
        CRYPTO_EX_cb_ctx* cb_ctx, WOLFSSL_CRYPTO_EX_DATA* ex_data);
7896
WOLFSSL_LOCAL void crypto_ex_cb_free_data(void *obj, CRYPTO_EX_cb_ctx* cb_ctx,
7897
        WOLFSSL_CRYPTO_EX_DATA* ex_data);
7898
WOLFSSL_LOCAL int crypto_ex_cb_dup_data(const WOLFSSL_CRYPTO_EX_DATA *in,
7899
        WOLFSSL_CRYPTO_EX_DATA *out, CRYPTO_EX_cb_ctx* cb_ctx);
7900
WOLFSSL_LOCAL int wolfssl_local_get_ex_new_index(int class_index, long ctx_l,
7901
        void* ctx_ptr, WOLFSSL_CRYPTO_EX_new* new_func,
7902
        WOLFSSL_CRYPTO_EX_dup* dup_func, WOLFSSL_CRYPTO_EX_free* free_func);
7903
#endif /* HAVE_EX_DATA_CRYPTO */
7904
7905
WOLFSSL_LOCAL WC_RNG* wolfssl_get_global_rng(void);
7906
WOLFSSL_LOCAL WC_RNG* wolfssl_make_global_rng(void);
7907
7908
#if !defined(WOLFCRYPT_ONLY) && defined(OPENSSL_EXTRA)
7909
#if defined(WOLFSSL_KEY_GEN) && defined(WOLFSSL_PEM_TO_DER)
7910
WOLFSSL_LOCAL int EncryptDerKey(byte *der, int *derSz,
7911
    const WOLFSSL_EVP_CIPHER* cipher, unsigned char* passwd, int passwdSz,
7912
    byte **cipherInfo, int maxDerSz, int hashType);
7913
#endif
7914
#endif
7915
7916
#if !defined(NO_RSA) && defined(OPENSSL_EXTRA)
7917
WOLFSSL_LOCAL int wolfSSL_RSA_To_Der(WOLFSSL_RSA* rsa, byte** outBuf,
7918
    int publicKey, void* heap);
7919
#endif
7920
7921
#if defined(OPENSSL_ALL) || defined(WOLFSSL_NGINX) || defined(WOLFSSL_HAPROXY) \
7922
    || defined(OPENSSL_EXTRA) || defined(HAVE_LIGHTY) || defined(HAVE_SECRET_CALLBACK)
7923
WOLFSSL_LOCAL int wolfSSL_SSL_do_handshake_internal(WOLFSSL *s);
7924
#endif
7925
7926
#ifdef WOLFSSL_QUIC
7927
#define WOLFSSL_IS_QUIC(s)  (((s) != NULL) && ((s)->quic.method != NULL))
7928
WOLFSSL_LOCAL int wolfSSL_quic_receive(WOLFSSL* ssl, byte* buf, word32 sz);
7929
WOLFSSL_LOCAL int wolfSSL_quic_send(WOLFSSL* ssl);
7930
WOLFSSL_LOCAL void wolfSSL_quic_clear(WOLFSSL* ssl);
7931
WOLFSSL_LOCAL void wolfSSL_quic_free(WOLFSSL* ssl);
7932
WOLFSSL_LOCAL int wolfSSL_quic_forward_secrets(WOLFSSL *ssl,
7933
                                               int ktype, int side);
7934
WOLFSSL_LOCAL int wolfSSL_quic_keys_active(WOLFSSL* ssl, enum encrypt_side side);
7935
7936
#else
7937
0
#define WOLFSSL_IS_QUIC(s) 0
7938
#endif /* WOLFSSL_QUIC (else) */
7939
7940
#if defined(SHOW_SECRETS) && defined(WOLFSSL_SSLKEYLOGFILE)
7941
WOLFSSL_LOCAL int tls13ShowSecrets(WOLFSSL* ssl, int id, const unsigned char* secret,
7942
    int secretSz, void* ctx);
7943
#endif
7944
7945
#if defined(SHOW_SECRETS)
7946
WOLFSSL_LOCAL int tlsShowSecrets(WOLFSSL* ssl, void* secret,
7947
        int secretSz, void* ctx);
7948
#endif
7949
7950
