Coverage Report

Created: 2026-09-20 06:33

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wolfssl-openssl-api/src/tls13.c
Line
Count
Source
1
/* tls13.c
2
 *
3
 * Copyright (C) 2006-2026 wolfSSL Inc.
4
 *
5
 * This file is part of wolfSSL.
6
 *
7
 * wolfSSL is free software; you can redistribute it and/or modify
8
 * it under the terms of the GNU General Public License as published by
9
 * the Free Software Foundation; either version 3 of the License, or
10
 * (at your option) any later version.
11
 *
12
 * wolfSSL is distributed in the hope that it will be useful,
13
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
15
 * GNU General Public License for more details.
16
 *
17
 * You should have received a copy of the GNU General Public License
18
 * along with this program; if not, write to the Free Software
19
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335, USA
20
 */
21
22
#include <wolfssl/wolfcrypt/libwolfssl_sources.h>
23
24
/*
25
 * TLS 1.3-Specific Build Options:
26
 * (See tls.c for generic TLS options: extensions, curves, callbacks, etc.)
27
 *
28
 * Protocol:
29
 * WOLFSSL_TLS13:            Enable TLS 1.3 protocol               default: on
30
 * WOLFSSL_TLS13_DRAFT:      Enable TLS 1.3 draft version support  default: off
31
 * WOLFSSL_QUIC:             Enable QUIC protocol support (TLS 1.3) default: off
32
 * WOLFSSL_DTLS13_NO_HRR_ON_RESUME: Skip HRR on DTLS 1.3 resume   default: off
33
 * WOLFSSL_DTLS_CH_FRAG:     Enable DTLS 1.3 ClientHello frag     default: off
34
 *
35
 * Handshake:
36
 * WOLFSSL_TLS13_MIDDLEBOX_COMPAT: Client-side middlebox compatibility
37
 *                            default: off
38
 *                            Makes the client send a fake session id and its
39
 *                            own ChangeCipherSpec. The server always answers
40
 *                            a non-empty client session id with a
41
 *                            ChangeCipherSpec, as RFC 8446 Appendix D.4
42
 *                            requires, whether or not this is defined.
43
 * WOLFSSL_SEND_HRR_COOKIE:  Send cookie in HelloRetryRequest     default: off
44
 *                            for stateless ClientHello tracking. A client
45
 *                            always echoes back a cookie it is sent.
46
 * WOLFSSL_MAX_TLS13_COOKIE_SZ: Largest cookie a client accepts  default: 4096
47
 *                            in a HelloRetryRequest.
48
 * WOLFSSL_EARLY_DATA:       Allow 0-RTT early data                default: off
49
 * WOLFSSL_EARLY_DATA_GROUP: Group early data with ClientHello     default: off
50
 * WOLFSSL_POST_HANDSHAKE_AUTH: Post-handshake client auth         default: off
51
 * WOLFSSL_TLS13_TICKET_BEFORE_FINISHED: Send NewSessionTicket     default: off
52
 *                            before client Finished message. Violates the
53
 *                            RFC 8446 Section 4.6.1 ordering requirement; for
54
 *                            interop with peers that expect the early ticket.
55
 * WOLFSSL_DTLS13_ECHO_LEGACY_SESSION_ID: Echo legacy_session_id   default: off
56
 *                            in DTLS 1.3. Violates RFC 9147 Section 5 ("DTLS
57
 *                            servers MUST NOT echo the legacy_session_id
58
 *                            value from the client"). A server built with this
59
 *                            option echoes the session ID, which a compliant
60
 *                            client rejects, so enable it only where the peer
61
 *                            is wolfSSL <= 5.9.0 or shares this option.
62
 * WOLFSSL_NO_CLIENT_AUTH:   Disable TLS 1.3 client authentication default: off
63
 * WOLFSSL_NO_CLIENT_CERT_ERROR: Require client certificate        default: off
64
 * WOLFSSL_CERT_SETUP_CB:    Certificate setup callback            default: off
65
 * WOLFSSL_ALLOW_BAD_TLS_LEGACY_VERSION: Allow bad legacy version  default: off
66
 *
67
 * Security:
68
 * WOLFSSL_BLIND_PRIVATE_KEY: Blind private key during signing     default: off
69
 * WOLFSSL_CHECK_SIG_FAULTS: Verify signature after ECC signing    default: off
70
 *                            to detect fault injection attacks
71
 * WOLFSSL_CIPHER_TEXT_CHECK: Verify ciphertext integrity          default: off
72
 * WOLFSSL_TLS13_NULL_CIPHER_IN_DEFAULT: Include RFC 9150 suites   default: off
73
 *                            in the default cipher suite list (requires
74
 *                            HAVE_NULL_CIPHER). Without it the integrity-only
75
 *                            suites must be requested explicitly in the
76
 *                            cipher list, by name or with "eNULL".
77
 *
78
 * TLS 1.3 PSK:
79
 * WOLFSSL_PSK_ONE_ID:       Single PSK identity per connect       default: off
80
 * WOLFSSL_PSK_MULTI_ID_PER_CS: Multiple PSK IDs per cipher suite default: off
81
 * WOLFSSL_PRIORITIZE_PSK:   Prioritize PSK over ciphersuite order default: off
82
 *
83
 * TLS 1.3 Session Tickets:
84
 * WOLFSSL_TICKET_HAVE_ID:   Session tickets include ID            default: off
85
 *                            Forced on when WOLFSSL_EARLY_DATA is set.
86
 * WOLFSSL_TICKET_NONCE_MALLOC: Dynamically allocate ticket nonce  default: off
87
 * WOLFSSL_TLS13_TICKET_CHECK_PSK_MODES: Withhold NewSessionTicket default: off
88
 *                            when the ClientHello advertised no usable
89
 *                            psk_key_exchange_modes, as RFC 9846 Sections
90
 *                            4.3.9 and 4.7.1 require. Off by default: a peer
91
 *                            that omits the extension but expects a ticket
92
 *                            stops getting one.
93
 *
94
 * TLS 1.3 Key Exchange:
95
 * HAVE_KEYING_MATERIAL:     Export keying material (RFC 8446 7.5) default: off
96
 * WOLFSSL_HAVE_TLS_UNIQUE:  Enable tls-unique channel binding     default: off
97
 *
98
 * TLS 1.3 Hash/Signature:
99
 * WOLFSSL_TLS13_SHA512:     Allow SHA-512 in TLS 1.3 handshake   default: off
100
 *                            (no ciphersuite requires it currently)
101
 * WOLFSSL_ERROR_CODE_OPENSSL: Use OpenSSL-compatible error codes  default: off
102
 * WOLFSSL_SSLKEYLOGFILE_OUTPUT: Set key log output file path      default: off
103
 * WOLFSSL_SSLKEYLOGFILE_USE_ENV: Use SSLKEYLOGFILE env var path   default: off
104
 * WOLFSSL_RW_THREADED:      Enable read/write threading support   default: off
105
 * WOLFSSL_ASYNC_IO:         Enable async I/O operations           default: off
106
 * WOLFSSL_NONBLOCK_OCSP:    Non-blocking OCSP processing          default: off
107
 * WOLFSSL_TLS_OCSP_MULTI:   Multiple OCSP responses               default: off
108
 * WOLFSSL_WOLFSENTRY_HOOKS: wolfSentry integration hooks          default: off
109
 */
110
111
#if !defined(NO_TLS) && defined(WOLFSSL_TLS13)
112
113
/* 0-RTT anti-replay eviction needs the session cache. */
114
#if defined(WOLFSSL_EARLY_DATA) && defined(HAVE_SESSION_TICKET) && \
115
    defined(NO_SESSION_CACHE) && !defined(NO_WOLFSSL_SERVER) && \
116
    !defined(WOLFSSL_EARLY_DATA_NO_ANTI_REPLAY)
117
#error "WOLFSSL_EARLY_DATA with tickets requires !NO_SESSION_CACHE, or " \
118
       "define WOLFSSL_EARLY_DATA_NO_ANTI_REPLAY to opt out."
119
#endif
120
121
#ifndef WOLFCRYPT_ONLY
122
123
#ifdef HAVE_ERRNO_H
124
    #include <errno.h>
125
#endif
126
127
#if defined(__MACH__) || defined(__FreeBSD__) || \
128
    defined(__INCLUDE_NUTTX_CONFIG_H) || defined(WOLFSSL_RIOT_OS)
129
#include <sys/time.h>
130
#endif /* __MACH__ || __FreeBSD__ ||
131
          __INCLUDE_NUTTX_CONFIG_H || WOLFSSL_RIOT_OS */
132
133
134
#include <wolfssl/internal.h>
135
#include <wolfssl/error-ssl.h>
136
#include <wolfssl/wolfcrypt/asn.h>
137
#include <wolfssl/wolfcrypt/dh.h>
138
#include <wolfssl/wolfcrypt/kdf.h>
139
#include <wolfssl/wolfcrypt/signature.h>
140
#ifdef NO_INLINE
141
    #include <wolfssl/wolfcrypt/misc.h>
142
#else
143
    #define WOLFSSL_MISC_INCLUDED
144
    #include <wolfcrypt/src/misc.c>
145
#endif
146
147
#ifdef __sun
148
    #include <sys/filio.h>
149
#endif
150
151
#ifndef TRUE
152
    #define TRUE  1
153
#endif
154
#ifndef FALSE
155
    #define FALSE 0
156
#endif
157
158
#ifndef HAVE_AEAD
159
    #if !defined(_MSC_VER) && !defined(__TASKING__)
160
        #error "The build option HAVE_AEAD is required for TLS 1.3"
161
    #else
162
        #pragma \
163
        message("error: The build option HAVE_AEAD is required for TLS 1.3")
164
    #endif
165
#endif
166
167
#ifndef HAVE_HKDF
168
    #if !defined(_MSC_VER) && !defined(__TASKING__)
169
        #error "The build option HAVE_HKDF is required for TLS 1.3"
170
    #else
171
        #pragma message("error: The build option HAVE_HKDF is required for TLS 1.3")
172
    #endif
173
#endif
174
175
#ifndef HAVE_TLS_EXTENSIONS
176
    #if !defined(_MSC_VER) && !defined(__TASKING__)
177
        #error "The build option HAVE_TLS_EXTENSIONS is required for TLS 1.3"
178
    #else
179
        #pragma message("error: The build option HAVE_TLS_EXTENSIONS is required for TLS 1.3")
180
    #endif
181
#endif
182
183
184
/* Set ret to error value and jump to label.
185
 *
186
 * err     The error value to set.
187
 * eLabel  The label to jump to.
188
 */
189
0
#define ERROR_OUT(err, eLabel) { ret = (err); goto eLabel; }
190
191
/* Senders suspend/resume a pending record build only on the re-invoke path;
192
 * poll-completing backends block inside EncryptTls13() as before. */
193
#if defined(WOLFSSL_ASYNC_REINVOKE) && !defined(WOLF_CRYPTO_CB_ASYNC_POLL)
194
    #define TLS13_HS_ASYNC_OKAY 1
195
#else
196
0
    #define TLS13_HS_ASYNC_OKAY 0
197
#endif
198
199
#ifdef WOLFSSL_ASYNC_REINVOKE
200
/* Arm ssl->kdfAsyncDev for a key-schedule op that may pend, retiring this
201
 * connection's previous KDF event first (re-pushing a queued event would
202
 * self-link the event list). Returns 0 on success. */
203
static int Tls13KdfAsyncInit(WOLFSSL* ssl)
204
{
205
    int ret;
206
207
    if (ssl->asyncDev == &ssl->kdfAsyncDev) {
208
        ret = wolfSSL_AsyncPop(ssl, NULL);
209
        if (ret != 0 && ret != WC_NO_ERR_TRACE(WC_NO_PENDING_E) &&
210
                ret != WC_NO_ERR_TRACE(WC_PENDING_E)) {
211
            return ret;
212
        }
213
    }
214
215
#if defined(WOLF_CRYPTO_CB) && defined(WOLF_CRYPTO_CB_ASYNC_POLL)
216
    /* Never poll-routed: a zeroed cryptocbDevId would look poll-stamped to
217
     * wolfSSL_AsyncPop() and stop the resume state advancing. */
218
    ssl->kdfAsyncDev.cryptocbDevId = INVALID_DEVID;
219
#endif
220
    return wolfSSL_AsyncInit(ssl, &ssl->kdfAsyncDev, WC_ASYNC_FLAG_CALL_AGAIN);
221
}
222
223
#endif /* WOLFSSL_ASYNC_REINVOKE */
224
225
/* Cap on re-invoking a callback for a record the caller cannot resume
226
 * (alerts, asyncOkay = 0 senders); bounds the otherwise unbounded spin. */
227
#ifndef WOLFSSL_ASYNC_MAX_REINVOKE
228
#define WOLFSSL_ASYNC_MAX_REINVOKE 1000
229
#endif
230
231
/* Size of the TLS v1.3 label use when deriving keys. */
232
0
#define TLS13_PROTOCOL_LABEL_SZ    6
233
/* The protocol label for TLS v1.3. */
234
static const byte tls13ProtocolLabel[TLS13_PROTOCOL_LABEL_SZ + 1] = "tls13 ";
235
236
#ifdef WOLFSSL_DTLS13
237
#define DTLS13_PROTOCOL_LABEL_SZ    6
238
static const byte dtls13ProtocolLabel[DTLS13_PROTOCOL_LABEL_SZ + 1] = "dtls13";
239
#endif /* WOLFSSL_DTLS13 */
240
241
#if defined(HAVE_ECH)
242
#define ECH_ACCEPT_CONFIRMATION_LABEL_SZ 23
243
#define ECH_HRR_ACCEPT_CONFIRMATION_LABEL_SZ 27
244
static const byte
245
    echAcceptConfirmationLabel[ECH_ACCEPT_CONFIRMATION_LABEL_SZ + 1] =
246
    "ech accept confirmation";
247
static const byte
248
    echHrrAcceptConfirmationLabel[ECH_HRR_ACCEPT_CONFIRMATION_LABEL_SZ + 1] =
249
    "hrr ech accept confirmation";
250
#endif
251
252
#ifndef NO_CERTS
253
#if !defined(NO_RSA) || defined(HAVE_ECC) || defined(HAVE_ED25519) || \
254
    defined(HAVE_ED448) || defined(HAVE_FALCON) || defined(WOLFSSL_HAVE_MLDSA) || \
255
    defined(WOLFSSL_HAVE_SLHDSA)
256
257
static WC_INLINE int GetMsgHash(WOLFSSL* ssl, byte* hash);
258
259
#endif
260
#endif
261
262
/* Expand data using HMAC, salt and label and info.
263
 * TLS v1.3 defines this function. Use callback if available. */
264
static int Tls13HKDFExpandLabel(WOLFSSL* ssl, byte* okm, word32 okmLen,
265
                                const byte* prk, word32 prkLen,
266
                                const byte* protocol, word32 protocolLen,
267
                                const byte* label, word32 labelLen,
268
                                const byte* info, word32 infoLen,
269
                                int digest)
270
5.04k
{
271
5.04k
    int ret = WC_NO_ERR_TRACE(NOT_COMPILED_IN);
272
#ifdef WOLFSSL_ASYNC_REINVOKE
273
    int aret;
274
275
    /* Armed before the provider runs so a pending from the PK callback or
276
     * wolfCrypt path falls through to the single push below. */
277
    aret = Tls13KdfAsyncInit(ssl);
278
    if (aret != 0)
279
        return aret;
280
#endif
281
282
#if defined(HAVE_PK_CALLBACKS)
283
    if (ssl->ctx && ssl->ctx->HKDFExpandLabelCb) {
284
        ret = ssl->ctx->HKDFExpandLabelCb(okm, okmLen, prk, prkLen,
285
                                          protocol, protocolLen,
286
                                          label, labelLen,
287
                                          info, infoLen, digest,
288
                                          WOLFSSL_CLIENT_END /* ignored */);
289
    }
290
291
    if (ret == WC_NO_ERR_TRACE(NOT_COMPILED_IN))
292
#endif
293
5.04k
    {
294
5.04k
    PRIVATE_KEY_UNLOCK();
295
5.04k
#if !defined(HAVE_FIPS) || (defined(FIPS_VERSION_GE) && FIPS_VERSION_GE(6,0))
296
5.04k
    ret = wc_Tls13_HKDF_Expand_Label_ex(okm, okmLen, prk, prkLen,
297
5.04k
                                     protocol, protocolLen,
298
5.04k
                                     label, labelLen,
299
5.04k
                                     info, infoLen, digest,
300
5.04k
                                     ssl->heap, ssl->devId);
301
#else
302
    (void)ssl;
303
    ret = wc_Tls13_HKDF_Expand_Label(okm, okmLen, prk, prkLen,
304
                                     protocol, protocolLen,
305
                                     label, labelLen,
306
                                     info, infoLen, digest);
307
#endif
308
5.04k
    PRIVATE_KEY_LOCK();
309
5.04k
    }
310
#ifdef WOLFSSL_ASYNC_REINVOKE
311
    /* HKDF has no key object to carry a WC_ASYNC_DEV, so queue the
312
     * SSL-owned KDF device; without it the pop finds nothing pending and
313
     * replays the handshake message. CALL_AGAIN keeps the state put. */
314
    if (ret == WC_NO_ERR_TRACE(WC_PENDING_E))
315
        ret = wolfSSL_AsyncPush(ssl, &ssl->kdfAsyncDev);
316
#endif
317
5.04k
    return ret;
318
5.04k
}
319
320
/* Same as above, but pass in the side we are expanding for:
321
 * side: either WOLFSSL_CLIENT_END or WOLFSSL_SERVER_END.
322
 */
323
static int Tls13HKDFExpandKeyLabel(WOLFSSL* ssl, byte* okm, word32 okmLen,
324
                                   const byte* prk, word32 prkLen,
325
                                   const byte* protocol, word32 protocolLen,
326
                                   const byte* label, word32 labelLen,
327
                                   const byte* info, word32 infoLen,
328
                                   int digest, int side)
329
9.08k
{
330
9.08k
    int ret;
331
#ifdef WOLFSSL_ASYNC_REINVOKE
332
    ret = Tls13KdfAsyncInit(ssl);
333
    if (ret != 0)
334
        return ret;
335
#endif
336
337
#if defined(HAVE_PK_CALLBACKS)
338
    ret = WC_NO_ERR_TRACE(NOT_COMPILED_IN);
339
    if (ssl->ctx && ssl->ctx->HKDFExpandLabelCb) {
340
        ret = ssl->ctx->HKDFExpandLabelCb(okm, okmLen, prk, prkLen,
341
                                         protocol, protocolLen,
342
                                         label, labelLen,
343
                                         info, infoLen,
344
                                         digest, side);
345
    }
346
    /* No early return: a pending here must reach the push at the end. */
347
    if (ret == WC_NO_ERR_TRACE(NOT_COMPILED_IN))
348
#endif
349
9.08k
    {
350
351
9.08k
#if !defined(HAVE_FIPS) || (defined(FIPS_VERSION_GE) && FIPS_VERSION_GE(6,0))
352
9.08k
    ret = wc_Tls13_HKDF_Expand_Label_ex(okm, okmLen, prk, prkLen,
353
9.08k
                                      protocol, protocolLen,
354
9.08k
                                      label, labelLen,
355
9.08k
                                      info, infoLen, digest,
356
9.08k
                                      ssl->heap, ssl->devId);
357
358
#elif defined(HAVE_FIPS) && defined(wc_Tls13_HKDF_Expand_Label)
359
    ret = wc_Tls13_HKDF_Expand_Label_fips(okm, okmLen, prk, prkLen,
360
                                      protocol, protocolLen,
361
                                      label, labelLen,
362
                                      info, infoLen, digest);
363
#else
364
    ret = wc_Tls13_HKDF_Expand_Label(okm, okmLen, prk, prkLen,
365
                                      protocol, protocolLen,
366
                                      label, labelLen,
367
                                      info, infoLen, digest);
368
#endif
369
9.08k
    }
370
#ifdef WOLFSSL_ASYNC_REINVOKE
371
    /* HKDF has no key object to carry a WC_ASYNC_DEV, so queue the
372
     * SSL-owned KDF device; without it the pop finds nothing pending and
373
     * replays the handshake message. CALL_AGAIN keeps the state put. */
374
    if (ret == WC_NO_ERR_TRACE(WC_PENDING_E))
375
        ret = wolfSSL_AsyncPush(ssl, &ssl->kdfAsyncDev);
376
#endif
377
9.08k
    (void)ssl;
378
9.08k
    (void)side;
379
9.08k
    return ret;
380
9.08k
}
381
382
383
/* Derive a key from a message.
384
 *
385
 * ssl        The SSL/TLS object.
386
 * output     The buffer to hold the derived key.
387
 * outputLen  The length of the derived key.
388
 * secret     The secret used to derive the key (HMAC secret).
389
 * label      The label used to distinguish the context.
390
 * labelLen   The length of the label.
391
 * msg        The message data to derive key from.
392
 * msgLen     The length of the message data to derive key from.
393
 * hashAlgo   The hash algorithm to use in the HMAC.
394
 * returns 0 on success, otherwise failure.
395
 */
396
static int DeriveKeyMsg(WOLFSSL* ssl, byte* output, int outputLen,
397
                        const byte* secret, const byte* label, word32 labelLen,
398
                        byte* msg, int msgLen, int hashAlgo)
399
{
400
    byte        hash[WC_MAX_DIGEST_SIZE];
401
    Digest      digest;
402
    word32      hashSz = 0;
403
    const byte* protocol;
404
    word32      protocolLen;
405
    int         digestAlg = -1;
406
    int         ret = WC_NO_ERR_TRACE(BAD_FUNC_ARG);
407
408
    switch (hashAlgo) {
409
#ifndef NO_SHA256
410
        case sha256_mac:
411
            ret = wc_InitSha256_ex(&digest.sha256, ssl->heap, ssl->devId);
412
            if (ret == 0) {
413
                    ret = wc_Sha256Update(&digest.sha256, msg, (word32)msgLen);
414
                if (ret == 0)
415
                    ret = wc_Sha256Final(&digest.sha256, hash);
416
                wc_Sha256Free(&digest.sha256);
417
            }
418
            hashSz = WC_SHA256_DIGEST_SIZE;
419
            digestAlg = WC_SHA256;
420
            break;
421
#endif
422
#ifdef WOLFSSL_SHA384
423
        case sha384_mac:
424
            ret = wc_InitSha384_ex(&digest.sha384, ssl->heap, ssl->devId);
425
            if (ret == 0) {
426
                ret = wc_Sha384Update(&digest.sha384, msg, (word32)msgLen);
427
                if (ret == 0)
428
                    ret = wc_Sha384Final(&digest.sha384, hash);
429
                wc_Sha384Free(&digest.sha384);
430
            }
431
            hashSz = WC_SHA384_DIGEST_SIZE;
432
            digestAlg = WC_SHA384;
433
            break;
434
#endif
435
#ifdef WOLFSSL_TLS13_SHA512
436
        case sha512_mac:
437
            ret = wc_InitSha512_ex(&digest.sha512, ssl->heap, ssl->devId);
438
            if (ret == 0) {
439
                ret = wc_Sha512Update(&digest.sha512, msg, (word32)msgLen);
440
                if (ret == 0)
441
                    ret = wc_Sha512Final(&digest.sha512, hash);
442
                wc_Sha512Free(&digest.sha512);
443
            }
444
            hashSz = WC_SHA512_DIGEST_SIZE;
445
            digestAlg = WC_SHA512;
446
            break;
447
#endif
448
#ifdef WOLFSSL_SM3
449
        case sm3_mac:
450
            ret = wc_InitSm3(&digest.sm3, ssl->heap, ssl->devId);
451
            if (ret == 0) {
452
                ret = wc_Sm3Update(&digest.sm3, msg, (word32)msgLen);
453
                if (ret == 0)
454
                    ret = wc_Sm3Final(&digest.sm3, hash);
455
                wc_Sm3Free(&digest.sm3);
456
            }
457
            hashSz = WC_SM3_DIGEST_SIZE;
458
            digestAlg = WC_SM3;
459
            break;
460
#endif
461
        default:
462
            ret = BAD_FUNC_ARG;
463
            digestAlg = -1;
464
            break;
465
    }
466
467
    if (digestAlg < 0)
468
        return HASH_TYPE_E;
469
470
    if (ret != 0)
471
        return ret;
472
473
    switch (ssl->version.minor) {
474
        case TLSv1_3_MINOR:
475
            protocol = tls13ProtocolLabel;
476
            protocolLen = TLS13_PROTOCOL_LABEL_SZ;
477
            break;
478
#ifdef WOLFSSL_DTLS13
479
        case DTLSv1_3_MINOR:
480
            if (!ssl->options.dtls)
481
                return VERSION_ERROR;
482
483
            protocol = dtls13ProtocolLabel;
484
            protocolLen = DTLS13_PROTOCOL_LABEL_SZ;
485
            break;
486
#endif /* WOLFSSL_DTLS13 */
487
        default:
488
            return VERSION_ERROR;
489
    }
490
    if (outputLen == -1)
491
        outputLen = (int)hashSz;
492
493
    ret = Tls13HKDFExpandLabel(ssl, output, (word32)outputLen, secret, hashSz,
494
                               protocol, protocolLen, label, labelLen,
495
                               hash, hashSz, digestAlg);
496
    return ret;
497
}
498
499
/* Derive a key.
500
 *
501
 * ssl          The SSL/TLS object.
502
 * output       The buffer to hold the derived key.
503
 * outputLen    The length of the derived key.
504
 * secret       The secret used to derive the key (HMAC secret).
505
 * label        The label used to distinguish the context.
506
 * labelLen     The length of the label.
507
 * hashAlgo     The hash algorithm to use in the HMAC.
508
 * includeMsgs  Whether to include a hash of the handshake messages so far.
509
 * side         The side that we are deriving the secret for.
510
 * returns 0 on success, otherwise failure.
511
 */
512
int Tls13DeriveKey(WOLFSSL* ssl, byte* output, int outputLen,
513
                   const byte* secret, const byte* label, word32 labelLen,
514
                   int hashAlgo, int includeMsgs, int side)
515
0
{
516
0
    int         ret = 0;
517
0
    byte        hash[WC_MAX_DIGEST_SIZE];
518
0
    word32      hashSz = 0;
519
0
    word32      hashOutSz = 0;
520
0
    const byte* protocol;
521
0
    word32      protocolLen;
522
0
    int         digestAlg = 0;
523
524
525
0
    switch (hashAlgo) {
526
0
    #ifndef NO_SHA256
527
0
        case sha256_mac:
528
0
            hashSz    = WC_SHA256_DIGEST_SIZE;
529
0
            digestAlg = WC_SHA256;
530
0
            if (includeMsgs)
531
0
                ret = wc_Sha256GetHash(&ssl->hsHashes->hashSha256, hash);
532
0
            break;
533
0
    #endif
534
535
0
    #ifdef WOLFSSL_SHA384
536
0
        case sha384_mac:
537
0
            hashSz    = WC_SHA384_DIGEST_SIZE;
538
0
            digestAlg = WC_SHA384;
539
0
            if (includeMsgs)
540
0
                ret = wc_Sha384GetHash(&ssl->hsHashes->hashSha384, hash);
541
0
            break;
542
0
    #endif
543
544
    #ifdef WOLFSSL_TLS13_SHA512
545
        case sha512_mac:
546
            hashSz    = WC_SHA512_DIGEST_SIZE;
547
            digestAlg = WC_SHA512;
548
            if (includeMsgs)
549
                ret = wc_Sha512GetHash(&ssl->hsHashes->hashSha512, hash);
550
            break;
551
    #endif
552
553
0
    #ifdef WOLFSSL_SM3
554
0
        case sm3_mac:
555
0
            hashSz    = WC_SM3_DIGEST_SIZE;
556
0
            digestAlg = WC_SM3;
557
0
            if (includeMsgs)
558
0
                ret = wc_Sm3GetHash(&ssl->hsHashes->hashSm3, hash);
559
0
            break;
560
0
    #endif
561
562
0
        default:
563
0
            ret = HASH_TYPE_E;
564
0
            break;
565
0
    }
566
0
    if (ret != 0)
567
0
        return ret;
568
569
0
    protocol = tls13ProtocolLabel;
570
0
    protocolLen = TLS13_PROTOCOL_LABEL_SZ;
571
572
#ifdef WOLFSSL_DTLS13
573
    if (ssl->options.dtls) {
574
         protocol = dtls13ProtocolLabel;
575
         protocolLen = DTLS13_PROTOCOL_LABEL_SZ;
576
    }
577
#endif /* WOLFSSL_DTLS13 */
578
579
0
    if (outputLen == -1) {
580
0
        outputLen = (int)hashSz;
581
0
    }
582
0
    if (includeMsgs) {
583
0
        hashOutSz = hashSz;
584
0
    }
585
0
    else {
586
        /* Appease static analyzers by making sure hash is cleared, since it is
587
         * passed into expand key label where older wc_Tls13_HKDF_Expand_Label
588
         * will unconditionally try to call a memcpy on it, however length will
589
         * always be 0. */
590
0
        XMEMSET(hash, 0, sizeof(hash));
591
0
        hashOutSz = 0;
592
0
    }
593
594
0
    PRIVATE_KEY_UNLOCK();
595
0
    ret = Tls13HKDFExpandKeyLabel(ssl, output, (word32)outputLen, secret, hashSz,
596
0
                                  protocol, protocolLen, label, labelLen,
597
0
                                  hash, hashOutSz, digestAlg, side);
598
0
    PRIVATE_KEY_LOCK();
599
600
#ifdef WOLFSSL_CHECK_MEM_ZERO
601
    wc_MemZero_Add("TLS 1.3 derived key", output, outputLen);
602
#endif
603
0
    return ret;
604
0
}
605
606
/* Convert TLS mac ID to a hash algorithm ID
607
 *
608
 * mac Mac ID to convert
609
 * returns hash ID on success, or the NONE type.
610
 */
611
static WC_INLINE int mac2hash(int mac)
612
{
613
    int hash;
614
    switch (mac) {
615
        #ifndef NO_SHA256
616
        case sha256_mac:
617
            hash = WC_SHA256;
618
            break;
619
        #endif
620
621
        #ifdef WOLFSSL_SHA384
622
        case sha384_mac:
623
            hash = WC_SHA384;
624
            break;
625
        #endif
626
627
        #ifdef WOLFSSL_TLS13_SHA512
628
        case sha512_mac:
629
            hash = WC_SHA512;
630
            break;
631
        #endif
632
633
        #ifdef WOLFSSL_SM3
634
        case sm3_mac:
635
            hash = WC_SM3;
636
            break;
637
        #endif
638
639
    default:
640
        hash = WC_HASH_TYPE_NONE;
641
    }
642
    return hash;
643
}
644
645
#ifndef NO_PSK
646
/* The length of the binder key label. */
647
#define BINDER_KEY_LABEL_SZ         10
648
/* The binder key label. */
649
static const byte binderKeyLabel[BINDER_KEY_LABEL_SZ + 1] =
650
    "ext binder";
651
652
/* Derive the binder key.
653
 *
654
 * ssl  The SSL/TLS object.
655
 * key  The derived key.
656
 * returns 0 on success, otherwise failure.
657
 */
658
static int DeriveBinderKey(WOLFSSL* ssl, byte* key)
659
{
660
    WOLFSSL_MSG("Derive Binder Key");
661
    if (ssl == NULL || ssl->arrays == NULL) {
662
        return BAD_FUNC_ARG;
663
    }
664
    return DeriveKeyMsg(ssl, key, -1, ssl->arrays->secret,
665
                        binderKeyLabel, BINDER_KEY_LABEL_SZ,
666
                        NULL, 0, ssl->specs.mac_algorithm);
667
}
668
#endif /* !NO_PSK */
669
670
#if defined(HAVE_SESSION_TICKET) && \
671
    (!defined(NO_WOLFSSL_CLIENT) || !defined(NO_WOLFSSL_SERVER))
672
/* The length of the binder key resume label. */
673
0
#define BINDER_KEY_RESUME_LABEL_SZ  10
674
/* The binder key resume label. */
675
static const byte binderKeyResumeLabel[BINDER_KEY_RESUME_LABEL_SZ + 1] =
676
    "res binder";
677
678
/* Derive the binder resumption key.
679
 *
680
 * ssl  The SSL/TLS object.
681
 * key  The derived key.
682
 * returns 0 on success, otherwise failure.
683
 */
684
static int DeriveBinderKeyResume(WOLFSSL* ssl, byte* key)
685
0
{
686
0
    WOLFSSL_MSG("Derive Binder Key - Resumption");
687
0
    if (ssl == NULL || ssl->arrays == NULL) {
688
0
        return BAD_FUNC_ARG;
689
0
    }
690
0
    return DeriveKeyMsg(ssl, key, -1, ssl->arrays->secret,
691
0
                        binderKeyResumeLabel, BINDER_KEY_RESUME_LABEL_SZ,
692
0
                        NULL, 0, ssl->specs.mac_algorithm);
693
0
}
694
#endif /* HAVE_SESSION_TICKET && (!NO_WOLFSSL_CLIENT || !NO_WOLFSSL_SERVER) */
695
696
#ifdef WOLFSSL_EARLY_DATA
697
698
/* The length of the early traffic label. */
699
#define EARLY_TRAFFIC_LABEL_SZ      11
700
/* The early traffic label. */
701
static const byte earlyTrafficLabel[EARLY_TRAFFIC_LABEL_SZ + 1] =
702
    "c e traffic";
703
704
/* Derive the early traffic key.
705
 *
706
 * ssl  The SSL/TLS object.
707
 * key  The derived key.
708
 * side The side that we are deriving the secret for.
709
 * returns 0 on success, otherwise failure.
710
 */
711
static int DeriveEarlyTrafficSecret(WOLFSSL* ssl, byte* key, int side)
712
{
713
    int ret;
714
    WOLFSSL_MSG("Derive Early Traffic Secret");
715
    if (ssl == NULL || ssl->arrays == NULL) {
716
        return BAD_FUNC_ARG;
717
    }
718
719
#if defined(WOLFSSL_SNIFFER) && defined(WOLFSSL_SNIFFER_KEYLOGFILE)
720
    /* If this is called from a sniffer session with keylog file support,
721
     * obtain the appropriate secret from the callback */
722
    if (ssl->snifferSecretCb != NULL) {
723
        return ssl->snifferSecretCb(ssl->arrays->clientRandom,
724
                                    SNIFFER_SECRET_CLIENT_EARLY_TRAFFIC_SECRET,
725
                                    key);
726
    }
727
#endif /* WOLFSSL_SNIFFER && WOLFSSL_SNIFFER_KEYLOGFILE */
728
729
    ret = Tls13DeriveKey(ssl, key, -1, ssl->arrays->secret,
730
                    earlyTrafficLabel, EARLY_TRAFFIC_LABEL_SZ,
731
                    ssl->specs.mac_algorithm, 1, side);
732
#ifdef HAVE_SECRET_CALLBACK
733
    if (ret == 0 && ssl->tls13SecretCb != NULL) {
734
        ret = ssl->tls13SecretCb(ssl, CLIENT_EARLY_TRAFFIC_SECRET, key,
735
                                 ssl->specs.hash_size, ssl->tls13SecretCtx);
736
        if (ret != 0) {
737
            WOLFSSL_ERROR_VERBOSE(TLS13_SECRET_CB_E);
738
            return TLS13_SECRET_CB_E;
739
        }
740
    }
741
#ifdef OPENSSL_EXTRA
742
    if (ret == 0 && ssl->tls13KeyLogCb != NULL) {
743
        ret = ssl->tls13KeyLogCb(ssl, CLIENT_EARLY_TRAFFIC_SECRET, key,
744
                                ssl->specs.hash_size, NULL);
745
        if (ret != 0) {
746
            WOLFSSL_ERROR_VERBOSE(TLS13_SECRET_CB_E);
747
            return TLS13_SECRET_CB_E;
748
        }
749
    }
750
#endif /* OPENSSL_EXTRA */
751
#endif /* HAVE_SECRET_CALLBACK */
752
    return ret;
753
}
754
755
#endif
756
757
/* The length of the client handshake label. */
758
561
#define CLIENT_HANDSHAKE_LABEL_SZ   12
759
/* The client handshake label. */
760
static const byte clientHandshakeLabel[CLIENT_HANDSHAKE_LABEL_SZ + 1] =
761
    "c hs traffic";
762
763
/* Derive the client handshake key.
764
 *
765
 * ssl  The SSL/TLS object.
766
 * key  The derived key.
767
 * returns 0 on success, otherwise failure.
768
 */
769
static int DeriveClientHandshakeSecret(WOLFSSL* ssl, byte* key)
770
561
{
771
561
    int ret;
772
561
    WOLFSSL_MSG("Derive Client Handshake Secret");
773
561
    if (ssl == NULL || ssl->arrays == NULL) {
774
0
        return BAD_FUNC_ARG;
775
0
    }
776
777
#if defined(WOLFSSL_SNIFFER) && defined(WOLFSSL_SNIFFER_KEYLOGFILE)
778
    /* If this is called from a sniffer session with keylog file support,
779
     * obtain the appropriate secret from the callback */
780
    if (ssl->snifferSecretCb != NULL) {
781
        return ssl->snifferSecretCb(ssl->arrays->clientRandom,
782
                               SNIFFER_SECRET_CLIENT_HANDSHAKE_TRAFFIC_SECRET,
783
                               key);
784
    }
785
#endif /* WOLFSSL_SNIFFER && WOLFSSL_SNIFFER_KEYLOGFILE */
786
787
561
    ret = Tls13DeriveKey(ssl, key, -1, ssl->arrays->preMasterSecret,
788
561
                    clientHandshakeLabel, CLIENT_HANDSHAKE_LABEL_SZ,
789
561
                    ssl->specs.mac_algorithm, 1, WOLFSSL_CLIENT_END);
790
#ifdef HAVE_SECRET_CALLBACK
791
    if (ret == 0 && ssl->tls13SecretCb != NULL) {
792
        ret = ssl->tls13SecretCb(ssl, CLIENT_HANDSHAKE_TRAFFIC_SECRET, key,
793
                                 ssl->specs.hash_size, ssl->tls13SecretCtx);
794
        if (ret != 0) {
795
            WOLFSSL_ERROR_VERBOSE(TLS13_SECRET_CB_E);
796
            return TLS13_SECRET_CB_E;
797
        }
798
    }
799
#ifdef OPENSSL_EXTRA
800
    if (ret == 0 && ssl->tls13KeyLogCb != NULL) {
801
        ret = ssl->tls13KeyLogCb(ssl, CLIENT_HANDSHAKE_TRAFFIC_SECRET, key,
802
                                ssl->specs.hash_size, NULL);
803
        if (ret != 0) {
804
            WOLFSSL_ERROR_VERBOSE(TLS13_SECRET_CB_E);
805
            return TLS13_SECRET_CB_E;
806
        }
807
    }
808
#endif /* OPENSSL_EXTRA */
809
#endif /* HAVE_SECRET_CALLBACK */
810
561
    return ret;
811
561
}
812
813
/* The length of the server handshake label. */
814
551
#define SERVER_HANDSHAKE_LABEL_SZ   12
815
/* The server handshake label. */
816
static const byte serverHandshakeLabel[SERVER_HANDSHAKE_LABEL_SZ + 1] =
817
    "s hs traffic";
818
819
/* Derive the server handshake key.
820
 *
821
 * ssl  The SSL/TLS object.
822
 * key  The derived key.
823
 * returns 0 on success, otherwise failure.
824
 */
825
static int DeriveServerHandshakeSecret(WOLFSSL* ssl, byte* key)
826
551
{
827
551
    int ret;
828
551
    WOLFSSL_MSG("Derive Server Handshake Secret");
829
551
    if (ssl == NULL || ssl->arrays == NULL) {
830
0
        return BAD_FUNC_ARG;
831
0
    }
832
833
#if defined(WOLFSSL_SNIFFER) && defined(WOLFSSL_SNIFFER_KEYLOGFILE)
834
    /* If this is called from a sniffer session with keylog file support,
835
     * obtain the appropriate secret from the callback */
836
    if (ssl->snifferSecretCb != NULL) {
837
        return ssl->snifferSecretCb(ssl->arrays->clientRandom,
838
                                SNIFFER_SECRET_SERVER_HANDSHAKE_TRAFFIC_SECRET,
839
                                key);
840
    }
841
#endif /* WOLFSSL_SNIFFER && WOLFSSL_SNIFFER_KEYLOGFILE */
842
843
551
    ret = Tls13DeriveKey(ssl, key, -1, ssl->arrays->preMasterSecret,
844
551
                    serverHandshakeLabel, SERVER_HANDSHAKE_LABEL_SZ,
845
551
                    ssl->specs.mac_algorithm, 1, WOLFSSL_SERVER_END);
846
847
#ifdef HAVE_SECRET_CALLBACK
848
    if (ret == 0 && ssl->tls13SecretCb != NULL) {
849
        ret = ssl->tls13SecretCb(ssl, SERVER_HANDSHAKE_TRAFFIC_SECRET, key,
850
                                 ssl->specs.hash_size, ssl->tls13SecretCtx);
851
        if (ret != 0) {
852
            WOLFSSL_ERROR_VERBOSE(TLS13_SECRET_CB_E);
853
            return TLS13_SECRET_CB_E;
854
        }
855
    }
856
#ifdef OPENSSL_EXTRA
857
    if (ret == 0 && ssl->tls13KeyLogCb != NULL) {
858
        ret = ssl->tls13KeyLogCb(ssl, SERVER_HANDSHAKE_TRAFFIC_SECRET, key,
859
                                ssl->specs.hash_size, NULL);
860
        if (ret != 0) {
861
            WOLFSSL_ERROR_VERBOSE(TLS13_SECRET_CB_E);
862
            return TLS13_SECRET_CB_E;
863
        }
864
    }
865
#endif /* OPENSSL_EXTRA */
866
#endif /* HAVE_SECRET_CALLBACK */
867
551
    return ret;
868
551
}
869
870
/* The length of the client application traffic label. */
871
225
#define CLIENT_APP_LABEL_SZ         12
872
/* The client application traffic label. */
873
static const byte clientAppLabel[CLIENT_APP_LABEL_SZ + 1] =
874
    "c ap traffic";
875
876
/* Derive the client application traffic key.
877
 *
878
 * ssl  The SSL/TLS object.
879
 * key  The derived key.
880
 * returns 0 on success, otherwise failure.
881
 */
882
static int DeriveClientTrafficSecret(WOLFSSL* ssl, byte* key)
883
225
{
884
225
    int ret;
885
225
    WOLFSSL_MSG("Derive Client Traffic Secret");
886
225
    if (ssl == NULL || ssl->arrays == NULL) {
887
0
        return BAD_FUNC_ARG;
888
0
    }
889
890
#if defined(WOLFSSL_SNIFFER) && defined(WOLFSSL_SNIFFER_KEYLOGFILE)
891
    /* If this is called from a sniffer session with keylog file support,
892
     * obtain the appropriate secret from the callback */
893
    if (ssl->snifferSecretCb != NULL) {
894
        return ssl->snifferSecretCb(ssl->arrays->clientRandom,
895
                                    SNIFFER_SECRET_CLIENT_TRAFFIC_SECRET,
896
                                    key);
897
    }
898
#endif /* WOLFSSL_SNIFFER && WOLFSSL_SNIFFER_KEYLOGFILE */
899
900
225
    ret = Tls13DeriveKey(ssl, key, -1, ssl->arrays->masterSecret,
901
225
                    clientAppLabel, CLIENT_APP_LABEL_SZ,
902
225
                    ssl->specs.mac_algorithm, 1, WOLFSSL_CLIENT_END);
903
904
#ifdef HAVE_SECRET_CALLBACK
905
    if (ret == 0 && ssl->tls13SecretCb != NULL) {
906
        ret = ssl->tls13SecretCb(ssl, CLIENT_TRAFFIC_SECRET, key,
907
                                 ssl->specs.hash_size, ssl->tls13SecretCtx);
908
        if (ret != 0) {
909
            WOLFSSL_ERROR_VERBOSE(TLS13_SECRET_CB_E);
910
            return TLS13_SECRET_CB_E;
911
        }
912
    }
913
#ifdef OPENSSL_EXTRA
914
    if (ret == 0 && ssl->tls13KeyLogCb != NULL) {
915
        ret = ssl->tls13KeyLogCb(ssl, CLIENT_TRAFFIC_SECRET, key,
916
                                ssl->specs.hash_size, NULL);
917
        if (ret != 0) {
918
            WOLFSSL_ERROR_VERBOSE(TLS13_SECRET_CB_E);
919
            return TLS13_SECRET_CB_E;
920
        }
921
    }
922
#endif /* OPENSSL_EXTRA */
923
#endif /* HAVE_SECRET_CALLBACK */
924
225
    return ret;
925
225
}
926
927
/* The length of the server application traffic label. */
928
231
#define SERVER_APP_LABEL_SZ         12
929
/* The  server application traffic label. */
930
static const byte serverAppLabel[SERVER_APP_LABEL_SZ + 1] =
931
    "s ap traffic";
932
933
/* Derive the server application traffic key.
934
 *
935
 * ssl  The SSL/TLS object.
936
 * key  The derived key.
937
 * returns 0 on success, otherwise failure.
938
 */
939
static int DeriveServerTrafficSecret(WOLFSSL* ssl, byte* key)
940
231
{
941
231
    int ret;
942
231
    WOLFSSL_MSG("Derive Server Traffic Secret");
943
231
    if (ssl == NULL || ssl->arrays == NULL) {
944
0
        return BAD_FUNC_ARG;
945
0
    }
946
947
#if defined(WOLFSSL_SNIFFER) && defined(WOLFSSL_SNIFFER_KEYLOGFILE)
948
    /* If this is called from a sniffer session with keylog file support,
949
     * obtain the appropriate secret from the callback */
950
    if (ssl->snifferSecretCb != NULL) {
951
        return ssl->snifferSecretCb(ssl->arrays->clientRandom,
952
                                    SNIFFER_SECRET_SERVER_TRAFFIC_SECRET,
953
                                    key);
954
    }
955
#endif /* WOLFSSL_SNIFFER && WOLFSSL_SNIFFER_KEYLOGFILE */
956
957
231
    ret = Tls13DeriveKey(ssl, key, -1, ssl->arrays->masterSecret,
958
231
                    serverAppLabel, SERVER_APP_LABEL_SZ,
959
231
                    ssl->specs.mac_algorithm, 1, WOLFSSL_SERVER_END);
960
961
#ifdef HAVE_SECRET_CALLBACK
962
    if (ret == 0 && ssl->tls13SecretCb != NULL) {
963
        ret = ssl->tls13SecretCb(ssl, SERVER_TRAFFIC_SECRET, key,
964
                                 ssl->specs.hash_size, ssl->tls13SecretCtx);
965
        if (ret != 0) {
966
            WOLFSSL_ERROR_VERBOSE(TLS13_SECRET_CB_E);
967
            return TLS13_SECRET_CB_E;
968
        }
969
    }
970
#ifdef OPENSSL_EXTRA
971
    if (ret == 0 && ssl->tls13KeyLogCb != NULL) {
972
        ret = ssl->tls13KeyLogCb(ssl, SERVER_TRAFFIC_SECRET, key,
973
                                ssl->specs.hash_size, NULL);
974
        if (ret != 0) {
975
            WOLFSSL_ERROR_VERBOSE(TLS13_SECRET_CB_E);
976
            return TLS13_SECRET_CB_E;
977
        }
978
    }
979
#endif /* OPENSSL_EXTRA */
980
#endif /* HAVE_SECRET_CALLBACK */
981
231
    return ret;
982
231
}
983
984
#ifdef HAVE_KEYING_MATERIAL
985
/* The length of the exporter master secret label. */
986
#define EXPORTER_MASTER_LABEL_SZ    10
987
/* The exporter master secret label. */
988
static const byte exporterMasterLabel[EXPORTER_MASTER_LABEL_SZ + 1] =
989
    "exp master";
990
991
/* Derive the exporter secret.
992
 *
993
 * ssl  The SSL/TLS object.
994
 * key  The derived key.
995
 * returns 0 on success, otherwise failure.
996
 */
997
static int DeriveExporterSecret(WOLFSSL* ssl, byte* key)
998
{
999
    int ret;
1000
    WOLFSSL_ENTER("Derive Exporter Secret");
1001
    if (ssl == NULL || ssl->arrays == NULL) {
1002
        return BAD_FUNC_ARG;
1003
    }
1004
    ret = Tls13DeriveKey(ssl, key, -1, ssl->arrays->masterSecret,
1005
                        exporterMasterLabel, EXPORTER_MASTER_LABEL_SZ,
1006
                        ssl->specs.mac_algorithm, 1, 0 /* Unused */);
1007
#ifdef HAVE_SECRET_CALLBACK
1008
    if (ret == 0 && ssl->tls13SecretCb != NULL) {
1009
        ret = ssl->tls13SecretCb(ssl, EXPORTER_SECRET, key,
1010
                                 ssl->specs.hash_size, ssl->tls13SecretCtx);
1011
        if (ret != 0) {
1012
            WOLFSSL_ERROR_VERBOSE(TLS13_SECRET_CB_E);
1013
            return TLS13_SECRET_CB_E;
1014
        }
1015
    }
1016
#ifdef OPENSSL_EXTRA
1017
    if (ret == 0 && ssl->tls13KeyLogCb != NULL) {
1018
        ret = ssl->tls13KeyLogCb(ssl, EXPORTER_SECRET, key,
1019
                                ssl->specs.hash_size, NULL);
1020
        if (ret != 0) {
1021
            WOLFSSL_ERROR_VERBOSE(TLS13_SECRET_CB_E);
1022
            return TLS13_SECRET_CB_E;
1023
        }
1024
    }
1025
#endif /* OPENSSL_EXTRA */
1026
#endif /* HAVE_SECRET_CALLBACK */
1027
    return ret;
1028
}
1029
1030
/* The length of the exporter label. */
1031
#define EXPORTER_LABEL_SZ    8
1032
/* The exporter label. */
1033
static const byte exporterLabel[EXPORTER_LABEL_SZ + 1] =
1034
    "exporter";
1035
/* Hash("") */
1036
#ifndef NO_SHA256
1037
static const byte emptySHA256Hash[] = {
1038
    0xE3, 0xB0, 0xC4, 0x42, 0x98, 0xFC, 0x1C, 0x14, 0x9A, 0xFB, 0xF4, 0xC8,
1039
    0x99, 0x6F, 0xB9, 0x24, 0x27, 0xAE, 0x41, 0xE4, 0x64, 0x9B, 0x93, 0x4C,
1040
    0xA4, 0x95, 0x99, 0x1B, 0x78, 0x52, 0xB8, 0x55
1041
};
1042
#endif
1043
#ifdef WOLFSSL_SHA384
1044
static const byte emptySHA384Hash[] = {
1045
    0x38, 0xB0, 0x60, 0xA7, 0x51, 0xAC, 0x96, 0x38, 0x4C, 0xD9, 0x32, 0x7E,
1046
    0xB1, 0xB1, 0xE3, 0x6A, 0x21, 0xFD, 0xB7, 0x11, 0x14, 0xBE, 0x07, 0x43,
1047
    0x4C, 0x0C, 0xC7, 0xBF, 0x63, 0xF6, 0xE1, 0xDA, 0x27, 0x4E, 0xDE, 0xBF,
1048
    0xE7, 0x6F, 0x65, 0xFB, 0xD5, 0x1A, 0xD2, 0xF1, 0x48, 0x98, 0xB9, 0x5B
1049
};
1050
#endif
1051
#ifdef WOLFSSL_TLS13_SHA512
1052
static const byte emptySHA512Hash[] = {
1053
    0xCF, 0x83, 0xE1, 0x35, 0x7E, 0xEF, 0xB8, 0xBD, 0xF1, 0x54, 0x28, 0x50,
1054
    0xD6, 0x6D, 0x80, 0x07, 0xD6, 0x20, 0xE4, 0x05, 0x0B, 0x57, 0x15, 0xDC,
1055
    0x83, 0xF4, 0xA9, 0x21, 0xD3, 0x6C, 0xE9, 0xCE, 0x47, 0xD0, 0xD1, 0x3C,
1056
    0x5D, 0x85, 0xF2, 0xB0, 0xFF, 0x83, 0x18, 0xD2, 0x87, 0x7E, 0xEC, 0x2F,
1057
    0x63, 0xB9, 0x31, 0xBD, 0x47, 0x41, 0x7A, 0x81, 0xA5, 0x38, 0x32, 0x7A,
1058
    0xF9, 0x27, 0xDA, 0x3E
1059
};
1060
#endif
1061
#ifdef WOLFSSL_SM3
1062
static const byte emptySM3Hash[] = {
1063
    0x1A, 0xB2, 0x1D, 0x83, 0x55, 0xCF, 0xA1, 0x7F, 0x8E, 0x61, 0x19, 0x48,
1064
    0x31, 0xE8, 0x1A, 0x8F, 0x22, 0xBE, 0xC8, 0xC7, 0x28, 0xFE, 0xFB, 0x74,
1065
    0x7E, 0xD0, 0x35, 0xEB, 0x50, 0x82, 0xAA, 0x2B
1066
};
1067
#endif
1068
/**
1069
 * Implement section 7.5 of RFC 8446
1070
 * @return  0 on success
1071
 *         <0 on failure
1072
 */
1073
int Tls13_Exporter(WOLFSSL* ssl, unsigned char *out, size_t outLen,
1074
        const char *label, size_t labelLen,
1075
        const unsigned char *context, size_t contextLen)
1076
{
1077
    int                 ret;
1078
    enum wc_HashType    hashType = WC_HASH_TYPE_NONE;
1079
    word32              hashLen = 0;
1080
    byte                hashOut[WC_MAX_DIGEST_SIZE];
1081
    const byte*         emptyHash = NULL;
1082
    byte                firstExpand[WC_MAX_DIGEST_SIZE];
1083
    const byte*         protocol = tls13ProtocolLabel;
1084
    word32              protocolLen = TLS13_PROTOCOL_LABEL_SZ;
1085
1086
    if (ssl->options.dtls && ssl->version.minor != DTLSv1_3_MINOR)
1087
        return VERSION_ERROR;
1088
1089
    if (!ssl->options.dtls && ssl->version.minor != TLSv1_3_MINOR)
1090
        return VERSION_ERROR;
1091
1092
#ifdef WOLFSSL_DTLS13
1093
    if (ssl->options.dtls) {
1094
        protocol = dtls13ProtocolLabel;
1095
        protocolLen = DTLS13_PROTOCOL_LABEL_SZ;
1096
    }
1097
#endif /* WOLFSSL_DTLS13 */
1098
1099
    /* Sanity check contextLen to prevent truncation when cast to word32. */
1100
    if (contextLen > WOLFSSL_MAX_32BIT)
1101
        return BAD_FUNC_ARG;
1102
    /* RFC 8446 HkdfLabel encodes the output length as a uint16, so requested
1103
     * lengths > 65535 cannot be represented and must be rejected. */
1104
    if (outLen > WOLFSSL_MAX_16BIT)
1105
        return BAD_FUNC_ARG;
1106
    /* RFC 8446 HkdfLabel encodes the label length in a single byte, so
1107
     * anything > 255 cannot be represented and must be rejected.
1108
     * The protocol length is included in the label. */
1109
    if ((labelLen +  protocolLen) > WOLFSSL_MAX_8BIT)
1110
        return BAD_FUNC_ARG;
1111
1112
    switch (ssl->specs.mac_algorithm) {
1113
        #ifndef NO_SHA256
1114
        case sha256_mac:
1115
            hashType  = WC_HASH_TYPE_SHA256;
1116
            hashLen   = WC_SHA256_DIGEST_SIZE;
1117
            emptyHash = emptySHA256Hash;
1118
            break;
1119
        #endif
1120
1121
        #ifdef WOLFSSL_SHA384
1122
        case sha384_mac:
1123
            hashType  = WC_HASH_TYPE_SHA384;
1124
            hashLen   = WC_SHA384_DIGEST_SIZE;
1125
            emptyHash = emptySHA384Hash;
1126
            break;
1127
        #endif
1128
1129
        #ifdef WOLFSSL_TLS13_SHA512
1130
        case sha512_mac:
1131
            hashType  = WC_HASH_TYPE_SHA512;
1132
            hashLen   = WC_SHA512_DIGEST_SIZE;
1133
            emptyHash = emptySHA512Hash;
1134
            break;
1135
        #endif
1136
1137
        #ifdef WOLFSSL_SM3
1138
        case sm3_mac:
1139
            hashType  = WC_HASH_TYPE_SM3;
1140
            hashLen   = WC_SM3_DIGEST_SIZE;
1141
            emptyHash = emptySM3Hash;
1142
            break;
1143
        #endif
1144
1145
        default:
1146
            return BAD_FUNC_ARG;
1147
    }
1148
1149
#ifdef WOLFSSL_CHECK_MEM_ZERO
1150
    /* Poison and register firstExpand before it is written so that any path
1151
     * below (all of which funnel through cleanup) is covered. */
1152
    XMEMSET(firstExpand, 0xff, sizeof(firstExpand));
1153
    wc_MemZero_Add("Tls13_Exporter firstExpand", firstExpand,
1154
                   sizeof(firstExpand));
1155
#endif
1156
1157
    /* Derive-Secret(Secret, label, "") */
1158
    ret = Tls13HKDFExpandLabel(ssl, firstExpand, hashLen,
1159
            ssl->arrays->exporterSecret, hashLen,
1160
            protocol, protocolLen, (byte*)label, (word32)labelLen,
1161
            emptyHash, hashLen, (int)hashType);
1162
    if (ret != 0)
1163
        goto cleanup;
1164
1165
    /* Hash(context_value) */
1166
    ret = wc_Hash(hashType, context, (word32)contextLen, hashOut, WC_MAX_DIGEST_SIZE);
1167
    if (ret != 0)
1168
        goto cleanup;
1169
1170
    ret = Tls13HKDFExpandLabel(ssl, out, (word32)outLen, firstExpand, hashLen,
1171
            protocol, protocolLen, exporterLabel, EXPORTER_LABEL_SZ,
1172
            hashOut, hashLen, (int)hashType);
1173
1174
cleanup:
1175
    /* firstExpand is the per-label Derive-Secret PRK and hashOut holds
1176
     * Hash(context_value); wipe both before the stack frame is reclaimed. */
1177
    ForceZero(firstExpand, sizeof(firstExpand));
1178
    ForceZero(hashOut, sizeof(hashOut));
1179
#ifdef WOLFSSL_CHECK_MEM_ZERO
1180
    wc_MemZero_Check(firstExpand, sizeof(firstExpand));
1181
#endif
1182
    return ret;
1183
}
1184
#endif
1185
1186
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
1187
/* The length of the resumption master secret label. */
1188
0
#define RESUME_MASTER_LABEL_SZ      10
1189
/* The resumption master secret label. */
1190
static const byte resumeMasterLabel[RESUME_MASTER_LABEL_SZ + 1] =
1191
    "res master";
1192
1193
/* Derive the resumption secret.
1194
 *
1195
 * ssl  The SSL/TLS object.
1196
 * key  The derived key.
1197
 * returns 0 on success, otherwise failure.
1198
 */
1199
int DeriveResumptionSecret(WOLFSSL* ssl, byte* key)
1200
0
{
1201
0
    byte* masterSecret;
1202
1203
0
    WOLFSSL_MSG("Derive Resumption Secret");
1204
0
    if (ssl == NULL) {
1205
0
        return BAD_FUNC_ARG;
1206
0
    }
1207
0
    if (ssl->arrays != NULL) {
1208
0
        masterSecret = ssl->arrays->masterSecret;
1209
0
    }
1210
0
    else {
1211
0
        masterSecret = ssl->session->masterSecret;
1212
0
    }
1213
0
    return Tls13DeriveKey(ssl, key, -1, masterSecret, resumeMasterLabel,
1214
0
                     RESUME_MASTER_LABEL_SZ, ssl->specs.mac_algorithm, 1,
1215
0
                     0 /* Unused */);
1216
0
}
1217
#endif
1218
1219
/* Length of the finished label. */
1220
4.70k
#define FINISHED_LABEL_SZ           8
1221
/* Finished label for generating finished key. */
1222
static const byte finishedLabel[FINISHED_LABEL_SZ+1] = "finished";
1223
/* Derive the finished secret.
1224
 *
1225
 * ssl     The SSL/TLS object.
1226
 * key     The key to use with the HMAC.
1227
 * secret  The derived secret.
1228
 * side    The side that we are deriving the secret for.
1229
 * returns 0 on success, otherwise failure.
1230
 */
1231
static int DeriveFinishedSecret(WOLFSSL* ssl, byte* key, byte* secret,
1232
                                int side)
1233
4.70k
{
1234
4.70k
    WOLFSSL_MSG("Derive Finished Secret");
1235
4.70k
    return Tls13DeriveKey(ssl, secret, -1, key, finishedLabel,
1236
4.70k
                          FINISHED_LABEL_SZ,  ssl->specs.mac_algorithm, 0,
1237
4.70k
                          side);
1238
4.70k
}
1239
1240
/* The length of the application traffic label. */
1241
0
#define APP_TRAFFIC_LABEL_SZ        11
1242
/* The application traffic label. */
1243
static const byte appTrafficLabel[APP_TRAFFIC_LABEL_SZ + 1] =
1244
    "traffic upd";
1245
1246
/* Update the traffic secret.
1247
 *
1248
 * ssl     The SSL/TLS object.
1249
 * secret  The previous secret and derived secret.
1250
 * side    The side that we are deriving the secret for.
1251
 * returns 0 on success, otherwise failure.
1252
 */
1253
static int DeriveTrafficSecret(WOLFSSL* ssl, byte* secret, int side)
1254
0
{
1255
0
    WOLFSSL_MSG("Derive New Application Traffic Secret");
1256
0
    return Tls13DeriveKey(ssl, secret, -1, secret,
1257
0
                     appTrafficLabel, APP_TRAFFIC_LABEL_SZ,
1258
0
                     ssl->specs.mac_algorithm, 0, side);
1259
0
}
1260
1261
1262
static int Tls13_HKDF_Extract(WOLFSSL *ssl, byte* prk, const byte* salt,
1263
                              int saltLen, byte* ikm, int ikmLen, int digest)
1264
6.00k
{
1265
6.00k
    int ret;
1266
#ifdef HAVE_PK_CALLBACKS
1267
    void *cb_ctx;
1268
    CallbackHKDFExtract cb;
1269
#endif
1270
1271
#ifdef WOLFSSL_ASYNC_REINVOKE
1272
    ret = Tls13KdfAsyncInit(ssl);
1273
    if (ret != 0)
1274
        return ret;
1275
#endif
1276
1277
#ifdef HAVE_PK_CALLBACKS
1278
    cb_ctx = ssl->HkdfExtractCtx;
1279
    cb = ssl->ctx->HkdfExtractCb;
1280
    if (cb != NULL) {
1281
        ret = cb(prk, salt, (word32)saltLen, ikm, (word32)ikmLen, digest, cb_ctx);
1282
    }
1283
    else
1284
#endif
1285
6.00k
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
1286
6.00k
    if ((int)ssl->arrays->psk_keySz < 0) {
1287
0
        ret = PSK_KEY_ERROR;
1288
0
    }
1289
6.00k
    else
1290
6.00k
#endif
1291
6.00k
    {
1292
6.00k
    #if !defined(HAVE_FIPS) || \
1293
6.00k
        (defined(FIPS_VERSION_GE) && FIPS_VERSION_GE(6,0))
1294
6.00k
        ret = wc_Tls13_HKDF_Extract_ex(prk, salt, (word32)saltLen, ikm, (word32)ikmLen, digest,
1295
6.00k
            ssl->heap, ssl->devId);
1296
    #else
1297
        ret = wc_Tls13_HKDF_Extract(prk, salt, saltLen, ikm, ikmLen, digest);
1298
        (void)ssl;
1299
    #endif
1300
6.00k
    }
1301
#ifdef WOLFSSL_ASYNC_REINVOKE
1302
    if (ret == WC_NO_ERR_TRACE(WC_PENDING_E))
1303
        ret = wolfSSL_AsyncPush(ssl, &ssl->kdfAsyncDev);
1304
#endif
1305
6.00k
    return ret;
1306
6.00k
}
1307
1308
/* Derive the early secret using HKDF Extract.
1309
 *
1310
 * ssl  The SSL/TLS object.
1311
 */
1312
int DeriveEarlySecret(WOLFSSL* ssl)
1313
5.20k
{
1314
5.20k
    int ret;
1315
1316
5.20k
    WOLFSSL_MSG("Derive Early Secret");
1317
5.20k
    if (ssl == NULL || ssl->arrays == NULL) {
1318
0
        return BAD_FUNC_ARG;
1319
0
    }
1320
#if defined(WOLFSSL_RENESAS_TSIP_TLS)
1321
    ret = tsip_Tls13DeriveEarlySecret(ssl);
1322
    if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE))
1323
        return ret;
1324
#endif
1325
5.20k
    PRIVATE_KEY_UNLOCK();
1326
5.20k
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
1327
5.20k
    ret = Tls13_HKDF_Extract(ssl, ssl->arrays->secret, NULL, 0,
1328
5.20k
            ssl->arrays->psk_key, (int)ssl->arrays->psk_keySz,
1329
5.20k
            mac2hash(ssl->specs.mac_algorithm));
1330
#else
1331
    ret = Tls13_HKDF_Extract(ssl, ssl->arrays->secret, NULL, 0,
1332
            ssl->arrays->masterSecret, 0, mac2hash(ssl->specs.mac_algorithm));
1333
#endif
1334
5.20k
    PRIVATE_KEY_LOCK();
1335
5.20k
    return ret;
1336
5.20k
}
1337
1338
/* The length of the derived label. */
1339
582
#define DERIVED_LABEL_SZ        7
1340
/* The derived label. */
1341
static const byte derivedLabel[DERIVED_LABEL_SZ + 1] =
1342
    "derived";
1343
1344
/* Derive the handshake secret using HKDF Extract.
1345
 *
1346
 * ssl  The SSL/TLS object.
1347
 */
1348
int DeriveHandshakeSecret(WOLFSSL* ssl)
1349
582
{
1350
582
    byte key[WC_MAX_DIGEST_SIZE];
1351
582
    int ret;
1352
582
    WOLFSSL_MSG("Derive Handshake Secret");
1353
582
    if (ssl == NULL || ssl->arrays == NULL) {
1354
0
        return BAD_FUNC_ARG;
1355
0
    }
1356
#if defined(WOLFSSL_RENESAS_TSIP_TLS)
1357
    ret = tsip_Tls13DeriveHandshakeSecret(ssl);
1358
    if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE))
1359
        return ret;
1360
#endif
1361
1362
    /* Derive-Secret(., "derived", "") per RFC 8446 Section 7.1.
1363
     * Empty hash (NULL, 0) is required by the TLS 1.3 key schedule. */
1364
582
    ret = DeriveKeyMsg(ssl, key, -1, ssl->arrays->secret,
1365
582
                        derivedLabel, DERIVED_LABEL_SZ,
1366
582
                        NULL, 0, ssl->specs.mac_algorithm);
1367
582
    if (ret == 0) {
1368
567
        PRIVATE_KEY_UNLOCK();
1369
567
        ret = Tls13_HKDF_Extract(ssl, ssl->arrays->preMasterSecret,
1370
567
                key, ssl->specs.hash_size,
1371
567
                ssl->arrays->preMasterSecret, (int)ssl->arrays->preMasterSz,
1372
567
                mac2hash(ssl->specs.mac_algorithm));
1373
567
        PRIVATE_KEY_LOCK();
1374
567
    }
1375
1376
#ifdef WOLFSSL_CHECK_MEM_ZERO
1377
    wc_MemZero_Add("DeriveHandshakeSecret key", key, WC_MAX_DIGEST_SIZE);
1378
#endif
1379
582
    ForceZero(key, sizeof(key));
1380
#ifdef WOLFSSL_CHECK_MEM_ZERO
1381
    wc_MemZero_Check(key, sizeof(key));
1382
#endif
1383
582
    return ret;
1384
582
}
1385
1386
/* Derive the master secret using HKDF Extract.
1387
 *
1388
 * ssl  The SSL/TLS object.
1389
 */
1390
int DeriveMasterSecret(WOLFSSL* ssl)
1391
{
1392
    byte key[WC_MAX_DIGEST_SIZE];
1393
    int ret;
1394
    WOLFSSL_MSG("Derive Master Secret");
1395
    if (ssl == NULL || ssl->arrays == NULL) {
1396
        return BAD_FUNC_ARG;
1397
    }
1398
1399
#if defined(WOLFSSL_RENESAS_TSIP_TLS)
1400
    ret = tsip_Tls13DeriveMasterSecret(ssl);
1401
    if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE))
1402
        return ret;
1403
#endif
1404
1405
    /* Derive-Secret(., "derived", "") per RFC 8446 Section 7.1.
1406
     * Empty hash (NULL, 0) is required by the TLS 1.3 key schedule. */
1407
    ret = DeriveKeyMsg(ssl, key, -1, ssl->arrays->preMasterSecret,
1408
                        derivedLabel, DERIVED_LABEL_SZ,
1409
                        NULL, 0, ssl->specs.mac_algorithm);
1410
    if (ret == 0) {
1411
        PRIVATE_KEY_UNLOCK();
1412
        ret = Tls13_HKDF_Extract(ssl, ssl->arrays->masterSecret,
1413
                                 key, ssl->specs.hash_size,
1414
                                 ssl->arrays->masterSecret, 0,
1415
                                 mac2hash(ssl->specs.mac_algorithm));
1416
        PRIVATE_KEY_LOCK();
1417
    }
1418
1419
#ifdef WOLFSSL_CHECK_MEM_ZERO
1420
    wc_MemZero_Add("DeriveMasterSecret key", key, WC_MAX_DIGEST_SIZE);
1421
#endif
1422
    ForceZero(key, sizeof(key));
1423
#ifdef WOLFSSL_CHECK_MEM_ZERO
1424
    wc_MemZero_Check(key, sizeof(key));
1425
#endif
1426
1427
#ifdef HAVE_KEYING_MATERIAL
1428
    if (ret != 0)
1429
        return ret;
1430
    /* Calculate exporter secret only when saving arrays */
1431
    if (ssl->options.saveArrays)
1432
        ret = DeriveExporterSecret(ssl, ssl->arrays->exporterSecret);
1433
#endif
1434
1435
    return ret;
1436
}
1437
1438
#if defined(HAVE_SESSION_TICKET)
1439
/* Length of the resumption label. */
1440
0
#define RESUMPTION_LABEL_SZ         10
1441
/* Resumption label for generating PSK associated with the ticket. */
1442
static const byte resumptionLabel[RESUMPTION_LABEL_SZ+1] = "resumption";
1443
1444
/* Derive the PSK associated with the ticket.
1445
 *
1446
 * ssl       The SSL/TLS object.
1447
 * nonce     The nonce to derive with.
1448
 * nonceLen  The length of the nonce to derive with.
1449
 * secret    The derived secret.
1450
 * returns 0 on success, otherwise failure.
1451
 */
1452
int DeriveResumptionPSK(WOLFSSL* ssl, byte* nonce, byte nonceLen, byte* secret)
1453
0
{
1454
0
    int         digestAlg;
1455
    /* Only one protocol version defined at this time. */
1456
0
    const byte* protocol    = tls13ProtocolLabel;
1457
0
    word32      protocolLen = TLS13_PROTOCOL_LABEL_SZ;
1458
0
    int         ret;
1459
1460
0
    WOLFSSL_MSG("Derive Resumption PSK");
1461
1462
#ifdef WOLFSSL_DTLS13
1463
    if (ssl->options.dtls) {
1464
        protocol = dtls13ProtocolLabel;
1465
        protocolLen = DTLS13_PROTOCOL_LABEL_SZ;
1466
    }
1467
#endif /* WOLFSSL_DTLS13 */
1468
1469
0
    switch (ssl->specs.mac_algorithm) {
1470
0
        #ifndef NO_SHA256
1471
0
        case sha256_mac:
1472
0
            digestAlg = WC_SHA256;
1473
0
            break;
1474
0
        #endif
1475
1476
0
        #ifdef WOLFSSL_SHA384
1477
0
        case sha384_mac:
1478
0
            digestAlg = WC_SHA384;
1479
0
            break;
1480
0
        #endif
1481
1482
        #ifdef WOLFSSL_TLS13_SHA512
1483
        case sha512_mac:
1484
            digestAlg = WC_SHA512;
1485
            break;
1486
        #endif
1487
1488
0
        #ifdef WOLFSSL_SM3
1489
0
        case sm3_mac:
1490
0
            digestAlg = WC_SM3;
1491
0
            break;
1492
0
        #endif
1493
1494
0
        default:
1495
0
            return BAD_FUNC_ARG;
1496
0
    }
1497
1498
#if defined(WOLFSSL_TICKET_NONCE_MALLOC) &&                                    \
1499
    (!defined(HAVE_FIPS) || (defined(FIPS_VERSION_GE) && FIPS_VERSION_GE(5,3)))
1500
    PRIVATE_KEY_UNLOCK();
1501
    ret = wc_Tls13_HKDF_Expand_Label_Alloc(secret, ssl->specs.hash_size,
1502
        ssl->session->masterSecret, ssl->specs.hash_size, protocol, protocolLen,
1503
        resumptionLabel, RESUMPTION_LABEL_SZ, nonce, nonceLen, digestAlg,
1504
        ssl->heap);
1505
    PRIVATE_KEY_LOCK();
1506
#else
1507
0
    ret = Tls13HKDFExpandLabel(ssl, secret, ssl->specs.hash_size,
1508
0
                               ssl->session->masterSecret, ssl->specs.hash_size,
1509
0
                               protocol, protocolLen, resumptionLabel,
1510
0
                               RESUMPTION_LABEL_SZ, nonce, nonceLen, digestAlg);
1511
0
#endif /* !defined(HAVE_FIPS) || FIPS_VERSION_GE(5,3) */
1512
0
    return ret;
1513
0
}
1514
#endif /* HAVE_SESSION_TICKET */
1515
1516
1517
/* Calculate the HMAC of message data to this point.
1518
 *
1519
 * ssl   The SSL/TLS object.
1520
 * key   The HMAC key.
1521
 * hash  The hash result - verify data.
1522
 * returns length of verify data generated.
1523
 */
1524
#if defined(WOLFSSL_ASYNC_REINVOKE) && !defined(NO_HMAC)
1525
/* Release the held transcript Hmac and its resume state. */
1526
void Tls13FreeHsHmac(WOLFSSL* ssl)
1527
{
1528
    if (ssl->hsHmac != NULL) {
1529
        wc_HmacFree(ssl->hsHmac);
1530
        XFREE(ssl->hsHmac, ssl->heap, DYNAMIC_TYPE_HMAC);
1531
        ssl->hsHmac = NULL;
1532
    }
1533
    ssl->hsHmacStep = 0;
1534
    ssl->hsHmacOut = NULL;
1535
}
1536
#endif /* WOLFSSL_ASYNC_REINVOKE && !NO_HMAC */
1537
1538
static int BuildTls13HandshakeHmac(WOLFSSL* ssl, byte* key, byte* hash,
1539
    word32* pHashSz)
1540
0
{
1541
0
#ifndef WOLFSSL_ASYNC_REINVOKE
1542
0
    WC_DECLARE_VAR(verifyHmac, Hmac, 1, 0);
1543
0
#endif
1544
0
    int  hashType = WC_SHA256;
1545
0
    int  hashSz = WC_SHA256_DIGEST_SIZE;
1546
0
    int  ret = WC_NO_ERR_TRACE(BAD_FUNC_ARG);
1547
1548
0
    if (ssl == NULL || key == NULL || hash == NULL) {
1549
0
        return BAD_FUNC_ARG;
1550
0
    }
1551
1552
    /* Get the hash of the previous handshake messages. */
1553
0
    switch (ssl->specs.mac_algorithm) {
1554
0
    #ifndef NO_SHA256
1555
0
        case sha256_mac:
1556
0
            hashType = WC_SHA256;
1557
0
            hashSz = WC_SHA256_DIGEST_SIZE;
1558
0
            ret = wc_Sha256GetHash(&ssl->hsHashes->hashSha256, hash);
1559
0
            break;
1560
0
    #endif /* !NO_SHA256 */
1561
0
    #ifdef WOLFSSL_SHA384
1562
0
        case sha384_mac:
1563
0
            hashType = WC_SHA384;
1564
0
            hashSz = WC_SHA384_DIGEST_SIZE;
1565
0
            ret = wc_Sha384GetHash(&ssl->hsHashes->hashSha384, hash);
1566
0
            break;
1567
0
    #endif /* WOLFSSL_SHA384 */
1568
    #ifdef WOLFSSL_TLS13_SHA512
1569
        case sha512_mac:
1570
            hashType = WC_SHA512;
1571
            hashSz = WC_SHA512_DIGEST_SIZE;
1572
            ret = wc_Sha512GetHash(&ssl->hsHashes->hashSha512, hash);
1573
            break;
1574
    #endif /* WOLFSSL_TLS13_SHA512 */
1575
0
    #ifdef WOLFSSL_SM3
1576
0
        case sm3_mac:
1577
0
            hashType = WC_SM3;
1578
0
            hashSz = WC_SM3_DIGEST_SIZE;
1579
0
            ret = wc_Sm3GetHash(&ssl->hsHashes->hashSm3, hash);
1580
0
            break;
1581
0
    #endif /* WOLFSSL_SM3 */
1582
0
        default:
1583
0
            ret = BAD_FUNC_ARG;
1584
0
            break;
1585
0
    }
1586
0
    if (ret != 0)
1587
0
        return ret;
1588
1589
#ifdef WOLFSSL_DEBUG_TLS
1590
    WOLFSSL_MSG("  Key");
1591
    WOLFSSL_BUFFER(key, ssl->specs.hash_size);
1592
    WOLFSSL_MSG("  Msg Hash");
1593
    WOLFSSL_BUFFER(hash, hashSz);
1594
#endif
1595
1596
#ifdef WOLFSSL_ASYNC_REINVOKE
1597
    /* Held on the SSL object so a crypto callback WC_PENDING_E resumes by
1598
     * re-invoking the same Hmac with identical arguments; the transcript
1599
     * hash input is recomputed deterministically by the caller's retry.
1600
     * Bound to the output buffer: a replayed caller that computes several
1601
     * HMACs (the PSK binder list) must not resume one request against
1602
     * another's key, so a different output discards the held state. */
1603
    if (ssl->hsHmac != NULL && ssl->hsHmacOut != hash)
1604
        Tls13FreeHsHmac(ssl);
1605
    if (ssl->hsHmac == NULL) {
1606
        ssl->hsHmac = (Hmac*)XMALLOC(sizeof(Hmac), ssl->heap,
1607
                                     DYNAMIC_TYPE_HMAC);
1608
        if (ssl->hsHmac == NULL)
1609
            return MEMORY_E;
1610
        ret = wc_HmacInit(ssl->hsHmac, ssl->heap, ssl->devId);
1611
        if (ret != 0) {
1612
            Tls13FreeHsHmac(ssl);
1613
            return ret;
1614
        }
1615
        ssl->hsHmacStep = 0;
1616
        ssl->hsHmacOut = hash;
1617
    }
1618
    /* Armed before the operations, matching the HKDF helpers. */
1619
    ret = Tls13KdfAsyncInit(ssl);
1620
    if (ret != 0) {
1621
        Tls13FreeHsHmac(ssl);
1622
        return ret;
1623
    }
1624
    if (ssl->hsHmacStep == 0) {
1625
        ret = wc_HmacSetKey(ssl->hsHmac, hashType, key,
1626
                            ssl->specs.hash_size);
1627
        if (ret == 0)
1628
            ssl->hsHmacStep = 1;
1629
    }
1630
    if (ret == 0 && ssl->hsHmacStep == 1) {
1631
        ret = wc_HmacUpdate(ssl->hsHmac, hash, (word32)hashSz);
1632
        if (ret == 0)
1633
            ssl->hsHmacStep = 2;
1634
    }
1635
    if (ret == 0 && ssl->hsHmacStep == 2)
1636
        ret = wc_HmacFinal(ssl->hsHmac, hash);
1637
    if (ret == WC_NO_ERR_TRACE(WC_PENDING_E))
1638
        return wolfSSL_AsyncPush(ssl, &ssl->kdfAsyncDev);
1639
    Tls13FreeHsHmac(ssl);
1640
#else
1641
0
    WC_ALLOC_VAR_EX(verifyHmac, Hmac, 1, NULL, DYNAMIC_TYPE_HMAC,
1642
0
        return MEMORY_E);
1643
1644
    /* Calculate the verify data. */
1645
0
    ret = wc_HmacInit(verifyHmac, ssl->heap, ssl->devId);
1646
0
    if (ret == 0) {
1647
0
        ret = wc_HmacSetKey(verifyHmac, hashType, key, ssl->specs.hash_size);
1648
0
        if (ret == 0)
1649
0
            ret = wc_HmacUpdate(verifyHmac, hash, (word32)hashSz);
1650
0
        if (ret == 0)
1651
0
            ret = wc_HmacFinal(verifyHmac, hash);
1652
0
        wc_HmacFree(verifyHmac);
1653
0
    }
1654
1655
0
    WC_FREE_VAR_EX(verifyHmac, NULL, DYNAMIC_TYPE_HMAC);
1656
0
#endif /* WOLFSSL_ASYNC_REINVOKE */
1657
1658
#ifdef WOLFSSL_DEBUG_TLS
1659
    WOLFSSL_MSG("  Hash");
1660
    WOLFSSL_BUFFER(hash, hashSz);
1661
#endif
1662
1663
0
    if (pHashSz)
1664
0
        *pHashSz = (word32)hashSz;
1665
1666
0
    return ret;
1667
0
}
1668
1669
/* The length of the label to use when deriving keys. */
1670
0
#define WRITE_KEY_LABEL_SZ     3
1671
/* The length of the label to use when deriving IVs. */
1672
0
#define WRITE_IV_LABEL_SZ      2
1673
/* The label to use when deriving keys. */
1674
static const byte writeKeyLabel[WRITE_KEY_LABEL_SZ+1] = "key";
1675
/* The label to use when deriving IVs. */
1676
static const byte writeIVLabel[WRITE_IV_LABEL_SZ+1]   = "iv";
1677
1678
/* Derive the keys and IVs for TLS v1.3.
1679
 *
1680
 * ssl      The SSL/TLS object.
1681
 * secret   early_data_key when deriving the key and IV for encrypting early
1682
 *          data application data and end_of_early_data messages.
1683
 *          handshake_key when deriving keys and IVs for encrypting handshake
1684
 *          messages.
1685
 *          traffic_key when deriving first keys and IVs for encrypting
1686
 *          traffic messages.
1687
 *          update_traffic_key when deriving next keys and IVs for encrypting
1688
 *          traffic messages.
1689
 *          no_key when deriving keys and IVs from existing secrets without
1690
 *          re-deriving the secrets. Used during early data transitions.
1691
 * side     ENCRYPT_SIDE_ONLY when only encryption secret needs to be derived.
1692
 *          DECRYPT_SIDE_ONLY when only decryption secret needs to be derived.
1693
 *          ENCRYPT_AND_DECRYPT_SIDE when both secret needs to be derived.
1694
 * store    1 indicates to derive the keys and IVs from derived secret and
1695
 *          store ready for provisioning.
1696
 * returns 0 on success, otherwise failure.
1697
 */
1698
int DeriveTls13Keys(WOLFSSL* ssl, int secret, int side, int store)
1699
0
{
1700
0
    int   ret = WC_NO_ERR_TRACE(BAD_FUNC_ARG); /* Assume failure */
1701
0
    int   i = 0;
1702
0
    WC_DECLARE_VAR(key_dig, byte, MAX_PRF_DIG, 0);
1703
0
    int   provision;
1704
1705
#if defined(WOLFSSL_RENESAS_TSIP_TLS)
1706
    ret = tsip_Tls13DeriveKeys(ssl, secret, side);
1707
    if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) {
1708
        return ret;
1709
    }
1710
    ret = WC_NO_ERR_TRACE(BAD_FUNC_ARG); /* Assume failure */
1711
#endif
1712
1713
0
    WC_ALLOC_VAR_EX(key_dig, byte, MAX_PRF_DIG, ssl->heap,
1714
0
        DYNAMIC_TYPE_DIGEST, return MEMORY_E);
1715
1716
#ifdef WOLFSSL_CHECK_MEM_ZERO
1717
    XMEMSET(key_dig, 0xff, MAX_PRF_DIG);
1718
    wc_MemZero_Add("DeriveTls13Keys key_dig", key_dig, MAX_PRF_DIG);
1719
#endif
1720
1721
0
    if (side == ENCRYPT_AND_DECRYPT_SIDE) {
1722
0
        provision = PROVISION_CLIENT_SERVER;
1723
0
    }
1724
0
    else {
1725
0
        provision = ((ssl->options.side != WOLFSSL_CLIENT_END) ^
1726
0
                     (side == ENCRYPT_SIDE_ONLY)) ? PROVISION_CLIENT :
1727
0
                                                    PROVISION_SERVER;
1728
0
    }
1729
1730
    /* Derive the appropriate secret to use in the HKDF. */
1731
0
    switch (secret) {
1732
#ifdef WOLFSSL_EARLY_DATA
1733
        case early_data_key:
1734
            ret = DeriveEarlyTrafficSecret(ssl, ssl->clientSecret,
1735
                                           WOLFSSL_CLIENT_END);
1736
            if (ret != 0)
1737
                goto end;
1738
            break;
1739
#endif
1740
1741
0
        case handshake_key:
1742
0
            if (provision & PROVISION_CLIENT) {
1743
0
                ret = DeriveClientHandshakeSecret(ssl,
1744
0
                                                  ssl->clientSecret);
1745
0
                if (ret != 0)
1746
0
                    goto end;
1747
0
            }
1748
0
            if (provision & PROVISION_SERVER) {
1749
0
                ret = DeriveServerHandshakeSecret(ssl,
1750
0
                                                  ssl->serverSecret);
1751
0
                if (ret != 0)
1752
0
                    goto end;
1753
0
            }
1754
0
            break;
1755
1756
0
        case traffic_key:
1757
0
            if (provision & PROVISION_CLIENT) {
1758
0
                ret = DeriveClientTrafficSecret(ssl, ssl->clientSecret);
1759
0
                if (ret != 0)
1760
0
                    goto end;
1761
0
            }
1762
0
            if (provision & PROVISION_SERVER) {
1763
0
                ret = DeriveServerTrafficSecret(ssl, ssl->serverSecret);
1764
0
                if (ret != 0)
1765
0
                    goto end;
1766
0
            }
1767
0
            break;
1768
1769
0
        case update_traffic_key:
1770
0
            if (provision & PROVISION_CLIENT) {
1771
0
                ret = DeriveTrafficSecret(ssl, ssl->clientSecret,
1772
0
                                          WOLFSSL_CLIENT_END);
1773
0
                if (ret != 0)
1774
0
                    goto end;
1775
0
            }
1776
0
            if (provision & PROVISION_SERVER) {
1777
0
                ret = DeriveTrafficSecret(ssl, ssl->serverSecret,
1778
0
                                          WOLFSSL_SERVER_END);
1779
0
                if (ret != 0)
1780
0
                    goto end;
1781
0
            }
1782
0
            break;
1783
1784
0
        case no_key:
1785
            /* Called with early data to derive keys from existing secrets
1786
             * without re-deriving the secrets themselves. */
1787
0
            ret = 0;
1788
0
            break;
1789
1790
0
        default:
1791
0
            ret = BAD_FUNC_ARG;
1792
0
            break;
1793
0
    }
1794
1795
#ifdef WOLFSSL_QUIC
1796
    if (WOLFSSL_IS_QUIC(ssl)) {
1797
        ret = wolfSSL_quic_forward_secrets(ssl, secret, side);
1798
        if (ret != 0)
1799
            goto end;
1800
    }
1801
#endif /* WOLFSSL_QUIC */
1802
1803
0
    if (!store)
1804
0
        goto end;
1805
1806
    /* Key data = client key | server key | client IV | server IV */
1807
1808
0
    if (provision & PROVISION_CLIENT) {
1809
        /* Derive the client key.  */
1810
0
        WOLFSSL_MSG("Derive Client Key");
1811
0
        ret = Tls13DeriveKey(ssl, &key_dig[i], ssl->specs.key_size,
1812
0
                        ssl->clientSecret, writeKeyLabel,
1813
0
                        WRITE_KEY_LABEL_SZ, ssl->specs.mac_algorithm, 0,
1814
0
                        WOLFSSL_CLIENT_END);
1815
0
        if (ret != 0)
1816
0
            goto end;
1817
0
        i += ssl->specs.key_size;
1818
0
    }
1819
1820
0
    if (provision & PROVISION_SERVER) {
1821
        /* Derive the server key.  */
1822
0
        WOLFSSL_MSG("Derive Server Key");
1823
0
        ret = Tls13DeriveKey(ssl, &key_dig[i], ssl->specs.key_size,
1824
0
                        ssl->serverSecret, writeKeyLabel,
1825
0
                        WRITE_KEY_LABEL_SZ, ssl->specs.mac_algorithm, 0,
1826
0
                        WOLFSSL_SERVER_END);
1827
0
        if (ret != 0)
1828
0
            goto end;
1829
0
        i += ssl->specs.key_size;
1830
0
    }
1831
1832
0
    if (provision & PROVISION_CLIENT) {
1833
        /* Derive the client IV.  */
1834
0
        WOLFSSL_MSG("Derive Client IV");
1835
0
        ret = Tls13DeriveKey(ssl, &key_dig[i], ssl->specs.iv_size,
1836
0
                        ssl->clientSecret, writeIVLabel,
1837
0
                        WRITE_IV_LABEL_SZ, ssl->specs.mac_algorithm, 0,
1838
0
                        WOLFSSL_CLIENT_END);
1839
0
        if (ret != 0)
1840
0
            goto end;
1841
0
        i += ssl->specs.iv_size;
1842
0
    }
1843
1844
0
    if (provision & PROVISION_SERVER) {
1845
        /* Derive the server IV.  */
1846
0
        WOLFSSL_MSG("Derive Server IV");
1847
0
        ret = Tls13DeriveKey(ssl, &key_dig[i], ssl->specs.iv_size,
1848
0
                        ssl->serverSecret, writeIVLabel,
1849
0
                        WRITE_IV_LABEL_SZ, ssl->specs.mac_algorithm, 0,
1850
0
                        WOLFSSL_SERVER_END);
1851
0
        if (ret != 0)
1852
0
            goto end;
1853
        /* Server IV is the last key material written to key_dig, so i is not
1854
         * advanced here; the whole buffer is zeroed at end regardless. */
1855
0
    }
1856
1857
    /* Store keys and IVs but don't activate them. */
1858
0
    ret = StoreKeys(ssl, key_dig, provision);
1859
1860
#ifdef WOLFSSL_DTLS13
1861
    if (ret != 0)
1862
      goto end;
1863
1864
    if (ssl->options.dtls) {
1865
        w64wrapper epochNumber;
1866
        ret = Dtls13DeriveSnKeys(ssl, provision);
1867
        if (ret != 0)
1868
            goto end;
1869
1870
        switch (secret) {
1871
            case early_data_key:
1872
                epochNumber = w64From32(0, DTLS13_EPOCH_EARLYDATA);
1873
                break;
1874
            case handshake_key:
1875
                epochNumber = w64From32(0, DTLS13_EPOCH_HANDSHAKE);
1876
                break;
1877
            case traffic_key:
1878
            case no_key:
1879
                epochNumber = w64From32(0, DTLS13_EPOCH_TRAFFIC0);
1880
                break;
1881
            case update_traffic_key:
1882
                if (side == ENCRYPT_SIDE_ONLY) {
1883
                    epochNumber = ssl->dtls13Epoch;
1884
                }
1885
                else if (side == DECRYPT_SIDE_ONLY) {
1886
                    epochNumber = ssl->dtls13PeerEpoch;
1887
                }
1888
                else {
1889
                    ret = BAD_STATE_E;
1890
                    goto end;
1891
                }
1892
                w64Increment(&epochNumber);
1893
                break;
1894
            default:
1895
                ret = BAD_STATE_E;
1896
                goto end;
1897
        }
1898
        ret = Dtls13NewEpoch(ssl, epochNumber, side);
1899
        if (ret != 0)
1900
            goto end;
1901
    }
1902
1903
#endif /* WOLFSSL_DTLS13 */
1904
1905
0
end:
1906
    /* Zero the whole key_dig buffer (not just the i bytes derived) so no
1907
     * key-schedule material can linger in the unused tail. */
1908
0
    ForceZero(key_dig, MAX_PRF_DIG);
1909
0
#ifdef WOLFSSL_SMALL_STACK
1910
0
    XFREE(key_dig, ssl->heap, DYNAMIC_TYPE_DIGEST);
1911
#elif defined(WOLFSSL_CHECK_MEM_ZERO)
1912
    wc_MemZero_Check(key_dig, MAX_PRF_DIG);
1913
#endif
1914
1915
0
    if (ret != 0) {
1916
0
        WOLFSSL_ERROR_VERBOSE(ret);
1917
0
    }
1918
1919
0
    return ret;
1920
0
}
1921
1922
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK) || defined(WOLFSSL_DTLS13)
1923
#ifdef WOLFSSL_32BIT_MILLI_TIME
1924
#ifndef NO_ASN_TIME
1925
#if defined(USER_TICKS)
1926
#if 0
1927
    word32 TimeNowInMilliseconds(void)
1928
    {
1929
        /*
1930
        write your own clock tick function if don't want gettimeofday()
1931
        needs millisecond accuracy but doesn't have to correlated to EPOCH
1932
        */
1933
    }
1934
#endif
1935
1936
#elif defined(TIME_OVERRIDES)
1937
#if !defined(NO_ASN) && !defined(NO_ASN_TIME)
1938
    word32 TimeNowInMilliseconds(void)
1939
    {
1940
        return (word32) wc_Time(0) * 1000;
1941
    }
1942
#else
1943
    #ifndef HAVE_TIME_T_TYPE
1944
        typedef long time_t;
1945
    #endif
1946
    extern time_t XTIME(time_t * timer);
1947
1948
    /* The time in milliseconds.
1949
     * Used for tickets to represent difference between when first seen and when
1950
     * sending.
1951
     *
1952
     * returns the time in milliseconds as a 32-bit value.
1953
     */
1954
    word32 TimeNowInMilliseconds(void)
1955
    {
1956
        return (word32) XTIME(0) * 1000;
1957
    }
1958
#endif
1959
1960
#elif defined(XTIME_MS)
1961
    word32 TimeNowInMilliseconds(void)
1962
    {
1963
        return (word32)XTIME_MS(0);
1964
    }
1965
1966
#elif defined(USE_WINDOWS_API)
1967
    /* The time in milliseconds.
1968
     * Used for tickets to represent difference between when first seen and when
1969
     * sending.
1970
     *
1971
     * returns the time in milliseconds as a 32-bit value.
1972
     */
1973
    word32 TimeNowInMilliseconds(void)
1974
    {
1975
        static int           init = 0;
1976
        static LARGE_INTEGER freq;
1977
        LARGE_INTEGER        count;
1978
1979
        if (!init) {
1980
            QueryPerformanceFrequency(&freq);
1981
            init = 1;
1982
        }
1983
1984
        QueryPerformanceCounter(&count);
1985
1986
        return (word32)(count.QuadPart / (freq.QuadPart / 1000));
1987
    }
1988
1989
#elif defined(HAVE_RTP_SYS)
1990
    #include "rtptime.h"
1991
1992
    /* The time in milliseconds.
1993
     * Used for tickets to represent difference between when first seen and when
1994
     * sending.
1995
     *
1996
     * returns the time in milliseconds as a 32-bit value.
1997
     */
1998
    word32 TimeNowInMilliseconds(void)
1999
    {
2000
        return (word32)rtp_get_system_sec() * 1000;
2001
    }
2002
#elif defined(WOLFSSL_DEOS)
2003
    word32 TimeNowInMilliseconds(void)
2004
    {
2005
        const word32 systemTickTimeInHz = 1000000 / systemTickInMicroseconds();
2006
        word32 *systemTickPtr = systemTickPointer();
2007
2008
        return (word32) (*systemTickPtr/systemTickTimeInHz) * 1000;
2009
    }
2010
#elif defined(MICRIUM)
2011
    /* The time in milliseconds.
2012
     * Used for tickets to represent difference between when first seen and when
2013
     * sending.
2014
     *
2015
     * returns the time in milliseconds as a 32-bit value.
2016
     */
2017
    word32 TimeNowInMilliseconds(void)
2018
    {
2019
        OS_TICK ticks = 0;
2020
        OS_ERR  err;
2021
2022
        ticks = OSTimeGet(&err);
2023
2024
        return (word32) (ticks / OSCfg_TickRate_Hz) * 1000;
2025
    }
2026
#elif defined(MICROCHIP_TCPIP_V5)
2027
    /* The time in milliseconds.
2028
     * Used for tickets to represent difference between when first seen and when
2029
     * sending.
2030
     *
2031
     * returns the time in milliseconds as a 32-bit value.
2032
     */
2033
    word32 TimeNowInMilliseconds(void)
2034
    {
2035
        return (word32) (TickGet() / (TICKS_PER_SECOND / 1000));
2036
    }
2037
#elif defined(MICROCHIP_TCPIP)
2038
    #if defined(MICROCHIP_MPLAB_HARMONY)
2039
        #include <system/tmr/sys_tmr.h>
2040
2041
    /* The time in milliseconds.
2042
     * Used for tickets to represent difference between when first seen and when
2043
     * sending.
2044
     *
2045
     * returns the time in milliseconds as a 32-bit value.
2046
     */
2047
    word32 TimeNowInMilliseconds(void)
2048
    {
2049
        return (word32)(SYS_TMR_TickCountGet() /
2050
                        (SYS_TMR_TickCounterFrequencyGet() / 1000));
2051
    }
2052
    #else
2053
    /* The time in milliseconds.
2054
     * Used for tickets to represent difference between when first seen and when
2055
     * sending.
2056
     *
2057
     * returns the time in milliseconds as a 32-bit value.
2058
     */
2059
    word32 TimeNowInMilliseconds(void)
2060
    {
2061
        return (word32)(SYS_TICK_Get() / (SYS_TICK_TicksPerSecondGet() / 1000));
2062
    }
2063
2064
    #endif
2065
2066
#elif defined(FREESCALE_MQX) || defined(FREESCALE_KSDK_MQX)
2067
    /* The time in milliseconds.
2068
     * Used for tickets to represent difference between when first seen and when
2069
     * sending.
2070
     *
2071
     * returns the time in milliseconds as a 32-bit value.
2072
     */
2073
    word32 TimeNowInMilliseconds(void)
2074
    {
2075
        TIME_STRUCT mqxTime;
2076
2077
        _time_get_elapsed(&mqxTime);
2078
2079
        return (word32) mqxTime.SECONDS * 1000;
2080
    }
2081
#elif defined(FREESCALE_FREE_RTOS) || defined(FREESCALE_KSDK_FREERTOS)
2082
    #include "include/task.h"
2083
2084
    /* The time in milliseconds.
2085
     * Used for tickets to represent difference between when first seen and when
2086
     * sending.
2087
     *
2088
     * returns the time in milliseconds as a 32-bit value.
2089
     */
2090
    word32 TimeNowInMilliseconds(void)
2091
    {
2092
        return (unsigned int)(((float)xTaskGetTickCount()) /
2093
                              (configTICK_RATE_HZ / 1000));
2094
    }
2095
#elif defined(FREESCALE_KSDK_BM)
2096
    #include "lwip/sys.h" /* lwIP */
2097
2098
    /* The time in milliseconds.
2099
     * Used for tickets to represent difference between when first seen and when
2100
     * sending.
2101
     *
2102
     * returns the time in milliseconds as a 32-bit value.
2103
     */
2104
    word32 TimeNowInMilliseconds(void)
2105
    {
2106
        return sys_now();
2107
    }
2108
2109
#elif defined(WOLFSSL_CMSIS_RTOS) || defined(WOLFSSL_CMSIS_RTOSv2)
2110
2111
    word32 TimeNowInMilliseconds(void)
2112
    {
2113
        return (word32)osKernelGetTickCount();
2114
    }
2115
2116
#elif defined(WOLFSSL_TIRTOS)
2117
    /* The time in milliseconds.
2118
     * Used for tickets to represent difference between when first seen and when
2119
     * sending.
2120
     *
2121
     * returns the time in milliseconds as a 32-bit value.
2122
     */
2123
    word32 TimeNowInMilliseconds(void)
2124
    {
2125
        return (word32) Seconds_get() * 1000;
2126
    }
2127
#elif defined(WOLFSSL_UTASKER)
2128
    /* The time in milliseconds.
2129
     * Used for tickets to represent difference between when first seen and when
2130
     * sending.
2131
     *
2132
     * returns the time in milliseconds as a 32-bit value.
2133
     */
2134
    word32 TimeNowInMilliseconds(void)
2135
    {
2136
        return (word32)(uTaskerSystemTick / (TICK_RESOLUTION / 1000));
2137
    }
2138
#elif defined(WOLFSSL_LINUXKM)
2139
    word32 TimeNowInMilliseconds(void)
2140
    {
2141
        s64 t;
2142
#if LINUX_VERSION_CODE < KERNEL_VERSION(4, 0, 0)
2143
        struct timespec ts;
2144
        getnstimeofday(&ts);
2145
        t = ts.tv_sec * (s64)1000;
2146
        t += ts.tv_nsec / (s64)1000000;
2147
#else
2148
        struct timespec64 ts;
2149
#if LINUX_VERSION_CODE < KERNEL_VERSION(5, 0, 0)
2150
        ts = current_kernel_time64();
2151
#else
2152
        ktime_get_coarse_real_ts64(&ts);
2153
#endif
2154
        t = ts.tv_sec * 1000L;
2155
        t += ts.tv_nsec / 1000000L;
2156
#endif
2157
        return (word32)t;
2158
    }
2159
#elif defined(WOLFSSL_QNX_CAAM)
2160
    word32 TimeNowInMilliseconds(void)
2161
    {
2162
        struct timespec now;
2163
        clock_gettime(CLOCK_REALTIME, &now);
2164
        return (word32)(now.tv_sec * 1000 + now.tv_nsec / 1000000);
2165
    }
2166
#elif defined(FUSION_RTOS)
2167
    /* The time in milliseconds.
2168
     * Used for tickets to represent difference between when first seen and when
2169
     * sending.
2170
     *
2171
     * returns the time in milliseconds as a 32-bit value.
2172
     */
2173
    word32 TimeNowInMilliseconds(void)
2174
    {
2175
        struct timeval now;
2176
        if (FCL_GETTIMEOFDAY(&now, 0) < 0)
2177
            return 0;
2178
2179
        /* Convert to milliseconds number. */
2180
        return (word32)(now.tv_sec * 1000 + now.tv_usec / 1000);
2181
    }
2182
#elif defined(WOLFSSL_ZEPHYR)
2183
    word32 TimeNowInMilliseconds(void)
2184
    {
2185
        int64_t t;
2186
    #if defined(CONFIG_ARCH_POSIX)
2187
        k_cpu_idle();
2188
    #endif
2189
        t = k_uptime_get(); /* returns current uptime in milliseconds */
2190
        return (word32)t;
2191
    }
2192
#elif defined(FREERTOS)
2193
    word32 TimeNowInMilliseconds(void)
2194
    {
2195
        return (word32)((uint64_t)(xTaskGetTickCount() * 1000) /
2196
            configTICK_RATE_HZ);
2197
    }
2198
#else
2199
    /* The time in milliseconds.
2200
     * Used for tickets to represent difference between when first seen and when
2201
     * sending.
2202
     *
2203
     * returns the time in milliseconds as a 32-bit value.
2204
     */
2205
    word32 TimeNowInMilliseconds(void)
2206
    {
2207
        struct timeval now;
2208
2209
        if (gettimeofday(&now, 0) < 0)
2210
            return 0;
2211
2212
        /* Convert to milliseconds number. */
2213
        return (word32)(now.tv_sec * 1000 + now.tv_usec / 1000);
2214
    }
2215
#endif
2216
#else
2217
    /* user must supply time in milliseconds function:
2218
     *   word32 TimeNowInMilliseconds(void);
2219
     * The response is milliseconds elapsed
2220
     */
2221
#endif /* !NO_ASN_TIME */
2222
#else
2223
#ifndef NO_ASN_TIME
2224
#if defined(USER_TICKS)
2225
#if 0
2226
    sword64 TimeNowInMilliseconds(void)
2227
    {
2228
        /*
2229
        write your own clock tick function if don't want gettimeofday()
2230
        needs millisecond accuracy but doesn't have to correlated to EPOCH
2231
        */
2232
    }
2233
#endif
2234
2235
#elif defined(TIME_OVERRIDES)
2236
#if !defined(NO_ASN) && !defined(NO_ASN_TIME)
2237
    sword64 TimeNowInMilliseconds(void)
2238
    {
2239
        return (sword64) wc_Time(0) * 1000;
2240
    }
2241
#else
2242
    #ifndef HAVE_TIME_T_TYPE
2243
        typedef long time_t;
2244
    #endif
2245
    extern time_t XTIME(time_t * timer);
2246
2247
    /* The time in milliseconds.
2248
     * Used for tickets to represent difference between when first seen and when
2249
     * sending.
2250
     *
2251
     * returns the time in milliseconds as a 32-bit value.
2252
     */
2253
    sword64 TimeNowInMilliseconds(void)
2254
    {
2255
        return (sword64) XTIME(0) * 1000;
2256
    }
2257
#endif
2258
2259
#elif defined(XTIME_MS)
2260
    sword64 TimeNowInMilliseconds(void)
2261
    {
2262
        return (sword64)XTIME_MS(0);
2263
    }
2264
2265
#elif defined(USE_WINDOWS_API)
2266
    /* The time in milliseconds.
2267
     * Used for tickets to represent difference between when first seen and when
2268
     * sending.
2269
     *
2270
     * returns the time in milliseconds as a 64-bit value.
2271
     */
2272
    sword64 TimeNowInMilliseconds(void)
2273
    {
2274
        static int           init = 0;
2275
        static LARGE_INTEGER freq;
2276
        LARGE_INTEGER        count;
2277
2278
        if (!init) {
2279
            QueryPerformanceFrequency(&freq);
2280
            init = 1;
2281
        }
2282
2283
        QueryPerformanceCounter(&count);
2284
2285
        return (sword64)(count.QuadPart / (freq.QuadPart / 1000));
2286
    }
2287
2288
#elif defined(HAVE_RTP_SYS)
2289
    #include "rtptime.h"
2290
2291
    /* The time in milliseconds.
2292
     * Used for tickets to represent difference between when first seen and when
2293
     * sending.
2294
     *
2295
     * returns the time in milliseconds as a 64-bit value.
2296
     */
2297
    sword64 TimeNowInMilliseconds(void)
2298
    {
2299
        return (sword64)rtp_get_system_sec() * 1000;
2300
    }
2301
#elif defined(WOLFSSL_DEOS)
2302
    sword64 TimeNowInMilliseconds(void)
2303
    {
2304
        const word32 systemTickTimeInHz = 1000000 / systemTickInMicroseconds();
2305
        word32 *systemTickPtr = systemTickPointer();
2306
2307
        return (sword64) (*systemTickPtr/systemTickTimeInHz) * 1000;
2308
    }
2309
#elif defined(MICRIUM)
2310
    /* The time in milliseconds.
2311
     * Used for tickets to represent difference between when first seen and when
2312
     * sending.
2313
     *
2314
     * returns the time in milliseconds as a 64-bit value.
2315
     */
2316
    sword64 TimeNowInMilliseconds(void)
2317
    {
2318
        OS_TICK ticks = 0;
2319
        OS_ERR  err;
2320
2321
        ticks = OSTimeGet(&err);
2322
2323
        return (sword64) (ticks / OSCfg_TickRate_Hz) * 1000;
2324
    }
2325
#elif defined(MICROCHIP_TCPIP_V5)
2326
    /* The time in milliseconds.
2327
     * Used for tickets to represent difference between when first seen and when
2328
     * sending.
2329
     *
2330
     * returns the time in milliseconds as a 64-bit value.
2331
     */
2332
    sword64 TimeNowInMilliseconds(void)
2333
    {
2334
        return (sword64) (TickGet() / (TICKS_PER_SECOND / 1000));
2335
    }
2336
#elif defined(MICROCHIP_TCPIP)
2337
    #if defined(MICROCHIP_MPLAB_HARMONY)
2338
        #include <system/tmr/sys_tmr.h>
2339
2340
    /* The time in milliseconds.
2341
     * Used for tickets to represent difference between when first seen and when
2342
     * sending.
2343
     *
2344
     * returns the time in milliseconds as a 64-bit value.
2345
     */
2346
    sword64 TimeNowInMilliseconds(void)
2347
    {
2348
        return (sword64)SYS_TMR_TickCountGet() /
2349
                        (SYS_TMR_TickCounterFrequencyGet() / 1000);
2350
    }
2351
    #else
2352
    /* The time in milliseconds.
2353
     * Used for tickets to represent difference between when first seen and when
2354
     * sending.
2355
     *
2356
     * returns the time in milliseconds as a 64-bit value.
2357
     */
2358
    sword64 TimeNowInMilliseconds(void)
2359
    {
2360
        return (sword64)SYS_TICK_Get() / (SYS_TICK_TicksPerSecondGet() / 1000);
2361
    }
2362
2363
    #endif
2364
2365
#elif defined(FREESCALE_MQX) || defined(FREESCALE_KSDK_MQX)
2366
    /* The time in milliseconds.
2367
     * Used for tickets to represent difference between when first seen and when
2368
     * sending.
2369
     *
2370
     * returns the time in milliseconds as a 64-bit value.
2371
     */
2372
    sword64 TimeNowInMilliseconds(void)
2373
    {
2374
        TIME_STRUCT mqxTime;
2375
2376
        _time_get_elapsed(&mqxTime);
2377
2378
        return (sword64) mqxTime.SECONDS * 1000;
2379
    }
2380
#elif defined(FREESCALE_FREE_RTOS) || defined(FREESCALE_KSDK_FREERTOS)
2381
    #include "include/task.h"
2382
2383
    /* The time in milliseconds.
2384
     * Used for tickets to represent difference between when first seen and when
2385
     * sending.
2386
     *
2387
     * returns the time in milliseconds as a 64-bit value.
2388
     */
2389
    sword64 TimeNowInMilliseconds(void)
2390
    {
2391
        return (sword64)xTaskGetTickCount() / (configTICK_RATE_HZ / 1000);
2392
    }
2393
#elif defined(FREESCALE_KSDK_BM)
2394
    #include "lwip/sys.h" /* lwIP */
2395
2396
    /* The time in milliseconds.
2397
     * Used for tickets to represent difference between when first seen and when
2398
     * sending.
2399
     *
2400
     * returns the time in milliseconds as a 64-bit value.
2401
     */
2402
    sword64 TimeNowInMilliseconds(void)
2403
    {
2404
        return sys_now();
2405
    }
2406
2407
#elif defined(WOLFSSL_CMSIS_RTOS) || defined(WOLFSSL_CMSIS_RTOSv2)
2408
2409
    sword64 TimeNowInMilliseconds(void)
2410
    {
2411
        return (sword64)osKernelGetTickCount();
2412
    }
2413
2414
#elif defined(WOLFSSL_TIRTOS)
2415
    /* The time in milliseconds.
2416
     * Used for tickets to represent difference between when first seen and when
2417
     * sending.
2418
     *
2419
     * returns the time in milliseconds as a 64-bit value.
2420
     */
2421
    sword64 TimeNowInMilliseconds(void)
2422
    {
2423
        return (sword64) Seconds_get() * 1000;
2424
    }
2425
#elif defined(WOLFSSL_UTASKER)
2426
    /* The time in milliseconds.
2427
     * Used for tickets to represent difference between when first seen and when
2428
     * sending.
2429
     *
2430
     * returns the time in milliseconds as a 64-bit value.
2431
     */
2432
    sword64 TimeNowInMilliseconds(void)
2433
    {
2434
        return (sword64)(uTaskerSystemTick / (TICK_RESOLUTION / 1000));
2435
    }
2436
#elif defined(WOLFSSL_LINUXKM)
2437
    sword64 TimeNowInMilliseconds(void)
2438
    {
2439
        s64 t;
2440
#if LINUX_VERSION_CODE < KERNEL_VERSION(4, 0, 0)
2441
        struct timespec ts;
2442
        getnstimeofday(&ts);
2443
        t = ts.tv_sec * (s64)1000;
2444
        t += ts.tv_nsec / (s64)1000000;
2445
#else
2446
        struct timespec64 ts;
2447
#if LINUX_VERSION_CODE < KERNEL_VERSION(5, 0, 0)
2448
        ts = current_kernel_time64();
2449
#else
2450
        ktime_get_coarse_real_ts64(&ts);
2451
#endif
2452
        t = ts.tv_sec * 1000L;
2453
        t += ts.tv_nsec / 1000000L;
2454
#endif
2455
        return (sword64)t;
2456
    }
2457
#elif defined(WOLFSSL_QNX_CAAM)
2458
    sword64 TimeNowInMilliseconds(void)
2459
    {
2460
        struct timespec now;
2461
        clock_gettime(CLOCK_REALTIME, &now);
2462
        return (sword64)(now.tv_sec * 1000 + now.tv_nsec / 1000000);
2463
    }
2464
#elif defined(FUSION_RTOS)
2465
    /* The time in milliseconds.
2466
     * Used for tickets to represent difference between when first seen and when
2467
     * sending.
2468
     *
2469
     * returns the time in milliseconds as a 64-bit value.
2470
     */
2471
    sword64 TimeNowInMilliseconds(void)
2472
    {
2473
        struct timeval now;
2474
        if (FCL_GETTIMEOFDAY(&now, 0) < 0)
2475
            return 0;
2476
2477
        /* Convert to milliseconds number. */
2478
        return (sword64)now.tv_sec * 1000 + now.tv_usec / 1000;
2479
    }
2480
#elif defined(WOLFSSL_ZEPHYR)
2481
    sword64 TimeNowInMilliseconds(void)
2482
    {
2483
        int64_t t;
2484
    #if defined(CONFIG_ARCH_POSIX)
2485
        k_cpu_idle();
2486
    #endif
2487
        t = k_uptime_get(); /* returns current uptime in milliseconds */
2488
        return (sword64)t;
2489
    }
2490
#elif defined(FREERTOS)
2491
    sword64 TimeNowInMilliseconds(void)
2492
    {
2493
        return (sword64)((uint64_t)(xTaskGetTickCount() * 1000) /
2494
            configTICK_RATE_HZ);
2495
    }
2496
#else
2497
    /* The time in milliseconds.
2498
     * Used for tickets to represent difference between when first seen and when
2499
     * sending.
2500
     *
2501
     * returns the time in milliseconds as a 64-bit value.
2502
     */
2503
    sword64 TimeNowInMilliseconds(void)
2504
678
    {
2505
678
        struct timeval now;
2506
2507
678
        if (gettimeofday(&now, 0) < 0)
2508
0
            return 0;
2509
2510
        /* Convert to milliseconds number. */
2511
678
        return (sword64)now.tv_sec * 1000 + now.tv_usec / 1000;
2512
678
    }
2513
#endif
2514
#else
2515
    /* user must supply time in milliseconds function:
2516
     *   sword64 TimeNowInMilliseconds(void);
2517
     * The response is milliseconds elapsed
2518
     */
2519
#endif /* !NO_ASN_TIME */
2520
#endif /* WOLFSSL_32BIT_MILLI_TIME */
2521
#endif /* HAVE_SESSION_TICKET || !NO_PSK || WOLFSSL_DTLS13 */
2522
2523
/* Add record layer header to message.
2524
 *
2525
 * output  The buffer to write the record layer header into.
2526
 * length  The length of the record data.
2527
 * type    The type of record message.
2528
 * ssl     The SSL/TLS object.
2529
 */
2530
static void AddTls13RecordHeader(byte* output, word32 length, byte type,
2531
                                 WOLFSSL* ssl)
2532
5.80k
{
2533
5.80k
    RecordLayerHeader* rl;
2534
2535
5.80k
    rl = (RecordLayerHeader*)output;
2536
5.80k
    rl->type    = type;
2537
5.80k
    rl->pvMajor = ssl->version.major;
2538
    /* NOTE: May be TLSv1_MINOR when sending first ClientHello. */
2539
5.80k
    rl->pvMinor = TLSv1_2_MINOR;
2540
5.80k
    c16toa((word16)length, rl->length);
2541
5.80k
}
2542
2543
/* Add handshake header to message.
2544
 *
2545
 * output      The buffer to write the handshake header into.
2546
 * length      The length of the handshake data.
2547
 * fragOffset  The offset of the fragment data. (DTLS)
2548
 * fragLength  The length of the fragment data. (DTLS)
2549
 * type        The type of handshake message.
2550
 * ssl         The SSL/TLS object. (DTLS)
2551
 */
2552
static void AddTls13HandShakeHeader(byte* output, word32 length,
2553
                                    word32 fragOffset, word32 fragLength,
2554
                                    byte type, WOLFSSL* ssl)
2555
{
2556
    HandShakeHeader* hs;
2557
    (void)fragOffset;
2558
    (void)fragLength;
2559
    (void)ssl;
2560
2561
#ifdef WOLFSSL_DTLS13
2562
    /* message_hash type is used for a synthetic message that replaces the first
2563
       ClientHello in the hash transcript when using HelloRetryRequest. It will
2564
       never be transmitted and, as the DTLS-only fields must not be considered
2565
       when computing the hash transcript, we can avoid to use the DTLS
2566
       handshake header. */
2567
    if (ssl->options.dtls && type != message_hash) {
2568
        Dtls13HandshakeAddHeader(ssl, output, (enum HandShakeType)type, length);
2569
        return;
2570
    }
2571
#endif /* WOLFSSL_DTLS13 */
2572
2573
    /* handshake header */
2574
    hs = (HandShakeHeader*)output;
2575
    hs->type = type;
2576
    c32to24(length, hs->length);
2577
}
2578
2579
2580
/* Add both record layer and handshake header to message.
2581
 *
2582
 * output      The buffer to write the headers into.
2583
 * length      The length of the handshake data.
2584
 * type        The type of record layer message.
2585
 * ssl         The SSL/TLS object. (DTLS)
2586
 */
2587
static void AddTls13Headers(byte* output, word32 length, byte type,
2588
                            WOLFSSL* ssl)
2589
{
2590
    word32 lengthAdj = HANDSHAKE_HEADER_SZ;
2591
    word32 outputAdj = RECORD_HEADER_SZ;
2592
2593
#ifdef WOLFSSL_DTLS13
2594
    if (ssl->options.dtls) {
2595
        Dtls13AddHeaders(output, length, (enum HandShakeType)type, ssl);
2596
        return;
2597
    }
2598
#endif /* WOLFSSL_DTLS13 */
2599
2600
    AddTls13RecordHeader(output, length + lengthAdj, handshake, ssl);
2601
    AddTls13HandShakeHeader(output + outputAdj, length, 0, length, type, ssl);
2602
}
2603
2604
#if (!defined(NO_WOLFSSL_CLIENT) || !defined(NO_WOLFSSL_SERVER)) \
2605
    && !defined(NO_CERTS)
2606
/* Add both record layer and fragment handshake header to message.
2607
 *
2608
 * output      The buffer to write the headers into.
2609
 * fragOffset  The offset of the fragment data. (DTLS)
2610
 * fragLength  The length of the fragment data. (DTLS)
2611
 * length      The length of the handshake data.
2612
 * type        The type of record layer message.
2613
 * ssl         The SSL/TLS object. (DTLS)
2614
 */
2615
static void AddTls13FragHeaders(byte* output, word32 fragSz, word32 fragOffset,
2616
                                word32 length, byte type, WOLFSSL* ssl)
2617
{
2618
    word32 lengthAdj = HANDSHAKE_HEADER_SZ;
2619
    word32 outputAdj = RECORD_HEADER_SZ;
2620
    (void)fragSz;
2621
2622
#ifdef WOLFSSL_DTLS13
2623
    /* we ignore fragmentation fields here because fragmentation logic for
2624
       DTLS1.3 is inside dtls13_handshake_send(). */
2625
    if (ssl->options.dtls) {
2626
        Dtls13AddHeaders(output, length, (enum HandShakeType)type, ssl);
2627
        return;
2628
    }
2629
#endif /* WOLFSSL_DTLS13 */
2630
2631
    AddTls13RecordHeader(output, fragSz + lengthAdj, handshake, ssl);
2632
    AddTls13HandShakeHeader(output + outputAdj, length, fragOffset, fragSz,
2633
                            type, ssl);
2634
}
2635
#endif /* (!NO_WOLFSSL_CLIENT || !NO_WOLFSSL_SERVER) && !NO_CERTS */
2636
2637
/* Write the sequence number into the buffer.
2638
 * No DTLS v1.3 support.
2639
 *
2640
 * ssl          The SSL/TLS object.
2641
 * verifyOrder  Which set of sequence numbers to use.
2642
 * out          The buffer to write into.
2643
 */
2644
static WC_INLINE void WriteSEQTls13(WOLFSSL* ssl, int verifyOrder, byte* out)
2645
1.68k
{
2646
1.68k
    word32 seq[2] = {0, 0};
2647
2648
1.68k
    if (ssl->options.dtls) {
2649
#ifdef WOLFSSL_DTLS13
2650
        Dtls13GetSeq(ssl, verifyOrder, seq, 1);
2651
#endif /* WOLFSSL_DTLS13 */
2652
0
    }
2653
1.68k
    else if (verifyOrder == PEER_ORDER) {
2654
130
        seq[0] = ssl->keys.peer_sequence_number_hi;
2655
130
        seq[1] = ssl->keys.peer_sequence_number_lo++;
2656
        /* handle rollover */
2657
130
        if (seq[1] > ssl->keys.peer_sequence_number_lo)
2658
0
            ssl->keys.peer_sequence_number_hi++;
2659
130
    }
2660
1.55k
    else {
2661
1.55k
        seq[0] = ssl->keys.sequence_number_hi;
2662
1.55k
        seq[1] = ssl->keys.sequence_number_lo++;
2663
        /* handle rollover */
2664
1.55k
        if (seq[1] > ssl->keys.sequence_number_lo)
2665
0
            ssl->keys.sequence_number_hi++;
2666
1.55k
    }
2667
#ifdef WOLFSSL_DEBUG_TLS
2668
    WOLFSSL_MSG_EX("TLS 1.3 Write Sequence %d %d", seq[0], seq[1]);
2669
#endif
2670
2671
1.68k
    c32toa(seq[0], out);
2672
1.68k
    c32toa(seq[1], out + OPAQUE32_LEN);
2673
1.68k
}
2674
2675
/* Build the nonce for TLS v1.3 encryption and decryption.
2676
 *
2677
 * ssl    The SSL/TLS object.
2678
 * nonce  The nonce data to use when encrypting or decrypting.
2679
 * iv     The derived IV.
2680
 * order  The side on which the message is to be or was sent.
2681
 */
2682
static WC_INLINE void BuildTls13Nonce(WOLFSSL* ssl, byte* nonce, const byte* iv,
2683
                                   int ivSz, int order)
2684
1.68k
{
2685
1.68k
    int seq_offset;
2686
    /* Ensure minimum nonce size for standard AEAD ciphers */
2687
1.68k
    if (ivSz < AEAD_NONCE_SZ)
2688
0
        ivSz = AEAD_NONCE_SZ;
2689
1.68k
    seq_offset = ivSz - SEQ_SZ;
2690
    /* The nonce is the IV with the sequence XORed into the last bytes. */
2691
1.68k
    WriteSEQTls13(ssl, order, nonce + seq_offset);
2692
1.68k
    XMEMCPY(nonce, iv, seq_offset);
2693
1.68k
    xorbuf(nonce + seq_offset, iv + seq_offset, SEQ_SZ);
2694
1.68k
}
2695
2696
#if defined(HAVE_CHACHA) && defined(HAVE_POLY1305)
2697
/* Encrypt with ChaCha20 and create authentication tag with Poly1305.
2698
 *
2699
 * ssl     The SSL/TLS object.
2700
 * output  The buffer to write encrypted data and authentication tag into.
2701
 *         May be the same pointer as input.
2702
 * input   The data to encrypt.
2703
 * sz      The number of bytes to encrypt.
2704
 * nonce   The nonce to use with ChaCha20.
2705
 * aad     The additional authentication data.
2706
 * aadSz   The size of the addition authentication data.
2707
 * tag     The authentication tag buffer.
2708
 * returns 0 on success, otherwise failure.
2709
 */
2710
static int ChaCha20Poly1305_Encrypt(WOLFSSL* ssl, byte* output,
2711
                                    const byte* input, word16 sz, byte* nonce,
2712
                                    const byte* aad, word16 aadSz, byte* tag)
2713
519
{
2714
    /* Persistent-key stitched helper: derives the per-record Poly1305 key from
2715
     * the keyed ChaCha, then encrypts and authenticates in one pass (the IFMA
2716
     * stitch for large records, else two-pass).  TLS 1.3 is always RFC 8439. */
2717
519
    return wc_ChaCha20Poly1305_Encrypt_ex(ssl->encrypt.chacha,
2718
519
        ssl->auth.poly1305, output, input, sz, nonce, tag, aad, aadSz);
2719
519
}
2720
#endif
2721
2722
#ifdef HAVE_NULL_CIPHER
2723
/* Create authentication tag and copy data over input.
2724
 *
2725
 * ssl     The SSL/TLS object.
2726
 * output  The buffer to copy data into.
2727
 *         May be the same pointer as input.
2728
 * input   The data.
2729
 * sz      The number of bytes of data.
2730
 * nonce   The nonce to use with authentication.
2731
 * aad     The additional authentication data.
2732
 * aadSz   The size of the addition authentication data.
2733
 * tag     The authentication tag buffer.
2734
 * returns 0 on success, otherwise failure.
2735
 */
2736
static int Tls13IntegrityOnly_Encrypt(WOLFSSL* ssl, byte* output,
2737
                                      const byte* input, word16 sz,
2738
                                      const byte* nonce,
2739
                                      const byte* aad, word16 aadSz, byte* tag)
2740
{
2741
    int ret;
2742
2743
    /* HMAC: nonce | aad | input  */
2744
    ret = wc_HmacUpdate(ssl->encrypt.hmac, nonce, ssl->specs.iv_size);
2745
    if (ret == 0)
2746
        ret = wc_HmacUpdate(ssl->encrypt.hmac, aad, aadSz);
2747
    if (ret == 0)
2748
        ret = wc_HmacUpdate(ssl->encrypt.hmac, input, sz);
2749
    if (ret == 0)
2750
        ret = wc_HmacFinal(ssl->encrypt.hmac, tag);
2751
    /* Copy the input to output if not the same buffer */
2752
    if (ret == 0 && output != input)
2753
        XMEMCPY(output, input, sz);
2754
    return ret;
2755
}
2756
#endif
2757
2758
/* Encrypt data for TLS v1.3.
2759
 *
2760
 * ssl     The SSL/TLS object.
2761
 * output  The buffer to write encrypted data and authentication tag into.
2762
 *         May be the same pointer as input.
2763
 * input   The record header and data to encrypt.
2764
 * sz      The number of bytes to encrypt.
2765
 * aad     The additional authentication data.
2766
 * aadSz   The size of the addition authentication data.
2767
 * asyncOkay If non-zero can return WC_PENDING_E, otherwise blocks on crypto
2768
 * returns 0 on success, otherwise failure.
2769
 */
2770
static int EncryptTls13(WOLFSSL* ssl, byte* output, const byte* input,
2771
                        word16 sz, const byte* aad, word16 aadSz, int asyncOkay)
2772
{
2773
    int    ret    = 0;
2774
    word16 dataSz;
2775
    word16 macSz  = ssl->specs.aead_mac_size;
2776
    word32 nonceSz = 0;
2777
#ifdef WOLFSSL_ASYNC_CRYPT
2778
    /* Only AES-GCM/AES-CCM assign asyncDev, so only they may pend under a
2779
     * poll-completing device; the crypto-callback re-invoke path returns
2780
     * before the push and is not limited this way. */
2781
    WC_ASYNC_DEV* asyncDev = NULL;
2782
    word32 event_flags = WC_ASYNC_FLAG_CALL_AGAIN;
2783
#endif
2784
2785
    WOLFSSL_ENTER("EncryptTls13");
2786
    if (sz < ssl->specs.aead_mac_size)
2787
        return BUFFER_E;
2788
    dataSz = sz - ssl->specs.aead_mac_size;
2789
2790
    (void)output;
2791
    (void)input;
2792
    (void)sz;
2793
    (void)dataSz;
2794
    (void)macSz;
2795
    (void)asyncOkay;
2796
    (void)nonceSz;
2797
2798
#ifdef WOLFSSL_ASYNC_CRYPT
2799
    if (ssl->error == WC_NO_ERR_TRACE(WC_PENDING_E)) {
2800
        ssl->error = 0; /* clear async */
2801
    }
2802
#endif
2803
#if defined(WOLFSSL_RENESAS_TSIP_TLS)
2804
    ret = tsip_Tls13AesEncrypt(ssl, output, input, dataSz);
2805
    if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) {
2806
        if (ret > 0) {
2807
            ret = 0; /* tsip_Tls13AesEncrypt returns output size */
2808
        }
2809
        return ret;
2810
    }
2811
    ret = 0;
2812
#endif /* WOLFSSL_RENESAS_TSIP_TLS */
2813
2814
    switch (ssl->encrypt.state) {
2815
        case CIPHER_STATE_BEGIN:
2816
        {
2817
        #ifdef WOLFSSL_DEBUG_TLS
2818
            WOLFSSL_MSG("Data to encrypt");
2819
            WOLFSSL_BUFFER(input, dataSz);
2820
            WOLFSSL_MSG("Additional Authentication Data");
2821
            WOLFSSL_BUFFER(aad, aadSz);
2822
        #endif
2823
2824
        #ifdef WOLFSSL_CIPHER_TEXT_CHECK
2825
            if (ssl->specs.bulk_cipher_algorithm != wolfssl_cipher_null &&
2826
                    dataSz >= sizeof(ssl->encrypt.sanityCheck)) {
2827
                XMEMCPY(ssl->encrypt.sanityCheck, input,
2828
                    sizeof(ssl->encrypt.sanityCheck));
2829
            }
2830
        #endif
2831
2832
        #ifdef CIPHER_NONCE
2833
            if (ssl->encrypt.nonce == NULL) {
2834
                ssl->encrypt.nonce = (byte*)XMALLOC(AEAD_MAX_IMP_SZ,
2835
                                                ssl->heap, DYNAMIC_TYPE_CIPHER);
2836
            #ifdef WOLFSSL_CHECK_MEM_ZERO
2837
                if (ssl->encrypt.nonce != NULL) {
2838
                    wc_MemZero_Add("EncryptTls13 nonce", ssl->encrypt.nonce,
2839
                        ssl->specs.iv_size);
2840
                }
2841
            #endif
2842
            }
2843
            if (ssl->encrypt.nonce == NULL)
2844
                return MEMORY_E;
2845
2846
            BuildTls13Nonce(ssl, ssl->encrypt.nonce, ssl->keys.aead_enc_imp_IV,
2847
                            ssl->specs.iv_size, CUR_ORDER);
2848
        #endif
2849
2850
            /* Advance state and proceed */
2851
            ssl->encrypt.state = CIPHER_STATE_DO;
2852
        }
2853
        FALL_THROUGH;
2854
2855
        case CIPHER_STATE_DO:
2856
        {
2857
            switch (ssl->specs.bulk_cipher_algorithm) {
2858
            #ifdef BUILD_AESGCM
2859
                case wolfssl_aes_gcm:
2860
                #ifdef WOLFSSL_ASYNC_CRYPT
2861
                    /* initialize event */
2862
                    asyncDev = &ssl->encrypt.aes->asyncDev;
2863
                    ret = wolfSSL_AsyncInit(ssl, asyncDev, event_flags);
2864
                    if (ret != 0)
2865
                        break;
2866
                #endif
2867
2868
                    nonceSz = AESGCM_NONCE_SZ;
2869
2870
                #if defined(HAVE_PK_CALLBACKS)
2871
                    ret = WC_NO_ERR_TRACE(NOT_COMPILED_IN);
2872
                    if (ssl->ctx && ssl->ctx->PerformTlsRecordProcessingCb) {
2873
                        ret = ssl->ctx->PerformTlsRecordProcessingCb(ssl, 1,
2874
                                  output, input, dataSz,
2875
                                  ssl->encrypt.nonce, nonceSz,
2876
                                  output + dataSz, macSz,
2877
                                  aad, aadSz);
2878
                    }
2879
                    if (ret == WC_NO_ERR_TRACE(NOT_COMPILED_IN))
2880
                #endif
2881
                    {
2882
2883
                #if ((defined(HAVE_FIPS) || defined(HAVE_SELFTEST)) && \
2884
                    (!defined(HAVE_FIPS_VERSION) || (HAVE_FIPS_VERSION < 2)))
2885
                        ret = wc_AesGcmEncrypt(ssl->encrypt.aes, output, input,
2886
                            dataSz, ssl->encrypt.nonce, nonceSz,
2887
                            output + dataSz, macSz, aad, aadSz);
2888
                #else
2889
                        ret = wc_AesGcmSetExtIV(ssl->encrypt.aes,
2890
                                ssl->encrypt.nonce, nonceSz);
2891
                        if (ret == 0) {
2892
                            ret = wc_AesGcmEncrypt_ex(ssl->encrypt.aes, output,
2893
                                    input, dataSz, ssl->encrypt.nonce, nonceSz,
2894
                                    output + dataSz, macSz, aad, aadSz);
2895
                        }
2896
                #endif
2897
                    }
2898
                    break;
2899
            #endif
2900
2901
            #ifdef HAVE_AESCCM
2902
                case wolfssl_aes_ccm:
2903
                #ifdef WOLFSSL_ASYNC_CRYPT
2904
                    /* initialize event */
2905
                    asyncDev = &ssl->encrypt.aes->asyncDev;
2906
                    ret = wolfSSL_AsyncInit(ssl, asyncDev, event_flags);
2907
                    if (ret != 0)
2908
                        break;
2909
                #endif
2910
2911
                    nonceSz = AESCCM_NONCE_SZ;
2912
                #if defined(HAVE_PK_CALLBACKS)
2913
                    ret = WC_NO_ERR_TRACE(NOT_COMPILED_IN);
2914
                    if (ssl->ctx && ssl->ctx->PerformTlsRecordProcessingCb) {
2915
                        ret = ssl->ctx->PerformTlsRecordProcessingCb(ssl, 1,
2916
                                  output, input, dataSz,
2917
                                  ssl->encrypt.nonce, nonceSz,
2918
                                  output + dataSz, macSz,
2919
                                  aad, aadSz);
2920
                    }
2921
                    if (ret == WC_NO_ERR_TRACE(NOT_COMPILED_IN))
2922
                #endif
2923
                    {
2924
                #if ((defined(HAVE_FIPS) || defined(HAVE_SELFTEST)) && \
2925
                    (!defined(HAVE_FIPS_VERSION) || (HAVE_FIPS_VERSION < 2)))
2926
                        ret = wc_AesCcmEncrypt(ssl->encrypt.aes, output, input,
2927
                            dataSz, ssl->encrypt.nonce, nonceSz,
2928
                            output + dataSz, macSz, aad, aadSz);
2929
                #else
2930
                        ret = wc_AesCcmSetNonce(ssl->encrypt.aes,
2931
                                ssl->encrypt.nonce, nonceSz);
2932
                        if (ret == 0) {
2933
                            ret = wc_AesCcmEncrypt_ex(ssl->encrypt.aes, output,
2934
                                    input, dataSz, ssl->encrypt.nonce, nonceSz,
2935
                                    output + dataSz, macSz, aad, aadSz);
2936
                        }
2937
                #endif
2938
                    }
2939
                    break;
2940
            #endif
2941
2942
            #if defined(HAVE_CHACHA) && defined(HAVE_POLY1305)
2943
                case wolfssl_chacha:
2944
                    ret = ChaCha20Poly1305_Encrypt(ssl, output, input, dataSz,
2945
                        ssl->encrypt.nonce, aad, aadSz, output + dataSz);
2946
                    break;
2947
            #endif
2948
2949
            #ifdef WOLFSSL_SM4_GCM
2950
                case wolfssl_sm4_gcm:
2951
                    nonceSz = SM4_GCM_NONCE_SZ;
2952
                    ret = wc_Sm4GcmEncrypt(ssl->encrypt.sm4, output, input,
2953
                        dataSz, ssl->encrypt.nonce, nonceSz, output + dataSz,
2954
                        macSz, aad, aadSz);
2955
                    break;
2956
            #endif
2957
2958
            #ifdef WOLFSSL_SM4_CCM
2959
                case wolfssl_sm4_ccm:
2960
                    nonceSz = SM4_CCM_NONCE_SZ;
2961
                    ret = wc_Sm4CcmEncrypt(ssl->encrypt.sm4, output, input,
2962
                        dataSz, ssl->encrypt.nonce, nonceSz, output + dataSz,
2963
                        macSz, aad, aadSz);
2964
                    break;
2965
            #endif
2966
2967
            #ifdef HAVE_NULL_CIPHER
2968
                case wolfssl_cipher_null:
2969
                    ret = Tls13IntegrityOnly_Encrypt(ssl, output, input, dataSz,
2970
                        ssl->encrypt.nonce, aad, aadSz, output + dataSz);
2971
                    break;
2972
            #endif
2973
2974
                default:
2975
                    WOLFSSL_MSG("wolfSSL Encrypt programming error");
2976
                    return ENCRYPT_ERROR;
2977
            }
2978
2979
        #ifdef WOLFSSL_ASYNC_CRYPT
2980
            if (ret == WC_NO_ERR_TRACE(WC_PENDING_E)) {
2981
                /* if async is not okay, then block */
2982
                if (!asyncOkay) {
2983
                #if defined(WOLFSSL_ASYNC_REINVOKE) && \
2984
                    !defined(WOLF_CRYPTO_CB_ASYNC_POLL)
2985
                    /* wc_AsyncWait() never runs a callback: leave the state
2986
                     * at CIPHER_STATE_DO for the caller to re-invoke. */
2987
                    return ret;
2988
                #else
2989
                    ret = wc_AsyncWait(ret, asyncDev, event_flags);
2990
                #endif
2991
                }
2992
                else {
2993
                #if !defined(WOLFSSL_ASYNC_REINVOKE) || \
2994
                    defined(WOLF_CRYPTO_CB_ASYNC_POLL)
2995
                    /* Poll completes into output; the resume must skip the
2996
                     * in-place AEAD or it would encrypt its own output. */
2997
                    ssl->encrypt.state = CIPHER_STATE_END;
2998
                #endif
2999
                    /* Else stay at CIPHER_STATE_DO: the retry must re-invoke
3000
                     * the callback or the record goes out unencrypted. */
3001
                    return wolfSSL_AsyncPush(ssl, asyncDev);
3002
                }
3003
            }
3004
        #endif
3005
3006
            /* Advance state */
3007
            ssl->encrypt.state = CIPHER_STATE_END;
3008
        }
3009
        FALL_THROUGH;
3010
3011
        case CIPHER_STATE_END:
3012
        {
3013
        #ifdef WOLFSSL_DEBUG_TLS
3014
            #ifdef CIPHER_NONCE
3015
                WOLFSSL_MSG("Nonce");
3016
                WOLFSSL_BUFFER(ssl->encrypt.nonce, ssl->specs.iv_size);
3017
            #endif
3018
                WOLFSSL_MSG("Encrypted data");
3019
                WOLFSSL_BUFFER(output, dataSz);
3020
                WOLFSSL_MSG("Authentication Tag");
3021
                WOLFSSL_BUFFER(output + dataSz, macSz);
3022
        #endif
3023
3024
        #ifdef WOLFSSL_CIPHER_TEXT_CHECK
3025
            if (ssl->specs.bulk_cipher_algorithm != wolfssl_cipher_null &&
3026
                    dataSz >= sizeof(ssl->encrypt.sanityCheck) &&
3027
                XMEMCMP(output, ssl->encrypt.sanityCheck,
3028
                    sizeof(ssl->encrypt.sanityCheck)) == 0) {
3029
3030
                WOLFSSL_MSG("EncryptTls13 sanity check failed! Glitch?");
3031
                return ENCRYPT_ERROR;
3032
            }
3033
            ForceZero(ssl->encrypt.sanityCheck,
3034
                sizeof(ssl->encrypt.sanityCheck));
3035
        #endif
3036
        #ifdef WOLFSSL_CHECK_MEM_ZERO
3037
            if ((ssl->specs.bulk_cipher_algorithm != wolfssl_cipher_null) &&
3038
                    (output != input) && (ret == 0)) {
3039
                wc_MemZero_Add("TLS 1.3 Encrypt plaintext", input, sz);
3040
            }
3041
        #endif
3042
3043
        #ifdef CIPHER_NONCE
3044
            ForceZero(ssl->encrypt.nonce, ssl->specs.iv_size);
3045
        #endif
3046
3047
            break;
3048
        }
3049
3050
        default:
3051
            break;
3052
    }
3053
3054
3055
    /* Reset state */
3056
    ssl->encrypt.state = CIPHER_STATE_BEGIN;
3057
3058
    return ret;
3059
}
3060
3061
#if defined(HAVE_CHACHA) && defined(HAVE_POLY1305)
3062
/* Decrypt with ChaCha20 and check authentication tag with Poly1305.
3063
 *
3064
 * ssl     The SSL/TLS object.
3065
 * output  The buffer to write decrypted data into.
3066
 *         May be the same pointer as input.
3067
 * input   The data to decrypt.
3068
 * sz      The number of bytes to decrypt.
3069
 * nonce   The nonce to use with ChaCha20.
3070
 * aad     The additional authentication data.
3071
 * aadSz   The size of the addition authentication data.
3072
 * tagIn   The authentication tag data from packet.
3073
 * returns 0 on success, otherwise failure.
3074
 */
3075
static int ChaCha20Poly1305_Decrypt(WOLFSSL* ssl, byte* output,
3076
                                    const byte* input, word16 sz, byte* nonce,
3077
                                    const byte* aad, word16 aadSz,
3078
                                    const byte* tagIn)
3079
38
{
3080
38
    int ret;
3081
3082
    /* Persistent-key stitched helper: verifies the Poly1305 tag over
3083
     * aad+ciphertext and decrypts in one pass (the IFMA decrypt stitch for
3084
     * large records, else two-pass); it zeroes output on tag mismatch. */
3085
38
    ret = wc_ChaCha20Poly1305_Decrypt_ex(ssl->decrypt.chacha,
3086
38
        ssl->auth.poly1305, output, input, sz, nonce, tagIn, aad, aadSz);
3087
38
    if (ret == WC_NO_ERR_TRACE(MAC_CMP_FAILED_E)) {
3088
38
        WOLFSSL_MSG("MAC did not match");
3089
38
        ret = VERIFY_MAC_ERROR;
3090
38
    }
3091
3092
38
    return ret;
3093
38
}
3094
#endif
3095
3096
#ifdef HAVE_NULL_CIPHER
3097
/* Check HMAC tag and copy over input.
3098
 *
3099
 * ssl     The SSL/TLS object.
3100
 * output  The buffer to copy data into.
3101
 *         May be the same pointer as input.
3102
 * input   The data.
3103
 * sz      The number of bytes of data.
3104
 * nonce   The nonce to use with authentication.
3105
 * aad     The additional authentication data.
3106
 * aadSz   The size of the addition authentication data.
3107
 * tagIn   The authentication tag data from packet.
3108
 * returns 0 on success, otherwise failure.
3109
 */
3110
static int Tls13IntegrityOnly_Decrypt(WOLFSSL* ssl, byte* output,
3111
                                      const byte* input, word16 sz,
3112
                                      const byte* nonce,
3113
                                      const byte* aad, word16 aadSz,
3114
                                      const byte* tagIn)
3115
{
3116
    int ret;
3117
    byte hmac[WC_MAX_DIGEST_SIZE];
3118
3119
    /* HMAC: nonce | aad | input  */
3120
    ret = wc_HmacUpdate(ssl->decrypt.hmac, nonce, ssl->specs.iv_size);
3121
    if (ret == 0)
3122
        ret = wc_HmacUpdate(ssl->decrypt.hmac, aad, aadSz);
3123
    if (ret == 0)
3124
        ret = wc_HmacUpdate(ssl->decrypt.hmac, input, sz);
3125
    if (ret == 0)
3126
        ret = wc_HmacFinal(ssl->decrypt.hmac, hmac);
3127
    /* Check authentication tag matches */
3128
    if (ret == 0 && ConstantCompare(tagIn, hmac, ssl->specs.hash_size) != 0)
3129
        ret = DECRYPT_ERROR;
3130
    /* Copy the input to output if not the same buffer */
3131
    if (ret == 0 && output != input)
3132
        XMEMCPY(output, input, sz);
3133
    ForceZero(hmac, sizeof(hmac));
3134
    return ret;
3135
}
3136
#endif
3137
3138
/* Decrypt data for TLS v1.3.
3139
 *
3140
 * ssl     The SSL/TLS object.
3141
 * output  The buffer to write decrypted data into.
3142
 *         May be the same pointer as input.
3143
 * input   The data to decrypt and authentication tag.
3144
 * sz      The length of the encrypted data plus authentication tag.
3145
 * aad     The additional authentication data.
3146
 * aadSz   The size of the addition authentication data.
3147
 * returns 0 on success, otherwise failure.
3148
 */
3149
int DecryptTls13(WOLFSSL* ssl, byte* output, const byte* input, word16 sz,
3150
                 const byte* aad, word16 aadSz)
3151
0
{
3152
0
    int    ret    = 0;
3153
0
    word16 dataSz;
3154
0
    word16 macSz  = ssl->specs.aead_mac_size;
3155
0
    word32 nonceSz = 0;
3156
3157
0
    WOLFSSL_ENTER("DecryptTls13");
3158
0
    if (sz < ssl->specs.aead_mac_size) {
3159
0
        return BAD_FUNC_ARG;
3160
0
    }
3161
0
    dataSz = sz - ssl->specs.aead_mac_size;
3162
3163
#if defined(WOLFSSL_RENESAS_TSIP_TLS)
3164
    ret = tsip_Tls13AesDecrypt(ssl, output, input, sz);
3165
3166
    if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) {
3167
        #ifndef WOLFSSL_EARLY_DATA
3168
        if (ret < 0) {
3169
            ret = VERIFY_MAC_ERROR;
3170
            WOLFSSL_ERROR_VERBOSE(ret);
3171
        }
3172
        #endif
3173
        return ret;
3174
    }
3175
#endif
3176
3177
#ifdef WOLFSSL_ASYNC_CRYPT
3178
    ret = wolfSSL_AsyncPop(ssl, &ssl->decrypt.state);
3179
    if (ret != WC_NO_ERR_TRACE(WC_NO_PENDING_E)) {
3180
        /* check for still pending */
3181
        if (ret == WC_NO_ERR_TRACE(WC_PENDING_E))
3182
            return ret;
3183
3184
        ssl->error = 0; /* clear async */
3185
3186
        /* let failures through so CIPHER_STATE_END logic is run */
3187
    }
3188
    else
3189
#endif
3190
0
    {
3191
        /* Reset state */
3192
0
        ret = 0;
3193
0
        ssl->decrypt.state = CIPHER_STATE_BEGIN;
3194
0
    }
3195
3196
0
    (void)output;
3197
0
    (void)input;
3198
0
    (void)sz;
3199
0
    (void)dataSz;
3200
0
    (void)macSz;
3201
0
    (void)nonceSz;
3202
3203
0
    switch (ssl->decrypt.state) {
3204
0
        case CIPHER_STATE_BEGIN:
3205
0
        {
3206
        #ifdef WOLFSSL_DEBUG_TLS
3207
            WOLFSSL_MSG("Data to decrypt");
3208
            WOLFSSL_BUFFER(input, dataSz);
3209
            WOLFSSL_MSG("Additional Authentication Data");
3210
            WOLFSSL_BUFFER(aad, aadSz);
3211
            WOLFSSL_MSG("Authentication tag");
3212
            WOLFSSL_BUFFER(input + dataSz, macSz);
3213
        #endif
3214
3215
0
        #ifdef CIPHER_NONCE
3216
0
            if (ssl->decrypt.nonce == NULL) {
3217
0
                ssl->decrypt.nonce = (byte*)XMALLOC(AEAD_MAX_IMP_SZ,
3218
0
                                                ssl->heap, DYNAMIC_TYPE_CIPHER);
3219
            #ifdef WOLFSSL_CHECK_MEM_ZERO
3220
                if (ssl->decrypt.nonce != NULL) {
3221
                    wc_MemZero_Add("DecryptTls13 nonce", ssl->decrypt.nonce,
3222
                        ssl->specs.iv_size);
3223
                }
3224
            #endif
3225
0
            }
3226
0
            if (ssl->decrypt.nonce == NULL)
3227
0
                return MEMORY_E;
3228
3229
0
            BuildTls13Nonce(ssl, ssl->decrypt.nonce, ssl->keys.aead_dec_imp_IV,
3230
0
                            ssl->specs.iv_size, PEER_ORDER);
3231
0
        #endif
3232
3233
            /* Advance state and proceed */
3234
0
            ssl->decrypt.state = CIPHER_STATE_DO;
3235
0
        }
3236
0
        FALL_THROUGH;
3237
3238
0
        case CIPHER_STATE_DO:
3239
0
        {
3240
0
            switch (ssl->specs.bulk_cipher_algorithm) {
3241
0
            #ifdef BUILD_AESGCM
3242
0
                case wolfssl_aes_gcm:
3243
                #ifdef WOLFSSL_ASYNC_CRYPT
3244
                    /* initialize event */
3245
                    ret = wolfSSL_AsyncInit(ssl, &ssl->decrypt.aes->asyncDev,
3246
                        WC_ASYNC_FLAG_NONE);
3247
                    if (ret != 0)
3248
                        break;
3249
                #endif
3250
3251
0
                    nonceSz = AESGCM_NONCE_SZ;
3252
3253
                #if defined(HAVE_PK_CALLBACKS)
3254
                    ret = WC_NO_ERR_TRACE(NOT_COMPILED_IN);
3255
                    if (ssl->ctx && ssl->ctx->PerformTlsRecordProcessingCb) {
3256
                        ret = ssl->ctx->PerformTlsRecordProcessingCb(ssl, 0,
3257
                                  output, input, dataSz,
3258
                                  ssl->decrypt.nonce, nonceSz,
3259
                                  (byte *)(input + dataSz), macSz,
3260
                                  aad, aadSz);
3261
                    }
3262
                    if (ret == WC_NO_ERR_TRACE(NOT_COMPILED_IN))
3263
                #endif
3264
0
                    {
3265
3266
0
                        ret = wc_AesGcmDecrypt(ssl->decrypt.aes, output, input,
3267
0
                            dataSz, ssl->decrypt.nonce, nonceSz,
3268
0
                            input + dataSz, macSz, aad, aadSz);
3269
3270
                #ifdef WOLFSSL_ASYNC_CRYPT
3271
                        if (ret == WC_NO_ERR_TRACE(WC_PENDING_E)) {
3272
                            ret = wolfSSL_AsyncPush(ssl,
3273
                                &ssl->decrypt.aes->asyncDev);
3274
                        }
3275
                #endif
3276
3277
0
                    }
3278
0
                    break;
3279
0
            #endif
3280
3281
0
            #ifdef HAVE_AESCCM
3282
0
                case wolfssl_aes_ccm:
3283
                #ifdef WOLFSSL_ASYNC_CRYPT
3284
                    /* initialize event */
3285
                    ret = wolfSSL_AsyncInit(ssl, &ssl->decrypt.aes->asyncDev,
3286
                        WC_ASYNC_FLAG_NONE);
3287
                    if (ret != 0)
3288
                        break;
3289
                #endif
3290
3291
0
                    nonceSz = AESCCM_NONCE_SZ;
3292
                #if defined(HAVE_PK_CALLBACKS)
3293
                    ret = WC_NO_ERR_TRACE(NOT_COMPILED_IN);
3294
                    if (ssl->ctx && ssl->ctx->PerformTlsRecordProcessingCb) {
3295
                        ret = ssl->ctx->PerformTlsRecordProcessingCb(ssl, 0,
3296
                                  output, input, dataSz,
3297
                                  ssl->decrypt.nonce, nonceSz,
3298
                                  (byte *)(input + dataSz), macSz,
3299
                                  aad, aadSz);
3300
                    }
3301
                    if (ret == WC_NO_ERR_TRACE(NOT_COMPILED_IN))
3302
                #endif
3303
0
                    {
3304
0
                        ret = wc_AesCcmDecrypt(ssl->decrypt.aes, output, input,
3305
0
                            dataSz, ssl->decrypt.nonce, nonceSz,
3306
0
                            input + dataSz, macSz, aad, aadSz);
3307
                #ifdef WOLFSSL_ASYNC_CRYPT
3308
                        if (ret == WC_NO_ERR_TRACE(WC_PENDING_E)) {
3309
                            ret = wolfSSL_AsyncPush(ssl,
3310
                                &ssl->decrypt.aes->asyncDev);
3311
                        }
3312
                #endif
3313
0
                    }
3314
0
                    break;
3315
0
            #endif
3316
3317
0
            #if defined(HAVE_CHACHA) && defined(HAVE_POLY1305)
3318
0
                case wolfssl_chacha:
3319
0
                    ret = ChaCha20Poly1305_Decrypt(ssl, output, input, dataSz,
3320
0
                        ssl->decrypt.nonce, aad, aadSz, input + dataSz);
3321
0
                    break;
3322
0
            #endif
3323
3324
0
            #ifdef WOLFSSL_SM4_GCM
3325
0
                case wolfssl_sm4_gcm:
3326
0
                    nonceSz = SM4_GCM_NONCE_SZ;
3327
0
                    ret = wc_Sm4GcmDecrypt(ssl->decrypt.sm4, output, input,
3328
0
                        dataSz, ssl->decrypt.nonce, nonceSz, input + dataSz,
3329
0
                        macSz, aad, aadSz);
3330
0
                    break;
3331
0
            #endif
3332
3333
0
            #ifdef WOLFSSL_SM4_CCM
3334
0
                case wolfssl_sm4_ccm:
3335
0
                    nonceSz = SM4_CCM_NONCE_SZ;
3336
0
                    ret = wc_Sm4CcmDecrypt(ssl->decrypt.sm4, output, input,
3337
0
                        dataSz, ssl->decrypt.nonce, nonceSz, input + dataSz,
3338
0
                        macSz, aad, aadSz);
3339
0
                    break;
3340
0
            #endif
3341
3342
            #ifdef HAVE_NULL_CIPHER
3343
                case wolfssl_cipher_null:
3344
                    ret = Tls13IntegrityOnly_Decrypt(ssl, output, input, dataSz,
3345
                        ssl->decrypt.nonce, aad, aadSz, input + dataSz);
3346
                    break;
3347
            #endif
3348
0
                default:
3349
0
                    WOLFSSL_MSG("wolfSSL Decrypt programming error");
3350
0
                    return DECRYPT_ERROR;
3351
0
            }
3352
3353
        #ifdef WOLFSSL_ASYNC_CRYPT
3354
            if (ret == WC_NO_ERR_TRACE(WC_PENDING_E)) {
3355
            #if !defined(WOLFSSL_ASYNC_REINVOKE) || \
3356
                defined(WOLF_CRYPTO_CB_ASYNC_POLL)
3357
                /* The poll completes the operation into the output buffer,
3358
                 * so the resume must not run the AEAD again: advance past
3359
                 * it now (the pop does not, the event is CALL_AGAIN). */
3360
                ssl->decrypt.state = CIPHER_STATE_END;
3361
            #else
3362
                /* Crypto callback re-invocation: leave the state at
3363
                 * CIPHER_STATE_DO so the retry re-enters the AEAD;
3364
                 * advancing would hand back the undecrypted record. */
3365
            #endif
3366
                return ret;
3367
            }
3368
        #endif
3369
3370
            /* Advance state */
3371
0
            ssl->decrypt.state = CIPHER_STATE_END;
3372
0
        }
3373
0
        FALL_THROUGH;
3374
3375
0
        case CIPHER_STATE_END:
3376
0
        {
3377
        #ifdef WOLFSSL_DEBUG_TLS
3378
            #ifdef CIPHER_NONCE
3379
                WOLFSSL_MSG("Nonce");
3380
                WOLFSSL_BUFFER(ssl->decrypt.nonce, ssl->specs.iv_size);
3381
            #endif
3382
                WOLFSSL_MSG("Decrypted data");
3383
                WOLFSSL_BUFFER(output, dataSz);
3384
        #endif
3385
        #ifdef WOLFSSL_CHECK_MEM_ZERO
3386
            if ((ssl->specs.bulk_cipher_algorithm != wolfssl_cipher_null) &&
3387
                    (ret == 0)) {
3388
                wc_MemZero_Add("TLS 1.3 Decrypted data", output, sz);
3389
            }
3390
        #endif
3391
3392
0
        #ifdef CIPHER_NONCE
3393
0
            ForceZero(ssl->decrypt.nonce, ssl->specs.iv_size);
3394
0
        #endif
3395
3396
0
            break;
3397
0
        }
3398
3399
0
       default:
3400
0
            break;
3401
0
    }
3402
3403
0
    if (ret < 0) {
3404
0
        WOLFSSL_ERROR_VERBOSE(ret);
3405
0
    }
3406
3407
0
    return ret;
3408
0
}
3409
3410
/* Build SSL Message, encrypted.
3411
 * TLS v1.3 encryption is AEAD only.
3412
 *
3413
 * ssl         The SSL/TLS object.
3414
 * output      The buffer to write record message to.
3415
 * outSz       Size of the buffer being written into.
3416
 * input       The record data to encrypt (excluding record header).
3417
 * inSz        The size of the record data.
3418
 * type        The recorder header content type.
3419
 * hashOutput  Whether to hash the unencrypted record data.
3420
 * sizeOnly    Only want the size of the record message.
3421
 * asyncOkay   If non-zero can return WC_PENDING_E, otherwise blocks on crypto
3422
 * returns the size of the encrypted record message or negative value on error.
3423
 */
3424
int BuildTls13Message(WOLFSSL* ssl, byte* output, int outSz, const byte* input,
3425
                int inSz, int type, int hashOutput, int sizeOnly, int asyncOkay)
3426
{
3427
    int ret;
3428
    BuildMsgArgs* args;
3429
    BuildMsgArgs  lcl_args;
3430
3431
    WOLFSSL_ENTER("BuildTls13Message");
3432
3433
    if (ssl == NULL) {
3434
        return BAD_FUNC_ARG;
3435
    }
3436
3437
#ifdef WOLFSSL_ASYNC_CRYPT
3438
    ret = WC_NO_PENDING_E;
3439
    if (asyncOkay) {
3440
        if (ssl->async == NULL) {
3441
            ssl->async = (struct WOLFSSL_ASYNC*)
3442
                    XMALLOC(sizeof(struct WOLFSSL_ASYNC), ssl->heap,
3443
                            DYNAMIC_TYPE_ASYNC);
3444
            if (ssl->async == NULL)
3445
                return MEMORY_E;
3446
            XMEMSET(ssl->async, 0, sizeof(struct WOLFSSL_ASYNC));
3447
        }
3448
        /* Not ssl->async->args: that buffer belongs to the handler that
3449
         * called down into the record builder. */
3450
        args = &ssl->async->buildArgs;
3451
3452
        ret = wolfSSL_AsyncPop(ssl, &ssl->options.buildMsgState);
3453
        if (ret != WC_NO_ERR_TRACE(WC_NO_PENDING_E)) {
3454
            /* Check for error */
3455
            if (ret < 0)
3456
                goto exit_buildmsg;
3457
        }
3458
    }
3459
    else
3460
#endif
3461
    {
3462
        args = &lcl_args;
3463
    }
3464
3465
    /* buildArgs13Set, not the pop result, marks a resume: the handler
3466
     * already popped the pending, and resetting on the pop result would
3467
     * rebuild a half-built record (transcript/sequence advance twice). */
3468
#ifdef WOLFSSL_ASYNC_CRYPT
3469
    if (!asyncOkay || !ssl->options.buildArgs13Set)
3470
#endif
3471
    {
3472
        /* Note: these hit ssl->options even for a sizeOnly probe, where every
3473
         * other result goes to lcl_args, so a probe destroys the resume point
3474
         * of a suspended asynchronous build. wolfssl_local_GetRecordSize() is
3475
         * the only sizeOnly caller and restores them; a new one must too. */
3476
        ret = 0;
3477
        ssl->options.buildMsgState = BUILD_MSG_BEGIN;
3478
        /* A fresh record must not inherit a suspended build's mid-way
3479
         * cipher state. Not for sizeOnly probes: GetRecordSize() does not
3480
         * save this field and rewinding would re-run the AEAD. */
3481
        if (!sizeOnly)
3482
            ssl->encrypt.state = CIPHER_STATE_BEGIN;
3483
        XMEMSET(args, 0, sizeof(BuildMsgArgs));
3484
3485
        args->headerSz = RECORD_HEADER_SZ;
3486
#ifdef WOLFSSL_DTLS13
3487
        if (ssl->options.dtls)
3488
            args->headerSz = Dtls13GetRlHeaderLength(ssl, 1);
3489
#endif /* WOLFSSL_DTLS13 */
3490
3491
        args->sz = args->headerSz + (word32)inSz;
3492
        args->idx  = args->headerSz;
3493
    }
3494
3495
#ifdef WOLFSSL_ASYNC_CRYPT
3496
    if (ret == WC_NO_ERR_TRACE(WC_NO_PENDING_E))
3497
        ret = 0;
3498
#endif
3499
3500
    switch (ssl->options.buildMsgState) {
3501
        case BUILD_MSG_BEGIN:
3502
        {
3503
           /* catch mistaken sizeOnly parameter */
3504
            if (sizeOnly) {
3505
                if (output || input) {
3506
                    WOLFSSL_MSG("BuildTls13Message with sizeOnly "
3507
                                "doesn't need input or output");
3508
                    return BAD_FUNC_ARG;
3509
                }
3510
            }
3511
            else if (output == NULL || input == NULL) {
3512
                return BAD_FUNC_ARG;
3513
            }
3514
3515
            /* Record layer content type at the end of record data. */
3516
            args->sz++;
3517
            /* Authentication data at the end. */
3518
            args->sz += ssl->specs.aead_mac_size;
3519
#ifdef WOLFSSL_DTLS13
3520
            /* Pad to minimum length */
3521
            if (ssl->options.dtls &&
3522
                    args->sz < (word32)Dtls13MinimumRecordLength(ssl)) {
3523
                args->pad = Dtls13MinimumRecordLength(ssl) - args->sz;
3524
                args->sz = Dtls13MinimumRecordLength(ssl);
3525
            }
3526
#endif
3527
            if (sizeOnly)
3528
                return (int)args->sz;
3529
3530
            if (args->sz > (word32)outSz) {
3531
                WOLFSSL_MSG("Oops, want to write past output buffer size");
3532
                return BUFFER_E;
3533
            }
3534
3535
            /* Record data length. */
3536
            args->size = (word16)(args->sz - args->headerSz);
3537
            /* Write/update the record header with the new size.
3538
             * Always have the content type as application data for encrypted
3539
             * messages in TLS v1.3.
3540
             */
3541
3542
            if (ssl->options.dtls) {
3543
#ifdef WOLFSSL_DTLS13
3544
                Dtls13RlAddCiphertextHeader(ssl, output, args->size);
3545
#endif /* WOLFSSL_DTLS13 */
3546
            }
3547
            else {
3548
                AddTls13RecordHeader(output, args->size, application_data, ssl);
3549
            }
3550
3551
            /* TLS v1.3 can do in place encryption. */
3552
            if (input != output + args->idx)
3553
                XMEMCPY(output + args->idx, input, (size_t)inSz);
3554
            args->idx += (word32)inSz;
3555
3556
    #ifdef WOLFSSL_ASYNC_CRYPT
3557
            /* Set only after the argument checks above cannot return any
3558
             * more: an early error return must not leave the resume marker
3559
             * set, or the next build would reuse stale args. */
3560
            if (asyncOkay)
3561
                ssl->options.buildArgs13Set = 1;
3562
    #endif
3563
            ssl->options.buildMsgState = BUILD_MSG_HASH;
3564
        }
3565
        FALL_THROUGH;
3566
3567
        case BUILD_MSG_HASH:
3568
        {
3569
            if (hashOutput) {
3570
                ret = HashOutput(ssl, output, (int)args->headerSz + inSz, 0);
3571
                if (ret != 0)
3572
                    goto exit_buildmsg;
3573
            }
3574
3575
            /* The real record content type goes at the end of the data. */
3576
            output[args->idx++] = (byte)type;
3577
            /* Double check that any necessary padding is zero'd out */
3578
            XMEMSET(output + args->idx, 0, args->pad);
3579
            args->idx += args->pad;
3580
3581
            ssl->options.buildMsgState = BUILD_MSG_ENCRYPT;
3582
        }
3583
        FALL_THROUGH;
3584
3585
        case BUILD_MSG_ENCRYPT:
3586
        {
3587
#ifdef WOLFSSL_QUIC
3588
            if (WOLFSSL_IS_QUIC(ssl)) {
3589
                /* QUIC does not use encryption of the TLS Record Layer.
3590
                 * Return the original length + added headers
3591
                 * and restore it in the record header. */
3592
                AddTls13RecordHeader(output, (word32)inSz, (byte)type, ssl);
3593
                ret = (int)args->headerSz + inSz;
3594
                goto exit_buildmsg;
3595
            }
3596
#endif
3597
        #ifdef ATOMIC_USER
3598
            if (ssl->ctx->MacEncryptCb) {
3599
                /* User Record Layer Callback handling */
3600
                byte* mac = output + args->idx;
3601
                output += args->headerSz;
3602
3603
                ret = ssl->ctx->MacEncryptCb(ssl, mac, output, (unsigned int)inSz, (byte)type, 0,
3604
                        output, output, args->size, ssl->MacEncryptCtx);
3605
            }
3606
            else
3607
        #endif
3608
            {
3609
                const byte* aad = output;
3610
                output += args->headerSz;
3611
                ret = EncryptTls13(ssl, output, output, args->size, aad,
3612
                                   (word16)args->headerSz, asyncOkay);
3613
            #ifdef WOLFSSL_ASYNC_REINVOKE
3614
                /* Non-resumable caller (alerts): finish the encryption by
3615
                 * re-invoking; devices were already waited on above. */
3616
                if (!asyncOkay) {
3617
                    int reinvoke = 0;
3618
3619
                    while (ret == WC_NO_ERR_TRACE(WC_PENDING_E) &&
3620
                            reinvoke++ < WOLFSSL_ASYNC_MAX_REINVOKE) {
3621
                        ret = EncryptTls13(ssl, output, output, args->size,
3622
                                           aad, (word16)args->headerSz,
3623
                                           asyncOkay);
3624
                    }
3625
                    if (ret == WC_NO_ERR_TRACE(WC_PENDING_E)) {
3626
                        /* A device that never completes would otherwise spin
3627
                         * here forever, which is what wc_AsyncWait() used to
3628
                         * do. Report it instead. */
3629
                        WOLFSSL_MSG("Crypto callback still pending after "
3630
                                    "retry limit on a blocking record");
3631
                        ret = WC_HW_WAIT_E;
3632
                    }
3633
                }
3634
            #endif
3635
                if (ret != 0) {
3636
                #ifdef WOLFSSL_ASYNC_CRYPT
3637
                    if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
3638
                #endif
3639
                    {
3640
                        /* Zeroize plaintext. */
3641
                        ForceZero(output, args->size);
3642
                    }
3643
                }
3644
#ifdef WOLFSSL_DTLS13
3645
                if (ret == 0 && ssl->options.dtls) {
3646
                    /* AAD points to the header. Reuse the variable  */
3647
                    ret = Dtls13EncryptRecordNumber(ssl, (byte*)aad,
3648
                                                    (word16)args->sz);
3649
                }
3650
#endif /* WOLFSSL_DTLS13 */
3651
            }
3652
            break;
3653
        }
3654
3655
        default:
3656
            break;
3657
    }
3658
3659
exit_buildmsg:
3660
3661
    WOLFSSL_LEAVE("BuildTls13Message", ret);
3662
3663
#ifdef WOLFSSL_ASYNC_CRYPT
3664
    if (ret == WC_NO_ERR_TRACE(WC_PENDING_E)) {
3665
        return ret;
3666
    }
3667
#endif
3668
3669
    /* make sure build message state is reset */
3670
    ssl->options.buildMsgState = BUILD_MSG_BEGIN;
3671
3672
    /* return sz on success */
3673
    if (ret == 0) {
3674
        ret = (int)args->sz;
3675
    }
3676
    else {
3677
        WOLFSSL_ERROR_VERBOSE(ret);
3678
    }
3679
3680
    /* Final cleanup */
3681
#ifdef WOLFSSL_ASYNC_CRYPT
3682
    if (asyncOkay)
3683
        ssl->options.buildArgs13Set = 0;
3684
#endif
3685
3686
    return ret;
3687
}
3688
3689
#if !defined(NO_WOLFSSL_CLIENT) || (!defined(NO_WOLFSSL_SERVER) && \
3690
    (defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)) && \
3691
    (defined(WOLFSSL_PSK_ONE_ID) || defined(WOLFSSL_PRIORITIZE_PSK)))
3692
/* Find the cipher suite in the suites set in the SSL.
3693
 *
3694
 * ssl    SSL/TLS object.
3695
 * suite  Cipher suite to look for.
3696
 * returns 1 when suite is found in SSL/TLS object's list and 0 otherwise.
3697
 */
3698
int FindSuiteSSL(const WOLFSSL* ssl, byte* suite)
3699
220
{
3700
220
    word16 i;
3701
220
    const Suites* suites = WOLFSSL_SUITES(ssl);
3702
3703
408
    for (i = 0; i < suites->suiteSz; i += 2) {
3704
408
        if (suites->suites[i+0] == suite[0] &&
3705
388
                suites->suites[i+1] == suite[1]) {
3706
220
            return 1;
3707
220
        }
3708
408
    }
3709
3710
0
    return 0;
3711
220
}
3712
#endif
3713
3714
#ifndef NO_PSK
3715
/* Get the MAC algorithm for the TLS 1.3 cipher suite.
3716
 *
3717
 * @param [in] suite.
3718
 * @return  A value from wc_MACAlgorithm enumeration.
3719
 */
3720
byte SuiteMac(const byte* suite)
3721
{
3722
    byte mac = no_mac;
3723
3724
    if (suite[0] == TLS13_BYTE) {
3725
        switch (suite[1]) {
3726
        #ifdef BUILD_TLS_AES_128_GCM_SHA256
3727
            case TLS_AES_128_GCM_SHA256:
3728
                mac = sha256_mac;
3729
                break;
3730
        #endif
3731
        #ifdef BUILD_TLS_CHACHA20_POLY1305_SHA256
3732
            case TLS_CHACHA20_POLY1305_SHA256:
3733
                mac = sha256_mac;
3734
                break;
3735
        #endif
3736
        #ifdef BUILD_TLS_AES_128_CCM_SHA256
3737
            case TLS_AES_128_CCM_SHA256:
3738
                mac = sha256_mac;
3739
                break;
3740
        #endif
3741
        #ifdef BUILD_TLS_AES_128_CCM_8_SHA256
3742
            case TLS_AES_128_CCM_8_SHA256:
3743
                mac = sha256_mac;
3744
                break;
3745
        #endif
3746
        #ifdef BUILD_TLS_AES_256_GCM_SHA384
3747
            case TLS_AES_256_GCM_SHA384:
3748
                mac = sha384_mac;
3749
                break;
3750
        #endif
3751
            default:
3752
                break;
3753
        }
3754
    }
3755
#if (defined(WOLFSSL_SM4_GCM) || defined(WOLFSSL_SM4_CCM)) && \
3756
     defined(WOLFSSL_SM3)
3757
    else if (suite[0] == CIPHER_BYTE) {
3758
        switch (suite[1]) {
3759
        #ifdef BUILD_TLS_SM4_GCM_SM3
3760
            case TLS_SM4_GCM_SM3:
3761
                mac = sm3_mac;
3762
                break;
3763
        #endif
3764
        #ifdef BUILD_TLS_SM4_CCM_SM3
3765
            case TLS_SM4_CCM_SM3:
3766
                mac = sm3_mac;
3767
                break;
3768
        #endif
3769
            default:
3770
                break;
3771
        }
3772
    }
3773
#endif
3774
#ifdef HAVE_NULL_CIPHER
3775
    else if (suite[0] == ECC_BYTE) {
3776
        switch (suite[1]) {
3777
        #ifdef BUILD_TLS_SHA256_SHA256
3778
            case TLS_SHA256_SHA256:
3779
                mac = sha256_mac;
3780
                break;
3781
        #endif
3782
        #ifdef BUILD_TLS_SHA384_SHA384
3783
            case TLS_SHA384_SHA384:
3784
                mac = sha384_mac;
3785
                break;
3786
        #endif
3787
            default:
3788
                break;
3789
        }
3790
    }
3791
#endif
3792
3793
    return mac;
3794
}
3795
#endif
3796
3797
#if defined(WOLFSSL_SEND_HRR_COOKIE) && !defined(NO_WOLFSSL_SERVER)
3798
/* Create Cookie extension using the hash of the first ClientHello.
3799
 *
3800
 * ssl     SSL/TLS object.
3801
 * hash    The hash data.
3802
 * hashSz  The size of the hash data in bytes.
3803
 * returns 0 on success, otherwise failure.
3804
 */
3805
int CreateCookieExt(const WOLFSSL* ssl, byte* hash, word16 hashSz,
3806
                    TLSX** exts, byte cipherSuite0, byte cipherSuite)
3807
{
3808
    int  ret;
3809
    byte mac[WC_MAX_DIGEST_SIZE] = {0};
3810
    WC_DECLARE_VAR(cookieHmac, Hmac, 1, ssl->heap);
3811
    byte cookieType = 0;
3812
    byte macSz = 0;
3813
    byte cookie[OPAQUE8_LEN + WC_MAX_DIGEST_SIZE + OPAQUE16_LEN * 2];
3814
    TLSX* ext;
3815
    word16 cookieSz = 0;
3816
3817
    if (hash == NULL || hashSz == 0) {
3818
        return BAD_FUNC_ARG;
3819
    }
3820
3821
    if (ssl->buffers.tls13CookieSecret.buffer == NULL ||
3822
            ssl->buffers.tls13CookieSecret.length == 0) {
3823
        WOLFSSL_MSG("Missing DTLS 1.3 cookie secret");
3824
        return COOKIE_ERROR;
3825
    }
3826
3827
    /* Cookie Data = Hash Len | Hash | CS | KeyShare Group */
3828
    cookie[cookieSz++] = (byte)hashSz;
3829
    XMEMCPY(cookie + cookieSz, hash, hashSz);
3830
    cookieSz += hashSz;
3831
    cookie[cookieSz++] = cipherSuite0;
3832
    cookie[cookieSz++] = cipherSuite;
3833
    if ((ext = TLSX_Find(*exts, TLSX_KEY_SHARE)) != NULL) {
3834
        KeyShareEntry* kse = (KeyShareEntry*)ext->data;
3835
        if (kse == NULL) {
3836
            WOLFSSL_MSG("KeyShareEntry can't be empty when negotiating "
3837
                        "parameters");
3838
            return BAD_STATE_E;
3839
        }
3840
        c16toa(kse->group, cookie + cookieSz);
3841
        cookieSz += OPAQUE16_LEN;
3842
    }
3843
3844
#ifndef NO_SHA256
3845
    cookieType = WC_SHA256;
3846
    macSz = WC_SHA256_DIGEST_SIZE;
3847
#elif defined(WOLFSSL_SHA384)
3848
    cookieType = WC_SHA384;
3849
    macSz = WC_SHA384_DIGEST_SIZE;
3850
#elif defined(WOLFSSL_TLS13_SHA512)
3851
    cookieType = WC_SHA512;
3852
    macSz = WC_SHA512_DIGEST_SIZE;
3853
#elif defined(WOLFSSL_SM3)
3854
    cookieType = WC_SM3;
3855
    macSz = WC_SM3_DIGEST_SIZE;
3856
#else
3857
    #error "No digest to available to use with HMAC for cookies."
3858
#endif /* NO_SHA */
3859
3860
    WC_ALLOC_VAR_EX(cookieHmac, Hmac, 1, ssl->heap, DYNAMIC_TYPE_HMAC,
3861
                    return MEMORY_E);
3862
3863
    ret = wc_HmacInit(cookieHmac, ssl->heap, ssl->devId);
3864
    if (ret == 0) {
3865
        ret = wc_HmacSetKey(cookieHmac, cookieType,
3866
                            ssl->buffers.tls13CookieSecret.buffer,
3867
                            ssl->buffers.tls13CookieSecret.length);
3868
    }
3869
    if (ret == 0)
3870
        ret = wc_HmacUpdate(cookieHmac, cookie, cookieSz);
3871
#ifdef WOLFSSL_DTLS13
3872
    /* Tie cookie to peer address */
3873
    if (ret == 0) {
3874
        /* peerLock not necessary. Still in handshake phase. */
3875
        if (ssl->options.dtls && ssl->buffers.dtlsCtx.peer.sz > 0) {
3876
            ret = wc_HmacUpdate(cookieHmac,
3877
                (byte*)ssl->buffers.dtlsCtx.peer.sa,
3878
                ssl->buffers.dtlsCtx.peer.sz);
3879
        }
3880
    }
3881
#endif
3882
    if (ret == 0)
3883
        ret = wc_HmacFinal(cookieHmac, mac);
3884
3885
    wc_HmacFree(cookieHmac);
3886
    WC_FREE_VAR_EX(cookieHmac, ssl->heap, DYNAMIC_TYPE_HMAC);
3887
    if (ret != 0)
3888
        return ret;
3889
3890
    /* The cookie data is the hash and the integrity check. */
3891
    return TLSX_Cookie_Use(ssl, cookie, cookieSz, mac, macSz, 1, exts);
3892
}
3893
#endif
3894
3895
#ifdef WOLFSSL_DTLS13
3896
#define HRR_MAX_HS_HEADER_SZ DTLS_HANDSHAKE_HEADER_SZ
3897
#else
3898
#define HRR_MAX_HS_HEADER_SZ HANDSHAKE_HEADER_SZ
3899
#endif /* WOLFSSL_DTLS13 */
3900
3901
static int CreateCookie(const WOLFSSL* ssl, byte** hash, byte* hashSz,
3902
                            Hashes* hashes, TLSX** exts)
3903
{
3904
    int    ret = 0;
3905
3906
    (void)exts;
3907
3908
    *hash = NULL;
3909
    switch (ssl->specs.mac_algorithm) {
3910
    #ifndef NO_SHA256
3911
        case sha256_mac:
3912
            *hash = hashes->sha256;
3913
            break;
3914
    #endif
3915
    #ifdef WOLFSSL_SHA384
3916
        case sha384_mac:
3917
            *hash = hashes->sha384;
3918
            break;
3919
    #endif
3920
    #ifdef WOLFSSL_TLS13_SHA512
3921
        case sha512_mac:
3922
            *hash = hashes->sha512;
3923
            break;
3924
    #endif
3925
    #ifdef WOLFSSL_SM3
3926
        case sm3_mac:
3927
            *hash = hashes->sm3;
3928
            break;
3929
    #endif
3930
    }
3931
    *hashSz = ssl->specs.hash_size;
3932
3933
    /* check hash */
3934
    if (*hash == NULL && *hashSz > 0)
3935
        return BAD_FUNC_ARG;
3936
3937
#if defined(WOLFSSL_SEND_HRR_COOKIE) && !defined(NO_WOLFSSL_SERVER)
3938
    if (ssl->options.sendCookie && ssl->options.side == WOLFSSL_SERVER_END)
3939
        ret = CreateCookieExt(ssl, *hash, *hashSz, exts,
3940
                ssl->options.cipherSuite0, ssl->options.cipherSuite);
3941
#endif
3942
    return ret;
3943
}
3944
3945
/* Restart the handshake hash with a hash of the previous messages.
3946
 *
3947
 * ssl The SSL/TLS object.
3948
 * returns 0 on success, otherwise failure.
3949
 */
3950
int RestartHandshakeHash(WOLFSSL* ssl)
3951
0
{
3952
0
    int    ret;
3953
0
    byte   header[HANDSHAKE_HEADER_SZ] = {0};
3954
0
    Hashes hashes;
3955
0
    byte*  hash = NULL;
3956
0
    byte   hashSz = 0;
3957
3958
0
    ret = BuildCertHashes(ssl, &hashes);
3959
0
    if (ret != 0)
3960
0
        return ret;
3961
0
    ret = CreateCookie(ssl, &hash, &hashSz, &hashes, &ssl->extensions);
3962
0
    if (ret != 0)
3963
0
        return ret;
3964
#if defined(WOLFSSL_SEND_HRR_COOKIE) && !defined(NO_WOLFSSL_SERVER)
3965
    if (ssl->options.sendCookie && ssl->options.side == WOLFSSL_SERVER_END)
3966
        return 0;
3967
#endif
3968
3969
0
    AddTls13HandShakeHeader(header, hashSz, 0, 0, message_hash, ssl);
3970
3971
#ifdef WOLFSSL_DEBUG_TLS
3972
    WOLFSSL_MSG("Restart Hash");
3973
    WOLFSSL_BUFFER(hash, hashSz);
3974
#endif
3975
3976
0
    ret = InitHandshakeHashes(ssl);
3977
0
    if (ret != 0)
3978
0
        return ret;
3979
0
    ret = HashRaw(ssl, header, sizeof(header));
3980
0
    if (ret != 0)
3981
0
        return ret;
3982
0
    return HashRaw(ssl, hash, hashSz);
3983
0
}
3984
3985
#if !defined(NO_WOLFSSL_CLIENT) || !defined(NO_WOLFSSL_SERVER)
3986
/* The value in the random field of a ServerHello to indicate
3987
 * HelloRetryRequest.
3988
 */
3989
static byte helloRetryRequestRandom[] = {
3990
    0xCF, 0x21, 0xAD, 0x74, 0xE5, 0x9A, 0x61, 0x11,
3991
    0xBE, 0x1D, 0x8C, 0x02, 0x1E, 0x65, 0xB8, 0x91,
3992
    0xC2, 0xA2, 0x11, 0x16, 0x7A, 0xBB, 0x8C, 0x5E,
3993
    0x07, 0x9E, 0x09, 0xE2, 0xC8, 0xA8, 0x33, 0x9C
3994
};
3995
#endif
3996
3997
#ifdef HAVE_ECH
3998
/* returns the index of the first supported cipher suite, -1 if none */
3999
int EchConfigGetSupportedCipherSuite(WOLFSSL_EchConfig* config)
4000
{
4001
    int i = 0;
4002
4003
    if (!wc_HpkeKemIsSupported(config->kemId)) {
4004
        WOLFSSL_MSG("ECH config: KEM not supported");
4005
        return WOLFSSL_FATAL_ERROR;
4006
    }
4007
4008
    for (i = 0; i < config->numCipherSuites; i++) {
4009
        if (wc_HpkeKdfIsSupported(config->cipherSuites[i].kdfId) &&
4010
                wc_HpkeAeadIsSupported(config->cipherSuites[i].aeadId)) {
4011
            return i;
4012
        }
4013
    }
4014
4015
    WOLFSSL_MSG("ECH config: KDF or AEAD not supported");
4016
    return WOLFSSL_FATAL_ERROR;
4017
}
4018
4019
/* Hash the inner client hello, initializing the hsHashesEch field if needed.
4020
 * This should receive the client hello without outer_extensions 'encoding'
4021
 *
4022
 * ssl      SSL/TLS object.
4023
 * ech      ECH object.
4024
 * returns 0 on success and otherwise failure.
4025
 */
4026
static int EchHashHelloInner(WOLFSSL* ssl, WOLFSSL_ECH* ech)
4027
{
4028
    int ret = 0;
4029
    int headerSz;
4030
    word32 realSz;
4031
    HS_Hashes* tmpHashes;
4032
#ifndef NO_WOLFSSL_CLIENT
4033
    byte falseHeader[HRR_MAX_HS_HEADER_SZ];
4034
#endif
4035
4036
    if (ssl == NULL || ech == NULL) {
4037
        return BAD_FUNC_ARG;
4038
    }
4039
4040
#ifdef WOLFSSL_DTLS13
4041
    headerSz = ssl->options.dtls ? DTLS13_HANDSHAKE_HEADER_SZ :
4042
                                   HANDSHAKE_HEADER_SZ;
4043
#else
4044
    headerSz = HANDSHAKE_HEADER_SZ;
4045
#endif
4046
4047
    realSz = ech->innerClientHelloLen;
4048
4049
    tmpHashes = ssl->hsHashes;
4050
4051
    ssl->hsHashes = ssl->hsHashesEch;
4052
    if (ssl->hsHashes == NULL) {
4053
        ret = InitHandshakeHashes(ssl);
4054
        if (ret == 0) {
4055
            ssl->hsHashesEch = ssl->hsHashes;
4056
        }
4057
    }
4058
4059
    if (ret == 0) {
4060
#ifndef NO_WOLFSSL_CLIENT
4061
        if (ssl->options.side == WOLFSSL_CLIENT_END) {
4062
            /* client-side: innerClientHello contains body only */
4063
            AddTls13HandShakeHeader(falseHeader, realSz, 0, 0, client_hello,
4064
                                    ssl);
4065
            ret = HashRaw(ssl, falseHeader, headerSz);
4066
            if (ret == 0) {
4067
                ret = HashRaw(ssl, ech->innerClientHello, realSz);
4068
            }
4069
        }
4070
#endif
4071
#ifndef NO_WOLFSSL_SERVER
4072
        if (ssl->options.side == WOLFSSL_SERVER_END) {
4073
            /* server-side: innerClientHello contains header + body */
4074
            ret = HashRaw(ssl, ech->innerClientHello, headerSz + realSz);
4075
        }
4076
#endif
4077
    }
4078
4079
    ssl->hsHashes = tmpHashes;
4080
    return ret;
4081
}
4082
4083
/* Calculate the 8 ECH confirmation bytes.
4084
 *
4085
 * ssl            SSL/TLS object.
4086
 * label          Ascii string describing ECH acceptance or rejection.
4087
 * labelSz        Length of label excluding NULL character.
4088
 * input          The buffer to calculate confirmation off of.
4089
 * acceptOffset   Where the 8 ECH confirmation bytes start.
4090
 * helloSz        Size of hello message.
4091
 * isHrr          Whether message is a HelloRetryRequest or not.
4092
 * acceptExpanded An 8 byte array to store calculated confirmation to.
4093
 * returns 0 on success and otherwise failure.
4094
 */
4095
static int EchCalcAcceptance(WOLFSSL* ssl, byte* label, word16 labelSz,
4096
    const byte* input, int acceptOffset, int helloSz, byte isHrr,
4097
    byte* acceptExpanded)
4098
{
4099
    int ret = 0;
4100
    int digestType = 0;
4101
    int digestSize = 0;
4102
    int hashSz = 0;
4103
    int headerSz;
4104
    HS_Hashes* tmpHashes;
4105
    HS_Hashes* acceptHash = NULL;
4106
    byte zeros[WC_MAX_DIGEST_SIZE];
4107
    byte transcriptEchConf[WC_MAX_DIGEST_SIZE];
4108
    byte clientHelloInnerHash[WC_MAX_DIGEST_SIZE];
4109
    byte expandLabelPrk[WC_MAX_DIGEST_SIZE];
4110
    byte messageHashHeader[HRR_MAX_HS_HEADER_SZ];
4111
4112
    XMEMSET(zeros, 0, sizeof(zeros));
4113
    XMEMSET(transcriptEchConf, 0, sizeof(transcriptEchConf));
4114
    XMEMSET(clientHelloInnerHash, 0, sizeof(clientHelloInnerHash));
4115
    XMEMSET(expandLabelPrk, 0, sizeof(expandLabelPrk));
4116
4117
#ifdef WOLFSSL_CHECK_MEM_ZERO
4118
    wc_MemZero_Add("ECH PRK", expandLabelPrk, sizeof(expandLabelPrk));
4119
#endif
4120
4121
    tmpHashes = ssl->hsHashes;
4122
    ssl->hsHashes = ssl->hsHashesEch;
4123
4124
#ifdef WOLFSSL_DTLS13
4125
    headerSz = ssl->options.dtls ? DTLS13_HANDSHAKE_HEADER_SZ :
4126
                                   HANDSHAKE_HEADER_SZ;
4127
#else
4128
    headerSz = HANDSHAKE_HEADER_SZ;
4129
#endif
4130
4131
    if (isHrr) {
4132
        /* the transcript hash of ClientHelloInner1 */
4133
        ret = GetMsgHash(ssl, clientHelloInnerHash);
4134
        if (ret > 0) {
4135
            hashSz = ret;
4136
            ret = 0;
4137
        }
4138
        else if (ret == 0) {
4139
            ret = HASH_TYPE_E;
4140
        }
4141
4142
        /* restart ECH transcript hash, similar to RestartHandshakeHash but
4143
         * don't add a cookie */
4144
        if (ret == 0) {
4145
            ret = InitHandshakeHashes(ssl);
4146
            ssl->hsHashesEch = ssl->hsHashes;
4147
        }
4148
        if (ret == 0) {
4149
            AddTls13HandShakeHeader(messageHashHeader, (word32)hashSz, 0, 0,
4150
                message_hash, ssl);
4151
            ret = HashRaw(ssl, messageHashHeader, headerSz);
4152
        }
4153
        if (ret == 0) {
4154
            ret = HashRaw(ssl, clientHelloInnerHash, (word32)hashSz);
4155
        }
4156
    }
4157
4158
    /* hash with zeros for confirmation computation */
4159
    if (ret == 0) {
4160
        ret = InitHandshakeHashesAndCopy(ssl, ssl->hsHashesEch, &acceptHash);
4161
    }
4162
    if (ret == 0) {
4163
        ssl->hsHashes = acceptHash;
4164
        ret = HashRaw(ssl, input, acceptOffset);
4165
    }
4166
    if (ret == 0) {
4167
        ret = HashRaw(ssl, zeros, ECH_ACCEPT_CONFIRMATION_SZ);
4168
    }
4169
    if (ret == 0) {
4170
        ret = HashRaw(ssl, input + acceptOffset + ECH_ACCEPT_CONFIRMATION_SZ,
4171
            helloSz + headerSz - (acceptOffset + ECH_ACCEPT_CONFIRMATION_SZ));
4172
    }
4173
4174
    /* get the modified transcript hash */
4175
    if (ret == 0) {
4176
        ret = GetMsgHash(ssl, transcriptEchConf);
4177
        if (ret > 0) {
4178
            ret = 0;
4179
        }
4180
        else if (ret == 0) {
4181
            ret = HASH_TYPE_E;
4182
        }
4183
    }
4184
4185
    /* pick the right type and size based on mac_algorithm */
4186
    if (ret == 0) {
4187
        switch (ssl->specs.mac_algorithm) {
4188
#ifndef NO_SHA256
4189
            case sha256_mac:
4190
                digestType = WC_SHA256;
4191
                digestSize = WC_SHA256_DIGEST_SIZE;
4192
                break;
4193
#endif /* !NO_SHA256 */
4194
#ifdef WOLFSSL_SHA384
4195
            case sha384_mac:
4196
                digestType = WC_SHA384;
4197
                digestSize = WC_SHA384_DIGEST_SIZE;
4198
                break;
4199
#endif /* WOLFSSL_SHA384 */
4200
#ifdef WOLFSSL_TLS13_SHA512
4201
            case sha512_mac:
4202
                digestType = WC_SHA512;
4203
                digestSize = WC_SHA512_DIGEST_SIZE;
4204
                break;
4205
#endif /* WOLFSSL_TLS13_SHA512 */
4206
#ifdef WOLFSSL_SM3
4207
            case sm3_mac:
4208
                digestType = WC_SM3;
4209
                digestSize = WC_SM3_DIGEST_SIZE;
4210
                break;
4211
#endif /* WOLFSSL_SM3 */
4212
            default:
4213
                ret = WOLFSSL_FATAL_ERROR;
4214
                break;
4215
        }
4216
    }
4217
4218
    /* extract clientRandomInner with a key of all zeros */
4219
    if (ret == 0) {
4220
        PRIVATE_KEY_UNLOCK();
4221
    #if !defined(HAVE_FIPS) || \
4222
        (defined(FIPS_VERSION_GE) && FIPS_VERSION_GE(6,0))
4223
        ret = wc_HKDF_Extract_ex(digestType, zeros, (word32)digestSize,
4224
            ssl->arrays->clientRandomInner, RAN_LEN, expandLabelPrk,
4225
            ssl->heap, ssl->devId);
4226
    #else
4227
        ret = wc_HKDF_Extract(digestType, zeros, digestSize,
4228
            ssl->arrays->clientRandomInner, RAN_LEN, expandLabelPrk);
4229
    #endif
4230
        PRIVATE_KEY_LOCK();
4231
    }
4232
4233
    /* tls expand with the confirmation label */
4234
    if (ret == 0) {
4235
        PRIVATE_KEY_UNLOCK();
4236
#ifdef WOLFSSL_DTLS13
4237
        if (ssl->options.dtls) {
4238
            ret = Tls13HKDFExpandKeyLabel(ssl, acceptExpanded,
4239
                ECH_ACCEPT_CONFIRMATION_SZ, expandLabelPrk, (word32)digestSize,
4240
                dtls13ProtocolLabel, DTLS13_PROTOCOL_LABEL_SZ, label, labelSz,
4241
                transcriptEchConf, (word32)digestSize, digestType,
4242
                WOLFSSL_SERVER_END);
4243
        }
4244
        else
4245
#endif
4246
        {
4247
            ret = Tls13HKDFExpandKeyLabel(ssl, acceptExpanded,
4248
                ECH_ACCEPT_CONFIRMATION_SZ, expandLabelPrk, (word32)digestSize,
4249
                tls13ProtocolLabel, TLS13_PROTOCOL_LABEL_SZ, label, labelSz,
4250
                transcriptEchConf, (word32)digestSize, digestType,
4251
                WOLFSSL_SERVER_END);
4252
        }
4253
        PRIVATE_KEY_LOCK();
4254
    }
4255
4256
    if (acceptHash != NULL) {
4257
        ssl->hsHashes = acceptHash;
4258
        FreeHandshakeHashes(ssl);
4259
    }
4260
4261
    ssl->hsHashes = tmpHashes;
4262
    ForceZero(expandLabelPrk, sizeof(expandLabelPrk));
4263
#ifdef WOLFSSL_CHECK_MEM_ZERO
4264
    wc_MemZero_Check(expandLabelPrk, sizeof(expandLabelPrk));
4265
#endif
4266
    return ret;
4267
}
4268
#endif
4269
4270
#if !defined(NO_CERTS) && !defined(WOLFSSL_NO_SIGALG) && \
4271
    (!defined(NO_WOLFSSL_CLIENT) || !defined(NO_WOLFSSL_SERVER))
4272
/* Record whether the peer's advertised algorithms permit SHA-1 signed
4273
 * certificates.
4274
 *
4275
 * RFC 8446 Section 4.2.3 has signature_algorithms cover certificate signatures
4276
 * when signature_algorithms_cert is absent.
4277
 *
4278
 * ssl         The SSL/TLS object.
4279
 * peerSuites  The peer's signature_algorithms list.
4280
 */
4281
static void SetPeerSha1CertOk(WOLFSSL* ssl, const Suites* peerSuites)
4282
1.30k
{
4283
1.30k
    const byte* list = NULL;
4284
1.30k
    word16      listSz = 0;
4285
1.30k
    word16      i;
4286
4287
1.30k
    ssl->options.peerSha1CertOk = 0;
4288
4289
1.30k
    if (ssl->certHashSigAlgoSz > 0) {
4290
10
        list = ssl->certHashSigAlgo;
4291
10
        listSz = ssl->certHashSigAlgoSz;
4292
10
    }
4293
1.29k
    else if (peerSuites != NULL) {
4294
1.29k
        list = peerSuites->hashSigAlgo;
4295
1.29k
        listSz = peerSuites->hashSigAlgoSz;
4296
1.29k
    }
4297
0
    else {
4298
0
        return;
4299
0
    }
4300
4301
13.4k
    for (i = 0; i + 2 <= listSz; i += 2) {
4302
        /* Only rsa_pkcs1_sha1, dsa_sha1 and ecdsa_sha1 carry sha_mac as the
4303
         * first byte of the signature scheme. */
4304
13.1k
        if (list[i] == sha_mac) {
4305
1.00k
            ssl->options.peerSha1CertOk = 1;
4306
1.00k
            break;
4307
1.00k
        }
4308
13.1k
    }
4309
1.30k
}
4310
#endif /* !NO_CERTS && !WOLFSSL_NO_SIGALG && (client || server) */
4311
4312
#ifndef NO_WOLFSSL_CLIENT
4313
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
4314
#if defined(OPENSSL_EXTRA) && !defined(WOLFSSL_PSK_ONE_ID) && \
4315
    !defined(NO_PSK)
4316
/**
4317
* convert mac algorithm to WOLFSSL_EVP_MD
4318
* @param mac_alg mac algorithm
4319
* @return const WOLFSSL_EVP_MD on successful, otherwise NULL
4320
*/
4321
static const WOLFSSL_EVP_MD* ssl_handshake_md(const byte mac_alg)
4322
{
4323
    switch(mac_alg) {
4324
        case no_mac:
4325
            return NULL;
4326
    #ifndef NO_MD5
4327
        case md5_mac:
4328
            return wolfSSL_EVP_md5();
4329
    #endif
4330
    #ifndef NO_SHA
4331
        case sha_mac:
4332
            return wolfSSL_EVP_sha1();
4333
    #endif
4334
    #ifdef WOLFSSL_SHA224
4335
        case sha224_mac:
4336
            return wolfSSL_EVP_sha224();
4337
    #endif
4338
        case sha256_mac:
4339
            return wolfSSL_EVP_sha256();
4340
    #ifdef WOLFSSL_SHA384
4341
        case sha384_mac:
4342
            return wolfSSL_EVP_sha384();
4343
    #endif
4344
    #ifdef WOLFSSL_SHA512
4345
        case sha512_mac:
4346
            return wolfSSL_EVP_sha512();
4347
    #endif
4348
        case rmd_mac:
4349
        case blake2b_mac:
4350
            WOLFSSL_MSG("no suitable EVP_MD");
4351
            return NULL;
4352
        default:
4353
            WOLFSSL_MSG("Unknown mac algorithm");
4354
            return NULL;
4355
    }
4356
}
4357
#endif
4358
/* Setup pre-shared key based on the details in the extension data.
4359
 *
4360
 * ssl          SSL/TLS object.
4361
 * psk          Pre-shared key extension data.
4362
 * clientHello  Whether called from client_hello construction.
4363
 * returns 0 on success, PSK_KEY_ERROR when the client PSK callback fails and
4364
 * other negative value on failure.