/* Optional Pre-Master-Secret logging for Wireshark */
7951
#if !defined(NO_FILESYSTEM) && defined(WOLFSSL_SSLKEYLOGFILE)
7952
#ifndef WOLFSSL_SSLKEYLOGFILE_OUTPUT
7953
    #define WOLFSSL_SSLKEYLOGFILE_OUTPUT "sslkeylog.log"
7954
#endif
7955
#endif
7956
7957
#if defined(WOLFSSL_TLS13) && !defined(NO_PSK)
7958
WOLFSSL_LOCAL int FindPskSuite(const WOLFSSL* ssl, PreSharedKey* psk,
7959
        byte* psk_key, word32* psk_keySz, const byte* suite, int* found,
7960
        byte* foundSuite);
7961
#endif
7962
7963
WOLFSSL_LOCAL int wolfSSL_GetHmacType_ex(CipherSpecs* specs);
7964
7965
#if defined(WOLFSSL_SEND_HRR_COOKIE) && !defined(NO_WOLFSSL_SERVER)
7966
WOLFSSL_LOCAL int CreateCookieExt(const WOLFSSL* ssl, byte* hash,
7967
                                  word16 hashSz, TLSX** exts,
7968
                                  byte cipherSuite0, byte cipherSuite);
7969
#endif
7970
7971
WOLFSSL_LOCAL int TranslateErrorToAlert(int err);
7972
7973
#if defined(OPENSSL_EXTRA) || defined(WOLFSSL_WPAS_SMALL)
7974
WOLFSSL_LOCAL void* wolfssl_sk_pop_type(WOLFSSL_STACK* sk,
7975
                                        WOLF_STACK_TYPE type);
7976
WOLFSSL_LOCAL void* wolfSSL_sk_pop_node(WOLFSSL_STACK* sk, int idx);
7977
WOLFSSL_LOCAL WOLFSSL_STACK* wolfssl_sk_new_type(WOLF_STACK_TYPE type);
7978
WOLFSSL_LOCAL WOLFSSL_STACK* wolfssl_sk_new_type_ex(WOLF_STACK_TYPE type,
7979
        void* heap);
7980
7981
WOLFSSL_LOCAL int wolfssl_asn1_obj_set(WOLFSSL_ASN1_OBJECT* obj,
7982
        const byte* der, word32 len, int addHdr);
7983
#endif
7984
7985
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
7986
WOLFSSL_LOCAL int pkcs8_encode(WOLFSSL_EVP_PKEY* pkey, byte* key,
7987
        word32* keySz);
7988
WOLFSSL_LOCAL int pkcs8_encrypt(WOLFSSL_EVP_PKEY* pkey,
7989
        const WOLFSSL_EVP_CIPHER* enc, char* passwd, int passwdSz, byte* key,
7990
        word32* keySz);
7991
#endif /* OPENSSL_EXTRA || OPENSSL_EXTRA_X509_SMALL */
7992
7993
#if (defined(OPENSSL_EXTRA) || defined(OPENSSL_ALL)) && !defined(NO_BIO)
7994
WOLFSSL_LOCAL int wolfSSL_PEM_X509_X509_CRL_X509_PKEY_read_bio(
7995
        WOLFSSL_BIO* bio, wc_pem_password_cb* cb, WOLFSSL_X509** x509,
7996
        WOLFSSL_X509_CRL** crl, WOLFSSL_X509_PKEY** x_pkey);
7997
#endif
7998
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_ALL)
7999
WOLFSSL_LOCAL void wolfSSL_X509_PKEY_free(WOLFSSL_X509_PKEY* xPkey);
8000
#endif
8001
8002
WOLFSSL_LOCAL void wolfssl_local_MaybeCheckAlertOnErr(WOLFSSL* ssl, int err);
8003
8004
#ifdef __cplusplus
8005
    }  /* extern "C" */
8006
#endif
8007
8008
#endif /* wolfSSL_INT_H */