4365
 */
4366
static int SetupPskKey(WOLFSSL* ssl, PreSharedKey* psk, int clientHello)
4367
0
{
4368
0
#if defined(HAVE_SESSION_TICKET) || !defined(WOLFSSL_PSK_ONE_ID)
4369
0
    int ret;
4370
0
#endif
4371
0
    byte suite[2];
4372
4373
0
    if (psk == NULL)
4374
0
        return BAD_FUNC_ARG;
4375
4376
0
    if (!HaveUniqueSessionObj(ssl)) {
4377
0
        WOLFSSL_MSG("Unable to have unique session object");
4378
0
        WOLFSSL_ERROR_VERBOSE(MEMORY_ERROR);
4379
0
        return MEMORY_ERROR;
4380
0
    }
4381
4382
0
    suite[0] = ssl->options.cipherSuite0;
4383
0
    suite[1] = ssl->options.cipherSuite;
4384
4385
0
#ifdef HAVE_SESSION_TICKET
4386
0
    if (psk->resumption) {
4387
0
        if (clientHello) {
4388
0
            suite[0] = psk->cipherSuite0;
4389
0
            suite[1] = psk->cipherSuite;
4390
4391
            /* Ensure cipher suite is supported or changed suite to one with
4392
             * the same MAC algorithm. */
4393
0
            if (!FindSuiteSSL(ssl, suite)) {
4394
0
                WOLFSSL_ERROR_VERBOSE(PSK_KEY_ERROR);
4395
0
                return PSK_KEY_ERROR;
4396
0
            }
4397
4398
0
            ssl->options.cipherSuite0 = suite[0];
4399
0
            ssl->options.cipherSuite = suite[1];
4400
4401
            /* Setting mac for binder and keys for deriving EarlyData. */
4402
0
            ret = SetCipherSpecs(ssl);
4403
0
            if (ret != 0)
4404
0
                return ret;
4405
0
        }
4406
4407
    #ifdef WOLFSSL_EARLY_DATA
4408
        if (ssl->session->maxEarlyDataSz == 0)
4409
            ssl->earlyData = no_early_data;
4410
    #endif
4411
        /* Resumption PSK is master secret. */
4412
0
        ssl->arrays->psk_keySz = ssl->specs.hash_size;
4413
0
        if ((ret = DeriveResumptionPSK(ssl, ssl->session->ticketNonce.data,
4414
0
                   ssl->session->ticketNonce.len, ssl->arrays->psk_key)) != 0) {
4415
0
            return ret;
4416
0
        }
4417
0
        if (!clientHello) {
4418
            /* CLIENT: using secret in ticket for peer authentication. */
4419
0
            ssl->options.peerAuthGood = 1;
4420
0
        }
4421
0
    }
4422
0
#endif
4423
#ifndef NO_PSK
4424
    if (!psk->resumption) {
4425
        /* Get the pre-shared key. */
4426
#ifndef WOLFSSL_PSK_ONE_ID
4427
        const char* cipherName = NULL;
4428
    #ifdef OPENSSL_EXTRA
4429
        WOLFSSL_SESSION* psksession = NULL;
4430
    #endif
4431
4432
        /* Set the client identity to use. */
4433
        if (psk->identityLen > MAX_PSK_ID_LEN)
4434
            return PSK_KEY_ERROR;
4435
        XMEMSET(ssl->arrays->client_identity, 0,
4436
            sizeof(ssl->arrays->client_identity));
4437
        XMEMCPY(ssl->arrays->client_identity, psk->identity, psk->identityLen);
4438
4439
    #ifdef WOLFSSL_DEBUG_TLS
4440
        WOLFSSL_MSG("PSK cipher suite:");
4441
        WOLFSSL_MSG(GetCipherNameInternal(psk->cipherSuite0, psk->cipherSuite));
4442
    #endif
4443
4444
        /* Get the pre-shared key. */
4445
    #ifdef OPENSSL_EXTRA
4446
        if (ssl->options.session_psk_cb != NULL) {
4447
            const unsigned char* id = NULL;
4448
            size_t idlen = 0;
4449
            const WOLFSSL_EVP_MD* handshake_md = NULL;
4450
4451
            if (ssl->msgsReceived.got_hello_retry_request >= 1) {
4452
                handshake_md = ssl_handshake_md(ssl->specs.mac_algorithm);
4453
            }
4454
            /* OpenSSL compatible callback that gets cached session. */
4455
            if (ssl->options.session_psk_cb(ssl, handshake_md, &id, &idlen,
4456
                                                            &psksession) == 0) {
4457
                wolfSSL_FreeSession(ssl->ctx, psksession);
4458
                WOLFSSL_MSG("psk session callback failed");
4459
                return PSK_KEY_ERROR;
4460
            }
4461
            if (psksession != NULL) {
4462
                if (idlen > MAX_PSK_KEY_LEN) {
4463
                    wolfSSL_FreeSession(ssl->ctx, psksession);
4464
                    WOLFSSL_MSG("psk key length is too long");
4465
                    WOLFSSL_ERROR_VERBOSE(PSK_KEY_ERROR);
4466
                    return PSK_KEY_ERROR;
4467
                }
4468
4469
                ssl->arrays->psk_keySz = (word32)idlen;
4470
                XMEMCPY(ssl->arrays->psk_key, id, idlen);
4471
                suite[0] = psksession->cipherSuite0;
4472
                suite[1] = psksession->cipherSuite;
4473
                /* Not needed anymore. */
4474
                wolfSSL_FreeSession(ssl->ctx, psksession);
4475
                /* Leave pointer not NULL to indicate success with callback. */
4476
            }
4477
        }
4478
        if (psksession != NULL) {
4479
            /* Don't try other callbacks - we have an answer. */
4480
        }
4481
        else
4482
    #endif /* OPENSSL_EXTRA */
4483
        if (ssl->options.client_psk_cs_cb != NULL) {
4484
        #ifdef WOLFSSL_PSK_MULTI_ID_PER_CS
4485
            ssl->arrays->client_identity[0] = 0;
4486
        #endif
4487
            /* Lookup key again for next identity. */
4488
            ssl->arrays->psk_keySz = ssl->options.client_psk_cs_cb(
4489
                ssl, ssl->arrays->server_hint,
4490
                ssl->arrays->client_identity, MAX_PSK_ID_LEN,
4491
                ssl->arrays->psk_key, MAX_PSK_KEY_LEN,
4492
                GetCipherNameInternal(psk->cipherSuite0, psk->cipherSuite));
4493
            if (clientHello) {
4494
                /* Use PSK cipher suite. */
4495
                ssl->options.cipherSuite0 = psk->cipherSuite0;
4496
                ssl->options.cipherSuite  = psk->cipherSuite;
4497
            }
4498
            else {
4499
                byte pskCS[2];
4500
                pskCS[0] = psk->cipherSuite0;
4501
                pskCS[1] = psk->cipherSuite;
4502
4503
                /* Ensure PSK and negotiated cipher suites have same hash. */
4504
                if (SuiteMac(pskCS) != SuiteMac(suite)) {
4505
                    WOLFSSL_ERROR_VERBOSE(PSK_KEY_ERROR);
4506
                    return PSK_KEY_ERROR;
4507
                }
4508
                /* Negotiated cipher suite is to be used - update PSK. */
4509
                psk->cipherSuite0 = suite[0];
4510
                psk->cipherSuite  = suite[1];
4511
            }
4512
        }
4513
        else if (ssl->options.client_psk_tls13_cb != NULL) {
4514
            byte cipherSuite0;
4515
            byte cipherSuite;
4516
            int cipherSuiteFlags = WOLFSSL_CIPHER_SUITE_FLAG_NONE;
4517
4518
            ssl->arrays->psk_keySz = ssl->options.client_psk_tls13_cb(ssl,
4519
                    ssl->arrays->server_hint, ssl->arrays->client_identity,
4520
                    MAX_PSK_ID_LEN, ssl->arrays->psk_key, MAX_PSK_KEY_LEN,
4521
                    &cipherName);
4522
            if (GetCipherSuiteFromName(cipherName, &cipherSuite0,
4523
                            &cipherSuite, NULL, NULL, &cipherSuiteFlags) != 0) {
4524
                WOLFSSL_ERROR_VERBOSE(PSK_KEY_ERROR);
4525
                return PSK_KEY_ERROR;
4526
            }
4527
            ssl->options.cipherSuite0 = cipherSuite0;
4528
            ssl->options.cipherSuite  = cipherSuite;
4529
            (void)cipherSuiteFlags;
4530
        }
4531
        else {
4532
            ssl->arrays->psk_keySz = ssl->options.client_psk_cb(ssl,
4533
                    ssl->arrays->server_hint, ssl->arrays->client_identity,
4534
                    MAX_PSK_ID_LEN, ssl->arrays->psk_key, MAX_PSK_KEY_LEN);
4535
            ssl->options.cipherSuite0 = TLS13_BYTE;
4536
            ssl->options.cipherSuite  = WOLFSSL_DEF_PSK_CIPHER;
4537
        }
4538
        if (ssl->arrays->psk_keySz == 0 ||
4539
                (ssl->arrays->psk_keySz > MAX_PSK_KEY_LEN &&
4540
            (int)ssl->arrays->psk_keySz != WC_NO_ERR_TRACE(USE_HW_PSK))) {
4541
            WOLFSSL_ERROR_VERBOSE(PSK_KEY_ERROR);
4542
            return PSK_KEY_ERROR;
4543
        }
4544
4545
        ret = SetCipherSpecs(ssl);
4546
        if (ret != 0)
4547
            return ret;
4548
#else
4549
        /* PSK information loaded during setting of default TLS extensions. */
4550
#endif /* !WOLFSSL_PSK_ONE_ID */
4551
4552
        if (!clientHello && (psk->cipherSuite0 != suite[0] ||
4553
                             psk->cipherSuite  != suite[1])) {
4554
            WOLFSSL_ERROR_VERBOSE(PSK_KEY_ERROR);
4555
            return PSK_KEY_ERROR;
4556
        }
4557
4558
        if (!clientHello) {
4559
#ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
4560
            if (ssl->options.certWithExternPsk) {
4561
                /* Certificate authentication is still required. */
4562
                ssl->options.peerAuthGood = 0;
4563
            }
4564
            else
4565
#endif
4566
            {
4567
                /* CLIENT: using PSK for peer authentication. */
4568
                ssl->options.peerAuthGood = 1;
4569
            }
4570
        }
4571
    }
4572
#endif
4573
4574
0
#ifdef HAVE_SUPPORTED_CURVES
4575
0
    if (!clientHello) {
4576
0
        TLSX* ext;
4577
0
        word32 modes;
4578
0
        KeyShareEntry* kse = NULL;
4579
4580
        /* Get the PSK key exchange modes the client wants to negotiate. */
4581
0
        ext = TLSX_Find(ssl->extensions, TLSX_PSK_KEY_EXCHANGE_MODES);
4582
0
        if (ext == NULL) {
4583
0
            WOLFSSL_ERROR_VERBOSE(PSK_KEY_ERROR);
4584
0
            return PSK_KEY_ERROR;
4585
0
        }
4586
0
        modes = ext->val;
4587
4588
0
        ext = TLSX_Find(ssl->extensions, TLSX_KEY_SHARE);
4589
0
        if (ext != NULL) {
4590
0
            kse = (KeyShareEntry*)ext->data;
4591
0
        }
4592
        /* Use (EC)DHE for forward-security if possible. */
4593
0
        if (((modes & (1 << PSK_DHE_KE)) != 0) && (!ssl->options.noPskDheKe) &&
4594
0
                                                (kse != NULL) && kse->derived) {
4595
0
            if ((kse->session != 0) && (kse->session != kse->group)) {
4596
0
                WOLFSSL_ERROR_VERBOSE(PSK_KEY_ERROR);
4597
0
                return PSK_KEY_ERROR;
4598
0
            }
4599
0
        }
4600
0
        else if (ssl->options.onlyPskDheKe ||
4601
0
                 (ssl->options.failNoPSK && !psk->resumption)) {
4602
            /* A mandatory external PSK (failNoPSK) must be combined with
4603
             * (EC)DHE for forward secrecy, so reject a pure psk_ke
4604
             * negotiation. Session-ticket resumption is exempt. */
4605
0
            WOLFSSL_ERROR_VERBOSE(PSK_KEY_ERROR);
4606
0
            return PSK_KEY_ERROR;
4607
0
        }
4608
0
        else if (ssl->options.noPskDheKe) {
4609
0
            ssl->arrays->preMasterSz = 0;
4610
0
        }
4611
0
    }
4612
0
    else
4613
0
#endif
4614
0
    if (ssl->options.noPskDheKe) {
4615
0
        ssl->arrays->preMasterSz = 0;
4616
0
    }
4617
4618
    /* Derive the early secret using the PSK. */
4619
0
    return DeriveEarlySecret(ssl);
4620
0
}
4621
4622
/* Derive and write the binders into the ClientHello in space left when
4623
 * writing the Pre-Shared Key extension.
4624
 *
4625
 * ssl     The SSL/TLS object.
4626
 * output  The buffer containing the ClientHello.
4627
 * idx     The index at the end of the completed ClientHello.
4628
 * returns 0 on success and otherwise failure.
4629
 */
4630
static int WritePSKBinders(WOLFSSL* ssl, byte* output, word32 idx)
4631
{
4632
    int           ret;
4633
    TLSX*         ext;
4634
    PreSharedKey* current;
4635
    byte          binderKey[WC_MAX_DIGEST_SIZE];
4636
    word16        len;
4637
4638
    WOLFSSL_ENTER("WritePSKBinders");
4639
4640
    if (idx > WOLFSSL_MAX_16BIT) {
4641
        return INPUT_SIZE_E;
4642
    }
4643
4644
    ext = TLSX_Find(ssl->extensions, TLSX_PRE_SHARED_KEY);
4645
    if (ext == NULL)
4646
        return SANITY_MSG_E;
4647
4648
    /* Get the size of the binders to determine where to write binders. */
4649
    ret = TLSX_PreSharedKey_GetSizeBinders((PreSharedKey*)ext->data,
4650
                                                            client_hello, &len);
4651
    if (ret < 0)
4652
        return ret;
4653
    idx -= len;
4654
4655
    /* Hash truncated ClientHello - up to binders. */
4656
#ifdef WOLFSSL_DTLS13
4657
    if (ssl->options.dtls)
4658
        ret = Dtls13HashHandshake(ssl, output + Dtls13GetRlHeaderLength(ssl, 0),
4659
                                 (word16)idx - Dtls13GetRlHeaderLength(ssl, 0));
4660
    else
4661
#endif /* WOLFSSL_DTLS13 */
4662
        ret = HashOutput(ssl, output, (int)idx, 0);
4663
4664
    if (ret != 0)
4665
        return ret;
4666
4667
    current = (PreSharedKey*)ext->data;
4668
#ifdef WOLFSSL_CHECK_MEM_ZERO
4669
    if (current != NULL) {
4670
        wc_MemZero_Add("WritePSKBinders binderKey", binderKey,
4671
            sizeof(binderKey));
4672
    }
4673
#endif
4674
    /* Calculate the binder for each identity based on previous handshake data.
4675
     */
4676
    while (current != NULL) {
4677
        if ((ret = SetupPskKey(ssl, current, 1)) != 0)
4678
            break;
4679
4680
    #ifdef HAVE_SESSION_TICKET
4681
        if (current->resumption)
4682
            ret = DeriveBinderKeyResume(ssl, binderKey);
4683
    #endif
4684
    #ifndef NO_PSK
4685
        if (!current->resumption)
4686
            ret = DeriveBinderKey(ssl, binderKey);
4687
    #endif
4688
        if (ret != 0)
4689
            break;
4690
4691
        /* Derive the Finished message secret. */
4692
        ret = DeriveFinishedSecret(ssl, binderKey,
4693
                                   ssl->keys.client_write_MAC_secret,
4694
                                   0 /* neither end */);
4695
        if (ret != 0)
4696
            break;
4697
4698
        /* Build the HMAC of the handshake message data = binder. */
4699
        ret = BuildTls13HandshakeHmac(ssl, ssl->keys.client_write_MAC_secret,
4700
            current->binder, &current->binderLen);
4701
        if (ret != 0)
4702
            break;
4703
4704
        current = current->next;
4705
    }
4706
4707
    ForceZero(binderKey, sizeof(binderKey));
4708
#ifdef WOLFSSL_CHECK_MEM_ZERO
4709
    wc_MemZero_Check(binderKey, sizeof(binderKey));
4710
#endif
4711
    if (ret != 0)
4712
        return ret;
4713
4714
    /* Data entered into extension, now write to message. */
4715
    ret = TLSX_PreSharedKey_WriteBinders((PreSharedKey*)ext->data, output + idx,
4716
                                                            client_hello, &len);
4717
    if (ret < 0)
4718
        return ret;
4719
4720
    /* Hash binders to complete the hash of the ClientHello. */
4721
    ret = HashRaw(ssl, output + idx, len);
4722
    if (ret < 0)
4723
        return ret;
4724
4725
    #ifdef WOLFSSL_EARLY_DATA
4726
    if (ssl->earlyData != no_early_data) {
4727
        if ((ret = SetupPskKey(ssl, (PreSharedKey*)ext->data, 1)) != 0)
4728
            return ret;
4729
4730
        /* Derive early data encryption key. */
4731
        ret = DeriveTls13Keys(ssl, early_data_key, ENCRYPT_SIDE_ONLY, 1);
4732
        if (ret != 0)
4733
            return ret;
4734
        if ((ret = SetKeysSide(ssl, ENCRYPT_SIDE_ONLY)) != 0)
4735
            return ret;
4736
4737
    }
4738
    #endif
4739
4740
    WOLFSSL_LEAVE("WritePSKBinders", ret);
4741
4742
    return ret;
4743
}
4744
#endif
4745
4746
static void GetTls13SessionId(WOLFSSL* ssl, byte* output, word32* idx)
4747
8.62k
{
4748
8.62k
    if (ssl->session->sessionIDSz > 0) {
4749
        /* Session resumption for old versions of protocol. */
4750
0
        if (ssl->session->sessionIDSz <= ID_LEN) {
4751
0
            if (output != NULL)
4752
0
                output[*idx] = ssl->session->sessionIDSz;
4753
0
            (*idx)++;
4754
0
            if (output != NULL) {
4755
0
                XMEMCPY(output + *idx, ssl->session->sessionID,
4756
0
                    ssl->session->sessionIDSz);
4757
0
            }
4758
0
            *idx += ssl->session->sessionIDSz;
4759
0
        }
4760
0
        else {
4761
            /* Invalid session ID length. Reset it. */
4762
0
            ssl->session->sessionIDSz = 0;
4763
0
            if (output != NULL)
4764
0
                output[*idx] = 0;
4765
0
            (*idx)++;
4766
0
        }
4767
0
    }
4768
8.62k
    else {
4769
    #ifdef WOLFSSL_TLS13_MIDDLEBOX_COMPAT
4770
        if (ssl->options.tls13MiddleBoxCompat) {
4771
            if (output != NULL)
4772
                output[*idx] = ID_LEN;
4773
            (*idx)++;
4774
            if (output != NULL)
4775
                XMEMCPY(output + *idx, ssl->arrays->clientRandom, ID_LEN);
4776
            *idx += ID_LEN;
4777
        }
4778
        else
4779
    #endif /* WOLFSSL_TLS13_MIDDLEBOX_COMPAT */
4780
8.62k
        {
4781
            /* TLS v1.3 does not use session id - 0 length. */
4782
8.62k
            if (output != NULL)
4783
4.27k
                output[*idx] = 0;
4784
8.62k
            (*idx)++;
4785
8.62k
        }
4786
8.62k
    }
4787
8.62k
}
4788
4789
/* handle generation of TLS 1.3 client_hello (1) */
4790
/* Send a ClientHello message to the server.
4791
 * Include the information required to start a handshake with servers using
4792
 * protocol versions less than TLS v1.3.
4793
 * Only a client will send this message.
4794
 *
4795
 * ssl  The SSL/TLS object.
4796
 * returns 0 on success and otherwise failure.
4797
 */
4798
4799
typedef struct Sch13Args {
4800
    byte*  output;
4801
    word32 idx;
4802
    int    sendSz;
4803
    word32 length;
4804
#if defined(HAVE_ECH)
4805
    int clientRandomOffset;
4806
    word32 preXLength;
4807
    word32 expandedInnerLen;
4808
    WOLFSSL_ECH* ech;
4809
#endif
4810
} Sch13Args;
4811
4812
#ifdef WOLFSSL_EARLY_DATA
4813
/* Check if early data can potentially be sent.
4814
 * Returns 1 if early data is possible, 0 otherwise.
4815
 */
4816
static int EarlyDataPossible(WOLFSSL* ssl)
4817
{
4818
    /* Need session resumption OR PSK callback configured */
4819
    if (ssl->options.resuming) {
4820
        return 1;
4821
    }
4822
#ifndef NO_PSK
4823
    if (ssl->options.client_psk_tls13_cb != NULL ||
4824
        ssl->options.client_psk_cb != NULL) {
4825
        return 1;
4826
    }
4827
#endif
4828
    return 0;
4829
}
4830
#endif /* WOLFSSL_EARLY_DATA */
4831
4832
int SendTls13ClientHello(WOLFSSL* ssl)
4833
0
{
4834
0
    int ret;
4835
#ifdef WOLFSSL_ASYNC_CRYPT
4836
    Sch13Args* args = NULL;
4837
    WOLFSSL_ASSERT_SIZEOF_GE(ssl->async->args, *args);
4838
#else
4839
0
    Sch13Args  args[1];
4840
0
#endif
4841
0
    byte major, tls12minor;
4842
0
    const Suites* suites;
4843
4844
0
    WOLFSSL_START(WC_FUNC_CLIENT_HELLO_SEND);
4845
0
    WOLFSSL_ENTER("SendTls13ClientHello");
4846
4847
0
    if (ssl == NULL) {
4848
0
        return BAD_FUNC_ARG;
4849
0
    }
4850
4851
0
#if defined(HAVE_SECURE_RENEGOTIATION) || defined(HAVE_SERVER_RENEGOTIATION_INFO)
4852
    /* Re-establish renegotiation_info advertising for a reused object
4853
     * (wolfSSL_clear frees it) so a TLS 1.2 downgrade still enforces what the
4854
     * ClientHello advertised. Only when absent, to keep any existing state. */
4855
0
    if (ssl->secure_renegotiation == NULL) {
4856
0
        ret = SetupClientSecureRenegotiation(ssl);
4857
0
        if (ret != WOLFSSL_SUCCESS)
4858
0
            return ret;
4859
0
    }
4860
0
#endif
4861
4862
0
    ssl->options.buildingMsg = 1;
4863
0
    major = SSLv3_MAJOR;
4864
0
    tls12minor = TLSv1_2_MINOR;
4865
4866
#ifdef WOLFSSL_DTLS13
4867
    if (ssl->options.dtls) {
4868
        major = DTLS_MAJOR;
4869
        tls12minor = DTLSv1_2_MINOR;
4870
    }
4871
#endif /* WOLFSSL_DTLS */
4872
4873
0
    if (ssl->options.resuming &&
4874
0
            ssl->session->version.major != 0 &&
4875
0
            (ssl->session->version.major != ssl->version.major ||
4876
0
             ssl->session->version.minor != ssl->version.minor)) {
4877
0
    #ifndef WOLFSSL_NO_TLS12
4878
0
        if (ssl->session->version.major == ssl->version.major &&
4879
0
            ssl->session->version.minor < ssl->version.minor) {
4880
            /* Cannot resume with a different protocol version. */
4881
0
            ssl->options.resuming = 0;
4882
0
            ssl->version.major = ssl->session->version.major;
4883
0
            ssl->version.minor = ssl->session->version.minor;
4884
0
            return SendClientHello(ssl);
4885
0
        }
4886
0
        else
4887
0
    #endif
4888
0
        {
4889
0
            WOLFSSL_ERROR_VERBOSE(VERSION_ERROR);
4890
0
            return VERSION_ERROR;
4891
0
        }
4892
0
    }
4893
4894
0
    suites = WOLFSSL_SUITES(ssl);
4895
0
    if (suites == NULL) {
4896
0
        WOLFSSL_MSG("Bad suites pointer in SendTls13ClientHello");
4897
0
        return SUITES_ERROR;
4898
0
    }
4899
4900
#ifdef WOLFSSL_ASYNC_CRYPT
4901
    if (ssl->async == NULL) {
4902
        ssl->async = (struct WOLFSSL_ASYNC*)
4903
                XMALLOC(sizeof(struct WOLFSSL_ASYNC), ssl->heap,
4904
                        DYNAMIC_TYPE_ASYNC);
4905
        if (ssl->async == NULL)
4906
            return MEMORY_E;
4907
        ssl->async->freeArgs = NULL;
4908
    }
4909
    args = (Sch13Args*)ssl->async->args;
4910
4911
    ret = wolfSSL_AsyncPop(ssl, &ssl->options.asyncState);
4912
    if (ret != WC_NO_ERR_TRACE(WC_NO_PENDING_E)) {
4913
        /* Check for error */
4914
        if (ret < 0)
4915
            return ret;
4916
    }
4917
    else
4918
#endif
4919
0
    {
4920
        /* Reset state */
4921
0
        ssl->options.asyncState = TLS_ASYNC_BEGIN;
4922
0
        XMEMSET(args, 0, sizeof(Sch13Args));
4923
0
    }
4924
4925
0
    switch (ssl->options.asyncState) {
4926
0
    case TLS_ASYNC_BEGIN:
4927
0
    {
4928
0
    word32 sessIdSz = 0;
4929
4930
0
    args->idx = RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ;
4931
4932
#ifdef WOLFSSL_DTLS13
4933
    if (ssl->options.dtls)
4934
        args->idx += DTLS_RECORD_EXTRA + DTLS_HANDSHAKE_EXTRA;
4935
#endif /* WOLFSSL_DTLS13 */
4936
4937
    /* Version | Random | Cipher Suites | Compression */
4938
0
    args->length = VERSION_SZ + RAN_LEN + suites->suiteSz +
4939
0
            SUITE_LEN + COMP_LEN + ENUM_LEN;
4940
#ifdef WOLFSSL_QUIC
4941
    if (WOLFSSL_IS_QUIC(ssl)) {
4942
        /* RFC 9001 ch. 8.4 sessionID in ClientHello MUST be 0 length */
4943
        ssl->session->sessionIDSz = 0;
4944
        ssl->options.tls13MiddleBoxCompat = 0;
4945
    }
4946
#endif
4947
#ifdef WOLFSSL_DTLS13
4948
    if (ssl->options.dtls) {
4949
        /* RFC 9147 Section 5: DTLS implementations do not use the
4950
         *                     TLS 1.3 "compatibility mode" */
4951
        ssl->options.tls13MiddleBoxCompat = 0;
4952
    }
4953
#endif
4954
0
    GetTls13SessionId(ssl, NULL, &sessIdSz);
4955
0
    args->length += (word16)sessIdSz;
4956
4957
#ifdef WOLFSSL_DTLS13
4958
    if (ssl->options.dtls) {
4959
        /* legacy_cookie_id len */
4960
        args->length += ENUM_LEN;
4961
4962
        /* server sent us an HelloVerifyRequest and we allow downgrade  */
4963
        if (ssl->arrays->cookieSz > 0 && ssl->options.downgrade)
4964
            args->length += ssl->arrays->cookieSz;
4965
    }
4966
#endif /* WOLFSSL_DTLS13 */
4967
4968
    /* Advance state and proceed */
4969
0
    ssl->options.asyncState = TLS_ASYNC_BUILD;
4970
0
    } /* case TLS_ASYNC_BEGIN */
4971
0
    FALL_THROUGH;
4972
4973
0
    case TLS_ASYNC_BUILD:
4974
0
    case TLS_ASYNC_DO:
4975
0
    {
4976
    /* Auto populate extensions supported unless user defined. */
4977
0
    if ((ret = TLSX_PopulateExtensions(ssl, 0)) != 0)
4978
0
        return ret;
4979
4980
    /* Advance state and proceed */
4981
0
    ssl->options.asyncState = TLS_ASYNC_FINALIZE;
4982
0
    } /* case TLS_ASYNC_BUILD */
4983
0
    FALL_THROUGH;
4984
4985
0
    case TLS_ASYNC_FINALIZE:
4986
0
    {
4987
#ifdef WOLFSSL_EARLY_DATA
4988
    if (!EarlyDataPossible(ssl))
4989
        ssl->earlyData = no_early_data;
4990
    if (ssl->options.serverState == SERVER_HELLO_RETRY_REQUEST_COMPLETE)
4991
        ssl->earlyData = no_early_data;
4992
    if (ssl->earlyData == no_early_data)
4993
        TLSX_Remove(&ssl->extensions, TLSX_EARLY_DATA, ssl->heap);
4994
    if (ssl->earlyData != no_early_data &&
4995
        (ret = TLSX_EarlyData_Use(ssl, 0, 0)) < 0) {
4996
        return ret;
4997
    }
4998
#endif
4999
#ifdef WOLFSSL_QUIC
5000
    if (WOLFSSL_IS_QUIC(ssl) && IsAtLeastTLSv1_3(ssl->version)) {
5001
        ret = wolfSSL_quic_add_transport_extensions(ssl, client_hello);
5002
        if (ret != 0)
5003
            return ret;
5004
    }
5005
#endif
5006
5007
    /* find length of outer and inner */
5008
#if defined(HAVE_ECH)
5009
    if (!ssl->options.disableECH) {
5010
        TLSX* echX = TLSX_Find(ssl->extensions, TLSX_ECH);
5011
        void* hostName = NULL;
5012
        word16 nameLen;
5013
        if (echX == NULL)
5014
            return WOLFSSL_FATAL_ERROR;
5015
5016
        args->ech = (WOLFSSL_ECH*)echX->data;
5017
        if (args->ech == NULL)
5018
            return WOLFSSL_FATAL_ERROR;
5019
5020
        /* if ECH was rejected by the HRR then the server MUST stop
5021
         * decrypting ECH, so send a GREASE ECH for the follow-up CH */
5022
        if (ssl->echConfigs != NULL && !ssl->options.echAccepted &&
5023
                ssl->options.serverState ==
5024
                    SERVER_HELLO_RETRY_REQUEST_COMPLETE) {
5025
            args->ech->state = ECH_WRITE_GREASE;
5026
        }
5027
5028
        /* only prepare if we have a chance at acceptance (real ECH only) */
5029
        if (ssl->echConfigs != NULL &&
5030
                (ssl->options.echAccepted || args->ech->innerCount == 0)) {
5031
            word32 encodedLen;
5032
            byte downgrade;
5033
5034
            /* ensure that a version less than TLS1.3 is never offered  */
5035
            downgrade = ssl->options.downgrade;
5036
            ssl->options.downgrade = 0;
5037
5038
            /* set the type to inner */
5039
            args->ech->type = ECH_TYPE_INNER;
5040
            args->preXLength = args->length;
5041
5042
            /* get expanded inner size (used for transcript) */
5043
            ret = TLSX_GetRequestSize(ssl, client_hello, &args->length);
5044
            if (ret != 0) {
5045
                args->ech->type = ECH_TYPE_OUTER;
5046
                ssl->options.downgrade = downgrade;
5047
                return ret;
5048
            }
5049
5050
            /* args->expandedInnerLen carries the length for the hash */
5051
            args->expandedInnerLen = args->length;
5052
            if (args->expandedInnerLen > 0xFFFF) {
5053
                args->ech->type = ECH_TYPE_OUTER;
5054
                ssl->options.downgrade = downgrade;
5055
                return BUFFER_E;
5056
            }
5057
5058
            /* get encoded inner size */
5059
            args->ech->writeEncoded = 1;
5060
            encodedLen = args->preXLength;
5061
            ret = TLSX_GetRequestSize(ssl, client_hello, &encodedLen);
5062
            args->ech->writeEncoded = 0;
5063
            /* set the type to outer */
5064
            args->ech->type = ECH_TYPE_OUTER;
5065
            ssl->options.downgrade = downgrade;
5066
            if (ret != 0)
5067
                return ret;
5068
5069
            /* calculate padding (RFC 9849, section 6.1.3) */
5070
            nameLen = TLSX_SNI_GetRequest(ssl->extensions,
5071
                WOLFSSL_SNI_HOST_NAME, &hostName, 1);
5072
            if (nameLen == 0 && ssl->ctx != NULL)
5073
                nameLen = TLSX_SNI_GetRequest(ssl->ctx->extensions,
5074
                    WOLFSSL_SNI_HOST_NAME, &hostName, 1);
5075
5076
            if (nameLen != 0) {
5077
                if (nameLen > args->ech->echConfig->maxNameLen)
5078
                    args->ech->paddingLen = 0;
5079
                else
5080
                    args->ech->paddingLen =
5081
                        (word16)args->ech->echConfig->maxNameLen - nameLen;
5082
            }
5083
            else {
5084
                /* maxNameLen + length of the SNI extension */
5085
                args->ech->paddingLen = args->ech->echConfig->maxNameLen + 9;
5086
            }
5087
5088
            /* innerClientHelloLen and padding are based on the
5089
             * encoded (sealed) inner */
5090
            args->ech->paddingLen +=
5091
                ECH_PADDING_TO_32(encodedLen + args->ech->paddingLen);
5092
            args->ech->innerClientHelloLen = encodedLen +
5093
                args->ech->paddingLen + args->ech->hpke->Nt;
5094
5095
            if (args->ech->innerClientHelloLen > 0xFFFF)
5096
                return BUFFER_E;
5097
5098
            /* restore the length to pre-ClientHelloInner computations */
5099
            args->length = args->preXLength;
5100
        }
5101
    }
5102
#endif
5103
5104
0
    {
5105
#ifdef WOLFSSL_DTLS_CH_FRAG
5106
        word16 maxFrag = wolfssl_local_GetMaxPlaintextSize(ssl);
5107
        word16 lenWithoutExts = args->length;
5108
#endif
5109
5110
        /* Include length of TLS extensions. */
5111
0
        ret = TLSX_GetRequestSize(ssl, client_hello, &args->length);
5112
0
        if (ret != 0)
5113
0
            return ret;
5114
5115
        /* Total message size. */
5116
0
        args->sendSz =
5117
0
                (int)(args->length + HANDSHAKE_HEADER_SZ + RECORD_HEADER_SZ);
5118
5119
#ifdef WOLFSSL_DTLS13
5120
        if (ssl->options.dtls)
5121
            args->sendSz += DTLS_RECORD_EXTRA + DTLS_HANDSHAKE_EXTRA;
5122
#endif /* WOLFSSL_DTLS13 */
5123
5124
#ifdef WOLFSSL_DTLS_CH_FRAG
5125
        /* Only empty the key share on the first CH; this avoids first CH
5126
         * fragmentation (wolfSSL refuses them) */
5127
        if (ssl->options.dtls && args->sendSz > maxFrag &&
5128
                ssl->options.serverState !=
5129
                    SERVER_HELLO_RETRY_REQUEST_COMPLETE) {
5130
            /* Try again with an empty key share if we would be fragmenting */
5131
            ret = TLSX_KeyShare_Empty(ssl);
5132
            if (ret != 0)
5133
                return ret;
5134
            args->length = lenWithoutExts;
5135
            ret = TLSX_GetRequestSize(ssl, client_hello, &args->length);
5136
            if (ret != 0)
5137
                return ret;
5138
            args->sendSz = (int)(args->length +
5139
                    DTLS_HANDSHAKE_HEADER_SZ + DTLS_RECORD_HEADER_SZ);
5140
            if (args->sendSz > maxFrag) {
5141
                WOLFSSL_MSG("Can't fit first CH in one fragment.");
5142
                return BUFFER_ERROR;
5143
            }
5144
            WOLFSSL_MSG("Sending empty key share so we don't fragment CH1");
5145
        }
5146
#endif
5147
0
    }
5148
5149
    /* Check buffers are big enough and grow if needed. */
5150
0
    if ((ret = CheckAvailableSize(ssl, args->sendSz)) != 0)
5151
0
        return ret;
5152
5153
    /* Get position in output buffer to write new message to. */
5154
0
    args->output = GetOutputBuffer(ssl);
5155
5156
    /* Put the record and handshake headers on. */
5157
0
    AddTls13Headers(args->output, args->length, client_hello, ssl);
5158
5159
    /* Protocol version - negotiation now in extension: supported_versions. */
5160
0
    args->output[args->idx++] = major;
5161
0
    args->output[args->idx++] = tls12minor;
5162
5163
    /* Keep for downgrade. */
5164
0
    ssl->chVersion = ssl->version;
5165
5166
0
    if (ssl->arrays == NULL) {
5167
0
        return BAD_FUNC_ARG;
5168
0
    }
5169
    /* Client Random */
5170
0
    if (ssl->options.connectState == CONNECT_BEGIN) {
5171
0
        ret = wc_RNG_GenerateBlock(ssl->rng, args->output + args->idx, RAN_LEN);
5172
0
        if (ret != 0)
5173
0
            return ret;
5174
5175
        /* Store random for possible second ClientHello. */
5176
0
        XMEMCPY(ssl->arrays->clientRandom, args->output + args->idx, RAN_LEN);
5177
0
    }
5178
0
    else
5179
0
        XMEMCPY(args->output + args->idx, ssl->arrays->clientRandom, RAN_LEN);
5180
5181
#if defined(HAVE_ECH)
5182
    args->clientRandomOffset = (int)args->idx;
5183
#endif
5184
5185
0
    args->idx += RAN_LEN;
5186
5187
0
    GetTls13SessionId(ssl, args->output, &args->idx);
5188
5189
#ifdef WOLFSSL_DTLS13
5190
    if (ssl->options.dtls) {
5191
        args->output[args->idx++] = ssl->arrays->cookieSz;
5192
5193
        if (ssl->arrays->cookieSz > 0) {
5194
            /* We have a cookie saved, so the server sent us an
5195
             * HelloVerifyRequest, it means it is a v1.2 server */
5196
            if (!ssl->options.downgrade)
5197
                return VERSION_ERROR;
5198
            XMEMCPY(args->output + args->idx, ssl->arrays->cookie,
5199
                ssl->arrays->cookieSz);
5200
            args->idx += ssl->arrays->cookieSz;
5201
        }
5202
    }
5203
#endif /* WOLFSSL_DTLS13 */
5204
5205
    /* Cipher suites */
5206
0
    c16toa(suites->suiteSz, args->output + args->idx);
5207
0
    args->idx += OPAQUE16_LEN;
5208
0
    XMEMCPY(args->output + args->idx, &suites->suites,
5209
0
        suites->suiteSz);
5210
0
    args->idx += suites->suiteSz;
5211
#ifdef WOLFSSL_DEBUG_TLS
5212
    {
5213
        int ii;
5214
        WOLFSSL_MSG("Ciphers:");
5215
        for (ii = 0 ; ii < suites->suiteSz; ii += 2) {
5216
            WOLFSSL_MSG(GetCipherNameInternal(suites->suites[ii+0],
5217
                                              suites->suites[ii+1]));
5218
        }
5219
    }
5220
#endif
5221
5222
    /* Compression not supported in TLS v1.3. */
5223
0
    args->output[args->idx++] = COMP_LEN;
5224
0
    args->output[args->idx++] = NO_COMPRESSION;
5225
5226
#if defined(HAVE_ECH)
5227
    /* Build the expanded inner ClientHello */
5228
    if (ssl->echConfigs != NULL && !ssl->options.disableECH &&
5229
            (ssl->options.echAccepted || args->ech->innerCount == 0)) {
5230
        byte downgrade;
5231
5232
        /* calculate maximum buffer size needed */
5233
        word32 encodedBodyLen = args->ech->innerClientHelloLen -
5234
            args->ech->hpke->Nt;
5235
        word32 innerBufSize = args->expandedInnerLen;
5236
        if (encodedBodyLen > innerBufSize)
5237
            innerBufSize = encodedBodyLen;
5238
5239
        /* set the type to inner */
5240
        args->ech->type = ECH_TYPE_INNER;
5241
        /* innerClientHello may already exist from hrr, free if it does */
5242
        if (args->ech->innerClientHello != NULL) {
5243
            XFREE(args->ech->innerClientHello, ssl->heap,
5244
                DYNAMIC_TYPE_TMP_BUFFER);
5245
        }
5246
        /* allocate the inner */
5247
        args->ech->innerClientHello =
5248
            (byte*)XMALLOC(innerBufSize, ssl->heap, DYNAMIC_TYPE_TMP_BUFFER);
5249
        if (args->ech->innerClientHello == NULL) {
5250
            args->ech->type = ECH_TYPE_OUTER;
5251
            return MEMORY_E;
5252
        }
5253
        /* copy everything before extensions into the innerClientHello
5254
         * ignore record and handshake headers */
5255
        XMEMCPY(args->ech->innerClientHello,
5256
            args->output + RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ,
5257
            args->preXLength);
5258
        /* copy the client random to inner - only for first CH, not after HRR */
5259
        if (!ssl->options.echAccepted) {
5260
            XMEMCPY(ssl->arrays->clientRandomInner, ssl->arrays->clientRandom,
5261
                RAN_LEN);
5262
        }
5263
        else {
5264
            /* After HRR, use the same inner random as CH1 */
5265
            XMEMCPY(args->ech->innerClientHello + VERSION_SZ,
5266
                ssl->arrays->clientRandomInner, RAN_LEN);
5267
        }
5268
        /* change the outer client random */
5269
        ret = wc_RNG_GenerateBlock(ssl->rng, args->output +
5270
            args->clientRandomOffset, RAN_LEN);
5271
        if (ret != 0) {
5272
            args->ech->type = ECH_TYPE_OUTER;
5273
            return ret;
5274
        }
5275
        /* copy the new client random */
5276
        XMEMCPY(ssl->arrays->clientRandom, args->output +
5277
            args->clientRandomOffset, RAN_LEN);
5278
5279
        /* ensure that a version less than TLS1.3 is never offered  */
5280
        downgrade = ssl->options.downgrade;
5281
        ssl->options.downgrade = 0;
5282
5283
        /* write the expanded extensions into the inner buffer */
5284
        args->length = 0;
5285
        ret = TLSX_WriteRequest(ssl,
5286
            args->ech->innerClientHello + args->preXLength, client_hello,
5287
            &args->length);
5288
        if (ret != 0) {
5289
            args->ech->type = ECH_TYPE_OUTER;
5290
            ssl->options.downgrade = downgrade;
5291
            return ret;
5292
        }
5293
5294
        /* hash expanded form */
5295
        args->ech->innerClientHelloLen = args->expandedInnerLen;
5296
        ret = EchHashHelloInner(ssl, args->ech);
5297
        args->ech->innerClientHelloLen = encodedBodyLen + args->ech->hpke->Nt;
5298
        if (ret != 0) {
5299
            args->ech->type = ECH_TYPE_OUTER;
5300
            ssl->options.downgrade = downgrade;
5301
            return ret;
5302
        }
5303
5304
        /* zero padding bytes sealed with the inner hello */
5305
        XMEMSET(args->ech->innerClientHello +
5306
            args->ech->innerClientHelloLen - args->ech->hpke->Nt -
5307
            args->ech->paddingLen, 0, args->ech->paddingLen);
5308
        /* Rewrite inner buffer with the encoded form for sealing */
5309
        args->ech->writeEncoded = 1;
5310
        args->length = 0;
5311
        ret = TLSX_WriteRequest(ssl,
5312
            args->ech->innerClientHello + args->preXLength, client_hello,
5313
            &args->length);
5314
        args->ech->writeEncoded = 0;
5315
        /* set the type to outer */
5316
        args->ech->type = ECH_TYPE_OUTER;
5317
        ssl->options.downgrade = downgrade;
5318
        if (ret != 0)
5319
            return ret;
5320
    }
5321
#endif
5322
5323
    /* Write out extensions for a request. */
5324
0
    args->length = 0;
5325
0
    ret = TLSX_WriteRequest(ssl, args->output + args->idx, client_hello,
5326
0
        &args->length);
5327
0
    if (ret != 0)
5328
0
        return ret;
5329
5330
0
    args->idx += args->length;
5331
5332
#if defined(HAVE_ECH)
5333
    /* HPKE-seal inner hello and place into outer ECH extension's payload */
5334
    if (ssl->echConfigs != NULL && !ssl->options.disableECH &&
5335
            (ssl->options.echAccepted || args->ech->innerCount == 0)) {
5336
#if defined(WOLFSSL_TEST_ECH)
5337
        if (ssl->echInnerHelloCb != NULL) {
5338
            ret = ssl->echInnerHelloCb(args->ech->innerClientHello,
5339
                args->ech->innerClientHelloLen - args->ech->hpke->Nt);
5340
            if (ret != 0)
5341
                return ret;
5342
        }
5343
#endif
5344
        ret = TLSX_FinalizeEch(ssl, args->ech,
5345
            args->output + RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ,
5346
            (word32)(args->sendSz - (RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ)));
5347
5348
        if (ret != 0)
5349
            return ret;
5350
    }
5351
    /* Mark CH1 done for any ECH extension (real or GREASE) */
5352
    if (args->ech != NULL)
5353
        args->ech->innerCount = 1;
5354
#endif
5355
5356
0
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
5357
    /* Resumption has a specific set of extensions and binder is calculated
5358
     * for each identity.
5359
     */
5360
0
    if (TLSX_Find(ssl->extensions, TLSX_PRE_SHARED_KEY)) {
5361
0
        ret = WritePSKBinders(ssl, args->output, args->idx);
5362
0
    }
5363
0
    else
5364
0
#endif
5365
0
    {
5366
#ifdef WOLFSSL_DTLS13
5367
        if (ssl->options.dtls)
5368
            ret = Dtls13HashHandshake(ssl,
5369
                args->output + Dtls13GetRlHeaderLength(ssl, 0),
5370
                (word16)args->idx - Dtls13GetRlHeaderLength(ssl, 0));
5371
        else
5372
#endif /* WOLFSSL_DTLS13 */
5373
0
        {
5374
            /* compute the outer hash */
5375
0
            ret = HashOutput(ssl, args->output, (int)args->idx, 0);
5376
0
        }
5377
0
    }
5378
0
    if (ret != 0)
5379
0
        return ret;
5380
5381
0
    ssl->options.clientState = CLIENT_HELLO_COMPLETE;
5382
5383
0
#if defined(WOLFSSL_CALLBACKS) || defined(OPENSSL_EXTRA)
5384
0
    if (ssl->hsInfoOn) AddPacketName(ssl, "ClientHello");
5385
0
    if (ssl->toInfoOn) {
5386
0
        ret = AddPacketInfo(ssl, "ClientHello", handshake, args->output,
5387
0
                      args->sendSz, WRITE_PROTO, 0, ssl->heap);
5388
0
        if (ret != 0)
5389
0
            return ret;
5390
0
    }
5391
0
#endif
5392
5393
0
    ssl->options.buildingMsg = 0;
5394
#ifdef WOLFSSL_DTLS13
5395
    if (ssl->options.dtls) {
5396
        ret = Dtls13HandshakeSend(ssl, args->output, (word16)args->sendSz,
5397
                                  (word16)args->idx, client_hello, 0);
5398
        break;
5399
    }
5400
#endif /* WOLFSSL_DTLS13 */
5401
5402
0
    ssl->buffers.outputBuffer.length += (word32)args->sendSz;
5403
5404
    /* Advance state and proceed */
5405
0
    ssl->options.asyncState = TLS_ASYNC_END;
5406
0
    }
5407
    /* case TLS_ASYNC_BUILD */
5408
0
    FALL_THROUGH;
5409
5410
0
    case TLS_ASYNC_END:
5411
0
    {
5412
#ifdef WOLFSSL_EARLY_DATA_GROUP
5413
    /* QUIC needs to forward records at their encryption level
5414
     * and is therefore unable to group here */
5415
    if (ssl->earlyData == no_early_data || WOLFSSL_IS_QUIC(ssl))
5416
#endif
5417
0
        ret = SendBuffered(ssl);
5418
5419
0
    break;
5420
0
    }
5421
0
    default:
5422
0
        ret = INPUT_CASE_ERROR;
5423
0
    } /* switch (ssl->options.asyncState) */
5424
5425
#ifdef WOLFSSL_ASYNC_CRYPT
5426
    if (ret == 0)
5427
        FreeAsyncCtx(ssl, 0);
5428
#endif
5429
5430
0
    WOLFSSL_LEAVE("SendTls13ClientHello", ret);
5431
0
    WOLFSSL_END(WC_FUNC_CLIENT_HELLO_SEND);
5432
5433
0
    return ret;
5434
0
}
5435
5436
#if defined(WOLFSSL_DTLS13) && !defined(NO_WOLFSSL_CLIENT)
5437
static int Dtls13ClientDoDowngrade(WOLFSSL* ssl)
5438
{
5439
    int ret;
5440
    if (ssl->dtls13ClientHello == NULL)
5441
        return BAD_STATE_E;
5442
5443
    /* v1.3 and v1.2 hash messages to compute the transcript hash. When we are
5444
     * using DTLSv1.3 we hash the first clientHello following v1.3 but the
5445
     * server can negotiate a lower version. So we need to re-hash the
5446
     * clientHello to adhere to DTLS <= v1.2 rules. */
5447
    ret = InitHandshakeHashes(ssl);
5448
    if (ret != 0)
5449
        return ret;
5450
    ret = HashRaw(ssl, ssl->dtls13ClientHello, ssl->dtls13ClientHelloSz);
5451
    XFREE(ssl->dtls13ClientHello, ssl->heap, DYNAMIC_TYPE_DTLS_MSG);
5452
    ssl->dtls13ClientHello = NULL;
5453
    ssl->dtls13ClientHelloSz = 0;
5454
    ssl->keys.dtls_sequence_number_hi =
5455
        (word16)w64GetHigh32(ssl->dtls13EncryptEpoch->nextSeqNumber);
5456
    ssl->keys.dtls_sequence_number_lo =
5457
        w64GetLow32(ssl->dtls13EncryptEpoch->nextSeqNumber);
5458
    return ret;
5459
}
5460
#endif /* WOLFSSL_DTLS13 && !NO_WOLFSSL_CLIENT*/
5461
5462
#if defined(HAVE_ECH)
5463
/* Calculate ECH acceptance and verify the server accepted ECH.
5464
 *
5465
 * ssl          SSL/TLS object.
5466
 * label        Ascii string describing ECH acceptance type.
5467
 * labelSz      Length of label excluding NULL character.
5468
 * input        The buffer to calculate confirmation off of.
5469
 * acceptOffset Where the 8 ECH confirmation bytes start.
5470
 * helloSz      Size of hello message.
5471
 * returns 0 on success and otherwise failure.
5472
 */
5473
static int EchCheckAcceptance(WOLFSSL* ssl, byte* label, word16 labelSz,
5474
    const byte* input, int acceptOffset, int helloSz, byte msgType)
5475
{
5476
    int ret = 0;
5477
    int headerSz;
5478
    HS_Hashes* tmpHashes;
5479
    byte acceptConfirmation[ECH_ACCEPT_CONFIRMATION_SZ];
5480
5481
    XMEMSET(acceptConfirmation, 0, sizeof(acceptConfirmation));
5482
5483
#ifdef WOLFSSL_DTLS13
5484
    headerSz = ssl->options.dtls ? DTLS13_HANDSHAKE_HEADER_SZ :
5485
                                   HANDSHAKE_HEADER_SZ;
5486
#else
5487
    headerSz = HANDSHAKE_HEADER_SZ;
5488
#endif
5489
5490
    ret = EchCalcAcceptance(ssl, label, labelSz, input, acceptOffset, helloSz,
5491
            msgType == hello_retry_request, acceptConfirmation);
5492
5493
    if (ret == 0) {
5494
        tmpHashes = ssl->hsHashes;
5495
        ssl->hsHashes = ssl->hsHashesEch;
5496
5497
        /* last 8 bytes must match the expand output */
5498
        ret = ConstantCompare(acceptConfirmation, input + acceptOffset,
5499
            ECH_ACCEPT_CONFIRMATION_SZ);
5500
5501
        if (ret == 0) {
5502
            WOLFSSL_MSG("ECH accepted");
5503
            ssl->options.echAccepted = 1;
5504
5505
            /* after HRR, hsHashesEch must contain:
5506
             * message_hash(ClientHelloInner1) || HRR (actual, not zeros) */
5507
            if (msgType == hello_retry_request) {
5508
                ret = HashRaw(ssl, input, helloSz + headerSz);
5509
            }
5510
            /* normal TLS code will calculate transcript of ServerHello */
5511
            else {
5512
                ssl->hsHashes = tmpHashes;
5513
                FreeHandshakeHashes(ssl);
5514
                tmpHashes = ssl->hsHashesEch;
5515
                ssl->hsHashesEch = NULL;
5516
            }
5517
        }
5518
        else {
5519
            if (msgType != hello_retry_request && ssl->options.echAccepted) {
5520
                /* the SH has rejected ECH after the HRR has accepted it
5521
                 * RFC 9849, section 6.1.5 */
5522
                WOLFSSL_MSG("ECH rejected, but it was previously accepted...");
5523
                ret = INVALID_PARAMETER;
5524
            }
5525
            else {
5526
                WOLFSSL_MSG("ECH rejected");
5527
                ret = 0;
5528
            }
5529
            ssl->options.echAccepted = 0;
5530
5531
            /* ECH rejected, continue with outer transcript */
5532
            FreeHandshakeHashes(ssl);
5533
            ssl->hsHashesEch = NULL;
5534
        }
5535
5536
        ssl->hsHashes = tmpHashes;
5537
    }
5538
5539
    /* Skip only when the HRR signals ECH acceptance
5540
     * -> CH2 still needs ech->extensions for inner/outer extension swap
5541
     *    during write */
5542
    if (ret == 0 &&
5543
            (msgType != hello_retry_request || !ssl->options.echAccepted))
5544
        ret = TLSX_EchReplaceExtensions(ssl, ssl->options.echAccepted);
5545
5546
    return ret;
5547
}
5548
#endif /* HAVE_ECH */
5549
5550
/* handle processing of TLS 1.3 server_hello (2) and hello_retry_request (6) */
5551
/* Handle the ServerHello message from the server.
5552
 * Only a client will receive this message.
5553
 *
5554
 * ssl       The SSL/TLS object.
5555
 * input     The message buffer.
5556
 * inOutIdx  On entry, the index into the message buffer of ServerHello.
5557
 *           On exit, the index of byte after the ServerHello message.
5558
 * helloSz   The length of the current handshake message.
5559
 * returns 0 on success and otherwise failure.
5560
 */
5561
5562
typedef struct Dsh13Args {
5563
    ProtocolVersion pv;
5564
    word32          idx;
5565
    word32          begin;
5566
    const byte*     sessId;
5567
    word16          totalExtSz;
5568
    byte            sessIdSz;
5569
    byte            extMsgType;
5570
#if defined(HAVE_ECH)
5571
    TLSX* echX;
5572
    byte* acceptLabel;
5573
    word32 acceptOffset;
5574
    word16 acceptLabelSz;
5575
#endif
5576
} Dsh13Args;
5577
5578
/* sessIdSz below bounds both the copy into arrays->sessionID and the comparison
5579
 * against arrays->clientRandom, so one check only covers both while these
5580
 * match. */
5581
wc_static_assert(ID_LEN == RAN_LEN);
5582
5583
int DoTls13ServerHello(WOLFSSL* ssl, const byte* input, word32* inOutIdx,
5584
                       word32 helloSz, byte* extMsgType)
5585
0
{
5586
0
    int ret;
5587
0
    byte suite[2];
5588
0
    byte tls12minor;
5589
#ifdef WOLFSSL_ASYNC_CRYPT
5590
    Dsh13Args* args = NULL;
5591
#else
5592
0
    Dsh13Args  args[1];
5593
0
#endif
5594
#ifdef WOLFSSL_ASYNC_CRYPT
5595
    WOLFSSL_ASSERT_SIZEOF_GE(ssl->async->args, *args);
5596
#endif
5597
5598
0
    WOLFSSL_START(WC_FUNC_SERVER_HELLO_DO);
5599
0
    WOLFSSL_ENTER("DoTls13ServerHello");
5600
5601
0
    if (ssl == NULL || ssl->arrays == NULL)
5602
0
        return BAD_FUNC_ARG;
5603
5604
0
    tls12minor = TLSv1_2_MINOR;
5605
5606
#ifdef WOLFSSL_DTLS13
5607
    if (ssl->options.dtls)
5608
        tls12minor = DTLSv1_2_MINOR;
5609
#endif /*  WOLFSSL_DTLS13 */
5610
5611
#ifdef WOLFSSL_ASYNC_CRYPT
5612
    if (ssl->async == NULL) {
5613
        ssl->async = (struct WOLFSSL_ASYNC*)
5614
                XMALLOC(sizeof(struct WOLFSSL_ASYNC), ssl->heap,
5615
                        DYNAMIC_TYPE_ASYNC);
5616
        if (ssl->async == NULL)
5617
            return MEMORY_E;
5618
        ssl->async->freeArgs = NULL;
5619
    }
5620
    args = (Dsh13Args*)ssl->async->args;
5621
5622
    ret = wolfSSL_AsyncPop(ssl, &ssl->options.asyncState);
5623
    if (ret != WC_NO_ERR_TRACE(WC_NO_PENDING_E)) {
5624
        /* Check for error */
5625
        if (ret < 0) {
5626
            if (ret == WC_NO_ERR_TRACE(WC_PENDING_E)) {
5627
                /* Mark message as not received so it can process again */
5628
                ssl->msgsReceived.got_server_hello = 0;
5629
            }
5630
            return ret;
5631
        }
5632
    }
5633
    else
5634
#endif
5635
0
    {
5636
        /* Reset state */
5637
0
        ssl->options.asyncState = TLS_ASYNC_BEGIN;
5638
0
        XMEMSET(args, 0, sizeof(Dsh13Args));
5639
0
    }
5640
5641
0
    switch (ssl->options.asyncState) {
5642
0
    case TLS_ASYNC_BEGIN:
5643
0
    {
5644
0
    byte b;
5645
#if defined(WOLFSSL_DTLS13) && defined(WOLFSSL_DTLS_CID)
5646
    ssl->options.haveSupportedVersions = 0;
5647
#endif
5648
#ifdef WOLFSSL_CALLBACKS
5649
    if (ssl->hsInfoOn) AddPacketName(ssl, "ServerHello");
5650
    if (ssl->toInfoOn) AddLateName("ServerHello", &ssl->timeoutInfo);
5651
#endif
5652
5653
    /* Protocol version length check. */
5654
0
    if (helloSz < OPAQUE16_LEN)
5655
0
        return BUFFER_ERROR;
5656
5657
0
    args->idx = *inOutIdx;
5658
0
    args->begin = args->idx;
5659
5660
    /* Protocol version */
5661
0
    XMEMCPY(&args->pv, input + args->idx, OPAQUE16_LEN);
5662
0
    args->idx += OPAQUE16_LEN;
5663
5664
#ifdef WOLFSSL_DTLS
5665
    if (ssl->options.dtls &&
5666
        (args->pv.major != DTLS_MAJOR || args->pv.minor == DTLS_BOGUS_MINOR))
5667
        return VERSION_ERROR;
5668
#endif /* WOLFSSL_DTLS */
5669
5670
0
#ifndef WOLFSSL_NO_TLS12
5671
0
    {
5672
0
        byte wantDowngrade;
5673
5674
0
        wantDowngrade = args->pv.major == ssl->version.major &&
5675
0
            args->pv.minor < TLSv1_2_MINOR;
5676
5677
#ifdef WOLFSSL_DTLS13
5678
        if (ssl->options.dtls)
5679
            wantDowngrade = args->pv.major == ssl->version.major &&
5680
                args->pv.minor > DTLSv1_2_MINOR;
5681
#endif /* WOLFSSL_DTLS13 */
5682
5683
0
        if (wantDowngrade && ssl->options.downgrade) {
5684
            /* Force client hello version 1.2 to work for static RSA. */
5685
0
            ssl->chVersion.minor = TLSv1_2_MINOR;
5686
0
            ssl->version.minor = TLSv1_2_MINOR;
5687
0
            ssl->options.tls1_3 = 0;
5688
5689
#ifdef WOLFSSL_DTLS13
5690
            if (ssl->options.dtls) {
5691
                ssl->chVersion.minor = DTLSv1_2_MINOR;
5692
                ssl->version.minor = DTLSv1_2_MINOR;
5693
                ret = Dtls13ClientDoDowngrade(ssl);
5694
                if (ret != 0)
5695
                    return ret;
5696
            }
5697
#endif /* WOLFSSL_DTLS13 */
5698
5699
0
            return DoServerHello(ssl, input, inOutIdx, helloSz);
5700
0
        }
5701
0
    }
5702
0
#endif
5703
5704
0
    if (args->pv.major != ssl->version.major ||
5705
0
        args->pv.minor != tls12minor) {
5706
0
        WOLFSSL_ERROR_VERBOSE(VERSION_ERROR);
5707
0
        return VERSION_ERROR;
5708
0
    }
5709
5710
    /* Random and session id length check */
5711
0
    if ((args->idx - args->begin) + RAN_LEN + ENUM_LEN > helloSz)
5712
0
        return BUFFER_ERROR;
5713
5714
    /* Check if hello retry request */
5715
0
    if (XMEMCMP(input + args->idx, helloRetryRequestRandom, RAN_LEN) == 0) {
5716
0
        WOLFSSL_MSG("HelloRetryRequest format");
5717
0
        *extMsgType = hello_retry_request;
5718
5719
0
        if (ssl->msgsReceived.got_hello_verify_request) {
5720
0
            WOLFSSL_MSG("Received HelloRetryRequest after a "
5721
0
                        "HelloVerifyRequest");
5722
0
            WOLFSSL_ERROR_VERBOSE(VERSION_ERROR);
5723
0
            return VERSION_ERROR;
5724
0
        }
5725
5726
        /* A HelloRetryRequest comes in as an ServerHello for MiddleBox compat.
5727
         * Found message to be a HelloRetryRequest.
5728
         * Don't allow more than one HelloRetryRequest or ServerHello.
5729
         */
5730
0
        if (ssl->msgsReceived.got_hello_retry_request) {
5731
0
            WOLFSSL_ERROR_VERBOSE(DUPLICATE_MSG_E);
5732
0
            return DUPLICATE_MSG_E;
5733
0
        }
5734
0
    }
5735
0
    args->extMsgType = *extMsgType;
5736
5737
    /* Server random - keep for debugging. */
5738
0
    XMEMCPY(ssl->arrays->serverRandom, input + args->idx, RAN_LEN);
5739
#if defined(HAVE_ECH)
5740
    /* last 8 bytes of server random */
5741
    args->acceptOffset = args->idx + RAN_LEN - ECH_ACCEPT_CONFIRMATION_SZ;
5742
#endif
5743
0
    args->idx += RAN_LEN;
5744
5745
    /* Session id */
5746
0
    args->sessIdSz = input[args->idx++];
5747
0
    if (args->sessIdSz > ID_LEN ||
5748
0
        ((args->idx - args->begin) + args->sessIdSz > helloSz))
5749
0
        return BUFFER_ERROR;
5750
0
    args->sessId = input + args->idx;
5751
0
    args->idx += args->sessIdSz;
5752
5753
0
    ssl->options.haveSessionId = 1;
5754
5755
    /* Ciphersuite and compression check */
5756
0
    if ((args->idx - args->begin) + OPAQUE16_LEN + OPAQUE8_LEN > helloSz)
5757
0
        return BUFFER_ERROR;
5758
5759
    /* Set the cipher suite from the message. */
5760
0
    ssl->options.cipherSuite0 = input[args->idx++];
5761
0
    ssl->options.cipherSuite  = input[args->idx++];
5762
0
    if (*extMsgType == hello_retry_request) {
5763
0
        ssl->options.hrrCipherSuite0 = ssl->options.cipherSuite0;
5764
0
        ssl->options.hrrCipherSuite  = ssl->options.cipherSuite;
5765
0
    }
5766
0
    else if (ssl->msgsReceived.got_hello_retry_request &&
5767
0
             (ssl->options.hrrCipherSuite0 != ssl->options.cipherSuite0 ||
5768
0
                     ssl->options.hrrCipherSuite != ssl->options.cipherSuite)) {
5769
0
        WOLFSSL_MSG("Received ServerHello with different cipher suite than "
5770
0
                    "HelloRetryRequest");
5771
0
        WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
5772
0
        return INVALID_PARAMETER;
5773
0
    }
5774
#ifdef WOLFSSL_DEBUG_TLS
5775
    WOLFSSL_MSG("Chosen cipher suite:");
5776
    WOLFSSL_MSG(GetCipherNameInternal(ssl->options.cipherSuite0,
5777
                                      ssl->options.cipherSuite));
5778
#endif
5779
5780
    /* Compression */
5781
0
    b = input[args->idx++];
5782
0
    if (b != 0) {
5783
0
        WOLFSSL_MSG("Must be no compression types in list");
5784
0
        WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
5785
0
        return INVALID_PARAMETER;
5786
0
    }
5787
5788
0
    if ((args->idx - args->begin) + OPAQUE16_LEN > helloSz) {
5789
        /* Fewer than OPAQUE16_LEN bytes remain after the compression method, so
5790
         * there is no complete extensions length field. */
5791
0
        if ((args->idx - args->begin) < helloSz) {
5792
            /* A partial extensions length field is genuinely malformed: report
5793
             * it as a decode error regardless of message type. */
5794
0
            WOLFSSL_MSG("Truncated extensions length in ServerHello");
5795
0
            return BUFFER_ERROR;
5796
0
        }
5797
5798
        /* No extensions field at all. */
5799
0
        if (args->extMsgType == hello_retry_request) {
5800
            /* The sentinel Random (RFC 8446 4.1.3) identifies this as a TLS 1.3
5801
             * HelloRetryRequest, which MUST carry supported_versions
5802
             * (4.2.1/9.2). Its complete absence is a missing mandatory
5803
             * extension, so - consistently with the extensions-present case
5804
             * handled later - report it as missing_extension (via
5805
             * INCOMPLETE_DATA), regardless of whether a downgrade would
5806
             * otherwise be allowed. Reject here before DoServerHello would
5807
             * reinterpret the sentinel as a plain TLS 1.2 ServerHello.Random. */
5808
0
            WOLFSSL_MSG("HelloRetryRequest with no supported_versions");
5809
0
            WOLFSSL_ERROR_VERBOSE(INCOMPLETE_DATA);
5810
0
            return INCOMPLETE_DATA;
5811
0
        }
5812
5813
0
        if (!ssl->options.downgrade) {
5814
            /* A plain ServerHello with no extensions is not offering TLS 1.3
5815
             * (no supported_versions extension - see RFC 8446 4.2.1) but TLS
5816
             * 1.2 or below. This is a well-formed message, so a TLS 1.3-only
5817
             * client (downgrade disabled) must reject it as a version mismatch,
5818
             * not as a malformed message. Returning VERSION_ERROR makes the
5819
             * caller send a protocol_version alert (RFC 8446 6.2) rather than
5820
             * decode_error. */
5821
0
            WOLFSSL_MSG("Server offered TLS 1.2 (no supported_versions ext) "
5822
0
                        "but downgrade not allowed");
5823
0
            WOLFSSL_ERROR_VERBOSE(VERSION_ERROR);
5824
0
            return VERSION_ERROR;
5825
0
        }
5826
0
#ifndef WOLFSSL_NO_TLS12
5827
        /* Force client hello version 1.2 to work for static RSA. */
5828
0
        ssl->chVersion.minor = TLSv1_2_MINOR;
5829
0
        ssl->version.minor = TLSv1_2_MINOR;
5830
5831
#ifdef WOLFSSL_DTLS13
5832
        if (ssl->options.dtls) {
5833
            ssl->chVersion.minor = DTLSv1_2_MINOR;
5834
            ssl->version.minor = DTLSv1_2_MINOR;
5835
            ssl->options.tls1_3 = 0;
5836
            ret = Dtls13ClientDoDowngrade(ssl);
5837
            if (ret != 0)
5838
                return ret;
5839
        }
5840
#endif /* WOLFSSL_DTLS13 */
5841
5842
0
#endif
5843
0
        ssl->options.haveEMS = 0;
5844
0
        if (args->pv.minor < ssl->options.minDowngrade) {
5845
0
            WOLFSSL_ERROR_VERBOSE(VERSION_ERROR);
5846
0
            return VERSION_ERROR;
5847
0
        }
5848
0
#ifndef WOLFSSL_NO_TLS12
5849
0
        ssl->options.tls1_3 = 0;
5850
0
        return DoServerHello(ssl, input, inOutIdx, helloSz);
5851
#else
5852
        WOLFSSL_ERROR_VERBOSE(VERSION_ERROR);
5853
        return VERSION_ERROR;
5854
#endif
5855
0
    }
5856
5857
0
    if ((args->idx - args->begin) < helloSz) {
5858
0
        int foundVersion;
5859
5860
        /* Get extension length and length check. */
5861
0
        if ((args->idx - args->begin) + OPAQUE16_LEN > helloSz)
5862
0
            return BUFFER_ERROR;
5863
0
        ato16(&input[args->idx], &args->totalExtSz);
5864
0
        args->idx += OPAQUE16_LEN;
5865
0
        if ((args->idx - args->begin) + args->totalExtSz > helloSz)
5866
0
            return BUFFER_ERROR;
5867
5868
        /* Need to negotiate version first. */
5869
0
        if ((ret = TLSX_ParseVersion(ssl, input + args->idx,
5870
0
            args->totalExtSz, *extMsgType, &foundVersion))) {
5871
0
            return ret;
5872
0
        }
5873
0
        if (!foundVersion) {
5874
            /* RFC 8446 4.1.4: "The server's extensions MUST contain
5875
             * 'supported_versions'." (also 9.2: "supported_versions" is
5876
             * REQUIRED for all ... HelloRetryRequest messages). The HRR random
5877
             * unambiguously identifies a TLS 1.3 server, so its absence is not
5878
             * a downgrade attempt but a missing mandatory extension, which per
5879
             * the "missing_extension" alert definition must be reported as
5880
             * such. Return INCOMPLETE_DATA (which maps to a missing_extension
5881
             * alert) and let the caller emit the alert via
5882
             * TranslateErrorToAlert(). */
5883
0
            if (*extMsgType == hello_retry_request) {
5884
0
                WOLFSSL_MSG("HelloRetryRequest missing supported_versions "
5885
0
                            "extension");
5886
0
                WOLFSSL_ERROR_VERBOSE(INCOMPLETE_DATA);
5887
0
                return INCOMPLETE_DATA;
5888
0
            }
5889
0
            if (!ssl->options.downgrade) {
5890
0
                WOLFSSL_MSG("Server trying to downgrade to version less than "
5891
0
                            "TLS v1.3");
5892
0
                WOLFSSL_ERROR_VERBOSE(VERSION_ERROR);
5893
0
                return VERSION_ERROR;
5894
0
            }
5895
0
#if defined(OPENSSL_EXTRA) || defined(HAVE_WEBSERVER) || \
5896
0
    defined(WOLFSSL_WPAS_SMALL)
5897
            /* Check if client has disabled TLS 1.2 */
5898
0
            if (args->pv.minor == TLSv1_2_MINOR &&
5899
0
                (ssl->options.mask & WOLFSSL_OP_NO_TLSv1_2)
5900
0
                == WOLFSSL_OP_NO_TLSv1_2)
5901
0
            {
5902
0
                WOLFSSL_MSG("\tOption set to not allow TLSv1.2");
5903
0
                WOLFSSL_ERROR_VERBOSE(VERSION_ERROR);
5904
0
                return VERSION_ERROR;
5905
0
            }
5906
0
#endif
5907
5908
0
            if (!ssl->options.dtls &&
5909
0
                args->pv.minor < ssl->options.minDowngrade) {
5910
0
                WOLFSSL_ERROR_VERBOSE(VERSION_ERROR);
5911
0
                return VERSION_ERROR;
5912
0
            }
5913
5914
0
            if (ssl->options.dtls &&
5915
0
                args->pv.minor > ssl->options.minDowngrade) {
5916
0
                WOLFSSL_ERROR_VERBOSE(VERSION_ERROR);
5917
0
                return VERSION_ERROR;
5918
0
            }
5919
5920
0
            ssl->version.minor = args->pv.minor;
5921
0
            ssl->options.tls1_3 = 0;
5922
5923
#ifdef WOLFSSL_DTLS13
5924
            if (ssl->options.dtls) {
5925
                ret = Dtls13ClientDoDowngrade(ssl);
5926
                if (ret != 0)
5927
                    return ret;
5928
            }
5929
#endif /* WOLFSSL_DTLS13 */
5930
0
        }
5931
0
    }
5932
5933
#ifdef WOLFSSL_DTLS13
5934
    /* we are sure that version is >= v1.3 now, we can get rid of buffered
5935
     * ClientHello that was buffered to re-compute the hash in case of
5936
     * downgrade */
5937
    if (ssl->options.dtls && ssl->dtls13ClientHello != NULL) {
5938
        XFREE(ssl->dtls13ClientHello, ssl->heap, DYNAMIC_TYPE_DTLS_MSG);
5939
        ssl->dtls13ClientHello = NULL;
5940
        ssl->dtls13ClientHelloSz = 0;
5941
    }
5942
#endif /* WOLFSSL_DTLS13 */
5943
5944
    /* Advance state and proceed */
5945
0
    ssl->options.asyncState = TLS_ASYNC_BUILD;
5946
0
    } /* case TLS_ASYNC_BEGIN */
5947
0
    FALL_THROUGH;
5948
5949
0
    case TLS_ASYNC_BUILD:
5950
0
    case TLS_ASYNC_DO:
5951
0
    {
5952
    /* restore message type */
5953
0
    *extMsgType = args->extMsgType;
5954
5955
    /* Parse and handle extensions, unless lower than TLS1.3. In that case,
5956
     * extensions will be parsed in DoServerHello. */
5957
0
    if (args->totalExtSz > 0 && IsAtLeastTLSv1_3(ssl->version)) {
5958
0
        ret = TLSX_Parse(ssl, input + args->idx, args->totalExtSz,
5959
0
            *extMsgType, NULL);
5960
0
        if (ret != 0) {
5961
        #ifdef WOLFSSL_ASYNC_CRYPT
5962
            /* Handle async operation */
5963
            if (ret == WC_NO_ERR_TRACE(WC_PENDING_E)) {
5964
                /* Mark message as not received so it can process again */
5965
                ssl->msgsReceived.got_server_hello = 0;
5966
            }
5967
        #endif
5968
0
            return ret;
5969
0
        }
5970
5971
0
        if (*extMsgType == hello_retry_request) {
5972
            /* Update counts to reflect change of message type. */
5973
0
            ssl->msgsReceived.got_hello_retry_request = 1;
5974
0
            ssl->msgsReceived.got_server_hello = 0;
5975
0
        }
5976
0
    }
5977
5978
0
    if (args->totalExtSz > 0) {
5979
0
        args->idx += args->totalExtSz;
5980
0
    }
5981
5982
#ifdef WOLFSSL_DTLS_CID
5983
    if (ssl->options.useDtlsCID && *extMsgType == server_hello)
5984
        DtlsCIDOnExtensionsParsed(ssl);
5985
#endif /* WOLFSSL_DTLS_CID */
5986
5987
0
    if (IsAtLeastTLSv1_3(ssl->version)) {
5988
0
        *inOutIdx = args->idx;
5989
0
    }
5990
5991
0
    ssl->options.serverState = SERVER_HELLO_COMPLETE;
5992
5993
#ifdef HAVE_SECRET_CALLBACK
5994
    if (ssl->sessionSecretCb != NULL
5995
#ifdef HAVE_SESSION_TICKET
5996
            && ssl->session->ticketLen > 0
5997
#endif
5998
            ) {
5999
        int secretSz = SECRET_LEN;
6000
        ret = ssl->sessionSecretCb(ssl, ssl->session->masterSecret,
6001
                                   &secretSz, ssl->sessionSecretCtx);
6002
        if (ret != 0 || secretSz != SECRET_LEN) {
6003
            WOLFSSL_ERROR_VERBOSE(SESSION_SECRET_CB_E);
6004
            return SESSION_SECRET_CB_E;
6005
        }
6006
    }
6007
#endif /* HAVE_SECRET_CALLBACK */
6008
6009
    /* Version only negotiated in extensions for TLS v1.3.
6010
     * Only now do we know how to deal with session id.
6011
     */
6012
0
    if (!IsAtLeastTLSv1_3(ssl->version)) {
6013
0
#ifndef WOLFSSL_NO_TLS12
6014
0
        ssl->arrays->sessionIDSz = args->sessIdSz;
6015
6016
0
        if (ssl->arrays->sessionIDSz > ID_LEN) {
6017
0
            WOLFSSL_MSG("Invalid session ID size");
6018
0
            ssl->arrays->sessionIDSz = 0;
6019
0
            return BUFFER_ERROR;
6020
0
        }
6021
0
        else if (ssl->arrays->sessionIDSz) {
6022
0
            XMEMCPY(ssl->arrays->sessionID, args->sessId,
6023
0
                ssl->arrays->sessionIDSz);
6024
0
            ssl->options.haveSessionId = 1;
6025
0
        }
6026
6027
        /* Force client hello version 1.2 to work for static RSA. */
6028
0
        if (ssl->options.dtls)
6029
0
            ssl->chVersion.minor = DTLSv1_2_MINOR;
6030
0
        else
6031
0
            ssl->chVersion.minor = TLSv1_2_MINOR;
6032
        /* Complete TLS v1.2 processing of ServerHello. */
6033
0
        ret = DoServerHello(ssl, input, inOutIdx, helloSz);
6034
#else
6035
        WOLFSSL_MSG("Client using higher version, fatal error");
6036
        WOLFSSL_ERROR_VERBOSE(VERSION_ERROR);
6037
        ret = VERSION_ERROR;
6038
#endif
6039
6040
0
        WOLFSSL_LEAVE("DoTls13ServerHello", ret);
6041
6042
0
        return ret;
6043
0
    }
6044
6045
    /* Advance state and proceed */
6046
0
    ssl->options.asyncState = TLS_ASYNC_FINALIZE;
6047
0
    } /* case TLS_ASYNC_BUILD || TLS_ASYNC_DO */
6048
0
    FALL_THROUGH;
6049
6050
0
    case TLS_ASYNC_FINALIZE:
6051
0
    {
6052
#ifdef WOLFSSL_TLS13_MIDDLEBOX_COMPAT
6053
    if (ssl->options.tls13MiddleBoxCompat) {
6054
        if (args->sessIdSz == 0) {
6055
            WOLFSSL_MSG("args->sessIdSz == 0");
6056
            WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
6057
            return INVALID_PARAMETER;
6058
        }
6059
        if (ssl->session->sessionIDSz != 0) {
6060
            if (ssl->session->sessionIDSz != args->sessIdSz ||
6061
                XMEMCMP(ssl->session->sessionID, args->sessId,
6062
                    args->sessIdSz) != 0) {
6063
                WOLFSSL_MSG("session id doesn't match");
6064
                WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
6065
                return INVALID_PARAMETER;
6066
            }
6067
        }
6068
        else if (XMEMCMP(ssl->arrays->clientRandom, args->sessId,
6069
                args->sessIdSz) != 0) {
6070
            WOLFSSL_MSG("session id doesn't match client random");
6071
            WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
6072
            return INVALID_PARAMETER;
6073
        }
6074
    }
6075
    else
6076
#endif /* WOLFSSL_TLS13_MIDDLEBOX_COMPAT */
6077
#if defined(WOLFSSL_QUIC) || defined(WOLFSSL_DTLS13)
6078
    if (0
6079
#ifdef WOLFSSL_QUIC
6080
        || WOLFSSL_IS_QUIC(ssl)
6081
#endif
6082
#ifdef WOLFSSL_DTLS13
6083
        || ssl->options.dtls
6084
#endif
6085
    ) {
6086
        /* RFC 9147 Section 5 / RFC 9001 Section 8.4: DTLS 1.3 and QUIC
6087
         * ServerHello must have empty legacy_session_id_echo. */
6088
        int requireEmptyEcho = 1;
6089
#ifdef WOLFSSL_DTLS13_ECHO_LEGACY_SESSION_ID
6090
        /* Compat: a wolfSSL <= 5.9.0 DTLS 1.3 server echoes the client's
6091
         * legacy_session_id back instead of omitting it. */
6092
        if (ssl->options.dtls)
6093
            requireEmptyEcho = 0;
6094
#endif
6095
        if (requireEmptyEcho && args->sessIdSz != 0) {
6096
            WOLFSSL_MSG("args->sessIdSz != 0");
6097
            WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
6098
            return INVALID_PARAMETER;
6099
        }
6100
#ifdef WOLFSSL_DTLS13_ECHO_LEGACY_SESSION_ID
6101
        /* An echoing wolfSSL <= 5.9.0 server must still send back what was
6102
         * sent (RFC 8446 Section 4.1.3), so don't accept an arbitrary value.
6103
         * An empty echo is the compliant server case and stays acceptable. */
6104
        if (!requireEmptyEcho && args->sessIdSz != 0 &&
6105
                (args->sessIdSz != ssl->session->sessionIDSz ||
6106
                 XMEMCMP(ssl->session->sessionID, args->sessId,
6107
                         args->sessIdSz) != 0)) {
6108
            WOLFSSL_MSG("Server sent different session id");
6109
            WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
6110
            return INVALID_PARAMETER;
6111
        }
6112
#endif
6113
    }
6114
    else
6115
#endif /* WOLFSSL_QUIC || WOLFSSL_DTLS13 */
6116
0
    if (args->sessIdSz != ssl->session->sessionIDSz || (args->sessIdSz > 0 &&
6117
0
        XMEMCMP(ssl->session->sessionID, args->sessId, args->sessIdSz) != 0))
6118
0
    {
6119
0
        WOLFSSL_MSG("Server sent different session id");
6120
0
        WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
6121
0
        return INVALID_PARAMETER;
6122
0
    }
6123
6124
0
    ret = SetCipherSpecs(ssl);
6125
0
    if (ret != 0)
6126
0
        return ret;
6127
6128
#ifdef HAVE_NULL_CIPHER
6129
    if (ssl->options.cipherSuite0 == ECC_BYTE &&
6130
                              (ssl->options.cipherSuite == TLS_SHA256_SHA256 ||
6131
                               ssl->options.cipherSuite == TLS_SHA384_SHA384)) {
6132
        ;
6133
    }
6134
    else
6135
#endif
6136
0
#if defined(WOLFSSL_SM4_GCM) && defined(WOLFSSL_SM3)
6137
0
    if (ssl->options.cipherSuite0 == CIPHER_BYTE &&
6138
0
            ssl->options.cipherSuite == TLS_SM4_GCM_SM3) {
6139
0
        ; /* Do nothing. */
6140
0
    }
6141
0
    else
6142
0
#endif
6143
0
#if defined(WOLFSSL_SM4_CCM) && defined(WOLFSSL_SM3)
6144
0
    if (ssl->options.cipherSuite0 == CIPHER_BYTE &&
6145
0
            ssl->options.cipherSuite == TLS_SM4_CCM_SM3) {
6146
0
        ; /* Do nothing. */
6147
0
    }
6148
0
    else
6149
0
#endif
6150
    /* Check that the negotiated ciphersuite matches protocol version. */
6151
0
    if (ssl->options.cipherSuite0 != TLS13_BYTE) {
6152
0
        WOLFSSL_MSG("Server sent non-TLS13 cipher suite in TLS 1.3 packet");
6153
0
        WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
6154
0
        return INVALID_PARAMETER;
6155
0
    }
6156
6157
0
    suite[0] = ssl->options.cipherSuite0;
6158
0
    suite[1] = ssl->options.cipherSuite;
6159
0
    if (!FindSuiteSSL(ssl, suite)) {
6160
0
        WOLFSSL_MSG("Cipher suite not supported on client");
6161
0
        WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
6162
0
        return INVALID_PARAMETER;
6163
0
    }
6164
6165
#if defined(HAVE_ECH)
6166
    /* check for acceptConfirmation */
6167
    if (ssl->echConfigs != NULL && !ssl->options.disableECH &&
6168
            ssl->hsHashesEch != NULL) {
6169
        args->echX = TLSX_Find(ssl->extensions, TLSX_ECH);
6170
        if (args->echX == NULL || args->echX->data == NULL)
6171
            return WOLFSSL_FATAL_ERROR;
6172
6173
        if (args->extMsgType == hello_retry_request &&
6174
                ((WOLFSSL_ECH*)args->echX->data)->confBuf == NULL) {
6175
            /* server rejected ECH, fall back to outer */
6176
            Free_HS_Hashes(ssl->hsHashesEch, ssl->heap);
6177
            ssl->hsHashesEch = NULL;
6178
            /* EchCheckAcceptance is bypassed, so replace extensions now */
6179
            ret = TLSX_EchReplaceExtensions(ssl, 0);
6180
            if (ret != 0)
6181
                return ret;
6182
        }
6183
        else {
6184
            /* account for hrr extension instead of server random */
6185
            if (args->extMsgType == hello_retry_request) {
6186
                args->acceptOffset =
6187
                    (word32)(((WOLFSSL_ECH*)args->echX->data)->confBuf - input);
6188
                args->acceptLabel = (byte*)echHrrAcceptConfirmationLabel;
6189
                args->acceptLabelSz = ECH_HRR_ACCEPT_CONFIRMATION_LABEL_SZ;
6190
            }
6191
            else {
6192
                args->acceptLabel = (byte*)echAcceptConfirmationLabel;
6193
                args->acceptLabelSz = ECH_ACCEPT_CONFIRMATION_LABEL_SZ;
6194
            }
6195
            /* check acceptance */
6196
            if (ret == 0) {
6197
                ret = EchCheckAcceptance(ssl, args->acceptLabel,
6198
                    args->acceptLabelSz, input, args->acceptOffset, helloSz,
6199
                    args->extMsgType);
6200
            }
6201
            if (ret != 0)
6202
                return ret;
6203
            /* use the inner random for client random */
6204
            if (args->extMsgType != hello_retry_request &&
6205
                    ssl->options.echAccepted) {
6206
                XMEMCPY(ssl->arrays->clientRandom,
6207
                    ssl->arrays->clientRandomInner, RAN_LEN);
6208
            }
6209
        }
6210
    }
6211
#endif /* HAVE_ECH */
6212
6213
0
    if (*extMsgType == server_hello) {
6214
0
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
6215
0
        PreSharedKey* psk = NULL;
6216
0
        TLSX* ext = TLSX_Find(ssl->extensions, TLSX_PRE_SHARED_KEY);
6217
0
        if (ext != NULL)
6218
0
            psk = (PreSharedKey*)ext->data;
6219
0
        while (psk != NULL && !psk->chosen)
6220
0
            psk = psk->next;
6221
0
        if (psk == NULL) {
6222
            /* A mandatory PSK is satisfied by any PSK the server chose,
6223
             * including a resumption PSK - this matches the server-side
6224
             * failNoPSK semantics, where a negotiated PSK (external or
6225
             * resumption) is accepted. The error only fires when no PSK was
6226
             * chosen at all. havePSK is only set by an external-PSK callback,
6227
             * so a peer relying solely on session-ticket resumption is
6228
             * unaffected. */
6229
0
            if (ssl->options.havePSK && ssl->options.failNoPSK) {
6230
0
                WOLFSSL_MSG("Server did not negotiate a mandatory PSK");
6231
0
                WOLFSSL_ERROR_VERBOSE(PSK_MISSING_ERROR);
6232
0
                return PSK_MISSING_ERROR;
6233
0
            }
6234
0
            ssl->options.resuming = 0;
6235
0
            ssl->arrays->psk_keySz = 0;
6236
0
            XMEMSET(ssl->arrays->psk_key, 0, MAX_PSK_KEY_LEN);
6237
0
        }
6238
0
        else {
6239
#if defined(HAVE_ECH)
6240
            /* do not resume when outerHandshake will be negotiated */
6241
            if (ssl->echConfigs != NULL && !ssl->options.disableECH &&
6242
                    !ssl->options.echAccepted) {
6243
                WOLFSSL_MSG("ECH rejected but server negotiated PSK");
6244
                return INVALID_PARAMETER;
6245
            }
6246
#endif
6247
#ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
6248
            if (ssl->options.certWithExternPsk && psk->resumption) {
6249
                /* RFC 9973 mode requires external PSK, not ticket resumption. */
6250
                WOLFSSL_ERROR_VERBOSE(PSK_KEY_ERROR);
6251
                return PSK_KEY_ERROR;
6252
            }
6253
            if (ssl->options.certWithExternPsk && ssl->options.shSentKeyShare == 0) {
6254
                /* RFC 9973 Sect. 3: cert_with_extern_psk requires psk_dhe_ke;
6255
                 * a ServerHello without a key_share confirms only psk_ke. */
6256
                WOLFSSL_MSG("cert_with_extern_psk: ServerHello missing key_share");
6257
                WOLFSSL_ERROR_VERBOSE(EXT_MISSING);
6258
                return EXT_MISSING;
6259
            }
6260
#endif
6261
0
            if ((ret = SetupPskKey(ssl, psk, 0)) != 0)
6262
0
                return ret;
6263
0
            ssl->options.pskNegotiated = 1;
6264
0
        }
6265
#else
6266
        /* no resumption possible */
6267
        ssl->options.resuming = 0;
6268
#endif
6269
6270
        /* sanity check on PSK / KSE */
6271
0
        if (
6272
0
    #if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
6273
0
            ssl->options.pskNegotiated == 0 &&
6274
0
    #endif
6275
0
            (ssl->session->namedGroup == 0 ||
6276
0
             ssl->options.shSentKeyShare == 0)) {
6277
0
            return EXT_MISSING;
6278
0
        }
6279
6280
0
        ssl->keys.encryptionOn = 1;
6281
0
        ssl->options.serverState = SERVER_HELLO_COMPLETE;
6282
6283
0
    }
6284
0
    else {
6285
        /* https://datatracker.ietf.org/doc/html/rfc8446#section-4.1.4
6286
         * Clients MUST abort the handshake with an
6287
         * "illegal_parameter" alert if the HelloRetryRequest would not result
6288
         * in any change in the ClientHello.
6289
         */
6290
        /* Check if the HRR contained a cookie or a keyshare */
6291
0
        if (!ssl->options.hrrSentKeyShare
6292
0
#ifdef WOLFSSL_TLS13_COOKIE
6293
0
                && !ssl->options.hrrSentCookie
6294
0
#endif
6295
0
                ) {
6296
0
            SendAlert(ssl, alert_fatal, illegal_parameter);
6297
0
            return EXT_MISSING;
6298
0
        }
6299
6300
0
        ssl->options.tls1_3 = 1;
6301
0
        ssl->options.serverState = SERVER_HELLO_RETRY_REQUEST_COMPLETE;
6302
6303
0
        ret = RestartHandshakeHash(ssl);
6304
0
    }
6305
6306
0
    break;
6307
0
    } /* case TLS_ASYNC_FINALIZE */
6308
0
    default:
6309
0
        ret = INPUT_CASE_ERROR;
6310
0
    } /* switch (ssl->options.asyncState) */
6311
6312
#ifdef WOLFSSL_ASYNC_CRYPT
6313
    if (ret == 0) {
6314
        FreeAsyncCtx(ssl, 0);
6315
        /* Replays skip the sanity check that re-sets got_server_hello;
6316
         * restore on completion (not for HRR, which re-counts it). */
6317
        if (*extMsgType == server_hello &&
6318
                ssl->msgsReceived.got_server_hello == 0) {
6319
            ssl->msgsReceived.got_server_hello = 1;
6320
        }
6321
    }
6322
#endif
6323
6324
0
    WOLFSSL_LEAVE("DoTls13ServerHello", ret);
6325
0
    WOLFSSL_END(WC_FUNC_SERVER_HELLO_DO);
6326
6327
0
    return ret;
6328
0
}
6329
6330
/* handle processing TLS 1.3 encrypted_extensions (8) */
6331
/* Parse and handle an EncryptedExtensions message.
6332
 * Only a client will receive this message.
6333
 *
6334
 * ssl       The SSL/TLS object.
6335
 * input     The message buffer.
6336
 * inOutIdx  On entry, the index into the message buffer of
6337
 *           EncryptedExtensions.
6338
 *           On exit, the index of byte after the EncryptedExtensions
6339
 *           message.
6340
 * totalSz   The length of the current handshake message.
6341
 * returns 0 on success and otherwise failure.
6342
 */
6343
static int DoTls13EncryptedExtensions(WOLFSSL* ssl, const byte* input,
6344
                                      word32* inOutIdx, word32 totalSz)
6345
0
{
6346
0
    int    ret;
6347
0
    word32 begin = *inOutIdx;
6348
0
    word32 i = begin;
6349
0
    word16 totalExtSz;
6350
6351
0
    WOLFSSL_START(WC_FUNC_ENCRYPTED_EXTENSIONS_DO);
6352
0
    WOLFSSL_ENTER("DoTls13EncryptedExtensions");
6353
6354
#ifdef WOLFSSL_CALLBACKS
6355
    if (ssl->hsInfoOn) AddPacketName(ssl, "EncryptedExtensions");
6356
    if (ssl->toInfoOn) AddLateName("EncryptedExtensions", &ssl->timeoutInfo);
6357
#endif
6358
6359
    /* Length field of extension data. */
6360
0
    if (totalSz < OPAQUE16_LEN)
6361
0
        return BUFFER_ERROR;
6362
0
    ato16(&input[i], &totalExtSz);
6363
0
    i += OPAQUE16_LEN;
6364
6365
    /* Extension data. */
6366
0
    if (i - begin + totalExtSz != totalSz)
6367
0
        return BUFFER_ERROR;
6368
0
    if ((ret = TLSX_Parse(ssl, input + i, totalExtSz, encrypted_extensions,
6369
0
                                                                       NULL))) {
6370
0
        return ret;
6371
0
    }
6372
6373
    /* Move index to byte after message. */
6374
0
    *inOutIdx = i + totalExtSz;
6375
6376
#ifdef WOLFSSL_EARLY_DATA
6377
    if (ssl->earlyData != no_early_data) {
6378
        TLSX* ext = TLSX_Find(ssl->extensions, TLSX_EARLY_DATA);
6379
        if (ext == NULL || !ext->val) {
6380
            WOLFSSL_MSG("Early data rejected by server (no early_data "
6381
                        "EncryptedExtensions response)");
6382
            ssl->earlyData = no_early_data;
6383
        }
6384
    }
6385
6386
    if (ssl->earlyData == no_early_data) {
6387
        ret = SetKeysSide(ssl, ENCRYPT_SIDE_ONLY);
6388
        if (ret != 0)
6389
            return ret;
6390
    }
6391
#endif /* WOLFSSL_EARLY_DATA */
6392
6393
0
    ssl->options.serverState = SERVER_ENCRYPTED_EXTENSIONS_COMPLETE;
6394
6395
0
    WOLFSSL_LEAVE("DoTls13EncryptedExtensions", ret);
6396
0
    WOLFSSL_END(WC_FUNC_ENCRYPTED_EXTENSIONS_DO);
6397
6398
0
    return ret;
6399
0
}
6400
6401
#ifndef NO_CERTS
6402
/* handle processing TLS v1.3 certificate_request (13) */
6403
/* Handle a TLS v1.3 CertificateRequest message.
6404
 * This message is always encrypted.
6405
 * Only a client will receive this message.
6406
 *
6407
 * ssl       The SSL/TLS object.
6408
 * input     The message buffer.
6409
 * inOutIdx  On entry, the index into the message buffer of CertificateRequest.
6410
 *           On exit, the index of byte after the CertificateRequest message.
6411
 * size      The length of the current handshake message.
6412
 * returns 0 on success and otherwise failure.
6413
 */
6414
static int DoTls13CertificateRequest(WOLFSSL* ssl, const byte* input,
6415
                                     word32* inOutIdx, word32 size)
6416
0
{
6417
0
    word16      len;
6418
0
    word32      begin = *inOutIdx;
6419
0
    int         ret = 0;
6420
0
    Suites      peerSuites;
6421
#ifdef WOLFSSL_POST_HANDSHAKE_AUTH
6422
    word16      reqCtxLen;
6423
    const byte* reqCtxData;
6424
#endif
6425
6426
0
    WOLFSSL_START(WC_FUNC_CERTIFICATE_REQUEST_DO);
6427
0
    WOLFSSL_ENTER("DoTls13CertificateRequest");
6428
6429
0
    XMEMSET(&peerSuites, 0, sizeof(Suites));
6430
0
#if !defined(WOLFSSL_NO_SIGALG)
6431
    /* Post-handshake auth can deliver several requests; each one's cert
6432
     * signature algorithms replace the last rather than adding to them. */
6433
0
    ssl->certHashSigAlgoSz = 0;
6434
0
#endif
6435
6436
#ifdef WOLFSSL_CALLBACKS
6437
    if (ssl->hsInfoOn) AddPacketName(ssl, "CertificateRequest");
6438
    if (ssl->toInfoOn) AddLateName("CertificateRequest", &ssl->timeoutInfo);
6439
#endif
6440
6441
0
    if (OPAQUE8_LEN > size)
6442
0
        return BUFFER_ERROR;
6443
6444
    /* Length of the request context. */
6445
0
    len = input[(*inOutIdx)++];
6446
0
    if ((*inOutIdx - begin) + len > size)
6447
0
        return BUFFER_ERROR;
6448
    /* INVALID_PARAMETER does not map to illegal_parameter in the central
6449
     * alert path, so emit the alert explicitly before returning. */
6450
0
    if (ssl->options.connectState < FINISHED_DONE) {
6451
        /* RFC 8446 Section 4.3.2: in the handshake the context is zero
6452
         * length. */
6453
0
        if (len > 0) {
6454
0
            SendAlert(ssl, alert_fatal, illegal_parameter);
6455
0
            WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
6456
0
            return INVALID_PARAMETER;
6457
0
        }
6458
0
    }
6459
#ifdef WOLFSSL_POST_HANDSHAKE_AUTH
6460
#ifdef WOLFSSL_QUIC
6461
    else if (WOLFSSL_IS_QUIC(ssl)) {
6462
        WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
6463
        return OUT_OF_ORDER_E;
6464
    }
6465
#endif
6466
    else if (len == 0) {
6467
        /* RFC 8446 Section 4.3.2: a post-handshake CertificateRequest context
6468
         * MUST be non-empty and unique for the connection. */
6469
        SendAlert(ssl, alert_fatal, illegal_parameter);
6470
        WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
6471
        return INVALID_PARAMETER;
6472
    }
6473
#endif
6474
6475
#ifdef WOLFSSL_POST_HANDSHAKE_AUTH
6476
    /* Remember the request context bytes; the CertReqCtx allocation and
6477
     * linking into ssl->certReqCtx is deferred until after the rest of the
6478
     * message has been validated.
6479
     */
6480
    reqCtxLen = len;
6481
    reqCtxData = input + *inOutIdx;
6482
    /* Reject a context that duplicates one still pending on the connection. */
6483
    if (ssl->options.connectState >= FINISHED_DONE) {
6484
        CertReqCtx* dup;
6485
        for (dup = ssl->certReqCtx; dup != NULL; dup = dup->next) {
6486
            if (dup->len == reqCtxLen &&
6487
                    XMEMCMP(&dup->ctx, reqCtxData, reqCtxLen) == 0) {
6488
                SendAlert(ssl, alert_fatal, illegal_parameter);
6489
                WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
6490
                return INVALID_PARAMETER;
6491
            }
6492
        }
6493
    }
6494
#endif
6495
0
    *inOutIdx += len;
6496
6497
    /* TODO: Add support for more extensions:
6498
     *   signed_certificate_timestamp, certificate_authorities, oid_filters.
6499
     */
6500
    /* Certificate extensions */
6501
0
    if ((*inOutIdx - begin) + OPAQUE16_LEN > size)
6502
0
        return BUFFER_ERROR;
6503
0
    ato16(input + *inOutIdx, &len);
6504
0
    *inOutIdx += OPAQUE16_LEN;
6505
0
    if ((*inOutIdx - begin) + len > size)
6506
0
        return BUFFER_ERROR;
6507
    /* RFC 9846 Section 4.4.2: CertificateRequest.extensions has a lower bound of
6508
     * 0, so an empty extensions block is parsed rather than rejected here. A
6509
     * request missing the mandatory signature_algorithms extension is caught by
6510
     * the check below. */
6511
0
    if ((ret = TLSX_Parse(ssl, input + *inOutIdx, len, certificate_request,
6512
0
                                                                &peerSuites))) {
6513
0
        return ret;
6514
0
    }
6515
0
    *inOutIdx += len;
6516
6517
    /* No trailing bytes allowed (RFC 8446 4.3.2). */
6518
0
    if ((*inOutIdx - begin) != size)
6519
0
        return BUFFER_ERROR;
6520
6521
    /* RFC 8446 Section 4.3.2: the signature_algorithms extension MUST be
6522
     * present in a CertificateRequest. */
6523
0
    if (peerSuites.hashSigAlgoSz == 0) {
6524
0
        SendAlert(ssl, alert_fatal, missing_extension);
6525
0
        WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
6526
0
        return INVALID_PARAMETER;
6527
0
    }
6528
6529
0
#if !defined(NO_CERTS) && !defined(WOLFSSL_NO_SIGALG)
6530
0
    SetPeerSha1CertOk(ssl, &peerSuites);
6531
0
#endif
6532
6533
0
#ifdef WOLFSSL_CERT_SETUP_CB
6534
0
    if ((ret = CertSetupCbWrapper(ssl)) != 0)
6535
0
        return ret;
6536
0
#endif
6537
6538
#if defined(HAVE_ECH)
6539
    /* RFC 9849 s6.1.7: ECH was offered but rejected by the server...
6540
     * the client MUST respond with an empty Certificate message. */
6541
    if (ssl->echConfigs != NULL && !ssl->options.disableECH &&
6542
            !ssl->options.echAccepted) {
6543
        ssl->options.sendVerify = SEND_BLANK_CERT;
6544
    }
6545
    else
6546
#endif
6547
0
    if ((ssl->buffers.certificate && ssl->buffers.certificate->buffer &&
6548
0
        ((ssl->buffers.key && ssl->buffers.key->buffer)
6549
        #ifdef HAVE_PK_CALLBACKS
6550
            || wolfSSL_CTX_IsPrivatePkSet(ssl->ctx)
6551
        #endif
6552
0
    ))
6553
0
        #ifdef OPENSSL_EXTRA
6554
0
            || ssl->ctx->certSetupCb != NULL
6555
0
        #endif
6556
0
            ) {
6557
0
        if (PickHashSigAlgo(ssl, peerSuites.hashSigAlgo,
6558
0
                            peerSuites.hashSigAlgoSz, 0) != 0) {
6559
0
            WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
6560
0
            return INVALID_PARAMETER;
6561
0
        }
6562
0
        ssl->options.sendVerify = SEND_CERT;
6563
0
    }
6564
0
    else {
6565
0
#ifndef WOLFSSL_NO_CLIENT_CERT_ERROR
6566
0
        ssl->options.sendVerify = SEND_BLANK_CERT;
6567
#else
6568
        WOLFSSL_MSG("Certificate required but none set on client");
6569
        /* RFC 8446 Section 4.4.2.4: send certificate_required when a
6570
         * peer (here, the client) cannot provide a certificate that the
6571
         * other peer required. */
6572
        SendAlert(ssl, alert_fatal, certificate_required);
6573
        WOLFSSL_ERROR_VERBOSE(NO_CERT_ERROR);
6574
        return NO_CERT_ERROR;
6575
#endif
6576
0
    }
6577
6578
#ifdef WOLFSSL_POST_HANDSHAKE_AUTH
6579
    {
6580
        /* CertReqCtx has one byte at end for context value.
6581
        * Increase size to handle other implementations sending more than one byte.
6582
        * That is, allocate extra space, over one byte, to hold the context value.
6583
        */
6584
        CertReqCtx* certReqCtx = (CertReqCtx*)XMALLOC(
6585
            sizeof(CertReqCtx) + (reqCtxLen == 0 ? 0 : reqCtxLen - 1),
6586
            ssl->heap, DYNAMIC_TYPE_TMP_BUFFER);
6587
        if (certReqCtx == NULL)
6588
            return MEMORY_E;
6589
        certReqCtx->next = ssl->certReqCtx;
6590
        certReqCtx->len = reqCtxLen;
6591
        XMEMCPY(&certReqCtx->ctx, reqCtxData, reqCtxLen);
6592
        ssl->certReqCtx = certReqCtx;
6593
    }
6594
#endif
6595
6596
0
    WOLFSSL_LEAVE("DoTls13CertificateRequest", ret);
6597
0
    WOLFSSL_END(WC_FUNC_CERTIFICATE_REQUEST_DO);
6598
6599
0
    return ret;
6600
0
}
6601
#endif /* !NO_CERTS */
6602
#endif /* !NO_WOLFSSL_CLIENT */
6603
6604
#ifndef NO_WOLFSSL_SERVER
6605
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
6606
#ifndef NO_PSK
6607
int FindPskSuite(const WOLFSSL* ssl, PreSharedKey* psk, byte* psk_key,
6608
        word32* psk_keySz, const byte* suite, int* found, byte* foundSuite)
6609
{
6610
    const char* cipherName = NULL;
6611
    byte        cipherSuite0 = TLS13_BYTE;
6612
    byte        cipherSuite  = WOLFSSL_DEF_PSK_CIPHER;
6613
    int         ret = 0;
6614
6615
    *found = 0;
6616
    (void)suite;
6617
6618
    if (ssl->options.server_psk_tls13_cb != NULL) {
6619
         *psk_keySz = ssl->options.server_psk_tls13_cb((WOLFSSL*)ssl,
6620
             (char*)psk->identity, psk_key, MAX_PSK_KEY_LEN, &cipherName);
6621
         if (*psk_keySz != 0) {
6622
             int cipherSuiteFlags = WOLFSSL_CIPHER_SUITE_FLAG_NONE;
6623
             *found = (GetCipherSuiteFromName(cipherName, &cipherSuite0,
6624
                 &cipherSuite, NULL, NULL, &cipherSuiteFlags) == 0);
6625
             (void)cipherSuiteFlags;
6626
         }
6627
    }
6628
    if (*found == 0 && (ssl->options.server_psk_cb != NULL)) {
6629
         *psk_keySz = ssl->options.server_psk_cb((WOLFSSL*)ssl,
6630
                             (char*)psk->identity, psk_key,
6631
                             MAX_PSK_KEY_LEN);
6632
         *found = (*psk_keySz != 0);
6633
    }
6634
    if (*found) {
6635
        if (*psk_keySz > MAX_PSK_KEY_LEN &&
6636
            (int)*psk_keySz != WC_NO_ERR_TRACE(USE_HW_PSK)) {
6637
            WOLFSSL_MSG("Key len too long in FindPsk()");
6638
            ret = PSK_KEY_ERROR;
6639
            WOLFSSL_ERROR_VERBOSE(ret);
6640
            *found = 0;
6641
        }
6642
        if (ret == 0) {
6643
        #if !defined(WOLFSSL_PSK_ONE_ID) && !defined(WOLFSSL_PRIORITIZE_PSK)
6644
            /* Check whether PSK ciphersuite is in SSL. */
6645
            *found = (suite[0] == cipherSuite0) && (suite[1] == cipherSuite);
6646
        #else
6647
            (void)suite;
6648
            /* Check whether PSK ciphersuite is in SSL. */
6649
            {
6650
                byte s[2] = {
6651
                    cipherSuite0,
6652
                    cipherSuite,
6653
                };
6654
                *found = FindSuiteSSL(ssl, s);
6655
            }
6656
        #endif
6657
        }
6658
    }
6659
    if (*found && foundSuite != NULL) {
6660
        foundSuite[0] = cipherSuite0;
6661
        foundSuite[1] = cipherSuite;
6662
    }
6663
6664
    return ret;
6665
}
6666
6667
/* Attempt to find the PSK (not session ticket) that matches.
6668
 *
6669
 * @param [in, out] ssl    The SSL/TLS object.
6670
 * @param [in]      psk    A pre-shared key from the extension.
6671
 * @param [out]     suite  Cipher suite to use with PSK.
6672
 * @param [out]     err    Error code.
6673
 *                         PSK_KEY_ERROR when key is too big,
6674
 *                         UNSUPPORTED_SUITE on invalid suite.
6675
 *                         Other error when attempting to derive early secret.
6676
 * @return  1 when a match found - but check error code.
6677
 * @return  0 when no match found.
6678
 */
6679
static int FindPsk(WOLFSSL* ssl, PreSharedKey* psk, const byte* suite, int* err)
6680
{
6681
    int         ret = 0;
6682
    int         found = 0;
6683
    byte        foundSuite[SUITE_LEN];
6684
6685
    WOLFSSL_ENTER("FindPsk");
6686
6687
    XMEMSET(foundSuite, 0, sizeof(foundSuite));
6688
6689
    ret = FindPskSuite(ssl, psk, ssl->arrays->psk_key, &ssl->arrays->psk_keySz,
6690
                       suite, &found, foundSuite);
6691
    if (ret == 0 && found) {
6692
        /* This identity matched via external PSK callback, not ticket resume. */
6693
        psk->resumption = 0;
6694
        /* Default to ciphersuite if cb doesn't specify. */
6695
        ssl->options.resuming = 0;
6696
        /* Don't send certificate request when using PSK. */
6697
#ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
6698
        if (!ssl->options.certWithExternPsk)
6699
#endif
6700
            ssl->options.verifyPeer = 0;
6701
6702
        /* obfuscated_ticket_age is not checked: RFC 8446 Section 4.2.11
6703
         * requires servers to ignore it for an external identity. */
6704
        /* Set PSK ciphersuite into SSL. */
6705
        ssl->options.cipherSuite0 = foundSuite[0];
6706
        ssl->options.cipherSuite  = foundSuite[1];
6707
        ret = SetCipherSpecs(ssl);
6708
        if (ret == 0) {
6709
            /* Derive the early secret using the PSK. */
6710
            ret = DeriveEarlySecret(ssl);
6711
        }
6712
        if (ret == 0) {
6713
            /* PSK negotiation has succeeded */
6714
            ssl->options.isPSK = 1;
6715
#ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
6716
            if (!ssl->options.certWithExternPsk)
6717
#endif
6718
            {
6719
                /* SERVER: using PSK for peer authentication. */
6720
                ssl->options.peerAuthGood = 1;
6721
            }
6722
        }
6723
    }
6724
6725
    *err = ret;
6726
    WOLFSSL_LEAVE("FindPsk", found);
6727
    WOLFSSL_LEAVE("FindPsk", ret);
6728
    return found;
6729
}
6730
#endif /* !NO_PSK */
6731
6732
/* Handle any Pre-Shared Key (PSK) extension.
6733
 * Find a PSK that supports the cipher suite passed in.
6734
 *
6735
 * ssl         SSL/TLS object.
6736
 * suite       Cipher suite to find PSK for.
6737
 * usingPSK    1=Indicates handshake is using Pre-Shared Keys (2=Ephemeral)
6738
 * first       Set to 1 if first in extension
6739
 * returns 0 on success and otherwise failure.
6740
 */
6741
static int DoPreSharedKeys(WOLFSSL* ssl, const byte* input, word32 inputSz,
6742
    const byte* suite, int* usingPSK, int* first)
6743
{
6744
    int           ret = 0;
6745
    TLSX*         ext;
6746
    PreSharedKey* current;
6747
    byte          binderKey[WC_MAX_DIGEST_SIZE];
6748
    byte          binder[WC_MAX_DIGEST_SIZE];
6749
    word32        binderLen;
6750
#if defined(WOLFSSL_CERT_WITH_EXTERN_PSK) && defined(HAVE_SESSION_TICKET)
6751
    int           certWithExternOffered = 0;
6752
#endif
6753
6754
    #ifdef NO_PSK
6755
        (void) suite; /* to avoid unused var warning when not used */
6756
    #endif
6757
6758
    WOLFSSL_ENTER("DoPreSharedKeys");
6759
6760
    (void)suite;
6761
6762
#ifdef WOLFSSL_CHECK_MEM_ZERO
6763
    /* Poison and register binderKey up front; every exit below (including the
6764
     * error paths) funnels through the cleanup label which zeroes it. */
6765
    XMEMSET(binderKey, 0xff, sizeof(binderKey));
6766
    wc_MemZero_Add("DoPreSharedKeys binderKey", binderKey, sizeof(binderKey));
6767
#endif
6768
6769
#if defined(HAVE_SESSION_TICKET) && defined(WOLFSSL_EARLY_DATA)
6770
    ssl->options.ticketPredatesCtx = 0;
6771
#endif
6772
6773
    ext = TLSX_Find(ssl->extensions, TLSX_PRE_SHARED_KEY);
6774
    if (ext == NULL) {
6775
        WOLFSSL_MSG("No pre shared extension keys found");
6776
        ret = BAD_FUNC_ARG;
6777
        goto cleanup;
6778
    }
6779
#if defined(WOLFSSL_CERT_WITH_EXTERN_PSK) && defined(HAVE_SESSION_TICKET)
6780
    certWithExternOffered =
6781
        TLSX_Find(ssl->extensions, TLSX_CERT_WITH_EXTERN_PSK) != NULL;
6782
#endif
6783
6784
    /* Look through all client's pre-shared keys for a match. */
6785
    for (current = (PreSharedKey*)ext->data; current != NULL;
6786
            current = current->next) {
6787
    #ifndef NO_PSK
6788
        if (current->identityLen > MAX_PSK_ID_LEN) {
6789
            ret = BUFFER_ERROR;
6790
            goto cleanup;
6791
        }
6792
        XMEMCPY(ssl->arrays->client_identity, current->identity,
6793
                current->identityLen);
6794
        ssl->arrays->client_identity[current->identityLen] = '\0';
6795
    #endif
6796
6797
    #ifdef HAVE_SESSION_TICKET
6798
        /* Decode the identity. */
6799
        switch (current->decryptRet) {
6800
            case PSK_DECRYPT_NONE:
6801
                ret = DoClientTicket_ex(ssl, current, 1);
6802
                /* psk->sess may be set. Need to clean up later. */
6803
                break;
6804
            case PSK_DECRYPT_OK:
6805
                ret = WOLFSSL_TICKET_RET_OK;
6806
                break;
6807
            case PSK_DECRYPT_CREATE:
6808
                ret = WOLFSSL_TICKET_RET_CREATE;
6809
                break;
6810
            case PSK_DECRYPT_FAIL:
6811
                ret = WOLFSSL_TICKET_RET_REJECT;
6812
                break;
6813
        }
6814
6815
        #ifdef WOLFSSL_ASYNC_CRYPT
6816
        if (ret == WC_NO_ERR_TRACE(WC_PENDING_E))
6817
            goto cleanup;
6818
        #endif
6819
6820
        if (ret != WOLFSSL_TICKET_RET_OK && current->sess_free_cb != NULL) {
6821
            current->sess_free_cb(ssl, current->sess,
6822
                    &current->sess_free_cb_ctx);
6823
            current->sess = NULL;
6824
            current->sess_free_cb = NULL;
6825
            XMEMSET(&current->sess_free_cb_ctx, 0,
6826
                    sizeof(psk_sess_free_cb_ctx));
6827
        }
6828
        if (ret == WOLFSSL_TICKET_RET_OK) {
6829
#if defined(WOLFSSL_CERT_WITH_EXTERN_PSK) && defined(HAVE_SESSION_TICKET)
6830
            /* RFC 9973 Sect. 5.1: all PSKs listed alongside
6831
             * tls_cert_with_extern_psk MUST be external PSKs.  A successfully
6832
             * decrypted session ticket identity is a resumption PSK, so the
6833
             * server MUST abort with illegal_parameter regardless of whether
6834
             * the ticket would otherwise be acceptable.  Check here, before
6835
             * DoClientTicketFinalize, to avoid polluting ssl->session with
6836
             * ticket state that will not be used. */
6837
            if (certWithExternOffered) {
6838
                if (current->sess_free_cb != NULL) {
6839
                    current->sess_free_cb(ssl, current->sess,
6840
                            &current->sess_free_cb_ctx);
6841
                    current->sess = NULL;
6842
                    current->sess_free_cb = NULL;
6843
                    XMEMSET(&current->sess_free_cb_ctx, 0,
6844
                            sizeof(psk_sess_free_cb_ctx));
6845
                }
6846
                ret = PSK_KEY_ERROR;
6847
                WOLFSSL_ERROR_VERBOSE(ret);
6848
                goto cleanup;
6849
            }
6850
#endif
6851
            ret = DoClientTicketCheck(ssl, current, ssl->timeout, suite);
6852
        #if defined(HAVE_SNI) || defined(HAVE_ALPN)
6853
            if (ret == 0) {
6854
                /* Decline this PSK if the SNI/ALPN bound to the ticket
6855
                 * does not match the current connection. RFC 6066 Sect.
6856
                 * 3 mandates this for SNI; wolfSSL applies the same
6857
                 * policy to ALPN as defense in depth. Skipping the PSK
6858
                 * (rather than aborting) lets the server try the next
6859
                 * candidate or fall back to a full handshake naturally
6860
                 * without unwinding committed PSK state. ALPN_Select
6861
                 * has already run earlier in DoTls13ClientHello so the
6862
                 * negotiated ALPN is available to TicketAlpnHash. */
6863
                byte curHash[TICKET_BINDING_HASH_SZ];
6864
            #ifdef HAVE_SNI
6865
                if (TicketSniHash(ssl, curHash) != 0 ||
6866
                        XMEMCMP(curHash, current->it->sniHash,
6867
                                TICKET_BINDING_HASH_SZ) != 0) {
6868
                    WOLFSSL_MSG("Ticket SNI mismatch, skipping PSK");
6869
                    ret = WOLFSSL_FATAL_ERROR;
6870
                }
6871
            #endif
6872
            #ifdef HAVE_ALPN
6873
                if (ret == 0 &&
6874
                        (TicketAlpnHash(ssl, curHash) != 0 ||
6875
                         XMEMCMP(curHash, current->it->alpnHash,
6876
                                 TICKET_BINDING_HASH_SZ) != 0)) {
6877
                    WOLFSSL_MSG("Ticket ALPN mismatch, skipping PSK");
6878
                    ret = WOLFSSL_FATAL_ERROR;
6879
                }
6880
            #endif
6881
            }
6882
        #endif
6883
            if (ret == 0)
6884
                DoClientTicketFinalize(ssl, current->it, current->sess);
6885
            if (current->sess_free_cb != NULL) {
6886
                current->sess_free_cb(ssl, current->sess,
6887
                        &current->sess_free_cb_ctx);
6888
                current->sess = NULL;
6889
                current->sess_free_cb = NULL;
6890
                XMEMSET(&current->sess_free_cb_ctx, 0,
6891
                        sizeof(psk_sess_free_cb_ctx));
6892
            }
6893
            if (ret != 0)
6894
                continue;
6895
6896
            /* SERVER: using secret in session ticket for peer auth. */
6897
            ssl->options.peerAuthGood = 1;
6898
6899
        #ifdef WOLFSSL_EARLY_DATA
6900
            ssl->options.maxEarlyDataSz = ssl->session->maxEarlyDataSz;
6901
            /* RFC 8446 Section 8.2: fresh servers should reject 0-RTT.
6902
             * Flag tickets minted before this ctx was created. */
6903
            if (!ssl->ctx->noFreshStartCheck) {
6904
        #ifdef WOLFSSL_32BIT_MILLI_TIME
6905
                /* A 32 bit ms clock wraps every ~49.7 days, so the ctx age is
6906
                 * only exact while it stays below the max ticket age. Past
6907
                 * that point DoClientTicketCheck has already rejected
6908
                 * anything old enough to predate the ctx, so the check can be
6909
                 * skipped.
6910
                 *
6911
                 * ctxAge is unsigned, so a clock reading before the ctx start
6912
                 * time (a backward step) wraps to just under 2^32. Letting
6913
                 * that count as an old ctx would silently disable the check
6914
                 * and admit 0-RTT for tickets minted before a restart, so the
6915
                 * near-wrap band stays in the checked range.
6916
                 *
6917
                 * The two cases are indistinguishable on a wrapping 32 bit
6918
                 * clock, so a ctx aged between (2^32 - max ticket age) and
6919
                 * 2^32 ms also lands in the band and refuses 0-RTT until it
6920
                 * wraps out. Refusing 0-RTT only costs the early data round
6921
                 * trip, so the ambiguity is resolved that way. */
6922
                word32 maxAge = (word32)TLS13_MAX_TICKET_AGE * 1000;
6923
                word32 now = TimeNowInMilliseconds();
6924
                word32 ctxAge = now - ssl->ctx->ticketStartTime;
6925
                word32 delta = ssl->ctx->ticketStartTime -
6926
                               ssl->session->ticketSeen;
6927
                ssl->options.ticketPredatesCtx =
6928
                    (now != 0 &&
6929
                     (ctxAge <= maxAge || ctxAge >= (word32)0u - maxAge) &&
6930
                     delta != 0 &&
6931
                     delta <= maxAge);
6932
        #else
6933
                ssl->options.ticketPredatesCtx =
6934
                    (ssl->session->ticketSeen < ssl->ctx->ticketStartTime);
6935
        #endif
6936
            }
6937
        #endif
6938
            /* Use the same cipher suite as before and set up for use. */
6939
            ssl->options.cipherSuite0   = ssl->session->cipherSuite0;
6940
            ssl->options.cipherSuite    = ssl->session->cipherSuite;
6941
            ret = SetCipherSpecs(ssl);
6942
            if (ret != 0)
6943
                goto cleanup;
6944
6945
            /* Resumption PSK is resumption master secret. */
6946
            ssl->arrays->psk_keySz = ssl->specs.hash_size;
6947
            if ((ret = DeriveResumptionPSK(ssl, ssl->session->ticketNonce.data,
6948
                ssl->session->ticketNonce.len, ssl->arrays->psk_key)) != 0) {
6949
                goto cleanup;
6950
            }
6951
6952
            /* Derive the early secret using the PSK. */
6953
            ret = DeriveEarlySecret(ssl);
6954
            if (ret != 0)
6955
                goto cleanup;
6956
6957
            /* Hash data up to binders for deriving binders in PSK extension.
6958
             * A pended binder derive below re-enters DoTls13ClientHello at
6959
             * TLS_ASYNC_BEGIN, so the hash is guarded to run only once. */
6960
        #ifdef WOLFSSL_ASYNC_CRYPT
6961
            if (!ssl->options.chHashInput)
6962
        #endif
6963
            {
6964
                ret = HashInput(ssl, input, (int)inputSz);
6965
                if (ret < 0)
6966
                    goto cleanup;
6967
            }
6968
        #ifdef WOLFSSL_ASYNC_CRYPT
6969
            ssl->options.chHashInput = 1;
6970
        #endif
6971
6972
            /* Derive the binder key to use with HMAC. */
6973
            ret = DeriveBinderKeyResume(ssl, binderKey);
6974
            if (ret != 0)
6975
                goto cleanup;
6976
        }
6977
        else
6978
    #endif /* HAVE_SESSION_TICKET */
6979
    #ifndef NO_PSK
6980
        if (FindPsk(ssl, current, suite, &ret)) {
6981
            if (ret != 0)
6982
                goto cleanup;
6983
6984
        #ifdef WOLFSSL_ASYNC_CRYPT
6985
            if (!ssl->options.chHashInput)
6986
        #endif
6987
            {
6988
                ret = HashInput(ssl, input, (int)inputSz);
6989
                if (ret < 0)
6990
                    goto cleanup;
6991
            }
6992
        #ifdef WOLFSSL_ASYNC_CRYPT
6993
            ssl->options.chHashInput = 1;
6994
        #endif
6995
6996
            /* Derive the binder key to use with HMAC. */
6997
            ret = DeriveBinderKey(ssl, binderKey);
6998
            if (ret != 0)
6999
                goto cleanup;
7000
        }
7001
        else
7002
    #endif
7003
        {
7004
            continue;
7005
        }
7006
7007
        ssl->options.sendVerify = 0;
7008
7009
        /* Derive the Finished message secret. */
7010
        ret = DeriveFinishedSecret(ssl, binderKey,
7011
                                   ssl->keys.client_write_MAC_secret,
7012
                                   0 /* neither end */);
7013
        if (ret != 0)
7014
            goto cleanup;
7015
7016
        /* Derive the binder and compare with the one in the extension. */
7017
        ret = BuildTls13HandshakeHmac(ssl,
7018
                         ssl->keys.client_write_MAC_secret, binder, &binderLen);
7019
        if (ret != 0)
7020
            goto cleanup;
7021
        if (binderLen != current->binderLen ||
7022
                             ConstantCompare(binder, current->binder,
7023
                                binderLen) != 0) {
7024
            WOLFSSL_ERROR_VERBOSE(BAD_BINDER);
7025
            ret = BAD_BINDER;
7026
            goto cleanup;
7027
        }
7028
7029
        /* This PSK works, no need to try any more. */
7030
        current->chosen = 1;
7031
        ext->resp = 1;
7032
        break;
7033
    }
7034
7035
    if (current == NULL) {
7036
        ret = 0;
7037
        goto cleanup;
7038
    }
7039
7040
    *first = (current == ext->data);
7041
    *usingPSK = 1;
7042
7043
cleanup:
7044
    ForceZero(binderKey, sizeof(binderKey));
7045
    ForceZero(binder, sizeof(binder));
7046
#ifdef WOLFSSL_CHECK_MEM_ZERO
7047
    wc_MemZero_Check(binderKey, sizeof(binderKey));
7048
#endif
7049
    WOLFSSL_LEAVE("DoPreSharedKeys", ret);
7050
7051
    return ret;
7052
}
7053
7054
/* Check whether a PSK may be used given the key exchange modes the client
7055
 * advertised and the modes this server is configured to allow.
7056
 *
7057
 * RFC 9846 Section 4.3.9 forbids selecting a mode the client did not list.
7058
 * Section 4.3.11 says a server that finds no acceptable PSK should perform a
7059
 * non-PSK handshake instead of aborting. Deciding before a PSK is selected
7060
 * leaves nothing to unwind: no ticket is decrypted, no binder is verified, no
7061
 * secret is derived and no early data is accepted.
7062
 *
7063
 * The configured policy is read, not ssl->options.noPskDheKe, which also
7064
 * carries negotiated state and is cleared by every certificate handshake.
7065
 *
7066
 * ssl         SSL/TLS object.
7067
 * clSuites    Client's cipher suite list.
7068
 * returns 1 when PSK selection may proceed and 0 when the PSK must be ignored.
7069
 */
7070
static int PskModesUsable(const WOLFSSL* ssl, const Suites* clSuites)
7071
228
{
7072
228
#ifdef HAVE_SUPPORTED_CURVES
7073
228
    TLSX*  ext;
7074
228
    word32 modes;
7075
7076
    /* Offering pre_shared_key without psk_key_exchange_modes is a MUST-level
7077
     * abort (Section 4.3.9). Leave it to CheckPreSharedKeys. */
7078
228
    ext = TLSX_Find(ssl->extensions, TLSX_PSK_KEY_EXCHANGE_MODES);
7079
228
    if (ext == NULL)
7080
121
        return 1;
7081
107
    modes = ext->val;
7082
7083
#ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
7084
    /* RFC 9973 requires psk_dhe_ke and overrides the no-(EC)DHE policy, so a
7085
     * mismatch must abort rather than fall back. */
7086
    if (TLSX_Find(ssl->extensions, TLSX_CERT_WITH_EXTERN_PSK) != NULL)
7087
        return 1;
7088
#endif
7089
7090
    /* Only decline when a certificate handshake can actually run instead.
7091
     * These are the same two things DoTls13ClientHello() requires of a
7092
     * ClientHello that negotiates no PSK. */
7093
107
    if (TLSX_Find(ssl->extensions, TLSX_KEY_SHARE) == NULL)
7094
11
        return 1;
7095
96
    if (clSuites == NULL || clSuites->hashSigAlgoSz == 0)
7096
5
        return 1;
7097
7098
91
    if ((modes & (1 << PSK_DHE_KE)) != 0 && !ssl->options.noPskDheKePolicy)
7099
0
        return 1;
7100
91
    if (ssl->options.onlyPskDheKe)
7101
0
        return 0;
7102
91
    return (modes & (1 << PSK_KE)) != 0;
7103
#else
7104
    /* Without (EC)DHE there is no certificate handshake to fall back to. */
7105
    (void)ssl;
7106
    (void)clSuites;
7107
    return 1;
7108
#endif
7109
91
}
7110
7111
/* Handle any Pre-Shared Key (PSK) extension.
7112
 * Must do this in ClientHello as it requires a hash of the truncated message.
7113
 * Don't know size of binders until Pre-Shared Key extension has been parsed.
7114
 *
7115
 * ssl         SSL/TLS object.
7116
 * input       ClientHello message.
7117
 * helloSz     Size of the ClientHello message (including binders if present).
7118
 * clSuites    Client's cipher suite list.
7119
 * usingPSK    Indicates handshake is using Pre-Shared Keys.
7120
 */
7121
static int CheckPreSharedKeys(WOLFSSL* ssl, const byte* input, word32 helloSz,
7122
                              Suites* clSuites, int* usingPSK)
7123
0
{
7124
0
    int    ret;
7125
0
    TLSX*  ext;
7126
0
    word16 bindersLen;
7127
0
    int    first = 0;
7128
0
    int    usePsk;
7129
0
#ifndef WOLFSSL_PSK_ONE_ID
7130
0
    int    i;
7131
0
    const Suites* suites;
7132
#else
7133
    byte   suite[2];
7134
#endif
7135
7136
0
    WOLFSSL_ENTER("CheckPreSharedKeys");
7137
7138
0
    ext = TLSX_Find(ssl->extensions, TLSX_PRE_SHARED_KEY);
7139
0
    if (ext == NULL) {
7140
#ifdef WOLFSSL_EARLY_DATA
7141
        ssl->earlyData = no_early_data;
7142
#endif
7143
0
        if (usingPSK)
7144
0
            *usingPSK = 0;
7145
7146
        /* No PSK extension at all: if a mandatory external PSK is configured,
7147
         * refuse the connection rather than continue without one. havePSK is
7148
         * only set by an external-PSK callback, so a peer relying solely on
7149
         * session-ticket resumption is unaffected. */
7150
0
        if (ssl->options.havePSK && ssl->options.failNoPSK) {
7151
0
            WOLFSSL_ERROR_VERBOSE(PSK_MISSING_ERROR);
7152
0
            return PSK_MISSING_ERROR;
7153
0
        }
7154
7155
        /* Hash data up to binders for deriving binders in PSK extension. */
7156
0
        ret = HashInput(ssl, input,  (int)helloSz);
7157
0
        return ret;
7158
0
    }
7159
7160
    /* Wire-order check that PSK was the last extension in ClientHello is
7161
     * performed in DoTls13ClientHello immediately after TLSX_Parse, since
7162
     * post-parse code (e.g. ALPN_Select via TLSX_SetALPN) may legitimately
7163
     * prepend new entries to ssl->extensions before this point and would
7164
     * otherwise trip a head-of-list check here. */
7165
7166
    /* Assume we are going to resume with a pre-shared key. */
7167
0
    ssl->options.resuming = 1;
7168
7169
    /* Find the pre-shared key extension and calculate hash of truncated
7170
     * ClientHello for binders.
7171
     */
7172
0
    ret = TLSX_PreSharedKey_GetSizeBinders((PreSharedKey*)ext->data,
7173
0
                                                     client_hello, &bindersLen);
7174
0
    if (ret < 0)
7175
0
        return ret;
7176
0
    if (bindersLen > helloSz)
7177
0
        return BUFFER_ERROR;
7178
7179
    /* Refine list for PSK processing. */
7180
0
    sslRefineSuites(ssl, clSuites);
7181
7182
0
    usePsk = PskModesUsable(ssl, clSuites);
7183
0
    if (!usePsk) {
7184
0
        WOLFSSL_MSG("No usable psk_key_exchange_modes, ignoring PSK");
7185
0
    }
7186
7187
0
#ifndef WOLFSSL_PSK_ONE_ID
7188
0
    if (usingPSK == NULL)
7189
0
        return BAD_FUNC_ARG;
7190
7191
    /* set after refineSuites, to avoid taking a stale ptr to ctx->Suites */
7192
0
    suites = WOLFSSL_SUITES(ssl);
7193
    /* Server list has only common suites from refining in server or client
7194
     * order. */
7195
0
    for (i = 0; usePsk && !(*usingPSK) && i < suites->suiteSz; i += 2) {
7196
0
        ret = DoPreSharedKeys(ssl, input, helloSz - bindersLen,
7197
0
                suites->suites + i, usingPSK, &first);
7198
0
        if (ret != 0) {
7199
0
#ifdef HAVE_SESSION_TICKET
7200
#ifdef WOLFSSL_ASYNC_CRYPT
7201
            if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
7202
#endif
7203
0
                CleanupClientTickets((PreSharedKey*)ext->data);
7204
0
#endif
7205
0
            WOLFSSL_MSG_EX("DoPreSharedKeys: %d", ret);
7206
0
            return ret;
7207
0
        }
7208
0
    }
7209
0
#ifdef HAVE_SESSION_TICKET
7210
0
    CleanupClientTickets((PreSharedKey*)ext->data);
7211
0
#endif
7212
#else
7213
    if (usePsk) {
7214
        ret = DoPreSharedKeys(ssl, input, helloSz - bindersLen, suite, usingPSK,
7215
            &first);
7216
        if (ret != 0) {
7217
            WOLFSSL_MSG_EX("DoPreSharedKeys: %d", ret);
7218
            return ret;
7219
        }
7220
    }
7221
#endif
7222
7223
0
    if (!*usingPSK) {
7224
        /* No suitable PSK was negotiated. When a mandatory external PSK is
7225
         * configured, fail with a dedicated error instead of falling back to a
7226
         * certificate handshake. This must run before the no-certificate
7227
         * BAD_BINDER check below so a PSK-only server (no cert) still reports
7228
         * PSK_MISSING_ERROR. havePSK is only set by an external-PSK callback, so
7229
         * a peer relying solely on session-ticket resumption is unaffected. */
7230
0
        if (ssl->options.havePSK && ssl->options.failNoPSK) {
7231
0
            WOLFSSL_ERROR_VERBOSE(PSK_MISSING_ERROR);
7232
0
            return PSK_MISSING_ERROR;
7233
0
        }
7234
0
    #ifndef NO_CERTS
7235
0
        if (ssl->buffers.certificate == NULL
7236
0
        #ifdef WOLFSSL_CERT_SETUP_CB
7237
0
                && ssl->ctx->certSetupCb == NULL
7238
0
        #endif
7239
0
                )
7240
0
    #endif
7241
0
        {
7242
            /* Reused for identity protection: an unknown identity must look
7243
             * like a bad binder, so keep the error code shared. */
7244
0
            WOLFSSL_ERROR_VERBOSE(BAD_BINDER);
7245
0
            return BAD_BINDER;
7246
0
        }
7247
0
    }
7248
7249
0
    if (*usingPSK) {
7250
        /* While verifying the selected PSK, we updated the
7251
         * handshake hash up to the binder bytes in the PSK extensions.
7252
         * Continuing, we need the rest of the ClientHello hashed as well.
7253
         */
7254
0
        ret = HashRaw(ssl, input + helloSz - bindersLen, bindersLen);
7255
0
    }
7256
0
    else {
7257
        /* No suitable PSK found, Hash the complete ClientHello,
7258
         * as caller expect it after we return */
7259
0
        ret = HashInput(ssl, input,  (int)helloSz);
7260
0
    }
7261
0
    if (ret != 0)
7262
0
        return ret;
7263
7264
0
    if (*usingPSK != 0) {
7265
0
        word32 modes;
7266
#ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
7267
        int usingCertWithExternPsk = 0;
7268
        TLSX* certExt = NULL;
7269
        TLSX* pskExt = NULL;
7270
        PreSharedKey* chosenPsk = NULL;
7271
#endif
7272
    #ifdef WOLFSSL_EARLY_DATA
7273
        TLSX*  extEarlyData;
7274
    #ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
7275
        int hasCertWithExternPsk = (TLSX_Find(ssl->extensions,
7276
                                    TLSX_CERT_WITH_EXTERN_PSK) != NULL);
7277
    #endif
7278
7279
        extEarlyData = TLSX_Find(ssl->extensions, TLSX_EARLY_DATA);
7280
        if (extEarlyData != NULL) {
7281
            /* Check if accepting early data and first PSK.
7282
             * RFC 9973: early_data is not compatible with
7283
             * cert_with_extern_psk, so skip key derivation in that case. */
7284
            if (ssl->earlyData != no_early_data && first
7285
                && ssl->options.maxEarlyDataSz > 0
7286
    #ifdef HAVE_SESSION_TICKET
7287
                /* RFC 8446 section 8.2: freshly started servers should
7288
                 * reject 0-RTT. Tickets minted before this ctx was created
7289
                 * belong to a previous instance. */
7290
                && !ssl->options.ticketPredatesCtx
7291
    #endif
7292
    #ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
7293
                && !hasCertWithExternPsk
7294
    #endif
7295
    #if defined(HAVE_SESSION_TICKET) && !defined(NO_SESSION_CACHE)
7296
                /* RFC 8446 section 8: evict the session from the cache.
7297
                 * Accept 0-RTT only when the eviction found the entry
7298
                 * (single-use). */
7299
                && wolfSSL_SSL_CTX_remove_session(ssl->ctx, ssl->session)
7300
                    == 1
7301
    #endif
7302
            ) {
7303
                extEarlyData->resp = 1;
7304
7305
                /* Derive early data decryption key. */
7306
                ret = DeriveTls13Keys(ssl, early_data_key, DECRYPT_SIDE_ONLY,
7307
                                                                             1);
7308
                if (ret != 0)
7309
                    return ret;
7310
                if ((ret = SetKeysSide(ssl, DECRYPT_SIDE_ONLY)) != 0)
7311
                    return ret;
7312
7313
                ssl->keys.encryptionOn = 1;
7314
                ssl->earlyData = process_early_data;
7315
            }
7316
            else
7317
                extEarlyData->resp = 0;
7318
        }
7319
    #endif
7320
7321
        /* Get the PSK key exchange modes the client wants to negotiate. */
7322
0
        ext = TLSX_Find(ssl->extensions, TLSX_PSK_KEY_EXCHANGE_MODES);
7323
0
        if (ext == NULL) {
7324
0
            WOLFSSL_ERROR_VERBOSE(MISSING_HANDSHAKE_DATA);
7325
0
            return MISSING_HANDSHAKE_DATA;
7326
0
        }
7327
0
        modes = ext->val;
7328
7329
    #ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
7330
        certExt = TLSX_Find(ssl->extensions, TLSX_CERT_WITH_EXTERN_PSK);
7331
        if (certExt != NULL) {
7332
            pskExt = TLSX_Find(ssl->extensions, TLSX_PRE_SHARED_KEY);
7333
            if (pskExt != NULL)
7334
                chosenPsk = (PreSharedKey*)pskExt->data;
7335
            while (chosenPsk != NULL && !chosenPsk->chosen)
7336
                chosenPsk = chosenPsk->next;
7337
            if (chosenPsk == NULL || chosenPsk->resumption) {
7338
                WOLFSSL_ERROR_VERBOSE(PSK_KEY_ERROR);
7339
                return PSK_KEY_ERROR;
7340
            }
7341
            if ((modes & (1 << PSK_DHE_KE)) == 0) {
7342
                WOLFSSL_ERROR_VERBOSE(PSK_KEY_ERROR);
7343
                return PSK_KEY_ERROR;
7344
            }
7345
            usingCertWithExternPsk = 1;
7346
            ssl->options.certWithExternPsk = 1;
7347
            if (clSuites->hashSigAlgoSz == 0) {
7348
                WOLFSSL_ERROR_VERBOSE(MISSING_HANDSHAKE_DATA);
7349
                return MISSING_HANDSHAKE_DATA;
7350
            }
7351
            ret = PickHashSigAlgo(ssl, clSuites->hashSigAlgo,
7352
                                  clSuites->hashSigAlgoSz, 1);
7353
            if (ret != 0)
7354
                return ret;
7355
            ssl->options.sendVerify = SEND_CERT;
7356
            certExt->resp = 1;
7357
        #ifdef WOLFSSL_EARLY_DATA
7358
            /* RFC 9973: early_data is not compatible with
7359
             * cert_with_extern_psk.  TLSX_Parse already rejects the
7360
             * combination in the ClientHello, but clear the response flag
7361
             * here as a defense-in-depth measure. */
7362
            if (extEarlyData != NULL) {
7363
                WOLFSSL_MSG("Rejecting early data: "
7364
                            "cert_with_extern_psk is not 0-RTT compatible");
7365
                extEarlyData->resp = 0;
7366
                ssl->earlyData = no_early_data;
7367
            }
7368
        #endif
7369
        }
7370
        else {
7371
            ssl->options.certWithExternPsk = 0;
7372
        }
7373
    #endif
7374
7375
#ifndef HAVE_SUPPORTED_CURVES
7376
    #ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
7377
        if (usingCertWithExternPsk) {
7378
            WOLFSSL_ERROR_VERBOSE(PSK_KEY_ERROR);
7379
            return PSK_KEY_ERROR;
7380
        }
7381
    #endif
7382
#endif
7383
0
    #ifdef HAVE_SUPPORTED_CURVES
7384
0
        ext = TLSX_Find(ssl->extensions, TLSX_KEY_SHARE);
7385
        /* Use (EC)DHE for forward-security if possible. */
7386
0
        if (((modes & (1 << PSK_DHE_KE)) != 0 &&
7387
0
             !ssl->options.noPskDheKePolicy && ext != NULL)
7388
#ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
7389
             || usingCertWithExternPsk
7390
#endif
7391
0
        ) {
7392
0
            if (ext == NULL) {
7393
0
                WOLFSSL_ERROR_VERBOSE(EXT_MISSING);
7394
0
                return EXT_MISSING;
7395
0
            }
7396
            /* Resumption path uses previous session group. */
7397
#ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
7398
            if (!usingCertWithExternPsk)
7399
#endif
7400
0
                ssl->namedGroup = ssl->session->namedGroup;
7401
0
            *usingPSK = 2; /* generate new ephemeral key */
7402
0
        }
7403
0
        else if (ssl->options.onlyPskDheKe ||
7404
0
                 (ssl->options.failNoPSK && !ssl->options.resuming)) {
7405
            /* A mandatory external PSK (failNoPSK) must be combined with
7406
             * (EC)DHE for forward secrecy, so reject a pure psk_ke
7407
             * negotiation. Session-ticket resumption is exempt.
7408
             * onlyPskDheKe only reaches here when PskModesUsable() could not
7409
             * decline, i.e. there is no certificate handshake to fall back
7410
             * to. */
7411
0
            WOLFSSL_ERROR_VERBOSE(PSK_KEY_ERROR);
7412
0
            return PSK_KEY_ERROR;
7413
0
        }
7414
0
        else
7415
0
    #endif
7416
0
        {
7417
0
            if ((modes & (1 << PSK_KE)) == 0) {
7418
0
                WOLFSSL_MSG("psk_ke mode does not allow key share");
7419
0
                WOLFSSL_ERROR_VERBOSE(PSK_KEY_ERROR);
7420
0
                return PSK_KEY_ERROR;
7421
0
            }
7422
0
            ssl->options.noPskDheKe = 1;
7423
0
            ssl->arrays->preMasterSz = 0;
7424
7425
0
            *usingPSK = 1;
7426
0
        }
7427
0
    }
7428
0
    else {
7429
#ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
7430
        /* If no PSK is found, we remove the extension to make sure it
7431
         * is not sent back to the client */
7432
        TLSX_Remove(&ssl->extensions, TLSX_CERT_WITH_EXTERN_PSK, ssl->heap);
7433
        ssl->options.certWithExternPsk = 0;
7434
#endif
7435
        /* No PSK negotiated; the check above already aborted when there is no
7436
         * certificate. Fall through so the trace is emitted here too. */
7437
0
    }
7438
7439
0
    WOLFSSL_LEAVE("CheckPreSharedKeys", ret);
7440
7441
0
    return 0;
7442
0
}
7443
#endif /* HAVE_SESSION_TICKET || !NO_PSK */
7444
7445
#if defined(WOLFSSL_SEND_HRR_COOKIE)
7446
/* Compute the cookie integrity HMAC over the cookie data (and, for DTLS, the
7447
 * peer address) using the given secret and compare it in constant time against
7448
 * the MAC trailing the cookie.
7449
 *
7450
 * ssl        SSL/TLS object.
7451
 * cookie     The cookie data - hash and MAC.
7452
 * dataSz     Length of the cookie data preceding the trailing MAC.
7453
 * secret     Secret to key the HMAC with.
7454
 * secretSz   Length of the secret in bytes.
7455
 * cookieType Digest type to use for the HMAC.
7456
 * macSz      Length of the MAC in bytes.
7457
 * returns 0 on match, HRR_COOKIE_ERROR on mismatch, otherwise a negative error.
7458
 */
7459
static int TlsCheckCookieMac(const WOLFSSL* ssl, const byte* cookie,
7460
    word16 dataSz, const byte* secret, word32 secretSz, byte cookieType,
7461
    byte macSz)
7462
{
7463
    int  ret;
7464
    byte mac[WC_MAX_DIGEST_SIZE] = {0};
7465
    WC_DECLARE_VAR(cookieHmac, Hmac, 1, ssl->heap);
7466
7467
    WC_ALLOC_VAR_EX(cookieHmac, Hmac, 1, ssl->heap, DYNAMIC_TYPE_HMAC,
7468
                    return MEMORY_E);
7469
7470
    ret = wc_HmacInit(cookieHmac, ssl->heap, ssl->devId);
7471
    if (ret == 0)
7472
        ret = wc_HmacSetKey(cookieHmac, cookieType, secret, secretSz);
7473
    if (ret == 0)
7474
        ret = wc_HmacUpdate(cookieHmac, cookie, dataSz);
7475
#ifdef WOLFSSL_DTLS13
7476
    /* Tie cookie to peer address */
7477
    if (ret == 0) {
7478
        /* peerLock not necessary. Still in handshake phase. */
7479
        if (ssl->options.dtls && ssl->buffers.dtlsCtx.peer.sz > 0) {
7480
            ret = wc_HmacUpdate(cookieHmac,
7481
                (byte*)ssl->buffers.dtlsCtx.peer.sa,
7482
                ssl->buffers.dtlsCtx.peer.sz);
7483
        }
7484
    }
7485
#endif
7486
    if (ret == 0)
7487
        ret = wc_HmacFinal(cookieHmac, mac);
7488
7489
    wc_HmacFree(cookieHmac);
7490
    WC_FREE_VAR_EX(cookieHmac, ssl->heap, DYNAMIC_TYPE_HMAC);
7491
    if (ret != 0)
7492
        return ret;
7493
7494
    if (ConstantCompare(cookie + dataSz, mac, macSz) != 0)
7495
        return HRR_COOKIE_ERROR;
7496
7497
    return 0;
7498
}
7499
7500
/* Check that the Cookie data's integrity.
7501
 *
7502
 * ssl       SSL/TLS object.
7503
 * cookie    The cookie data - hash and MAC.
7504
 * cookieSz  The length of the cookie data in bytes.
7505
 * returns Length of the hash on success, otherwise failure.
7506
 */
7507
int TlsCheckCookie(const WOLFSSL* ssl, const byte* cookie, word16 cookieSz)
7508
{
7509
    int  ret;
7510
    byte cookieType = 0;
7511
    byte macSz = 0;
7512
7513
#ifndef NO_SHA256
7514
    cookieType = WC_SHA256;
7515
    macSz = WC_SHA256_DIGEST_SIZE;
7516
#elif defined(WOLFSSL_SHA384)
7517
    cookieType = WC_SHA384;
7518
    macSz = WC_SHA384_DIGEST_SIZE;
7519
#elif defined(WOLFSSL_TLS13_SHA512)
7520
    cookieType = WC_SHA512;
7521
    macSz = WC_SHA512_DIGEST_SIZE;
7522
#elif defined(WOLFSSL_SM3)
7523
    cookieType = WC_SM3;
7524
    macSz = WC_SM3_DIGEST_SIZE;
7525
#else
7526
    #error "No digest to available to use with HMAC for cookies."
7527
#endif /* NO_SHA */
7528
7529
    if ((ssl->buffers.tls13CookieSecret.buffer == NULL ||
7530
            ssl->buffers.tls13CookieSecret.length == 0)
7531
#ifdef WOLFSSL_DTLS13
7532
        && (ssl->buffers.tls13CookieSecretSecondary.buffer == NULL ||
7533
            ssl->buffers.tls13CookieSecretSecondary.length == 0)
7534
#endif
7535
        ) {
7536
        WOLFSSL_MSG("Missing DTLS 1.3 cookie secret");
7537
        return COOKIE_ERROR;
7538
    }
7539
7540
    if (cookieSz < ssl->specs.hash_size + macSz)
7541
        return HRR_COOKIE_ERROR;
7542
    cookieSz -= macSz;
7543
7544
    /* Verify against the primary secret first.  If that fails and a secondary
7545
     * (verify-only) secret is configured, try that too.  This lets a stateless
7546
     * DTLS 1.3 server keep accepting cookies issued under the secret it held
7547
     * before an application-driven secret rotation.  The secondary secret is
7548
     * DTLS 1.3 only, so its verify path is compiled in only for WOLFSSL_DTLS13. */
7549
    ret = WC_NO_ERR_TRACE(HRR_COOKIE_ERROR);
7550
    if (ssl->buffers.tls13CookieSecret.buffer != NULL &&
7551
            ssl->buffers.tls13CookieSecret.length > 0) {
7552
        ret = TlsCheckCookieMac(ssl, cookie, cookieSz,
7553
            ssl->buffers.tls13CookieSecret.buffer,
7554
            ssl->buffers.tls13CookieSecret.length, cookieType, macSz);
7555
        if (ret != 0 && ret != WC_NO_ERR_TRACE(HRR_COOKIE_ERROR))
7556
            return ret;
7557
    }
7558
#ifdef WOLFSSL_DTLS13
7559
    if (ret == WC_NO_ERR_TRACE(HRR_COOKIE_ERROR) &&
7560
            ssl->buffers.tls13CookieSecretSecondary.buffer != NULL &&
7561
            ssl->buffers.tls13CookieSecretSecondary.length > 0) {
7562
        ret = TlsCheckCookieMac(ssl, cookie, cookieSz,
7563
            ssl->buffers.tls13CookieSecretSecondary.buffer,
7564
            ssl->buffers.tls13CookieSecretSecondary.length, cookieType, macSz);
7565
        if (ret != 0 && ret != WC_NO_ERR_TRACE(HRR_COOKIE_ERROR))
7566
            return ret;
7567
    }
7568
#endif
7569
7570
    if (ret != 0) {
7571
        WOLFSSL_ERROR_VERBOSE(HRR_COOKIE_ERROR);
7572
        return HRR_COOKIE_ERROR;
7573
    }
7574
7575
    return cookieSz;
7576
}
7577
7578
/* Length of the KeyShare Extension */
7579
#define HRR_KEY_SHARE_SZ   (OPAQUE16_LEN + OPAQUE16_LEN + OPAQUE16_LEN)
7580
/* Length of the Supported Versions Extension */
7581
#define HRR_VERSIONS_SZ    (OPAQUE16_LEN + OPAQUE16_LEN + OPAQUE16_LEN)
7582
/* Length of the Cookie Extension excluding cookie data */
7583
#define HRR_COOKIE_HDR_SZ  (OPAQUE16_LEN + OPAQUE16_LEN + OPAQUE16_LEN)
7584
/* PV | Random | Session Id | CipherSuite | Compression | Ext Len */
7585
#define HRR_BODY_SZ        (VERSION_SZ + RAN_LEN + ENUM_LEN + ID_LEN + \
7586
                            SUITE_LEN + COMP_LEN + OPAQUE16_LEN)
7587
/* HH | PV | CipherSuite | Ext Len | Key Share | Supported Version | Cookie */
7588
#define MAX_HRR_SZ   (HRR_MAX_HS_HEADER_SZ   + \
7589
                        HRR_BODY_SZ         + \
7590
                          HRR_KEY_SHARE_SZ  + \
7591
                          HRR_VERSIONS_SZ   + \
7592
                          HRR_COOKIE_HDR_SZ)
7593
7594
7595
/* Restart the handshake hash from the cookie value.
7596
 *
7597
 * ssl     SSL/TLS object.
7598
 * cookie  Cookie data from client.
7599
 * returns 0 on success, otherwise failure.
7600
 */
7601
static int RestartHandshakeHashWithCookie(WOLFSSL* ssl, Cookie* cookie)
7602
{
7603
    byte   header[HANDSHAKE_HEADER_SZ] = {0};
7604
    byte   hrr[MAX_HRR_SZ] = {0};
7605
    int    hrrIdx;
7606
    word32 idx;
7607
    byte   hashSz;
7608
    byte*  cookieData;
7609
    word16 cookieDataSz;
7610
    word16 length;
7611
    int    keyShareExt = 0;
7612
    int    ret;
7613
    byte   sessIdSz;
7614
7615
    ret = TlsCheckCookie(ssl, cookie->data, cookie->len);
7616
    if (ret < 0)
7617
        return ret;
7618
    cookieDataSz = (word16)ret;
7619
    hashSz = cookie->data[0];
7620
    cookieData = cookie->data;
7621
    idx = OPAQUE8_LEN;
7622
7623
    /* Restart handshake hash with synthetic message hash. */
7624
    AddTls13HandShakeHeader(header, hashSz, 0, 0, message_hash, ssl);
7625
7626
    if ((ret = InitHandshakeHashes(ssl)) != 0)
7627
        return ret;
7628
    if ((ret = HashRaw(ssl, header, sizeof(header))) != 0)
7629
        return ret;
7630
#ifdef WOLFSSL_DEBUG_TLS
7631
    WOLFSSL_MSG("Restart Hash from Cookie");
7632
    WOLFSSL_BUFFER(cookieData + idx, hashSz);
7633
#endif
7634
    if ((ret = HashRaw(ssl, cookieData + idx, hashSz)) != 0)
7635
        return ret;
7636
7637
    /* Reconstruct the HelloRetryMessage for handshake hash. */
7638
    sessIdSz = ssl->session->sessionIDSz;
7639
#if defined(WOLFSSL_DTLS13) && !defined(WOLFSSL_DTLS13_ECHO_LEGACY_SESSION_ID)
7640
    /* RFC 9147 Section 5: a DTLS 1.3 server does not echo the session ID, so
7641
     * the reconstructed transcript must not carry one either. */
7642
    if (ssl->options.dtls)
7643
        sessIdSz = 0;
7644
#endif
7645
    length = HRR_BODY_SZ - ID_LEN + sessIdSz +
7646
             HRR_COOKIE_HDR_SZ + cookie->len;
7647
    length += HRR_VERSIONS_SZ;
7648
    /* HashSz (1 byte) + Hash (HashSz bytes) + CipherSuite (2 bytes) */
7649
    if (cookieDataSz > OPAQUE8_LEN + hashSz + OPAQUE16_LEN) {
7650
        keyShareExt = 1;
7651
        length += HRR_KEY_SHARE_SZ;
7652
    }
7653
7654
    AddTls13HandShakeHeader(hrr, length, 0, 0, server_hello, ssl);
7655
7656
    idx += hashSz;
7657
    hrrIdx = HANDSHAKE_HEADER_SZ;
7658
7659
#ifdef WOLFSSL_DTLS13
7660
    if (ssl->options.dtls)
7661
        hrrIdx += DTLS_HANDSHAKE_EXTRA;
7662
#endif /* WOLFSSL_DTLS13 */
7663
7664
    /* The negotiated protocol version. */
7665
    hrr[hrrIdx++] = ssl->version.major;
7666
    hrr[hrrIdx++] = ssl->options.dtls ? DTLSv1_2_MINOR : TLSv1_2_MINOR;
7667
7668
    /* HelloRetryRequest message has fixed value for random. */
7669
    XMEMCPY(hrr + hrrIdx, helloRetryRequestRandom, RAN_LEN);
7670
    hrrIdx += RAN_LEN;
7671
7672
    hrr[hrrIdx++] = sessIdSz;
7673
    if (sessIdSz > 0) {
7674
        XMEMCPY(hrr + hrrIdx, ssl->session->sessionID, sessIdSz);
7675
        hrrIdx += sessIdSz;
7676
    }
7677
7678
    /* Restore the cipher suite from the cookie. */
7679
    ssl->options.hrrCipherSuite0 = cookieData[idx];
7680
    hrr[hrrIdx++] = cookieData[idx++];
7681
    ssl->options.hrrCipherSuite  = cookieData[idx];
7682
    hrr[hrrIdx++] = cookieData[idx++];
7683
7684
    /* Compression not supported in TLS v1.3. */
7685
    hrr[hrrIdx++] = 0;
7686
7687
    /* Extensions' length */
7688
    length -= HRR_BODY_SZ - ID_LEN + sessIdSz;
7689
    c16toa(length, hrr + hrrIdx);
7690
    hrrIdx += 2;
7691
7692
    /* Optional KeyShare Extension */
7693
    if (keyShareExt) {
7694
        c16toa(TLSX_KEY_SHARE, hrr + hrrIdx);
7695
        hrrIdx += 2;
7696
        c16toa(OPAQUE16_LEN, hrr + hrrIdx);
7697
        hrrIdx += 2;
7698
        /* Restore the HRR key share group from the cookie. */
7699
        ato16(cookieData + idx, &ssl->hrr_keyshare_group);
7700
        hrr[hrrIdx++] = cookieData[idx++];
7701
        hrr[hrrIdx++] = cookieData[idx++];
7702
    }
7703
    c16toa(TLSX_SUPPORTED_VERSIONS, hrr + hrrIdx);
7704
    hrrIdx += 2;
7705
    c16toa(OPAQUE16_LEN, hrr + hrrIdx);
7706
    hrrIdx += 2;
7707
    #ifdef WOLFSSL_TLS13_DRAFT
7708
        hrr[hrrIdx++] = TLS_DRAFT_MAJOR;
7709
        hrr[hrrIdx++] = TLS_DRAFT_MINOR;
7710
    #else
7711
        hrr[hrrIdx++] = ssl->version.major;
7712
        hrr[hrrIdx++] = ssl->version.minor;
7713
    #endif
7714
7715
    /* Mandatory Cookie Extension */
7716
    c16toa(TLSX_COOKIE, hrr + hrrIdx);
7717
    hrrIdx += 2;
7718
    c16toa(cookie->len + OPAQUE16_LEN, hrr + hrrIdx);
7719
    hrrIdx += 2;
7720
    c16toa(cookie->len, hrr + hrrIdx);
7721
    hrrIdx += 2;
7722
7723
#ifdef WOLFSSL_DEBUG_TLS
7724
    WOLFSSL_MSG("Reconstructed HelloRetryRequest");
7725
    WOLFSSL_BUFFER(hrr, hrrIdx);
7726
    WOLFSSL_MSG("Cookie");
7727
    WOLFSSL_BUFFER(cookieData, cookie->len);
7728
#endif
7729
7730
#ifdef WOLFSSL_DTLS13
7731
    if (ssl->options.dtls) {
7732
        ret = Dtls13HashHandshake(ssl, hrr, (word16)hrrIdx);
7733
    }
7734
    else
7735
#endif /* WOLFSSL_DTLS13 */
7736
        {
7737
            ret = HashRaw(ssl, hrr, hrrIdx);
7738
        }
7739
7740
    if (ret != 0)
7741
        return ret;
7742
7743
    return HashRaw(ssl, cookieData, cookie->len);
7744
}
7745
#endif
7746
7747
/* Do SupportedVersion extension for TLS v1.3+ otherwise it is not.
7748
 *
7749
 * ssl       The SSL/TLS object.
7750
 * input     The message buffer.
7751
 * i         The index into the message buffer of ClientHello.
7752
 * helloSz   The length of the current handshake message.
7753
 * returns 0 on success and otherwise failure.
7754
 */
7755
static int DoTls13SupportedVersions(WOLFSSL* ssl, const byte* input, word32 i,
7756
                                    word32 helloSz, int* wantDowngrade)
7757
{
7758
    int    ret;
7759
    byte   b;
7760
    word16 suiteSz;
7761
    word16 totalExtSz;
7762
    int    foundVersion = 0;
7763
7764
    /* Client random */
7765
    i += RAN_LEN;
7766
7767
    if (i > helloSz)
7768
        return BUFFER_ERROR;
7769
    /* Session id - not used in TLS v1.3 */
7770
    if (helloSz - i < OPAQUE8_LEN) {
7771
        return BUFFER_ERROR;
7772
    }
7773
    b = input[i++];
7774
    if (b > helloSz - i) {
7775
        return BUFFER_ERROR;
7776
    }
7777
    i += b;
7778
#ifdef WOLFSSL_DTLS13
7779
    if (ssl->options.dtls) {
7780
        /* legacy_cookie - not used in DTLS v1.3 */
7781
        if (helloSz - i < OPAQUE8_LEN) {
7782
            return BUFFER_ERROR;
7783
        }
7784
        b = input[i++];
7785
        if (b > helloSz - i) {
7786
            return BUFFER_ERROR;
7787
        }
7788
        i += b;
7789
    }
7790
#endif /* WOLFSSL_DTLS13 */
7791
    /* Cipher suites */
7792
    if (helloSz - i < OPAQUE16_LEN)
7793
        return BUFFER_ERROR;
7794
    ato16(input + i, &suiteSz);
7795
    i += OPAQUE16_LEN;
7796
    if ((word32)suiteSz + OPAQUE8_LEN > helloSz - i)
7797
        return BUFFER_ERROR;
7798
    i += suiteSz;
7799
    /* Compression */
7800
    b = input[i++];
7801
    if (b > helloSz - i)
7802
        return BUFFER_ERROR;
7803
    i += b;
7804
7805
    /* TLS 1.3 must have extensions */
7806
    if (i < helloSz) {
7807
        if (helloSz - i < OPAQUE16_LEN)
7808
            return BUFFER_ERROR;
7809
        ato16(&input[i], &totalExtSz);
7810
        i += OPAQUE16_LEN;
7811
        if (totalExtSz != helloSz - i)
7812
            return BUFFER_ERROR;
7813
7814
        /* Need to negotiate version first. */
7815
        if ((ret = TLSX_ParseVersion(ssl, input + i, totalExtSz, client_hello,
7816
                                                              &foundVersion))) {
7817
            return ret;
7818
        }
7819
    }
7820
    *wantDowngrade = !foundVersion || !IsAtLeastTLSv1_3(ssl->version);
7821
7822
    return 0;
7823
}
7824
7825
#ifdef HAVE_ECH
7826
/* Calculate and write the 8 ECH confirmation bytes.
7827
 * Output into confirmation field on HRR and into ServerRandom on ServerHello.
7828
 *
7829
 * ssl          SSL/TLS object.
7830
 * label        Ascii string describing ECH acceptance or rejection.
7831
 * labelSz      Length of label excluding NULL character.
7832
 * output       The buffer to calculate/write confirmation from/to.
7833
 * acceptOffset Where the 8 ECH confirmation bytes should be placed.
7834
 * helloSz      Size of hello message.
7835
 * msgType      Type of message being written.
7836
 * returns 0 on success and otherwise failure.
7837
 */
7838
static int EchWriteAcceptance(WOLFSSL* ssl, byte* label, word16 labelSz,
7839
    byte* output, int acceptOffset, int helloSz, byte msgType)
7840
{
7841
    int ret = 0;
7842
    int headerSz;
7843
    HS_Hashes* tmpHashes;
7844
7845
#ifdef WOLFSSL_DTLS13
7846
    headerSz = ssl->options.dtls ? DTLS13_HANDSHAKE_HEADER_SZ :
7847
                                   HANDSHAKE_HEADER_SZ;
7848
#else
7849
    headerSz = HANDSHAKE_HEADER_SZ;
7850
#endif
7851
7852
    ret = EchCalcAcceptance(ssl, label, labelSz, output, acceptOffset,
7853
            helloSz - headerSz, msgType == hello_retry_request,
7854
            output + acceptOffset);
7855
7856
    if (ret == 0) {
7857
        tmpHashes = ssl->hsHashes;
7858
        ssl->hsHashes = ssl->hsHashesEch;
7859
7860
        /* after HRR, hsHashesEch must contain:
7861
         * message_hash(ClientHelloInner1) || HRR (actual, not zeros) */
7862
        if (msgType == hello_retry_request) {
7863
            ret = HashRaw(ssl, output, helloSz);
7864
        }
7865
        /* normal TLS code will calculate transcript of ServerHello */
7866
        else {
7867
            ssl->hsHashes = tmpHashes;
7868
            FreeHandshakeHashes(ssl);
7869
            tmpHashes = ssl->hsHashesEch;
7870
            ssl->hsHashesEch = NULL;
7871
        }
7872
7873
        ssl->hsHashes = tmpHashes;
7874
    }
7875
7876
    return ret;
7877
}
7878
#endif
7879
7880
/* Handle a ClientHello handshake message.
7881
 * If the protocol version in the message is not TLS v1.3 or higher, use
7882
 * DoClientHello()
7883
 * Only a server will receive this message.
7884
 *
7885
 * ssl       The SSL/TLS object.
7886
 * input     The message buffer.
7887
 * inOutIdx  On entry, the index into the message buffer of ClientHello.
7888
 *           On exit, the index of byte after the ClientHello message and
7889
 *           padding.
7890
 * helloSz   The length of the current handshake message.
7891
 * returns 0 on success and otherwise failure.
7892
 */
7893
7894
typedef struct Dch13Args {
7895
    ProtocolVersion pv;
7896
    word32          idx;
7897
    word32          begin;
7898
    int             usingPSK;
7899
} Dch13Args;
7900
7901
static void FreeDch13Args(WOLFSSL* ssl, void* pArgs)
7902
48.8k
{
7903
    /* openssl compat builds hang on to the client suites until WOLFSSL object
7904
     * is destroyed */
7905
#ifndef OPENSSL_EXTRA
7906
    if (ssl->clSuites) {
7907
        XFREE(ssl->clSuites, ssl->heap, DYNAMIC_TYPE_SUITES);
7908
        ssl->clSuites = NULL;
7909
    }
7910
#endif
7911
48.8k
    (void)ssl;
7912
48.8k
    (void)pArgs;
7913
7914
48.8k
}
7915
7916
int DoTls13ClientHello(WOLFSSL* ssl, const byte* input, word32* inOutIdx,
7917
                       word32 helloSz)
7918
{
7919
    int ret;
7920
#ifdef WOLFSSL_ASYNC_CRYPT
7921
    Dch13Args* args = NULL;
7922
    WOLFSSL_ASSERT_SIZEOF_GE(ssl->async->args, *args);
7923
#else
7924
    Dch13Args  args[1];
7925
#endif
7926
#if defined(HAVE_ECH)
7927
    TLSX* echX = NULL;
7928
#endif
7929
7930
    WOLFSSL_START(WC_FUNC_CLIENT_HELLO_DO);
7931
    WOLFSSL_ENTER("DoTls13ClientHello");
7932
7933
#ifdef WOLFSSL_ASYNC_CRYPT
7934
    if (ssl->async == NULL) {
7935
        ssl->async = (struct WOLFSSL_ASYNC*)
7936
                XMALLOC(sizeof(struct WOLFSSL_ASYNC), ssl->heap,
7937
                        DYNAMIC_TYPE_ASYNC);
7938
        if (ssl->async == NULL)
7939
            ERROR_OUT(MEMORY_E, exit_dch);
7940
        /* Zeroed so the mid-flight resume test below can never route into
7941
         * uninitialised args. */
7942
        XMEMSET(ssl->async, 0, sizeof(struct WOLFSSL_ASYNC));
7943
    }
7944
    args = (Dch13Args*)ssl->async->args;
7945
7946
    ret = wolfSSL_AsyncPop(ssl, &ssl->options.asyncState);
7947
    if (ret != WC_NO_ERR_TRACE(WC_NO_PENDING_E)) {
7948
        /* Check for error */
7949
        if (ret < 0) {
7950
            goto exit_dch;
7951
        }
7952
    }
7953
    else if (ssl->options.asyncState > TLS_ASYNC_BEGIN &&
7954
             ssl->options.asyncState < TLS_ASYNC_END) {
7955
        /* Mid-flight replay: the event may already be retired but
7956
         * asyncState/args are intact, so resume; resetting would hash the
7957
         * message twice. Fresh ClientHellos arrive at TLS_ASYNC_BEGIN. */
7958
        ret = 0;
7959
    }
7960
    else
7961
#endif
7962
    {
7963
        /* Reset state */
7964
        ret = WC_NO_ERR_TRACE(VERSION_ERROR);
7965
        ssl->options.asyncState = TLS_ASYNC_BEGIN;
7966
        XMEMSET(args, 0, sizeof(Dch13Args));
7967
    #ifdef WOLFSSL_ASYNC_CRYPT
7968
        ssl->async->freeArgs = FreeDch13Args;
7969
    #endif
7970
    }
7971
7972
    switch (ssl->options.asyncState) {
7973
    case TLS_ASYNC_BEGIN:
7974
    {
7975
    byte b;
7976
    byte sessIdSz;
7977
    int wantDowngrade = 0;
7978
    word16 totalExtSz = 0;
7979
7980
#if defined(WOLFSSL_DTLS13) && defined(WOLFSSL_DTLS_CID)
7981
    /* Reset for each ClientHello, including retries and legacy fallbacks. */
7982
    ssl->options.haveSupportedVersions = 0;
7983
#endif
7984
#ifdef WOLFSSL_CALLBACKS
7985
    if (ssl->hsInfoOn) AddPacketName(ssl, "ClientHello");
7986
    if (ssl->toInfoOn) AddLateName("ClientHello", &ssl->timeoutInfo);
7987
#endif
7988
7989
    /* do not change state in the SSL object before the next region of code
7990
     * to be able to statelessly compute a DTLS cookie */
7991
#if defined(WOLFSSL_DTLS13) && defined(WOLFSSL_SEND_HRR_COOKIE)
7992
    /* Update the ssl->options.dtlsStateful setting `if` statement in
7993
     * wolfSSL_accept_TLSv13 when changing this one. */
7994
    if (IsDtlsNotSctpMode(ssl) && ssl->options.sendCookie &&
7995
            !ssl->options.dtlsStateful) {
7996
        DtlsSetSeqNumForReply(ssl);
7997
        ret = DoClientHelloStateless(ssl, input + *inOutIdx, helloSz, 0, NULL);
7998
        if (ret != 0 || !ssl->options.dtlsStateful) {
7999
            *inOutIdx += helloSz;
8000
            goto exit_dch;
8001
        }
8002
        if (ssl->chGoodCb != NULL) {
8003
            int cbret = ssl->chGoodCb(ssl, ssl->chGoodCtx);
8004
            if (cbret < 0) {
8005
                ssl->error = cbret;
8006
                WOLFSSL_MSG("ClientHello Good Cb don't continue error");
8007
                return WOLFSSL_FATAL_ERROR;
8008
            }
8009
        }
8010
    }
8011
    ssl->options.dtlsStateful = 1;
8012
#endif /* WOLFSSL_DTLS */
8013
8014
    args->idx = *inOutIdx;
8015
    args->begin = args->idx;
8016
8017
    /* protocol version, random and session id length check */
8018
    if (OPAQUE16_LEN + RAN_LEN + OPAQUE8_LEN > helloSz) {
8019
        ERROR_OUT(BUFFER_ERROR, exit_dch);
8020
    }
8021
8022
    /* Protocol version */
8023
    XMEMCPY(&args->pv, input + args->idx, OPAQUE16_LEN);
8024
    ssl->chVersion = args->pv;   /* store */
8025
    args->idx += OPAQUE16_LEN;
8026
8027
8028
    /* this check pass for DTLS Major (0xff) */
8029
    if (args->pv.major < SSLv3_MAJOR) {
8030
        WOLFSSL_MSG("Legacy version field contains unsupported value");
8031
        ERROR_OUT(VERSION_ERROR, exit_dch);
8032
    }
8033
8034
#ifdef WOLFSSL_DTLS13
8035
    if (ssl->options.dtls &&
8036
        args->pv.major == DTLS_MAJOR && args->pv.minor > DTLSv1_2_MINOR) {
8037
        wantDowngrade = 1;
8038
        ssl->version.minor = args->pv.minor;
8039
    }
8040
#endif /* WOLFSSL_DTLS13 */
8041
8042
    if (!ssl->options.dtls) {
8043
#ifndef WOLFSSL_ALLOW_BAD_TLS_LEGACY_VERSION
8044
        /* Check for TLS 1.3 version (0x0304) in legacy version field. RFC 8446
8045
         * Section 4.2.1 allows this action:
8046
         *
8047
         * "Servers MAY abort the handshake upon receiving a ClientHello with
8048
         * legacy_version 0x0304 or later."
8049
         *
8050
         * Note that if WOLFSSL_ALLOW_BAD_TLS_LEGACY_VERSION is defined then the
8051
         * semantics of RFC 5246 Appendix E will be followed. A ServerHello with
8052
         * version 1.2 will be sent. The same is true if TLS 1.3 is not enabled.
8053
         */
8054
        if (args->pv.major == SSLv3_MAJOR && args->pv.minor >= TLSv1_3_MINOR) {
8055
            WOLFSSL_MSG("Legacy version field is TLS 1.3 or later. Aborting.");
8056
            ERROR_OUT(VERSION_ERROR, exit_dch);
8057
        }
8058
#endif /* WOLFSSL_ALLOW_BAD_TLS_LEGACY_VERSION */
8059
8060
        /* Legacy protocol version cannot negotiate TLS 1.3 or higher. */
8061
        if (args->pv.major > SSLv3_MAJOR || (args->pv.major == SSLv3_MAJOR &&
8062
                                             args->pv.minor >= TLSv1_3_MINOR)) {
8063
            args->pv.major = SSLv3_MAJOR;
8064
            args->pv.minor = TLSv1_2_MINOR;
8065
            wantDowngrade = 1;
8066
            ssl->version.minor = args->pv.minor;
8067
        }
8068
        /* Legacy version must be [ SSLv3_MAJOR, TLSv1_2_MINOR ] for TLS v1.3 */
8069
        else if (args->pv.major == SSLv3_MAJOR &&
8070
                 args->pv.minor < TLSv1_2_MINOR) {
8071
            wantDowngrade = 1;
8072
            ssl->version.minor = args->pv.minor;
8073
        }
8074
    }
8075
8076
    if (!wantDowngrade) {
8077
        ret = DoTls13SupportedVersions(ssl, input + args->begin,
8078
            args->idx - args->begin, helloSz, &wantDowngrade);
8079
        if (ret < 0)
8080
            goto exit_dch;
8081
    }
8082
8083
    if (wantDowngrade) {
8084
#ifndef WOLFSSL_NO_TLS12
8085
        byte realMinor;
8086
#endif
8087
#if defined(HAVE_ECH)
8088
        if (ssl->options.echProcessingInner) {
8089
            WOLFSSL_MSG("ECH: inner client hello does not support version "
8090
                        "less than TLS v1.3");
8091
            ERROR_OUT(INVALID_PARAMETER, exit_dch);
8092
        }
8093
#endif
8094
#ifndef WOLFSSL_NO_TLS12
8095
        if (!ssl->options.downgrade) {
8096
            WOLFSSL_MSG("Client trying to connect with lesser version than "
8097
                        "TLS v1.3");
8098
            ERROR_OUT(VERSION_ERROR, exit_dch);
8099
        }
8100
8101
        if ((!ssl->options.dtls
8102
                 && args->pv.minor < ssl->options.minDowngrade) ||
8103
            (ssl->options.dtls && args->pv.minor > ssl->options.minDowngrade)) {
8104
            WOLFSSL_MSG("\tversion below minimum allowed, fatal error");
8105
            ERROR_OUT(VERSION_ERROR, exit_dch);
8106
        }
8107
8108
        realMinor = ssl->version.minor;
8109
        ssl->version.minor = args->pv.minor;
8110
        ret = HashInput(ssl, input + args->begin, (int)helloSz);
8111
        ssl->version.minor = realMinor;
8112
        if (ret == 0) {
8113
            ret = DoClientHello(ssl, input, inOutIdx, helloSz);
8114
        }
8115
        goto exit_dch;
8116
#else
8117
        WOLFSSL_MSG("Client trying to connect with lesser version than "
8118
                    "TLS v1.3");
8119
        ERROR_OUT(VERSION_ERROR, exit_dch);
8120
#endif
8121
    }
8122
8123
    /* From here on we are a TLS 1.3 ClientHello. */
8124
8125
    /* Client random
8126
     * ECH Accepted -> This will fill with the innerClientRandom */
8127
    XMEMCPY(ssl->arrays->clientRandom, input + args->idx, RAN_LEN);
8128
    args->idx += RAN_LEN;
8129
8130
#ifdef WOLFSSL_DEBUG_TLS
8131
    WOLFSSL_MSG("client random");
8132
    WOLFSSL_BUFFER(ssl->arrays->clientRandom, RAN_LEN);
8133
#endif
8134
8135
    sessIdSz = input[args->idx++];
8136
    if (sessIdSz > ID_LEN)
8137
    {
8138
        ERROR_OUT(INVALID_PARAMETER, exit_dch);
8139
    }
8140
8141
    if (sessIdSz + args->idx > helloSz)
8142
        ERROR_OUT(BUFFER_ERROR, exit_dch);
8143
8144
#if defined(WOLFSSL_DTLS13) && !defined(WOLFSSL_DTLS13_ECHO_LEGACY_SESSION_ID)
8145
    /* RFC 9147 Section 5: "DTLS servers MUST NOT echo the legacy_session_id
8146
     * value from the client." Don't store it so SendTls13ServerHello can't
8147
     * echo it. */
8148
    if (ssl->options.dtls) {
8149
        ssl->session->sessionIDSz = 0;
8150
    }
8151
    else
8152
#endif
8153
    {
8154
        ssl->session->sessionIDSz = sessIdSz;
8155
        if (sessIdSz > 0)
8156
            XMEMCPY(ssl->session->sessionID, input + args->idx, sessIdSz);
8157
    }
8158
    args->idx += sessIdSz;
8159
8160
    /* RFC 8446 Appendix D.4: server MUST only send CCS if the client's
8161
     * ClientHello contains a non-empty legacy_session_id. An ECH inner hello
8162
     * is rebuilt with the outer session id, so it decides either way. */
8163
    if (sessIdSz == 0) {
8164
        ssl->options.tls13MiddleBoxCompat = 0;
8165
    }
8166
#ifdef WOLFSSL_QUIC
8167
    /* RFC 9001 Section 8.4: QUIC has no compatibility mode to be had. */
8168
    if (WOLFSSL_IS_QUIC(ssl)) {
8169
        ssl->options.tls13MiddleBoxCompat = 0;
8170
    }
8171
#endif
8172
8173
#ifdef WOLFSSL_DTLS13
8174
    /* legacy_cookie */
8175
    if (ssl->options.dtls) {
8176
        word32 rel = args->idx - args->begin;
8177
        byte cookieLen;
8178
        if (rel > helloSz || helloSz - rel < OPAQUE8_LEN)
8179
            ERROR_OUT(BUFFER_ERROR, exit_dch);
8180
        /* https://www.rfc-editor.org/rfc/rfc9147.html#section-5.3 */
8181
        cookieLen = input[args->idx++];
8182
        if (cookieLen != 0) {
8183
            ERROR_OUT(INVALID_PARAMETER, exit_dch);
8184
        }
8185
    }
8186
#endif /* WOLFSSL_DTLS13 */
8187
8188
    XFREE(ssl->clSuites, ssl->heap, DYNAMIC_TYPE_SUITES);
8189
    ssl->clSuites = (Suites*)XMALLOC(sizeof(Suites), ssl->heap,
8190
        DYNAMIC_TYPE_SUITES);
8191
    if (ssl->clSuites == NULL) {
8192
        ERROR_OUT(MEMORY_E, exit_dch);
8193
    }
8194
8195
    /* Cipher suites */
8196
    if ((args->idx - args->begin) + OPAQUE16_LEN > helloSz)
8197
        ERROR_OUT(BUFFER_ERROR, exit_dch);
8198
    ato16(&input[args->idx], &ssl->clSuites->suiteSz);
8199
    args->idx += OPAQUE16_LEN;
8200
    if ((ssl->clSuites->suiteSz % 2) != 0) {
8201
        ERROR_OUT(INVALID_PARAMETER, exit_dch);
8202
    }
8203
    /* suites and compression length check */
8204
    if ((args->idx - args->begin) + ssl->clSuites->suiteSz + OPAQUE8_LEN >
8205
            helloSz) {
8206
        ERROR_OUT(BUFFER_ERROR, exit_dch);
8207
    }
8208
    if (ssl->clSuites->suiteSz > WOLFSSL_MAX_SUITE_SZ)
8209
        ERROR_OUT(BUFFER_ERROR, exit_dch);
8210
    XMEMCPY(ssl->clSuites->suites, input + args->idx, ssl->clSuites->suiteSz);
8211
    args->idx += ssl->clSuites->suiteSz;
8212
    ssl->clSuites->hashSigAlgoSz = 0;
8213
#if !defined(NO_CERTS) && !defined(WOLFSSL_NO_SIGALG)
8214
    /* Discard any list kept from a previous ClientHello on this object; a
8215
     * second hello that drops signature_algorithms_cert must not inherit it. */
8216
    ssl->certHashSigAlgoSz = 0;
8217
#endif
8218
8219
    /* Compression */
8220
    b = input[args->idx++];
8221
    if ((args->idx - args->begin) + b > helloSz)
8222
        ERROR_OUT(BUFFER_ERROR, exit_dch);
8223
    if (b != COMP_LEN) {
8224
        WOLFSSL_MSG("Must be one compression type in list");
8225
        ERROR_OUT(INVALID_PARAMETER, exit_dch);
8226
    }
8227
    b = input[args->idx++];
8228
    if (b != NO_COMPRESSION) {
8229
        WOLFSSL_MSG("Must be no compression type in list");
8230
        ERROR_OUT(INVALID_PARAMETER, exit_dch);
8231
    }
8232
8233
    /* Extensions */
8234
    if ((args->idx - args->begin) == helloSz)
8235
        ERROR_OUT(BUFFER_ERROR, exit_dch);
8236
    if ((args->idx - args->begin) + OPAQUE16_LEN > helloSz)
8237
        ERROR_OUT(BUFFER_ERROR, exit_dch);
8238
8239
    ato16(&input[args->idx], &totalExtSz);
8240
    args->idx += OPAQUE16_LEN;
8241
    if ((args->idx - args->begin) + totalExtSz > helloSz)
8242
        ERROR_OUT(BUFFER_ERROR, exit_dch);
8243
8244
    /* Auto populate extensions supported unless user defined. */
8245
    if ((ret = TLSX_PopulateExtensions(ssl, 1)) != 0)
8246
        goto exit_dch;
8247
8248
#if defined(HAVE_ECH)
8249
    if (ssl->ctx->echConfigs != NULL && !ssl->options.disableECH) {
8250
        /* save the start of the buffer so we can use it when parsing ech */
8251
        echX = TLSX_Find(ssl->extensions, TLSX_ECH);
8252
8253
        if (echX == NULL)
8254
            ERROR_OUT(WOLFSSL_FATAL_ERROR, exit_dch);
8255
8256
        ((WOLFSSL_ECH*)echX->data)->aad = input + args->begin;
8257
        ((WOLFSSL_ECH*)echX->data)->aadLen = helloSz;
8258
    }
8259
#endif
8260
8261
    /* Parse extensions */
8262
    if ((ret = TLSX_Parse(ssl, input + args->idx, totalExtSz, client_hello,
8263
                                                            ssl->clSuites))) {
8264
        goto exit_dch;
8265
    }
8266
8267
#if !defined(NO_CERTS) && !defined(WOLFSSL_NO_SIGALG)
8268
    SetPeerSha1CertOk(ssl, ssl->clSuites);
8269
#endif
8270
8271
#if (defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)) && \
8272
    defined(HAVE_TLS_EXTENSIONS)
8273
    /* RFC 8446 Section 4.2.11: the pre_shared_key extension MUST be the
8274
     * last extension in the ClientHello. wolfSSL stores extensions in
8275
     * reverse wire order (TLSX_Push prepends), so a well-formed
8276
     * ClientHello with PSK leaves PSK at the head of ssl->extensions
8277
     * here, before any post-parse code (e.g. ALPN_Select) modifies the
8278
     * list. */
8279
    {
8280
        TLSX* pskExt = TLSX_Find(ssl->extensions, TLSX_PRE_SHARED_KEY);
8281
        if (pskExt != NULL && ssl->extensions != pskExt) {
8282
            WOLFSSL_MSG("pre_shared_key extension was not last in "
8283
                        "ClientHello");
8284
            WOLFSSL_ERROR_VERBOSE(PSK_KEY_ERROR);
8285
            ERROR_OUT(PSK_KEY_ERROR, exit_dch);
8286
        }
8287
    }
8288
#endif
8289
8290
#if defined(HAVE_ECH)
8291
    /* ECH accept/reject reconciliation is done at the end of TLSX_Parse. On
8292
     * acceptance the inner hello was decrypted, so jump to exit and let the
8293
     * caller re-invoke with the inner hello. */
8294
    if (!ssl->options.echProcessingInner && echX != NULL &&
8295
            ((WOLFSSL_ECH*)echX->data)->state == ECH_WRITE_NONE &&
8296
            ((WOLFSSL_ECH*)echX->data)->innerClientHello != NULL) {
8297
        goto exit_dch;
8298
    }
8299
#endif
8300
8301
#ifdef HAVE_SNI
8302
        if ((ret = SNI_Callback(ssl)) != 0)
8303
            goto exit_dch;
8304
        ssl->options.side = WOLFSSL_SERVER_END;
8305
#endif
8306
8307
    args->idx += totalExtSz;
8308
    ssl->options.haveSessionId = 1;
8309
    ssl->options.sendVerify = SEND_CERT;
8310
8311
#if defined(WOLFSSL_SEND_HRR_COOKIE)
8312
    ssl->options.cookieGood = 0;
8313
    if (ssl->options.sendCookie &&
8314
            (ssl->options.serverState == SERVER_HELLO_RETRY_REQUEST_COMPLETE
8315
#ifdef WOLFSSL_DTLS13
8316
                    /* Always check for a valid cookie since we may have already
8317
                     * sent a HRR but we reset the state. */
8318
                    || ssl->options.dtls
8319
#endif
8320
                    )) {
8321
        TLSX* ext = TLSX_Find(ssl->extensions, TLSX_COOKIE);
8322
8323
        if (ext != NULL) {
8324
            /* Ensure the cookie came from client and isn't the one in the
8325
            * response - HelloRetryRequest.
8326
            */
8327
            if (ext->resp == 0) {
8328
                ret = RestartHandshakeHashWithCookie(ssl, (Cookie*)ext->data);
8329
                if (ret != 0)
8330
                    goto exit_dch;
8331
                /* Don't change state here as we may want to enter
8332
                 * DoTls13ClientHello again. */
8333
                ssl->options.cookieGood = 1;
8334
            }
8335
            else {
8336
                ERROR_OUT(HRR_COOKIE_ERROR, exit_dch);
8337
            }
8338
        }
8339
        else {
8340
#if defined(WOLFSSL_DTLS13) && defined(WOLFSSL_DTLS13_NO_HRR_ON_RESUME)
8341
            /* Don't error out as we may be resuming. We confirm this later. */
8342
            if (!ssl->options.dtls)
8343
#endif
8344
                ERROR_OUT(HRR_COOKIE_ERROR, exit_dch);
8345
        }
8346
    }
8347
#endif
8348
8349
#ifdef HAVE_SUPPORTED_CURVES
8350
    if (ssl->hrr_keyshare_group != 0) {
8351
        /*
8352
         * https://datatracker.ietf.org/doc/html/rfc8446#section-4.2.8
8353
         *   when sending the new ClientHello, the client MUST
8354
         *   replace the original "key_share" extension with one containing only
8355
         *   a new KeyShareEntry for the group indicated in the selected_group
8356
         *   field of the triggering HelloRetryRequest.
8357
         */
8358
        TLSX* extension = TLSX_Find(ssl->extensions, TLSX_KEY_SHARE);
8359
        if (extension != NULL) {
8360
            KeyShareEntry* kse = (KeyShareEntry*)extension->data;
8361
            /* Exactly one KeyShareEntry with the HRR group must be present. */
8362
            if (kse == NULL || kse->next != NULL ||
8363
                                        kse->group != ssl->hrr_keyshare_group) {
8364
                ERROR_OUT(BAD_KEY_SHARE_DATA, exit_dch);
8365
            }
8366
        }
8367
        else
8368
            ERROR_OUT(BAD_KEY_SHARE_DATA, exit_dch);
8369
    }
8370
#endif
8371
8372
#if defined(HAVE_ECH)
8373
    /* hash clientHelloInner to hsHashesEch */
8374
    if (echX != NULL && ssl->ctx->echConfigs != NULL &&
8375
            !ssl->options.disableECH &&
8376
            ((WOLFSSL_ECH*)echX->data)->innerClientHello != NULL) {
8377
        ret = EchHashHelloInner(ssl, (WOLFSSL_ECH*)echX->data);
8378
        if (ret != 0)
8379
            goto exit_dch;
8380
        ((WOLFSSL_ECH*)echX->data)->innerCount = 1;
8381
    }
8382
#endif
8383
8384
#ifdef HAVE_ALPN
8385
    /* Select the ALPN protocol before PSK selection so that the
8386
     * selected value is available to the per-PSK SNI/ALPN binding check
8387
     * inside CheckPreSharedKeys/DoPreSharedKeys. ALPN_Select itself
8388
     * only inspects ssl->extensions and the app callback; it does not
8389
     * depend on any state set during PSK validation. */
8390
    if ((ret = ALPN_Select(ssl)) != 0)
8391
        goto exit_dch;
8392
#endif
8393
#if (defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)) && \
8394
                                                    defined(HAVE_TLS_EXTENSIONS)
8395
    ret = CheckPreSharedKeys(ssl, input + args->begin, helloSz, ssl->clSuites,
8396
        &args->usingPSK);
8397
    if (ret != 0)
8398
        goto exit_dch;
8399
#else
8400
    if ((ret = HashInput(ssl, input + args->begin, (int)helloSz)) != 0)
8401
        goto exit_dch;
8402
#endif
8403
8404
#if (defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)) && \
8405
                                                    defined(HAVE_TLS_EXTENSIONS)
8406
    if (!args->usingPSK
8407
#ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
8408
        || ssl->options.certWithExternPsk
8409
#endif
8410
    )
8411
#endif
8412
    {
8413
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
8414
        /* Not using PSK so don't require no KE. */
8415
        ssl->options.noPskDheKe = 0;
8416
#endif
8417
8418
#ifndef NO_CERTS
8419
        if (TLSX_Find(ssl->extensions, TLSX_KEY_SHARE) == NULL) {
8420
            WOLFSSL_MSG("Client did not send a KeyShare extension");
8421
            ERROR_OUT(INCOMPLETE_DATA, exit_dch);
8422
        }
8423
        /* Can't check ssl->extensions here as SigAlgs are unconditionally
8424
           set by TLSX_PopulateExtensions */
8425
        if (ssl->clSuites->hashSigAlgoSz == 0) {
8426
            WOLFSSL_MSG("Client did not send a SignatureAlgorithms extension");
8427
            ERROR_OUT(INCOMPLETE_DATA, exit_dch);
8428
        }
8429
#else
8430
        ERROR_OUT(INVALID_PARAMETER, exit_dch);
8431
#endif
8432
    }
8433
8434
    } /* case TLS_ASYNC_BEGIN */
8435
    FALL_THROUGH;
8436
8437
    case TLS_ASYNC_BUILD:
8438
    /* Advance state and proceed */
8439
    ssl->options.asyncState = TLS_ASYNC_DO;
8440
    FALL_THROUGH;
8441
8442
    case TLS_ASYNC_DO:
8443
    {
8444
#ifdef WOLFSSL_CERT_SETUP_CB
8445
    if ((ret = CertSetupCbWrapper(ssl)) != 0)
8446
        goto exit_dch;
8447
#endif
8448
#ifndef NO_CERTS
8449
    if (!args->usingPSK) {
8450
        if ((ret = MatchSuite(ssl, ssl->clSuites)) < 0) {
8451
        #ifdef WOLFSSL_ASYNC_CRYPT
8452
            if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
8453
        #endif
8454
                WOLFSSL_MSG("Unsupported cipher suite, ClientHello 1.3");
8455
            goto exit_dch;
8456
        }
8457
    }
8458
#endif
8459
#ifdef HAVE_SUPPORTED_CURVES
8460
    if (args->usingPSK == 2) {
8461
        /* Pick key share and Generate a new key if not present. */
8462
        int doHelloRetry = 0;
8463
        ret = TLSX_KeyShare_Establish(ssl, &doHelloRetry);
8464
        if (doHelloRetry) {
8465
            /* Make sure we don't send HRR twice */
8466
            if (ssl->options.serverState == SERVER_HELLO_RETRY_REQUEST_COMPLETE)
8467
                ERROR_OUT(INVALID_PARAMETER, exit_dch);
8468
            ssl->options.serverState = SERVER_HELLO_RETRY_REQUEST_COMPLETE;
8469
            if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
8470
                ret = 0; /* for hello_retry return 0 */
8471
        }
8472
        if (ret != 0)
8473
            goto exit_dch;
8474
    }
8475
#endif
8476
8477
    /* Verify the cipher suite is the same as what was chosen in HRR.
8478
     * got_client_hello == 2 covers the stateful path.
8479
     * cookieGood covers the stateless DTLS path. */
8480
    if ((ssl->msgsReceived.got_client_hello == 2
8481
#ifdef WOLFSSL_SEND_HRR_COOKIE
8482
            || ssl->options.cookieGood
8483
#endif
8484
        ) &&
8485
            (ssl->options.cipherSuite0 != ssl->options.hrrCipherSuite0 ||
8486
             ssl->options.cipherSuite  != ssl->options.hrrCipherSuite)) {
8487
        WOLFSSL_MSG("Cipher suite in second ClientHello does not match "
8488
                    "HelloRetryRequest");
8489
        ERROR_OUT(INVALID_PARAMETER, exit_dch);
8490
    }
8491
8492
    /* Advance state and proceed */
8493
    ssl->options.asyncState = TLS_ASYNC_VERIFY;
8494
    } /* case TLS_ASYNC_BUILD || TLS_ASYNC_DO */
8495
    FALL_THROUGH;
8496
8497
    case TLS_ASYNC_VERIFY:
8498
    {
8499
#if defined(WOLFSSL_ASYNC_CRYPT) && defined(HAVE_SUPPORTED_CURVES)
8500
    /* Check if the KeyShare calculations from the previous state are complete.
8501
     * wolfSSL_AsyncPop advances ssl->options.asyncState so we may end up here
8502
     * with a pending calculation. */
8503
    TLSX* extension = TLSX_Find(ssl->extensions, TLSX_KEY_SHARE);
8504
    if (extension != NULL && extension->resp == 1) {
8505
        KeyShareEntry* serverKSE = (KeyShareEntry*)extension->data;
8506
        if (serverKSE != NULL &&
8507
            serverKSE->lastRet == WC_NO_ERR_TRACE(WC_PENDING_E)) {
8508
    #if defined(WOLFSSL_HAVE_MLKEM)
8509
            if (WOLFSSL_NAMED_GROUP_IS_PQC_HYBRID(serverKSE->group)) {
8510
                ret = TLSX_KeyShare_HandlePqcHybridKeyServer(ssl, serverKSE,
8511
                        serverKSE->ke, serverKSE->keLen);
8512
            }
8513
            else
8514
    #endif
8515
            {
8516
                ret = TLSX_KeyShare_GenKey(ssl, serverKSE);
8517
            }
8518
            if (ret != 0)
8519
                goto exit_dch;
8520
        }
8521
    }
8522
#endif
8523
    /* Advance state and proceed */
8524
    ssl->options.asyncState = TLS_ASYNC_FINALIZE;
8525
    }
8526
    FALL_THROUGH;
8527
8528
    case TLS_ASYNC_FINALIZE:
8529
    {
8530
    *inOutIdx = args->idx;
8531
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
8532
    ssl->options.pskNegotiated = (args->usingPSK != 0);
8533
#endif
8534
8535
    if (!args->usingPSK) {
8536
#ifndef NO_CERTS
8537
        /* Check that the negotiated ciphersuite matches protocol version. */
8538
    #ifdef HAVE_NULL_CIPHER
8539
        if (ssl->options.cipherSuite0 == ECC_BYTE &&
8540
                              (ssl->options.cipherSuite == TLS_SHA256_SHA256 ||
8541
                               ssl->options.cipherSuite == TLS_SHA384_SHA384)) {
8542
            ;
8543
        }
8544
        else
8545
    #endif
8546
    #if defined(WOLFSSL_SM4_GCM) && defined(WOLFSSL_SM3)
8547
        if (ssl->options.cipherSuite0 == CIPHER_BYTE &&
8548
                ssl->options.cipherSuite == TLS_SM4_GCM_SM3) {
8549
            ; /* Do nothing. */
8550
        }
8551
        else
8552
    #endif
8553
    #if defined(WOLFSSL_SM4_CCM) && defined(WOLFSSL_SM3)
8554
        if (ssl->options.cipherSuite0 == CIPHER_BYTE &&
8555
                ssl->options.cipherSuite == TLS_SM4_CCM_SM3) {
8556
            ; /* Do nothing. */
8557
        }
8558
        else
8559
    #endif
8560
        if (ssl->options.cipherSuite0 != TLS13_BYTE) {
8561
            WOLFSSL_MSG("Negotiated ciphersuite from lesser version than "
8562
                        "TLS v1.3");
8563
            ERROR_OUT(MATCH_SUITE_ERROR, exit_dch);
8564
        }
8565
8566
    #if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
8567
        if (ssl->options.resuming) {
8568
            ssl->options.resuming = 0;
8569
            ssl->arrays->psk_keySz = 0;
8570
            XMEMSET(ssl->arrays->psk_key, 0, ssl->specs.hash_size);
8571
        }
8572
    #endif
8573
8574
        /* Derive early secret for handshake secret. */
8575
        if ((ret = DeriveEarlySecret(ssl)) != 0)
8576
            goto exit_dch;
8577
#endif /* !NO_CERTS */
8578
    }
8579
8580
    /* Advanced only after the derive: earlier would let the accept loop
8581
     * proceed on an unfinished early secret. */
8582
    ssl->options.clientState = CLIENT_HELLO_COMPLETE;
8583
    break;
8584
    } /* case TLS_ASYNC_FINALIZE */
8585
    default:
8586
        ret = INPUT_CASE_ERROR;
8587
    } /* switch (ssl->options.asyncState) */
8588
8589
#ifdef WOLFSSL_SEND_HRR_COOKIE
8590
    if (ret == 0 && ssl->options.sendCookie) {
8591
        if (ssl->options.cookieGood &&
8592
                ssl->options.acceptState == TLS13_ACCEPT_FIRST_REPLY_DONE) {
8593
            /* Processing second ClientHello. Clear HRR state. */
8594
            ssl->options.serverState = NULL_STATE;
8595
        }
8596
8597
        if (ssl->options.cookieGood &&
8598
            ssl->options.serverState == SERVER_HELLO_RETRY_REQUEST_COMPLETE) {
8599
            /* If we already verified the peer with a cookie then we can't
8600
             * do another HRR for cipher negotiation. Send alert and restart
8601
             * the entire handshake. */
8602
            ERROR_OUT(INVALID_PARAMETER, exit_dch);
8603
        }
8604
#ifdef WOLFSSL_DTLS13
8605
        if (ssl->options.dtls &&
8606
            ssl->options.serverState == SERVER_HELLO_RETRY_REQUEST_COMPLETE) {
8607
            /* Cookie and key share negotiation should be handled in
8608
             * DoClientHelloStateless. If we enter here then something went
8609
             * wrong in our logic. */
8610
            ERROR_OUT(BAD_HELLO, exit_dch);
8611
        }
8612
#endif
8613
        /* Send a cookie */
8614
        if (!ssl->options.cookieGood &&
8615
            ssl->options.serverState != SERVER_HELLO_RETRY_REQUEST_COMPLETE) {
8616
#ifdef WOLFSSL_DTLS13
8617
            if (ssl->options.dtls) {
8618
#ifdef WOLFSSL_DTLS13_NO_HRR_ON_RESUME
8619
                /* We can skip cookie on resumption */
8620
                if (!ssl->options.dtls || !ssl->options.dtls13NoHrrOnResume ||
8621
                        !args->usingPSK)
8622
#endif
8623
                    ERROR_OUT(BAD_HELLO, exit_dch);
8624
            }
8625
            else
8626
#endif
8627
            {
8628
                /* Need to remove the keyshare ext if we found a common group
8629
                 * and are not doing curve negotiation. */
8630
                TLSX_Remove(&ssl->extensions, TLSX_KEY_SHARE, ssl->heap);
8631
                ssl->options.serverState = SERVER_HELLO_RETRY_REQUEST_COMPLETE;
8632
            }
8633
8634
        }
8635
    }
8636
#endif /* WOLFSSL_DTLS13 */
8637
8638
#ifdef WOLFSSL_DTLS_CID
8639
    /* do not modify CID state if we are sending an HRR  */
8640
    if (ret == 0 && ssl->options.dtls && ssl->options.useDtlsCID &&
8641
            ssl->options.serverState != SERVER_HELLO_RETRY_REQUEST_COMPLETE)
8642
        DtlsCIDOnExtensionsParsed(ssl);
8643
#endif /* WOLFSSL_DTLS_CID */
8644
8645
8646
8647
exit_dch:
8648
8649
    WOLFSSL_LEAVE("DoTls13ClientHello", ret);
8650
8651
#ifdef WOLFSSL_ASYNC_CRYPT
8652
    if (ret == WC_NO_ERR_TRACE(WC_PENDING_E)) {
8653
        ssl->msgsReceived.got_client_hello = 0;
8654
        return ret;
8655
    }
8656
#endif
8657
8658
    FreeDch13Args(ssl, args);
8659
#ifdef WOLFSSL_ASYNC_CRYPT
8660
    FreeAsyncCtx(ssl, 0);
8661
    /* Back to BEGIN so a later ClientHello (HRR, duplicate) can never be
8662
     * mistaken for a replay and resume into freed args. */
8663
    ssl->options.asyncState = TLS_ASYNC_BEGIN;
8664
    /* This ClientHello is done; a later one (HRR CH2, duplicate) must hash
8665
     * itself afresh. */
8666
    ssl->options.chHashInput = 0;
8667
    /* Replays skip the sanity check that re-sets got_client_hello; restore
8668
     * on completion (only from 0: an HRR second ClientHello counts to 2). */
8669
    if (ret == 0 && ssl->msgsReceived.got_client_hello == 0) {
8670
        ssl->msgsReceived.got_client_hello = 1;
8671
    }
8672
#endif
8673
    WOLFSSL_END(WC_FUNC_CLIENT_HELLO_DO);
8674
8675
    if (ret != 0) {
8676
        WOLFSSL_ERROR_VERBOSE(ret);
8677
    }
8678
8679
#if defined(HAVE_ECH)
8680
    if (ret == 0 && echX != NULL &&
8681
        ((WOLFSSL_ECH*)echX->data)->state == ECH_WRITE_NONE &&
8682
        ((WOLFSSL_ECH*)echX->data)->innerClientHello != NULL) {
8683
8684
        /* add the header to the inner hello */
8685
        AddTls13HandShakeHeader(((WOLFSSL_ECH*)echX->data)->innerClientHello,
8686
            ((WOLFSSL_ECH*)echX->data)->innerClientHelloLen, 0, 0,
8687
            client_hello, ssl);
8688
    }
8689
#endif
8690
8691
    return ret;
8692
}
8693
8694
/* Send TLS v1.3 ServerHello message to client.
8695
 * Only a server will send this message.
8696
 *
8697
 * ssl  The SSL/TLS object.
8698
 * returns 0 on success, otherwise failure.
8699
 */
8700
/* handle generation of TLS 1.3 server_hello (2) */
8701
int SendTls13ServerHello(WOLFSSL* ssl, byte extMsgType)
8702
{
8703
    int    ret;
8704
    byte*  output;
8705
    word16 length;
8706
    word32 idx = RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ;
8707
    int    sendSz;
8708
#if defined(HAVE_ECH)
8709
    TLSX* echX = NULL;
8710
    byte* acceptLabel = (byte*)echAcceptConfirmationLabel;
8711
    word32 acceptOffset;
8712
    word16 acceptLabelSz = ECH_ACCEPT_CONFIRMATION_LABEL_SZ;
8713
#endif
8714
8715
    WOLFSSL_START(WC_FUNC_SERVER_HELLO_SEND);
8716
    WOLFSSL_ENTER("SendTls13ServerHello");
8717
8718
    /* When ssl->options.dtlsStateful is not set then cookie is calculated in
8719
     * dtls.c */
8720
    if (extMsgType == hello_retry_request
8721
#ifdef WOLFSSL_DTLS13
8722
            && (!ssl->options.dtls || ssl->options.dtlsStateful)
8723
#endif
8724
            ) {
8725
        WOLFSSL_MSG("wolfSSL Sending HelloRetryRequest");
8726
        if ((ret = RestartHandshakeHash(ssl)) < 0)
8727
            return ret;
8728
    }
8729
8730
    ssl->options.buildingMsg = 1;
8731
#ifdef WOLFSSL_DTLS13
8732
    if (ssl->options.dtls)
8733
        idx = DTLS_RECORD_HEADER_SZ + DTLS_HANDSHAKE_HEADER_SZ;
8734
#endif /* WOLFSSL_DTLS13 */
8735
8736
    /* Protocol version, server random, session id, cipher suite, compression
8737
     * and extensions.
8738
     */
8739
    length = VERSION_SZ + RAN_LEN + ENUM_LEN + ssl->session->sessionIDSz +
8740
             SUITE_LEN + COMP_LEN;
8741
    ret = TLSX_GetResponseSize(ssl, extMsgType, &length);
8742
    if (ret != 0)
8743
        return ret;
8744
    sendSz = (int)(idx + length);
8745
8746
    /* Check buffers are big enough and grow if needed. */
8747
    if ((ret = CheckAvailableSize(ssl, sendSz)) != 0)
8748
        return ret;
8749
8750
    /* Get position in output buffer to write new message to. */
8751
    output = GetOutputBuffer(ssl);
8752
8753
    /* Put the record and handshake headers on. */
8754
    AddTls13Headers(output, length, server_hello, ssl);
8755
8756
    /* The protocol version must be TLS v1.2 for middleboxes. */
8757
    output[idx++] = ssl->version.major;
8758
    output[idx++] = ssl->options.dtls ? DTLSv1_2_MINOR : TLSv1_2_MINOR;
8759
8760
    if (extMsgType == server_hello) {
8761
        /* Generate server random. */
8762
        if ((ret = wc_RNG_GenerateBlock(ssl->rng, output + idx, RAN_LEN)) != 0)
8763
            return ret;
8764
    }
8765
    else {
8766
        /* HelloRetryRequest message has fixed value for random. */
8767
        XMEMCPY(output + idx, helloRetryRequestRandom, RAN_LEN);
8768
    }
8769
8770
#if defined(HAVE_ECH)
8771
    /* last 8 bytes of server random */
8772
    acceptOffset = idx + RAN_LEN - ECH_ACCEPT_CONFIRMATION_SZ;
8773
#endif
8774
8775
    /* Store in SSL for debugging. */
8776
    XMEMCPY(ssl->arrays->serverRandom, output + idx, RAN_LEN);
8777
    idx += RAN_LEN;
8778
8779
#ifdef WOLFSSL_DEBUG_TLS
8780
    WOLFSSL_MSG("Server random");
8781
    WOLFSSL_BUFFER(ssl->arrays->serverRandom, RAN_LEN);
8782
#endif
8783
8784
#if defined(WOLFSSL_DTLS13) && !defined(WOLFSSL_DTLS13_ECHO_LEGACY_SESSION_ID)
8785
    if (ssl->options.dtls) {
8786
        /* RFC 9147 Section 5: "DTLS servers MUST NOT echo the
8787
         * legacy_session_id value from the client." */
8788
        output[idx++] = 0;
8789
    }
8790
    else
8791
#endif
8792
    {
8793
        output[idx++] = ssl->session->sessionIDSz;
8794
        if (ssl->session->sessionIDSz > 0) {
8795
            XMEMCPY(output + idx, ssl->session->sessionID,
8796
                ssl->session->sessionIDSz);
8797
            idx += ssl->session->sessionIDSz;
8798
        }
8799
    }
8800
8801
    /* Chosen cipher suite */
8802
    output[idx++] = ssl->options.cipherSuite0;
8803
    output[idx++] = ssl->options.cipherSuite;
8804
#ifdef WOLFSSL_DEBUG_TLS
8805
    WOLFSSL_MSG("Chosen cipher suite:");
8806
    WOLFSSL_MSG(GetCipherNameInternal(ssl->options.cipherSuite0,
8807
                                      ssl->options.cipherSuite));
8808
#endif
8809
8810
    /* Compression not supported in TLS v1.3. */
8811
    output[idx++] = 0;
8812
8813
    /* Extensions */
8814
    ret = TLSX_WriteResponse(ssl, output + idx, extMsgType, NULL);
8815
    if (ret != 0)
8816
        return ret;
8817
8818
    /* When we send a HRR, we store the selected key share group to later check
8819
     * that the client uses the same group in the second ClientHello.
8820
     *
8821
     * In case of stateless DTLS, we do not store the group, however, as it is
8822
     * already stored in the cookie that is sent to the client. We later recover
8823
     * the group from the cookie to prevent storing a state in a stateless
8824
     * server.
8825
     *
8826
     * Similar logic holds for the hrrCipherSuite. */
8827
    if (extMsgType == hello_retry_request
8828
#if defined(WOLFSSL_DTLS13) && defined(WOLFSSL_SEND_HRR_COOKIE)
8829
        && (!ssl->options.dtls || ssl->options.dtlsStateful)
8830
#endif
8831
    ) {
8832
        TLSX* ksExt = TLSX_Find(ssl->extensions, TLSX_KEY_SHARE);
8833
        if (ksExt != NULL) {
8834
            KeyShareEntry* kse = (KeyShareEntry*)ksExt->data;
8835
            if (kse != NULL)
8836
                ssl->hrr_keyshare_group = kse->group;
8837
        }
8838
8839
        ssl->options.hrrCipherSuite0 = ssl->options.cipherSuite0;
8840
        ssl->options.hrrCipherSuite  = ssl->options.cipherSuite;
8841
    }
8842
8843
#ifdef WOLFSSL_SEND_HRR_COOKIE
8844
    if (ssl->options.sendCookie && extMsgType == hello_retry_request) {
8845
        /* Reset the hashes from here. We will be able to restart the hashes
8846
         * from the cookie in RestartHandshakeHashWithCookie */
8847
#ifdef WOLFSSL_DTLS13
8848
        /* When ssl->options.dtlsStateful is not set then cookie is calculated
8849
         * in dtls.c */
8850
        if (ssl->options.dtls && !ssl->options.dtlsStateful)
8851
            ret = 0;
8852
        else
8853
#endif
8854
            ret = InitHandshakeHashes(ssl);
8855
    }
8856
    else
8857
#endif
8858
    {
8859
#ifdef WOLFSSL_DTLS13
8860
        if (ssl->options.dtls) {
8861
            ret = Dtls13HashHandshake(
8862
                ssl,
8863
                output + Dtls13GetRlHeaderLength(ssl, 0) ,
8864
                (word16)sendSz - Dtls13GetRlHeaderLength(ssl, 0));
8865
        }
8866
        else
8867
#endif /* WOLFSSL_DTLS13 */
8868
        {
8869
#if defined(HAVE_ECH)
8870
            if (ssl->ctx->echConfigs != NULL && !ssl->options.disableECH) {
8871
                echX = TLSX_Find(ssl->extensions, TLSX_ECH);
8872
                if (echX == NULL)
8873
                    return WOLFSSL_FATAL_ERROR;
8874
                /* use hrr offset */
8875
                if (extMsgType == hello_retry_request) {
8876
                    acceptOffset =
8877
                        (word32)(((WOLFSSL_ECH*)echX->data)->confBuf - output);
8878
                    acceptLabel = (byte*)echHrrAcceptConfirmationLabel;
8879
                    acceptLabelSz = ECH_HRR_ACCEPT_CONFIRMATION_LABEL_SZ;
8880
                }
8881
                /* replace the last 8 bytes of server random with the accept */
8882
                if (((WOLFSSL_ECH*)echX->data)->state == ECH_PARSED_INTERNAL) {
8883
                    if (ret == 0) {
8884
                        ret = EchWriteAcceptance(ssl, acceptLabel,
8885
                            acceptLabelSz, output + RECORD_HEADER_SZ,
8886
                            acceptOffset - RECORD_HEADER_SZ,
8887
                            sendSz - RECORD_HEADER_SZ, extMsgType);
8888
                    }
8889
                    if (extMsgType == hello_retry_request) {
8890
                        /* reset the ech state for round 2 */
8891
                        ((WOLFSSL_ECH*)echX->data)->state = ECH_WRITE_NONE;
8892
                        /* inner hello no longer needed, free it */
8893
                        XFREE(((WOLFSSL_ECH*)echX->data)->innerClientHello,
8894
                              ssl->heap, DYNAMIC_TYPE_TMP_BUFFER);
8895
                        ((WOLFSSL_ECH*)echX->data)->innerClientHello = NULL;
8896
                    }
8897
                    else {
8898
                        if (ret == 0) {
8899
                            /* update serverRandom on success */
8900
                            XMEMCPY(ssl->arrays->serverRandom,
8901
                                output + acceptOffset -
8902
                                (RAN_LEN -ECH_ACCEPT_CONFIRMATION_SZ), RAN_LEN);
8903
                        }
8904
                        /* remove ech so we don't keep sending it in write */
8905
                        TLSX_Remove(&ssl->extensions, TLSX_ECH, ssl->heap);
8906
                    }
8907
                }
8908
            }
8909
#endif
8910
            if (ret == 0)
8911
                ret = HashOutput(ssl, output, sendSz, 0);
8912
        }
8913
    }
8914
8915
    if (ret != 0)
8916
        return ret;
8917
8918
#if defined(WOLFSSL_CALLBACKS) || defined(OPENSSL_EXTRA)
8919
    if (ssl->hsInfoOn)
8920
        AddPacketName(ssl, "ServerHello");
8921
    if (ssl->toInfoOn) {
8922
        ret = AddPacketInfo(ssl, "ServerHello", handshake, output, sendSz,
8923
                      WRITE_PROTO, 0, ssl->heap);
8924
        if (ret != 0)
8925
            return ret;
8926
    }
8927
    #endif
8928
8929
    if (extMsgType == server_hello)
8930
        ssl->options.serverState = SERVER_HELLO_COMPLETE;
8931
8932
    ssl->options.buildingMsg = 0;
8933
#ifdef WOLFSSL_DTLS13
8934
    if (ssl->options.dtls) {
8935
        ret = Dtls13HandshakeSend(ssl, output, (word16)sendSz, (word16)sendSz,
8936
            (enum HandShakeType)extMsgType, 0);
8937
8938
        WOLFSSL_LEAVE("SendTls13ServerHello", ret);
8939
        WOLFSSL_END(WC_FUNC_SERVER_HELLO_SEND);
8940
        return ret;
8941
    }
8942
#endif /* WOLFSSL_DTLS13 */
8943
8944
    ssl->buffers.outputBuffer.length += (word32)sendSz;
8945
8946
    if (!ssl->options.groupMessages || extMsgType != server_hello)
8947
        ret = SendBuffered(ssl);
8948
8949
    WOLFSSL_LEAVE("SendTls13ServerHello", ret);
8950
    WOLFSSL_END(WC_FUNC_SERVER_HELLO_SEND);
8951
8952
    return ret;
8953
}
8954
8955
/* handle generation of TLS 1.3 encrypted_extensions (8) */
8956
/* Send the rest of the extensions encrypted under the handshake key.
8957
 * This message is always encrypted in TLS v1.3.
8958
 * Only a server will send this message.
8959
 *
8960
 * ssl  The SSL/TLS object.
8961
 * returns 0 on success, otherwise failure.
8962
 */
8963
static int SendTls13EncryptedExtensions(WOLFSSL* ssl)
8964
0
{
8965
0
    int    ret;
8966
0
    byte*  output;
8967
0
    word16 length = 0;
8968
0
    word32 idx;
8969
0
    int    sendSz;
8970
8971
0
    WOLFSSL_START(WC_FUNC_ENCRYPTED_EXTENSIONS_SEND);
8972
0
    WOLFSSL_ENTER("SendTls13EncryptedExtensions");
8973
8974
0
    ssl->options.buildingMsg = 1;
8975
0
    ssl->keys.encryptionOn = 1;
8976
8977
#ifdef WOLFSSL_DTLS13
8978
    if (ssl->options.dtls) {
8979
        idx = Dtls13GetHeadersLength(ssl, encrypted_extensions);
8980
    }
8981
    else
8982
#endif /* WOLFSSL_DTLS13 */
8983
0
    {
8984
0
        idx = RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ;
8985
0
    }
8986
8987
#ifdef WOLFSSL_ASYNC_CRYPT
8988
    /* A suspended build already ran the key schedule below; re-running it
8989
     * would extract in place over preMasterSecret a second time. */
8990
    if (ssl->options.buildArgs13Set)
8991
        goto tls13_send_ee_build;
8992
#endif
8993
8994
0
#if defined(HAVE_SUPPORTED_CURVES) && !defined(WOLFSSL_NO_SERVER_GROUPS_EXT)
8995
0
    if ((ret = TLSX_SupportedCurve_CheckPriority(ssl)) != 0)
8996
0
        return ret;
8997
0
#endif
8998
8999
    /* Derive the handshake secret now that we are at first message to be
9000
     * encrypted under the keys.
9001
     */
9002
0
    if (ssl->kdfDeriveStep <= TLS13_SEND_KDF_NONE) {
9003
0
        ret = DeriveHandshakeSecret(ssl);
9004
0
        if (ret != 0) {
9005
0
            if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
9006
0
                ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
9007
0
            return ret;
9008
0
        }
9009
0
        ssl->kdfDeriveStep = TLS13_SEND_KDF_EE_HS_SECRET;
9010
0
    }
9011
0
    if (ssl->kdfDeriveStep <= TLS13_SEND_KDF_EE_HS_SECRET) {
9012
0
        ret = DeriveTls13Keys(ssl, handshake_key, ENCRYPT_AND_DECRYPT_SIDE, 1);
9013
0
        if (ret != 0) {
9014
0
            if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
9015
0
                ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
9016
0
            return ret;
9017
0
        }
9018
0
        ssl->kdfDeriveStep = TLS13_SEND_KDF_EE_HS_KEYS;
9019
0
    }
9020
9021
    /* Setup encrypt/decrypt keys for following messages. */
9022
#ifdef WOLFSSL_EARLY_DATA
9023
    if (ssl->kdfDeriveStep <= TLS13_SEND_KDF_EE_HS_KEYS) {
9024
        ret = SetKeysSide(ssl, ENCRYPT_SIDE_ONLY);
9025
        if (ret != 0) {
9026
            if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
9027
                ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
9028
            return ret;
9029
        }
9030
        ssl->kdfDeriveStep = TLS13_SEND_KDF_EE_ENC_KEYS_SET;
9031
    }
9032
    if (ssl->earlyData != process_early_data) {
9033
        if (ssl->kdfDeriveStep <= TLS13_SEND_KDF_EE_ENC_KEYS_SET) {
9034
            ret = SetKeysSide(ssl, DECRYPT_SIDE_ONLY);
9035
            if (ret != 0) {
9036
                if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
9037
                    ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
9038
                return ret;
9039
            }
9040
            ssl->kdfDeriveStep = TLS13_SEND_KDF_EE_KEYS_SET;
9041
        }
9042
    }
9043
#else
9044
0
    if (ssl->kdfDeriveStep <= TLS13_SEND_KDF_EE_ENC_KEYS_SET) {
9045
0
        ret = SetKeysSide(ssl, ENCRYPT_AND_DECRYPT_SIDE);
9046
0
        if (ret != 0) {
9047
0
            if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
9048
0
                ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
9049
0
            return ret;
9050
0
        }
9051
0
        ssl->kdfDeriveStep = TLS13_SEND_KDF_EE_KEYS_SET;
9052
0
    }
9053
0
#endif
9054
#ifdef WOLFSSL_QUIC
9055
    if (IsAtLeastTLSv1_3(ssl->version) && WOLFSSL_IS_QUIC(ssl)) {
9056
        ret = wolfSSL_quic_add_transport_extensions(ssl, encrypted_extensions);
9057
        if (ret != 0)
9058
            return ret;
9059
    }
9060
#endif
9061
9062
#ifdef WOLFSSL_DTLS13
9063
    if (ssl->options.dtls) {
9064
        w64wrapper epochHandshake = w64From32(0, DTLS13_EPOCH_HANDSHAKE);
9065
        ssl->dtls13Epoch = epochHandshake;
9066
9067
        if (ssl->kdfDeriveStep <= TLS13_SEND_KDF_EE_KEYS_SET) {
9068
            ret = Dtls13SetEpochKeys(ssl, epochHandshake,
9069
                                     ENCRYPT_AND_DECRYPT_SIDE);
9070
            if (ret != 0) {
9071
                if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
9072
                    ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
9073
                return ret;
9074
            }
9075
            ssl->kdfDeriveStep = TLS13_SEND_KDF_EE_DTLS_EPOCH;
9076
        }
9077
    }
9078
#endif /* WOLFSSL_DTLS13 */
9079
0
    ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
9080
9081
#ifdef WOLFSSL_ASYNC_CRYPT
9082
tls13_send_ee_build:
9083
#endif
9084
9085
0
    ret = TLSX_GetResponseSize(ssl, encrypted_extensions, &length);
9086
0
    if (ret != 0)
9087
0
        return ret;
9088
9089
0
    sendSz = (int)(idx + length);
9090
    /* Encryption always on. */
9091
0
    sendSz += MAX_MSG_EXTRA;
9092
9093
    /* Check buffers are big enough and grow if needed. */
9094
0
    ret = CheckAvailableSize(ssl, sendSz);
9095
0
    if (ret != 0)
9096
0
        return ret;
9097
9098
    /* Get position in output buffer to write new message to. */
9099
0
    output = GetOutputBuffer(ssl);
9100
9101
#ifdef WOLFSSL_ASYNC_CRYPT
9102
    /* Skip on a resume: BuildTls13Message already replaced the record
9103
     * header; rewriting the plaintext headers would corrupt it. */
9104
    if (!ssl->options.buildArgs13Set)
9105
#endif
9106
0
    {
9107
        /* Put the record and handshake headers on. */
9108
0
        AddTls13Headers(output, length, encrypted_extensions, ssl);
9109
9110
0
        ret = TLSX_WriteResponse(ssl, output + idx, encrypted_extensions, NULL);
9111
0
        if (ret != 0)
9112
0
            return ret;
9113
0
    }
9114
0
    idx += length;
9115
9116
0
#if defined(WOLFSSL_CALLBACKS) || defined(OPENSSL_EXTRA)
9117
0
    if (ssl->hsInfoOn)
9118
0
        AddPacketName(ssl, "EncryptedExtensions");
9119
0
    if (ssl->toInfoOn) {
9120
0
        ret = AddPacketInfo(ssl, "EncryptedExtensions", handshake, output,
9121
0
                      sendSz, WRITE_PROTO, 0, ssl->heap);
9122
0
        if (ret != 0)
9123
0
            return ret;
9124
0
    }
9125
0
#endif
9126
9127
#ifdef WOLFSSL_DTLS13
9128
    if (ssl->options.dtls) {
9129
        ssl->options.buildingMsg = 0;
9130
        ret = Dtls13HandshakeSend(ssl, output, (word16)sendSz, (word16)idx,
9131
                                  encrypted_extensions, 1);
9132
9133
        if (ret == 0)
9134
            ssl->options.serverState = SERVER_ENCRYPTED_EXTENSIONS_COMPLETE;
9135
9136
        WOLFSSL_LEAVE("SendTls13EncryptedExtensions", ret);
9137
        WOLFSSL_END(WC_FUNC_ENCRYPTED_EXTENSIONS_SEND);
9138
9139
        return ret;
9140
    }
9141
#endif /* WOLFSSL_DTLS13 */
9142
9143
    /* This handshake message is always encrypted. */
9144
0
    sendSz = BuildTls13Message(ssl, output, sendSz, output + RECORD_HEADER_SZ,
9145
0
                               (int)(idx - RECORD_HEADER_SZ),
9146
0
                               handshake, 1, 0, TLS13_HS_ASYNC_OKAY);
9147
0
    if (sendSz < 0)
9148
0
        return sendSz;
9149
9150
0
    ssl->buffers.outputBuffer.length += (word32)sendSz;
9151
0
    ssl->options.buildingMsg = 0;
9152
0
    ssl->options.serverState = SERVER_ENCRYPTED_EXTENSIONS_COMPLETE;
9153
9154
0
    if (!ssl->options.groupMessages)
9155
0
        ret = SendBuffered(ssl);
9156
9157
9158
0
    WOLFSSL_LEAVE("SendTls13EncryptedExtensions", ret);
9159
0
    WOLFSSL_END(WC_FUNC_ENCRYPTED_EXTENSIONS_SEND);
9160
9161
0
    return ret;
9162
0
}
9163
9164
#ifndef NO_CERTS
9165
/* handle generation TLS v1.3 certificate_request (13) */
9166
/* Send the TLS v1.3 CertificateRequest message.
9167
 * This message is always encrypted in TLS v1.3.
9168
 * Only a server will send this message.
9169
 *
9170
 * ssl        SSL/TLS object.
9171
 * reqCtx     Request context.
9172
 * reqCtxLen  Length of context. 0 when sending as part of handshake.
9173
 * returns 0 on success, otherwise failure.
9174
 */
9175
static int SendTls13CertificateRequest(WOLFSSL* ssl, byte* reqCtx,
9176
                                       word32 reqCtxLen)
9177
0
{
9178
0
    byte*   output;
9179
0
    int    ret;
9180
0
    int    sendSz;
9181
0
    word32 i;
9182
0
    word32 reqSz;
9183
0
    SignatureAlgorithms* sa;
9184
9185
0
    WOLFSSL_START(WC_FUNC_CERTIFICATE_REQUEST_SEND);
9186
0
    WOLFSSL_ENTER("SendTls13CertificateRequest");
9187
9188
0
    ssl->options.buildingMsg = 1;
9189
9190
0
    if (ssl->options.side != WOLFSSL_SERVER_END)
9191
0
        return SIDE_ERROR;
9192
9193
    /* Use ssl->suites->hashSigAlgo so wolfSSL_set1_sigalgs_list() is honored.
9194
     * hashSigAlgoSz=0 makes GetSize/Write fall back to WOLFSSL_SUITES(ssl). */
9195
0
    sa = TLSX_SignatureAlgorithms_New(ssl, 0, ssl->heap);
9196
0
    if (sa == NULL)
9197
0
        return MEMORY_ERROR;
9198
0
    ret = TLSX_Push(&ssl->extensions, TLSX_SIGNATURE_ALGORITHMS, sa, ssl->heap);
9199
0
    if (ret != 0) {
9200
0
        TLSX_SignatureAlgorithms_FreeAll(sa, ssl->heap);
9201
0
        return ret;
9202
0
    }
9203
9204
0
    i = RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ;
9205
#ifdef WOLFSSL_DTLS13
9206
    if (ssl->options.dtls)
9207
        i = Dtls13GetRlHeaderLength(ssl, 1) + DTLS_HANDSHAKE_HEADER_SZ;
9208
#endif /* WOLFSSL_DTLS13 */
9209
9210
0
    reqSz = (word16)(OPAQUE8_LEN + reqCtxLen);
9211
0
    ret = TLSX_GetRequestSize(ssl, certificate_request, &reqSz);
9212
0
    if (ret != 0)
9213
0
        return ret;
9214
9215
0
    sendSz = (int)(i + reqSz);
9216
    /* Always encrypted and make room for padding. */
9217
0
    sendSz += MAX_MSG_EXTRA;
9218
9219
    /* Check buffers are big enough and grow if needed. */
9220
0
    if ((ret = CheckAvailableSize(ssl, sendSz)) != 0)
9221
0
        return ret;
9222
9223
    /* Get position in output buffer to write new message to. */
9224
0
    output = GetOutputBuffer(ssl);
9225
9226
    /* Put the record and handshake headers on. */
9227
0
    AddTls13Headers(output, reqSz, certificate_request, ssl);
9228
9229
    /* Certificate request context. */
9230
0
    output[i++] = (byte)reqCtxLen;
9231
0
    if (reqCtxLen != 0) {
9232
0
        XMEMCPY(output + i, reqCtx, reqCtxLen);
9233
0
        i += reqCtxLen;
9234
0
    }
9235
9236
    /* Certificate extensions. */
9237
0
    reqSz = 0;
9238
0
    ret = TLSX_WriteRequest(ssl, output + i, certificate_request, &reqSz);
9239
0
    if (ret != 0)
9240
0
        return ret;
9241
0
    i += reqSz;
9242
9243
#ifdef WOLFSSL_DTLS13
9244
    if (ssl->options.dtls) {
9245
        ssl->options.buildingMsg = 0;
9246
        ret =
9247
            Dtls13HandshakeSend(ssl, output, (word16)sendSz, (word16)i,
9248
                                certificate_request, 1);
9249
9250
        WOLFSSL_LEAVE("SendTls13CertificateRequest", ret);
9251
        WOLFSSL_END(WC_FUNC_CERTIFICATE_REQUEST_SEND);
9252
9253
        return ret;
9254
9255
    }
9256
#endif /* WOLFSSL_DTLS13 */
9257
9258
    /* Always encrypted. */
9259
0
    sendSz = BuildTls13Message(ssl, output, sendSz, output + RECORD_HEADER_SZ,
9260
0
                               (int)(i - RECORD_HEADER_SZ), handshake, 1, 0, 0);
9261
0
    if (sendSz < 0)
9262
0
        return sendSz;
9263
9264
0
    #if defined(WOLFSSL_CALLBACKS) || defined(OPENSSL_EXTRA)
9265
0
        if (ssl->hsInfoOn)
9266
0
            AddPacketName(ssl, "CertificateRequest");
9267
0
        if (ssl->toInfoOn) {
9268
0
            ret = AddPacketInfo(ssl, "CertificateRequest", handshake, output,
9269
0
                          sendSz, WRITE_PROTO, 0, ssl->heap);
9270
0
            if (ret != 0)
9271
0
                return ret;
9272
0
        }
9273
0
    #endif
9274
9275
0
    ssl->buffers.outputBuffer.length += (word32)sendSz;
9276
0
    ssl->options.buildingMsg = 0;
9277
0
    if (!ssl->options.groupMessages)
9278
0
        ret = SendBuffered(ssl);
9279
9280
0
    WOLFSSL_LEAVE("SendTls13CertificateRequest", ret);
9281
0
    WOLFSSL_END(WC_FUNC_CERTIFICATE_REQUEST_SEND);
9282
9283
0
    return ret;
9284
0
}
9285
#endif /* NO_CERTS */
9286
#endif /* NO_WOLFSSL_SERVER */
9287
9288
#ifndef NO_CERTS
9289
#if (!defined(NO_WOLFSSL_SERVER) || !defined(WOLFSSL_NO_CLIENT_AUTH)) && \
9290
    (!defined(NO_RSA) || defined(HAVE_ECC) || defined(HAVE_ED25519) || \
9291
     defined(HAVE_ED448) || defined(HAVE_FALCON) || defined(WOLFSSL_HAVE_MLDSA) || \
9292
     defined(WOLFSSL_HAVE_SLHDSA))
9293
/* Encode the signature algorithm into buffer.
9294
 *
9295
 * hashalgo  The hash algorithm.
9296
 * hsType   The signature type.
9297
 * output    The buffer to encode into.
9298
 */
9299
static WC_INLINE void EncodeSigAlg(const WOLFSSL * ssl, byte hashAlgo,
9300
    byte hsType, byte* output)
9301
{
9302
    (void)ssl;
9303
    (void)hashAlgo;
9304
    switch (hsType) {
9305
#ifdef HAVE_ECC
9306
        case ecc_dsa_sa_algo:
9307
            if (ssl->pkCurveOID == ECC_BRAINPOOLP256R1_OID) {
9308
                output[0] = NEW_SA_MAJOR;
9309
                output[1] = ECDSA_BRAINPOOLP256R1TLS13_SHA256_MINOR;
9310
            }
9311
            else if (ssl->pkCurveOID == ECC_BRAINPOOLP384R1_OID) {
9312
                output[0] = NEW_SA_MAJOR;
9313
                output[1] = ECDSA_BRAINPOOLP384R1TLS13_SHA384_MINOR;
9314
            }
9315
            else if (ssl->pkCurveOID == ECC_BRAINPOOLP512R1_OID) {
9316
                output[0] = NEW_SA_MAJOR;
9317
                output[1] = ECDSA_BRAINPOOLP512R1TLS13_SHA512_MINOR;
9318
            }
9319
            else {
9320
                output[0] = hashAlgo;
9321
                output[1] = ecc_dsa_sa_algo;
9322
            }
9323
            break;
9324
#endif
9325
#if defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3)
9326
        case sm2_sa_algo:
9327
            output[0] = SM2_SA_MAJOR;
9328
            output[1] = SM2_SA_MINOR;
9329
            break;
9330
#endif
9331
#ifdef HAVE_ED25519
9332
        /* ED25519: 0x0807 */
9333
        case ed25519_sa_algo:
9334
            output[0] = ED25519_SA_MAJOR;
9335
            output[1] = ED25519_SA_MINOR;
9336
            break;
9337
#endif
9338
#ifdef HAVE_ED448
9339
        /* ED448: 0x0808 */
9340
        case ed448_sa_algo:
9341
            output[0] = ED448_SA_MAJOR;
9342
            output[1] = ED448_SA_MINOR;
9343
            break;
9344
#endif
9345
#ifndef NO_RSA
9346
        /* PSS signatures: 0x080[4-6] or 0x080[9-B] */
9347
        case rsa_pss_sa_algo:
9348
            output[0] = rsa_pss_sa_algo;
9349
#ifdef WC_RSA_PSS
9350
            /* If the private key uses the RSA-PSS OID, and the peer supports
9351
             * the rsa_pss_pss_* signature algorithm in use, then report
9352
             * rsa_pss_pss_* rather than rsa_pss_rsae_*. */
9353
            if (ssl->useRsaPss &&
9354
                ((ssl->pssAlgo & (1U << hashAlgo)) != 0U) &&
9355
                (sha256_mac <= hashAlgo) && (hashAlgo <= sha512_mac))
9356
            {
9357
                output[1] = PSS_RSAE_TO_PSS_PSS(hashAlgo);
9358
            }
9359
            else
9360
#endif
9361
            {
9362
                output[1] = hashAlgo;
9363
            }
9364
            break;
9365
#endif
9366
#ifdef HAVE_FALCON
9367
        case falcon_level1_sa_algo:
9368
            output[0] = FALCON_LEVEL1_SA_MAJOR;
9369
            output[1] = FALCON_LEVEL1_SA_MINOR;
9370
            break;
9371
        case falcon_level5_sa_algo:
9372
            output[0] = FALCON_LEVEL5_SA_MAJOR;
9373
            output[1] = FALCON_LEVEL5_SA_MINOR;
9374
            break;
9375
#endif
9376
#ifdef WOLFSSL_HAVE_MLDSA
9377
        case mldsa_44_sa_algo:
9378
            output[0] = MLDSA_44_SA_MAJOR;
9379
            output[1] = MLDSA_44_SA_MINOR;
9380
            break;
9381
        case mldsa_65_sa_algo:
9382
            output[0] = MLDSA_65_SA_MAJOR;
9383
            output[1] = MLDSA_65_SA_MINOR;
9384
            break;
9385
        case mldsa_87_sa_algo:
9386
            output[0] = MLDSA_87_SA_MAJOR;
9387
            output[1] = MLDSA_87_SA_MINOR;
9388
            break;
9389
#endif
9390
#ifdef WOLFSSL_HAVE_SLHDSA
9391
    #if defined(WOLFSSL_SLHDSA_SHA2) && defined(WOLFSSL_SLHDSA_PARAM_SHA2_128S)
9392
        case slhdsa_sha2_128s_sa_algo:
9393
            output[0] = SLHDSA_SA_MAJOR;
9394
            output[1] = SLHDSA_SHA2_128S_SA_MINOR;
9395
            break;
9396
    #endif
9397
    #if defined(WOLFSSL_SLHDSA_SHA2) && defined(WOLFSSL_SLHDSA_PARAM_SHA2_128F)
9398
        case slhdsa_sha2_128f_sa_algo:
9399
            output[0] = SLHDSA_SA_MAJOR;
9400
            output[1] = SLHDSA_SHA2_128F_SA_MINOR;
9401
            break;
9402
    #endif
9403
    #if defined(WOLFSSL_SLHDSA_SHA2) && defined(WOLFSSL_SLHDSA_PARAM_SHA2_192S)
9404
        case slhdsa_sha2_192s_sa_algo:
9405
            output[0] = SLHDSA_SA_MAJOR;
9406
            output[1] = SLHDSA_SHA2_192S_SA_MINOR;
9407
            break;
9408
    #endif
9409
    #if defined(WOLFSSL_SLHDSA_SHA2) && defined(WOLFSSL_SLHDSA_PARAM_SHA2_192F)
9410
        case slhdsa_sha2_192f_sa_algo:
9411
            output[0] = SLHDSA_SA_MAJOR;
9412
            output[1] = SLHDSA_SHA2_192F_SA_MINOR;
9413
            break;
9414
    #endif
9415
    #if defined(WOLFSSL_SLHDSA_SHA2) && defined(WOLFSSL_SLHDSA_PARAM_SHA2_256S)
9416
        case slhdsa_sha2_256s_sa_algo:
9417
            output[0] = SLHDSA_SA_MAJOR;
9418
            output[1] = SLHDSA_SHA2_256S_SA_MINOR;
9419
            break;
9420
    #endif
9421
    #if defined(WOLFSSL_SLHDSA_SHA2) && defined(WOLFSSL_SLHDSA_PARAM_SHA2_256F)
9422
        case slhdsa_sha2_256f_sa_algo:
9423
            output[0] = SLHDSA_SA_MAJOR;
9424
            output[1] = SLHDSA_SHA2_256F_SA_MINOR;
9425
            break;
9426
    #endif
9427
    #ifdef WOLFSSL_SLHDSA_PARAM_128S
9428
        case slhdsa_shake_128s_sa_algo:
9429
            output[0] = SLHDSA_SA_MAJOR;
9430
            output[1] = SLHDSA_SHAKE_128S_SA_MINOR;
9431
            break;
9432
    #endif
9433
    #ifdef WOLFSSL_SLHDSA_PARAM_128F
9434
        case slhdsa_shake_128f_sa_algo:
9435
            output[0] = SLHDSA_SA_MAJOR;
9436
            output[1] = SLHDSA_SHAKE_128F_SA_MINOR;
9437
            break;
9438
    #endif
9439
    #ifdef WOLFSSL_SLHDSA_PARAM_192S
9440
        case slhdsa_shake_192s_sa_algo:
9441
            output[0] = SLHDSA_SA_MAJOR;
9442
            output[1] = SLHDSA_SHAKE_192S_SA_MINOR;
9443
            break;
9444
    #endif
9445
    #ifdef WOLFSSL_SLHDSA_PARAM_192F
9446
        case slhdsa_shake_192f_sa_algo:
9447
            output[0] = SLHDSA_SA_MAJOR;
9448
            output[1] = SLHDSA_SHAKE_192F_SA_MINOR;
9449
            break;
9450
    #endif
9451
    #ifdef WOLFSSL_SLHDSA_PARAM_256S
9452
        case slhdsa_shake_256s_sa_algo:
9453
            output[0] = SLHDSA_SA_MAJOR;
9454
            output[1] = SLHDSA_SHAKE_256S_SA_MINOR;
9455
            break;
9456
    #endif
9457
    #ifdef WOLFSSL_SLHDSA_PARAM_256F
9458
        case slhdsa_shake_256f_sa_algo:
9459
            output[0] = SLHDSA_SA_MAJOR;
9460
            output[1] = SLHDSA_SHAKE_256F_SA_MINOR;
9461
            break;
9462
    #endif
9463
#endif /* WOLFSSL_HAVE_SLHDSA */
9464
        default:
9465
            break;
9466
    }
9467
}
9468
#endif
9469
9470
#if !defined(NO_RSA) || defined(HAVE_ECC) || defined(HAVE_ED25519) || \
9471
    defined(HAVE_ED448) || defined(HAVE_FALCON) || defined(WOLFSSL_HAVE_MLDSA) || \
9472
    defined(WOLFSSL_HAVE_SLHDSA)
9473
#ifdef WOLFSSL_DUAL_ALG_CERTS
9474
/* These match up with what the OQS team has defined. */
9475
#define HYBRID_SA_MAJOR 0xFE
9476
#define HYBRID_P256_MLDSA_44_SA_MINOR            0xA1
9477
#define HYBRID_RSA3072_MLDSA_44_SA_MINOR         0xA2
9478
#define HYBRID_P384_MLDSA_65_SA_MINOR            0xA4
9479
#define HYBRID_P521_MLDSA_87_SA_MINOR            0xA6
9480
/* Falcon hybrid codepoints aligned with oqs-provider. */
9481
#define HYBRID_P256_FALCON_LEVEL1_SA_MINOR       0xD8
9482
#define HYBRID_RSA3072_FALCON_LEVEL1_SA_MINOR    0xD9
9483
#define HYBRID_P521_FALCON_LEVEL5_SA_MINOR       0xDB
9484
9485
/* Custom defined ones for PQC first */
9486
#define HYBRID_MLDSA_44_P256_SA_MINOR            0xD1
9487
#define HYBRID_MLDSA_44_RSA3072_SA_MINOR         0xD2
9488
#define HYBRID_MLDSA_65_P384_SA_MINOR            0xD3
9489
#define HYBRID_MLDSA_87_P521_SA_MINOR            0xD4
9490
#define HYBRID_FALCON_LEVEL1_P256_SA_MINOR       0xD5
9491
#define HYBRID_FALCON_LEVEL1_RSA3072_SA_MINOR    0xD6
9492
#define HYBRID_FALCON_LEVEL5_P521_SA_MINOR       0xD7
9493
9494
9495
static void EncodeDualSigAlg(byte sigAlg, byte altSigAlg, byte* output)
9496
{
9497
    /* Initialize output to error indicator. */
9498
    output[0] = 0x0;
9499
    output[1] = 0x0;
9500
9501
    if (sigAlg == ecc_dsa_sa_algo && altSigAlg == mldsa_44_sa_algo) {
9502
        output[1] = HYBRID_P256_MLDSA_44_SA_MINOR;
9503
    }
9504
    else if (sigAlg == rsa_pss_sa_algo &&
9505
             altSigAlg == mldsa_44_sa_algo) {
9506
        output[1] = HYBRID_RSA3072_MLDSA_44_SA_MINOR;
9507
    }
9508
    else if (sigAlg == ecc_dsa_sa_algo &&
9509
             altSigAlg == mldsa_65_sa_algo) {
9510
        output[1] = HYBRID_P384_MLDSA_65_SA_MINOR;
9511
    }
9512
    else if (sigAlg == ecc_dsa_sa_algo &&
9513
             altSigAlg == mldsa_87_sa_algo) {
9514
        output[1] = HYBRID_P521_MLDSA_87_SA_MINOR;
9515
    }
9516
    else if (sigAlg == ecc_dsa_sa_algo &&
9517
             altSigAlg == falcon_level1_sa_algo) {
9518
        output[1] = HYBRID_P256_FALCON_LEVEL1_SA_MINOR;
9519
    }
9520
    else if (sigAlg == rsa_pss_sa_algo &&
9521
             altSigAlg == falcon_level1_sa_algo) {
9522
        output[1] = HYBRID_RSA3072_FALCON_LEVEL1_SA_MINOR;
9523
    }
9524
    else if (sigAlg == ecc_dsa_sa_algo &&
9525
             altSigAlg == falcon_level5_sa_algo) {
9526
        output[1] = HYBRID_P521_FALCON_LEVEL5_SA_MINOR;
9527
    }
9528
    else if (sigAlg == mldsa_44_sa_algo &&
9529
             altSigAlg == ecc_dsa_sa_algo) {
9530
        output[1] = HYBRID_MLDSA_44_P256_SA_MINOR;
9531
    }
9532
    else if (sigAlg == mldsa_44_sa_algo &&
9533
             altSigAlg == rsa_pss_sa_algo) {
9534
        output[1] = HYBRID_MLDSA_44_RSA3072_SA_MINOR;
9535
    }
9536
    else if (sigAlg == mldsa_65_sa_algo &&
9537
             altSigAlg == ecc_dsa_sa_algo) {
9538
        output[1] = HYBRID_MLDSA_65_P384_SA_MINOR;
9539
    }
9540
    else if (sigAlg == mldsa_87_sa_algo &&
9541
             altSigAlg == ecc_dsa_sa_algo) {
9542
        output[1] = HYBRID_MLDSA_87_P521_SA_MINOR;
9543
    }
9544
    else if (sigAlg == falcon_level1_sa_algo &&
9545
             altSigAlg == ecc_dsa_sa_algo) {
9546
        output[1] = HYBRID_FALCON_LEVEL1_P256_SA_MINOR;
9547
    }
9548
    else if (sigAlg == falcon_level1_sa_algo &&
9549
             altSigAlg == rsa_pss_sa_algo) {
9550
        output[1] = HYBRID_FALCON_LEVEL1_RSA3072_SA_MINOR;
9551
    }
9552
    else if (sigAlg == falcon_level5_sa_algo &&
9553
             altSigAlg == ecc_dsa_sa_algo) {
9554
        output[1] = HYBRID_FALCON_LEVEL5_P521_SA_MINOR;
9555
    }
9556
9557
    if (output[1] != 0x0) {
9558
        output[0] = HYBRID_SA_MAJOR;
9559
    }
9560
}
9561
#endif /* WOLFSSL_DUAL_ALG_CERTS */
9562
9563
static enum wc_MACAlgorithm GetNewSAHashAlgo(int typeIn)
9564
0
{
9565
0
    switch (typeIn) {
9566
0
        case RSA_PSS_RSAE_SHA256_MINOR:
9567
0
        case RSA_PSS_PSS_SHA256_MINOR:
9568
0
        case ECDSA_BRAINPOOLP256R1TLS13_SHA256_MINOR:
9569
0
            return sha256_mac;
9570
9571
0
        case RSA_PSS_RSAE_SHA384_MINOR:
9572
0
        case RSA_PSS_PSS_SHA384_MINOR:
9573
0
        case ECDSA_BRAINPOOLP384R1TLS13_SHA384_MINOR:
9574
0
            return sha384_mac;
9575
9576
0
        case RSA_PSS_RSAE_SHA512_MINOR:
9577
0
        case RSA_PSS_PSS_SHA512_MINOR:
9578
0
        case ED25519_SA_MINOR:
9579
0
        case ED448_SA_MINOR:
9580
0
        case ECDSA_BRAINPOOLP512R1TLS13_SHA512_MINOR:
9581
0
            return sha512_mac;
9582
0
        default:
9583
0
            return no_mac;
9584
0
    }
9585
0
}
9586
9587
/* Decode the signature algorithm.
9588
 *
9589
 * input     The encoded signature algorithm.
9590
 * hashalgo  The hash algorithm.
9591
 * hsType    The signature type.
9592
 * returns INVALID_PARAMETER if not recognized and 0 otherwise.
9593
 */
9594
static WC_INLINE int DecodeTls13SigAlg(byte* input, byte* hashAlgo,
9595
                                       byte* hsType)
9596
0
{
9597
0
    int ret = 0;
9598
#if defined(WOLFSSL_HAVE_SLHDSA)
9599
    byte slhType;
9600
#endif
9601
9602
0
    switch (input[0]) {
9603
0
    #if defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3)
9604
0
        case SM2_SA_MAJOR:
9605
0
            if (input[1] == SM2_SA_MINOR) {
9606
0
                *hsType = sm2_sa_algo;
9607
0
                *hashAlgo = sm3_mac;
9608
0
            }
9609
0
            else
9610
0
                ret = INVALID_PARAMETER;
9611
0
            break;
9612
0
    #endif
9613
0
        case NEW_SA_MAJOR:
9614
0
        {
9615
0
            enum wc_MACAlgorithm mac = GetNewSAHashAlgo(input[1]);
9616
0
            *hashAlgo = (byte)mac;
9617
0
        }
9618
9619
            /* PSS encryption: 0x080[4-6] */
9620
0
            if (input[1] >= RSA_PSS_RSAE_SHA256_MINOR &&
9621
0
                    input[1] <= RSA_PSS_RSAE_SHA512_MINOR) {
9622
0
                *hsType   = input[0];
9623
0
            }
9624
            /* PSS signature: 0x080[9-B] */
9625
0
            else if (input[1] >= RSA_PSS_PSS_SHA256_MINOR &&
9626
0
                    input[1] <= RSA_PSS_PSS_SHA512_MINOR) {
9627
0
                *hsType   = input[0];
9628
0
            }
9629
0
    #ifdef HAVE_ED25519
9630
            /* ED25519: 0x0807 */
9631
0
            else if (input[1] == ED25519_SA_MINOR) {
9632
0
                *hsType = ed25519_sa_algo;
9633
                /* Hash performed as part of sign/verify operation. */
9634
0
            }
9635
0
    #endif
9636
0
    #ifdef HAVE_ED448
9637
            /* ED448: 0x0808 */
9638
0
            else if (input[1] == ED448_SA_MINOR) {
9639
0
                *hsType = ed448_sa_algo;
9640
                /* Hash performed as part of sign/verify operation. */
9641
0
            }
9642
0
    #endif
9643
0
    #ifdef HAVE_ECC_BRAINPOOL
9644
0
            else if ((input[1] == ECDSA_BRAINPOOLP256R1TLS13_SHA256_MINOR) ||
9645
0
                     (input[1] == ECDSA_BRAINPOOLP384R1TLS13_SHA384_MINOR) ||
9646
0
                     (input[1] == ECDSA_BRAINPOOLP512R1TLS13_SHA512_MINOR)) {
9647
0
                *hsType = ecc_dsa_sa_algo;
9648
0
            }
9649
0
    #endif
9650
0
            else
9651
0
                ret = INVALID_PARAMETER;
9652
0
            break;
9653
#if defined(HAVE_FALCON)
9654
        case FALCON_SA_MAJOR:
9655
            if (input[1] == FALCON_LEVEL1_SA_MINOR) {
9656
                *hsType = falcon_level1_sa_algo;
9657
                /* Hash performed as part of sign/verify operation. */
9658
                *hashAlgo = sha512_mac;
9659
            } else if (input[1] == FALCON_LEVEL5_SA_MINOR) {
9660
                *hsType = falcon_level5_sa_algo;
9661
                /* Hash performed as part of sign/verify operation. */
9662
                *hashAlgo = sha512_mac;
9663
            }
9664
            else
9665
                ret = INVALID_PARAMETER;
9666
            break;
9667
#endif /* HAVE_FALCON */
9668
#if defined(WOLFSSL_HAVE_MLDSA) || defined(WOLFSSL_HAVE_SLHDSA)
9669
        /* ML-DSA and SLH-DSA share the same major byte (0x09); their minor
9670
         * bytes are disjoint (ML-DSA 0x04-0x06, SLH-DSA 0x11-0x1C). */
9671
        case MLDSA_SA_MAJOR:
9672
            ret = INVALID_PARAMETER;
9673
    #if defined(WOLFSSL_HAVE_MLDSA)
9674
            if (input[1] == MLDSA_44_SA_MINOR) {
9675
                *hsType = mldsa_44_sa_algo;
9676
                /* Hash performed as part of sign/verify operation. */
9677
                *hashAlgo = sha512_mac;
9678
                ret = 0;
9679
            } else if (input[1] == MLDSA_65_SA_MINOR) {
9680
                *hsType = mldsa_65_sa_algo;
9681
                *hashAlgo = sha512_mac;
9682
                ret = 0;
9683
            } else if (input[1] == MLDSA_87_SA_MINOR) {
9684
                *hsType = mldsa_87_sa_algo;
9685
                *hashAlgo = sha512_mac;
9686
                ret = 0;
9687
            }
9688
    #endif /* WOLFSSL_HAVE_MLDSA */
9689
    #if defined(WOLFSSL_HAVE_SLHDSA)
9690
            if (ret != 0) {
9691
                slhType = SlhDsaSigMinorToType(input[1]);
9692
                if (slhType != (byte)invalid_sa_algo) {
9693
                    *hsType = slhType;
9694
                    /* Hash performed as part of sign/verify operation. */
9695
                    *hashAlgo = sha512_mac;
9696
                    ret = 0;
9697
                }
9698
            }
9699
    #endif /* WOLFSSL_HAVE_SLHDSA */
9700
            break;
9701
#endif /* WOLFSSL_HAVE_MLDSA || WOLFSSL_HAVE_SLHDSA */
9702
0
        default:
9703
0
            *hashAlgo = input[0];
9704
0
            *hsType   = input[1];
9705
0
            break;
9706
0
    }
9707
9708
0
    return ret;
9709
0
}
9710
9711
#ifdef WOLFSSL_DUAL_ALG_CERTS
9712
/* Decode the hybrid signature algorithm.
9713
 *
9714
 * input     The encoded signature algorithm.
9715
 * hashalgo  The hash algorithm.
9716
 * hsType    The signature type.
9717
 * returns INVALID_PARAMETER if not recognized and 0 otherwise.
9718
 */
9719
static WC_INLINE int DecodeTls13HybridSigAlg(byte* input, byte* hashAlg,
9720
                                             byte *sigAlg, byte *altSigAlg)
9721
{
9722
9723
    if (input[0] != HYBRID_SA_MAJOR) {
9724
        return INVALID_PARAMETER;
9725
    }
9726
9727
    if (input[1] == HYBRID_P256_MLDSA_44_SA_MINOR) {
9728
        *sigAlg = ecc_dsa_sa_algo;
9729
        *hashAlg = sha256_mac;
9730
        *altSigAlg = mldsa_44_sa_algo;
9731
    }
9732
    else if (input[1] == HYBRID_RSA3072_MLDSA_44_SA_MINOR) {
9733
        *sigAlg = rsa_pss_sa_algo;
9734
        *hashAlg = sha256_mac;
9735
        *altSigAlg = mldsa_44_sa_algo;
9736
    }
9737
    else if (input[1] == HYBRID_P384_MLDSA_65_SA_MINOR) {
9738
        *sigAlg = ecc_dsa_sa_algo;
9739
        *hashAlg = sha384_mac;
9740
        *altSigAlg = mldsa_65_sa_algo;
9741
    }
9742
    else if (input[1] == HYBRID_P521_MLDSA_87_SA_MINOR) {
9743
        *sigAlg = ecc_dsa_sa_algo;
9744
        *hashAlg = sha512_mac;
9745
        *altSigAlg = mldsa_87_sa_algo;
9746
    }
9747
    else if (input[1] == HYBRID_P256_FALCON_LEVEL1_SA_MINOR) {
9748
        *sigAlg = ecc_dsa_sa_algo;
9749
        *hashAlg = sha256_mac;
9750
        *altSigAlg = falcon_level1_sa_algo;
9751
    }
9752
    else if (input[1] == HYBRID_RSA3072_FALCON_LEVEL1_SA_MINOR) {
9753
        *sigAlg = rsa_pss_sa_algo;
9754
        *hashAlg = sha256_mac;
9755
        *altSigAlg = falcon_level1_sa_algo;
9756
    }
9757
    else if (input[1] == HYBRID_P521_FALCON_LEVEL5_SA_MINOR) {
9758
        *sigAlg = ecc_dsa_sa_algo;
9759
        *hashAlg = sha512_mac;
9760
        *altSigAlg = falcon_level5_sa_algo;
9761
    }
9762
    else if (input[1] == HYBRID_MLDSA_44_P256_SA_MINOR) {
9763
        *sigAlg = mldsa_44_sa_algo;
9764
        *hashAlg = sha256_mac;
9765
        *altSigAlg = ecc_dsa_sa_algo;
9766
    }
9767
    else if (input[1] == HYBRID_MLDSA_44_RSA3072_SA_MINOR) {
9768
        *sigAlg = mldsa_44_sa_algo;
9769
        *hashAlg = sha256_mac;
9770
        *altSigAlg = rsa_pss_sa_algo;
9771
    }
9772
    else if (input[1] == HYBRID_MLDSA_65_P384_SA_MINOR) {
9773
        *sigAlg = mldsa_65_sa_algo;
9774
        *hashAlg = sha384_mac;
9775
        *altSigAlg = ecc_dsa_sa_algo;
9776
    }
9777
    else if (input[1] == HYBRID_MLDSA_87_P521_SA_MINOR) {
9778
        *sigAlg = mldsa_87_sa_algo;
9779
        *hashAlg = sha512_mac;
9780
        *altSigAlg = ecc_dsa_sa_algo;
9781
    }
9782
    else if (input[1] == HYBRID_FALCON_LEVEL1_P256_SA_MINOR) {
9783
        *sigAlg = falcon_level1_sa_algo;
9784
        *hashAlg = sha256_mac;
9785
        *altSigAlg = ecc_dsa_sa_algo;
9786
    }
9787
    else if (input[1] == HYBRID_FALCON_LEVEL1_RSA3072_SA_MINOR) {
9788
        *sigAlg = falcon_level1_sa_algo;
9789
        *hashAlg = sha256_mac;
9790
        *altSigAlg = rsa_pss_sa_algo;
9791
    }
9792
    else if (input[1] == HYBRID_FALCON_LEVEL5_P521_SA_MINOR) {
9793
        *sigAlg = falcon_level5_sa_algo;
9794
        *hashAlg = sha512_mac;
9795
        *altSigAlg = ecc_dsa_sa_algo;
9796
    }
9797
    else {
9798
        return INVALID_PARAMETER;
9799
    }
9800
9801
    return 0;
9802
}
9803
#endif /* WOLFSSL_DUAL_ALG_CERTS */
9804
9805
/* Get the hash of the messages so far.
9806
 *
9807
 * ssl   The SSL/TLS object.
9808
 * hash  The buffer to write the hash to.
9809
 * returns the length of the hash.
9810
 */
9811
static WC_INLINE int GetMsgHash(WOLFSSL* ssl, byte* hash)
9812
0
{
9813
0
    int ret = 0;
9814
0
    switch (ssl->specs.mac_algorithm) {
9815
0
    #ifndef NO_SHA256
9816
0
        case sha256_mac:
9817
0
            ret = wc_Sha256GetHash(&ssl->hsHashes->hashSha256, hash);
9818
0
            if (ret == 0)
9819
0
                ret = WC_SHA256_DIGEST_SIZE;
9820
0
            break;
9821
0
    #endif /* !NO_SHA256 */
9822
0
    #ifdef WOLFSSL_SHA384
9823
0
        case sha384_mac:
9824
0
            ret = wc_Sha384GetHash(&ssl->hsHashes->hashSha384, hash);
9825
0
            if (ret == 0)
9826
0
                ret = WC_SHA384_DIGEST_SIZE;
9827
0
            break;
9828
0
    #endif /* WOLFSSL_SHA384 */
9829
    #ifdef WOLFSSL_TLS13_SHA512
9830
        case sha512_mac:
9831
            ret = wc_Sha512GetHash(&ssl->hsHashes->hashSha512, hash);
9832
            if (ret == 0)
9833
                ret = WC_SHA512_DIGEST_SIZE;
9834
            break;
9835
    #endif /* WOLFSSL_TLS13_SHA512 */
9836
0
    #ifdef WOLFSSL_SM3
9837
0
        case sm3_mac:
9838
0
            ret = wc_Sm3GetHash(&ssl->hsHashes->hashSm3, hash);
9839
0
            if (ret == 0)
9840
0
                ret = WC_SM3_DIGEST_SIZE;
9841
0
            break;
9842
0
    #endif /* WOLFSSL_SM3 */
9843
0
        default:
9844
0
            break;
9845
0
    }
9846
0
    return ret;
9847
0
}
9848
9849
/* The server certificate verification label. */
9850
static const byte serverCertVfyLabel[CERT_VFY_LABEL_SZ] =
9851
    "TLS 1.3, server CertificateVerify";
9852
/* The client certificate verification label. */
9853
static const byte clientCertVfyLabel[CERT_VFY_LABEL_SZ] =
9854
    "TLS 1.3, client CertificateVerify";
9855
/* The prefix byte in the signature data. */
9856
#define SIGNING_DATA_PREFIX_BYTE   0x20
9857
9858
/* Create the signature data for TLS v1.3 certificate verification.
9859
 *
9860
 * ssl        The SSL/TLS object.
9861
 * sigData    The signature data.
9862
 * sigDataSz  The length of the signature data.
9863
 * check      Indicates this is a check not create.
9864
 */
9865
int CreateSigData(WOLFSSL* ssl, byte* sigData, word16* sigDataSz,
9866
                  int check)
9867
374
{
9868
374
    word16 idx;
9869
374
    int side = ssl->options.side;
9870
374
    int ret;
9871
9872
    /* Signature Data = Prefix | Label | Handshake Hash */
9873
374
    XMEMSET(sigData, SIGNING_DATA_PREFIX_BYTE, SIGNING_DATA_PREFIX_SZ);
9874
374
    idx = SIGNING_DATA_PREFIX_SZ;
9875
9876
374
    if ((side == WOLFSSL_SERVER_END && check) ||
9877
374
        (side == WOLFSSL_CLIENT_END && !check)) {
9878
0
        XMEMCPY(&sigData[idx], clientCertVfyLabel, CERT_VFY_LABEL_SZ);
9879
0
    }
9880
374
    if ((side == WOLFSSL_CLIENT_END && check) ||
9881
374
        (side == WOLFSSL_SERVER_END && !check)) {
9882
374
        XMEMCPY(&sigData[idx], serverCertVfyLabel, CERT_VFY_LABEL_SZ);
9883
374
    }
9884
374
    idx += CERT_VFY_LABEL_SZ;
9885
9886
374
    ret = GetMsgHash(ssl, &sigData[idx]);
9887
374
    if (ret < 0)
9888
4
        return ret;
9889
370
    if (ret == 0)
9890
0
        return HASH_TYPE_E;
9891
9892
370
    *sigDataSz = (word16)(idx + ret);
9893
370
    ret = 0;
9894
9895
370
    return ret;
9896
370
}
9897
9898
#ifndef NO_RSA
9899
/* Encode the PKCS #1.5 RSA signature.
9900
 *
9901
 * sig        The buffer to place the encoded signature into.
9902
 * sigData    The data to be signed.
9903
 * sigDataSz  The size of the data to be signed.
9904
 * hashAlgo   The hash algorithm to use when signing.
9905
 * returns the length of the encoded signature or negative on error.
9906
 */
9907
int CreateRSAEncodedSig(byte* sig, byte* sigData, int sigDataSz,
9908
                        int sigAlgo, int hashAlgo)
9909
368
{
9910
368
    Digest digest;
9911
368
    int    hashSz = 0;
9912
368
    int    ret = WC_NO_ERR_TRACE(BAD_FUNC_ARG);
9913
368
    byte*  hash;
9914
9915
368
    (void)sigAlgo;
9916
9917
368
    hash = sig;
9918
9919
    /* Digest the signature data. */
9920
368
    switch (hashAlgo) {
9921
0
#ifndef NO_SHA256
9922
199
        case sha256_mac:
9923
199
            ret = wc_InitSha256(&digest.sha256);
9924
199
            if (ret == 0) {
9925
199
                ret = wc_Sha256Update(&digest.sha256, sigData, (word32)sigDataSz);
9926
199
                if (ret == 0)
9927
198
                    ret = wc_Sha256Final(&digest.sha256, hash);
9928
199
                wc_Sha256Free(&digest.sha256);
9929
199
            }
9930
199
            hashSz = WC_SHA256_DIGEST_SIZE;
9931
199
            break;
9932
0
#endif
9933
0
#ifdef WOLFSSL_SHA384
9934
54
        case sha384_mac:
9935
54
            ret = wc_InitSha384(&digest.sha384);
9936
54
            if (ret == 0) {
9937
54
                ret = wc_Sha384Update(&digest.sha384, sigData, (word32)sigDataSz);
9938
54
                if (ret == 0)
9939
53
                    ret = wc_Sha384Final(&digest.sha384, hash);
9940
54
                wc_Sha384Free(&digest.sha384);
9941
54
            }
9942
54
            hashSz = WC_SHA384_DIGEST_SIZE;
9943
54
            break;
9944
0
#endif
9945
0
#ifdef WOLFSSL_SHA512
9946
115
        case sha512_mac:
9947
115
            ret = wc_InitSha512(&digest.sha512);
9948
115
            if (ret == 0) {
9949
115
                ret = wc_Sha512Update(&digest.sha512, sigData, (word32)sigDataSz);
9950
115
                if (ret == 0)
9951
114
                    ret = wc_Sha512Final(&digest.sha512, hash);
9952
115
                wc_Sha512Free(&digest.sha512);
9953
115
            }
9954
115
            hashSz = WC_SHA512_DIGEST_SIZE;
9955
115
            break;
9956
0
#endif
9957
0
       default:
9958
0
            ret = BAD_FUNC_ARG;
9959
0
            break;
9960
9961
368
    }
9962
9963
368
    if (ret != 0)
9964
7
        return ret;
9965
9966
361
    return hashSz;
9967
368
}
9968
#endif /* !NO_RSA */
9969
9970
#ifdef HAVE_ECC
9971
/* Encode the ECC signature.
9972
 *
9973
 * sigData    The data to be signed.
9974
 * sigDataSz  The size of the data to be signed.
9975
 * hashAlgo   The hash algorithm to use when signing.
9976
 * returns the length of the encoded signature or negative on error.
9977
 */
9978
static int CreateECCEncodedSig(byte* sigData, int sigDataSz, int hashAlgo)
9979
0
{
9980
0
    Digest digest;
9981
0
    int    hashSz = 0;
9982
0
    int    ret = WC_NO_ERR_TRACE(BAD_FUNC_ARG);
9983
9984
    /* Digest the signature data. */
9985
0
    switch (hashAlgo) {
9986
0
#ifndef NO_SHA256
9987
0
        case sha256_mac:
9988
0
            ret = wc_InitSha256(&digest.sha256);
9989
0
            if (ret == 0) {
9990
0
                ret = wc_Sha256Update(&digest.sha256, sigData, (word32)sigDataSz);
9991
0
                if (ret == 0)
9992
0
                    ret = wc_Sha256Final(&digest.sha256, sigData);
9993
0
                wc_Sha256Free(&digest.sha256);
9994
0
            }
9995
0
            hashSz = WC_SHA256_DIGEST_SIZE;
9996
0
            break;
9997
0
#endif
9998
0
#ifdef WOLFSSL_SHA384
9999
0
        case sha384_mac:
10000
0
            ret = wc_InitSha384(&digest.sha384);
10001
0
            if (ret == 0) {
10002
0
                ret = wc_Sha384Update(&digest.sha384, sigData, (word32)sigDataSz);
10003
0
                if (ret == 0)
10004
0
                    ret = wc_Sha384Final(&digest.sha384, sigData);
10005
0
                wc_Sha384Free(&digest.sha384);
10006
0
            }
10007
0
            hashSz = WC_SHA384_DIGEST_SIZE;
10008
0
            break;
10009
0
#endif
10010
0
#ifdef WOLFSSL_SHA512
10011
0
        case sha512_mac:
10012
0
            ret = wc_InitSha512(&digest.sha512);
10013
0
            if (ret == 0) {
10014
0
                ret = wc_Sha512Update(&digest.sha512, sigData, (word32)sigDataSz);
10015
0
                if (ret == 0)
10016
0
                    ret = wc_Sha512Final(&digest.sha512, sigData);
10017
0
                wc_Sha512Free(&digest.sha512);
10018
0
            }
10019
0
            hashSz = WC_SHA512_DIGEST_SIZE;
10020
0
            break;
10021
0
#endif
10022
0
        default:
10023
0
            ret = BAD_FUNC_ARG;
10024
0
            break;
10025
0
    }
10026
10027
0
    if (ret != 0)
10028
0
        return ret;
10029
10030
0
    return hashSz;
10031
0
}
10032
#endif /* HAVE_ECC */
10033
10034
#if !defined(NO_RSA) && defined(WC_RSA_PSS)
10035
/* Check that the decrypted signature matches the encoded signature
10036
 * based on the digest of the signature data.
10037
 *
10038
 * ssl       The SSL/TLS object.
10039
 * sigAlgo   The signature algorithm used to generate signature.
10040
 * hashAlgo  The hash algorithm used to generate signature.
10041
 * decSig    The decrypted signature.
10042
 * decSigSz  The size of the decrypted signature.
10043
 * returns 0 on success, otherwise failure.
10044
 */
10045
static int CheckRSASignature(WOLFSSL* ssl, int sigAlgo, int hashAlgo,
10046
                             byte* decSig, word32 decSigSz)
10047
0
{
10048
0
    int    ret = 0;
10049
0
    byte   sigData[MAX_SIG_DATA_SZ];
10050
0
    word16 sigDataSz;
10051
10052
0
    ret = CreateSigData(ssl, sigData, &sigDataSz, 1);
10053
0
    if (ret != 0)
10054
0
        return ret;
10055
10056
0
    if (sigAlgo == rsa_pss_sa_algo) {
10057
0
        enum wc_HashType hashType = WC_HASH_TYPE_NONE;
10058
0
        word32 sigSz;
10059
10060
0
        ret = ConvertHashPss(hashAlgo, &hashType, NULL);
10061
0
        if (ret < 0)
10062
0
            return ret;
10063
10064
        /* PSS signature can be done in-place */
10065
0
        ret = CreateRSAEncodedSig(sigData, sigData, sigDataSz,
10066
0
                                  sigAlgo, hashAlgo);
10067
0
        if (ret < 0)
10068
0
            return ret;
10069
0
        sigSz = (word32)ret;
10070
10071
0
        ret = wc_RsaPSS_CheckPadding(sigData, sigSz, decSig, decSigSz,
10072
0
                                     hashType);
10073
0
    }
10074
10075
0
    return ret;
10076
0
}
10077
#endif /* !NO_RSA && WC_RSA_PSS */
10078
#endif /* !NO_RSA || HAVE_ECC */
10079
10080
#if !defined(NO_WOLFSSL_CLIENT) || !defined(NO_WOLFSSL_SERVER)
10081
/* Get the next certificate from the list for writing into the TLS v1.3
10082
 * Certificate message.
10083
 *
10084
 * data    The certificate list.
10085
 * length  The length of the certificate data in the list.
10086
 * idx     The index of the next certificate.
10087
 * returns the length of the certificate data. 0 indicates no more certificates
10088
 * in the list.
10089
 */
10090
static word32 NextCert(byte* data, word32 length, word32* idx)
10091
0
{
10092
0
    word32 len;
10093
10094
    /* Would index read past end of list? */
10095
0
    if (*idx + 3 > length)
10096
0
        return 0;
10097
10098
    /* Length of the current ASN.1 encoded certificate. */
10099
0
    c24to32(data + *idx, &len);
10100
    /* Include the length field. */
10101
0
    len += 3;
10102
10103
    /* Ensure len does not overrun certificate list */
10104
0
    if (*idx + len > length)
10105
0
        return 0;
10106
10107
    /* Move index to next certificate and return the current certificate's
10108
     * length.
10109
     */
10110
0
    *idx += len;
10111
0
    return len;
10112
0
}
10113
10114
#if defined(HAVE_CERTIFICATE_STATUS_REQUEST) && !defined(NO_WOLFSSL_SERVER)
10115
/* Write certificate status request into certificate to buffer.
10116
 *
10117
 * ssl       SSL/TLS object.
10118
 * certExts  DerBuffer array. buffers written
10119
 * extSz     word32 array.
10120
 *           Length of the certificate status request data for the certificate.
10121
 * extSz_num number of the CSR written
10122
 * extIdx    The index number of certificate status request data
10123
 *           for the certificate.
10124
 * offset    index offset
10125
 * returns   Total number of bytes written on success or negative value on error.
10126
 */
10127
static int WriteCSRToBuffer(WOLFSSL* ssl, DerBuffer** certExts,
10128
                                word16* extSz,  word16 extSz_num)
10129
{
10130
    int    ret = 0;
10131
    TLSX* ext;
10132
    CertificateStatusRequest* csr;
10133
    word32 ex_offset = HELLO_EXT_TYPE_SZ + OPAQUE16_LEN /* extension type */
10134
                    + OPAQUE16_LEN /* extension length */;
10135
    word32 totalSz = 0;
10136
    word32 tmpSz;
10137
    word32 extIdx;
10138
    DerBuffer* der;
10139
10140
    if (extSz_num > MAX_CERT_EXTENSIONS)
10141
        return MAX_CERT_EXTENSIONS_ERR;
10142
10143
    ext = TLSX_Find(ssl->extensions, TLSX_STATUS_REQUEST);
10144
    csr = ext ? (CertificateStatusRequest*)ext->data : NULL;
10145
10146
    if (csr) {
10147
        for (extIdx = 0; extIdx < (word16)(extSz_num); extIdx++) {
10148
            tmpSz = TLSX_CSR_GetSize_ex(csr, 0, (int)extIdx);
10149
10150
            if (ssl->fragOffset != 0 && certExts[extIdx] != NULL) {
10151
                /* A fragmented send is being resumed and this buffer was
10152
                 * written by the earlier call. extSz starts over on every
10153
                 * call, so recover this entry's size from the length written
10154
                 * into the buffer. */
10155
                ato16(certExts[extIdx]->buffer, &extSz[extIdx]);
10156
                extSz[extIdx] += OPAQUE16_LEN;
10157
            }
10158
            else {
10159
                /* Not a resume, so anything still allocated here is left over
10160
                 * from a completed message and must not be reused. */
10161
                FreeDer(&certExts[extIdx]);
10162
10163
                if (tmpSz > (OPAQUE8_LEN + OPAQUE24_LEN)) {
10164
                    /* csr extension is not zero */
10165
                    if (tmpSz > WOLFSSL_MAX_16BIT)
10166
                        return BUFFER_E;
10167
                    extSz[extIdx] = (word16)tmpSz;
10168
10169
                    ret = AllocDer(&certExts[extIdx], extSz[extIdx] + ex_offset,
10170
                                                        CERT_TYPE, ssl->heap);
10171
                    if (ret < 0)
10172
                        return ret;
10173
                    der = certExts[extIdx];
10174
10175
                    /* write extension type */
10176
                    c16toa(ext->type, der->buffer
10177
                                    + OPAQUE16_LEN);
10178
                    /* writes extension data length. */
10179
                    c16toa(extSz[extIdx], der->buffer
10180
                                + HELLO_EXT_TYPE_SZ + OPAQUE16_LEN);
10181
                    /* write extension data */
10182
                    extSz[extIdx] = (word16)TLSX_CSR_Write_ex(csr,
10183
                            der->buffer + ex_offset, 0, extIdx);
10184
                    /* add extension offset */
10185
                    extSz[extIdx] += (word16)ex_offset;
10186
                    /* extension length */
10187
                    c16toa(extSz[extIdx] - OPAQUE16_LEN,
10188
                                der->buffer);
10189
                }
10190
            }
10191
            totalSz += extSz[extIdx];
10192
        }
10193
    }
10194
    else {
10195
        /* chain cert empty extension size */
10196
        totalSz += OPAQUE16_LEN * extSz_num;
10197
    }
10198
    return (int)totalSz;
10199
}
10200
#endif /* HAVE_CERTIFICATE_STATUS_REQUEST */
10201
/* Add certificate data and empty extension to output up to the fragment size.
10202
 *
10203
 * ssl     SSL/TLS object.
10204
 * cert    The certificate data to write out.
10205
 * len     The length of the certificate data.
10206
 * extSz   Length of the extension data with the certificate.
10207
 * idx     The start of the certificate data to write out.
10208
 * fragSz  The maximum size of this fragment.
10209
 * output  The buffer to write to.
10210
 * extIdx  The index number of the extension data with the certificate
10211
 * returns the number of bytes written.
10212
 */
10213
static word32 AddCertExt(WOLFSSL* ssl, byte* cert, word32 len, word16 extSz,
10214
                         word32 idx, word32 fragSz, byte* output, word16 extIdx)
10215
401
{
10216
401
    word32 i = 0;
10217
401
    word32 copySz = min(len - idx, fragSz);
10218
10219
401
    if (idx < len) {
10220
401
        XMEMCPY(output, cert + idx, copySz);
10221
401
        i = copySz;
10222
401
        if (copySz == fragSz)
10223
0
            return i;
10224
401
    }
10225
401
    copySz = len + extSz - idx - i;
10226
10227
401
    if (extSz == OPAQUE16_LEN) {
10228
401
        if (copySz <= fragSz) {
10229
            /* Empty extension */
10230
401
            output[i++] = 0;
10231
401
            output[i++] = 0;
10232
401
        }
10233
401
    }
10234
0
    else {
10235
0
        byte* certExts = ssl->buffers.certExts[extIdx]->buffer + idx + i - len;
10236
        /* Put out as much of the extensions' data as will fit in fragment. */
10237
0
        if (copySz > fragSz - i)
10238
0
            copySz = fragSz - i;
10239
0
        XMEMCPY(output + i, certExts, copySz);
10240
0
        i += copySz;
10241
0
    }
10242
10243
401
    return i;
10244
401
}
10245
10246
#if defined(HAVE_CERTIFICATE_STATUS_REQUEST) && !defined(NO_WOLFSSL_SERVER)
10247
static int SetupOcspResp(WOLFSSL* ssl)
10248
{
10249
    DecodedCert* cert = NULL;
10250
    CertificateStatusRequest* csr = NULL;
10251
    TLSX* extension = NULL;
10252
    int ret = 0;
10253
    OcspRequest* request = NULL;
10254
    byte ctxOwnsRequest = 0;
10255
10256
    extension = TLSX_Find(ssl->extensions, TLSX_STATUS_REQUEST);
10257
#ifdef WOLFSSL_POST_HANDSHAKE_AUTH
10258
    /* During post-handshake client authentication the client must staple
10259
     * its own OCSP response, but the status_request extension it offered in
10260
     * the initial ClientHello is no longer present on ssl->extensions.
10261
     * Recreate it here (the request extension still lives on
10262
     * ctx->extensions). Pass ssl so csr->ssl is set, which the response
10263
     * size/write path requires. */
10264
    if (extension == NULL &&
10265
            ssl->options.side == WOLFSSL_CLIENT_END &&
10266
            ssl->options.handShakeDone &&
10267
            TLSX_Find(ssl->ctx->extensions, TLSX_STATUS_REQUEST) != NULL) {
10268
        ret = TLSX_UseCertificateStatusRequest(&ssl->extensions,
10269
                WOLFSSL_CSR_OCSP, 0, ssl, ssl->heap, ssl->devId);
10270
        if (ret != WOLFSSL_SUCCESS)
10271
            return ret;
10272
        extension = TLSX_Find(ssl->extensions, TLSX_STATUS_REQUEST);
10273
    }
10274
#endif
10275
    if (extension == NULL)
10276
        return 0; /* peer didn't signal ocsp support */
10277
    csr = (CertificateStatusRequest*)extension->data;
10278
    if (csr == NULL)
10279
        return MEMORY_ERROR;
10280
10281
    if (SSL_CM(ssl) != NULL &&
10282
            SSL_CM(ssl)->ocsp_stapling != NULL &&
10283
            SSL_CM(ssl)->ocsp_stapling->statusCb != NULL) {
10284
        return TLSX_CSR_SetResponseWithStatusCB(ssl);
10285
    }
10286
10287
    if (ssl->buffers.certificate == NULL) {
10288
        WOLFSSL_MSG("Certificate buffer not set!");
10289
        return BUFFER_ERROR;
10290
    }
10291
    cert = (DecodedCert*)XMALLOC(sizeof(DecodedCert), ssl->heap,
10292
                                 DYNAMIC_TYPE_DCERT);
10293
    if (cert == NULL) {
10294
        return MEMORY_E;
10295
    }
10296
    InitDecodedCert(cert, ssl->buffers.certificate->buffer,
10297
                    ssl->buffers.certificate->length, ssl->heap);
10298
    ret = ParseCert(cert, CERT_TYPE, NO_VERIFY, SSL_CM(ssl));
10299
    if (ret != 0) {
10300
        FreeDecodedCert(cert);
10301
        XFREE(cert, ssl->heap, DYNAMIC_TYPE_DCERT);
10302
        return ret;
10303
    }
10304
#ifdef WOLFSSL_POST_HANDSHAKE_AUTH
10305
    /* On client PHA the same certificate is re-stapled every round; reuse
10306
     * request slot 0 instead of appending, else csr->requests grows until
10307
     * MAX_CERT_EXTENSIONS_ERR. */
10308
    if (ssl->options.side == WOLFSSL_CLIENT_END && ssl->options.handShakeDone) {
10309
        ret = TLSX_CSR_InitRequest_ex(ssl->extensions, cert, ssl->heap, 0);
10310
    }
10311
    else
10312
#endif
10313
    {
10314
        ret = TLSX_CSR_InitRequest(ssl->extensions, cert, ssl->heap);
10315
    }
10316
    FreeDecodedCert(cert);
10317
    XFREE(cert, ssl->heap, DYNAMIC_TYPE_DCERT);
10318
    if (ret != 0 )
10319
        return ret;
10320
10321
    /* Free previous OCSP response buffers to avoid leak on PHA reuse */
10322
    {
10323
        int j;
10324
        for (j = 0; j < MAX_CERT_EXTENSIONS; j++) {
10325
            XFREE(csr->responses[j].buffer, ssl->heap,
10326
                DYNAMIC_TYPE_TMP_BUFFER);
10327
            csr->responses[j].buffer = NULL;
10328
            csr->responses[j].length = 0;
10329
        }
10330
    }
10331
    request = &csr->request.ocsp[0];
10332
    ret = CreateOcspResponse(ssl, &request, &csr->responses[0],
10333
                             &ctxOwnsRequest);
10334
    /* Only a successful call replaces "request", and only a request the CTX did
10335
     * not take ownership of is ours to free. Both are checked, matching the
10336
     * SendCertificateStatus() callers. */
10337
    if (ret == 0 && request != &csr->request.ocsp[0] && !ctxOwnsRequest) {
10338
        /* request was allocated in CreateOcspResponse() */
10339
        FreeOcspRequest(request);
10340
        XFREE(request, ssl->heap, DYNAMIC_TYPE_OCSP_REQUEST);
10341
    }
10342
    if (ret != 0)
10343
        return ret;
10344
10345
    if (csr->responses[0].buffer)
10346
        extension->resp = 1;
10347
#if defined(WOLFSSL_TLS_OCSP_MULTI)
10348
    /* process OCSP request in certificate chain */
10349
    if ((ret = ProcessChainOCSPRequest(ssl)) != 0) {
10350
        WOLFSSL_MSG("Process Cert Chain OCSP request failed");
10351
        WOLFSSL_ERROR_VERBOSE(ret);
10352
        return ret;
10353
    }
10354
#endif
10355
    return ret;
10356
}
10357
#endif
10358
10359
#if !defined(NO_CERTS) && !defined(WOLFSSL_NO_SIGALG)
10360
/* Certificate is signed with the deprecated SHA-1 hash. An unrecognized or
10361
 * unparsable algorithm is not SHA-1; the peer still verifies the chain.
10362
 *
10363
 * der    Buffer holding the DER encoded certificate.
10364
 * derSz  Length of the DER encoded certificate.
10365
 * returns 1 when SHA-1 signed, 0 otherwise.
10366
 */
10367
static int IsSha1SignedCert(const byte* der, word32 derSz)
10368
95
{
10369
95
    word32 idx = 0;
10370
95
    word32 oid = 0;
10371
95
    word32 algoIdEnd = 0;
10372
95
    int    len = 0;
10373
95
    int    isSha1 = 0;
10374
95
    int    ret;
10375
95
#if defined(WC_RSA_PSS) && !defined(NO_RSA)
10376
95
    enum wc_HashType hash = WC_HASH_TYPE_NONE;
10377
95
    int    mgf = 0;
10378
95
    int    saltLen = 0;
10379
95
#endif
10380
10381
    /* Certificate ::= SEQUENCE { tbsCertificate, signatureAlgorithm, ... }.
10382
     * GetSequence() checks each length against the maximum index passed in, so
10383
     * idx and idx + len stay inside the buffer. */
10384
95
    ret = GetSequence(der, &idx, &len, derSz);
10385
95
    if (ret >= 0)
10386
95
        ret = GetSequence(der, &idx, &len, derSz);
10387
95
    if (ret >= 0) {
10388
        /* signatureAlgorithm immediately follows the tbsCertificate. Decode
10389
         * the AlgorithmIdentifier here rather than with GetAlgoId() so the
10390
         * RSASSA-PSS parameters, which hold the digest, stay reachable. */
10391
95
        idx += (word32)len;
10392
95
        ret = GetSequence(der, &idx, &len, derSz);
10393
95
    }
10394
95
    if (ret >= 0) {
10395
95
        algoIdEnd = idx + (word32)len;
10396
95
        ret = GetObjectId(der, &idx, &oid, oidSigType, algoIdEnd);
10397
95
    }
10398
95
    if (ret >= 0) {
10399
95
        if ((oid == CTC_SHAwRSA) || (oid == CTC_SHAwECDSA) ||
10400
95
                (oid == CTC_SHAwDSA)) {
10401
0
            isSha1 = 1;
10402
0
        }
10403
95
    #if defined(WC_RSA_PSS) && !defined(NO_RSA)
10404
        /* RSASSA-PSS uses one signature OID for every digest and names the
10405
         * digest in the algorithm parameters instead. Absent parameters are
10406
         * passed through as a zero length buffer rather than skipped: RFC 4055
10407
         * makes them mean all defaults, which is SHA-1, and
10408
         * wc_DecodeRsaPssParams() reports that. */
10409
95
        else if ((oid == RSAPSSk) && (idx <= algoIdEnd) &&
10410
0
                (wc_DecodeRsaPssParams(der + idx, algoIdEnd - idx, &hash, &mgf,
10411
0
                                       &saltLen) == 0)) {
10412
0
            isSha1 = (hash == WC_HASH_TYPE_SHA);
10413
0
        }
10414
95
    #endif
10415
95
    }
10416
10417
95
    return isSha1;
10418
95
}
10419
10420
/* Certificate is self signed. RFC 8446 Section 4.4.2.2: "Certificates that are
10421
 * self-signed or certificates that are expected to be trust anchors are not
10422
 * validated as part of the chain and therefore MAY be signed with any
10423
 * algorithm."
10424
 *
10425
 * DecodedCert.selfSigned is an issuer/subject name hash compare rather than a
10426
 * verified self-signature, which is enough here: the chain is the one this end
10427
 * was configured with, not one an attacker supplies.
10428
 *
10429
 * The certificate is parsed as CA_TYPE rather than CERT_TYPE so a trust anchor
10430
 * carrying serial number 0 still decodes. ParseCertRelative() rejects a zero
10431
 * serial for CERT_TYPE, and legacy roots, the certificates most likely to be
10432
 * SHA-1 signed, are the ones that use it. With NO_VERIFY and no certificate
10433
 * manager the serial exemption is all the type changes, and that exemption
10434
 * still requires a self signed CA, so a leaf carrying serial 0 is reported as
10435
 * not self signed and stays subject to the SHA-1 rule.
10436
 *
10437
 * ssl           The SSL/TLS object.
10438
 * der           Buffer holding the DER encoded certificate.
10439
 * derSz         Length of the DER encoded certificate.
10440
 * isSelfSigned  On success, 1 when self signed, 0 otherwise. A certificate
10441
 *               that will not parse is reported as not self signed so the
10442
 *               SHA-1 rule still applies to it.
10443
 * returns 0 on success, MEMORY_E when the decoder cannot be allocated.
10444
 */
10445
static int IsSelfSignedCert(WOLFSSL* ssl, const byte* der, word32 derSz,
10446
                            int* isSelfSigned)
10447
0
{
10448
0
    DecodedCert* cert;
10449
10450
0
    *isSelfSigned = 0;
10451
10452
0
    cert = (DecodedCert*)XMALLOC(sizeof(DecodedCert), ssl->heap,
10453
0
                                 DYNAMIC_TYPE_DCERT);
10454
0
    if (cert == NULL)
10455
0
        return MEMORY_E;
10456
10457
0
    InitDecodedCert(cert, der, derSz, ssl->heap);
10458
0
    if (ParseCertRelative(cert, CA_TYPE, NO_VERIFY, NULL, NULL) == 0)
10459
0
        *isSelfSigned = (cert->selfSigned != 0);
10460
0
    else
10461
0
        WOLFSSL_MSG("Cannot decode certificate, not treating as self signed");
10462
0
    FreeDecodedCert(cert);
10463
0
    XFREE(cert, ssl->heap, DYNAMIC_TYPE_DCERT);
10464
10465
0
    return 0;
10466
0
}
10467
10468
/* Check the chain about to be sent against what the peer advertised.
10469
 *
10470
 * RFC 8446 Section 4.4.2.2 permits a fallback chain the peer did not advertise
10471
 * support for, but the chain "MUST NOT" use SHA-1 unless the peer's
10472
 * advertisement permits it. Section 4.4.2.3 requires client certificates to be
10473
 * signed with an acceptable algorithm "as described in Section 4.4.2.2", so the
10474
 * same rule covers both sides. How a failure is resolved differs by side and is
10475
 * left to the caller.
10476
 *
10477
 * ssl  The SSL/TLS object.
10478
 * returns 0 when the chain may be sent, MATCH_SUITE_ERROR when it may not and
10479
 * MEMORY_E when a certificate could not be examined.
10480
 */
10481
static int CheckCertChainSigAlgo(WOLFSSL* ssl)
10482
411
{
10483
411
    byte*  chain;
10484
411
    byte*  cur;
10485
411
    word32 chainSz;
10486
411
    word32 len;
10487
411
    word32 idx = 0;
10488
411
    int    selfSigned = 0;
10489
411
    int    ret = 0;
10490
10491
411
    if (ssl->options.peerSha1CertOk)
10492
316
        return 0;
10493
10494
95
    if (ssl->buffers.certificate == NULL ||
10495
95
            ssl->buffers.certificate->buffer == NULL) {
10496
0
        return 0;
10497
0
    }
10498
10499
95
    if (IsSha1SignedCert(ssl->buffers.certificate->buffer,
10500
95
                         ssl->buffers.certificate->length)) {
10501
0
        ret = IsSelfSignedCert(ssl, ssl->buffers.certificate->buffer,
10502
0
                               ssl->buffers.certificate->length, &selfSigned);
10503
0
        if (ret != 0)
10504
0
            return ret;
10505
0
        if (!selfSigned)
10506
0
            ret = MATCH_SUITE_ERROR;
10507
0
    }
10508
10509
95
    if (ret == 0 && ssl->buffers.certChain != NULL &&
10510
0
            ssl->buffers.certChain->buffer != NULL &&
10511
0
            ssl->buffers.certChainCnt > 0) {
10512
0
        chain = ssl->buffers.certChain->buffer;
10513
0
        chainSz = ssl->buffers.certChain->length;
10514
10515
0
        while (ret == 0) {
10516
0
            cur = chain + idx;
10517
            /* NextCert() length includes the CERT_HEADER_SZ byte prefix and
10518
             * is 0 at the end of the list. Keep this terminator matching the
10519
             * send loop so both walk the same certificates. */
10520
0
            len = NextCert(chain, chainSz, &idx);
10521
0
            if (len == 0)
10522
0
                break;
10523
0
            if (len <= CERT_HEADER_SZ)
10524
0
                continue;
10525
0
            cur += CERT_HEADER_SZ;
10526
0
            len -= CERT_HEADER_SZ;
10527
10528
0
            if (IsSha1SignedCert(cur, len)) {
10529
0
                ret = IsSelfSignedCert(ssl, cur, len, &selfSigned);
10530
0
                if (ret != 0)
10531
0
                    return ret;
10532
0
                if (!selfSigned)
10533
0
                    ret = MATCH_SUITE_ERROR;
10534
0
            }
10535
0
        }
10536
0
    }
10537
10538
95
    if (ret == WC_NO_ERR_TRACE(MATCH_SUITE_ERROR))
10539
0
        WOLFSSL_MSG("Chain is SHA-1 signed but peer did not advertise SHA-1");
10540
10541
95
    return ret;
10542
95
}
10543
#endif /* !NO_CERTS && !WOLFSSL_NO_SIGALG */
10544
10545
/* handle generation TLS v1.3 certificate (11) */
10546
/* Send the certificate for this end and any CAs that help with validation.
10547
 * This message is always encrypted in TLS v1.3.
10548
 *
10549
 * ssl  The SSL/TLS object.
10550
 * returns 0 on success, otherwise failure.
10551
 */
10552
static int SendTls13Certificate(WOLFSSL* ssl)
10553
{
10554
    int    ret = 0;
10555
    word32 certSz, certChainSz, headerSz, listSz, payloadSz;
10556
    word16 extSz[MAX_CERT_EXTENSIONS];
10557
    word16 extIdx = 0;
10558
    word32 maxFragment;
10559
    word32 totalextSz = 0;
10560
    word32 len = 0;
10561
    word32 idx = 0;
10562
    word32 offset = 0;
10563
    word32 entrySz = 0;
10564
    byte*  p = NULL;
10565
    byte   certReqCtxLen = 0;
10566
    sword32 length;
10567
#ifdef WOLFSSL_POST_HANDSHAKE_AUTH
10568
    byte*  certReqCtx = NULL;
10569
#endif
10570
#ifndef WOLFSSL_NO_SIGALG
10571
    int    chainRet;
10572
#endif
10573
10574
#ifdef OPENSSL_EXTRA
10575
    WOLFSSL_X509* x509 = NULL;
10576
    WOLFSSL_EVP_PKEY* pkey = NULL;
10577
#endif
10578
10579
    WOLFSSL_START(WC_FUNC_CERTIFICATE_SEND);
10580
    WOLFSSL_ENTER("SendTls13Certificate");
10581
10582
    XMEMSET(extSz, 0, sizeof(extSz));
10583
10584
    ssl->options.buildingMsg = 1;
10585
10586
#ifdef WOLFSSL_POST_HANDSHAKE_AUTH
10587
    if (ssl->options.side == WOLFSSL_CLIENT_END && ssl->certReqCtx != NULL) {
10588
        certReqCtxLen = ssl->certReqCtx->len;
10589
        certReqCtx = &ssl->certReqCtx->ctx;
10590
    }
10591
#endif
10592
10593
#if defined(OPENSSL_EXTRA) && defined(WOLFSSL_CERT_SETUP_CB)
10594
    /* call client cert callback if no cert has been loaded */
10595
    if ((ssl->ctx->CBClientCert != NULL) &&
10596
        (!ssl->buffers.certificate || !ssl->buffers.certificate->buffer)) {
10597
        ret = ssl->ctx->CBClientCert(ssl, &x509, &pkey);
10598
        if (ret == 1) {
10599
            if ((wolfSSL_CTX_use_certificate(ssl->ctx, x509) == WOLFSSL_SUCCESS) &&
10600
                (wolfSSL_CTX_use_PrivateKey(ssl->ctx, pkey) == WOLFSSL_SUCCESS)) {
10601
                ssl->options.sendVerify = SEND_CERT;
10602
            }
10603
            wolfSSL_X509_free(x509);
10604
            x509 = NULL;
10605
            wolfSSL_EVP_PKEY_free(pkey);
10606
        }
10607
    }
10608
#endif
10609
10610
#ifndef WOLFSSL_NO_SIGALG
10611
    /* Run before the blank certificate branch below so a client with nothing
10612
     * acceptable can fall into it. Only on first entry: fragOffset is reset to
10613
     * 0 before this message is built and is non-zero only while resuming a
10614
     * fragmented send, whose chain was checked on the first pass. The result is
10615
     * kept out of ret so a pending value there is left alone. */
10616
    if (ssl->options.sendVerify != SEND_BLANK_CERT && ssl->fragOffset == 0) {
10617
        chainRet = CheckCertChainSigAlgo(ssl);
10618
        if ((chainRet != 0) &&
10619
                (chainRet != WC_NO_ERR_TRACE(MATCH_SUITE_ERROR))) {
10620
            return chainRet;
10621
        }
10622
        if (chainRet == WC_NO_ERR_TRACE(MATCH_SUITE_ERROR)) {
10623
            if (ssl->options.side == WOLFSSL_SERVER_END) {
10624
                SendAlert(ssl, alert_fatal, handshake_failure);
10625
                WOLFSSL_ERROR_VERBOSE(MATCH_SUITE_ERROR);
10626
                return MATCH_SUITE_ERROR;
10627
            }
10628
        #ifndef WOLFSSL_NO_CLIENT_CERT_ERROR
10629
            /* RFC 8446 Section 4.4.2: a client with no acceptable certificate
10630
             * sends an empty certificate_list rather than failing. */
10631
            WOLFSSL_MSG("Client chain not acceptable, sending blank cert");
10632
            ssl->options.sendVerify = SEND_BLANK_CERT;
10633
        #else
10634
            /* RFC 8446 Section 4.4.2.2: an endpoint that cannot produce an
10635
             * acceptable chain aborts with a certificate related alert,
10636
             * unsupported_certificate by default. */
10637
            WOLFSSL_MSG("Client chain not acceptable and blank cert not "
10638
                        "allowed");
10639
            SendAlert(ssl, alert_fatal, unsupported_certificate);
10640
            WOLFSSL_ERROR_VERBOSE(NO_CERT_ERROR);
10641
            return NO_CERT_ERROR;
10642
        #endif
10643
        }
10644
    }
10645
#endif
10646
10647
    if (ssl->options.sendVerify == SEND_BLANK_CERT) {
10648
        certSz = 0;
10649
        certChainSz = 0;
10650
        headerSz = OPAQUE8_LEN + certReqCtxLen + CERT_HEADER_SZ;
10651
        length = (sword32)headerSz;
10652
        listSz = 0;
10653
    }
10654
    else {
10655
        if (!ssl->buffers.certificate || !ssl->buffers.certificate->buffer) {
10656
            WOLFSSL_MSG("Send Cert missing certificate buffer");
10657
            return NO_CERT_ERROR;
10658
        }
10659
        /* Certificate Data */
10660
        certSz = ssl->buffers.certificate->length;
10661
        if (ssl->buffers.certChainCnt > MAX_CHAIN_DEPTH) {
10662
            WOLFSSL_MSG("Certificate chain count exceeds maximum depth");
10663
            return MAX_CHAIN_ERROR;
10664
        }
10665
        /* Cert Req Ctx Len | Cert Req Ctx | Cert List Len | Cert Data Len */
10666
        headerSz = OPAQUE8_LEN + certReqCtxLen + CERT_HEADER_SZ +
10667
                   CERT_HEADER_SZ;
10668
        /* set empty extension as default */
10669
        for (extIdx = 0; extIdx < (word16)XELEM_CNT(extSz); extIdx++)
10670
            extSz[extIdx] = OPAQUE16_LEN;
10671
10672
    #if defined(HAVE_CERTIFICATE_STATUS_REQUEST) && !defined(NO_WOLFSSL_SERVER)
10673
        /* Staple our own OCSP response with the Certificate. Normally only the
10674
         * server staples; the client's CSR holds the server's response, so
10675
         * echoing it back is wrong. The exception is post-handshake auth (PHA),
10676
         * where the client sends its own Certificate and staples for it. */
10677
        if (ssl->options.side == WOLFSSL_SERVER_END
10678
        #ifdef WOLFSSL_POST_HANDSHAKE_AUTH
10679
            || (ssl->options.side == WOLFSSL_CLIENT_END
10680
                && ssl->options.handShakeDone)
10681
        #endif
10682
        ) {
10683
            /* Build the responses once. A resumed send reuses them: looking
10684
             * them up again appends another set of requests to the extension
10685
             * until it overflows with MAX_CERT_EXTENSIONS_ERR. */
10686
            if (ssl->fragOffset == 0) {
10687
                ret = SetupOcspResp(ssl);
10688
                if (ret != 0)
10689
                    return ret;
10690
            }
10691
10692
            if ((1 + ssl->buffers.certChainCnt) > MAX_CERT_EXTENSIONS)
10693
                ret = MAX_CERT_EXTENSIONS_ERR;
10694
            if (ret == 0)
10695
                ret = WriteCSRToBuffer(ssl, &ssl->buffers.certExts[0], &extSz[0],
10696
                        1 /* +1 for leaf */ + (word16)ssl->buffers.certChainCnt);
10697
            if (ret < 0)
10698
                return ret;
10699
            totalextSz += ret;
10700
            ret = 0; /* Clear to signal no error */
10701
        }
10702
        else
10703
    #endif
10704
        {
10705
            /* Leaf cert empty extension size */
10706
            totalextSz += OPAQUE16_LEN;
10707
            /* chain cert empty extension size */
10708
            totalextSz += OPAQUE16_LEN * ssl->buffers.certChainCnt;
10709
        }
10710
10711
        /* Length of message data with one certificate and extensions. */
10712
        length = (sword32)(headerSz + certSz + totalextSz);
10713
        /* Length of list data with one certificate and extensions. */
10714
        listSz = CERT_HEADER_SZ + certSz + totalextSz;
10715
10716
        /* Send rest of chain if sending cert (chain has leading size/s). */
10717
        if (certSz > 0 && ssl->buffers.certChainCnt > 0) {
10718
            p = ssl->buffers.certChain->buffer;
10719
            /* Chain length including extensions. */
10720
            certChainSz = ssl->buffers.certChain->length;
10721
10722
            length += certChainSz;
10723
            listSz += certChainSz;
10724
        }
10725
        else
10726
            certChainSz = 0;
10727
    }
10728
10729
    payloadSz = (word32)length;
10730
10731
    if (ssl->fragOffset != 0)
10732
        length -= (ssl->fragOffset + headerSz);
10733
10734
    maxFragment = (word32)wolfssl_local_GetMaxPlaintextSize(ssl);
10735
10736
    extIdx = 0;
10737
10738
    /* Only ssl->fragOffset survives a WANT_WRITE, so a resume inside the chain
10739
     * has to rebuild the walk cursor from it. */
10740
    if (certChainSz > 0 && ssl->fragOffset >= certSz + extSz[0]) {
10741
        word32 chainPos = ssl->fragOffset - (certSz + extSz[0]);
10742
10743
    #if defined(HAVE_CERTIFICATE_STATUS_REQUEST) && !defined(NO_WOLFSSL_SERVER)
10744
        /* The leaf is behind us and its buffer was rebuilt above. */
10745
        FreeDer(&ssl->buffers.certExts[0]);
10746
    #endif
10747
10748
        while (chainPos > 0) {
10749
            word32 prevIdx = idx;
10750
10751
            len = NextCert(ssl->buffers.certChain->buffer,
10752
                           ssl->buffers.certChain->length, &idx);
10753
            if (len == 0)
10754
                break;
10755
        #if defined(HAVE_CERTIFICATE_STATUS_REQUEST) && \
10756
                !defined(NO_WOLFSSL_SERVER)
10757
            if (extIdx + 1 < MAX_CERT_EXTENSIONS)
10758
                extIdx++;
10759
        #endif
10760
            entrySz = len + extSz[extIdx];
10761
10762
            if (chainPos < entrySz) {
10763
                /* Resume part way through this entry. */
10764
                p = ssl->buffers.certChain->buffer + prevIdx;
10765
                offset = chainPos;
10766
                chainPos = 0;
10767
            }
10768
            else {
10769
                /* Entry already sent in full; stay primed for the next one. */
10770
            #if defined(HAVE_CERTIFICATE_STATUS_REQUEST) && \
10771
                    !defined(NO_WOLFSSL_SERVER)
10772
                /* Its buffer was rebuilt above and nothing writes it again. */
10773
                FreeDer(&ssl->buffers.certExts[extIdx]);
10774
            #endif
10775
                chainPos -= entrySz;
10776
                offset = 0;
10777
                entrySz = 0;
10778
            }
10779
        }
10780
    }
10781
10782
    while (length > 0 && ret == 0) {
10783
        byte*  output = NULL;
10784
        word32 fragSz = 0;
10785
        word32 i = RECORD_HEADER_SZ;
10786
        int    sendSz = RECORD_HEADER_SZ;
10787
10788
#ifdef WOLFSSL_DTLS13
10789
        if (ssl->options.dtls) {
10790
            i = Dtls13GetRlHeaderLength(ssl, 1);
10791
            sendSz = (int)i;
10792
        }
10793
#endif /* WOLFSSL_DTLS13 */
10794
10795
        if (ssl->fragOffset == 0) {
10796
            if (headerSz + certSz + totalextSz + certChainSz <=
10797
                                            maxFragment - HANDSHAKE_HEADER_SZ) {
10798
                fragSz = headerSz + certSz + totalextSz + certChainSz;
10799
            }
10800
#ifdef WOLFSSL_DTLS13
10801
            else if (ssl->options.dtls){
10802
                /* short-circuit the fragmentation logic here. DTLS
10803
                   fragmentation will be done in dtls13HandshakeSend() */
10804
                fragSz = headerSz + certSz + totalextSz + certChainSz;
10805
            }
10806
#endif /* WOLFSSL_DTLS13 */
10807
            else {
10808
                fragSz = maxFragment - HANDSHAKE_HEADER_SZ;
10809
            }
10810
10811
            sendSz += fragSz + HANDSHAKE_HEADER_SZ;
10812
            i += HANDSHAKE_HEADER_SZ;
10813
#ifdef WOLFSSL_DTLS13
10814
            if (ssl->options.dtls) {
10815
                sendSz += DTLS_HANDSHAKE_EXTRA;
10816
                i += DTLS_HANDSHAKE_EXTRA;
10817
            }
10818
#endif /* WOLFSSL_DTLS13 */
10819
        }
10820
        else {
10821
            fragSz = min((word32)length, maxFragment);
10822
            sendSz += fragSz;
10823
        }
10824
10825
        sendSz += MAX_MSG_EXTRA;
10826
10827
        /* Check buffers are big enough and grow if needed. */
10828
        if ((ret = CheckAvailableSize(ssl, sendSz)) != 0)
10829
            return ret;
10830
10831
        /* Get position in output buffer to write new message to. */
10832
        output = GetOutputBuffer(ssl);
10833
10834
        if (ssl->fragOffset == 0) {
10835
            AddTls13FragHeaders(output, fragSz, 0, payloadSz, certificate, ssl);
10836
10837
            /* Request context. */
10838
            output[i++] = certReqCtxLen;
10839
        #ifdef WOLFSSL_POST_HANDSHAKE_AUTH
10840
            if (certReqCtxLen > 0) {
10841
                XMEMCPY(output + i, certReqCtx, certReqCtxLen);
10842
                i += certReqCtxLen;
10843
            }
10844
        #endif
10845
            length -= OPAQUE8_LEN + certReqCtxLen;
10846
            fragSz -= OPAQUE8_LEN + certReqCtxLen;
10847
            /* Certificate list length. */
10848
            c32to24(listSz, output + i);
10849
            i += CERT_HEADER_SZ;
10850
            length -= CERT_HEADER_SZ;
10851
            fragSz -= CERT_HEADER_SZ;
10852
            /* Leaf certificate data length. */
10853
            if (certSz > 0) {
10854
                c32to24(certSz, output + i);
10855
                i += CERT_HEADER_SZ;
10856
                length -= CERT_HEADER_SZ;
10857
                fragSz -= CERT_HEADER_SZ;
10858
            }
10859
        }
10860
        else
10861
            AddTls13RecordHeader(output, fragSz, handshake, ssl);
10862
10863
        if (extIdx == 0) {
10864
            if (certSz > 0 && ssl->fragOffset < certSz + extSz[0]) {
10865
                /* Put in the leaf certificate with extensions. */
10866
                word32 copySz = AddCertExt(ssl, ssl->buffers.certificate->buffer,
10867
                                certSz, extSz[0], ssl->fragOffset, fragSz,
10868
                                output + i, 0);
10869
                i += copySz;
10870
                ssl->fragOffset += copySz;
10871
                length -= copySz;
10872
                fragSz -= copySz;
10873
                if (ssl->fragOffset == certSz + extSz[0])
10874
                    FreeDer(&ssl->buffers.certExts[0]);
10875
            }
10876
        }
10877
        if (certChainSz > 0 && fragSz > 0) {
10878
             /* Put in the CA certificates with extensions. */
10879
             while (fragSz > 0) {
10880
                word32 l;
10881
10882
                if (offset == entrySz) {
10883
                    /* Find next CA certificate to write out. */
10884
                    offset = 0;
10885
                    /* Point to the start of current cert in chain buffer. */
10886
                    p = ssl->buffers.certChain->buffer + idx;
10887
                    len = NextCert(ssl->buffers.certChain->buffer,
10888
                            ssl->buffers.certChain->length, &idx);
10889
                    if (len == 0)
10890
                        break;
10891
                #if defined(HAVE_CERTIFICATE_STATUS_REQUEST) && \
10892
                        !defined(NO_WOLFSSL_SERVER)
10893
                    if (extIdx + 1 < MAX_CERT_EXTENSIONS)
10894
                        extIdx++;
10895
                #endif
10896
                    /* Certificate and its extensions make up the entry. */
10897
                    entrySz = len + extSz[extIdx];
10898
                }
10899
                /* Write out certificate and extension. */
10900
                l = AddCertExt(ssl, p, len, extSz[extIdx], offset, fragSz,
10901
                                                       output + i, extIdx);
10902
                i += l;
10903
                ssl->fragOffset += l;
10904
                length -= l;
10905
                fragSz -= l;
10906
                offset += l;
10907
10908
                if (extIdx != 0 && extIdx < MAX_CERT_EXTENSIONS &&
10909
                    ssl->buffers.certExts[extIdx] != NULL &&
10910
                                offset == entrySz) {
10911
                    FreeDer(&ssl->buffers.certExts[extIdx]);
10912
                }
10913
            }
10914
        }
10915
10916
        if ((int)i - RECORD_HEADER_SZ < 0) {
10917
            WOLFSSL_MSG("Send Cert bad inputSz");
10918
            return BUFFER_E;
10919
        }
10920
10921
#ifdef WOLFSSL_DTLS13
10922
        if (ssl->options.dtls) {
10923
            /* DTLS1.3 uses a separate variable and logic for fragments */
10924
            ssl->options.buildingMsg = 0;
10925
            ssl->fragOffset = 0;
10926
            if ((word32)sendSz > WOLFSSL_MAX_16BIT || i > WOLFSSL_MAX_16BIT) {
10927
                WOLFSSL_MSG("Send Cert DTLS size exceeds word16");
10928
                return BUFFER_E;
10929
            }
10930
            ret = Dtls13HandshakeSend(ssl, output, (word16)sendSz, (word16)i,
10931
                                      certificate, 1);
10932
        }
10933
        else
10934
#endif /* WOLFSSL_DTLS13 */
10935
        {
10936
            /* This message is always encrypted. */
10937
            sendSz = BuildTls13Message(ssl, output, sendSz,
10938
                output + RECORD_HEADER_SZ, (int)(i - RECORD_HEADER_SZ),
10939
                handshake, 1,
10940
                0, 0);
10941
            if (sendSz < 0)
10942
                return sendSz;
10943
10944
#if defined(WOLFSSL_CALLBACKS) || defined(OPENSSL_EXTRA)
10945
            if (ssl->hsInfoOn)
10946
                AddPacketName(ssl, "Certificate");
10947
            if (ssl->toInfoOn) {
10948
                ret = AddPacketInfo(ssl, "Certificate", handshake, output,
10949
                              sendSz, WRITE_PROTO, 0, ssl->heap);
10950
                if (ret != 0)
10951
                    return ret;
10952
            }
10953
#endif
10954
10955
            ssl->buffers.outputBuffer.length += (word32)sendSz;
10956
            ssl->options.buildingMsg = 0;
10957
            if (!ssl->options.groupMessages)
10958
                ret = SendBuffered(ssl);
10959
        }
10960
    }
10961
10962
    if (ret != WC_NO_ERR_TRACE(WANT_WRITE)) {
10963
        /* Clean up the fragment offset. */
10964
        ssl->options.buildingMsg = 0;
10965
        ssl->fragOffset = 0;
10966
        if (ssl->options.side == WOLFSSL_SERVER_END)
10967
            ssl->options.serverState = SERVER_CERT_COMPLETE;
10968
    }
10969
10970
#ifdef WOLFSSL_POST_HANDSHAKE_AUTH
10971
    if (ssl->options.side == WOLFSSL_CLIENT_END && ssl->certReqCtx != NULL) {
10972
        CertReqCtx* ctx = ssl->certReqCtx;
10973
        ssl->certReqCtx = ssl->certReqCtx->next;
10974
        XFREE(ctx, ssl->heap, DYNAMIC_TYPE_TMP_BUFFER);
10975
    }
10976
#endif
10977
10978
    WOLFSSL_LEAVE("SendTls13Certificate", ret);
10979
    WOLFSSL_END(WC_FUNC_CERTIFICATE_SEND);
10980
10981
    return ret;
10982
}
10983
10984
#if (!defined(NO_RSA) || defined(HAVE_ECC) || defined(HAVE_ED25519) || \
10985
     defined(HAVE_ED448) || defined(HAVE_FALCON) || \
10986
     defined(WOLFSSL_HAVE_MLDSA) || defined(WOLFSSL_HAVE_SLHDSA)) && \
10987
    (!defined(NO_WOLFSSL_SERVER) || !defined(WOLFSSL_NO_CLIENT_AUTH))
10988
/* Members are grouped widest first so the struct carries no interior padding.
10989
 * Under WOLFSSL_ASYNC_CRYPT this must fit ssl->async->args (MAX_ASYNC_ARGS
10990
 * word32s), which the static assert in SendTls13CertificateVerify enforces. */
10991
typedef struct Scv13Args {
10992
    byte*  output; /* not allocated */
10993
    byte*  verify; /* not allocated */
10994
    byte*  sigData;
10995
#ifndef NO_RSA
10996
    byte*  toSign; /* not allocated */
10997
#endif
10998
#ifdef WOLFSSL_DUAL_ALG_CERTS
10999
    byte*  altSigData;
11000
#endif
11001
    /* Fragmented CertificateVerify send cursor, used when the signature does
11002
     * not fit in a single TLS record (SLH-DSA and other oversized signatures).
11003
     * Kept in the async args so a WC_PENDING_E from the record AEAD under
11004
     * WOLFSSL_ASYNC_CRYPT resumes on the same fragment instead of re-emitting
11005
     * the records already committed to the output buffer. */
11006
    byte*  frag;         /* body copy, freed by FreeScv13Args; NULL when idle */
11007
11008
    word32 idx;
11009
    word32 sigLen;
11010
    int    sendSz;
11011
    word32 length;
11012
#ifndef NO_RSA
11013
    word32 toSignSz;
11014
#endif
11015
#ifdef WOLFSSL_DUAL_ALG_CERTS
11016
    word32 altSigLen;    /* Only used in the case of both native and alt. */
11017
#endif
11018
    word32 outputSz;     /* reserved capacity of the output record buffer */
11019
    word32 fragOffset;   /* body bytes already committed to records */
11020
11021
    word16 sigDataSz;
11022
#ifdef WOLFSSL_DUAL_ALG_CERTS
11023
    word16 altSigDataSz;
11024
#endif
11025
11026
    byte   sigAlgo;
11027
#ifdef WOLFSSL_DUAL_ALG_CERTS
11028
    byte   altSigAlgo;
11029
#endif
11030
    byte   fragActive;   /* current fragment laid out, record build may pend */
11031
} Scv13Args;
11032
11033
static void FreeScv13Args(WOLFSSL* ssl, void* pArgs)
11034
383
{
11035
383
    Scv13Args* args = (Scv13Args*)pArgs;
11036
11037
383
    (void)ssl;
11038
11039
383
    if (args && args->sigData) {
11040
374
        XFREE(args->sigData, ssl->heap, DYNAMIC_TYPE_SIGNATURE);
11041
374
        args->sigData = NULL;
11042
374
    }
11043
#ifdef WOLFSSL_DUAL_ALG_CERTS
11044
    if (args && args->altSigData != NULL) {
11045
        XFREE(args->altSigData, ssl->heap, DYNAMIC_TYPE_SIGNATURE);
11046
        args->altSigData = NULL;
11047
    }
11048
#endif
11049
383
    if (args != NULL && args->frag != NULL) {
11050
0
        XFREE(args->frag, ssl->heap, DYNAMIC_TYPE_TMP_BUFFER);
11051
0
        args->frag = NULL;
11052
0
    }
11053
383
}
11054
11055
/* handle generation TLS v1.3 certificate_verify (15) */
11056
/* Send the TLS v1.3 CertificateVerify message.
11057
 * A hash of all the message so far is used.
11058
 * The signed data is:
11059
 *     0x20 * 64 | context string | 0x00 | hash of messages
11060
 * This message is always encrypted in TLS v1.3.
11061
 *
11062
 * ssl  The SSL/TLS object.
11063
 * returns 0 on success, otherwise failure.
11064
 */
11065
static int SendTls13CertificateVerify(WOLFSSL* ssl)
11066
{
11067
    int ret = 0;
11068
#ifndef NO_RSA
11069
    /* Use this as a temporary buffer for RSA signature verification. */
11070
    buffer* rsaSigBuf = &ssl->buffers.sig;
11071
#endif
11072
#ifdef WOLFSSL_ASYNC_CRYPT
11073
    Scv13Args* args = NULL;
11074
    WOLFSSL_ASSERT_SIZEOF_GE(ssl->async->args, *args);
11075
#else
11076
    Scv13Args  args[1];
11077
#endif
11078
11079
#ifdef WOLFSSL_DTLS13
11080
    int recordLayerHdrExtra;
11081
#endif /* WOLFSSL_DTLS13 */
11082
11083
    WOLFSSL_START(WC_FUNC_CERTIFICATE_VERIFY_SEND);
11084
    WOLFSSL_ENTER("SendTls13CertificateVerify");
11085
11086
#ifdef WOLFSSL_BLIND_PRIVATE_KEY
11087
    wolfssl_priv_der_blind_toggle(ssl->buffers.key, ssl->buffers.keyMask);
11088
#endif
11089
11090
    ssl->options.buildingMsg = 1;
11091
11092
#if defined(WOLFSSL_RENESAS_TSIP_TLS)
11093
    ret = tsip_Tls13SendCertVerify(ssl);
11094
    if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) {
11095
        goto exit_scv;
11096
    }
11097
    ret = 0;
11098
#endif /* WOLFSSL_RENESAS_TSIP_TLS */
11099
11100
#ifdef WOLFSSL_DTLS13
11101
    /* can be negative */
11102
    if (ssl->options.dtls)
11103
        recordLayerHdrExtra = Dtls13GetRlHeaderLength(ssl, 1) - RECORD_HEADER_SZ;
11104
    else
11105
        recordLayerHdrExtra = 0;
11106
11107
#endif /* WOLFSSL_DTLS13 */
11108
11109
#ifdef WOLFSSL_ASYNC_CRYPT
11110
    if (ssl->async == NULL) {
11111
        ssl->async = (struct WOLFSSL_ASYNC*)
11112
                XMALLOC(sizeof(struct WOLFSSL_ASYNC), ssl->heap,
11113
                        DYNAMIC_TYPE_ASYNC);
11114
        if (ssl->async == NULL)
11115
            ERROR_OUT(MEMORY_E, exit_scv);
11116
    }
11117
    args = (Scv13Args*)ssl->async->args;
11118
11119
    ret = wolfSSL_AsyncPop(ssl, &ssl->options.asyncState);
11120
    if (ret != WC_NO_ERR_TRACE(WC_NO_PENDING_E)) {
11121
        /* Check for error */
11122
        if (ret < 0)
11123
            goto exit_scv;
11124
    }
11125
    else
11126
#endif
11127
    {
11128
        /* Reset state */
11129
        ret = 0;
11130
        ssl->options.asyncState = TLS_ASYNC_BEGIN;
11131
        XMEMSET(args, 0, sizeof(Scv13Args));
11132
    #ifdef WOLFSSL_ASYNC_CRYPT
11133
        ssl->async->freeArgs = FreeScv13Args;
11134
    #endif
11135
    }
11136
11137
#ifdef WOLFSSL_TLS13_STREAM_CERT_VERIFY
11138
    /* Resuming a partially-sent streamed CertificateVerify (e.g. after a
11139
     * non-blocking WANT_WRITE): the signature is already assembled in
11140
     * ssl->buffers.certVerifyMsg and ssl->fragOffset marks how much has been
11141
     * committed to records, so skip re-signing and continue sending. */
11142
    if (ssl->buffers.certVerifyMsg.buffer != NULL && ssl->fragOffset != 0) {
11143
        ssl->options.asyncState = TLS_ASYNC_END;
11144
    }
11145
#endif
11146
11147
    switch(ssl->options.asyncState)
11148
    {
11149
        case TLS_ASYNC_BEGIN:
11150
        {
11151
            if (ssl->options.sendVerify == SEND_BLANK_CERT) {
11152
            #ifdef WOLFSSL_BLIND_PRIVATE_KEY
11153
                wolfssl_priv_der_blind_toggle(ssl->buffers.key,
11154
                    ssl->buffers.keyMask);
11155
            #endif
11156
                return 0;  /* sent blank cert, can't verify */
11157
            }
11158
11159
            /* The output buffer is reserved in TLS_ASYNC_BUILD, once the
11160
             * private key has been decoded and the actual signature size is
11161
             * known. This avoids reserving the worst-case WC_MAX_CERT_VERIFY_SZ
11162
             * (very large when SLH-DSA is enabled) for every algorithm. */
11163
11164
            /* Advance state and proceed */
11165
            ssl->options.asyncState = TLS_ASYNC_BUILD;
11166
        } /* case TLS_ASYNC_BEGIN */
11167
        FALL_THROUGH;
11168
11169
        case TLS_ASYNC_BUILD:
11170
        {
11171
            int rem;
11172
#ifdef WOLFSSL_TLS13_STREAM_CERT_VERIFY
11173
            word32 bodySz;
11174
            word32 maxFrag;
11175
#endif
11176
            int doStream = 0;
11177
11178
            /* Decode the private key first so the output buffer can be sized
11179
             * to the actual signature length rather than the worst-case
11180
             * WC_MAX_CERT_VERIFY_SZ (very large when SLH-DSA is enabled). */
11181
            if (ssl->buffers.key == NULL) {
11182
            #ifdef HAVE_PK_CALLBACKS
11183
                if (wolfSSL_CTX_IsPrivatePkSet(ssl->ctx))
11184
                    args->sigLen = (word32)GetPrivateKeySigSize(ssl);
11185
                else
11186
            #endif
11187
                    ERROR_OUT(NO_PRIVATE_KEY, exit_scv);
11188
            }
11189
            else {
11190
#ifdef WOLFSSL_DUAL_ALG_CERTS
11191
                if (ssl->sigSpec != NULL &&
11192
                    *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_ALTERNATIVE) {
11193
                    /* In the case of alternative, we swap in the alt. */
11194
                    if (ssl->buffers.altKey == NULL) {
11195
                        ERROR_OUT(NO_PRIVATE_KEY, exit_scv);
11196
                    }
11197
                    ssl->buffers.keyType = ssl->buffers.altKeyType;
11198
                    ssl->buffers.keySz = ssl->buffers.altKeySz;
11199
                    /* If we own it, free key before overriding it. */
11200
                    if (ssl->buffers.weOwnKey) {
11201
                        FreeDer(&ssl->buffers.key);
11202
                    #ifdef WOLFSSL_BLIND_PRIVATE_KEY
11203
                        FreeDer(&ssl->buffers.keyMask);
11204
                    #endif
11205
                    }
11206
11207
                    /* Swap keys */
11208
                    ssl->buffers.key     = ssl->buffers.altKey;
11209
                    ssl->buffers.weOwnKey = ssl->buffers.weOwnAltKey;
11210
                    /* buffers.key is the only owner of the alt key now. */
11211
                    ssl->buffers.weOwnAltKey = 0;
11212
11213
                #ifdef WOLFSSL_BLIND_PRIVATE_KEY
11214
                    ssl->buffers.keyMask = ssl->buffers.altKeyMask;
11215
                    /* Unblind the alternative key before decoding */
11216
                    wolfssl_priv_der_blind_toggle(ssl->buffers.key, ssl->buffers.keyMask);
11217
                #endif
11218
                }
11219
#endif /* WOLFSSL_DUAL_ALG_CERTS */
11220
                ret = DecodePrivateKey(ssl, &args->sigLen);
11221
                if (ret != 0)
11222
                    goto exit_scv;
11223
            }
11224
11225
            if (args->sigLen == 0) {
11226
                ERROR_OUT(NO_PRIVATE_KEY, exit_scv);
11227
            }
11228
11229
#ifdef WOLFSSL_DUAL_ALG_CERTS
11230
            if (ssl->peerSigSpec == NULL) {
11231
                /* The peer did not respond. We didn't send CKS or they don't
11232
                 * support it. Either way, we do not need to handle dual
11233
                 * key/sig case. */
11234
                ssl->sigSpec = NULL;
11235
                ssl->sigSpecSz = 0;
11236
            }
11237
11238
            if (ssl->sigSpec != NULL &&
11239
                *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH) {
11240
                /* The native was already decoded. Decode the alternative now
11241
                 * too so its signature length is included when the output
11242
                 * buffer is sized below. */
11243
                if (ssl->buffers.altKey == NULL) {
11244
                    ERROR_OUT(NO_PRIVATE_KEY, exit_scv);
11245
                }
11246
11247
                /* After this call, args->altSigLen has the length we need for
11248
                 * the alternative signature. */
11249
                ret = DecodeAltPrivateKey(ssl, &args->altSigLen);
11250
                if (ret != 0)
11251
                    goto exit_scv;
11252
11253
                if (ssl->buffers.altKeyType == ecc_dsa_sa_algo ||
11254
                    ssl->buffers.altKeyType == falcon_level1_sa_algo ||
11255
                    ssl->buffers.altKeyType == falcon_level5_sa_algo ||
11256
                    ssl->buffers.altKeyType == mldsa_44_sa_algo ||
11257
                    ssl->buffers.altKeyType == mldsa_65_sa_algo ||
11258
                    ssl->buffers.altKeyType == mldsa_87_sa_algo) {
11259
                    args->altSigAlgo = ssl->buffers.altKeyType;
11260
                }
11261
                else if (ssl->buffers.altKeyType == rsa_sa_algo &&
11262
                         ssl->hsAltType == DYNAMIC_TYPE_RSA) {
11263
                    args->altSigAlgo = rsa_pss_sa_algo;
11264
                }
11265
                else {
11266
                    ERROR_OUT(ALGO_ID_E, exit_scv);
11267
                }
11268
            }
11269
#endif /* WOLFSSL_DUAL_ALG_CERTS */
11270
11271
            /* Decide how the CertificateVerify body will be emitted. When it
11272
             * exceeds a single record (e.g. a large SLH-DSA/ML-DSA signature,
11273
             * or any signature under a small max_fragment_length) on TLS 1.3,
11274
             * use the streaming path: generate the signature into a
11275
             * connection-level body buffer and send it one record at a time in
11276
             * TLS_ASYNC_END, so the shared output buffer never has to hold the
11277
             * whole signature. Otherwise reserve the output buffer for the
11278
             * whole message and build it in place. */
11279
#ifdef WOLFSSL_TLS13_STREAM_CERT_VERIFY
11280
            bodySz = HASH_SIG_SIZE + VERIFY_HEADER + (word32)args->sigLen;
11281
        #ifdef WOLFSSL_DUAL_ALG_CERTS
11282
            /* A dual (BOTH) body carries a second length-prefixed signature.
11283
             * args->sigLen/altSigLen are upper bounds here for variable-length
11284
             * schemes (ECDSA, Falcon), so this may over-size the body buffer by
11285
             * a few bytes; the body is assembled contiguously with the actual
11286
             * lengths, the exact length is recorded in TLS_ASYNC_FINALIZE, and
11287
             * the trailing slack is never sent. */
11288
            if (ssl->sigSpec != NULL &&
11289
                    *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH) {
11290
                bodySz += (word32)args->altSigLen + OPAQUE16_LEN + OPAQUE16_LEN;
11291
            }
11292
        #endif
11293
            maxFrag = (word32)wolfssl_local_GetMaxPlaintextSize(ssl);
11294
            if (!ssl->options.dtls &&
11295
                    (word32)HANDSHAKE_HEADER_SZ + bodySz > maxFrag) {
11296
                doStream = 1;
11297
            }
11298
#endif /* WOLFSSL_TLS13_STREAM_CERT_VERIFY */
11299
11300
            if (doStream) {
11301
#ifdef WOLFSSL_TLS13_STREAM_CERT_VERIFY
11302
                /* Generate the body directly into the connection-level buffer.
11303
                 * bodySz is exact here (a single fixed-or-max-length
11304
                 * signature); the final length is recorded in
11305
                 * TLS_ASYNC_FINALIZE. args->output stays NULL to mark the
11306
                 * streaming path; the send loop reserves one record at a
11307
                 * time. */
11308
                XFREE(ssl->buffers.certVerifyMsg.buffer, ssl->heap,
11309
                      DYNAMIC_TYPE_TMP_BUFFER);
11310
                ssl->buffers.certVerifyMsg.buffer =
11311
                    (byte*)XMALLOC(bodySz, ssl->heap, DYNAMIC_TYPE_TMP_BUFFER);
11312
                if (ssl->buffers.certVerifyMsg.buffer == NULL) {
11313
                    ssl->buffers.certVerifyMsg.length = 0;
11314
                    ERROR_OUT(MEMORY_E, exit_scv);
11315
                }
11316
                ssl->buffers.certVerifyMsg.length = bodySz;
11317
                ssl->fragOffset = 0;
11318
                args->verify = ssl->buffers.certVerifyMsg.buffer;
11319
                args->idx = 0;
11320
                args->sendSz = (int)bodySz;
11321
                args->output = NULL;
11322
                args->outputSz = 0;
11323
#endif /* WOLFSSL_TLS13_STREAM_CERT_VERIFY */
11324
            }
11325
            else {
11326
                /* Reserve the output buffer, sized from the actual signature
11327
                 * length(s) plus record/handshake framing and encryption
11328
                 * slack. */
11329
                args->sendSz = RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ +
11330
                               HASH_SIG_SIZE + VERIFY_HEADER + (int)args->sigLen;
11331
            #ifdef WOLFSSL_DUAL_ALG_CERTS
11332
                /* A dual (BOTH) body carries a second signature behind its own
11333
                 * length prefix, plus the combined length prefix. Matches the
11334
                 * streaming bodySz above. */
11335
                if (ssl->sigSpec != NULL &&
11336
                        *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH) {
11337
                    args->sendSz += (int)args->altSigLen + OPAQUE16_LEN +
11338
                                    OPAQUE16_LEN;
11339
                }
11340
                else {
11341
                    args->sendSz += (int)args->altSigLen;
11342
                }
11343
            #endif
11344
            #ifdef WOLFSSL_DTLS13
11345
                if (ssl->options.dtls)
11346
                    args->sendSz += recordLayerHdrExtra + DTLS_HANDSHAKE_EXTRA;
11347
            #endif /* WOLFSSL_DTLS13 */
11348
                /* Framing and always-on encryption expansion. */
11349
                args->sendSz += MAX_MSG_EXTRA;
11350
11351
                /* check for available size */
11352
                if ((ret = CheckAvailableSize(ssl, args->sendSz)) != 0) {
11353
                    goto exit_scv;
11354
                }
11355
11356
                /* get output buffer */
11357
                args->output = GetOutputBuffer(ssl);
11358
                /* Remember the reserved capacity for BuildTls13Message /
11359
                 * Dtls13HandshakeSend in TLS_ASYNC_END. */
11360
                args->outputSz = (word32)args->sendSz;
11361
11362
                rem = (int)(ssl->buffers.outputBuffer.bufferSize
11363
                                - ssl->buffers.outputBuffer.length
11364
                                - RECORD_HEADER_SZ - HANDSHAKE_HEADER_SZ);
11365
11366
                /* idx is used to track verify pointer offset to output */
11367
                args->idx = RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ;
11368
                args->verify =
11369
                          &args->output[RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ];
11370
11371
            #ifdef WOLFSSL_DTLS13
11372
                if (ssl->options.dtls) {
11373
                    rem -= recordLayerHdrExtra + DTLS_HANDSHAKE_EXTRA;
11374
                    args->idx += recordLayerHdrExtra + DTLS_HANDSHAKE_EXTRA;
11375
                    args->verify += recordLayerHdrExtra + DTLS_HANDSHAKE_EXTRA;
11376
                }
11377
            #endif /* WOLFSSL_DTLS13 */
11378
11379
                if (rem < 0 || (int)args->sigLen > rem) {
11380
                    ERROR_OUT(BUFFER_E, exit_scv);
11381
                }
11382
            }
11383
11384
            /* Add signature algorithm. */
11385
            if (ssl->hsType == DYNAMIC_TYPE_RSA)
11386
                args->sigAlgo = rsa_pss_sa_algo;
11387
        #ifdef HAVE_ECC
11388
            else if (ssl->hsType == DYNAMIC_TYPE_ECC) {
11389
        #if defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3)
11390
                if (ssl->buffers.keyType == sm2_sa_algo) {
11391
                    args->sigAlgo = sm2_sa_algo;
11392
                }
11393
                else
11394
        #endif
11395
                {
11396
                    args->sigAlgo = ecc_dsa_sa_algo;
11397
                }
11398
            }
11399
        #endif
11400
        #ifdef HAVE_ED25519
11401
            else if (ssl->hsType == DYNAMIC_TYPE_ED25519)
11402
                args->sigAlgo = ed25519_sa_algo;
11403
        #endif
11404
        #ifdef HAVE_ED448
11405
            else if (ssl->hsType == DYNAMIC_TYPE_ED448)
11406
                args->sigAlgo = ed448_sa_algo;
11407
        #endif
11408
        #if defined(HAVE_FALCON)
11409
            else if (ssl->hsType == DYNAMIC_TYPE_FALCON) {
11410
                args->sigAlgo = ssl->buffers.keyType;
11411
            }
11412
        #endif /* HAVE_FALCON */
11413
        #if defined(WOLFSSL_HAVE_MLDSA)
11414
            else if (ssl->hsType == DYNAMIC_TYPE_MLDSA) {
11415
                args->sigAlgo = ssl->buffers.keyType;
11416
            }
11417
        #endif /* WOLFSSL_HAVE_MLDSA */
11418
        #if defined(WOLFSSL_HAVE_SLHDSA)
11419
            else if (ssl->hsType == DYNAMIC_TYPE_SLHDSA) {
11420
                args->sigAlgo = ssl->buffers.keyType;
11421
            }
11422
        #endif /* WOLFSSL_HAVE_SLHDSA */
11423
            else {
11424
                ERROR_OUT(ALGO_ID_E, exit_scv);
11425
            }
11426
11427
        #ifdef WOLFSSL_DUAL_ALG_CERTS
11428
            if (ssl->sigSpec != NULL &&
11429
                *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH) {
11430
                /* The alternative key was already decoded and its sig-alg
11431
                 * determined above (when sizing the output buffer). Encode the
11432
                 * dual (native + alternative) signature algorithm pair. */
11433
                EncodeDualSigAlg(args->sigAlgo, args->altSigAlgo, args->verify);
11434
                if (args->verify[0] == 0) {
11435
                    ERROR_OUT(ALGO_ID_E, exit_scv);
11436
                }
11437
            }
11438
            else
11439
        #endif /* WOLFSSL_DUAL_ALG_CERTS */
11440
                EncodeSigAlg(ssl, ssl->options.hashAlgo, args->sigAlgo,
11441
                             args->verify);
11442
11443
            if (args->sigData == NULL) {
11444
                word32 sigLen = MAX_SIG_DATA_SZ;
11445
                if ((ssl->hsType == DYNAMIC_TYPE_RSA) &&
11446
                    (args->sigLen > MAX_SIG_DATA_SZ)) {
11447
                    /* We store the RSA signature in the sigData buffer
11448
                     * temporarily, hence its size must be fitting. */
11449
                    sigLen = args->sigLen;
11450
                }
11451
                args->sigData = (byte*)XMALLOC(sigLen, ssl->heap,
11452
                                                    DYNAMIC_TYPE_SIGNATURE);
11453
                if (args->sigData == NULL) {
11454
                    ERROR_OUT(MEMORY_E, exit_scv);
11455
                }
11456
            }
11457
11458
        #ifdef WOLFSSL_DUAL_ALG_CERTS
11459
            if ((ssl->sigSpec != NULL) &&
11460
                (*ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH) &&
11461
                (args->altSigData == NULL)) {
11462
                word32 sigLen = MAX_SIG_DATA_SZ;
11463
                if (ssl->hsAltType == DYNAMIC_TYPE_RSA &&
11464
                    args->altSigLen > MAX_SIG_DATA_SZ) {
11465
                    /* We store the RSA signature in the sigData buffer
11466
                     * temporarily, hence its size must be fitting. */
11467
                    sigLen = args->altSigLen;
11468
                }
11469
                args->altSigData = (byte*)XMALLOC(sigLen, ssl->heap,
11470
                                                    DYNAMIC_TYPE_SIGNATURE);
11471
                if (args->altSigData == NULL) {
11472
                    ERROR_OUT(MEMORY_E, exit_scv);
11473
                }
11474
            }
11475
        #endif /* WOLFSSL_DUAL_ALG_CERTS */
11476
11477
            /* Create the data to be signed. */
11478
            ret = CreateSigData(ssl, args->sigData, &args->sigDataSz, 0);
11479
            if (ret != 0)
11480
                goto exit_scv;
11481
11482
        #ifdef WOLFSSL_DUAL_ALG_CERTS
11483
            if ((ssl->sigSpec != NULL) &&
11484
                (*ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH)) {
11485
                XMEMCPY(args->altSigData, args->sigData, args->sigDataSz);
11486
                args->altSigDataSz = args->sigDataSz;
11487
            }
11488
        #endif /* WOLFSSL_DUAL_ALG_CERTS */
11489
11490
        #ifndef NO_RSA
11491
            if (ssl->hsType == DYNAMIC_TYPE_RSA) {
11492
                /* build encoded signature buffer */
11493
                rsaSigBuf->length = WC_MAX_DIGEST_SIZE;
11494
                rsaSigBuf->buffer = (byte*)XMALLOC(rsaSigBuf->length, ssl->heap,
11495
                                                   DYNAMIC_TYPE_SIGNATURE);
11496
                if (rsaSigBuf->buffer == NULL) {
11497
                    ERROR_OUT(MEMORY_E, exit_scv);
11498
                }
11499
11500
                ret = CreateRSAEncodedSig(rsaSigBuf->buffer, args->sigData,
11501
                    args->sigDataSz, args->sigAlgo, ssl->options.hashAlgo);
11502
                if (ret < 0)
11503
                    goto exit_scv;
11504
                rsaSigBuf->length = (unsigned int)ret;
11505
                ret = 0;
11506
            }
11507
        #endif /* !NO_RSA */
11508
        #ifdef HAVE_ECC
11509
            if (ssl->hsType == DYNAMIC_TYPE_ECC) {
11510
                args->sigLen = (word32)args->sendSz - args->idx -
11511
                               HASH_SIG_SIZE -
11512
                               VERIFY_HEADER;
11513
            #if defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3)
11514
                if (ssl->buffers.keyType != sm2_sa_algo)
11515
            #endif
11516
                {
11517
                    ret = CreateECCEncodedSig(args->sigData,
11518
                        args->sigDataSz, ssl->options.hashAlgo);
11519
                    if (ret < 0)
11520
                        goto exit_scv;
11521
                    args->sigDataSz = (word16)ret;
11522
                    ret = 0;
11523
                }
11524
            }
11525
        #endif /* HAVE_ECC */
11526
        #ifdef HAVE_ED25519
11527
            if (ssl->hsType == DYNAMIC_TYPE_ED25519) {
11528
                ret = Ed25519CheckPubKey(ssl);
11529
                if (ret < 0) {
11530
                    ERROR_OUT(ret, exit_scv);
11531
                }
11532
                args->sigLen = ED25519_SIG_SIZE;
11533
            }
11534
        #endif /* HAVE_ED25519 */
11535
        #ifdef HAVE_ED448
11536
            if (ssl->hsType == DYNAMIC_TYPE_ED448) {
11537
                ret = Ed448CheckPubKey(ssl);
11538
                if (ret < 0) {
11539
                    ERROR_OUT(ret, exit_scv);
11540
                }
11541
                args->sigLen = ED448_SIG_SIZE;
11542
            }
11543
11544
        #endif /* HAVE_ED448 */
11545
        #if defined(HAVE_FALCON)
11546
            if (ssl->hsType == DYNAMIC_TYPE_FALCON) {
11547
                /* Per-key, not the family maximum: this is handed to the
11548
                 * signer as the output capacity and the buffer above was
11549
                 * reserved from this key's signature length. */
11550
                int fSigSz = wc_falcon_sig_size((falcon_key*)ssl->hsKey);
11551
                if (fSigSz <= 0) {
11552
                    ERROR_OUT(ALGO_ID_E, exit_scv);
11553
                }
11554
                args->sigLen = (word32)fSigSz;
11555
            }
11556
        #endif /* HAVE_FALCON */
11557
        #if defined(WOLFSSL_HAVE_MLDSA) && !defined(WOLFSSL_MLDSA_NO_SIGN)
11558
            if (ssl->hsType == DYNAMIC_TYPE_MLDSA) {
11559
                int mSigSz = wc_MlDsaKey_SigSize((wc_MlDsaKey*)ssl->hsKey);
11560
                if (mSigSz <= 0) {
11561
                    ERROR_OUT(ALGO_ID_E, exit_scv);
11562
                }
11563
                args->sigLen = (word32)mSigSz;
11564
            }
11565
        #endif /* WOLFSSL_HAVE_MLDSA && !WOLFSSL_MLDSA_NO_SIGN */
11566
        #if defined(WOLFSSL_HAVE_SLHDSA)
11567
            if (ssl->hsType == DYNAMIC_TYPE_SLHDSA) {
11568
                int slhSigSz = wc_SlhDsaKey_SigSize((SlhDsaKey*)ssl->hsKey);
11569
                if (slhSigSz <= 0) {
11570
                    ERROR_OUT(ALGO_ID_E, exit_scv);
11571
                }
11572
                args->sigLen = (word32)slhSigSz;
11573
            }
11574
        #endif /* WOLFSSL_HAVE_SLHDSA */
11575
11576
        #ifdef WOLFSSL_DUAL_ALG_CERTS
11577
            if (ssl->sigSpec != NULL &&
11578
                *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH) {
11579
11580
            #ifndef NO_RSA
11581
                if (ssl->hsAltType == DYNAMIC_TYPE_RSA) {
11582
                    /* build encoded signature buffer */
11583
                    XFREE(rsaSigBuf->buffer, ssl->heap, DYNAMIC_TYPE_SIGNATURE);
11584
                    rsaSigBuf->length = WC_MAX_DIGEST_SIZE;
11585
                    rsaSigBuf->buffer = (byte*)XMALLOC(rsaSigBuf->length,
11586
                                                       ssl->heap,
11587
                                                       DYNAMIC_TYPE_SIGNATURE);
11588
                    if (rsaSigBuf->buffer == NULL) {
11589
                        ERROR_OUT(MEMORY_E, exit_scv);
11590
                    }
11591
11592
                    ret = CreateRSAEncodedSig(rsaSigBuf->buffer,
11593
                                    args->altSigData, args->altSigDataSz,
11594
                                    args->altSigAlgo, ssl->options.hashAlgo);
11595
                    if (ret < 0)
11596
                        goto exit_scv;
11597
                    rsaSigBuf->length = ret;
11598
                    ret = 0;
11599
                }
11600
            #endif /* !NO_RSA */
11601
            #ifdef HAVE_ECC
11602
                if (ssl->hsAltType == DYNAMIC_TYPE_ECC) {
11603
                    ret = CreateECCEncodedSig(args->altSigData,
11604
                            args->altSigDataSz, ssl->options.hashAlgo);
11605
                    if (ret < 0)
11606
                        goto exit_scv;
11607
                    args->altSigDataSz = (word16)ret;
11608
                    ret = 0;
11609
                }
11610
            #endif /* HAVE_ECC */
11611
            }
11612
        #endif /* WOLFSSL_DUAL_ALG_CERTS */
11613
11614
            /* Advance state and proceed */
11615
            ssl->options.asyncState = TLS_ASYNC_DO;
11616
        } /* case TLS_ASYNC_BUILD */
11617
        FALL_THROUGH;
11618
11619
        case TLS_ASYNC_DO:
11620
        {
11621
            byte* sigOut = args->verify + HASH_SIG_SIZE + VERIFY_HEADER;
11622
        #ifdef WOLFSSL_DUAL_ALG_CERTS
11623
            if (ssl->sigSpec != NULL &&
11624
                *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH) {
11625
                /* As we have two signatures in the message, we store
11626
                 * the length of each before the actual signature. This
11627
                 * is necessary, as we could have two algorithms with
11628
                 * variable length signatures. */
11629
                sigOut += OPAQUE16_LEN;
11630
            }
11631
        #endif
11632
            /* Only the per-algorithm signing branches below consume this. */
11633
            (void)sigOut;
11634
        #ifdef HAVE_ECC
11635
            if (ssl->hsType == DYNAMIC_TYPE_ECC) {
11636
            #if defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3)
11637
                if (ssl->buffers.keyType == sm2_sa_algo) {
11638
                    ret = Sm2wSm3Sign(ssl, TLS13_SM2_SIG_ID,
11639
                        TLS13_SM2_SIG_ID_SZ, args->sigData, args->sigDataSz,
11640
                        sigOut, &args->sigLen, (ecc_key*)ssl->hsKey, NULL);
11641
                }
11642
                else
11643
            #endif
11644
                {
11645
                    ret = EccSign(ssl, args->sigData, args->sigDataSz,
11646
                        sigOut, &args->sigLen, (ecc_key*)ssl->hsKey,
11647
                #ifdef HAVE_PK_CALLBACKS
11648
                        ssl->buffers.key
11649
                #else
11650
                        NULL
11651
                #endif
11652
                    );
11653
                }
11654
                args->length = args->sigLen;
11655
            }
11656
        #endif /* HAVE_ECC */
11657
        #ifdef HAVE_ED25519
11658
            if (ssl->hsType == DYNAMIC_TYPE_ED25519) {
11659
                ret = Ed25519Sign(ssl, args->sigData, args->sigDataSz,
11660
                    sigOut, &args->sigLen, (ed25519_key*)ssl->hsKey,
11661
            #ifdef HAVE_PK_CALLBACKS
11662
                    ssl->buffers.key
11663
            #else
11664
                    NULL
11665
            #endif
11666
                );
11667
                args->length = args->sigLen;
11668
            }
11669
        #endif
11670
        #ifdef HAVE_ED448
11671
            if (ssl->hsType == DYNAMIC_TYPE_ED448) {
11672
                ret = Ed448Sign(ssl, args->sigData, args->sigDataSz,
11673
                    sigOut, &args->sigLen, (ed448_key*)ssl->hsKey,
11674
            #ifdef HAVE_PK_CALLBACKS
11675
                    ssl->buffers.key
11676
            #else
11677
                    NULL
11678
            #endif
11679
                );
11680
                args->length = args->sigLen;
11681
            }
11682
        #endif
11683
        #if defined(HAVE_FALCON)
11684
            if (ssl->hsType == DYNAMIC_TYPE_FALCON) {
11685
                ret = wc_falcon_sign_msg(args->sigData, args->sigDataSz,
11686
                                         sigOut, &args->sigLen,
11687
                                         (falcon_key*)ssl->hsKey, ssl->rng);
11688
                args->length = args->sigLen;
11689
            }
11690
        #endif /* HAVE_FALCON */
11691
        #if defined(WOLFSSL_HAVE_MLDSA) && !defined(WOLFSSL_MLDSA_NO_SIGN)
11692
            if (ssl->hsType == DYNAMIC_TYPE_MLDSA) {
11693
                ret = wc_MlDsaKey_SignCtx((wc_MlDsaKey*)ssl->hsKey, NULL, 0,
11694
                                          sigOut, &args->sigLen,
11695
                                          args->sigData, args->sigDataSz,
11696
                                          ssl->rng);
11697
                args->length = args->sigLen;
11698
            }
11699
        #endif /* WOLFSSL_HAVE_MLDSA */
11700
        #if defined(WOLFSSL_HAVE_SLHDSA) && !defined(WOLFSSL_SLHDSA_VERIFY_ONLY)
11701
            if (ssl->hsType == DYNAMIC_TYPE_SLHDSA) {
11702
                /* The FIPS wrapper for wc_SlhDsaKey_Sign gates on the per-thread
11703
                 * privateKeyReadEnable flag (unlike ML-DSA sign), returning
11704
                 * FIPS_PRIVATE_KEY_LOCKED_E when the key is locked. Bracket the
11705
                 * sign so it can read the SLH-DSA private key. */
11706
                PRIVATE_KEY_UNLOCK();
11707
                ret = wc_SlhDsaKey_Sign((SlhDsaKey*)ssl->hsKey, NULL, 0,
11708
                                        args->sigData, args->sigDataSz,
11709
                                        sigOut, &args->sigLen, ssl->rng);
11710
                PRIVATE_KEY_LOCK();
11711
                args->length = args->sigLen;
11712
            }
11713
        #endif /* WOLFSSL_HAVE_SLHDSA */
11714
        #if !defined(NO_RSA) && !defined(WOLFSSL_RSA_PUBLIC_ONLY) && \
11715
            !defined(WOLFSSL_RSA_VERIFY_ONLY)
11716
            if (ssl->hsType == DYNAMIC_TYPE_RSA) {
11717
                args->toSign = rsaSigBuf->buffer;
11718
                args->toSignSz = (word32)rsaSigBuf->length;
11719
            #if defined(HAVE_PK_CALLBACKS) && \
11720
                defined(TLS13_RSA_PSS_SIGN_CB_NO_PREHASH)
11721
                /* Pass full data to sign (args->sigData), not hash of */
11722
                if (ssl->ctx->RsaPssSignCb) {
11723
                    args->toSign = args->sigData;
11724
                    args->toSignSz = args->sigDataSz;
11725
                }
11726
            #endif
11727
                ret = RsaSign(ssl, (const byte*)args->toSign, args->toSignSz,
11728
                              sigOut, &args->sigLen, args->sigAlgo,
11729
                              ssl->options.hashAlgo, (RsaKey*)ssl->hsKey,
11730
                              ssl->buffers.key);
11731
                if (ret == 0) {
11732
                    args->length = args->sigLen;
11733
                    XMEMCPY(args->sigData, sigOut, args->sigLen);
11734
                }
11735
            }
11736
        #endif /* !NO_RSA && !WOLFSSL_RSA_PUBLIC_ONLY && !WOLFSSL_RSA_VERIFY_ONLY */
11737
11738
            /* Check for error */
11739
            if (ret != 0) {
11740
                goto exit_scv;
11741
            }
11742
11743
        #ifdef WOLFSSL_DUAL_ALG_CERTS
11744
            if (ssl->sigSpec != NULL &&
11745
                *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH) {
11746
                /* Add signature length for the first signature. */
11747
                c16toa((word16)args->sigLen, sigOut - OPAQUE16_LEN);
11748
                args->length += OPAQUE16_LEN;
11749
11750
                /* Advance our pointer to where we store the alt signature.
11751
                 * We also add additional space for the length field of the
11752
                 * second signature. */
11753
                sigOut += args->sigLen + OPAQUE16_LEN;
11754
11755
                /* Generate the alternative signature */
11756
            #ifdef HAVE_ECC
11757
                if (ssl->hsAltType == DYNAMIC_TYPE_ECC) {
11758
                    ret = EccSign(ssl, args->altSigData, args->altSigDataSz,
11759
                                  sigOut, &args->altSigLen,
11760
                                  (ecc_key*)ssl->hsAltKey,
11761
                    #ifdef HAVE_PK_CALLBACKS
11762
                                  ssl->buffers.altKey
11763
                    #else
11764
                                  NULL
11765
                    #endif
11766
                                  );
11767
                }
11768
            #endif /* HAVE_ECC */
11769
            #if !defined(NO_RSA) && !defined(WOLFSSL_RSA_PUBLIC_ONLY) && \
11770
                !defined(WOLFSSL_RSA_VERIFY_ONLY)
11771
                if (ssl->hsAltType == DYNAMIC_TYPE_RSA) {
11772
                    args->toSign = rsaSigBuf->buffer;
11773
                    args->toSignSz = (word32)rsaSigBuf->length;
11774
                #if defined(HAVE_PK_CALLBACKS) && \
11775
                    defined(TLS13_RSA_PSS_SIGN_CB_NO_PREHASH)
11776
                    /* Pass full data to sign (args->altSigData), not hash of */
11777
                    if (ssl->ctx->RsaPssSignCb) {
11778
                        args->toSign = args->altSigData;
11779
                        args->toSignSz = (word32)args->altSigDataSz;
11780
                    }
11781
                #endif
11782
                    ret = RsaSign(ssl, (const byte*)args->toSign,
11783
                                  args->toSignSz, sigOut, &args->altSigLen,
11784
                                  args->altSigAlgo, ssl->options.hashAlgo,
11785
                                  (RsaKey*)ssl->hsAltKey,
11786
                                  ssl->buffers.altKey);
11787
11788
                    if (ret == 0) {
11789
                        XMEMCPY(args->altSigData, sigOut, args->altSigLen);
11790
                    }
11791
                }
11792
            #endif /* !NO_RSA && !WOLFSSL_RSA_PUBLIC_ONLY && !WOLFSSL_RSA_VERIFY_ONLY */
11793
            #if defined(HAVE_FALCON)
11794
                if (ssl->hsAltType == DYNAMIC_TYPE_FALCON) {
11795
                    ret = wc_falcon_sign_msg(args->altSigData,
11796
                                             args->altSigDataSz, sigOut,
11797
                                             &args->altSigLen,
11798
                                             (falcon_key*)ssl->hsAltKey,
11799
                                             ssl->rng);
11800
                }
11801
            #endif /* HAVE_FALCON */
11802
            #if defined(WOLFSSL_HAVE_MLDSA) && !defined(WOLFSSL_MLDSA_NO_SIGN)
11803
                if (ssl->hsAltType == DYNAMIC_TYPE_MLDSA) {
11804
                    ret = wc_MlDsaKey_SignCtx((wc_MlDsaKey*)ssl->hsAltKey,
11805
                                NULL, 0, sigOut, &args->altSigLen,
11806
                                args->altSigData, args->altSigDataSz, ssl->rng);
11807
                }
11808
            #endif /* WOLFSSL_HAVE_MLDSA */
11809
11810
                /* Check for error */
11811
                if (ret != 0) {
11812
                    goto exit_scv;
11813
                }
11814
11815
                /* Add signature length for the alternative signature. */
11816
                c16toa((word16)args->altSigLen, sigOut - OPAQUE16_LEN);
11817
11818
                /* Add length of the alt sig to the total length */
11819
                args->length += args->altSigLen + OPAQUE16_LEN;
11820
            }
11821
        #endif /* WOLFSSL_DUAL_ALG_CERTS */
11822
11823
            /* The TLS 1.3 CertificateVerify signature is length-prefixed with a
11824
             * 2-byte field (opaque signature<0..2^16-1>), so the body - a single
11825
             * signature, or the combined native + alternative signature with
11826
             * WOLFSSL_DUAL_ALG_CERTS - cannot exceed 65535 bytes. Reject rather
11827
             * than let c16toa truncate it into a malformed message. args->length
11828
             * is word32 so the dual-alg accumulation above cannot wrap before
11829
             * this check. */
11830
            if (args->length > WOLFSSL_MAX_16BIT) {
11831
                ERROR_OUT(BUFFER_E, exit_scv);
11832
            }
11833
11834
            /* Add signature length. */
11835
            c16toa((word16)args->length, args->verify + HASH_SIG_SIZE);
11836
11837
            /* Advance state and proceed */
11838
            ssl->options.asyncState = TLS_ASYNC_VERIFY;
11839
        } /* case TLS_ASYNC_DO */
11840
        FALL_THROUGH;
11841
11842
        case TLS_ASYNC_VERIFY:
11843
        {
11844
        #ifndef NO_RSA
11845
            if (ssl->hsType == DYNAMIC_TYPE_RSA) {
11846
                /* check for signature faults */
11847
                ret = VerifyRsaSign(ssl, args->sigData, args->sigLen,
11848
                    rsaSigBuf->buffer, (word32)rsaSigBuf->length, args->sigAlgo,
11849
                    ssl->options.hashAlgo, (RsaKey*)ssl->hsKey,
11850
                    ssl->buffers.key);
11851
            }
11852
        #ifdef WOLFSSL_DUAL_ALG_CERTS
11853
            if (ssl->sigSpec != NULL &&
11854
                *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH &&
11855
                ssl->hsAltType == DYNAMIC_TYPE_RSA) {
11856
                /* check for signature faults */
11857
                ret = VerifyRsaSign(ssl, args->altSigData, args->altSigLen,
11858
                        rsaSigBuf->buffer, (word32)rsaSigBuf->length,
11859
                        args->altSigAlgo, ssl->options.hashAlgo,
11860
                        (RsaKey*)ssl->hsAltKey, ssl->buffers.altKey);
11861
            }
11862
        #endif /* WOLFSSL_DUAL_ALG_CERTS */
11863
        #endif /* !NO_RSA */
11864
        #if defined(HAVE_ECC) && defined(WOLFSSL_CHECK_SIG_FAULTS)
11865
            if (ssl->hsType == DYNAMIC_TYPE_ECC) {
11866
                byte* sigOut = args->verify + HASH_SIG_SIZE + VERIFY_HEADER;
11867
            #ifdef WOLFSSL_DUAL_ALG_CERTS
11868
                if (ssl->sigSpec != NULL &&
11869
                    *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH) {
11870
                    /* Add our length offset. */
11871
                    sigOut += OPAQUE16_LEN;
11872
                }
11873
            #endif
11874
            #if defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3)
11875
                if (ssl->buffers.keyType == sm2_sa_algo) {
11876
                    ret = Sm2wSm3Verify(ssl, TLS13_SM2_SIG_ID,
11877
                        TLS13_SM2_SIG_ID_SZ,
11878
                        sigOut, args->sigLen, args->sigData, args->sigDataSz,
11879
                        (ecc_key*)ssl->hsKey, NULL);
11880
                }
11881
                else
11882
            #endif
11883
                {
11884
                #ifdef HAVE_PK_CALLBACKS
11885
                    buffer tmp;
11886
11887
                    /* Private key may be held by the PK callback. */
11888
                    tmp.length = ssl->buffers.key ?
11889
                        ssl->buffers.key->length : 0;
11890
                    tmp.buffer = ssl->buffers.key ?
11891
                        ssl->buffers.key->buffer : NULL;
11892
                #endif
11893
                    ret = EccVerify(ssl, sigOut, args->sigLen,
11894
                            args->sigData, args->sigDataSz,
11895
                            (ecc_key*)ssl->hsKey,
11896
                #ifdef HAVE_PK_CALLBACKS
11897
                            &tmp
11898
                #else
11899
                            NULL
11900
                #endif
11901
                            );
11902
                }
11903
            }
11904
        #ifdef WOLFSSL_DUAL_ALG_CERTS
11905
            if (ssl->sigSpec != NULL &&
11906
                *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH &&
11907
                ssl->hsAltType == DYNAMIC_TYPE_ECC) {
11908
                /* check for signature faults */
11909
                byte* sigOut = args->verify + HASH_SIG_SIZE + VERIFY_HEADER +
11910
                                args->sigLen + OPAQUE16_LEN + OPAQUE16_LEN;
11911
            #ifdef HAVE_PK_CALLBACKS
11912
                buffer tmp;
11913
11914
                /* Private key may be held by the PK callback. */
11915
                tmp.length = ssl->buffers.altKey ?
11916
                    ssl->buffers.altKey->length : 0;
11917
                tmp.buffer = ssl->buffers.altKey ?
11918
                    ssl->buffers.altKey->buffer : NULL;
11919
            #endif
11920
                ret = EccVerify(ssl, sigOut, args->altSigLen,
11921
                        args->altSigData, args->altSigDataSz,
11922
                        (ecc_key*)ssl->hsAltKey,
11923
            #ifdef HAVE_PK_CALLBACKS
11924
                        &tmp
11925
            #else
11926
                        NULL
11927
            #endif
11928
                        );
11929
            }
11930
        #endif /* WOLFSSL_DUAL_ALG_CERTS */
11931
        #endif /* HAVE_ECC && WOLFSSL_CHECK_SIG_FAULTS */
11932
11933
            /* Check for error */
11934
            if (ret != 0) {
11935
                goto exit_scv;
11936
            }
11937
11938
            /* Advance state and proceed */
11939
            ssl->options.asyncState = TLS_ASYNC_FINALIZE;
11940
        } /* case TLS_ASYNC_VERIFY */
11941
        FALL_THROUGH;
11942
11943
        case TLS_ASYNC_FINALIZE:
11944
        {
11945
#ifdef WOLFSSL_TLS13_STREAM_CERT_VERIFY
11946
            if (ssl->buffers.certVerifyMsg.buffer != NULL) {
11947
                /* Streaming path: the assembled body sits in certVerifyMsg;
11948
                 * record its final length (exact even for variable-length
11949
                 * signatures). Per-fragment record/handshake headers are added
11950
                 * in TLS_ASYNC_END. */
11951
                ssl->buffers.certVerifyMsg.length =
11952
                    (word32)args->length + HASH_SIG_SIZE + VERIFY_HEADER;
11953
            }
11954
#endif /* WOLFSSL_TLS13_STREAM_CERT_VERIFY */
11955
            /* In-place path: put the record and handshake headers on now.
11956
             * args->output is NULL only on the streaming path. */
11957
            if (args->output != NULL) {
11958
                AddTls13Headers(args->output, args->length + HASH_SIG_SIZE +
11959
                                VERIFY_HEADER, certificate_verify, ssl);
11960
11961
                args->sendSz = RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ +
11962
                                args->length + HASH_SIG_SIZE + VERIFY_HEADER;
11963
            #ifdef WOLFSSL_DTLS13
11964
                if (ssl->options.dtls)
11965
                    args->sendSz += recordLayerHdrExtra + DTLS_HANDSHAKE_EXTRA;
11966
            #endif /* WOLFSSL_DTLS13 */
11967
            }
11968
            /* Advance state and proceed */
11969
            ssl->options.asyncState = TLS_ASYNC_END;
11970
        } /* case TLS_ASYNC_FINALIZE */
11971
        FALL_THROUGH;
11972
11973
        case TLS_ASYNC_END:
11974
        {
11975
            /* Body of the handshake message: [sigAlg(2) | sigLen(2) | sig]. In
11976
             * the in-place path it sits at args->verify in the output buffer;
11977
             * in the streaming path it sits in ssl->buffers.certVerifyMsg. */
11978
            word32 msgSz;
11979
            word32 maxFrag = (word32)wolfssl_local_GetMaxPlaintextSize(ssl);
11980
            byte*  output;
11981
            word32 fragSz;
11982
            word32 i;
11983
            int    recSz;
11984
            int    thisSendSz;
11985
11986
#ifdef WOLFSSL_TLS13_STREAM_CERT_VERIFY
11987
            if (ssl->buffers.certVerifyMsg.buffer != NULL) {
11988
                /* Streamed send: the assembled body lives in
11989
                 * ssl->buffers.certVerifyMsg and the send cursor in
11990
                 * ssl->fragOffset - both connection-level - so a non-blocking
11991
                 * WANT_WRITE resumes here (via TLS_ASYNC_END) without
11992
                 * recomputing the signature. Emit one encrypted record per
11993
                 * iteration and flush it, so the output buffer never holds more
11994
                 * than a single fragment. Only the first record carries the
11995
                 * handshake header; BuildTls13Message hashes each fragment's
11996
                 * plaintext in order, keeping the transcript hash correct. The
11997
                 * cursor is advanced before the flush because the record is
11998
                 * already committed to the output buffer; the cursor tracks
11999
                 * message-body -> record progress, not bytes on the wire, so a
12000
                 * WANT_WRITE resumes on the next fragment. Advancing after the
12001
                 * flush would rebuild and double-send the fragment on resume.
12002
                 * This is not merely a convention: the accept/connect loop
12003
                 * flushes pending output and returns WANT_WRITE without
12004
                 * re-entering this function until the output buffer drains, so
12005
                 * the committed record is never skipped or overwritten.
12006
                 * certVerifyMsg is released on completion or error at exit_scv;
12007
                 * it is kept across WANT_WRITE for resume. */
12008
                msgSz = ssl->buffers.certVerifyMsg.length;
12009
                if (maxFrag <= HANDSHAKE_HEADER_SZ) {
12010
                    ERROR_OUT(BUFFER_E, exit_scv);
12011
                }
12012
                while (ssl->fragOffset < msgSz && ret == 0) {
12013
                    if (ssl->fragOffset == 0) {
12014
                        fragSz = maxFrag - HANDSHAKE_HEADER_SZ;
12015
                        if (fragSz > msgSz)
12016
                            fragSz = msgSz;
12017
                        i = RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ;
12018
                        thisSendSz = RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ +
12019
                                     (int)fragSz + MAX_MSG_EXTRA;
12020
                    }
12021
                    else {
12022
                        fragSz = msgSz - ssl->fragOffset;
12023
                        if (fragSz > maxFrag)
12024
                            fragSz = maxFrag;
12025
                        i = RECORD_HEADER_SZ;
12026
                        thisSendSz = RECORD_HEADER_SZ + (int)fragSz +
12027
                                     MAX_MSG_EXTRA;
12028
                    }
12029
12030
                    if ((ret = CheckAvailableSize(ssl, thisSendSz)) != 0) {
12031
                        goto exit_scv;
12032
                    }
12033
                    output = GetOutputBuffer(ssl);
12034
12035
                    if (ssl->fragOffset == 0) {
12036
                        AddTls13FragHeaders(output, fragSz, 0, msgSz,
12037
                                            certificate_verify, ssl);
12038
                    }
12039
                    else {
12040
                        AddTls13RecordHeader(output, fragSz, handshake, ssl);
12041
                    }
12042
                    XMEMCPY(output + i,
12043
                            ssl->buffers.certVerifyMsg.buffer + ssl->fragOffset,
12044
                            fragSz);
12045
12046
                    /* This message is always encrypted. */
12047
                    recSz = BuildTls13Message(ssl, output, thisSendSz,
12048
                                output + RECORD_HEADER_SZ,
12049
                                (int)(i - RECORD_HEADER_SZ + fragSz), handshake,
12050
                                1, 0, 0);
12051
                    if (recSz < 0) {
12052
                        ret = recSz;
12053
                        goto exit_scv;
12054
                    }
12055
12056
                #if defined(WOLFSSL_CALLBACKS) || defined(OPENSSL_EXTRA)
12057
                    /* Trace the logical CertificateVerify once (first fragment),
12058
                     * matching the single-record path. */
12059
                    if (ssl->fragOffset == 0) {
12060
                        if (ssl->hsInfoOn)
12061
                            AddPacketName(ssl, "CertificateVerify");
12062
                        if (ssl->toInfoOn) {
12063
                            ret = AddPacketInfo(ssl, "CertificateVerify",
12064
                                        handshake, output, recSz, WRITE_PROTO, 0,
12065
                                        ssl->heap);
12066
                            if (ret != 0)
12067
                                goto exit_scv;
12068
                        }
12069
                    }
12070
                #endif
12071
12072
                    ssl->buffers.outputBuffer.length += (word32)recSz;
12073
                    ssl->fragOffset += fragSz;
12074
                    /* Flush every fragment unconditionally - unlike the
12075
                     * in-place path this cannot honor ssl->options.groupMessages
12076
                     * (batch with later handshake messages), because streaming
12077
                     * exists precisely to keep the output buffer bounded to a
12078
                     * single fragment. */
12079
                    ret = SendBuffered(ssl);
12080
                }
12081
12082
                ssl->options.buildingMsg = 0;
12083
                break;
12084
            }
12085
#endif /* WOLFSSL_TLS13_STREAM_CERT_VERIFY */
12086
12087
            /* In-place path: the whole message is in args->output. */
12088
            msgSz = (word32)args->length + HASH_SIG_SIZE + VERIFY_HEADER;
12089
12090
#ifdef WOLFSSL_DTLS13
12091
            if (ssl->options.dtls) {
12092
                ssl->options.buildingMsg = 0;
12093
12094
                /* Dtls13HandshakeSend takes word16 output/send sizes, so the
12095
                 * whole assembled CertificateVerify (signature plus framing)
12096
                 * must fit in 16 bits. Every current SLH-DSA parameter set
12097
                 * stays well under this (256f, the largest, is ~50KB), but
12098
                 * guard the casts explicitly - mirroring the args->length check
12099
                 * on the TLS path - so a future larger signature fails loudly
12100
                 * instead of being silently truncated into a malformed record.
12101
                 * outputSz is the reserved capacity and is >= sendSz, so it
12102
                 * bounds both casts. */
12103
                if (args->outputSz > WOLFSSL_MAX_16BIT) {
12104
                    ERROR_OUT(BUFFER_E, exit_scv);
12105
                }
12106
12107
                ret = Dtls13HandshakeSend(ssl, args->output,
12108
                    (word16)args->outputSz,
12109
                    (word16)args->sendSz, certificate_verify, 1);
12110
                if (ret != 0)
12111
                    goto exit_scv;
12112
12113
                break;
12114
            }
12115
#endif /* WOLFSSL_DTLS13 */
12116
12117
            if (HANDSHAKE_HEADER_SZ + msgSz <= maxFrag) {
12118
                /* Fits in a single record: the common path used by RSA, ECC,
12119
                 * EdDSA and ML-DSA is left byte-for-byte unchanged. */
12120
12121
                /* Always encrypted. A record AEAD pend propagates through
12122
                 * exit_scv (args kept) and the retry resumes the build. */
12123
                ret = BuildTls13Message(ssl, args->output,
12124
                                        (int)args->outputSz,
12125
                                        args->output + RECORD_HEADER_SZ,
12126
                                        args->sendSz - RECORD_HEADER_SZ,
12127
                                        handshake, 1, 0,
12128
                                        TLS13_HS_ASYNC_OKAY);
12129
12130
                if (ret < 0) {
12131
                    goto exit_scv;
12132
                }
12133
                else {
12134
                    args->sendSz = ret;
12135
                    ret = 0;
12136
                }
12137
12138
            #if defined(WOLFSSL_CALLBACKS) || defined(OPENSSL_EXTRA)
12139
                if (ssl->hsInfoOn)
12140
                    AddPacketName(ssl, "CertificateVerify");
12141
                if (ssl->toInfoOn) {
12142
                    ret = AddPacketInfo(ssl, "CertificateVerify", handshake,
12143
                                args->output, args->sendSz, WRITE_PROTO, 0,
12144
                                ssl->heap);
12145
                    if (ret != 0)
12146
                        goto exit_scv;
12147
                }
12148
            #endif
12149
12150
                ssl->buffers.outputBuffer.length += (word32)args->sendSz;
12151
            }
12152
            else {
12153
                /* Signature does not fit in a single TLS record (e.g. SLH-DSA,
12154
                 * whose signatures range up to ~50KB). Fragment the handshake
12155
                 * message across multiple encrypted records. Only the first
12156
                 * fragment carries the 4-byte handshake header; the transcript
12157
                 * hash is maintained correctly because BuildTls13Message hashes
12158
                 * each fragment's plaintext in order.
12159
                 *
12160
                 * The fragmentation cursor lives in args (frag/fragOffset/
12161
                 * fragActive) so that a WC_PENDING_E from the record AEAD under
12162
                 * WOLFSSL_ASYNC_CRYPT resumes on the same fragment rather than
12163
                 * restarting at offset 0 and re-emitting committed records. */
12164
                if (maxFrag <= HANDSHAKE_HEADER_SZ) {
12165
                    ERROR_OUT(BUFFER_E, exit_scv);
12166
                }
12167
12168
                /* Copy the assembled body out of the output buffer once, before
12169
                 * we begin overwriting it with per-record data. args->frag is
12170
                 * preserved across async resumes and freed by FreeScv13Args. */
12171
                if (args->frag == NULL) {
12172
                    args->frag = (byte*)XMALLOC(msgSz, ssl->heap,
12173
                                                DYNAMIC_TYPE_TMP_BUFFER);
12174
                    if (args->frag == NULL) {
12175
                        ERROR_OUT(MEMORY_E, exit_scv);
12176
                    }
12177
                    XMEMCPY(args->frag, args->verify, msgSz);
12178
                    args->fragOffset = 0;
12179
                    args->fragActive = 0;
12180
                }
12181
12182
                while (args->fragOffset < msgSz && ret == 0) {
12183
                    if (args->fragOffset == 0) {
12184
                        fragSz = maxFrag - HANDSHAKE_HEADER_SZ;
12185
                        if (fragSz > msgSz)
12186
                            fragSz = msgSz;
12187
                        thisSendSz = RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ +
12188
                                     (int)fragSz + MAX_MSG_EXTRA;
12189
                    }
12190
                    else {
12191
                        fragSz = msgSz - args->fragOffset;
12192
                        if (fragSz > maxFrag)
12193
                            fragSz = maxFrag;
12194
                        thisSendSz = RECORD_HEADER_SZ + (int)fragSz +
12195
                                     MAX_MSG_EXTRA;
12196
                    }
12197
12198
                    if ((ret = CheckAvailableSize(ssl, thisSendSz)) != 0) {
12199
                        goto exit_scv;
12200
                    }
12201
                    output = GetOutputBuffer(ssl);
12202
12203
                    i = RECORD_HEADER_SZ;
12204
                    if (args->fragOffset == 0)
12205
                        i += HANDSHAKE_HEADER_SZ;
12206
12207
                    /* Lay out this fragment's record header and plaintext once.
12208
                     * On an async resume of a pending fragment they are already
12209
                     * in place (outputBuffer.length was not advanced), so skip
12210
                     * straight to re-driving BuildTls13Message. */
12211
                    if (!args->fragActive) {
12212
                        if (args->fragOffset == 0) {
12213
                            AddTls13FragHeaders(output, fragSz, 0, msgSz,
12214
                                                certificate_verify, ssl);
12215
                        }
12216
                        else {
12217
                            AddTls13RecordHeader(output, fragSz, handshake, ssl);
12218
                        }
12219
                        XMEMCPY(output + i, args->frag + args->fragOffset,
12220
                                fragSz);
12221
                        args->fragActive = 1;
12222
                    }
12223
                    i += fragSz;
12224
12225
                    /* This message is always encrypted. */
12226
                    recSz = BuildTls13Message(ssl, output, thisSendSz,
12227
                                output + RECORD_HEADER_SZ,
12228
                                (int)(i - RECORD_HEADER_SZ), handshake, 1, 0, 0);
12229
                    if (recSz < 0) {
12230
                        /* WC_PENDING_E leaves frag/fragOffset/fragActive intact
12231
                         * for resume; real errors are cleaned up by
12232
                         * FreeScv13Args at exit_scv. */
12233
                        ret = recSz;
12234
                        goto exit_scv;
12235
                    }
12236
12237
                #if defined(WOLFSSL_CALLBACKS) || defined(OPENSSL_EXTRA)
12238
                    /* Trace the logical CertificateVerify once (on the first
12239
                     * fragment), matching the single-record path rather than
12240
                     * emitting one entry per record. */
12241
                    if (args->fragOffset == 0) {
12242
                        if (ssl->hsInfoOn)
12243
                            AddPacketName(ssl, "CertificateVerify");
12244
                        if (ssl->toInfoOn) {
12245
                            ret = AddPacketInfo(ssl, "CertificateVerify",
12246
                                        handshake, output, recSz, WRITE_PROTO, 0,
12247
                                        ssl->heap);
12248
                            if (ret != 0)
12249
                                goto exit_scv;
12250
                        }
12251
                    }
12252
                #endif
12253
12254
                    ssl->buffers.outputBuffer.length += (word32)recSz;
12255
                    args->fragOffset += fragSz;
12256
                    args->fragActive = 0;
12257
                }
12258
            }
12259
12260
            ssl->options.buildingMsg = 0;
12261
            if (!ssl->options.groupMessages)
12262
                ret = SendBuffered(ssl);
12263
            break;
12264
        }
12265
        default:
12266
            ret = INPUT_CASE_ERROR;
12267
    } /* switch(ssl->options.asyncState) */
12268
12269
exit_scv:
12270
#ifdef WOLFSSL_TLS13_STREAM_CERT_VERIFY
12271
    /* A streamed CertificateVerify keeps its assembled body across a
12272
     * non-blocking WANT_WRITE so the send resumes without recomputing the
12273
     * signature; release it on completion or on any real error. This path is
12274
     * mutually exclusive with WOLFSSL_ASYNC_CRYPT (see the feature guard in
12275
     * internal.h), so ret is never WC_PENDING_E here and the buffer needs no
12276
     * retention across an async resume. */
12277
    if (ret != WC_NO_ERR_TRACE(WANT_WRITE) &&
12278
            ssl->buffers.certVerifyMsg.buffer != NULL) {
12279
        XFREE(ssl->buffers.certVerifyMsg.buffer, ssl->heap,
12280
              DYNAMIC_TYPE_TMP_BUFFER);
12281
        ssl->buffers.certVerifyMsg.buffer = NULL;
12282
        ssl->buffers.certVerifyMsg.length = 0;
12283
        ssl->fragOffset = 0;
12284
    }
12285
#endif /* WOLFSSL_TLS13_STREAM_CERT_VERIFY */
12286
#ifdef WOLFSSL_BLIND_PRIVATE_KEY
12287
    if (ret == 0) {
12288
        ret = wolfssl_priv_der_blind(ssl->rng, ssl->buffers.key,
12289
            &ssl->buffers.keyMask);
12290
    }
12291
    else {
12292
        wolfssl_priv_der_blind_toggle(ssl->buffers.key, ssl->buffers.keyMask);
12293
    }
12294
#endif
12295
12296
    WOLFSSL_LEAVE("SendTls13CertificateVerify", ret);
12297
    WOLFSSL_END(WC_FUNC_CERTIFICATE_VERIFY_SEND);
12298
12299
#ifdef WOLFSSL_ASYNC_CRYPT
12300
    /* Handle async operation */
12301
    if (ret == WC_NO_ERR_TRACE(WC_PENDING_E)) {
12302
        return ret;
12303
    }
12304
#endif /* WOLFSSL_ASYNC_CRYPT */
12305
12306
    /* Final cleanup */
12307
    FreeScv13Args(ssl, args);
12308
    FreeKeyExchange(ssl);
12309
#ifdef WOLFSSL_ASYNC_IO
12310
    /* Cleanup async */
12311
    FreeAsyncCtx(ssl, 0);
12312
#endif
12313
12314
    if (ret != 0) {
12315
        WOLFSSL_ERROR_VERBOSE(ret);
12316
    }
12317
12318
    return ret;
12319
}
12320
#endif
12321
#endif /* !NO_WOLFSSL_CLIENT || !NO_WOLFSSL_SERVER */
12322
12323
#if !defined(NO_WOLFSSL_CLIENT) || !defined(WOLFSSL_NO_CLIENT_AUTH)
12324
/* handle processing TLS v1.3 certificate (11) */
12325
/* Parse and handle a TLS v1.3 Certificate message.
12326
 *
12327
 * ssl       The SSL/TLS object.
12328
 * input     The message buffer.
12329
 * inOutIdx  On entry, the index into the message buffer of Certificate.
12330
 *           On exit, the index of byte after the Certificate message.
12331
 * totalSz   The length of the current handshake message.
12332
 * returns 0 on success and otherwise failure.
12333
 */
12334
static int DoTls13Certificate(WOLFSSL* ssl, byte* input, word32* inOutIdx,
12335
                              word32 totalSz)
12336
0
{
12337
0
    int ret = 0;
12338
12339
0
    WOLFSSL_START(WC_FUNC_CERTIFICATE_DO);
12340
0
    WOLFSSL_ENTER("DoTls13Certificate");
12341
12342
#ifdef WOLFSSL_DTLS13
12343
    if (ssl->options.dtls && ssl->options.handShakeDone) {
12344
        /* certificate needs some special care after the handshake */
12345
        ret = Dtls13RtxProcessingCertificate(
12346
            ssl, input + *inOutIdx, totalSz);
12347
    }
12348
#endif /* WOLFSSL_DTLS13 */
12349
12350
0
    if (ret == 0)
12351
0
        ret = ProcessPeerCerts(ssl, input, inOutIdx, totalSz);
12352
0
    if (ret == 0) {
12353
0
#if !defined(NO_WOLFSSL_CLIENT)
12354
0
        if (ssl->options.side == WOLFSSL_CLIENT_END)
12355
0
            ssl->options.serverState = SERVER_CERT_COMPLETE;
12356
0
#endif
12357
#if !defined(NO_WOLFSSL_SERVER) && defined(WOLFSSL_POST_HANDSHAKE_AUTH)
12358
        if (ssl->options.side == WOLFSSL_SERVER_END &&
12359
                                ssl->options.handShakeState == HANDSHAKE_DONE) {
12360
            /* reset handshake states */
12361
            ssl->options.serverState = SERVER_FINISHED_COMPLETE;
12362
            ssl->options.acceptState  = TICKET_SENT;
12363
            ssl->options.handShakeState = SERVER_FINISHED_COMPLETE;
12364
        }
12365
#endif
12366
0
    }
12367
12368
0
    WOLFSSL_LEAVE("DoTls13Certificate", ret);
12369
0
    WOLFSSL_END(WC_FUNC_CERTIFICATE_DO);
12370
12371
0
    return ret;
12372
0
}
12373
#endif
12374
12375
#if (!defined(NO_RSA) || defined(HAVE_ECC) || defined(HAVE_ED25519) || \
12376
     defined(HAVE_ED448) || defined(HAVE_FALCON) || \
12377
     defined(WOLFSSL_HAVE_MLDSA) || defined(WOLFSSL_HAVE_SLHDSA)) && \
12378
    !defined(NO_CERTS)
12379
12380
typedef struct Dcv13Args {
12381
    byte*  output; /* not allocated */
12382
    word32 sendSz;
12383
    word16 sz;
12384
    word32 sigSz;
12385
    word32 idx;
12386
    word32 begin;
12387
12388
    byte*  sigData;
12389
    word16 sigDataSz;
12390
#ifdef WOLFSSL_DUAL_ALG_CERTS
12391
    byte   altSigAlgo;
12392
    byte*  altSigData;
12393
    word32 altSigDataSz;
12394
    word32 altSignatureSz;
12395
    byte   altPeerAuthGood;
12396
#endif
12397
} Dcv13Args;
12398
12399
static void FreeDcv13Args(WOLFSSL* ssl, void* pArgs)
12400
0
{
12401
0
    Dcv13Args* args = (Dcv13Args*)pArgs;
12402
12403
0
    if (args && args->sigData != NULL) {
12404
0
        XFREE(args->sigData, ssl->heap, DYNAMIC_TYPE_SIGNATURE);
12405
0
        args->sigData = NULL;
12406
0
    }
12407
#ifdef WOLFSSL_DUAL_ALG_CERTS
12408
    if (args && args->altSigData != NULL) {
12409
        XFREE(args->altSigData, ssl->heap, DYNAMIC_TYPE_SIGNATURE);
12410
        args->altSigData = NULL;
12411
    }
12412
#endif
12413
0
    (void)ssl;
12414
0
}
12415
12416
#ifdef WOLFSSL_DUAL_ALG_CERTS
12417
#ifndef NO_RSA
12418
/* ssl->peerCert->sapkiDer is the alternative public key. Hopefully it is a
12419
 * RSA public key. Convert it into a usable public key. */
12420
static int decodeRsaKey(WOLFSSL* ssl)
12421
{
12422
    int keyRet;
12423
    word32 tmpIdx = 0;
12424
12425
    if (ssl->peerRsaKeyPresent)
12426
        return INVALID_PARAMETER;
12427
12428
    keyRet = AllocKey(ssl, DYNAMIC_TYPE_RSA, (void**)&ssl->peerRsaKey);
12429
    if (keyRet != 0)
12430
        return PEER_KEY_ERROR;
12431
12432
    ssl->peerRsaKeyPresent = 1;
12433
    keyRet = wc_RsaPublicKeyDecode(ssl->peerCert.sapkiDer, &tmpIdx,
12434
                                   ssl->peerRsaKey,
12435
                                   ssl->peerCert.sapkiLen);
12436
    if (keyRet != 0)
12437
        return PEER_KEY_ERROR;
12438
12439
    return 0;
12440
}
12441
#endif /* !NO_RSA */
12442
12443
#ifdef HAVE_ECC
12444
/* ssl->peerCert->sapkiDer is the alternative public key. Hopefully it is a
12445
 * ECC public key. Convert it into a usable public key. */
12446
static int decodeEccKey(WOLFSSL* ssl)
12447
{
12448
    int keyRet;
12449
    word32 tmpIdx = 0;
12450
12451
    if (ssl->peerEccDsaKeyPresent)
12452
        return INVALID_PARAMETER;
12453
12454
    keyRet = AllocKey(ssl, DYNAMIC_TYPE_ECC, (void**)&ssl->peerEccDsaKey);
12455
    if (keyRet != 0)
12456
        return PEER_KEY_ERROR;
12457
12458
    ssl->peerEccDsaKeyPresent = 1;
12459
    keyRet = wc_EccPublicKeyDecode(ssl->peerCert.sapkiDer, &tmpIdx,
12460
                                   ssl->peerEccDsaKey,
12461
                                   ssl->peerCert.sapkiLen);
12462
    if (keyRet != 0)
12463
        return PEER_KEY_ERROR;
12464
12465
    return 0;
12466
}
12467
#endif /* HAVE_ECC */
12468
12469
#ifdef WOLFSSL_HAVE_MLDSA
12470
/* ssl->peerCert->sapkiDer is the alternative public key. Hopefully it is a
12471
 * ML-DSA public key. Convert it into a usable public key. */
12472
static int decodeMlDsaKey(WOLFSSL* ssl, int level)
12473
{
12474
    int keyRet;
12475
    word32 tmpIdx = 0;
12476
12477
    if (ssl->peerMlDsaKeyPresent)
12478
        return INVALID_PARAMETER;
12479
12480
    keyRet = AllocKey(ssl, DYNAMIC_TYPE_MLDSA,
12481
                      (void**)&ssl->peerMlDsaKey);
12482
    if (keyRet != 0)
12483
        return PEER_KEY_ERROR;
12484
12485
    ssl->peerMlDsaKeyPresent = 1;
12486
    keyRet = wc_MlDsaKey_SetParams(ssl->peerMlDsaKey, level);
12487
    if (keyRet != 0)
12488
        return PEER_KEY_ERROR;
12489
12490
    keyRet = wc_MlDsaKey_PublicKeyDecode(ssl->peerMlDsaKey,
12491
                                         ssl->peerCert.sapkiDer,
12492
                                         ssl->peerCert.sapkiLen, &tmpIdx);
12493
    if (keyRet != 0)
12494
        return PEER_KEY_ERROR;
12495
12496
    return 0;
12497
}
12498
#endif /* WOLFSSL_HAVE_MLDSA */
12499
12500
#ifdef HAVE_FALCON
12501
/* ssl->peerCert->sapkiDer is the alternative public key. Hopefully it is a
12502
 * falcon public key. Convert it into a usable public key. */
12503
static int decodeFalconKey(WOLFSSL* ssl, int level)
12504
{
12505
    int keyRet;
12506
    word32 tmpIdx = 0;
12507
12508
    if (ssl->peerFalconKeyPresent)
12509
        return INVALID_PARAMETER;
12510
12511
    keyRet = AllocKey(ssl, DYNAMIC_TYPE_FALCON, (void**)&ssl->peerFalconKey);
12512
    if (keyRet != 0)
12513
        return PEER_KEY_ERROR;
12514
12515
    ssl->peerFalconKeyPresent = 1;
12516
    keyRet = wc_falcon_set_level(ssl->peerFalconKey, level);
12517
    if (keyRet != 0)
12518
        return PEER_KEY_ERROR;
12519
12520
    keyRet = wc_Falcon_PublicKeyDecode(ssl->peerCert.sapkiDer, &tmpIdx,
12521
                                       ssl->peerFalconKey,
12522
                                       ssl->peerCert.sapkiLen);
12523
    if (keyRet != 0)
12524
        return PEER_KEY_ERROR;
12525
12526
    return 0;
12527
}
12528
#endif /* HAVE_FALCON */
12529
#endif /* WOLFSSL_DUAL_ALG_CERTS */
12530
12531
/* handle processing TLS v1.3 certificate_verify (15) */
12532
/* Parse and handle a TLS v1.3 CertificateVerify message.
12533
 *
12534
 * ssl       The SSL/TLS object.
12535
 * input     The message buffer.
12536
 * inOutIdx  On entry, the index into the message buffer of
12537
 *           CertificateVerify.
12538
 *           On exit, the index of byte after the CertificateVerify message.
12539
 * totalSz   The length of the current handshake message.
12540
 * returns 0 on success and otherwise failure.
12541
 */
12542
static int DoTls13CertificateVerify(WOLFSSL* ssl, byte* input,
12543
                                    word32* inOutIdx, word32 totalSz)
12544
0
{
12545
0
    int         ret = 0;
12546
0
    byte*       sig = NULL;
12547
0
#ifndef NO_RSA
12548
    /* Use this as a temporary buffer for RSA signature verification. */
12549
0
    buffer*     rsaSigBuf = &ssl->buffers.sig;
12550
0
#endif
12551
#ifdef WOLFSSL_ASYNC_CRYPT
12552
    Dcv13Args* args = NULL;
12553
    WOLFSSL_ASSERT_SIZEOF_GE(ssl->async->args, *args);
12554
#else
12555
0
    Dcv13Args  args[1];
12556
0
#endif
12557
12558
0
    WOLFSSL_START(WC_FUNC_CERTIFICATE_VERIFY_DO);
12559
0
    WOLFSSL_ENTER("DoTls13CertificateVerify");
12560
12561
#if defined(WOLFSSL_RENESAS_TSIP_TLS)
12562
    ret = tsip_Tls13CertificateVerify(ssl, input, inOutIdx, totalSz);
12563
    if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) {
12564
        goto exit_dcv;
12565
    }
12566
    ret = 0;
12567
#endif
12568
12569
#ifdef WOLFSSL_ASYNC_CRYPT
12570
    if (ssl->async == NULL) {
12571
        ssl->async = (struct WOLFSSL_ASYNC*)
12572
                XMALLOC(sizeof(struct WOLFSSL_ASYNC), ssl->heap,
12573
                        DYNAMIC_TYPE_ASYNC);
12574
        if (ssl->async == NULL)
12575
            ERROR_OUT(MEMORY_E, exit_dcv);
12576
    }
12577
    args = (Dcv13Args*)ssl->async->args;
12578
12579
    ret = wolfSSL_AsyncPop(ssl, &ssl->options.asyncState);
12580
    if (ret != WC_NO_ERR_TRACE(WC_NO_PENDING_E)) {
12581
        /* Check for error */
12582
        if (ret < 0)
12583
            goto exit_dcv;
12584
    }
12585
    else
12586
#endif
12587
0
    {
12588
        /* Reset state */
12589
0
        ret = 0;
12590
0
        ssl->options.asyncState = TLS_ASYNC_BEGIN;
12591
0
        XMEMSET(args, 0, sizeof(Dcv13Args));
12592
0
        ssl->options.peerHashAlgo = sha_mac;
12593
0
        ssl->options.peerSigAlgo = anonymous_sa_algo;
12594
0
        args->idx = *inOutIdx;
12595
0
        args->begin = *inOutIdx;
12596
    #ifdef WOLFSSL_ASYNC_CRYPT
12597
        ssl->async->freeArgs = FreeDcv13Args;
12598
    #endif
12599
0
    }
12600
12601
0
    switch(ssl->options.asyncState)
12602
0
    {
12603
0
        case TLS_ASYNC_BEGIN:
12604
0
        {
12605
        #ifdef WOLFSSL_CALLBACKS
12606
            if (ssl->hsInfoOn) AddPacketName(ssl, "CertificateVerify");
12607
            if (ssl->toInfoOn) AddLateName("CertificateVerify",
12608
                                           &ssl->timeoutInfo);
12609
        #endif
12610
12611
            /* Advance state and proceed */
12612
0
            ssl->options.asyncState = TLS_ASYNC_BUILD;
12613
0
        } /* case TLS_ASYNC_BEGIN */
12614
0
        FALL_THROUGH;
12615
12616
0
        case TLS_ASYNC_BUILD:
12617
0
        {
12618
0
            int validSigAlgo;
12619
0
            const Suites* suites = WOLFSSL_SUITES(ssl);
12620
0
            word16 i;
12621
12622
            /* Signature algorithm. */
12623
0
            if ((args->idx - args->begin) + ENUM_LEN + ENUM_LEN > totalSz) {
12624
0
                ERROR_OUT(BUFFER_ERROR, exit_dcv);
12625
0
            }
12626
12627
#ifdef WOLFSSL_DUAL_ALG_CERTS
12628
            if (ssl->peerSigSpec == NULL) {
12629
                /* The peer did not respond. We didn't send CKS or they don't
12630
                 * support it. Either way, we do not need to handle dual
12631
                 * key/sig case. */
12632
                ssl->sigSpec = NULL;
12633
                ssl->sigSpecSz = 0;
12634
            }
12635
12636
            /* If no CKS extension or either native or alternative, then just
12637
             * get a normal sigalgo.  But if BOTH, then get the native and alt
12638
             * sig algos. */
12639
            if (ssl->sigSpec == NULL ||
12640
                *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_NATIVE ||
12641
                *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_ALTERNATIVE) {
12642
#endif /* WOLFSSL_DUAL_ALG_CERTS */
12643
0
                validSigAlgo = 0;
12644
0
                for (i = 0; i < suites->hashSigAlgoSz; i += 2) {
12645
0
                     if ((suites->hashSigAlgo[i + 0] == input[args->idx + 0]) &&
12646
0
                             (suites->hashSigAlgo[i + 1] == input[args->idx + 1])) {
12647
0
                         validSigAlgo = 1;
12648
0
                         break;
12649
0
                     }
12650
0
                }
12651
0
                if (!validSigAlgo) {
12652
0
                    ERROR_OUT(INVALID_PARAMETER, exit_dcv);
12653
0
                }
12654
12655
0
                ret = DecodeTls13SigAlg(input + args->idx,
12656
0
                        &ssl->options.peerHashAlgo, &ssl->options.peerSigAlgo);
12657
#ifdef WOLFSSL_DUAL_ALG_CERTS
12658
            }
12659
            else {
12660
                ret = DecodeTls13HybridSigAlg(input + args->idx,
12661
                                              &ssl->options.peerHashAlgo,
12662
                                              &ssl->options.peerSigAlgo,
12663
                                              &args->altSigAlgo);
12664
            }
12665
#endif /* WOLFSSL_DUAL_ALG_CERTS */
12666
12667
0
            if (ret < 0)
12668
0
                goto exit_dcv;
12669
0
            args->idx += OPAQUE16_LEN;
12670
12671
            /* Signature length. */
12672
0
            if ((args->idx - args->begin) + OPAQUE16_LEN > totalSz) {
12673
0
                ERROR_OUT(BUFFER_ERROR, exit_dcv);
12674
0
            }
12675
0
            ato16(input + args->idx, &args->sz);
12676
0
            args->idx += OPAQUE16_LEN;
12677
12678
            /* Signature data. */
12679
0
            if ((args->idx - args->begin) + args->sz > totalSz) {
12680
0
                ERROR_OUT(BUFFER_ERROR, exit_dcv);
12681
0
            }
12682
12683
#ifdef WOLFSSL_DUAL_ALG_CERTS
12684
            if ((ssl->sigSpec != NULL) &&
12685
                (*ssl->sigSpec != WOLFSSL_CKS_SIGSPEC_NATIVE)) {
12686
12687
                word16 sa;
12688
                if (args->altSigAlgo == 0)
12689
                    sa = ssl->options.peerSigAlgo;
12690
                else
12691
                    sa = args->altSigAlgo;
12692
12693
                switch(sa) {
12694
            #ifndef NO_RSA
12695
                case rsa_pss_sa_algo:
12696
                    ret = decodeRsaKey(ssl);
12697
                    break;
12698
            #endif
12699
            #ifdef HAVE_ECC
12700
                case ecc_dsa_sa_algo:
12701
                    ret = decodeEccKey(ssl);
12702
                    break;
12703
            #endif
12704
            #ifdef WOLFSSL_HAVE_MLDSA
12705
                case mldsa_44_sa_algo:
12706
                    ret = decodeMlDsaKey(ssl, WC_ML_DSA_44);
12707
                    break;
12708
                case mldsa_65_sa_algo:
12709
                    ret = decodeMlDsaKey(ssl, WC_ML_DSA_65);
12710
                    break;
12711
                case mldsa_87_sa_algo:
12712
                    ret = decodeMlDsaKey(ssl, WC_ML_DSA_87);
12713
                    break;
12714
            #endif
12715
            #ifdef WOLFSSL_HAVE_SLHDSA
12716
                case slhdsa_sha2_128s_sa_algo:
12717
                case slhdsa_sha2_128f_sa_algo:
12718
                case slhdsa_sha2_192s_sa_algo:
12719
                case slhdsa_sha2_192f_sa_algo:
12720
                case slhdsa_sha2_256s_sa_algo:
12721
                case slhdsa_sha2_256f_sa_algo:
12722
                case slhdsa_shake_128s_sa_algo:
12723
                case slhdsa_shake_128f_sa_algo:
12724
                case slhdsa_shake_192s_sa_algo:
12725
                case slhdsa_shake_192f_sa_algo:
12726
                case slhdsa_shake_256s_sa_algo:
12727
                case slhdsa_shake_256f_sa_algo:
12728
                    /* SLH-DSA is not supported as an alternative (dual-algorithm
12729
                     * / CKS) key. The alternative-signature verification block
12730
                     * in this function has no SLH-DSA case, so a decoded key
12731
                     * would never be verified and the handshake would always be
12732
                     * rejected at TLS_ASYNC_FINALIZE. Fail fast here instead of
12733
                     * allocating a key that can never authenticate the peer. */
12734
                    ERROR_OUT(ALGO_ID_E, exit_dcv);
12735
            #endif
12736
            #ifdef HAVE_FALCON
12737
                case falcon_level1_sa_algo:
12738
                    ret = decodeFalconKey(ssl, 1);
12739
                    break;
12740
                case falcon_level5_sa_algo:
12741
                    ret = decodeFalconKey(ssl, 5);
12742
                    break;
12743
            #endif
12744
                default:
12745
                    ERROR_OUT(PEER_KEY_ERROR, exit_dcv);
12746
                }
12747
12748
                if (ret != 0)
12749
                    ERROR_OUT(ret, exit_dcv);
12750
12751
                if (*ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_ALTERNATIVE) {
12752
                    /* Now swap in the alternative by removing the native.
12753
                     * sa contains the alternative signature type. */
12754
                #ifndef NO_RSA
12755
                    if (ssl->peerRsaKeyPresent && sa != rsa_pss_sa_algo) {
12756
                        FreeKey(ssl, DYNAMIC_TYPE_RSA,
12757
                                (void**)&ssl->peerRsaKey);
12758
                        ssl->peerRsaKeyPresent = 0;
12759
                    }
12760
                #endif
12761
                #ifdef HAVE_ECC
12762
                    else if (ssl->peerEccDsaKeyPresent &&
12763
                             sa != ecc_dsa_sa_algo) {
12764
                        FreeKey(ssl, DYNAMIC_TYPE_ECC,
12765
                                (void**)&ssl->peerEccDsaKey);
12766
                        ssl->peerEccDsaKeyPresent = 0;
12767
                    }
12768
                #endif
12769
                #ifdef WOLFSSL_HAVE_MLDSA
12770
                    else if (ssl->peerMlDsaKeyPresent &&
12771
                             sa != mldsa_44_sa_algo &&
12772
                             sa != mldsa_65_sa_algo &&
12773
                             sa != mldsa_87_sa_algo) {
12774
                        FreeKey(ssl, DYNAMIC_TYPE_MLDSA,
12775
                                (void**)&ssl->peerMlDsaKey);
12776
                        ssl->peerMlDsaKeyPresent = 0;
12777
                    }
12778
                #endif
12779
                #ifdef WOLFSSL_HAVE_SLHDSA
12780
                    else if (ssl->peerSlhDsaKeyPresent &&
12781
                             !IsSlhDsaSigAlgo(sa)) {
12782
                        FreeKey(ssl, DYNAMIC_TYPE_SLHDSA,
12783
                                (void**)&ssl->peerSlhDsaKey);
12784
                        ssl->peerSlhDsaKeyPresent = 0;
12785
                    }
12786
                #endif
12787
                #ifdef HAVE_FALCON
12788
                    else if (ssl->peerFalconKeyPresent &&
12789
                             sa != falcon_level1_sa_algo &&
12790
                             sa != falcon_level5_sa_algo) {
12791
                        FreeKey(ssl, DYNAMIC_TYPE_FALCON,
12792
                                (void**)&ssl->peerFalconKey);
12793
                        ssl->peerFalconKeyPresent = 0;
12794
                    }
12795
                #endif
12796
                    else {
12797
                        ERROR_OUT(PEER_KEY_ERROR, exit_dcv);
12798
                    }
12799
                }
12800
            }
12801
#endif /* WOLFSSL_DUAL_ALG_CERTS */
12802
12803
            /* Check for public key of required type. */
12804
            /* Assume invalid unless signature algo matches the key provided */
12805
0
            validSigAlgo = 0;
12806
0
        #ifdef HAVE_ED25519
12807
0
            if (ssl->options.peerSigAlgo == ed25519_sa_algo) {
12808
0
                WOLFSSL_MSG("Peer sent ED25519 sig");
12809
0
                validSigAlgo = (ssl->peerEd25519Key != NULL) &&
12810
0
                                                     ssl->peerEd25519KeyPresent;
12811
0
            }
12812
0
        #endif
12813
0
        #ifdef HAVE_ED448
12814
0
            if (ssl->options.peerSigAlgo == ed448_sa_algo) {
12815
0
                WOLFSSL_MSG("Peer sent ED448 sig");
12816
0
                validSigAlgo = (ssl->peerEd448Key != NULL) &&
12817
0
                                                       ssl->peerEd448KeyPresent;
12818
0
            }
12819
0
        #endif
12820
0
        #ifdef HAVE_ECC
12821
0
            if (ssl->options.peerSigAlgo == ecc_dsa_sa_algo) {
12822
0
                WOLFSSL_MSG("Peer sent ECC sig");
12823
0
                validSigAlgo = (ssl->peerEccDsaKey != NULL) &&
12824
0
                                                      ssl->peerEccDsaKeyPresent;
12825
0
            }
12826
0
        #endif
12827
0
        #if defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3)
12828
0
            if (ssl->options.peerSigAlgo == sm2_sa_algo) {
12829
0
                WOLFSSL_MSG("Peer sent SM2 sig");
12830
0
                validSigAlgo = (ssl->peerEccDsaKey != NULL) &&
12831
0
                                                      ssl->peerEccDsaKeyPresent;
12832
0
            }
12833
0
        #endif
12834
        #ifdef HAVE_FALCON
12835
            if (ssl->options.peerSigAlgo == falcon_level1_sa_algo) {
12836
                WOLFSSL_MSG("Peer sent Falcon Level 1 sig");
12837
                validSigAlgo = (ssl->peerFalconKey != NULL) &&
12838
                               ssl->peerFalconKeyPresent;
12839
            }
12840
            if (ssl->options.peerSigAlgo == falcon_level5_sa_algo) {
12841
                WOLFSSL_MSG("Peer sent Falcon Level 5 sig");
12842
                validSigAlgo = (ssl->peerFalconKey != NULL) &&
12843
                               ssl->peerFalconKeyPresent;
12844
            }
12845
        #endif
12846
        #ifdef WOLFSSL_HAVE_MLDSA
12847
            if (ssl->options.peerSigAlgo == mldsa_44_sa_algo) {
12848
                WOLFSSL_MSG("Peer sent ML-DSA Level 2 sig");
12849
                validSigAlgo = (ssl->peerMlDsaKey != NULL) &&
12850
                               ssl->peerMlDsaKeyPresent;
12851
            }
12852
            if (ssl->options.peerSigAlgo == mldsa_65_sa_algo) {
12853
                WOLFSSL_MSG("Peer sent ML-DSA Level 3 sig");
12854
                validSigAlgo = (ssl->peerMlDsaKey != NULL) &&
12855
                               ssl->peerMlDsaKeyPresent;
12856
            }
12857
            if (ssl->options.peerSigAlgo == mldsa_87_sa_algo) {
12858
                WOLFSSL_MSG("Peer sent ML-DSA Level 5 sig");
12859
                validSigAlgo = (ssl->peerMlDsaKey != NULL) &&
12860
                               ssl->peerMlDsaKeyPresent;
12861
            }
12862
        #endif
12863
        #ifdef WOLFSSL_HAVE_SLHDSA
12864
            if (IsSlhDsaSigAlgo(ssl->options.peerSigAlgo)) {
12865
                WOLFSSL_MSG("Peer sent SLH-DSA sig");
12866
                validSigAlgo = (ssl->peerSlhDsaKey != NULL) &&
12867
                               ssl->peerSlhDsaKeyPresent;
12868
            }
12869
        #endif
12870
0
        #ifndef NO_RSA
12871
0
            if (ssl->options.peerSigAlgo == rsa_sa_algo) {
12872
0
                WOLFSSL_MSG("Peer sent PKCS#1.5 algo - not valid TLS 1.3");
12873
0
                ERROR_OUT(INVALID_PARAMETER, exit_dcv);
12874
0
            }
12875
0
            if (ssl->options.peerSigAlgo == rsa_pss_sa_algo) {
12876
0
                WOLFSSL_MSG("Peer sent RSA sig");
12877
0
                validSigAlgo = (ssl->peerRsaKey != NULL) &&
12878
0
                                                         ssl->peerRsaKeyPresent;
12879
0
            }
12880
0
        #endif
12881
0
            if (!validSigAlgo) {
12882
0
                WOLFSSL_MSG("Sig algo doesn't correspond to certificate");
12883
0
                ERROR_OUT(SIG_VERIFY_E, exit_dcv);
12884
0
            }
12885
12886
0
            args->sigSz = args->sz;
12887
#ifdef WOLFSSL_DUAL_ALG_CERTS
12888
            if (ssl->sigSpec != NULL &&
12889
                *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH) {
12890
                /* In case we received two signatures, both of them are encoded
12891
                 * with their size as 16-bit integeter prior in memory. Hence,
12892
                 * we can decode both lengths here now. */
12893
                word32 tmpIdx = args->idx;
12894
                word16 tmpSz = 0;
12895
                if (args->sz < OPAQUE16_LEN) {
12896
                    ERROR_OUT(BUFFER_ERROR, exit_dcv);
12897
                }
12898
                ato16(input + tmpIdx, &tmpSz);
12899
                args->sigSz = tmpSz;
12900
12901
                tmpIdx += OPAQUE16_LEN + args->sigSz;
12902
                if (tmpIdx - args->idx + OPAQUE16_LEN > args->sz) {
12903
                    ERROR_OUT(BUFFER_ERROR, exit_dcv);
12904
                }
12905
                ato16(input + tmpIdx, &tmpSz);
12906
                args->altSignatureSz = tmpSz;
12907
12908
                if (args->sz != (args->sigSz + args->altSignatureSz +
12909
                                    OPAQUE16_LEN + OPAQUE16_LEN)) {
12910
                    ERROR_OUT(BUFFER_ERROR, exit_dcv);
12911
                }
12912
            }
12913
#endif /* WOLFSSL_DUAL_ALG_CERTS */
12914
12915
0
        #if !defined(NO_RSA) && defined(WC_RSA_PSS)
12916
            /* In case we have to verify an RSA signature, we have to store the
12917
             * signature in the 'rsaSigBuf' structure for further processing.
12918
             */
12919
0
            if (ssl->peerRsaKey != NULL && ssl->peerRsaKeyPresent != 0) {
12920
0
                word32 sigSz = args->sigSz;
12921
0
                sig = input + args->idx;
12922
            #ifdef WOLFSSL_DUAL_ALG_CERTS
12923
                /* Check if our alternative signature was RSA */
12924
                if (ssl->sigSpec != NULL &&
12925
                    *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH) {
12926
                    if (ssl->options.peerSigAlgo != rsa_pss_sa_algo) {
12927
                        /* We have to skip the first signature (length field
12928
                         * and signature itself) and the length field of the
12929
                         * alternative signature. */
12930
                        sig += OPAQUE16_LEN + OPAQUE16_LEN + args->sigSz;
12931
                        sigSz = args->altSignatureSz;
12932
                    }
12933
                    else {
12934
                        /* We have to skip the length field */
12935
                        sig += OPAQUE16_LEN;
12936
                    }
12937
                }
12938
            #endif
12939
0
                rsaSigBuf->buffer = (byte*)XMALLOC(sigSz, ssl->heap,
12940
0
                                         DYNAMIC_TYPE_SIGNATURE);
12941
0
                if (rsaSigBuf->buffer == NULL) {
12942
0
                    ERROR_OUT(MEMORY_E, exit_dcv);
12943
0
                }
12944
0
                rsaSigBuf->length = sigSz;
12945
0
                XMEMCPY(rsaSigBuf->buffer, sig, rsaSigBuf->length);
12946
0
            }
12947
0
        #endif /* !NO_RSA && WC_RSA_PSS */
12948
12949
0
            args->sigData = (byte*)XMALLOC(MAX_SIG_DATA_SZ, ssl->heap,
12950
0
                                                    DYNAMIC_TYPE_SIGNATURE);
12951
0
            if (args->sigData == NULL) {
12952
0
                ERROR_OUT(MEMORY_E, exit_dcv);
12953
0
            }
12954
12955
0
            ret = CreateSigData(ssl, args->sigData, &args->sigDataSz, 1);
12956
0
            if (ret < 0)
12957
0
                goto exit_dcv;
12958
12959
        #ifdef WOLFSSL_DUAL_ALG_CERTS
12960
            if ((ssl->sigSpec != NULL) &&
12961
                (*ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH)) {
12962
                args->altSigData = (byte*)XMALLOC(MAX_SIG_DATA_SZ, ssl->heap,
12963
                                                        DYNAMIC_TYPE_SIGNATURE);
12964
                if (args->altSigData == NULL) {
12965
                    ERROR_OUT(MEMORY_E, exit_dcv);
12966
                }
12967
                XMEMCPY(args->altSigData, args->sigData, args->sigDataSz);
12968
                args->altSigDataSz = args->sigDataSz;
12969
            }
12970
        #endif /* WOLFSSL_DUAL_ALG_CERTS */
12971
12972
0
        #ifdef HAVE_ECC
12973
0
            if ((ssl->options.peerSigAlgo == ecc_dsa_sa_algo) &&
12974
0
                (ssl->peerEccDsaKeyPresent)) {
12975
0
                ret = CreateECCEncodedSig(args->sigData,
12976
0
                    args->sigDataSz, ssl->options.peerHashAlgo);
12977
0
                if (ret < 0)
12978
0
                    goto exit_dcv;
12979
0
                args->sigDataSz = (word16)ret;
12980
0
                ret = 0;
12981
0
            }
12982
12983
        #ifdef WOLFSSL_DUAL_ALG_CERTS
12984
            if ((ssl->sigSpec != NULL) &&
12985
                (*ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH) &&
12986
                (args->altSigAlgo == ecc_dsa_sa_algo) &&
12987
                (ssl->peerEccDsaKeyPresent)) {
12988
                ret = CreateECCEncodedSig(args->altSigData,
12989
                        args->altSigDataSz, ssl->options.peerHashAlgo);
12990
                    if (ret < 0)
12991
                        goto exit_dcv;
12992
                    args->altSigDataSz = (word16)ret;
12993
                    ret = 0;
12994
            }
12995
        #endif /* WOLFSSL_DUAL_ALG_CERTS */
12996
0
        #endif /* HAVE_ECC */
12997
12998
            /* Advance state and proceed */
12999
0
            ssl->options.asyncState = TLS_ASYNC_DO;
13000
0
        } /* case TLS_ASYNC_BUILD */
13001
0
        FALL_THROUGH;
13002
13003
0
        case TLS_ASYNC_DO:
13004
0
        {
13005
0
            sig = input + args->idx;
13006
0
            (void)sig;
13007
        #ifdef WOLFSSL_DUAL_ALG_CERTS
13008
            if (ssl->sigSpec != NULL &&
13009
                *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH) {
13010
                /* As we have two signatures in the message, we stored
13011
                 * the length of each before the actual signature. This
13012
                 * is necessary, as we could have two algorithms with
13013
                 * variable length signatures. */
13014
                sig += OPAQUE16_LEN;
13015
            }
13016
        #endif
13017
0
        #ifndef NO_RSA
13018
0
            if ((ssl->options.peerSigAlgo == rsa_pss_sa_algo) &&
13019
0
                (ssl->peerRsaKey != NULL) && (ssl->peerRsaKeyPresent != 0)) {
13020
0
                WOLFSSL_MSG("Doing RSA peer cert verify");
13021
0
                ret = RsaVerify(ssl, rsaSigBuf->buffer,
13022
0
                                (word32)rsaSigBuf->length, &args->output,
13023
0
                                ssl->options.peerSigAlgo,
13024
0
                                ssl->options.peerHashAlgo, ssl->peerRsaKey,
13025
                #ifdef HAVE_PK_CALLBACKS
13026
                                &ssl->buffers.peerRsaKey
13027
                #else
13028
0
                                NULL
13029
0
                #endif
13030
0
                                );
13031
0
                if (ret >= 0) {
13032
0
                    args->sendSz = (word32)ret;
13033
0
                    ret = 0;
13034
0
                }
13035
0
            }
13036
0
        #endif /* !NO_RSA */
13037
0
        #ifdef HAVE_ECC
13038
0
            if ((ssl->options.peerSigAlgo == ecc_dsa_sa_algo) &&
13039
0
                    ssl->peerEccDsaKeyPresent) {
13040
0
                WOLFSSL_MSG("Doing ECC peer cert verify");
13041
0
                ret = EccVerify(ssl, sig, args->sigSz,
13042
0
                    args->sigData, args->sigDataSz,
13043
0
                    ssl->peerEccDsaKey,
13044
                #ifdef HAVE_PK_CALLBACKS
13045
                    &ssl->buffers.peerEccDsaKey
13046
                #else
13047
0
                    NULL
13048
0
                #endif
13049
0
                    );
13050
13051
0
                if (ret >= 0) {
13052
                    /* CLIENT/SERVER: data verified with public key from
13053
                     * certificate. */
13054
0
                    ssl->options.peerAuthGood = 1;
13055
13056
0
                    FreeKey(ssl, DYNAMIC_TYPE_ECC, (void**)&ssl->peerEccDsaKey);
13057
0
                    ssl->peerEccDsaKeyPresent = 0;
13058
0
                }
13059
0
            }
13060
0
        #endif /* HAVE_ECC */
13061
0
        #if defined(HAVE_ECC) && defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3)
13062
0
            if ((ssl->options.peerSigAlgo == sm2_sa_algo) &&
13063
0
                   ssl->peerEccDsaKeyPresent) {
13064
0
                WOLFSSL_MSG("Doing SM2/SM3 peer cert verify");
13065
0
                ret = Sm2wSm3Verify(ssl, TLS13_SM2_SIG_ID, TLS13_SM2_SIG_ID_SZ,
13066
0
                    sig, args->sigSz, args->sigData, args->sigDataSz,
13067
0
                    ssl->peerEccDsaKey, NULL);
13068
0
                if (ret >= 0) {
13069
                    /* CLIENT/SERVER: data verified with public key from
13070
                     * certificate. */
13071
0
                    ssl->options.peerAuthGood = 1;
13072
13073
0
                    FreeKey(ssl, DYNAMIC_TYPE_ECC, (void**)&ssl->peerEccDsaKey);
13074
0
                    ssl->peerEccDsaKeyPresent = 0;
13075
0
                }
13076
0
            }
13077
0
        #endif
13078
0
        #ifdef HAVE_ED25519
13079
0
            if ((ssl->options.peerSigAlgo == ed25519_sa_algo) &&
13080
0
                (ssl->peerEd25519KeyPresent)) {
13081
0
                WOLFSSL_MSG("Doing ED25519 peer cert verify");
13082
0
                ret = Ed25519Verify(ssl, sig, args->sigSz,
13083
0
                    args->sigData, args->sigDataSz,
13084
0
                    ssl->peerEd25519Key,
13085
                #ifdef HAVE_PK_CALLBACKS
13086
                    &ssl->buffers.peerEd25519Key
13087
                #else
13088
0
                    NULL
13089
0
                #endif
13090
0
                    );
13091
13092
0
                if (ret >= 0) {
13093
                    /* CLIENT/SERVER: data verified with public key from
13094
                     * certificate. */
13095
0
                    ssl->options.peerAuthGood = 1;
13096
0
                    FreeKey(ssl, DYNAMIC_TYPE_ED25519,
13097
0
                                                  (void**)&ssl->peerEd25519Key);
13098
0
                    ssl->peerEd25519KeyPresent = 0;
13099
0
                }
13100
0
            }
13101
0
        #endif
13102
0
        #ifdef HAVE_ED448
13103
0
            if ((ssl->options.peerSigAlgo == ed448_sa_algo) &&
13104
0
                (ssl->peerEd448KeyPresent)) {
13105
0
                WOLFSSL_MSG("Doing ED448 peer cert verify");
13106
0
                ret = Ed448Verify(ssl, sig, args->sigSz,
13107
0
                    args->sigData, args->sigDataSz,
13108
0
                    ssl->peerEd448Key,
13109
                #ifdef HAVE_PK_CALLBACKS
13110
                    &ssl->buffers.peerEd448Key
13111
                #else
13112
0
                    NULL
13113
0
                #endif
13114
0
                );
13115
13116
0
                if (ret >= 0) {
13117
                    /* CLIENT/SERVER: data verified with public key from
13118
                     * certificate. */
13119
0
                    ssl->options.peerAuthGood = 1;
13120
0
                    FreeKey(ssl, DYNAMIC_TYPE_ED448,
13121
0
                                                    (void**)&ssl->peerEd448Key);
13122
0
                    ssl->peerEd448KeyPresent = 0;
13123
0
                }
13124
0
            }
13125
0
        #endif
13126
        #if defined(HAVE_FALCON)
13127
            if (((ssl->options.peerSigAlgo == falcon_level1_sa_algo) ||
13128
                 (ssl->options.peerSigAlgo == falcon_level5_sa_algo)) &&
13129
                (ssl->peerFalconKeyPresent)) {
13130
                int res = 0;
13131
                WOLFSSL_MSG("Doing Falcon peer cert verify");
13132
                ret = wc_falcon_verify_msg(sig, args->sigSz,
13133
                                           args->sigData, args->sigDataSz,
13134
                                           &res, ssl->peerFalconKey);
13135
13136
                if ((ret >= 0) && (res == 1)) {
13137
                    /* CLIENT/SERVER: data verified with public key from
13138
                     * certificate. */
13139
                    ssl->options.peerAuthGood = 1;
13140
13141
                    FreeKey(ssl, DYNAMIC_TYPE_FALCON,
13142
                                                   (void**)&ssl->peerFalconKey);
13143
                    ssl->peerFalconKeyPresent = 0;
13144
                }
13145
                else if ((ret >= 0) && (res == 0)) {
13146
                    WOLFSSL_MSG("Falcon signature verification failed");
13147
                    ret = SIG_VERIFY_E;
13148
                }
13149
            }
13150
        #endif /* HAVE_FALCON */
13151
        #if defined(WOLFSSL_HAVE_MLDSA) && !defined(WOLFSSL_MLDSA_NO_VERIFY)
13152
            if (((ssl->options.peerSigAlgo == mldsa_44_sa_algo) ||
13153
                 (ssl->options.peerSigAlgo == mldsa_65_sa_algo) ||
13154
                 (ssl->options.peerSigAlgo == mldsa_87_sa_algo)) &&
13155
                (ssl->peerMlDsaKeyPresent)) {
13156
                int res = 0;
13157
                WOLFSSL_MSG("Doing ML-DSA peer cert verify");
13158
                ret = wc_MlDsaKey_VerifyCtx(ssl->peerMlDsaKey, sig, args->sigSz,
13159
                                            NULL, 0, args->sigData,
13160
                                            args->sigDataSz, &res);
13161
13162
                if ((ret >= 0) && (res == 1)) {
13163
                    /* CLIENT/SERVER: data verified with public key from
13164
                     * certificate. */
13165
                    ssl->options.peerAuthGood = 1;
13166
13167
                    FreeKey(ssl, DYNAMIC_TYPE_MLDSA,
13168
                            (void**)&ssl->peerMlDsaKey);
13169
                    ssl->peerMlDsaKeyPresent = 0;
13170
                }
13171
                else if ((ret >= 0) && (res == 0)) {
13172
                    WOLFSSL_MSG("ML-DSA signature verification failed");
13173
                    ret = SIG_VERIFY_E;
13174
                }
13175
            }
13176
        #endif /* WOLFSSL_HAVE_MLDSA */
13177
        #if defined(WOLFSSL_HAVE_SLHDSA)
13178
            if (IsSlhDsaSigAlgo(ssl->options.peerSigAlgo) &&
13179
                (ssl->peerSlhDsaKeyPresent)) {
13180
                WOLFSSL_MSG("Doing SLH-DSA peer cert verify");
13181
13182
                /* The advertised signature scheme must match the parameter set
13183
                 * of the peer's certificate key (RFC 8446 4.4.3). The key
13184
                 * params come from the certificate OID, so a mismatch means the
13185
                 * peer is over-claiming its security level; reject it. */
13186
                if ((ssl->peerSlhDsaKey->params == NULL) ||
13187
                    (SlhDsaParamToType((int)ssl->peerSlhDsaKey->params->param)
13188
                        != ssl->options.peerSigAlgo)) {
13189
                    ERROR_OUT(SIG_VERIFY_E, exit_dcv);
13190
                }
13191
13192
                /* wc_SlhDsaKey_Verify returns 0 for a valid signature. */
13193
                ret = wc_SlhDsaKey_Verify(ssl->peerSlhDsaKey, NULL, 0,
13194
                                          args->sigData, args->sigDataSz,
13195
                                          sig, args->sigSz);
13196
13197
                if (ret == 0) {
13198
                    /* CLIENT/SERVER: data verified with public key from
13199
                     * certificate. */
13200
                    ssl->options.peerAuthGood = 1;
13201
13202
                    FreeKey(ssl, DYNAMIC_TYPE_SLHDSA,
13203
                            (void**)&ssl->peerSlhDsaKey);
13204
                    ssl->peerSlhDsaKeyPresent = 0;
13205
                }
13206
                else {
13207
                    /* wc_SlhDsaKey_Verify already returns SIG_VERIFY_E on a
13208
                     * signature mismatch and propagates real errors verbatim
13209
                     * (WC_PENDING_E on the async crypto-callback path, MEMORY_E,
13210
                     * ...), so leave ret unchanged. Flattening everything to
13211
                     * SIG_VERIFY_E would break async resume and mask
13212
                     * diagnostics; the ML-DSA/Falcon blocks above likewise
13213
                     * preserve non-completion return codes. */
13214
                    WOLFSSL_MSG("SLH-DSA signature verification failed");
13215
                }
13216
            }
13217
        #endif /* WOLFSSL_HAVE_SLHDSA */
13218
13219
            /* Check for error */
13220
0
            if (ret != 0) {
13221
0
                goto exit_dcv;
13222
0
            }
13223
13224
        #ifdef WOLFSSL_DUAL_ALG_CERTS
13225
            if (ssl->sigSpec != NULL &&
13226
                *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH) {
13227
                /* Move forward to the alternative signature. */
13228
                sig += args->sigSz + OPAQUE16_LEN;
13229
13230
                /* Verify the alternative signature */
13231
            #ifndef NO_RSA
13232
                if ((args->altSigAlgo == rsa_pss_sa_algo) &&
13233
                    (ssl->peerRsaKey != NULL) &&
13234
                    (ssl->peerRsaKeyPresent != 0)) {
13235
                    WOLFSSL_MSG("Doing RSA peer cert alt verify");
13236
                    ret = RsaVerify(ssl, rsaSigBuf->buffer,
13237
                                    (word32)rsaSigBuf->length,
13238
                                    &args->output, args->altSigAlgo,
13239
                                    ssl->options.peerHashAlgo, ssl->peerRsaKey,
13240
                    #ifdef HAVE_PK_CALLBACKS
13241
                                    &ssl->buffers.peerRsaKey
13242
                    #else
13243
                                    NULL
13244
                    #endif
13245
                                    );
13246
                    if (ret >= 0) {
13247
                        args->sendSz = ret;
13248
                        ret = 0;
13249
                    }
13250
                }
13251
            #endif /* !NO_RSA */
13252
            #ifdef HAVE_ECC
13253
                if ((args->altSigAlgo == ecc_dsa_sa_algo) &&
13254
                    (ssl->peerEccDsaKeyPresent)) {
13255
                    WOLFSSL_MSG("Doing ECC peer cert alt verify");
13256
                    ret = EccVerify(ssl, sig, args->altSignatureSz,
13257
                                args->altSigData, args->altSigDataSz,
13258
                                ssl->peerEccDsaKey,
13259
                    #ifdef HAVE_PK_CALLBACKS
13260
                                &ssl->buffers.peerEccDsaKey
13261
                    #else
13262
                                NULL
13263
                    #endif
13264
                                );
13265
13266
                    if (ret >= 0) {
13267
                        /* CLIENT/SERVER: data verified with public key from
13268
                        * certificate. */
13269
                        args->altPeerAuthGood = 1;
13270
13271
                        FreeKey(ssl, DYNAMIC_TYPE_ECC,
13272
                                                (void**)&ssl->peerEccDsaKey);
13273
                        ssl->peerEccDsaKeyPresent = 0;
13274
                    }
13275
                }
13276
            #endif /* HAVE_ECC */
13277
            #if defined(HAVE_FALCON)
13278
                if (((args->altSigAlgo == falcon_level1_sa_algo) ||
13279
                     (args->altSigAlgo == falcon_level5_sa_algo)) &&
13280
                    (ssl->peerFalconKeyPresent)) {
13281
                    int res = 0;
13282
                    WOLFSSL_MSG("Doing Falcon peer cert alt verify");
13283
                    ret = wc_falcon_verify_msg(sig, args->altSignatureSz,
13284
                                        args->altSigData, args->altSigDataSz,
13285
                                        &res, ssl->peerFalconKey);
13286
13287
                    if ((ret >= 0) && (res == 1)) {
13288
                        /* CLIENT/SERVER: data verified with public key from
13289
                        * certificate. */
13290
                        args->altPeerAuthGood = 1;
13291
13292
                        FreeKey(ssl, DYNAMIC_TYPE_FALCON,
13293
                                                (void**)&ssl->peerFalconKey);
13294
                        ssl->peerFalconKeyPresent = 0;
13295
                    }
13296
                    else if ((ret >= 0) && (res == 0)) {
13297
                        WOLFSSL_MSG("Falcon signature verification failed");
13298
                        ret = SIG_VERIFY_E;
13299
                    }
13300
                }
13301
            #endif /* HAVE_FALCON */
13302
            #if defined(WOLFSSL_HAVE_MLDSA) && !defined(WOLFSSL_MLDSA_NO_VERIFY)
13303
                if (((args->altSigAlgo == mldsa_44_sa_algo) ||
13304
                     (args->altSigAlgo == mldsa_65_sa_algo) ||
13305
                     (args->altSigAlgo == mldsa_87_sa_algo)) &&
13306
                    (ssl->peerMlDsaKeyPresent)) {
13307
                    int res = 0;
13308
                    WOLFSSL_MSG("Doing ML-DSA peer cert alt verify");
13309
                    ret = wc_MlDsaKey_VerifyCtx(ssl->peerMlDsaKey, sig,
13310
                                        args->altSignatureSz, NULL, 0,
13311
                                        args->altSigData,
13312
                                        args->altSigDataSz, &res);
13313
13314
                    if ((ret >= 0) && (res == 1)) {
13315
                        /* CLIENT/SERVER: data verified with public key from
13316
                        * certificate. */
13317
                        args->altPeerAuthGood = 1;
13318
13319
                        FreeKey(ssl, DYNAMIC_TYPE_MLDSA,
13320
                                            (void**)&ssl->peerMlDsaKey);
13321
                        ssl->peerMlDsaKeyPresent = 0;
13322
                    }
13323
                    else if ((ret >= 0) && (res == 0)) {
13324
                        WOLFSSL_MSG("ML-DSA signature verification failed");
13325
                        ret = SIG_VERIFY_E;
13326
                    }
13327
                }
13328
            #endif /* WOLFSSL_HAVE_MLDSA */
13329
13330
                /* Check for error */
13331
                if (ret != 0) {
13332
                    goto exit_dcv;
13333
                }
13334
            }
13335
        #endif /* WOLFSSL_DUAL_ALG_CERTS */
13336
13337
            /* Advance state and proceed */
13338
0
            ssl->options.asyncState = TLS_ASYNC_VERIFY;
13339
0
        } /* case TLS_ASYNC_DO */
13340
0
        FALL_THROUGH;
13341
13342
0
        case TLS_ASYNC_VERIFY:
13343
0
        {
13344
0
        #if !defined(NO_RSA) && defined(WC_RSA_PSS)
13345
0
            if (ssl->peerRsaKey != NULL && ssl->peerRsaKeyPresent != 0) {
13346
0
                int sigAlgo = ssl->options.peerSigAlgo;
13347
            #ifdef WOLFSSL_DUAL_ALG_CERTS
13348
                /* Check if our alternative signature was RSA */
13349
                if (ssl->sigSpec != NULL &&
13350
                    *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH &&
13351
                    ssl->options.peerSigAlgo != rsa_pss_sa_algo) {
13352
                    sigAlgo = args->altSigAlgo;
13353
                }
13354
            #endif
13355
0
                ret = CheckRSASignature(ssl, sigAlgo,
13356
0
                        ssl->options.peerHashAlgo, args->output, args->sendSz);
13357
0
                if (ret != 0)
13358
0
                    goto exit_dcv;
13359
13360
                /* CLIENT/SERVER: data verified with public key from
13361
                 * certificate. */
13362
0
                ssl->peerRsaKeyPresent = 0;
13363
0
                FreeKey(ssl, DYNAMIC_TYPE_RSA, (void**)&ssl->peerRsaKey);
13364
            #ifdef WOLFSSL_DUAL_ALG_CERTS
13365
                /* Check if our alternative signature was RSA */
13366
                if (ssl->sigSpec != NULL &&
13367
                    *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH &&
13368
                    ssl->options.peerSigAlgo != rsa_pss_sa_algo) {
13369
                    args->altPeerAuthGood = 1;
13370
                }
13371
                else
13372
            #endif
13373
0
                    ssl->options.peerAuthGood = 1;
13374
0
            }
13375
0
        #endif /* !NO_RSA && WC_RSA_PSS */
13376
13377
            /* Advance state and proceed */
13378
0
            ssl->options.asyncState = TLS_ASYNC_FINALIZE;
13379
0
        } /* case TLS_ASYNC_VERIFY */
13380
0
        FALL_THROUGH;
13381
13382
0
        case TLS_ASYNC_FINALIZE:
13383
0
        {
13384
#ifdef WOLFSSL_DUAL_ALG_CERTS
13385
            if (ssl->options.peerAuthGood &&
13386
                ssl->sigSpec != NULL &&
13387
                *ssl->sigSpec == WOLFSSL_CKS_SIGSPEC_BOTH) {
13388
                ssl->options.peerAuthGood = args->altPeerAuthGood;
13389
            }
13390
#endif /* WOLFSSL_DUAL_ALG_CERTS */
13391
0
            ssl->options.havePeerVerify = 1;
13392
13393
            /* Set final index */
13394
0
            args->idx += args->sz;
13395
0
            *inOutIdx = args->idx;
13396
13397
            /* Advance state and proceed */
13398
0
            ssl->options.asyncState = TLS_ASYNC_END;
13399
13400
0
        #if !defined(NO_WOLFSSL_CLIENT)
13401
0
            if (ssl->options.side == WOLFSSL_CLIENT_END)
13402
0
                ssl->options.serverState = SERVER_CERT_VERIFY_COMPLETE;
13403
0
        #endif
13404
0
        } /* case TLS_ASYNC_FINALIZE */
13405
0
        FALL_THROUGH;
13406
13407
0
        case TLS_ASYNC_END:
13408
0
        {
13409
0
            break;
13410
0
        }
13411
13412
0
        default:
13413
0
            ret = INPUT_CASE_ERROR;
13414
0
    } /* switch(ssl->options.asyncState) */
13415
13416
0
exit_dcv:
13417
13418
0
    WOLFSSL_LEAVE("DoTls13CertificateVerify", ret);
13419
0
    WOLFSSL_END(WC_FUNC_CERTIFICATE_VERIFY_DO);
13420
13421
#ifdef WOLFSSL_ASYNC_CRYPT
13422
    /* Handle async operation */
13423
    if (ret == WC_NO_ERR_TRACE(WC_PENDING_E)) {
13424
        /* Mark message as not received so it can process again */
13425
        ssl->msgsReceived.got_certificate_verify = 0;
13426
13427
        return ret;
13428
    }
13429
    else
13430
#endif /* WOLFSSL_ASYNC_CRYPT */
13431
0
    if (ret != 0) {
13432
0
        WOLFSSL_ERROR_VERBOSE(ret);
13433
13434
0
        if (ret != WC_NO_ERR_TRACE(INVALID_PARAMETER)) {
13435
0
            SendAlert(ssl, alert_fatal, decrypt_error);
13436
0
        }
13437
0
    }
13438
13439
    /* Final cleanup */
13440
0
    FreeDcv13Args(ssl, args);
13441
0
    FreeKeyExchange(ssl);
13442
0
#ifdef WOLFSSL_ASYNC_IO
13443
    /* Cleanup async */
13444
0
    FreeAsyncCtx(ssl, 0);
13445
0
#endif
13446
#ifdef WOLFSSL_ASYNC_CRYPT
13447
    /* Replays skip the sanity check that re-sets got_certificate_verify;
13448
     * restore on completion or Finished reports out-of-order. */
13449
    if (ret == 0 && ssl->msgsReceived.got_certificate_verify == 0) {
13450
        ssl->msgsReceived.got_certificate_verify = 1;
13451
    }
13452
#endif
13453
13454
0
    return ret;
13455
0
}
13456
#endif /* !NO_RSA || HAVE_ECC || HAVE_ED25519 || HAVE_ED448 ||
13457
        * HAVE_FALCON || WOLFSSL_HAVE_MLDSA || WOLFSSL_HAVE_SLHDSA */
13458
#endif /* !NO_CERTS */
13459
13460
#ifdef WOLFSSL_POST_HANDSHAKE_AUTH
13461
/* Message is being processed after the enclosing handshake completed. Whatever
13462
 * resumption, PSK or deferred (post-handshake) verification excused during that
13463
 * handshake, a later post-handshake exchange has to stand on its own. */
13464
#define TLS13_AFTER_HANDSHAKE(ssl)  ((ssl)->options.handShakeDone)
13465
#else
13466
0
#define TLS13_AFTER_HANDSHAKE(ssl)  0
13467
#endif
13468
13469
/* Parse and handle a TLS v1.3 Finished message.
13470
 *
13471
 * ssl       The SSL/TLS object.
13472
 * input     The message buffer.
13473
 * inOutIdx  On entry, the index into the message buffer of Finished.
13474
 *           On exit, the index of byte after the Finished message and padding.
13475
 * size      Length of message data.
13476
 * totalSz   Length of remaining data in the message buffer.
13477
 * sniff     Indicates whether we are sniffing packets.
13478
 * returns 0 on success and otherwise failure.
13479
 */
13480
int DoTls13Finished(WOLFSSL* ssl, const byte* input, word32* inOutIdx,
13481
                           word32 size, word32 totalSz, int sniff)
13482
0
{
13483
0
    int    ret;
13484
0
    word32 finishedSz = 0;
13485
0
    byte*  secret;
13486
0
    byte   mac[WC_MAX_DIGEST_SIZE];
13487
13488
0
    WOLFSSL_START(WC_FUNC_FINISHED_DO);
13489
0
    WOLFSSL_ENTER("DoTls13Finished");
13490
13491
0
#if !defined(NO_CERTS) && !defined(WOLFSSL_NO_CLIENT_AUTH)
13492
    /* verify the client sent certificate if required */
13493
0
    if (ssl->options.side == WOLFSSL_SERVER_END &&
13494
0
            (!ssl->options.resuming || TLS13_AFTER_HANDSHAKE(ssl)) &&
13495
0
            (ssl->options.mutualAuth || ssl->options.failNoCert)) {
13496
#ifdef OPENSSL_COMPATIBLE_DEFAULTS
13497
        if (ssl->options.isPSK && !TLS13_AFTER_HANDSHAKE(ssl)) {
13498
            WOLFSSL_MSG("TLS v1.3 client used PSK but cert required. Allowing "
13499
                        "for OpenSSL compatibility");
13500
        }
13501
        else
13502
#endif
13503
0
        if (
13504
        #ifdef WOLFSSL_POST_HANDSHAKE_AUTH
13505
            /* Exempt only the enclosing handshake; a post-handshake exchange
13506
             * still requires a peer certificate and a valid
13507
             * CertificateVerify. */
13508
            (!ssl->options.verifyPostHandshake || TLS13_AFTER_HANDSHAKE(ssl)) &&
13509
        #endif
13510
0
            (!ssl->options.havePeerCert || !ssl->options.havePeerVerify)) {
13511
0
            ret = NO_PEER_CERT; /* NO_PEER_VERIFY */
13512
0
            WOLFSSL_MSG("TLS v1.3 client did not present peer cert");
13513
0
            DoCertFatalAlert(ssl, ret);
13514
0
            goto cleanup;
13515
0
        }
13516
0
    }
13517
0
#endif
13518
13519
#if !defined(NO_CERTS) && !defined(NO_PSK) && \
13520
    defined(WOLFSSL_CERT_WITH_EXTERN_PSK)
13521
    /* Verify the server sent a certificate if requested */
13522
    if (ssl->options.side == WOLFSSL_CLIENT_END && ssl->options.pskNegotiated &&
13523
            ssl->options.failNoCert) {
13524
        if ((TLSX_Find(ssl->extensions, TLSX_CERT_WITH_EXTERN_PSK) != NULL) &&
13525
                (!ssl->options.havePeerCert || !ssl->options.havePeerVerify)) {
13526
            ret = NO_PEER_CERT;
13527
            WOLFSSL_MSG("TLS v1.3 server did not present peer cert");
13528
            DoCertFatalAlert(ssl, ret);
13529
            goto cleanup;
13530
        }
13531
    }
13532
#endif
13533
13534
    /* check against totalSz */
13535
0
    if (*inOutIdx + size > totalSz) {
13536
0
        ret = BUFFER_E;
13537
0
        goto cleanup;
13538
0
    }
13539
13540
#if defined(WOLFSSL_RENESAS_TSIP_TLS)
13541
    ret = tsip_Tls13HandleFinished(ssl, input, inOutIdx, size, totalSz);
13542
    if (ret == 0) {
13543
        ssl->options.serverState = SERVER_FINISHED_COMPLETE;
13544
        goto cleanup;
13545
    }
13546
    if (ret == WC_NO_ERR_TRACE(VERIFY_FINISHED_ERROR)) {
13547
        SendAlert(ssl, alert_fatal, decrypt_error);
13548
        goto cleanup;
13549
    }
13550
    if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) {
13551
        /* other errors */
13552
        goto cleanup;
13553
    }
13554
    ret = 0;
13555
#endif /* WOLFSSL_RENESAS_TSIP_TLS */
13556
13557
0
    if (ssl->options.handShakeDone) {
13558
0
        ret = DeriveFinishedSecret(ssl, ssl->clientSecret,
13559
0
                                   ssl->keys.client_write_MAC_secret,
13560
0
                                   WOLFSSL_CLIENT_END);
13561
0
        if (ret != 0)
13562
0
            goto cleanup;
13563
13564
0
        secret = ssl->keys.client_write_MAC_secret;
13565
0
    }
13566
0
    else if (ssl->options.side == WOLFSSL_CLIENT_END) {
13567
        /* All the handshake messages have been received to calculate
13568
         * client and server finished keys.
13569
         */
13570
0
        ret = DeriveFinishedSecret(ssl, ssl->clientSecret,
13571
0
                                   ssl->keys.client_write_MAC_secret,
13572
0
                                   WOLFSSL_CLIENT_END);
13573
0
        if (ret != 0)
13574
0
            goto cleanup;
13575
13576
0
        ret = DeriveFinishedSecret(ssl, ssl->serverSecret,
13577
0
                                   ssl->keys.server_write_MAC_secret,
13578
0
                                   WOLFSSL_SERVER_END);
13579
0
        if (ret != 0)
13580
0
            goto cleanup;
13581
13582
0
        secret = ssl->keys.server_write_MAC_secret;
13583
0
    }
13584
0
    else {
13585
0
        secret = ssl->keys.client_write_MAC_secret;
13586
0
    }
13587
13588
0
    if (sniff == NO_SNIFF) {
13589
13590
0
        ret = BuildTls13HandshakeHmac(ssl, secret, mac, &finishedSz);
13591
0
    #ifdef WOLFSSL_HAVE_TLS_UNIQUE
13592
0
        if (finishedSz > TLS_FINISHED_SZ_MAX) {
13593
0
            ret = BUFFER_ERROR;
13594
0
            goto cleanup;
13595
0
        }
13596
0
        if (ssl->options.side == WOLFSSL_CLIENT_END) {
13597
0
            XMEMCPY(ssl->serverFinished, mac, finishedSz);
13598
0
            ssl->serverFinished_len = (byte)finishedSz;
13599
0
        }
13600
0
        else {
13601
0
            XMEMCPY(ssl->clientFinished, mac, finishedSz);
13602
0
            ssl->clientFinished_len = (byte)finishedSz;
13603
0
        }
13604
0
    #endif /* WOLFSSL_HAVE_TLS_UNIQUE */
13605
0
        if (ret != 0)
13606
0
            goto cleanup;
13607
0
        if (size != finishedSz) {
13608
0
            ret = BUFFER_ERROR;
13609
0
            goto cleanup;
13610
0
        }
13611
0
    }
13612
13613
#ifdef WOLFSSL_CALLBACKS
13614
    if (ssl->hsInfoOn) AddPacketName(ssl, "Finished");
13615
    if (ssl->toInfoOn) AddLateName("Finished", &ssl->timeoutInfo);
13616
#endif
13617
13618
0
    if (sniff == NO_SNIFF) {
13619
        /* Actually check verify data. */
13620
0
        if (size > WC_MAX_DIGEST_SIZE ||
13621
0
                ConstantCompare(input + *inOutIdx, mac, size) != 0){
13622
0
            WOLFSSL_MSG("Verify finished error on hashes");
13623
0
            SendAlert(ssl, alert_fatal, decrypt_error);
13624
0
            WOLFSSL_ERROR_VERBOSE(VERIFY_FINISHED_ERROR);
13625
0
            ret = VERIFY_FINISHED_ERROR;
13626
0
            goto cleanup;
13627
0
        }
13628
0
    }
13629
13630
0
    *inOutIdx += size;
13631
13632
0
#ifndef NO_WOLFSSL_SERVER
13633
0
    if (ssl->options.side == WOLFSSL_SERVER_END &&
13634
0
                                                  !ssl->options.handShakeDone) {
13635
#ifdef WOLFSSL_EARLY_DATA
13636
        if (ssl->earlyData != no_early_data) {
13637
            if ((ret = DeriveTls13Keys(ssl, no_key, DECRYPT_SIDE_ONLY, 1)) != 0)
13638
                goto cleanup;
13639
        }
13640
#endif
13641
        /* Setup keys for application data messages from client. */
13642
0
        if ((ret = SetKeysSide(ssl, DECRYPT_SIDE_ONLY)) != 0)
13643
0
            goto cleanup;
13644
0
    }
13645
0
#endif
13646
13647
0
#ifndef NO_WOLFSSL_CLIENT
13648
0
    if (ssl->options.side == WOLFSSL_CLIENT_END)
13649
0
        ssl->options.serverState = SERVER_FINISHED_COMPLETE;
13650
0
#endif
13651
0
#ifndef NO_WOLFSSL_SERVER
13652
0
    if (ssl->options.side == WOLFSSL_SERVER_END) {
13653
0
        ssl->options.clientState = CLIENT_FINISHED_COMPLETE;
13654
0
        ssl->options.handShakeState = HANDSHAKE_DONE;
13655
0
        ssl->options.handShakeDone  = 1;
13656
0
    }
13657
0
#endif
13658
13659
#if defined(WOLFSSL_DTLS13) && defined(WOLFSSL_EARLY_DATA)
13660
    if (ssl->options.dtls && ssl->earlyData > early_data_ext) {
13661
        /* DTLSv1.3 has no EndOfearlydata messages. We stop processing EarlyData
13662
           as soon we receive the client's finished message */
13663
        ssl->earlyData = done_early_data;
13664
    }
13665
#endif /* WOLFSSL_DTLS13 && WOLFSSL_EARLY_DATA */
13666
#if defined(WOLFSSL_QUIC) && defined(WOLFSSL_EARLY_DATA)
13667
    if (WOLFSSL_IS_QUIC(ssl) && ssl->earlyData > early_data_ext) {
13668
        /* QUIC has no EndOfEarlyData messages. We stop processing EarlyData
13669
           as soon we receive the client's finished message */
13670
        ssl->earlyData = done_early_data;
13671
    }
13672
#endif /* WOLFSSL_QUIC && WOLFSSL_EARLY_DATA */
13673
13674
0
    ret = 0;
13675
0
cleanup:
13676
0
    ForceZero(mac, sizeof(mac));
13677
0
    WOLFSSL_LEAVE("DoTls13Finished", ret);
13678
0
    WOLFSSL_END(WC_FUNC_FINISHED_DO);
13679
13680
0
    return ret;
13681
0
}
13682
13683
#if !defined(NO_WOLFSSL_CLIENT) || !defined(NO_WOLFSSL_SERVER)
13684
/* Send the TLS v1.3 Finished message.
13685
 *
13686
 * ssl  The SSL/TLS object.
13687
 * returns 0 on success, otherwise failure.
13688
 */
13689
static int SendTls13Finished(WOLFSSL* ssl)
13690
{
13691
    byte  finishedSz = ssl->specs.hash_size;
13692
    byte* input;
13693
    byte* output;
13694
    int   ret = 0; /* the resume goto can skip every build-phase assign */
13695
    int   headerSz = HANDSHAKE_HEADER_SZ;
13696
    int   outputSz;
13697
    byte* secret;
13698
13699
#ifdef WOLFSSL_DTLS13
13700
    int dtlsRet = 0, isDtls = 0;
13701
#endif /* WOLFSSL_DTLS13 */
13702
13703
    WOLFSSL_START(WC_FUNC_FINISHED_SEND);
13704
    WOLFSSL_ENTER("SendTls13Finished");
13705
13706
#ifdef WOLFSSL_DTLS13
13707
    if (ssl->options.dtls) {
13708
        headerSz = DTLS_HANDSHAKE_HEADER_SZ;
13709
        /* using isDtls instead of ssl->options.dtls will abide clang static
13710
           analyzer on using an uninitialized value */
13711
        isDtls = 1;
13712
    }
13713
#endif /* WOLFSSL_DTLS13 */
13714
13715
    /* Post-send key-schedule resume: the Finished record is already
13716
     * queued, so skip the build phase (re-running would queue it twice). */
13717
    if (ssl->kdfDeriveStep > 0)
13718
        goto tls13_send_finished_derives;
13719
13720
    ssl->options.buildingMsg = 1;
13721
13722
    outputSz = WC_MAX_DIGEST_SIZE + headerSz + MAX_MSG_EXTRA;
13723
#ifdef WOLFSSL_DTLS13
13724
    /* MAX_MSG_EXTRA reserves RECORD_HEADER_SZ, which is the size of the DTLS
13725
     * 1.3 unified header without the CID, so only the CID is missing. */
13726
    if (isDtls)
13727
        outputSz += DtlsGetCidTxSize(ssl);
13728
#endif /* WOLFSSL_DTLS13 */
13729
    /* Check buffers are big enough and grow if needed. */
13730
    if ((ret = CheckAvailableSize(ssl, outputSz)) != 0)
13731
        return ret;
13732
13733
    /* get output buffer */
13734
    output = GetOutputBuffer(ssl);
13735
    input = output + RECORD_HEADER_SZ;
13736
13737
#ifdef WOLFSSL_DTLS13
13738
    if (isDtls)
13739
        input = output + Dtls13GetRlHeaderLength(ssl, 1);
13740
#endif /* WOLFSSL_DTLS13 */
13741
13742
    AddTls13HandShakeHeader(input, (word32)finishedSz, 0, (word32)finishedSz,
13743
            finished, ssl);
13744
13745
#ifdef WOLFSSL_ASYNC_CRYPT
13746
    /* A suspended build already wrote the verify data and hashed it;
13747
     * recomputing would hash the body twice. */
13748
    if (ssl->options.buildArgs13Set)
13749
        goto tls13_send_finished_encrypt;
13750
#endif
13751
13752
#if defined(WOLFSSL_RENESAS_TSIP_TLS)
13753
    if (ssl->options.side == WOLFSSL_CLIENT_END) {
13754
        ret = tsip_Tls13SendFinished(ssl, output, outputSz, input, 1);
13755
        if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) {
13756
            return ret;
13757
        }
13758
        ret = 0;
13759
    }
13760
#endif /* WOLFSSL_RENESAS_TSIP_TLS */
13761
13762
    /* make finished hashes */
13763
    if (ssl->options.handShakeDone) {
13764
        ret = DeriveFinishedSecret(ssl, ssl->clientSecret,
13765
                                   ssl->keys.client_write_MAC_secret,
13766
                                   WOLFSSL_CLIENT_END);
13767
        if (ret != 0)
13768
            return ret;
13769
13770
        secret = ssl->keys.client_write_MAC_secret;
13771
    }
13772
    else if (ssl->options.side == WOLFSSL_CLIENT_END)
13773
        secret = ssl->keys.client_write_MAC_secret;
13774
    else {
13775
        /* All the handshake messages have been done to calculate client and
13776
         * server finished keys.
13777
         */
13778
        ret = DeriveFinishedSecret(ssl, ssl->clientSecret,
13779
                                   ssl->keys.client_write_MAC_secret,
13780
                                   WOLFSSL_CLIENT_END);
13781
        if (ret != 0)
13782
            return ret;
13783
13784
        ret = DeriveFinishedSecret(ssl, ssl->serverSecret,
13785
                                   ssl->keys.server_write_MAC_secret,
13786
                                   WOLFSSL_SERVER_END);
13787
        if (ret != 0)
13788
            return ret;
13789
13790
        secret = ssl->keys.server_write_MAC_secret;
13791
    }
13792
    ret = BuildTls13HandshakeHmac(ssl, secret, &input[headerSz], NULL);
13793
    if (ret != 0)
13794
        return ret;
13795
    #ifdef WOLFSSL_HAVE_TLS_UNIQUE
13796
        if (ssl->options.side == WOLFSSL_CLIENT_END) {
13797
            XMEMCPY(ssl->clientFinished, &input[headerSz], finishedSz);
13798
            ssl->clientFinished_len = finishedSz;
13799
        }
13800
        else {
13801
            XMEMCPY(ssl->serverFinished, &input[headerSz], finishedSz);
13802
            ssl->serverFinished_len = finishedSz;
13803
        }
13804
    #endif /* WOLFSSL_HAVE_TLS_UNIQUE */
13805
13806
#ifdef WOLFSSL_ASYNC_CRYPT
13807
tls13_send_finished_encrypt:
13808
#endif
13809
13810
#ifdef WOLFSSL_DTLS13
13811
    if (isDtls) {
13812
        dtlsRet = Dtls13HandshakeSend(ssl, output, (word16)outputSz,
13813
            (word16)(Dtls13GetRlHeaderLength(ssl, 1) + headerSz + finishedSz), finished,
13814
            1);
13815
        if (dtlsRet != 0 && dtlsRet != WC_NO_ERR_TRACE(WANT_WRITE))
13816
            return dtlsRet;
13817
13818
    } else
13819
#endif /* WOLFSSL_DTLS13 */
13820
    {
13821
        /* This message is always encrypted. */
13822
        int sendSz = BuildTls13Message(ssl, output, outputSz, input,
13823
                                   headerSz + finishedSz, handshake, 1, 0,
13824
                                   TLS13_HS_ASYNC_OKAY);
13825
        if (sendSz < 0) {
13826
        #ifdef WOLFSSL_ASYNC_CRYPT
13827
            /* Propagate a pending record encryption rather than reporting it
13828
             * as a build failure: the retry resumes the record. */
13829
            if (sendSz == WC_NO_ERR_TRACE(WC_PENDING_E))
13830
                return sendSz;
13831
        #endif
13832
            WOLFSSL_ERROR_VERBOSE(BUILD_MSG_ERROR);
13833
            return BUILD_MSG_ERROR;
13834
        }
13835
13836
        #if defined(WOLFSSL_CALLBACKS) || defined(OPENSSL_EXTRA)
13837
            if (ssl->hsInfoOn) AddPacketName(ssl, "Finished");
13838
            if (ssl->toInfoOn) {
13839
                ret = AddPacketInfo(ssl, "Finished", handshake, output, sendSz,
13840
                              WRITE_PROTO, 0, ssl->heap);
13841
                if (ret != 0)
13842
                    return ret;
13843
            }
13844
        #endif
13845
13846
        ssl->buffers.outputBuffer.length += (word32)sendSz;
13847
        ssl->options.buildingMsg = 0;
13848
    }
13849
13850
    /* Build phase complete; steps below are individually resumable. */
13851
    ssl->kdfDeriveStep = TLS13_SEND_KDF_FIN_ENTERED;
13852
tls13_send_finished_derives:
13853
13854
    if (ssl->options.side == WOLFSSL_SERVER_END) {
13855
#ifdef WOLFSSL_EARLY_DATA
13856
        byte storeTrafficDecKeys = ssl->earlyData == no_early_data;
13857
#endif
13858
        /* Can send application data now. */
13859
        if (ssl->kdfDeriveStep <= TLS13_SEND_KDF_FIN_ENTERED) {
13860
            ret = DeriveMasterSecret(ssl);
13861
            if (ret != 0) {
13862
                if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
13863
                    ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
13864
                return ret;
13865
            }
13866
            ssl->kdfDeriveStep = TLS13_SEND_KDF_FIN_MASTER_SECRET;
13867
        }
13868
        /* Last use of preMasterSecret - zeroize as soon as possible. */
13869
        ForceZero(ssl->arrays->preMasterSecret, ssl->arrays->preMasterSz);
13870
#ifdef WOLFSSL_EARLY_DATA
13871
13872
#ifdef WOLFSSL_DTLS13
13873
        /* DTLS13 dynamically change keys and it needs all
13874
           the keys in ssl->keys to save the keying material */
13875
        if (isDtls)
13876
            storeTrafficDecKeys = 1;
13877
#endif /* WOLFSSL_DTLS13 */
13878
13879
        if (ssl->kdfDeriveStep <= TLS13_SEND_KDF_FIN_MASTER_SECRET) {
13880
            ret = DeriveTls13Keys(ssl, traffic_key, ENCRYPT_SIDE_ONLY, 1);
13881
            if (ret != 0) {
13882
                if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
13883
                    ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
13884
                return ret;
13885
            }
13886
            ssl->kdfDeriveStep = TLS13_SEND_KDF_FIN_ENC_TRAFFIC_KEYS;
13887
        }
13888
        if (ssl->kdfDeriveStep <= TLS13_SEND_KDF_FIN_ENC_TRAFFIC_KEYS) {
13889
            ret = DeriveTls13Keys(ssl, traffic_key, DECRYPT_SIDE_ONLY,
13890
                                  storeTrafficDecKeys);
13891
            if (ret != 0) {
13892
                if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
13893
                    ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
13894
                return ret;
13895
            }
13896
            ssl->kdfDeriveStep = TLS13_SEND_KDF_FIN_TRAFFIC_KEYS;
13897
        }
13898
#else
13899
        if (ssl->kdfDeriveStep <= TLS13_SEND_KDF_FIN_ENC_TRAFFIC_KEYS) {
13900
            ret = DeriveTls13Keys(ssl, traffic_key, ENCRYPT_AND_DECRYPT_SIDE,
13901
                                  1);
13902
            if (ret != 0) {
13903
                if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
13904
                    ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
13905
                return ret;
13906
            }
13907
            ssl->kdfDeriveStep = TLS13_SEND_KDF_FIN_TRAFFIC_KEYS;
13908
        }
13909
#endif
13910
        if (ssl->kdfDeriveStep <= TLS13_SEND_KDF_FIN_TRAFFIC_KEYS) {
13911
            ret = SetKeysSide(ssl, ENCRYPT_SIDE_ONLY);
13912
            if (ret != 0) {
13913
                if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
13914
                    ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
13915
                return ret;
13916
            }
13917
            ssl->kdfDeriveStep = TLS13_SEND_KDF_FIN_ENC_KEYS_SET;
13918
        }
13919
13920
#ifdef WOLFSSL_DTLS13
13921
        if (isDtls) {
13922
            w64wrapper epochTraffic0;
13923
            epochTraffic0 = w64From32(0, DTLS13_EPOCH_TRAFFIC0);
13924
            ssl->dtls13Epoch = epochTraffic0;
13925
            ssl->dtls13PeerEpoch = epochTraffic0;
13926
13927
            if (ssl->kdfDeriveStep <= TLS13_SEND_KDF_FIN_ENC_KEYS_SET) {
13928
                ret = Dtls13SetEpochKeys(ssl, epochTraffic0,
13929
                                         ENCRYPT_AND_DECRYPT_SIDE);
13930
                if (ret != 0) {
13931
                    if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
13932
                        ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
13933
                    return ret;
13934
                }
13935
                ssl->kdfDeriveStep = TLS13_SEND_KDF_FIN_DTLS_TRAFFIC_EPOCH;
13936
            }
13937
        }
13938
#endif /* WOLFSSL_DTLS13 */
13939
13940
    }
13941
13942
    if (ssl->options.side == WOLFSSL_CLIENT_END &&
13943
                                                  !ssl->options.handShakeDone) {
13944
#ifdef WOLFSSL_EARLY_DATA
13945
        if (ssl->earlyData != no_early_data) {
13946
            if (ssl->kdfDeriveStep <= TLS13_SEND_KDF_FIN_DTLS_TRAFFIC_EPOCH) {
13947
                ret = DeriveTls13Keys(ssl, no_key, ENCRYPT_SIDE_ONLY, 1);
13948
                if (ret != 0) {
13949
                    if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
13950
                        ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
13951
                    return ret;
13952
                }
13953
                ssl->kdfDeriveStep = TLS13_SEND_KDF_FIN_EARLY_ENC_KEYS;
13954
            }
13955
        }
13956
#endif
13957
        /* Setup keys for application data messages. */
13958
        if (ssl->kdfDeriveStep <= TLS13_SEND_KDF_FIN_EARLY_ENC_KEYS) {
13959
            ret = SetKeysSide(ssl, ENCRYPT_SIDE_ONLY);
13960
            if (ret != 0) {
13961
                if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
13962
                    ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
13963
                return ret;
13964
            }
13965
            ssl->kdfDeriveStep = TLS13_SEND_KDF_FIN_EARLY_KEYS_SET;
13966
        }
13967
13968
#if defined(HAVE_SESSION_TICKET)
13969
        if (ssl->kdfDeriveStep <= TLS13_SEND_KDF_FIN_EARLY_KEYS_SET) {
13970
            ret = DeriveResumptionSecret(ssl, ssl->session->masterSecret);
13971
            if (ret != 0) {
13972
                if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
13973
                    ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
13974
                return ret;
13975
            }
13976
            ssl->kdfDeriveStep = TLS13_SEND_KDF_FIN_RESUMPTION_SECRET;
13977
        }
13978
#endif
13979
13980
#ifdef WOLFSSL_DTLS13
13981
        if (isDtls) {
13982
            w64wrapper epochTraffic0;
13983
            epochTraffic0 = w64From32(0, DTLS13_EPOCH_TRAFFIC0);
13984
            ssl->dtls13Epoch = epochTraffic0;
13985
            ssl->dtls13PeerEpoch = epochTraffic0;
13986
13987
            /* Step-guarded like every other derive in this function, so a
13988
             * pend resumes here and a real error clears the resume state. */
13989
            if (ssl->kdfDeriveStep <= TLS13_SEND_KDF_FIN_RESUMPTION_SECRET) {
13990
                ret = Dtls13SetEpochKeys(
13991
                    ssl, epochTraffic0, ENCRYPT_AND_DECRYPT_SIDE);
13992
                if (ret != 0) {
13993
                    if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
13994
                        ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
13995
                    return ret;
13996
                }
13997
                ssl->kdfDeriveStep = TLS13_SEND_KDF_FIN_DTLS_EPOCH_SET;
13998
            }
13999
        }
14000
#endif /* WOLFSSL_DTLS13 */
14001
    }
14002
14003
    ssl->kdfDeriveStep = TLS13_SEND_KDF_NONE;
14004
14005
#ifndef NO_WOLFSSL_CLIENT
14006
    if (ssl->options.side == WOLFSSL_CLIENT_END) {
14007
        ssl->options.clientState = CLIENT_FINISHED_COMPLETE;
14008
        ssl->options.handShakeState = HANDSHAKE_DONE;
14009
        ssl->options.handShakeDone  = 1;
14010
    }
14011
#endif
14012
#ifndef NO_WOLFSSL_SERVER
14013
    if (ssl->options.side == WOLFSSL_SERVER_END) {
14014
        ssl->options.serverState = SERVER_FINISHED_COMPLETE;
14015
    }
14016
#endif
14017
14018
#ifdef WOLFSSL_DTLS13
14019
    if (isDtls) {
14020
        WOLFSSL_LEAVE("SendTls13Finished", ret);
14021
        WOLFSSL_END(WC_FUNC_FINISHED_SEND);
14022
14023
        return dtlsRet;
14024
    }
14025
#endif /* WOLFSSL_DTLS13 */
14026
14027
    if ((ret = SendBuffered(ssl)) != 0)
14028
        return ret;
14029
14030
    WOLFSSL_LEAVE("SendTls13Finished", ret);
14031
    WOLFSSL_END(WC_FUNC_FINISHED_SEND);
14032
14033
    return ret;
14034
}
14035
#endif /* !NO_WOLFSSL_CLIENT || !NO_WOLFSSL_SERVER */
14036
14037
/* RFC 9846 Section 4.7.3: a TLS 1.3 sender MUST NOT allow its number of key
14038
 * updates to exceed 2^48-1. DTLS 1.3 bounds the epoch instead (RFC 9147
14039
 * Section 4.2.1), so this only covers TLS.
14040
 *
14041
 * ssl  The SSL/TLS object.
14042
 * returns 1 when a further KeyUpdate would exceed the limit, 0 otherwise.
14043
 */
14044
int Tls13KeyUpdateLimitReached(WOLFSSL* ssl)
14045
0
{
14046
0
    if (ssl->options.dtls)
14047
0
        return 0;
14048
14049
0
    return w64GTE(ssl->keys.keyUpdateCount,
14050
0
                  w64From32(TLS13_KEY_UPDATE_MAX_HI32,
14051
0
                            TLS13_KEY_UPDATE_MAX_LO32));
14052
0
}
14053
14054
/* handle generation TLS v1.3 key_update (24) */
14055
/* Send the TLS v1.3 KeyUpdate message.
14056
 *
14057
 * ssl  The SSL/TLS object.
14058
 * returns 0 on success, otherwise failure.
14059
 */
14060
int SendTls13KeyUpdate(WOLFSSL* ssl)
14061
0
{
14062
0
    byte*  input;
14063
0
    byte*  output;
14064
0
    int    ret;
14065
0
    int    headerSz = HANDSHAKE_HEADER_SZ;
14066
0
    int    outputSz;
14067
0
    word32 i = RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ;
14068
14069
0
    WOLFSSL_START(WC_FUNC_KEY_UPDATE_SEND);
14070
0
    WOLFSSL_ENTER("SendTls13KeyUpdate");
14071
14072
#ifdef WOLFSSL_DTLS13
14073
    if (ssl->options.dtls) {
14074
        /* RFC 9147 Section 4.2.1: do not send a KeyUpdate that would advance
14075
         * the sending epoch beyond 2^48-1. */
14076
        if (w64GTE(ssl->dtls13Epoch,
14077
                   w64From32(DTLS13_EPOCH_MAX_HI32, DTLS13_EPOCH_MAX_LO32))) {
14078
            WOLFSSL_MSG("DTLS 1.3 sending epoch at maximum; refusing KeyUpdate");
14079
            return BAD_STATE_E;
14080
        }
14081
        i = Dtls13GetRlHeaderLength(ssl, 1) + DTLS_HANDSHAKE_HEADER_SZ;
14082
    }
14083
#endif /* WOLFSSL_DTLS13 */
14084
14085
    /* RFC 9846 Section 4.7.3: a sending implementation MUST NOT allow its
14086
     * number of key updates to exceed 2^48-1. Receivers MUST NOT enforce this
14087
     * on the peer. */
14088
0
    if (Tls13KeyUpdateLimitReached(ssl)) {
14089
0
        WOLFSSL_MSG("TLS 1.3 key update count at maximum; refusing KeyUpdate");
14090
0
        return BAD_STATE_E;
14091
0
    }
14092
14093
    /* i already carries the real record and handshake header lengths.
14094
     * MAX_MSG_EXTRA only budgets RECORD_HEADER_SZ. */
14095
0
    outputSz = (int)i + OPAQUE8_LEN + MAX_MSG_EXTRA;
14096
    /* Check buffers are big enough and grow if needed. */
14097
0
    if ((ret = CheckAvailableSize(ssl, outputSz)) != 0)
14098
0
        return ret;
14099
14100
    /* get output buffer */
14101
0
    output = GetOutputBuffer(ssl);
14102
0
    input = output + RECORD_HEADER_SZ;
14103
14104
#ifdef WOLFSSL_DTLS13
14105
    if (ssl->options.dtls)
14106
        input = output + Dtls13GetRlHeaderLength(ssl, 1);
14107
#endif /* WOLFSSL_DTLS13 */
14108
14109
0
    AddTls13Headers(output, OPAQUE8_LEN, key_update, ssl);
14110
14111
    /* If:
14112
     *   1. I haven't sent a KeyUpdate requesting a response and
14113
     *   2. This isn't responding to peer KeyUpdate requiring a response then,
14114
     * I want a response.
14115
     */
14116
0
    ssl->keys.updateResponseReq = output[i++] =
14117
0
         !ssl->keys.updateResponseReq && !ssl->keys.keyUpdateRespond;
14118
    /* Sent response, no longer need to respond. */
14119
0
    ssl->keys.keyUpdateRespond = 0;
14120
14121
#ifdef WOLFSSL_DTLS13
14122
    if (ssl->options.dtls) {
14123
        ret = Dtls13HandshakeSend(ssl, output, (word16)outputSz,
14124
            OPAQUE8_LEN + Dtls13GetRlHeaderLength(ssl, 1) +
14125
                DTLS_HANDSHAKE_HEADER_SZ,
14126
            key_update, 0);
14127
    }
14128
    else
14129
#endif /* WOLFSSL_DTLS13 */
14130
0
    {
14131
        /* This message is always encrypted. */
14132
0
        int sendSz = BuildTls13Message(ssl, output, outputSz, input,
14133
0
                                   headerSz + OPAQUE8_LEN, handshake, 0, 0, 0);
14134
0
        if (sendSz < 0)
14135
0
            return BUILD_MSG_ERROR;
14136
14137
0
        #if defined(WOLFSSL_CALLBACKS) || defined(OPENSSL_EXTRA)
14138
0
            if (ssl->hsInfoOn) AddPacketName(ssl, "KeyUpdate");
14139
0
            if (ssl->toInfoOn) {
14140
0
                ret = AddPacketInfo(ssl, "KeyUpdate", handshake, output, sendSz,
14141
0
                              WRITE_PROTO, 0, ssl->heap);
14142
0
                if (ret != 0)
14143
0
                    return ret;
14144
0
            }
14145
0
        #endif
14146
14147
0
        ssl->buffers.outputBuffer.length += (word32)sendSz;
14148
14149
0
        ret = SendBuffered(ssl);
14150
14151
14152
0
        if (ret != 0 && ret != WC_NO_ERR_TRACE(WANT_WRITE))
14153
0
            return ret;
14154
0
    }
14155
14156
    /* In DTLS we must wait for the ack before setting up the new keys */
14157
0
    if (!ssl->options.dtls) {
14158
14159
        /* Future traffic uses new encryption keys. */
14160
0
        if ((ret = DeriveTls13Keys(
14161
0
                       ssl, update_traffic_key, ENCRYPT_SIDE_ONLY, 1))
14162
0
            != 0)
14163
0
            return ret;
14164
0
        if ((ret = SetKeysSide(ssl, ENCRYPT_SIDE_ONLY)) != 0)
14165
0
            return ret;
14166
14167
        /* Count this key update against the RFC 9846 sender limit. */
14168
0
        w64Increment(&ssl->keys.keyUpdateCount);
14169
0
    }
14170
14171
14172
0
    WOLFSSL_LEAVE("SendTls13KeyUpdate", ret);
14173
0
    WOLFSSL_END(WC_FUNC_KEY_UPDATE_SEND);
14174
14175
0
    return ret;
14176
0
}
14177
14178
/* handle processing TLS v1.3 key_update (24) */
14179
/* Parse and handle a TLS v1.3 KeyUpdate message.
14180
 *
14181
 * ssl       The SSL/TLS object.
14182
 * input     The message buffer.
14183
 * inOutIdx  On entry, the index into the message buffer of Finished.
14184
 *           On exit, the index of byte after the Finished message and padding.
14185
 * totalSz   The length of the current handshake message.
14186
 * returns 0 on success and otherwise failure.
14187
 */
14188
static int DoTls13KeyUpdate(WOLFSSL* ssl, const byte* input, word32* inOutIdx,
14189
                            word32 totalSz)
14190
0
{
14191
0
    int    ret;
14192
0
    word32 i = *inOutIdx;
14193
14194
0
    WOLFSSL_START(WC_FUNC_KEY_UPDATE_DO);
14195
0
    WOLFSSL_ENTER("DoTls13KeyUpdate");
14196
14197
    /* check against totalSz */
14198
0
    if (OPAQUE8_LEN != totalSz)
14199
0
        return BUFFER_E;
14200
14201
0
    switch (input[i]) {
14202
0
        case update_not_requested:
14203
            /* This message in response to any outstanding request. */
14204
0
            ssl->keys.keyUpdateRespond = 0;
14205
0
            ssl->keys.updateResponseReq = 0;
14206
0
            break;
14207
0
        case update_requested:
14208
            /* New key update requiring a response. */
14209
0
            ssl->keys.keyUpdateRespond = 1;
14210
0
            break;
14211
0
        default:
14212
0
            WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
14213
0
            return INVALID_PARAMETER;
14214
0
    }
14215
14216
    /* Move index to byte after message. */
14217
0
    *inOutIdx += totalSz;
14218
14219
    /* Future traffic uses new decryption keys. */
14220
0
    if ((ret = DeriveTls13Keys(ssl, update_traffic_key, DECRYPT_SIDE_ONLY, 1))
14221
0
                                                                         != 0) {
14222
0
        return ret;
14223
0
    }
14224
0
    if ((ret = SetKeysSide(ssl, DECRYPT_SIDE_ONLY)) != 0)
14225
0
        return ret;
14226
14227
#ifdef WOLFSSL_DTLS13
14228
    if (ssl->options.dtls) {
14229
        /* Increment on a local copy so ssl->dtls13PeerEpoch is left
14230
         * untouched when the check fails. */
14231
        w64wrapper newEpoch = ssl->dtls13PeerEpoch;
14232
        w64Increment(&newEpoch);
14233
14234
        /* RFC 9147 Section 8: the 2^48-1 cap is sender-only; receivers MUST
14235
         * NOT enforce it. Guard only the wrap-to-zero (Section 4.2.1). */
14236
        if (w64IsZero(newEpoch))
14237
            return BAD_STATE_E;
14238
14239
        ssl->dtls13PeerEpoch = newEpoch;
14240
14241
        ret = Dtls13SetEpochKeys(ssl, ssl->dtls13PeerEpoch, DECRYPT_SIDE_ONLY);
14242
        if (ret != 0)
14243
            return ret;
14244
    }
14245
#endif /* WOLFSSL_DTLS13 */
14246
14247
0
    if (ssl->keys.keyUpdateRespond) {
14248
14249
#ifdef WOLFSSL_DTLS13
14250
        /* we already sent a keyUpdate (either in response to a previous
14251
           KeyUpdate or initiated by the application) and we are waiting for the
14252
           ack. We can't send a new KeyUpdate right away but to honor the RFC we
14253
           should send another KeyUpdate after the one in-flight is acked. We
14254
           don't do that as it looks redundant, it will make the code more
14255
           complex and I don't see a good use case for that. */
14256
        if (ssl->options.dtls && ssl->dtls13WaitKeyUpdateAck) {
14257
            ssl->keys.keyUpdateRespond = 0;
14258
            return 0;
14259
        }
14260
#endif /* WOLFSSL_DTLS13 */
14261
14262
#if defined(HAVE_WRITE_DUP) && defined(WOLFSSL_TLS13)
14263
        /* Read side cannot write; delegate the response to the write side.
14264
         * The key update cap is deliberately not checked here: the two sides
14265
         * are separate WOLFSSL objects with separate keys, and only the write
14266
         * side ever sends a KeyUpdate, so this object's keyUpdateCount is not
14267
         * the one the limit applies to. The check is applied on the write side
14268
         * in wolfssl_write_dup_do_tls13_work(). */
14269
        if (ssl->dupWrite != NULL && ssl->dupSide == READ_DUP_SIDE) {
14270
            if (wc_LockMutex(&ssl->dupWrite->dupMutex) != 0)
14271
                return BAD_MUTEX_E;
14272
            ssl->dupWrite->keyUpdateRespond = 1;
14273
            wc_UnLockMutex(&ssl->dupWrite->dupMutex);
14274
            ssl->keys.keyUpdateRespond = 0;
14275
            return 0;
14276
        }
14277
#endif /* HAVE_WRITE_DUP && WOLFSSL_TLS13 */
14278
14279
        /* RFC 9846 Section 4.7.3: a sender that would exceed the key update
14280
         * limit "MUST NOT send its own KeyUpdate ... and SHOULD instead ignore
14281
         * the 'update_requested' flag". Dropping the response rather than
14282
         * failing keeps the connection alive on the current keys until the
14283
         * Section 5.5 data limits eventually force it closed. */
14284
0
        if (Tls13KeyUpdateLimitReached(ssl)) {
14285
0
            WOLFSSL_MSG("Key update limit reached; ignoring update_requested");
14286
0
            ssl->keys.keyUpdateRespond = 0;
14287
0
            return 0;
14288
0
        }
14289
14290
0
#ifndef WOLFSSL_RW_THREADED
14291
0
        return SendTls13KeyUpdate(ssl);
14292
#else
14293
        ssl->options.sendKeyUpdate = 1;
14294
        return 0;
14295
#endif
14296
0
    }
14297
14298
0
    WOLFSSL_LEAVE("DoTls13KeyUpdate", ret);
14299
0
    WOLFSSL_END(WC_FUNC_KEY_UPDATE_DO);
14300
14301
0
    return 0;
14302
0
}
14303
14304
#ifdef WOLFSSL_EARLY_DATA
14305
#ifndef NO_WOLFSSL_CLIENT
14306
/* Send the TLS v1.3 EndOfEarlyData message to indicate that there will be no
14307
 * more early application data.
14308
 * The encryption key now changes to the pre-calculated handshake key.
14309
 *
14310
 * ssl  The SSL/TLS object.
14311
 * returns 0 on success and otherwise failure.
14312
 */
14313
static int SendTls13EndOfEarlyData(WOLFSSL* ssl)
14314
{
14315
    byte*  output;
14316
    int    ret;
14317
    int    sendSz;
14318
    word32 length;
14319
    word32 idx = RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ;
14320
14321
    WOLFSSL_START(WC_FUNC_END_OF_EARLY_DATA_SEND);
14322
    WOLFSSL_ENTER("SendTls13EndOfEarlyData");
14323
14324
    length = 0;
14325
    sendSz = (int)(idx + length + MAX_MSG_EXTRA);
14326
    ssl->options.buildingMsg = 1;
14327
14328
    /* Check buffers are big enough and grow if needed. */
14329
    if ((ret = CheckAvailableSize(ssl, sendSz)) != 0)
14330
        return ret;
14331
14332
    /* Get position in output buffer to write new message to. */
14333
    output = GetOutputBuffer(ssl);
14334
14335
    /* Put the record and handshake headers on. */
14336
    AddTls13Headers(output, length, end_of_early_data, ssl);
14337
14338
    /* This message is always encrypted. */
14339
    sendSz = BuildTls13Message(ssl, output, sendSz, output + RECORD_HEADER_SZ,
14340
                               idx - RECORD_HEADER_SZ, handshake, 1, 0, 0);
14341
    if (sendSz < 0)
14342
        return sendSz;
14343
14344
    ssl->buffers.outputBuffer.length += sendSz;
14345
14346
    if ((ret = SetKeysSide(ssl, ENCRYPT_SIDE_ONLY)) != 0)
14347
        return ret;
14348
14349
    ssl->options.buildingMsg = 0;
14350
    if (!ssl->options.groupMessages)
14351
        ret = SendBuffered(ssl);
14352
14353
    ssl->earlyData = done_early_data;
14354
14355
    WOLFSSL_LEAVE("SendTls13EndOfEarlyData", ret);
14356
    WOLFSSL_END(WC_FUNC_END_OF_EARLY_DATA_SEND);
14357
14358
    return ret;
14359
}
14360
#endif /* !NO_WOLFSSL_CLIENT */
14361
14362
#ifndef NO_WOLFSSL_SERVER
14363
/* handle processing of TLS 1.3 end_of_early_data (5) */
14364
/* Parse the TLS v1.3 EndOfEarlyData message that indicates that there will be
14365
 * no more early application data.
14366
 * The decryption key now changes to the pre-calculated handshake key.
14367
 *
14368
 * ssl  The SSL/TLS object.
14369
 * returns 0 on success and otherwise failure.
14370
 */
14371
static int DoTls13EndOfEarlyData(WOLFSSL* ssl, const byte* input,
14372
                                 word32* inOutIdx, word32 size)
14373
{
14374
    int    ret;
14375
    word32 begin = *inOutIdx;
14376
14377
    (void)input;
14378
14379
    WOLFSSL_START(WC_FUNC_END_OF_EARLY_DATA_DO);
14380
    WOLFSSL_ENTER("DoTls13EndOfEarlyData");
14381
14382
    if ((*inOutIdx - begin) != size)
14383
        return BUFFER_ERROR;
14384
14385
    if (ssl->earlyData == no_early_data) {
14386
        WOLFSSL_MSG("EndOfEarlyData received unexpectedly");
14387
        SendAlert(ssl, alert_fatal, unexpected_message);
14388
        WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
14389
        return OUT_OF_ORDER_E;
14390
    }
14391
14392
    ssl->earlyData = done_early_data;
14393
14394
    ret = SetKeysSide(ssl, DECRYPT_SIDE_ONLY);
14395
14396
    WOLFSSL_LEAVE("DoTls13EndOfEarlyData", ret);
14397
    WOLFSSL_END(WC_FUNC_END_OF_EARLY_DATA_DO);
14398
14399
    return ret;
14400
}
14401
#endif /* !NO_WOLFSSL_SERVER */
14402
#endif /* WOLFSSL_EARLY_DATA */
14403
14404
#if defined(HAVE_SESSION_TICKET) && defined(WOLFSSL_TICKET_NONCE_MALLOC) &&    \
14405
    (!defined(HAVE_FIPS) || (defined(FIPS_VERSION_GE) && FIPS_VERSION_GE(5,3)))
14406
int SessionTicketNoncePopulate(WOLFSSL_SESSION *session, const byte *nonce,
14407
    byte len)
14408
{
14409
    if (session->ticketNonce.data
14410
            != session->ticketNonce.dataStatic) {
14411
         XFREE(session->ticketNonce.data, session->heap,
14412
             DYNAMIC_TYPE_SESSION_TICK);
14413
         session->ticketNonce.data = session->ticketNonce.dataStatic;
14414
         session->ticketNonce.len = 0;
14415
    }
14416
14417
    if (len > MAX_TICKET_NONCE_STATIC_SZ) {
14418
        WOLFSSL_MSG("Using dynamic nonce buffer");
14419
        session->ticketNonce.data = (byte*)XMALLOC(len,
14420
            session->heap, DYNAMIC_TYPE_SESSION_TICK);
14421
        if (session->ticketNonce.data == NULL)
14422
            return MEMORY_ERROR;
14423
    }
14424
    XMEMCPY(session->ticketNonce.data, nonce, len);
14425
    session->ticketNonce.len = len;
14426
    return 0;
14427
}
14428
#endif
14429
#ifndef NO_WOLFSSL_CLIENT
14430
/* Handle a New Session Ticket handshake message.
14431
 * Message contains the information required to perform resumption.
14432
 *
14433
 * ssl       The SSL/TLS object.
14434
 * input     The message buffer.
14435
 * inOutIdx  On entry, the index into the message buffer of Finished.
14436
 *           On exit, the index of byte after the Finished message and padding.
14437
 * size      The length of the current handshake message.
14438
 * returns 0 on success, otherwise failure.
14439
 */
14440
static int DoTls13NewSessionTicket(WOLFSSL* ssl, const byte* input,
14441
                                   word32* inOutIdx, word32 size)
14442
0
{
14443
0
#ifdef HAVE_SESSION_TICKET
14444
0
    int    ret;
14445
0
    word32 begin = *inOutIdx;
14446
0
    word32 lifetime;
14447
0
    word32 ageAdd;
14448
0
    word16 length;
14449
#ifdef WOLFSSL_32BIT_MILLI_TIME
14450
    word32 now;
14451
#else
14452
0
    sword64 now;
14453
0
#endif
14454
0
    const byte* nonce;
14455
0
    byte        nonceLength;
14456
14457
0
    WOLFSSL_START(WC_FUNC_NEW_SESSION_TICKET_DO);
14458
0
    WOLFSSL_ENTER("DoTls13NewSessionTicket");
14459
14460
#ifdef HAVE_ECH
14461
    /* ignore session ticket when ECH is rejected */
14462
    if (ssl->echConfigs != NULL && !ssl->options.disableECH &&
14463
            !ssl->options.echAccepted) {
14464
        *inOutIdx += size + ssl->keys.padSz;
14465
        return 0;
14466
    }
14467
#endif
14468
14469
    /* Lifetime hint. */
14470
0
    if ((*inOutIdx - begin) + SESSION_HINT_SZ > size)
14471
0
        return BUFFER_ERROR;
14472
0
    ato32(input + *inOutIdx, &lifetime);
14473
0
    *inOutIdx += SESSION_HINT_SZ;
14474
0
    if (lifetime > MAX_LIFETIME) {
14475
0
        WOLFSSL_ERROR_VERBOSE(SERVER_HINT_ERROR);
14476
0
        return SERVER_HINT_ERROR;
14477
0
    }
14478
14479
    /* Age add. */
14480
0
    if ((*inOutIdx - begin) + SESSION_ADD_SZ > size)
14481
0
        return BUFFER_ERROR;
14482
0
    ato32(input + *inOutIdx, &ageAdd);
14483
0
    *inOutIdx += SESSION_ADD_SZ;
14484
14485
    /* Ticket nonce. */
14486
0
    if ((*inOutIdx - begin) + 1 > size)
14487
0
        return BUFFER_ERROR;
14488
0
    nonceLength = input[*inOutIdx];
14489
0
#if !defined(WOLFSSL_TICKET_NONCE_MALLOC) &&                                   \
14490
0
    (!defined(HAVE_FIPS) || FIPS_VERSION_GE(5,3))
14491
0
    if (nonceLength > MAX_TICKET_NONCE_STATIC_SZ) {
14492
0
        WOLFSSL_MSG("Nonce length not supported");
14493
0
        WOLFSSL_ERROR_VERBOSE(INVALID_PARAMETER);
14494
0
        return INVALID_PARAMETER;
14495
0
    }
14496
0
#endif /* WOLFSSL_TICKET_NONCE_MALLOC && FIPS_VERSION_GE(5,3) */
14497
0
    *inOutIdx += 1;
14498
0
    if ((*inOutIdx - begin) + nonceLength > size)
14499
0
        return BUFFER_ERROR;
14500
0
    nonce = input + *inOutIdx;
14501
0
    *inOutIdx += nonceLength;
14502
14503
    /* Ticket length. */
14504
0
    if ((*inOutIdx - begin) + LENGTH_SZ > size)
14505
0
        return BUFFER_ERROR;
14506
0
    ato16(input + *inOutIdx, &length);
14507
0
    *inOutIdx += LENGTH_SZ;
14508
0
    if ((*inOutIdx - begin) + length > size)
14509
0
        return BUFFER_ERROR;
14510
    /* note: we reject zero length ticket here, and not in SetTicket(),
14511
     * because zero length is valid for TLS 1.2 */
14512
0
    if (length == 0)
14513
0
        return BUFFER_ERROR;
14514
14515
0
    if ((ret = SetTicket(ssl, input + *inOutIdx, length)) != 0)
14516
0
        return ret;
14517
0
    *inOutIdx += length;
14518
14519
0
    now = TimeNowInMilliseconds();
14520
0
    if (now == 0)
14521
0
        return GETTIME_ERROR;
14522
    /* Copy in ticket data (server identity). */
14523
0
    ssl->timeout                  = lifetime;
14524
0
    ssl->session->timeout         = lifetime;
14525
0
    ssl->session->cipherSuite0    = ssl->options.cipherSuite0;
14526
0
    ssl->session->cipherSuite     = ssl->options.cipherSuite;
14527
0
    ssl->session->ticketSeen      = now;
14528
0
    ssl->session->ticketAdd       = ageAdd;
14529
    #ifdef WOLFSSL_EARLY_DATA
14530
    ssl->session->maxEarlyDataSz  = ssl->options.maxEarlyDataSz;
14531
    #endif
14532
14533
#if defined(WOLFSSL_TICKET_NONCE_MALLOC) &&                                    \
14534
    (!defined(HAVE_FIPS) || (defined(FIPS_VERSION_GE) && FIPS_VERSION_GE(5,3)))
14535
    ret = SessionTicketNoncePopulate(ssl->session, nonce, nonceLength);
14536
    if (ret != 0)
14537
        return ret;
14538
#else
14539
0
    ssl->session->ticketNonce.len = nonceLength;
14540
0
    if (nonceLength > MAX_TICKET_NONCE_STATIC_SZ) {
14541
0
        ret = BUFFER_ERROR;
14542
0
        return ret;
14543
0
    }
14544
0
    if (nonceLength > 0)
14545
0
        XMEMCPY(ssl->session->ticketNonce.data, nonce, nonceLength);
14546
0
#endif /* defined(WOLFSSL_TICKET_NONCE_MALLOC) && FIPS_VERSION_GE(5,3) */
14547
14548
0
    ssl->session->namedGroup      = ssl->namedGroup;
14549
14550
0
    if ((*inOutIdx - begin) + EXTS_SZ > size)
14551
0
        return BUFFER_ERROR;
14552
0
    ato16(input + *inOutIdx, &length);
14553
0
    *inOutIdx += EXTS_SZ;
14554
0
    if ((*inOutIdx - begin) + length != size)
14555
0
        return BUFFER_ERROR;
14556
    /* RFC 9846 Section 4.7.1: the extensions are Section 4.3 Extension TLVs.
14557
     * Malformed framing is a syntax error even when no extension in the list
14558
     * is one we act on. */
14559
0
    ret = TLSX_Parse(ssl, input + *inOutIdx, length, session_ticket, NULL);
14560
0
    if (ret != 0)
14561
0
        return ret;
14562
0
    *inOutIdx += length;
14563
14564
0
    SetupSession(ssl);
14565
0
    #ifndef NO_SESSION_CACHE
14566
0
        AddSession(ssl);
14567
0
    #endif
14568
14569
0
    ssl->expect_session_ticket = 0;
14570
#else
14571
    (void)ssl;
14572
    (void)input;
14573
14574
    WOLFSSL_ENTER("DoTls13NewSessionTicket");
14575
14576
    *inOutIdx += size;
14577
#endif /* HAVE_SESSION_TICKET */
14578
14579
0
    WOLFSSL_LEAVE("DoTls13NewSessionTicket", 0);
14580
0
    WOLFSSL_END(WC_FUNC_NEW_SESSION_TICKET_DO);
14581
14582
0
    return 0;
14583
0
}
14584
#endif /* NO_WOLFSSL_CLIENT */
14585
14586
#ifndef NO_WOLFSSL_SERVER
14587
    #ifdef HAVE_SESSION_TICKET
14588
14589
#ifdef WOLFSSL_TLS13_TICKET_BEFORE_FINISHED
14590
/* Offset of the MAC size in the finished message. */
14591
#define FINISHED_MSG_SIZE_OFFSET    3
14592
14593
/* Calculate the resumption secret which includes the unseen client finished
14594
 * message.
14595
 *
14596
 * ssl  The SSL/TLS object.
14597
 * returns 0 on success, otherwise failure.
14598
 */
14599
static int ExpectedResumptionSecret(WOLFSSL* ssl)
14600
{
14601
    int         ret;
14602
    int         saveRet = 0;
14603
    word32      finishedSz = 0;
14604
    byte        mac[WC_MAX_DIGEST_SIZE];
14605
    Digest      digest;
14606
    byte header[] = { 0x14, 0x00, 0x00, 0x00 };
14607
14608
    XMEMSET(&digest, 0, sizeof(Digest));
14609
14610
    /* Copy the running hash so we can restore it after. */
14611
    switch (ssl->specs.mac_algorithm) {
14612
    #ifndef NO_SHA256
14613
        case sha256_mac:
14614
            ret = wc_Sha256Copy(&ssl->hsHashes->hashSha256, &digest.sha256);
14615
            if (ret != 0)
14616
                return ret;
14617
            break;
14618
    #endif
14619
    #ifdef WOLFSSL_SHA384
14620
        case sha384_mac:
14621
            ret = wc_Sha384Copy(&ssl->hsHashes->hashSha384, &digest.sha384);
14622
            if (ret != 0)
14623
                return ret;
14624
            break;
14625
    #endif
14626
    #ifdef WOLFSSL_TLS13_SHA512
14627
        case sha512_mac:
14628
            ret = wc_Sha512Copy(&ssl->hsHashes->hashSha512, &digest.sha512);
14629
            if (ret != 0)
14630
                return ret;
14631
            break;
14632
    #endif
14633
    #ifdef WOLFSSL_SM3
14634
        case sm3_mac:
14635
            ret = wc_Sm3Copy(&ssl->hsHashes->hashSm3, &digest.sm3);
14636
            if (ret != 0)
14637
                return ret;
14638
            break;
14639
    #endif
14640
    }
14641
14642
    /* Generate the Client's Finished message and hash it. */
14643
    ret = BuildTls13HandshakeHmac(ssl, ssl->keys.client_write_MAC_secret, mac,
14644
                                  &finishedSz);
14645
    if (ret != 0)
14646
        goto restore;
14647
    header[FINISHED_MSG_SIZE_OFFSET] = finishedSz;
14648
#ifdef WOLFSSL_EARLY_DATA
14649
    if (ssl->earlyData != no_early_data) {
14650
        static byte endOfEarlyData[] = { 0x05, 0x00, 0x00, 0x00 };
14651
        ret = HashRaw(ssl, endOfEarlyData, sizeof(endOfEarlyData));
14652
        if (ret != 0)
14653
            goto restore;
14654
    }
14655
#endif
14656
    if ((ret = HashRaw(ssl, header, sizeof(header))) != 0)
14657
        goto restore;
14658
    if ((ret = HashRaw(ssl, mac, finishedSz)) != 0)
14659
        goto restore;
14660
14661
    if ((ret = DeriveResumptionSecret(ssl, ssl->session->masterSecret)) != 0)
14662
        goto restore;
14663
14664
    /* Restore the hash inline with currently seen messages. */
14665
restore:
14666
    /* The restore result must not mask the error that got here, or a
14667
     * WC_PENDING_E would be reported as success with the derive skipped. */
14668
    saveRet = ret;
14669
    switch (ssl->specs.mac_algorithm) {
14670
    #ifndef NO_SHA256
14671
        case sha256_mac:
14672
            wc_Sha256Free(&ssl->hsHashes->hashSha256);
14673
            ret = wc_Sha256Copy(&digest.sha256, &ssl->hsHashes->hashSha256);
14674
            wc_Sha256Free(&digest.sha256);
14675
            break;
14676
    #endif
14677
    #ifdef WOLFSSL_SHA384
14678
        case sha384_mac:
14679
            wc_Sha384Free(&ssl->hsHashes->hashSha384);
14680
            ret = wc_Sha384Copy(&digest.sha384, &ssl->hsHashes->hashSha384);
14681
            wc_Sha384Free(&digest.sha384);
14682
            break;
14683
    #endif
14684
    #ifdef WOLFSSL_TLS13_SHA512
14685
        case sha512_mac:
14686
            wc_Sha512Free(&ssl->hsHashes->hashSha512);
14687
            ret = wc_Sha512Copy(&digest.sha512, &ssl->hsHashes->hashSha512);
14688
            wc_Sha512Free(&digest.sha512);
14689
            break;
14690
    #endif
14691
    #ifdef WOLFSSL_SM3
14692
        case sm3_mac:
14693
            wc_Sm3Free(&ssl->hsHashes->hashSm3);
14694
            ret = wc_Sm3Copy(&digest.sm3, &ssl->hsHashes->hashSm3);
14695
            wc_Sm3Free(&digest.sm3);
14696
            break;
14697
    #endif
14698
    }
14699
    if (saveRet != 0)
14700
        ret = saveRet;
14701
14702
    ForceZero(mac, sizeof(mac));
14703
    return ret;
14704
}
14705
#endif
14706
14707
/* Check the client advertised a PSK key exchange mode a resumption ticket can
14708
 * be used with.
14709
 *
14710
 * RFC 9846 Section 4.3.9: psk_key_exchange_modes restricts both the PSKs
14711
 * offered in the ClientHello and those the server might supply through
14712
 * NewSessionTicket, and servers should not send tickets that are incompatible
14713
 * with the advertised modes. RFC 9846 Section 4.7.1 makes sending a ticket
14714
 * conditional on the client's hello carrying a suitable extension.
14715
 *
14716
 * ssl  The SSL/TLS object.
14717
 * returns 0 when a ticket may be sent, MISSING_HANDSHAKE_DATA when the
14718
 *         extension was not received and PSK_KEY_ERROR when none of the
14719
 *         advertised modes is usable.
14720
 */
14721
static int CheckTls13TicketPskModes(WOLFSSL* ssl)
14722
0
{
14723
#ifdef WOLFSSL_TLS13_TICKET_CHECK_PSK_MODES
14724
    if (!ssl->options.pskKeModesRecvd) {
14725
        WOLFSSL_MSG("No psk_key_exchange_modes in ClientHello");
14726
        return MISSING_HANDSHAKE_DATA;
14727
    }
14728
14729
    if ((ssl->options.pskKeModes & (1 << PSK_KE)) != 0
14730
    #ifdef HAVE_SUPPORTED_CURVES
14731
        && !ssl->options.onlyPskDheKe
14732
    #endif
14733
        ) {
14734
        return 0;
14735
    }
14736
    /* The configured policy, not noPskDheKe - a certificate handshake clears
14737
     * that one before the ticket is sent, which would make this always true. */
14738
    if ((ssl->options.pskKeModes & (1 << PSK_DHE_KE)) != 0 &&
14739
            !ssl->options.noPskDheKePolicy) {
14740
        return 0;
14741
    }
14742
14743
    WOLFSSL_MSG("No usable psk_key_exchange_modes advertised by client");
14744
    return PSK_KEY_ERROR;
14745
#else
14746
0
    (void)ssl;
14747
0
    return 0;
14748
0
#endif
14749
0
}
14750
14751
/* Send New Session Ticket handshake message.
14752
 * Message contains the information required to perform resumption.
14753
 *
14754
 * ssl  The SSL/TLS object.
14755
 * returns 0 on success, otherwise failure.
14756
 */
14757
static int SendTls13NewSessionTicket(WOLFSSL* ssl)
14758
0
{
14759
0
    byte*  output;
14760
0
    int    ret;
14761
0
    word32 length;
14762
0
    int    sendSz;
14763
0
    word16 extSz;
14764
0
    word32 idx = RECORD_HEADER_SZ + HANDSHAKE_HEADER_SZ;
14765
14766
0
    WOLFSSL_START(WC_FUNC_NEW_SESSION_TICKET_SEND);
14767
0
    WOLFSSL_ENTER("SendTls13NewSessionTicket");
14768
14769
0
    if (DefTicketHintTooLarge(ssl)) {
14770
0
        WOLFSSL_MSG("Ticket hint exceeds half the ticket key lifetime; "
14771
0
                    "skipping ticket");
14772
0
        return 0;
14773
0
    }
14774
14775
0
    if (CheckTls13TicketPskModes(ssl) != 0) {
14776
0
        WOLFSSL_MSG("Client advertised no usable PSK key exchange mode; "
14777
0
                    "skipping ticket");
14778
0
        return 0;
14779
0
    }
14780
14781
#ifdef WOLFSSL_DTLS13
14782
    if (ssl->options.dtls)
14783
        idx = Dtls13GetRlHeaderLength(ssl, 1) + DTLS_HANDSHAKE_HEADER_SZ;
14784
#endif /* WOLFSSL_DTLS13 */
14785
14786
#ifdef WOLFSSL_TLS13_TICKET_BEFORE_FINISHED
14787
    if (!ssl->msgsReceived.got_finished) {
14788
        if ((ret = ExpectedResumptionSecret(ssl)) != 0)
14789
            return ret;
14790
    }
14791
#endif
14792
14793
    /* Start ticket nonce at 0 and go up to 255. */
14794
0
    if (ssl->session->ticketNonce.len == 0) {
14795
0
        ssl->session->ticketNonce.len = DEF_TICKET_NONCE_SZ;
14796
0
        ssl->session->ticketNonce.data[0] = 0;
14797
0
    }
14798
0
    else
14799
    #ifdef WOLFSSL_ASYNC_CRYPT
14800
        if (ssl->error != WC_NO_ERR_TRACE(WC_PENDING_E))
14801
    #endif
14802
0
    {
14803
0
        if (ssl->session->ticketNonce.data[0] == 255) {
14804
            /* RFC8446 Section 4.6.1: Each ticket must have a unique nonce
14805
             * value. As the nonce is only a single byte, we have to prevent
14806
             * the overflow and abort. */
14807
0
            return SESSION_TICKET_NONCE_OVERFLOW;
14808
0
        }
14809
0
        else
14810
0
            ssl->session->ticketNonce.data[0]++;
14811
0
    }
14812
14813
0
    if ((ssl->options.mask & WOLFSSL_OP_NO_TICKET) != 0) {
14814
        /* In this case we only send the ID as the ticket. Let's generate a new
14815
         * ID for the new ticket so that we don't overwrite any old ones */
14816
0
        ret = wc_RNG_GenerateBlock(ssl->rng, ssl->session->altSessionID,
14817
0
                                   ID_LEN);
14818
0
        if (ret != 0)
14819
0
            return ret;
14820
0
        ssl->session->haveAltSessionID = 1;
14821
0
    }
14822
14823
0
    if (!ssl->options.noTicketTls13) {
14824
0
        if ((ret = SetupTicket(ssl)) != 0)
14825
0
            return ret;
14826
        /* No need to create the ticket if we only send the ID */
14827
0
        if ((ssl->options.mask & WOLFSSL_OP_NO_TICKET) == 0) {
14828
0
            if ((ret = CreateTicket(ssl)) != 0)
14829
0
                return ret;
14830
0
        }
14831
0
    }
14832
14833
#ifdef WOLFSSL_EARLY_DATA
14834
    ssl->session->maxEarlyDataSz = ssl->options.maxEarlyDataSz;
14835
    if (ssl->session->maxEarlyDataSz > 0)
14836
        TLSX_EarlyData_Use(ssl, ssl->session->maxEarlyDataSz, 1);
14837
    extSz = 0;
14838
    ret = TLSX_GetResponseSize(ssl, session_ticket, &extSz);
14839
    if (ret != 0)
14840
        return ret;
14841
#else
14842
0
    extSz = EXTS_SZ;
14843
0
#endif
14844
    /* Lifetime | Age Add | Ticket session ID | Extensions */
14845
0
    length = SESSION_HINT_SZ + SESSION_ADD_SZ + LENGTH_SZ;
14846
0
    if ((ssl->options.mask & WOLFSSL_OP_NO_TICKET) != 0)
14847
0
        length += ID_LEN + extSz;
14848
0
    else
14849
0
        length += ssl->session->ticketLen + extSz;
14850
    /* Nonce */
14851
0
    length += TICKET_NONCE_LEN_SZ + DEF_TICKET_NONCE_SZ;
14852
14853
0
    sendSz = (int)(idx + length + MAX_MSG_EXTRA);
14854
14855
    /* Check buffers are big enough and grow if needed. */
14856
0
    if ((ret = CheckAvailableSize(ssl, sendSz)) != 0)
14857
0
        return ret;
14858
14859
    /* Get position in output buffer to write new message to. */
14860
0
    output = GetOutputBuffer(ssl);
14861
14862
    /* Put the record and handshake headers on. */
14863
0
    AddTls13Headers(output, length, session_ticket, ssl);
14864
14865
    /* Lifetime hint */
14866
0
    c32toa(ssl->ctx->ticketHint, output + idx);
14867
0
    idx += SESSION_HINT_SZ;
14868
    /* Age add - obfuscator */
14869
0
    c32toa(ssl->session->ticketAdd, output + idx);
14870
0
    idx += SESSION_ADD_SZ;
14871
14872
0
    output[idx++] = ssl->session->ticketNonce.len;
14873
0
    output[idx++] = ssl->session->ticketNonce.data[0];
14874
14875
    /* length */
14876
0
    if ((ssl->options.mask & WOLFSSL_OP_NO_TICKET) != 0) {
14877
0
        c16toa(ID_LEN, output + idx);
14878
0
    }
14879
0
    else {
14880
0
        c16toa(ssl->session->ticketLen, output + idx);
14881
0
    }
14882
14883
0
    idx += LENGTH_SZ;
14884
    /* ticket */
14885
0
    if ((ssl->options.mask & WOLFSSL_OP_NO_TICKET) != 0) {
14886
0
        if (ssl->session->haveAltSessionID)
14887
0
            XMEMCPY(output + idx, ssl->session->altSessionID, ID_LEN);
14888
0
        else
14889
0
            return BAD_FUNC_ARG; /* Should not happen */
14890
0
        idx += ID_LEN;
14891
0
    }
14892
0
    else {
14893
0
        XMEMCPY(output + idx, ssl->session->ticket, ssl->session->ticketLen);
14894
0
        idx += ssl->session->ticketLen;
14895
0
    }
14896
14897
#ifdef WOLFSSL_EARLY_DATA
14898
    extSz = 0;
14899
    ret = TLSX_WriteResponse(ssl, output + idx, session_ticket, &extSz);
14900
    if (ret != 0)
14901
        return ret;
14902
    idx += extSz;
14903
#else
14904
    /* No extension support - empty extensions. */
14905
0
    c16toa(0, output + idx);
14906
0
    idx += EXTS_SZ;
14907
0
#endif
14908
14909
0
    if (idx > WOLFSSL_MAX_16BIT ||
14910
0
        sendSz > (int)WOLFSSL_MAX_16BIT) {
14911
0
        return BAD_LENGTH_E;
14912
0
    }
14913
14914
0
    ssl->options.haveSessionId = 1;
14915
14916
0
    SetupSession(ssl);
14917
    /* Only add to cache when support built in and when the ticket contains
14918
     * an ID. Otherwise we have no way to actually retrieve the ticket from the
14919
     * cache. */
14920
0
#if !defined(NO_SESSION_CACHE) && defined(WOLFSSL_TICKET_HAVE_ID)
14921
0
    AddSession(ssl);
14922
0
#endif
14923
14924
#ifdef WOLFSSL_DTLS13
14925
    if (ssl->options.dtls)
14926
        return Dtls13HandshakeSend(ssl, output, (word16)sendSz,
14927
                                   (word16)idx, session_ticket, 0);
14928
#endif /* WOLFSSL_DTLS13 */
14929
14930
    /* This message is always encrypted. */
14931
0
    sendSz = BuildTls13Message(ssl, output, sendSz,
14932
0
                               output + RECORD_HEADER_SZ,
14933
0
                               (word16)idx - RECORD_HEADER_SZ,
14934
0
                               handshake, 0, 0, 0);
14935
0
    if (sendSz < 0)
14936
0
        return sendSz;
14937
14938
0
    ssl->buffers.outputBuffer.length += sendSz;
14939
14940
    /* Always send as this is either directly after server's Finished or only
14941
     * message after client's Finished.
14942
     */
14943
0
    ret = SendBuffered(ssl);
14944
14945
0
    WOLFSSL_LEAVE("SendTls13NewSessionTicket", 0);
14946
0
    WOLFSSL_END(WC_FUNC_NEW_SESSION_TICKET_SEND);
14947
14948
0
    return ret;
14949
0
}
14950
    #endif /* HAVE_SESSION_TICKET */
14951
#endif /* NO_WOLFSSL_SERVER */
14952
14953
/* Make sure no duplicates, no fast forward, or other problems
14954
 *
14955
 * ssl   The SSL/TLS object.
14956
 * type  Type of handshake message received.
14957
 * returns 0 on success, otherwise failure.
14958
 */
14959
static int SanityCheckTls13MsgReceived(WOLFSSL* ssl, byte type)
14960
{
14961
    /* verify not a duplicate, mark received, check state */
14962
    switch (type) {
14963
14964
#ifndef NO_WOLFSSL_SERVER
14965
        case client_hello:
14966
        #ifndef NO_WOLFSSL_CLIENT
14967
            /* Only valid when received on SERVER side. */
14968
            if (ssl->options.side == WOLFSSL_CLIENT_END) {
14969
                WOLFSSL_MSG("ClientHello received by client");
14970
                WOLFSSL_ERROR_VERBOSE(SIDE_ERROR);
14971
                return SIDE_ERROR;
14972
            }
14973
        #endif
14974
            /* A replay after a pend arrives with got_client_hello cleared
14975
             * (see exit_dch); a genuine duplicate arrives with it set. */
14976
            if (ssl->options.clientState >= CLIENT_HELLO_COMPLETE
14977
        #ifdef WOLFSSL_ASYNC_CRYPT
14978
                && ssl->msgsReceived.got_client_hello != 0
14979
        #endif
14980
                ) {
14981
                WOLFSSL_MSG("ClientHello received out of order");
14982
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
14983
                return OUT_OF_ORDER_E;
14984
            }
14985
            /* Check previously seen. */
14986
            /* Initial and after HelloRetryRequest - no more than 2. */
14987
            if (ssl->msgsReceived.got_client_hello == 2) {
14988
                WOLFSSL_MSG("Too many ClientHello received");
14989
                WOLFSSL_ERROR_VERBOSE(DUPLICATE_MSG_E);
14990
                return DUPLICATE_MSG_E;
14991
            }
14992
            /* Second only after HelloRetryRequest seen. */
14993
            if (ssl->msgsReceived.got_client_hello == 1 &&
14994
                ssl->options.serverState !=
14995
                                          SERVER_HELLO_RETRY_REQUEST_COMPLETE) {
14996
                WOLFSSL_MSG("Duplicate ClientHello received");
14997
                WOLFSSL_ERROR_VERBOSE(DUPLICATE_MSG_E);
14998
                return DUPLICATE_MSG_E;
14999
            }
15000
            ssl->msgsReceived.got_client_hello++;
15001
15002
            break;
15003
#endif
15004
15005
#ifndef NO_WOLFSSL_CLIENT
15006
        case server_hello:
15007
        #ifndef NO_WOLFSSL_SERVER
15008
            /* Only valid when received on CLIENT side. */
15009
            if (ssl->options.side == WOLFSSL_SERVER_END) {
15010
                WOLFSSL_MSG("ServerHello received by server");
15011
                WOLFSSL_ERROR_VERBOSE(SIDE_ERROR);
15012
                return SIDE_ERROR;
15013
            }
15014
        #endif
15015
            /* Check state. */
15016
            if (ssl->options.serverState >= SERVER_HELLO_COMPLETE) {
15017
                WOLFSSL_MSG("ServerHello received out of order");
15018
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15019
                return OUT_OF_ORDER_E;
15020
            }
15021
            /* Check previously seen. */
15022
            /* Only once after ClientHello.
15023
             * HelloRetryRequest has ServerHello type but count fixed up later
15024
             * - see DoTls13ServerHello().
15025
             */
15026
            if (ssl->msgsReceived.got_server_hello) {
15027
                WOLFSSL_MSG("Duplicate ServerHello received");
15028
                WOLFSSL_ERROR_VERBOSE(DUPLICATE_MSG_E);
15029
                return DUPLICATE_MSG_E;
15030
            }
15031
            ssl->msgsReceived.got_server_hello = 1;
15032
15033
            break;
15034
#endif
15035
15036
#ifndef NO_WOLFSSL_CLIENT
15037
        case session_ticket:
15038
        #ifndef NO_WOLFSSL_SERVER
15039
            /* Only valid when received on CLIENT side. */
15040
            if (ssl->options.side == WOLFSSL_SERVER_END) {
15041
                WOLFSSL_MSG("NewSessionTicket received by server");
15042
                WOLFSSL_ERROR_VERBOSE(SIDE_ERROR);
15043
                return SIDE_ERROR;
15044
            }
15045
        #endif
15046
            /* Check state. */
15047
        #ifdef WOLFSSL_TLS13_TICKET_BEFORE_FINISHED
15048
            /* Only allowed after server's Finished message. */
15049
            if (ssl->options.serverState < SERVER_FINISHED_COMPLETE) {
15050
                WOLFSSL_MSG("NewSessionTicket received out of order");
15051
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15052
                return OUT_OF_ORDER_E;
15053
            }
15054
        #else
15055
            /* Only allowed after client's Finished message. */
15056
            if (ssl->options.clientState < CLIENT_FINISHED_COMPLETE) {
15057
                WOLFSSL_MSG("NewSessionTicket received out of order");
15058
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15059
                return OUT_OF_ORDER_E;
15060
            }
15061
        #endif
15062
            /* Many SessionTickets can be sent. */
15063
            ssl->msgsReceived.got_session_ticket = 1;
15064
15065
            break;
15066
#endif
15067
15068
#ifndef NO_WOLFSSL_SERVER
15069
    #ifdef WOLFSSL_EARLY_DATA
15070
        case end_of_early_data:
15071
        #ifndef NO_WOLFSSL_CLIENT
15072
            /* Only valid when received on SERVER side. */
15073
            if (ssl->options.side == WOLFSSL_CLIENT_END) {
15074
                WOLFSSL_MSG("EndOfEarlyData received by client");
15075
                WOLFSSL_ERROR_VERBOSE(SIDE_ERROR);
15076
                return SIDE_ERROR;
15077
            }
15078
        #endif
15079
            /* Check state. */
15080
            /* Only after server's Finished and before client's Finished. */
15081
            if (ssl->options.serverState < SERVER_FINISHED_COMPLETE) {
15082
                WOLFSSL_MSG("EndOfEarlyData received out of order");
15083
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15084
                return OUT_OF_ORDER_E;
15085
            }
15086
            if (ssl->options.clientState >= CLIENT_FINISHED_COMPLETE) {
15087
                WOLFSSL_MSG("EndOfEarlyData received out of order");
15088
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15089
                return OUT_OF_ORDER_E;
15090
            }
15091
            /* Check previously seen. */
15092
            if (ssl->msgsReceived.got_end_of_early_data) {
15093
                WOLFSSL_MSG("Too many EndOfEarlyData received");
15094
                WOLFSSL_ERROR_VERBOSE(DUPLICATE_MSG_E);
15095
                return DUPLICATE_MSG_E;
15096
            }
15097
            ssl->msgsReceived.got_end_of_early_data = 1;
15098
15099
            break;
15100
    #endif
15101
#endif
15102
15103
#ifndef NO_WOLFSSL_CLIENT
15104
        case encrypted_extensions:
15105
        #ifndef NO_WOLFSSL_SERVER
15106
            /* Only valid when received on CLIENT side. */
15107
            if (ssl->options.side == WOLFSSL_SERVER_END) {
15108
                WOLFSSL_MSG("EncryptedExtensions received by server");
15109
                WOLFSSL_ERROR_VERBOSE(SIDE_ERROR);
15110
                return SIDE_ERROR;
15111
            }
15112
        #endif
15113
            /* Check state. */
15114
            /* Must be received directly after ServerHello.
15115
             * DoTls13EncryptedExtensions() changes state to:
15116
             *   SERVER_ENCRYPTED_EXTENSIONS_COMPLETE.
15117
             */
15118
            if (ssl->options.serverState != SERVER_HELLO_COMPLETE) {
15119
                WOLFSSL_MSG("EncryptedExtensions received out of order");
15120
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15121
                return OUT_OF_ORDER_E;
15122
            }
15123
            /* Check previously seen. */
15124
            if (ssl->msgsReceived.got_encrypted_extensions) {
15125
                WOLFSSL_MSG("Duplicate EncryptedExtensions received");
15126
                WOLFSSL_ERROR_VERBOSE(DUPLICATE_MSG_E);
15127
                return DUPLICATE_MSG_E;
15128
            }
15129
            ssl->msgsReceived.got_encrypted_extensions = 1;
15130
15131
            break;
15132
#endif
15133
15134
        case certificate:
15135
            /* Valid on both sides. */
15136
    #ifndef NO_WOLFSSL_CLIENT
15137
            /* Check state. */
15138
            /* On client, seen after EncryptedExtension and CertificateRequest
15139
             * (if sent) and before CertificateVerify and Finished.
15140
             * DoTls13Certificate() sets serverState to SERVER_CERT_COMPLETE.
15141
             */
15142
            if (ssl->options.side == WOLFSSL_CLIENT_END &&
15143
                ssl->options.serverState !=
15144
                                         SERVER_ENCRYPTED_EXTENSIONS_COMPLETE) {
15145
                WOLFSSL_MSG("Certificate received out of order - Client");
15146
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15147
                return OUT_OF_ORDER_E;
15148
            }
15149
        #if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
15150
            /* Server's authenticating with PSK must not send this. */
15151
            if (ssl->options.side == WOLFSSL_CLIENT_END &&
15152
                             ssl->options.serverState == SERVER_CERT_COMPLETE &&
15153
                             ssl->options.pskNegotiated
15154
#ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
15155
                             && !ssl->options.certWithExternPsk
15156
#endif
15157
               ) {
15158
                WOLFSSL_MSG("Certificate received while using PSK");
15159
                WOLFSSL_ERROR_VERBOSE(SANITY_MSG_E);
15160
                return SANITY_MSG_E;
15161
            }
15162
        #endif
15163
    #endif
15164
    #ifndef NO_WOLFSSL_SERVER
15165
            /* Check state. */
15166
            /* On Server, valid after ClientHello received and ServerFinished
15167
             * sent. */
15168
            if (ssl->options.side == WOLFSSL_SERVER_END &&
15169
                ssl->options.clientState != CLIENT_HELLO_COMPLETE &&
15170
                ssl->options.serverState < SERVER_FINISHED_COMPLETE) {
15171
                WOLFSSL_MSG("Certificate received out of order - Server");
15172
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15173
                return OUT_OF_ORDER_E;
15174
            }
15175
        #if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
15176
            /* RFC 8446 4.4.2: the client only sends this in response to a
15177
             * CertificateRequest, which a server authenticating with a PSK
15178
             * does not send in the main handshake (but may post-handshake). */
15179
            if (ssl->options.side == WOLFSSL_SERVER_END &&
15180
                ssl->options.pskNegotiated && !TLS13_AFTER_HANDSHAKE(ssl)
15181
#ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
15182
                && !ssl->options.certWithExternPsk
15183
#endif
15184
               ) {
15185
                WOLFSSL_MSG("Certificate received while using PSK - Server");
15186
                WOLFSSL_ERROR_VERBOSE(SANITY_MSG_E);
15187
                return SANITY_MSG_E;
15188
            }
15189
        #endif
15190
    #endif
15191
            /* Check previously seen. */
15192
            if (ssl->msgsReceived.got_certificate) {
15193
                WOLFSSL_MSG("Duplicate Certificate received");
15194
                WOLFSSL_ERROR_VERBOSE(DUPLICATE_MSG_E);
15195
                return DUPLICATE_MSG_E;
15196
            }
15197
            ssl->msgsReceived.got_certificate = 1;
15198
15199
            break;
15200
15201
#ifndef NO_WOLFSSL_CLIENT
15202
        case certificate_request:
15203
        #ifndef NO_WOLFSSL_SERVER
15204
            /* Only valid when received on CLIENT side. */
15205
            if (ssl->options.side == WOLFSSL_SERVER_END) {
15206
                WOLFSSL_MSG("CertificateRequest received by server");
15207
                WOLFSSL_ERROR_VERBOSE(SIDE_ERROR);
15208
                return SIDE_ERROR;
15209
            }
15210
        #endif
15211
            /* Check state. */
15212
        #ifndef WOLFSSL_POST_HANDSHAKE_AUTH
15213
            /* Only valid when sent after EncryptedExtensions and before
15214
             * Certificate. */
15215
            if (ssl->options.serverState !=
15216
                                         SERVER_ENCRYPTED_EXTENSIONS_COMPLETE) {
15217
                WOLFSSL_MSG("CertificateRequest received out of order");
15218
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15219
                return OUT_OF_ORDER_E;
15220
            }
15221
        #else
15222
            /* Valid when sent after EncryptedExtensions and before Certificate
15223
             * and after both client and server have sent Finished (Post
15224
             * Handshake Authentication). */
15225
            if (ssl->options.serverState !=
15226
                                         SERVER_ENCRYPTED_EXTENSIONS_COMPLETE &&
15227
                       (ssl->options.serverState < SERVER_FINISHED_COMPLETE ||
15228
                        ssl->options.clientState != CLIENT_FINISHED_COMPLETE)) {
15229
                WOLFSSL_MSG("CertificateRequest received out of order");
15230
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15231
                return OUT_OF_ORDER_E;
15232
            }
15233
            /* RFC 8446 4.6.2: A client that receives a post-handshake
15234
             * CertificateRequest message without having sent the
15235
             * "post_handshake_auth" extension MUST send an
15236
             * "unexpected_message" fatal alert. wolfSSL_allow_post_handshake_auth()
15237
             * must be called before wolfSSL_connect() so postHandshakeAuth
15238
             * reflects whether the extension was offered. */
15239
            if (ssl->options.serverState >= SERVER_FINISHED_COMPLETE &&
15240
                ssl->options.clientState == CLIENT_FINISHED_COMPLETE &&
15241
                !ssl->options.postHandshakeAuth) {
15242
                WOLFSSL_MSG("Post-handshake CertificateRequest received "
15243
                            "without having sent post_handshake_auth "
15244
                            "extension");
15245
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15246
                return OUT_OF_ORDER_E;
15247
            }
15248
        #endif
15249
        #if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
15250
            /* RFC 8446 4.3.2: a server authenticating with a PSK must not send
15251
             * this in the main handshake, but may send it post-handshake. */
15252
            if (ssl->options.pskNegotiated && !TLS13_AFTER_HANDSHAKE(ssl)
15253
#ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
15254
                && !ssl->options.certWithExternPsk
15255
#endif
15256
               ) {
15257
                WOLFSSL_MSG("CertificateRequest received while using PSK");
15258
                WOLFSSL_ERROR_VERBOSE(SANITY_MSG_E);
15259
                return SANITY_MSG_E;
15260
            }
15261
        #endif
15262
            /* Check previously seen. */
15263
        #ifndef WOLFSSL_POST_HANDSHAKE_AUTH
15264
            /* Only once during handshake. */
15265
            if (ssl->msgsReceived.got_certificate_request) {
15266
                WOLFSSL_MSG("Duplicate CertificateRequest received");
15267
                WOLFSSL_ERROR_VERBOSE(DUPLICATE_MSG_E);
15268
                return DUPLICATE_MSG_E;
15269
            }
15270
        #else
15271
            /* Only once during handshake. */
15272
            if (ssl->msgsReceived.got_certificate_request &&
15273
                ssl->options.clientState != CLIENT_FINISHED_COMPLETE) {
15274
                WOLFSSL_MSG("Duplicate CertificateRequest received");
15275
                WOLFSSL_ERROR_VERBOSE(DUPLICATE_MSG_E);
15276
                return DUPLICATE_MSG_E;
15277
            }
15278
        #endif
15279
            ssl->msgsReceived.got_certificate_request = 1;
15280
15281
            break;
15282
#endif
15283
15284
        case certificate_verify:
15285
            /* Valid on both sides. */
15286
    #ifndef NO_WOLFSSL_CLIENT
15287
            /* Check state on client.
15288
             * Valid only directly after a Certificate message. */
15289
            if (ssl->options.side == WOLFSSL_CLIENT_END) {
15290
                if (ssl->options.serverState != SERVER_CERT_COMPLETE) {
15291
                    WOLFSSL_MSG("No Cert before CertVerify");
15292
                    WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15293
                    return OUT_OF_ORDER_E;
15294
                }
15295
            #if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
15296
                /* Server's authenticating with PSK must not send this. */
15297
                if (ssl->options.pskNegotiated
15298
#ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
15299
                    && !ssl->options.certWithExternPsk
15300
#endif
15301
                   ) {
15302
                    WOLFSSL_MSG("CertificateVerify received while using PSK");
15303
                    WOLFSSL_ERROR_VERBOSE(SANITY_MSG_E);
15304
                    return SANITY_MSG_E;
15305
                }
15306
            #endif
15307
            }
15308
    #endif
15309
    #ifndef NO_WOLFSSL_SERVER
15310
            /* Check state on server. */
15311
            if (ssl->options.side == WOLFSSL_SERVER_END) {
15312
                /* Server must have sent Finished message. */
15313
                if (ssl->options.serverState < SERVER_FINISHED_COMPLETE) {
15314
                    WOLFSSL_MSG("CertificateVerify received out of order");
15315
                    WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15316
                    return OUT_OF_ORDER_E;
15317
                }
15318
                /* Valid only directly after a Certificate message. */
15319
                if (ssl->options.clientState < CLIENT_HELLO_COMPLETE) {
15320
                    WOLFSSL_MSG("CertificateVerify before ClientHello done");
15321
                    WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15322
                    return OUT_OF_ORDER_E;
15323
                }
15324
                if (!ssl->msgsReceived.got_certificate) {
15325
                    WOLFSSL_MSG("No Cert before CertificateVerify");
15326
                    WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15327
                    return OUT_OF_ORDER_E;
15328
                }
15329
            }
15330
    #endif
15331
            /* Check previously seen. */
15332
            if (ssl->msgsReceived.got_certificate_verify) {
15333
                WOLFSSL_MSG("Duplicate CertificateVerify received");
15334
                WOLFSSL_ERROR_VERBOSE(DUPLICATE_MSG_E);
15335
                return DUPLICATE_MSG_E;
15336
            }
15337
            ssl->msgsReceived.got_certificate_verify = 1;
15338
15339
            break;
15340
15341
        case finished:
15342
            /* Valid on both sides. */
15343
        #ifndef NO_WOLFSSL_CLIENT
15344
            /* Check state on client. */
15345
            if (ssl->options.side == WOLFSSL_CLIENT_END) {
15346
                /* After sending ClientHello */
15347
                if (ssl->options.clientState < CLIENT_HELLO_COMPLETE) {
15348
                    WOLFSSL_MSG("Finished received out of order - clientState");
15349
                    WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15350
                    return OUT_OF_ORDER_E;
15351
                }
15352
                /* Must have seen certificate and verify from server except when
15353
                 * using PSK. */
15354
            #if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
15355
                if (ssl->options.pskNegotiated) {
15356
#ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
15357
                    if (ssl->options.certWithExternPsk) {
15358
                        if (ssl->options.serverState !=
15359
                                                SERVER_CERT_VERIFY_COMPLETE) {
15360
                            WOLFSSL_MSG("Finished received out of order - "
15361
                                        "cert_with_extern_psk");
15362
                            WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15363
                            return OUT_OF_ORDER_E;
15364
                        }
15365
                    }
15366
                    else
15367
#endif
15368
                    {
15369
                        if (ssl->options.serverState !=
15370
                                         SERVER_ENCRYPTED_EXTENSIONS_COMPLETE) {
15371
                            WOLFSSL_MSG("Finished received out of order - PSK");
15372
                            WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15373
                            return OUT_OF_ORDER_E;
15374
                        }
15375
                    }
15376
                }
15377
                else
15378
            #endif
15379
                if (ssl->options.serverState != SERVER_CERT_VERIFY_COMPLETE) {
15380
                    WOLFSSL_MSG("Finished received out of order - serverState");
15381
                    WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15382
                    return OUT_OF_ORDER_E;
15383
                }
15384
            }
15385
        #endif
15386
        #ifndef NO_WOLFSSL_SERVER
15387
            /* Check state on server. */
15388
            if (ssl->options.side == WOLFSSL_SERVER_END) {
15389
                if (ssl->options.serverState < SERVER_FINISHED_COMPLETE) {
15390
                    WOLFSSL_MSG("Finished received out of order - serverState");
15391
                    WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15392
                    return OUT_OF_ORDER_E;
15393
                }
15394
                if (ssl->options.clientState < CLIENT_HELLO_COMPLETE) {
15395
                    WOLFSSL_MSG("Finished received out of order - clientState");
15396
                    WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15397
                    return OUT_OF_ORDER_E;
15398
                }
15399
            #ifdef WOLFSSL_EARLY_DATA
15400
                if (ssl->earlyData == process_early_data &&
15401
                    /* early data may be lost when using DTLS */
15402
                    !ssl->options.dtls
15403
                    /* QUIC does not use EndOfEarlyData records */
15404
                    && !WOLFSSL_IS_QUIC(ssl)) {
15405
                    WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15406
                    return OUT_OF_ORDER_E;
15407
                }
15408
            #endif
15409
            }
15410
        #endif
15411
        #if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
15412
            if (!ssl->options.pskNegotiated ||
15413
                (ssl->options.side == WOLFSSL_SERVER_END &&
15414
                 TLS13_AFTER_HANDSHAKE(ssl))
15415
#ifdef WOLFSSL_CERT_WITH_EXTERN_PSK
15416
                || ssl->options.certWithExternPsk
15417
#endif
15418
            )
15419
        #endif
15420
            {
15421
                /* Must have received a Certificate message from client if
15422
                 * verifying the peer. Empty certificate message indicates
15423
                 * no certificate available.
15424
                 */
15425
                if (ssl->options.verifyPeer &&
15426
                #ifdef WOLFSSL_POST_HANDSHAKE_AUTH
15427
                    /* The post-handshake-auth exemption is only valid during
15428
                     * the enclosing handshake. Once the server has requested a
15429
                     * certificate post-handshake, one is required again.
15430
                     * Whether an empty Certificate is then accepted follows the
15431
                     * verify mode (FAIL_IF_NO_PEER_CERT), exactly as for
15432
                     * first-handshake client authentication. */
15433
                    (!ssl->options.verifyPostHandshake ||
15434
                     TLS13_AFTER_HANDSHAKE(ssl)) &&
15435
                #endif
15436
                                           !ssl->msgsReceived.got_certificate) {
15437
                    WOLFSSL_MSG("Finished received out of order - "
15438
                                "missing Certificate message");
15439
                    WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15440
                    return OUT_OF_ORDER_E;
15441
                }
15442
                /* Mutual authentication on server requires a certificate from
15443
                 * peer. Verify peer set on client side requires a certificate
15444
                 * from peer as not doing PSK.
15445
                 */
15446
                if ((ssl->options.mutualAuth ||
15447
                    (ssl->options.side == WOLFSSL_CLIENT_END &&
15448
                     ssl->options.verifyPeer)) && !ssl->options.havePeerCert) {
15449
                    WOLFSSL_MSG("Finished received out of order - "
15450
                                "no valid certificate");
15451
                    WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15452
                    return OUT_OF_ORDER_E;
15453
                }
15454
            }
15455
            /* Must have received a valid CertificateVerify if got a peer
15456
             * certificate. A certificate without proof of possession is never
15457
             * acceptable, regardless of how the handshake was authenticated.
15458
             */
15459
            if (ssl->options.havePeerCert && !ssl->options.havePeerVerify) {
15460
                WOLFSSL_MSG("Finished received out of order - "
15461
                            "Certificate message but no CertificateVerify");
15462
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15463
                return OUT_OF_ORDER_E;
15464
            }
15465
            /* Check previously seen. */
15466
            if (ssl->msgsReceived.got_finished) {
15467
                WOLFSSL_MSG("Duplicate Finished received");
15468
                WOLFSSL_ERROR_VERBOSE(DUPLICATE_MSG_E);
15469
                return DUPLICATE_MSG_E;
15470
            }
15471
            ssl->msgsReceived.got_finished = 1;
15472
15473
            break;
15474
15475
        case key_update:
15476
            /* Valid on both sides. */
15477
#ifdef WOLFSSL_QUIC
15478
            /* RFC 9001 Section 6: QUIC performs key updates at the QUIC
15479
             * packet-protection layer, so a TLS KeyUpdate message must be
15480
             * rejected as a fatal unexpected_message connection error. */
15481
            if (WOLFSSL_IS_QUIC(ssl)) {
15482
                WOLFSSL_MSG("KeyUpdate received over QUIC");
15483
                WOLFSSL_ERROR_VERBOSE(SANITY_MSG_E);
15484
                return SANITY_MSG_E;
15485
            }
15486
#endif
15487
            /* Check state.
15488
             * Client and server must have received finished message from other
15489
             * side.
15490
             */
15491
            if (!ssl->msgsReceived.got_finished) {
15492
                WOLFSSL_MSG("No KeyUpdate before Finished");
15493
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15494
                return OUT_OF_ORDER_E;
15495
            }
15496
            /* Multiple KeyUpdates can be sent. */
15497
            break;
15498
#if defined(WOLFSSL_DTLS13) && !defined(WOLFSSL_NO_TLS12)
15499
        case hello_verify_request:
15500
            if (!ssl->options.dtls) {
15501
                WOLFSSL_MSG("HelloVerifyRequest when not in DTLS");
15502
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15503
                return OUT_OF_ORDER_E;
15504
            }
15505
            if (ssl->msgsReceived.got_hello_verify_request) {
15506
                WOLFSSL_MSG("Duplicate HelloVerifyRequest received");
15507
                WOLFSSL_ERROR_VERBOSE(DUPLICATE_MSG_E);
15508
                return DUPLICATE_MSG_E;
15509
            }
15510
            ssl->msgsReceived.got_hello_verify_request = 1;
15511
            if (ssl->msgsReceived.got_hello_retry_request) {
15512
                WOLFSSL_MSG(
15513
                    "Both HelloVerifyRequest and HelloRetryRequest received");
15514
                WOLFSSL_ERROR_VERBOSE(DUPLICATE_MSG_E);
15515
                return DUPLICATE_MSG_E;
15516
            }
15517
            if (ssl->options.serverState >=
15518
                    SERVER_HELLO_RETRY_REQUEST_COMPLETE ||
15519
                ssl->options.connectState != CLIENT_HELLO_SENT) {
15520
                WOLFSSL_MSG("HelloVerifyRequest received out of order");
15521
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15522
                return OUT_OF_ORDER_E;
15523
            }
15524
            if (ssl->options.side == WOLFSSL_SERVER_END) {
15525
                WOLFSSL_MSG("HelloVerifyRequest received on the server");
15526
                WOLFSSL_ERROR_VERBOSE(SIDE_ERROR);
15527
                return SIDE_ERROR;
15528
            }
15529
            if (!ssl->options.downgrade ||
15530
                ssl->options.minDowngrade < DTLSv1_2_MINOR) {
15531
                WOLFSSL_MSG(
15532
                    "HelloVerifyRequest received but not DTLSv1.2 allowed");
15533
                WOLFSSL_ERROR_VERBOSE(VERSION_ERROR);
15534
                return VERSION_ERROR;
15535
            }
15536
            break;
15537
#endif /* WOLFSSL_DTLS13 && !WOLFSSL_NO_TLS12*/
15538
15539
#if defined(WOLFSSL_DTLS13) && defined(WOLFSSL_DTLS_CID)
15540
        case request_connection_id:
15541
        case new_connection_id:
15542
        {
15543
            CIDInfo* cidInfo = ssl->dtlsCidInfo;
15544
15545
            /* DTLS 1.3 only (RFC 9147) */
15546
            if (!ssl->options.dtls) {
15547
                WOLFSSL_MSG("CID message received but not DTLS");
15548
                WOLFSSL_ERROR_VERBOSE(SANITY_MSG_E);
15549
                return SANITY_MSG_E;
15550
            }
15551
            /* RFC 9147 Section 9: if CIDs were not negotiated, MUST abort
15552
             * with an unexpected_message alert */
15553
            if (cidInfo == NULL || !cidInfo->negotiated) {
15554
                WOLFSSL_MSG("CID message received but CID not negotiated");
15555
                WOLFSSL_ERROR_VERBOSE(SANITY_MSG_E);
15556
                return SANITY_MSG_E;
15557
            }
15558
            if (ssl->options.handShakeState != HANDSHAKE_DONE) {
15559
                WOLFSSL_MSG("CID message received out of order");
15560
                WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15561
                return OUT_OF_ORDER_E;
15562
            }
15563
            if (type == request_connection_id) {
15564
                /* the peer MUST NOT request CIDs while sending an empty
15565
                 * CID itself */
15566
                if (cidInfo->rx == NULL || cidInfo->rx->length == 0) {
15567
                    WOLFSSL_MSG("RequestConnectionId from peer sending an "
15568
                                "empty CID");
15569
                    WOLFSSL_ERROR_VERBOSE(SANITY_MSG_E);
15570
                    return SANITY_MSG_E;
15571
                }
15572
            }
15573
            else {
15574
                /* the peer MUST NOT issue CIDs after negotiating receiving
15575
                 * an empty CID */
15576
                if (cidInfo->tx == NULL || cidInfo->tx->length == 0) {
15577
                    WOLFSSL_MSG("NewConnectionId from peer that negotiated "
15578
                                "an empty CID");
15579
                    WOLFSSL_ERROR_VERBOSE(SANITY_MSG_E);
15580
                    return SANITY_MSG_E;
15581
                }
15582
            }
15583
            break;
15584
        }
15585
#endif /* WOLFSSL_DTLS13 && WOLFSSL_DTLS_CID */
15586
15587
        default:
15588
            WOLFSSL_MSG("Unknown message type");
15589
            WOLFSSL_ERROR_VERBOSE(SANITY_MSG_E);
15590
            return SANITY_MSG_E;
15591
    }
15592
15593
    return 0;
15594
}
15595
15596
/* Handle a type of handshake message that has been received.
15597
 *
15598
 * ssl       The SSL/TLS object.
15599
 * input     The message buffer.
15600
 * inOutIdx  On entry, the index into the buffer of the current message.
15601
 *           On exit, the index into the buffer of the next message.
15602
 * size      The length of the current handshake message.
15603
 * totalSz   Length of remaining data in the message buffer.
15604
 * returns 0 on success and otherwise failure.
15605
 */
15606
/* Run the key schedule belonging to a just-processed handshake message.
15607
 * A pend here cannot replay the message (its handler already advanced
15608
 * state); the record is consumed and this is called again from
15609
 * DoProcessReplyEx() entry, pre-dispatch, or the reply-loop exits.
15610
 * Returns 0, WC_PENDING_E while the device is busy, else an error. */
15611
int DoTls13MsgDerives(WOLFSSL* ssl, byte type)
15612
0
{
15613
0
    int ret = 0;
15614
15615
0
    (void)ssl;
15616
0
    (void)type;
15617
15618
0
#ifndef NO_WOLFSSL_CLIENT
15619
0
    if (ssl->options.side == WOLFSSL_CLIENT_END) {
15620
0
        if (type == server_hello) {
15621
            /* Entered before the first derive, or a pend there would
15622
             * route the retry back to the message handler. */
15623
0
            if (ssl->kdfMsgStep == TLS13_MSG_KDF_NONE) {
15624
0
                ssl->kdfMsgStep = TLS13_MSG_KDF_SH_ENTERED;
15625
0
                ssl->kdfMsgType = type;
15626
0
            }
15627
15628
0
            if (ssl->kdfMsgStep <= TLS13_MSG_KDF_SH_ENTERED) {
15629
0
                ret = DeriveEarlySecret(ssl);
15630
0
                if (ret != 0) {
15631
0
                    if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
15632
0
                        ssl->kdfMsgStep = TLS13_MSG_KDF_NONE;
15633
0
                    return ret;
15634
0
                }
15635
0
                ssl->kdfMsgStep = TLS13_MSG_KDF_SH_EARLY_SECRET;
15636
0
            }
15637
0
            if (ssl->kdfMsgStep <= TLS13_MSG_KDF_SH_EARLY_SECRET) {
15638
0
                ret = DeriveHandshakeSecret(ssl);
15639
0
                if (ret != 0) {
15640
0
                    if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
15641
0
                        ssl->kdfMsgStep = TLS13_MSG_KDF_NONE;
15642
0
                    return ret;
15643
0
                }
15644
0
                ssl->kdfMsgStep = TLS13_MSG_KDF_SH_HS_SECRET;
15645
0
            }
15646
0
            if (ssl->kdfMsgStep <= TLS13_MSG_KDF_SH_HS_SECRET) {
15647
0
                ret = DeriveTls13Keys(ssl, handshake_key,
15648
0
                                      ENCRYPT_AND_DECRYPT_SIDE, 1);
15649
0
                if (ret != 0) {
15650
0
                    if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
15651
0
                        ssl->kdfMsgStep = TLS13_MSG_KDF_NONE;
15652
0
                    return ret;
15653
0
                }
15654
0
                ssl->kdfMsgStep = TLS13_MSG_KDF_SH_HS_KEYS;
15655
0
            }
15656
    #ifdef WOLFSSL_EARLY_DATA
15657
            if (ssl->earlyData != no_early_data) {
15658
                if (ssl->kdfMsgStep <= TLS13_MSG_KDF_SH_HS_KEYS) {
15659
                    ret = SetKeysSide(ssl, DECRYPT_SIDE_ONLY);
15660
                    if (ret != 0) {
15661
                        if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
15662
                            ssl->kdfMsgStep = TLS13_MSG_KDF_NONE;
15663
                        return ret;
15664
                    }
15665
                    ssl->kdfMsgStep = TLS13_MSG_KDF_SH_KEYS_SET;
15666
                }
15667
            }
15668
            else
15669
    #endif
15670
0
            {
15671
0
                if (ssl->kdfMsgStep <= TLS13_MSG_KDF_SH_HS_KEYS) {
15672
0
                    ret = SetKeysSide(ssl, ENCRYPT_AND_DECRYPT_SIDE);
15673
0
                    if (ret != 0) {
15674
0
                        if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
15675
0
                            ssl->kdfMsgStep = TLS13_MSG_KDF_NONE;
15676
0
                        return ret;
15677
0
                    }
15678
0
                    ssl->kdfMsgStep = TLS13_MSG_KDF_SH_KEYS_SET;
15679
0
                }
15680
0
            }
15681
15682
#ifdef WOLFSSL_DTLS13
15683
            if (ssl->options.dtls) {
15684
                w64wrapper epochHandshake;
15685
                epochHandshake = w64From32(0, DTLS13_EPOCH_HANDSHAKE);
15686
                ssl->dtls13Epoch = epochHandshake;
15687
                ssl->dtls13PeerEpoch = epochHandshake;
15688
15689
                if (ssl->kdfMsgStep <= TLS13_MSG_KDF_SH_KEYS_SET) {
15690
                    ret = Dtls13SetEpochKeys(ssl, epochHandshake,
15691
                                             ENCRYPT_AND_DECRYPT_SIDE);
15692
                    if (ret != 0) {
15693
                        if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
15694
                            ssl->kdfMsgStep = TLS13_MSG_KDF_NONE;
15695
                        return ret;
15696
                    }
15697
                    ssl->kdfMsgStep = TLS13_MSG_KDF_SH_DTLS_EPOCH;
15698
                }
15699
            }
15700
#endif /* WOLFSSL_DTLS13 */
15701
0
            ssl->kdfMsgStep = TLS13_MSG_KDF_NONE;
15702
0
        }
15703
15704
0
        if (type == finished) {
15705
            /* Mark the phase entered before the first derive, so a pending
15706
             * there still routes the retry back here. */
15707
0
            if (ssl->kdfMsgStep == TLS13_MSG_KDF_NONE) {
15708
0
                ssl->kdfMsgStep = TLS13_MSG_KDF_FIN_ENTERED;
15709
0
                ssl->kdfMsgType = type;
15710
0
            }
15711
15712
0
            if (ssl->kdfMsgStep <= TLS13_MSG_KDF_FIN_ENTERED) {
15713
0
                if ((ret = DeriveMasterSecret(ssl)) != 0) {
15714
0
                    if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
15715
0
                        ssl->kdfMsgStep = TLS13_MSG_KDF_NONE;
15716
0
                    return ret;
15717
0
                }
15718
                /* Zeroized only after the derive completed: a pend retry
15719
                 * still reads preMasterSecret. */
15720
0
                ForceZero(ssl->arrays->preMasterSecret,
15721
0
                    ssl->arrays->preMasterSz);
15722
0
                ssl->kdfMsgStep = TLS13_MSG_KDF_FIN_MASTER_SECRET;
15723
0
            }
15724
    #ifdef WOLFSSL_EARLY_DATA
15725
    #ifdef WOLFSSL_QUIC
15726
            if (ssl->kdfMsgStep <= TLS13_MSG_KDF_FIN_MASTER_SECRET) {
15727
                if (WOLFSSL_IS_QUIC(ssl) &&
15728
                        ssl->earlyData != no_early_data) {
15729
                    /* QUIC never sends/receives EndOfEarlyData, but
15730
                     * having early data means the last encryption keys
15731
                     * had not been set yet. */
15732
                    if ((ret = SetKeysSide(ssl, ENCRYPT_SIDE_ONLY)) != 0) {
15733
                        if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
15734
                            ssl->kdfMsgStep = TLS13_MSG_KDF_NONE;
15735
                        return ret;
15736
                    }
15737
                }
15738
                ssl->kdfMsgStep = TLS13_MSG_KDF_FIN_QUIC_EARLY_KEYS;
15739
            }
15740
    #endif
15741
            if (ssl->kdfMsgStep <= TLS13_MSG_KDF_FIN_QUIC_EARLY_KEYS) {
15742
                ret = DeriveTls13Keys(ssl, traffic_key,
15743
                            ENCRYPT_AND_DECRYPT_SIDE,
15744
                            ssl->earlyData == no_early_data);
15745
                if (ret != 0) {
15746
                    if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
15747
                        ssl->kdfMsgStep = TLS13_MSG_KDF_NONE;
15748
                    return ret;
15749
                }
15750
                ssl->kdfMsgStep = TLS13_MSG_KDF_FIN_TRAFFIC_KEYS;
15751
            }
15752
            if (ssl->earlyData != no_early_data) {
15753
                if (ssl->kdfMsgStep <= TLS13_MSG_KDF_FIN_TRAFFIC_KEYS) {
15754
                    if ((ret = DeriveTls13Keys(ssl, no_key,
15755
                                            DECRYPT_SIDE_ONLY, 1)) != 0) {
15756
                        if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
15757
                            ssl->kdfMsgStep = TLS13_MSG_KDF_NONE;
15758
                        return ret;
15759
                    }
15760
                    ssl->kdfMsgStep = TLS13_MSG_KDF_FIN_TRAFFIC_DONE;
15761
                }
15762
            }
15763
    #else
15764
0
            if (ssl->kdfMsgStep <= TLS13_MSG_KDF_FIN_QUIC_EARLY_KEYS) {
15765
0
                ret = DeriveTls13Keys(ssl, traffic_key,
15766
0
                            ENCRYPT_AND_DECRYPT_SIDE, 1);
15767
0
                if (ret != 0) {
15768
0
                    if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
15769
0
                        ssl->kdfMsgStep = TLS13_MSG_KDF_NONE;
15770
0
                    return ret;
15771
0
                }
15772
0
                ssl->kdfMsgStep = TLS13_MSG_KDF_FIN_TRAFFIC_DONE;
15773
0
            }
15774
0
    #endif
15775
            /* Setup keys for application data messages. */
15776
0
            if (ssl->kdfMsgStep <= TLS13_MSG_KDF_FIN_TRAFFIC_DONE) {
15777
0
                if ((ret = SetKeysSide(ssl, DECRYPT_SIDE_ONLY)) != 0) {
15778
0
                    if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
15779
0
                        ssl->kdfMsgStep = TLS13_MSG_KDF_NONE;
15780
0
                    return ret;
15781
0
                }
15782
0
                ssl->kdfMsgStep = TLS13_MSG_KDF_FIN_KEYS_SET;
15783
0
            }
15784
0
            ssl->kdfMsgStep = TLS13_MSG_KDF_NONE;
15785
0
        }
15786
0
    }
15787
0
#endif /* NO_WOLFSSL_CLIENT */
15788
15789
0
#ifndef NO_WOLFSSL_SERVER
15790
0
    #if defined(HAVE_SESSION_TICKET)
15791
0
        if (ssl->options.side == WOLFSSL_SERVER_END && type == finished) {
15792
0
            if (ssl->kdfMsgStep == TLS13_MSG_KDF_NONE) {
15793
0
                ssl->kdfMsgStep = TLS13_MSG_KDF_SFIN_ENTERED;
15794
0
                ssl->kdfMsgType = type;
15795
0
            }
15796
0
            if (ssl->kdfMsgStep <= TLS13_MSG_KDF_SFIN_ENTERED) {
15797
0
                ret = DeriveResumptionSecret(ssl, ssl->session->masterSecret);
15798
0
                if (ret != 0) {
15799
0
                    if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
15800
0
                        ssl->kdfMsgStep = TLS13_MSG_KDF_NONE;
15801
0
                    return ret;
15802
0
                }
15803
0
                ssl->kdfMsgStep = TLS13_MSG_KDF_SFIN_RESUMPTION_SECRET;
15804
0
            }
15805
0
            ssl->kdfMsgStep = TLS13_MSG_KDF_NONE;
15806
0
        }
15807
0
    #endif
15808
0
#endif /* NO_WOLFSSL_SERVER */
15809
15810
0
    return ret;
15811
0
}
15812
15813
int DoTls13HandShakeMsgType(WOLFSSL* ssl, byte* input, word32* inOutIdx,
15814
                            byte type, word32 size, word32 totalSz)
15815
{
15816
    int ret = 0, tmp;
15817
    word32 inIdx = *inOutIdx;
15818
    int alertType;
15819
    int skipSanity = 0;
15820
#if defined(HAVE_ECH) && !defined(NO_WOLFSSL_SERVER)
15821
    TLSX* echX = NULL;
15822
    word32 echInOutIdx;
15823
#endif
15824
15825
    (void)totalSz;
15826
15827
    WOLFSSL_ENTER("DoTls13HandShakeMsgType");
15828
15829
    /* make sure we can read the message */
15830
    if (*inOutIdx + size > totalSz)
15831
        return INCOMPLETE_DATA;
15832
15833
#ifdef WOLFSSL_ASYNC_CRYPT
15834
    /* A message being replayed after its own handler pended has already
15835
     * passed its sanity check and advanced the got_* state on the first
15836
     * pass; the handler restores its cleared marker on completion. Consume
15837
     * the one-shot marker here so only that replayed message skips the
15838
     * check - messages dispatched after it (ssl->error may still read
15839
     * WC_PENDING_E from a trailing key-schedule pend) are still checked. */
15840
    skipSanity = ssl->options.asyncReplayMsg;
15841
    ssl->options.asyncReplayMsg = 0;
15842
#endif
15843
15844
    /* Sanity check msg received. Skipped on a WC_PENDING_E resume (it
15845
     * would reject the replay against already-advanced state); handlers
15846
     * restore their cleared got_* markers on completion instead. */
15847
    if (!skipSanity &&
15848
            (ret = SanityCheckTls13MsgReceived(ssl, type)) != 0) {
15849
        WOLFSSL_MSG("Sanity Check on handshake message type received failed");
15850
        if (ret == WC_NO_ERR_TRACE(VERSION_ERROR))
15851
            SendAlert(ssl, alert_fatal, wolfssl_alert_protocol_version);
15852
        else
15853
            SendAlert(ssl, alert_fatal, unexpected_message);
15854
        return ret;
15855
    }
15856
15857
#if defined(WOLFSSL_CALLBACKS)
15858
    /* add name later, add on record and handshake header part back on */
15859
    if (ssl->toInfoOn) {
15860
        ret = AddPacketInfo(ssl, 0, handshake, input + *inOutIdx -
15861
            HANDSHAKE_HEADER_SZ, size + HANDSHAKE_HEADER_SZ, READ_PROTO,
15862
            RECORD_HEADER_SZ, ssl->heap);
15863
        if (ret != 0)
15864
            return ret;
15865
        AddLateRecordHeader(&ssl->curRL, &ssl->timeoutInfo);
15866
    }
15867
#endif
15868
15869
    if (ssl->options.handShakeState == HANDSHAKE_DONE &&
15870
            type != session_ticket && type != certificate_request &&
15871
            type != certificate && type != key_update && type != finished
15872
#if defined(WOLFSSL_DTLS13) && defined(WOLFSSL_DTLS_CID)
15873
            && type != request_connection_id && type != new_connection_id
15874
#endif
15875
            ) {
15876
        WOLFSSL_MSG("HandShake message after handshake complete");
15877
        SendAlert(ssl, alert_fatal, unexpected_message);
15878
        WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15879
        return OUT_OF_ORDER_E;
15880
    }
15881
15882
    if (ssl->options.side == WOLFSSL_CLIENT_END &&
15883
               ssl->options.serverState == NULL_STATE &&
15884
               type != server_hello && type != hello_retry_request
15885
#if defined(WOLFSSL_DTLS13) && !defined(WOLFSSL_NO_TLS12)
15886
        && (!ssl->options.dtls || type != hello_verify_request)
15887
#endif /* defined(WOLFSSL_DTLS13) && !defined(WOLFSSL_NO_TLS12) */
15888
        ) {
15889
        WOLFSSL_MSG("First server message not server hello");
15890
        SendAlert(ssl, alert_fatal, unexpected_message);
15891
        WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15892
        return OUT_OF_ORDER_E;
15893
    }
15894
15895
    if (ssl->options.side == WOLFSSL_SERVER_END &&
15896
               ssl->options.clientState == NULL_STATE && type != client_hello) {
15897
        WOLFSSL_MSG("First client message not client hello");
15898
        SendAlert(ssl, alert_fatal, unexpected_message);
15899
        WOLFSSL_ERROR_VERBOSE(OUT_OF_ORDER_E);
15900
        return OUT_OF_ORDER_E;
15901
    }
15902
15903
    /* above checks handshake state */
15904
    /* Finish an earlier message's key schedule before this message is
15905
     * judged: it installs state this one is checked against. */
15906
    if (ssl->kdfMsgStep > 0) {
15907
        ret = DoTls13MsgDerives(ssl, ssl->kdfMsgType);
15908
        if (ret != 0)
15909
            return ret;
15910
        /* A resolved pend must not suppress the next sanity check. */
15911
        if (ssl->error == WC_NO_ERR_TRACE(WC_PENDING_E)) {
15912
            ssl->error = 0;
15913
        }
15914
    }
15915
15916
    switch (type) {
15917
#ifndef NO_WOLFSSL_CLIENT
15918
    /* Messages only received by client. */
15919
    case server_hello:
15920
        WOLFSSL_MSG("processing server hello");
15921
        ret = DoTls13ServerHello(ssl, input, inOutIdx, size, &type);
15922
    #if !defined(WOLFSSL_NO_CLIENT_AUTH) && \
15923
               ((defined(HAVE_ED25519) && !defined(NO_ED25519_CLIENT_AUTH)) || \
15924
                (defined(HAVE_ED448) && !defined(NO_ED448_CLIENT_AUTH)))
15925
        if (ssl->options.resuming || !IsAtLeastTLSv1_2(ssl) ||
15926
                                               IsAtLeastTLSv1_3(ssl->version)) {
15927
            ssl->options.cacheMessages = 0;
15928
            if ((ssl->hsHashes != NULL) && (ssl->hsHashes->messages != NULL)) {
15929
                ForceZero(ssl->hsHashes->messages, ssl->hsHashes->length);
15930
                XFREE(ssl->hsHashes->messages, ssl->heap, DYNAMIC_TYPE_HASHES);
15931
                ssl->hsHashes->messages = NULL;
15932
            }
15933
        }
15934
    #endif
15935
        break;
15936
15937
    case encrypted_extensions:
15938
        WOLFSSL_MSG("processing encrypted extensions");
15939
        ret = DoTls13EncryptedExtensions(ssl, input, inOutIdx, size);
15940
        break;
15941
15942
    #ifndef NO_CERTS
15943
    case certificate_request:
15944
        WOLFSSL_MSG("processing certificate request");
15945
        ret = DoTls13CertificateRequest(ssl, input, inOutIdx, size);
15946
        break;
15947
    #endif
15948
15949
    case session_ticket:
15950
        WOLFSSL_MSG("processing new session ticket");
15951
        ret = DoTls13NewSessionTicket(ssl, input, inOutIdx, size);
15952
        break;
15953
#endif /* !NO_WOLFSSL_CLIENT */
15954
15955
#ifndef NO_WOLFSSL_SERVER
15956
    /* Messages only received by server. */
15957
    case client_hello:
15958
        WOLFSSL_MSG("processing client hello");
15959
#if defined(HAVE_ECH)
15960
        /* keep the start idx so we can restore it for the inner call */
15961
        echInOutIdx = *inOutIdx;
15962
#endif
15963
        ret = DoTls13ClientHello(ssl, input, inOutIdx, size);
15964
    #if !defined(WOLFSSL_NO_CLIENT_AUTH) && \
15965
               ((defined(HAVE_ED25519) && !defined(NO_ED25519_CLIENT_AUTH)) || \
15966
                (defined(HAVE_ED448) && !defined(NO_ED448_CLIENT_AUTH)))
15967
        if ((ssl->options.resuming || !ssl->options.verifyPeer ||
15968
               !IsAtLeastTLSv1_2(ssl) || IsAtLeastTLSv1_3(ssl->version))
15969
        #ifdef WOLFSSL_DTLS13
15970
               && (!ssl->options.dtls)
15971
        #endif
15972
               ) {
15973
        #if defined(WOLFSSL_ASYNC_CRYPT) || defined(WOLFSSL_NONBLOCK_OCSP)
15974
            if (ret != WC_NO_ERR_TRACE(WC_PENDING_E) &&
15975
                ret != WC_NO_ERR_TRACE(OCSP_WANT_READ))
15976
        #endif
15977
            {
15978
                ssl->options.cacheMessages = 0;
15979
                if ((ssl->hsHashes != NULL) &&
15980
                        (ssl->hsHashes->messages != NULL)) {
15981
                    ForceZero(ssl->hsHashes->messages, ssl->hsHashes->length);
15982
                    XFREE(ssl->hsHashes->messages, ssl->heap,
15983
                        DYNAMIC_TYPE_HASHES);
15984
                    ssl->hsHashes->messages = NULL;
15985
                }
15986
            }
15987
        }
15988
    #endif
15989
#if defined(HAVE_ECH)
15990
        if (ret == 0) {
15991
            echX = TLSX_Find(ssl->extensions, TLSX_ECH);
15992
15993
            if (echX != NULL &&
15994
                    ((WOLFSSL_ECH*)echX->data)->state == ECH_WRITE_NONE &&
15995
                    ((WOLFSSL_ECH*)echX->data)->innerClientHello != NULL) {
15996
                byte copyRandom = ((WOLFSSL_ECH*)echX->data)->innerCount == 0;
15997
                /* reset the inOutIdx to the outer start */
15998
                *inOutIdx = echInOutIdx;
15999
                /* call again with the inner hello */
16000
                if (ret == 0) {
16001
                    echInOutIdx = HANDSHAKE_HEADER_SZ;
16002
#ifdef WOLFSSL_DTLS13
16003
                    if (ssl->options.dtls)
16004
                        echInOutIdx = DTLS13_HANDSHAKE_HEADER_SZ;
16005
#endif
16006
                    ssl->options.echProcessingInner = 1;
16007
                    ret = DoTls13ClientHello(ssl,
16008
                        ((WOLFSSL_ECH*)echX->data)->innerClientHello,
16009
                        &echInOutIdx,
16010
                        ((WOLFSSL_ECH*)echX->data)->innerClientHelloLen);
16011
                    ssl->options.echProcessingInner = 0;
16012
                }
16013
                if (ret == 0 && ((WOLFSSL_ECH*)echX->data)->state !=
16014
                        ECH_PARSED_INTERNAL) {
16015
                    WOLFSSL_MSG("ECH: inner ClientHello missing ECH extension");
16016
                    ret = INVALID_PARAMETER;
16017
                }
16018
                /* if the inner ech parsed successfully we have successfully
16019
                 * handled the hello and can skip the whole message */
16020
                if (ret == 0) {
16021
                    /* Copy inner client random for ECH acceptance calculation.
16022
                     * Only on first inner ClientHello (before HRR), not CH2. */
16023
                    if (copyRandom) {
16024
                        XMEMCPY(ssl->arrays->clientRandomInner,
16025
                                ssl->arrays->clientRandom, RAN_LEN);
16026
                    }
16027
                    *inOutIdx += size;
16028
                }
16029
            }
16030
        }
16031
#endif /* HAVE_ECH */
16032
        break;
16033
16034
    #ifdef WOLFSSL_EARLY_DATA
16035
    case end_of_early_data:
16036
        WOLFSSL_MSG("processing end of early data");
16037
        ret = DoTls13EndOfEarlyData(ssl, input, inOutIdx, size);
16038
        break;
16039
    #endif
16040
#endif /* !NO_WOLFSSL_SERVER */
16041
16042
    /* Messages received by both client and server. */
16043
#if !defined(NO_CERTS) && (!defined(NO_WOLFSSL_CLIENT) || \
16044
                           !defined(WOLFSSL_NO_CLIENT_AUTH))
16045
    case certificate:
16046
        WOLFSSL_MSG("processing certificate");
16047
        ret = DoTls13Certificate(ssl, input, inOutIdx, size);
16048
        break;
16049
#endif
16050
16051
#if (!defined(NO_RSA) || defined(HAVE_ECC) || defined(HAVE_ED25519) || \
16052
     defined(HAVE_ED448) || defined(HAVE_FALCON) || \
16053
     defined(WOLFSSL_HAVE_MLDSA) || defined(WOLFSSL_HAVE_SLHDSA)) && \
16054
    !defined(NO_CERTS)
16055
    case certificate_verify:
16056
        WOLFSSL_MSG("processing certificate verify");
16057
        ret = DoTls13CertificateVerify(ssl, input, inOutIdx, size);
16058
        break;
16059
#endif
16060
    case finished:
16061
        WOLFSSL_MSG("processing finished");
16062
        ret = DoTls13Finished(ssl, input, inOutIdx, size, totalSz, NO_SNIFF);
16063
        break;
16064
16065
    case key_update:
16066
        WOLFSSL_MSG("processing key update");
16067
        ret = DoTls13KeyUpdate(ssl, input, inOutIdx, size);
16068
        break;
16069
16070
#if defined(WOLFSSL_DTLS13) && defined(WOLFSSL_DTLS_CID)
16071
    case request_connection_id:
16072
        WOLFSSL_MSG("processing request connection id");
16073
        ret = DoDtls13RequestConnectionId(ssl, input, inOutIdx, size);
16074
        break;
16075
16076
    case new_connection_id:
16077
        WOLFSSL_MSG("processing new connection id");
16078
        ret = DoDtls13NewConnectionId(ssl, input, inOutIdx, size);
16079
        break;
16080
#endif /* WOLFSSL_DTLS13 && WOLFSSL_DTLS_CID */
16081
16082
#if defined(WOLFSSL_DTLS13) && !defined(WOLFSSL_NO_TLS12) && \
16083
    !defined(NO_WOLFSSL_CLIENT)
16084
    case hello_verify_request:
16085
        WOLFSSL_MSG("processing hello verify request");
16086
        ret = DoHelloVerifyRequest(ssl, input, inOutIdx, size);
16087
        break;
16088
#endif
16089
    default:
16090
        WOLFSSL_MSG("Unknown handshake message type");
16091
        ret = UNKNOWN_HANDSHAKE_TYPE;
16092
        break;
16093
    }
16094
16095
#ifdef WOLFSSL_ASYNC_CRYPT
16096
    /* Handler pended: this exact message will be replayed. Mark it so the
16097
     * replay skips its sanity check (it already passed and advanced state).
16098
     * Set from the handler's own ret, before the trailing key-schedule
16099
     * derive below can re-raise WC_PENDING_E for an already-done message. */
16100
    if (ret == WC_NO_ERR_TRACE(WC_PENDING_E))
16101
        ssl->options.asyncReplayMsg = 1;
16102
#endif
16103
16104
#if defined(WOLFSSL_ASYNC_CRYPT) || defined(WOLFSSL_ASYNC_IO)
16105
    /* if async, offset index so this msg will be processed again */
16106
    /* NOTE: check this now before other calls can overwrite ret */
16107
    if ((ret == WC_NO_ERR_TRACE(WC_PENDING_E) ||
16108
         ret == WC_NO_ERR_TRACE(OCSP_WANT_READ)) && *inOutIdx > 0) {
16109
        /* DTLS always stores a message in a buffer when async is enable, so we
16110
         * don't need to adjust for the extra bytes here (*inOutIdx is always
16111
         * == 0) */
16112
        *inOutIdx -= HANDSHAKE_HEADER_SZ;
16113
    }
16114
16115
    /* make sure async error is cleared */
16116
    if (ret == 0 &&
16117
        (ssl->error == WC_NO_ERR_TRACE(WC_PENDING_E) ||
16118
         ssl->error == WC_NO_ERR_TRACE(OCSP_WANT_READ))) {
16119
        ssl->error = 0;
16120
    }
16121
#endif
16122
#if defined(HAVE_WRITE_DUP) && defined(WOLFSSL_POST_HANDSHAKE_AUTH)
16123
    /* Read side: a fresh PHA CertificateRequest. Resume from the transcript
16124
     * the write side published after the previous PHA response, so this CR is
16125
     * hashed onto the same base the server has. */
16126
    if (ret == 0 && type == certificate_request &&
16127
            ssl->options.side == WOLFSSL_CLIENT_END &&
16128
            ssl->dupSide == READ_DUP_SIDE &&
16129
            ssl->options.handShakeState == HANDSHAKE_DONE &&
16130
            ssl->dupWrite != NULL) {
16131
        if (wc_LockMutex(&ssl->dupWrite->dupMutex) != 0)
16132
            return BAD_MUTEX_E;
16133
        if (ssl->dupWrite->postHandshakeSyncedHashState != NULL) {
16134
            FreeHandshakeHashes(ssl);
16135
            ssl->hsHashes = ssl->dupWrite->postHandshakeSyncedHashState;
16136
            ssl->dupWrite->postHandshakeSyncedHashState = NULL;
16137
        }
16138
        wc_UnLockMutex(&ssl->dupWrite->dupMutex);
16139
    }
16140
#endif /* HAVE_WRITE_DUP && WOLFSSL_POST_HANDSHAKE_AUTH */
16141
    if (ret == 0 && type != client_hello && type != session_ticket &&
16142
                                                           type != key_update
16143
#if defined(WOLFSSL_DTLS13) && defined(WOLFSSL_DTLS_CID)
16144
            && type != request_connection_id && type != new_connection_id
16145
#endif
16146
            ) {
16147
        ret = HashInput(ssl, input + inIdx, (int)size);
16148
    }
16149
16150
    alertType = TranslateErrorToAlert(ret);
16151
16152
    /* Skip when a fatal alert already went out for this error. The message
16153
     * handlers reached above send their own, more specific alert before
16154
     * returning (a protocol_version from the version checks in DoClientHello,
16155
     * decode_error, illegal_parameter, inappropriate_fallback), and a second
16156
     * fatal alert on a connection that is already being torn down is not a
16157
     * message the peer can act on. Matches the guard in
16158
     * SendFatalAlertOnly(). */
16159
    if (alertType != invalid_alert &&
16160
            ssl->alert_history.last_tx.level != alert_fatal) {
16161
#ifdef WOLFSSL_DTLS13
16162
        if (type == client_hello && ssl->options.dtls)
16163
            DtlsSetSeqNumForReply(ssl);
16164
#endif
16165
        tmp = SendAlert(ssl, alert_fatal, alertType);
16166
        /* propagate socket error instead of tls error to be sure the error is
16167
         * not ignored by DTLS code */
16168
        if (tmp == WC_NO_ERR_TRACE(SOCKET_ERROR_E))
16169
            ret = SOCKET_ERROR_E;
16170
    }
16171
16172
    if (ret == 0 && ssl->options.tls1_3) {
16173
        /* The message is hashed by now; run the key schedule that belongs to
16174
         * it. */
16175
        ret = DoTls13MsgDerives(ssl, type);
16176
        if (ret != 0)
16177
            return ret;
16178
16179
    #if !defined(NO_WOLFSSL_CLIENT) && defined(WOLFSSL_POST_HANDSHAKE_AUTH)
16180
        if (ssl->options.side == WOLFSSL_CLIENT_END) {
16181
            if (type == certificate_request &&
16182
                                ssl->options.handShakeState == HANDSHAKE_DONE) {
16183
#if defined(HAVE_WRITE_DUP)
16184
                /* Read side cannot write; delegate the cert response to the
16185
                 * write side by saving auth state in the shared WriteDup. */
16186
                if (ssl->dupSide == READ_DUP_SIDE) {
16187
                    if (ssl->dupWrite == NULL)
16188
                        return BAD_STATE_E;
16189
                    if (wc_LockMutex(&ssl->dupWrite->dupMutex) != 0)
16190
                        return BAD_MUTEX_E;
16191
                    /* Copy the current transcript so the write side can
16192
                     * compute the correct Finished MAC. */
16193
                    ret = InitHandshakeHashesAndCopy(ssl, ssl->hsHashes,
16194
                                      &ssl->dupWrite->postHandshakeHashState);
16195
                    if (ret == 0) {
16196
                        /* Copy the cert request context. */
16197
                        CertReqCtx** tail = &ssl->certReqCtx;
16198
                        while (*tail != NULL)
16199
                            tail = &(*tail)->next;
16200
                        *tail = ssl->dupWrite->postHandshakeCertReqCtx;
16201
                        ssl->dupWrite->postHandshakeCertReqCtx = ssl->certReqCtx;
16202
                        ssl->certReqCtx = NULL;
16203
                        ssl->dupWrite->postHandshakeSendVerify =
16204
                            ssl->options.sendVerify;
16205
                        ssl->dupWrite->postHandshakeSigAlgo =
16206
                            ssl->options.sigAlgo;
16207
                        ssl->dupWrite->postHandshakeHashAlgo =
16208
                            ssl->options.hashAlgo;
16209
                    #if !defined(NO_CERTS) && !defined(WOLFSSL_NO_SIGALG)
16210
                        /* The request just parsed decides whether the chain
16211
                         * about to be sent may be SHA-1 signed. */
16212
                        ssl->dupWrite->postHandshakeSha1CertOk =
16213
                            (byte)ssl->options.peerSha1CertOk;
16214
                    #endif
16215
                        ssl->dupWrite->postHandshakeAuthPending = 1;
16216
                    }
16217
                    wc_UnLockMutex(&ssl->dupWrite->dupMutex);
16218
                    /* Leave ssl->options unchanged: read side must not reset
16219
                     * its states or call wolfSSL_connect_TLSv13. */
16220
                }
16221
                else
16222
#endif /* HAVE_WRITE_DUP */
16223
                {
16224
                    /* reset handshake states */
16225
                    ssl->options.clientState = CLIENT_HELLO_COMPLETE;
16226
                    ssl->options.connectState  = FIRST_REPLY_DONE;
16227
                    ssl->options.handShakeState = CLIENT_HELLO_COMPLETE;
16228
                    ssl->options.processReply = 0; /* doProcessInit */
16229
16230
                    /*
16231
                       DTLSv1.3 note: We can't reset serverState to
16232
                       SERVER_FINISHED_COMPLETE with the goal that this connect
16233
                       blocks until the cert/cert_verify/finished flight gets ACKed
16234
                       by the server. The problem is that we will invoke
16235
                       ProcessReplyEx() in that case, but we came here from
16236
                       ProcessReplyEx() and it is not re-entrant safe (the input
16237
                       buffer would still have the certificate_request message). */
16238
16239
                    if (wolfSSL_connect_TLSv13(ssl) != WOLFSSL_SUCCESS) {
16240
                        ret = ssl->error;
16241
                        if (ret != WC_NO_ERR_TRACE(WC_PENDING_E))
16242
                            ret = POST_HAND_AUTH_ERROR;
16243
                    }
16244
                }
16245
            }
16246
        }
16247
    #endif /* !NO_WOLFSSL_CLIENT && WOLFSSL_POST_HANDSHAKE_AUTH */
16248
    }
16249
16250
#ifdef WOLFSSL_DTLS13
16251
    if (ssl->options.dtls && !ssl->options.dtlsStateful) {
16252
        DtlsResetState(ssl);
16253
        if (DtlsIgnoreError(ret))
16254
            ret = 0;
16255
    }
16256
#endif
16257
16258
    WOLFSSL_LEAVE("DoTls13HandShakeMsgType()", ret);
16259
    return ret;
16260
}
16261
16262
16263
/* Handle a handshake message that has been received.
16264
 *
16265
 * ssl       The SSL/TLS object.
16266
 * input     The message buffer.
16267
 * inOutIdx  On entry, the index into the buffer of the current message.
16268
 *           On exit, the index into the buffer of the next message.
16269
 * totalSz   Length of remaining data in the message buffer.
16270
 * returns 0 on success and otherwise failure.
16271
 */
16272
int DoTls13HandShakeMsg(WOLFSSL* ssl, byte* input, word32* inOutIdx,
16273
                        word32 totalSz)
16274
26.2k
{
16275
26.2k
    int    ret = 0;
16276
26.2k
    word32 inputLength;
16277
26.2k
    byte   type;
16278
26.2k
    word32 size = 0;
16279
#if defined(WOLFSSL_ASYNC_CRYPT) || defined(WOLFSSL_NONBLOCK_OCSP)
16280
    /* Nonzero on entry: an earlier message's schedule is unfinished, so a
16281
     * pend from its pre-dispatch drain must re-present this message. */
16282
    byte   kdfStepEntry = ssl->kdfMsgStep;
16283
#endif
16284
16285
26.2k
    WOLFSSL_ENTER("DoTls13HandShakeMsg");
16286
16287
    /* totalSz is now curStartIdx + curSize (content-only, padSz already
16288
     * subtracted in ProcessReply). */
16289
26.2k
    if (*inOutIdx > totalSz)
16290
0
        return BUFFER_ERROR;
16291
26.2k
    inputLength = totalSz - *inOutIdx;
16292
16293
    /* If there is a pending fragmented handshake message,
16294
     * pending message size will be non-zero. */
16295
26.2k
    if (ssl->pendingMsgSz == 0) {
16296
    #if defined(WOLFSSL_ASYNC_CRYPT) || defined(WOLFSSL_NONBLOCK_OCSP)
16297
        word32 startIdx = *inOutIdx;
16298
    #endif
16299
16300
14.3k
        if (GetHandshakeHeader(ssl, input, inOutIdx, &type, &size,
16301
14.3k
                               totalSz) != 0) {
16302
20
            WOLFSSL_ERROR_VERBOSE(PARSE_ERROR);
16303
20
            return PARSE_ERROR;
16304
20
        }
16305
16306
14.3k
        ret = EarlySanityCheckMsgReceived(ssl, type,
16307
14.3k
                (inputLength > HANDSHAKE_HEADER_SZ) ?
16308
13.8k
                min(inputLength - HANDSHAKE_HEADER_SZ, size) : 0);
16309
14.3k
        if (ret != 0) {
16310
126
            WOLFSSL_ERROR(ret);
16311
126
            return ret;
16312
126
        }
16313
16314
        /* Cap the maximum size of a handshake message to something reasonable.
16315
         * By default is the maximum size of a certificate message assuming
16316
         * nine 2048-bit RSA certificates in the chain. */
16317
14.2k
        if (size > MAX_HANDSHAKE_SZ) {
16318
120
            WOLFSSL_MSG("Handshake message too large");
16319
120
            WOLFSSL_ERROR_VERBOSE(HANDSHAKE_SIZE_ERROR);
16320
120
            return HANDSHAKE_SIZE_ERROR;
16321
120
        }
16322
16323
        /* size is the size of the certificate message payload */
16324
14.0k
        if (inputLength - HANDSHAKE_HEADER_SZ < size) {
16325
            /* Commit pending state only after the allocation succeeds. */
16326
759
            ssl->pendingMsg = (byte*)XMALLOC(size + HANDSHAKE_HEADER_SZ,
16327
759
                                             ssl->heap, DYNAMIC_TYPE_ARRAYS);
16328
759
            if (ssl->pendingMsg == NULL)
16329
27
                return MEMORY_E;
16330
732
            ssl->pendingMsgType = type;
16331
732
            ssl->pendingMsgSz = size + HANDSHAKE_HEADER_SZ;
16332
732
            XMEMCPY(ssl->pendingMsg,
16333
732
                    input + *inOutIdx - HANDSHAKE_HEADER_SZ,
16334
732
                    inputLength);
16335
732
            ssl->pendingMsgOffset = inputLength;
16336
732
            *inOutIdx += inputLength - HANDSHAKE_HEADER_SZ;
16337
732
            return 0;
16338
759
        }
16339
16340
13.3k
        ret = DoTls13HandShakeMsgType(ssl, input, inOutIdx, type, size,
16341
13.3k
                                      totalSz);
16342
    #if defined(WOLFSSL_ASYNC_CRYPT) || defined(WOLFSSL_NONBLOCK_OCSP)
16343
        if ((ret == WC_NO_ERR_TRACE(WC_PENDING_E) &&
16344
                 (ssl->kdfMsgStep == 0 || kdfStepEntry != 0) &&
16345
                 ssl->options.processReply != 0 /* doProcessInit */) ||
16346
                ret == WC_NO_ERR_TRACE(OCSP_WANT_READ)) {
16347
            /* Re-present for in-handler pends and pre-dispatch drain pends.
16348
             * Not for post-handler pends, which committed the message: a
16349
             * key-schedule pend (kdfMsgStep != 0) resumes through
16350
             * DoTls13MsgDerives(), and a post-handshake-auth send pend
16351
             * (processReply reset to doProcessInit) resumes through
16352
             * wolfSSL_negotiate(). */
16353
            *inOutIdx = startIdx;
16354
        }
16355
    #endif
16356
13.3k
    }
16357
11.8k
    else {
16358
11.8k
        if (inputLength + ssl->pendingMsgOffset > ssl->pendingMsgSz) {
16359
52
            inputLength = ssl->pendingMsgSz - ssl->pendingMsgOffset;
16360
52
        }
16361
16362
11.8k
        ret = EarlySanityCheckMsgReceived(ssl, ssl->pendingMsgType,
16363
11.8k
                inputLength);
16364
11.8k
        if (ret != 0) {
16365
23
            WOLFSSL_ERROR(ret);
16366
23
            return ret;
16367
23
        }
16368
16369
11.8k
        XMEMCPY(ssl->pendingMsg + ssl->pendingMsgOffset,
16370
11.8k
                input + *inOutIdx, inputLength);
16371
11.8k
        ssl->pendingMsgOffset += inputLength;
16372
11.8k
        *inOutIdx += inputLength;
16373
16374
11.8k
        if (ssl->pendingMsgOffset == ssl->pendingMsgSz)
16375
56
        {
16376
56
            word32 idx = 0;
16377
56
            ret = DoTls13HandShakeMsgType(ssl,
16378
56
                                ssl->pendingMsg + HANDSHAKE_HEADER_SZ,
16379
56
                                &idx, ssl->pendingMsgType,
16380
56
                                ssl->pendingMsgSz - HANDSHAKE_HEADER_SZ,
16381
56
                                ssl->pendingMsgSz);
16382
        #if defined(WOLFSSL_ASYNC_CRYPT) || defined(WOLFSSL_NONBLOCK_OCSP)
16383
            if ((ret == WC_NO_ERR_TRACE(WC_PENDING_E) &&
16384
                 (ssl->kdfMsgStep == 0 || kdfStepEntry != 0) &&
16385
                 ssl->options.processReply != 0 /* doProcessInit */) ||
16386
                ret == WC_NO_ERR_TRACE(OCSP_WANT_READ)) {
16387
                /* Re-present the fragment; a post-handler pend falls
16388
                 * through and consumes the message. */
16389
                ssl->pendingMsgOffset -= inputLength;
16390
                *inOutIdx -= inputLength;
16391
            }
16392
            else
16393
        #endif
16394
56
            {
16395
56
                XFREE(ssl->pendingMsg, ssl->heap, DYNAMIC_TYPE_ARRAYS);
16396
56
                ssl->pendingMsg = NULL;
16397
56
                ssl->pendingMsgSz = 0;
16398
56
            }
16399
56
        }
16400
11.8k
    }
16401
16402
25.1k
    WOLFSSL_LEAVE("DoTls13HandShakeMsg", ret);
16403
25.1k
    return ret;
16404
26.2k
}
16405
16406
#ifndef NO_WOLFSSL_CLIENT
16407
16408
/* The client connecting to the server.
16409
 * The protocol version is expecting to be TLS v1.3.
16410
 * If the server downgrades, and older versions of the protocol are compiled
16411
 * in, the client will fallback to wolfSSL_connect().
16412
 * Please see note at top of README if you get an error from connect.
16413
 *
16414
 * ssl  The SSL/TLS object.
16415
 * returns WOLFSSL_SUCCESS on successful handshake, WOLFSSL_FATAL_ERROR when
16416
 * unrecoverable error occurs and 0 otherwise.
16417
 * For more error information use wolfSSL_get_error().
16418
 */
16419
int wolfSSL_connect_TLSv13(WOLFSSL* ssl)
16420
{
16421
    int advanceState;
16422
    int ret = 0;
16423
16424
    WOLFSSL_ENTER("wolfSSL_connect_TLSv13");
16425
16426
#ifdef HAVE_ERRNO_H
16427
    errno = 0;
16428
#endif
16429
16430
    if (ssl == NULL)
16431
        return BAD_FUNC_ARG;
16432
16433
    if (ssl->options.side != WOLFSSL_CLIENT_END) {
16434
        ssl->error = SIDE_ERROR;
16435
        WOLFSSL_ERROR(ssl->error);
16436
        return WOLFSSL_FATAL_ERROR;
16437
    }
16438
16439
    /* make sure this wolfSSL object has arrays and rng setup. Protects
16440
     * case where the WOLFSSL object is reused via wolfSSL_clear() */
16441
    if ((ret = ReinitSSL(ssl, ssl->ctx, 0)) != 0) {
16442
        return ret;
16443
    }
16444
16445
#ifdef WOLFSSL_DTLS
16446
    if (ssl->version.major == DTLS_MAJOR) {
16447
        ssl->options.dtls   = 1;
16448
        ssl->options.dtlsStateful = 1;
16449
    }
16450
#endif
16451
16452
#ifdef WOLFSSL_WOLFSENTRY_HOOKS
16453
    if ((ssl->ConnectFilter != NULL) &&
16454
        (ssl->options.connectState == CONNECT_BEGIN))
16455
    {
16456
        wolfSSL_netfilter_decision_t res;
16457
        if ((ssl->ConnectFilter(ssl, ssl->ConnectFilter_arg, &res) ==
16458
             WOLFSSL_SUCCESS) &&
16459
            (res == WOLFSSL_NETFILTER_REJECT)) {
16460
            ssl->error = SOCKET_FILTERED_E;
16461
            WOLFSSL_ERROR(ssl->error);
16462
            return WOLFSSL_FATAL_ERROR;
16463
        }
16464
    }
16465
#endif /* WOLFSSL_WOLFSENTRY_HOOKS */
16466
16467
    /* fragOffset is non-zero when sending fragments. On the last
16468
     * fragment, fragOffset is zero again, and the state can be
16469
     * advanced. Also, only advance from states in which we send data */
16470
    advanceState = (ssl->options.connectState == CONNECT_BEGIN ||
16471
            ssl->options.connectState == HELLO_AGAIN ||
16472
            (ssl->options.connectState >= FIRST_REPLY_DONE &&
16473
             ssl->options.connectState <= FIRST_REPLY_FOURTH));
16474
16475
#ifdef WOLFSSL_DTLS13
16476
    if (ssl->options.dtls)
16477
        advanceState = advanceState && !ssl->dtls13SendingFragments
16478
            && !ssl->dtls13SendingAckOrRtx;
16479
#endif /* WOLFSSL_DTLS13 */
16480
16481
    if (ssl->buffers.outputBuffer.length > 0
16482
    #ifdef WOLFSSL_ASYNC_CRYPT
16483
        /* do not send buffered or advance state if last error was an
16484
            async pending operation */
16485
        && ssl->error != WC_NO_ERR_TRACE(WC_PENDING_E)
16486
    #endif
16487
    ) {
16488
        if ((ret = SendBuffered(ssl)) == 0) {
16489
            if (ssl->fragOffset == 0 && !ssl->options.buildingMsg) {
16490
                if (advanceState) {
16491
#ifdef WOLFSSL_DTLS13
16492
                    if (ssl->options.dtls && IsAtLeastTLSv1_3(ssl->version) &&
16493
                        ssl->options.connectState == FIRST_REPLY_FOURTH) {
16494
                    /* WAIT_FINISHED_ACK is a state added afterwards, but it
16495
                       can't follow FIRST_REPLY_FOURTH in the enum order. Indeed
16496
                       the value of the enum ConnectState is stored in
16497
                       serialized session. This would make importing serialized
16498
                       session from other wolfSSL version incompatible */
16499
                        ssl->options.connectState = WAIT_FINISHED_ACK;
16500
                    }
16501
                    else
16502
#endif /* WOLFSSL_DTLS13 */
16503
                    {
16504
                        ssl->options.connectState++;
16505
                    }
16506
                    WOLFSSL_MSG("connect state: "
16507
                                "Advanced from last buffered fragment send");
16508
#ifdef WOLFSSL_ASYNC_IO
16509
                    FreeAsyncCtx(ssl, 0);
16510
#endif
16511
16512
                }
16513
            }
16514
            else {
16515
                WOLFSSL_MSG("connect state: "
16516
                            "Not advanced, more fragments to send");
16517
            }
16518
#ifdef WOLFSSL_DTLS13
16519
            if (ssl->options.dtls)
16520
                ssl->dtls13SendingAckOrRtx = 0;
16521
#endif /* WOLFSSL_DTLS13 */
16522
16523
        }
16524
        else {
16525
            ssl->error = ret;
16526
            WOLFSSL_ERROR(ssl->error);
16527
            return WOLFSSL_FATAL_ERROR;
16528
        }
16529
    }
16530
16531
    ret = RetrySendAlert(ssl);
16532
    if (ret != 0) {
16533
        ssl->error = ret;
16534
        WOLFSSL_ERROR(ssl->error);
16535
        return WOLFSSL_FATAL_ERROR;
16536
    }
16537
16538
#ifdef WOLFSSL_DTLS13
16539
    if (ssl->options.dtls && ssl->dtls13SendingFragments) {
16540
        if ((ssl->error = Dtls13FragmentsContinue(ssl)) != 0) {
16541
                WOLFSSL_ERROR(ssl->error);
16542
                return WOLFSSL_FATAL_ERROR;
16543
        }
16544
16545
        /* we sent all the fragments. Advance state. */
16546
        ssl->options.connectState++;
16547
    }
16548
#endif /* WOLFSSL_DTLS13 */
16549
16550
    switch (ssl->options.connectState) {
16551
16552
        case CONNECT_BEGIN:
16553
            /* Always send client hello first. */
16554
            if ((ssl->error = SendTls13ClientHello(ssl)) != 0) {
16555
                WOLFSSL_ERROR(ssl->error);
16556
                return WOLFSSL_FATAL_ERROR;
16557
            }
16558
16559
            ssl->options.connectState = CLIENT_HELLO_SENT;
16560
            WOLFSSL_MSG("TLSv13 connect state: CLIENT_HELLO_SENT");
16561
            FALL_THROUGH;
16562
16563
        case CLIENT_HELLO_SENT:
16564
    #ifdef WOLFSSL_EARLY_DATA
16565
            if (ssl->earlyData != no_early_data &&
16566
                ssl->options.handShakeState != CLIENT_HELLO_COMPLETE) {
16567
        #if defined(WOLFSSL_TLS13_MIDDLEBOX_COMPAT)
16568
                    if (!ssl->options.dtls && !ssl->options.sentChangeCipher
16569
                            && ssl->options.tls13MiddleBoxCompat) {
16570
                        ssl->error = SendChangeCipher(ssl);
16571
                        /* A short send leaves the record queued in the output
16572
                         * buffer, so a resumed connect must not build a second
16573
                         * one. Same on every other site. */
16574
                        if (ssl->error == 0 ||
16575
                                ssl->error == WC_NO_ERR_TRACE(WANT_WRITE)) {
16576
                            ssl->options.sentChangeCipher = 1;
16577
                        }
16578
                        if (ssl->error != 0) {
16579
                            WOLFSSL_ERROR(ssl->error);
16580
                            return WOLFSSL_FATAL_ERROR;
16581
                        }
16582
                    }
16583
        #endif
16584
                ssl->options.handShakeState = CLIENT_HELLO_COMPLETE;
16585
                return WOLFSSL_SUCCESS;
16586
            }
16587
    #endif
16588
            /* Get the response/s from the server. */
16589
            while (ssl->options.serverState <
16590
                    SERVER_HELLOVERIFYREQUEST_COMPLETE) {
16591
                if ((ssl->error = ProcessReply(ssl)) < 0) {
16592
                        WOLFSSL_ERROR(ssl->error);
16593
                        return WOLFSSL_FATAL_ERROR;
16594
                }
16595
16596
#ifdef WOLFSSL_DTLS13
16597
                if (ssl->options.dtls) {
16598
                    if ((ssl->error = Dtls13DoScheduledWork(ssl)) < 0) {
16599
                        WOLFSSL_ERROR(ssl->error);
16600
                        return WOLFSSL_FATAL_ERROR;
16601
                    }
16602
                }
16603
#endif /* WOLFSSL_DTLS13 */
16604
            }
16605
16606
            if (!ssl->options.tls1_3) {
16607
    #ifndef WOLFSSL_NO_TLS12
16608
                if (ssl->options.downgrade)
16609
                    return wolfSSL_connect(ssl);
16610
    #endif
16611
                WOLFSSL_MSG("Client using higher version, fatal error");
16612
                WOLFSSL_ERROR_VERBOSE(VERSION_ERROR);
16613
                return VERSION_ERROR;
16614
            }
16615
16616
            ssl->options.connectState = HELLO_AGAIN;
16617
            WOLFSSL_MSG("connect state: HELLO_AGAIN");
16618
            FALL_THROUGH;
16619
16620
        case HELLO_AGAIN:
16621
16622
            if (ssl->options.serverState ==
16623
                                          SERVER_HELLO_RETRY_REQUEST_COMPLETE) {
16624
        #if defined(WOLFSSL_TLS13_MIDDLEBOX_COMPAT)
16625
                if (!ssl->options.dtls && !ssl->options.sentChangeCipher
16626
                    && ssl->options.tls13MiddleBoxCompat) {
16627
                    ssl->error = SendChangeCipher(ssl);
16628
                    if (ssl->error == 0 ||
16629
                            ssl->error == WC_NO_ERR_TRACE(WANT_WRITE)) {
16630
                        ssl->options.sentChangeCipher = 1;
16631
                    }
16632
                    if (ssl->error != 0) {
16633
                        /* The second ClientHello still has to follow, so hold
16634
                         * the state machine on this case while the record
16635
                         * drains. */
16636
                        ssl->options.buildingMsg = 1;
16637
                        WOLFSSL_ERROR(ssl->error);
16638
                        return WOLFSSL_FATAL_ERROR;
16639
                    }
16640
                }
16641
        #endif
16642
                /* Try again with different security parameters. */
16643
                if ((ssl->error = SendTls13ClientHello(ssl)) != 0) {
16644
                    WOLFSSL_ERROR(ssl->error);
16645
                    return WOLFSSL_FATAL_ERROR;
16646
                }
16647
            }
16648
16649
            ssl->options.connectState = HELLO_AGAIN_REPLY;
16650
            WOLFSSL_MSG("connect state: HELLO_AGAIN_REPLY");
16651
            FALL_THROUGH;
16652
16653
        case HELLO_AGAIN_REPLY:
16654
            /* Get the response/s from the server. */
16655
            while (ssl->options.serverState < SERVER_FINISHED_COMPLETE) {
16656
#ifdef WOLFSSL_DTLS13
16657
                if (!IsAtLeastTLSv1_3(ssl->version)) {
16658
        #ifndef WOLFSSL_NO_TLS12
16659
                    if (ssl->options.downgrade)
16660
                        return wolfSSL_connect(ssl);
16661
        #endif
16662
                }
16663
#endif /* WOLFSSL_DTLS13 */
16664
                if ((ssl->error = ProcessReply(ssl)) < 0) {
16665
                        WOLFSSL_ERROR(ssl->error);
16666
                        return WOLFSSL_FATAL_ERROR;
16667
                }
16668
16669
#ifdef WOLFSSL_DTLS13
16670
                if (ssl->options.dtls) {
16671
                    if ((ssl->error = Dtls13DoScheduledWork(ssl)) < 0) {
16672
                        WOLFSSL_ERROR(ssl->error);
16673
                        return WOLFSSL_FATAL_ERROR;
16674
                    }
16675
                }
16676
#endif /* WOLFSSL_DTLS13 */
16677
            }
16678
16679
            /* Finish a key schedule the Finished handler left pending:
16680
             * it must complete before this side's sends advance the
16681
             * transcript the traffic secrets hash. */
16682
            if (ssl->kdfMsgStep > 0) {
16683
                ssl->error = DoTls13MsgDerives(ssl, ssl->kdfMsgType);
16684
                if (ssl->error != 0) {
16685
                    WOLFSSL_ERROR(ssl->error);
16686
                    return WOLFSSL_FATAL_ERROR;
16687
                }
16688
            }
16689
16690
            ssl->options.connectState = FIRST_REPLY_DONE;
16691
            WOLFSSL_MSG("connect state: FIRST_REPLY_DONE");
16692
            FALL_THROUGH;
16693
16694
        case FIRST_REPLY_DONE:
16695
            if (ssl->options.certOnly)
16696
                return WOLFSSL_SUCCESS;
16697
        #ifdef WOLFSSL_EARLY_DATA
16698
            if (!ssl->options.dtls && ssl->earlyData != no_early_data
16699
                && !WOLFSSL_IS_QUIC(ssl)) {
16700
                if ((ssl->error = SendTls13EndOfEarlyData(ssl)) != 0) {
16701
                    WOLFSSL_ERROR(ssl->error);
16702
                    return WOLFSSL_FATAL_ERROR;
16703
                }
16704
                WOLFSSL_MSG("sent: end_of_early_data");
16705
            }
16706
        #endif
16707
16708
            ssl->options.connectState = FIRST_REPLY_FIRST;
16709
            WOLFSSL_MSG("connect state: FIRST_REPLY_FIRST");
16710
            FALL_THROUGH;
16711
16712
        case FIRST_REPLY_FIRST:
16713
        #if defined(WOLFSSL_TLS13_MIDDLEBOX_COMPAT)
16714
            if (!ssl->options.sentChangeCipher && !ssl->options.dtls
16715
                && ssl->options.tls13MiddleBoxCompat) {
16716
                ssl->error = SendChangeCipher(ssl);
16717
                if (ssl->error == 0 ||
16718
                        ssl->error == WC_NO_ERR_TRACE(WANT_WRITE)) {
16719
                    ssl->options.sentChangeCipher = 1;
16720
                }
16721
                if (ssl->error != 0) {
16722
                    WOLFSSL_ERROR(ssl->error);
16723
                    return WOLFSSL_FATAL_ERROR;
16724
                }
16725
            }
16726
        #endif
16727
16728
            ssl->options.connectState = FIRST_REPLY_SECOND;
16729
            WOLFSSL_MSG("connect state: FIRST_REPLY_SECOND");
16730
            FALL_THROUGH;
16731
16732
        case FIRST_REPLY_SECOND:
16733
            /* CLIENT: check peer authentication. */
16734
            if (!ssl->options.peerAuthGood) {
16735
                WOLFSSL_MSG("Server authentication did not happen");
16736
                WOLFSSL_ERROR_VERBOSE(WOLFSSL_FATAL_ERROR);
16737
                return WOLFSSL_FATAL_ERROR;
16738
            }
16739
        #ifndef NO_CERTS
16740
            if ((!ssl->options.resuming || TLS13_AFTER_HANDSHAKE(ssl)) &&
16741
                    ssl->options.sendVerify) {
16742
                ssl->error = SendTls13Certificate(ssl);
16743
                if (ssl->error != 0) {
16744
                    wolfssl_local_MaybeCheckAlertOnErr(ssl, ssl->error);
16745
                    WOLFSSL_ERROR(ssl->error);
16746
                    return WOLFSSL_FATAL_ERROR;
16747
                }
16748
                WOLFSSL_MSG("sent: certificate");
16749
            }
16750
        #endif
16751
16752
            ssl->options.connectState = FIRST_REPLY_THIRD;
16753
            WOLFSSL_MSG("connect state: FIRST_REPLY_THIRD");
16754
            FALL_THROUGH;
16755
16756
        case FIRST_REPLY_THIRD:
16757
        #if (!defined(NO_CERTS) && (!defined(NO_RSA) || defined(HAVE_ECC) || \
16758
             defined(HAVE_ED25519) || defined(HAVE_ED448) || \
16759
             defined(HAVE_FALCON) || defined(WOLFSSL_HAVE_MLDSA) || \
16760
             defined(WOLFSSL_HAVE_SLHDSA))) && \
16761
             (!defined(NO_WOLFSSL_SERVER) || !defined(WOLFSSL_NO_CLIENT_AUTH))
16762
            if ((!ssl->options.resuming || TLS13_AFTER_HANDSHAKE(ssl)) &&
16763
                    ssl->options.sendVerify) {
16764
                ssl->error = SendTls13CertificateVerify(ssl);
16765
                if (ssl->error != 0) {
16766
                    wolfssl_local_MaybeCheckAlertOnErr(ssl, ssl->error);
16767
                    WOLFSSL_ERROR(ssl->error);
16768
                    return WOLFSSL_FATAL_ERROR;
16769
                }
16770
                WOLFSSL_MSG("sent: certificate verify");
16771
            }
16772
        #endif
16773
16774
            ssl->options.connectState = FIRST_REPLY_FOURTH;
16775
            WOLFSSL_MSG("connect state: FIRST_REPLY_FOURTH");
16776
            FALL_THROUGH;
16777
16778
        case FIRST_REPLY_FOURTH:
16779
            if ((ssl->error = SendTls13Finished(ssl)) != 0) {
16780
                wolfssl_local_MaybeCheckAlertOnErr(ssl, ssl->error);
16781
                WOLFSSL_ERROR(ssl->error);
16782
                return WOLFSSL_FATAL_ERROR;
16783
            }
16784
            WOLFSSL_MSG("sent: finished");
16785
16786
#ifdef WOLFSSL_DTLS13
16787
            ssl->options.connectState = WAIT_FINISHED_ACK;
16788
            WOLFSSL_MSG("connect state: WAIT_FINISHED_ACK");
16789
            FALL_THROUGH;
16790
16791
        case WAIT_FINISHED_ACK:
16792
            if (ssl->options.dtls) {
16793
                while (ssl->options.serverState != SERVER_FINISHED_ACKED) {
16794
                    if ((ssl->error = ProcessReply(ssl)) < 0) {
16795
                        WOLFSSL_ERROR(ssl->error);
16796
                        return WOLFSSL_FATAL_ERROR;
16797
                    }
16798
16799
                    if ((ssl->error = Dtls13DoScheduledWork(ssl)) < 0) {
16800
                        WOLFSSL_ERROR(ssl->error);
16801
                        return WOLFSSL_FATAL_ERROR;
16802
                    }
16803
                }
16804
            }
16805
#endif /* WOLFSSL_DTLS13 */
16806
            ssl->options.connectState = FINISHED_DONE;
16807
            WOLFSSL_MSG("connect state: FINISHED_DONE");
16808
            FALL_THROUGH;
16809
16810
        case FINISHED_DONE:
16811
        #ifndef NO_HANDSHAKE_DONE_CB
16812
            if (ssl->hsDoneCb != NULL) {
16813
                int cbret = ssl->hsDoneCb(ssl, ssl->hsDoneCtx);
16814
                if (cbret < 0) {
16815
                    ssl->error = cbret;
16816
                    WOLFSSL_ERROR_VERBOSE(ssl->error);
16817
                    WOLFSSL_MSG("HandShake Done Cb don't continue error");
16818
                    return WOLFSSL_FATAL_ERROR;
16819
                }
16820
            }
16821
        #endif /* NO_HANDSHAKE_DONE_CB */
16822
16823
        #if defined(HAVE_ECH)
16824
            /* RFC 9849 s6.1.6: if we offered ECH but the server rejected it,
16825
             * send ech_required alert and abort before returning to the app */
16826
            if (ssl->echConfigs != NULL && !ssl->options.disableECH &&
16827
                    !ssl->options.echAccepted) {
16828
                if (ssl->echRetryConfigs != NULL) {
16829
                    ssl->options.echRetryConfigsAccepted = 1;
16830
                }
16831
                SendAlert(ssl, alert_fatal, ech_required);
16832
                ssl->error = ECH_REQUIRED_E;
16833
                WOLFSSL_ERROR_VERBOSE(ECH_REQUIRED_E);
16834
                return WOLFSSL_FATAL_ERROR;
16835
            }
16836
        #endif /* HAVE_ECH */
16837
16838
            if (!ssl->options.keepResources) {
16839
                FreeHandshakeResources(ssl);
16840
            }
16841
        #if defined(WOLFSSL_ASYNC_IO) && !defined(WOLFSSL_ASYNC_CRYPT)
16842
            /* Free the remaining async context if not using it for crypto */
16843
            FreeAsyncCtx(ssl, 1);
16844
        #endif
16845
16846
            ssl->error = 0; /* clear the error */
16847
16848
            WOLFSSL_LEAVE("wolfSSL_connect_TLSv13", WOLFSSL_SUCCESS);
16849
            return WOLFSSL_SUCCESS;
16850
16851
        default:
16852
            WOLFSSL_MSG("Unknown connect state ERROR");
16853
            return WOLFSSL_FATAL_ERROR; /* unknown connect state */
16854
    }
16855
}
16856
#endif
16857
16858
#if defined(WOLFSSL_SEND_HRR_COOKIE)
16859
/* Send a cookie with the HelloRetryRequest to avoid storing state.
16860
 *
16861
 * ssl       SSL/TLS object.
16862
 * secret    Secret to use when generating integrity check for cookie.
16863
 *           A value of NULL indicates to generate a new random secret.
16864
 * secretSz  Size of secret data in bytes.
16865
 *           Use a value of 0 to indicate use of default size.
16866
 * returns BAD_FUNC_ARG when ssl is NULL or not using TLS v1.3, SIDE_ERROR when
16867
 * called on a client; WOLFSSL_SUCCESS on success and otherwise failure.
16868
 */
16869
int wolfSSL_send_hrr_cookie(WOLFSSL* ssl, const unsigned char* secret,
16870
                            unsigned int secretSz)
16871
{
16872
    int ret;
16873
16874
    if (ssl == NULL || !IsAtLeastTLSv1_3(ssl->version))
16875
        return BAD_FUNC_ARG;
16876
 #ifndef NO_WOLFSSL_SERVER
16877
    if (ssl->options.side == WOLFSSL_CLIENT_END)
16878
        return SIDE_ERROR;
16879
16880
    if (secretSz == 0) {
16881
    #ifndef NO_SHA256
16882
        secretSz = WC_SHA256_DIGEST_SIZE;
16883
    #elif defined(WOLFSSL_SHA384)
16884
        secretSz = WC_SHA384_DIGEST_SIZE;
16885
    #elif defined(WOLFSSL_TLS13_SHA512)
16886
        secretSz = WC_SHA512_DIGEST_SIZE;
16887
    #elif defined(WOLFSSL_SM3)
16888
        secretSz = WC_SM3_DIGEST_SIZE;
16889
    #else
16890
        #error "No digest to available to use with HMAC for cookies."
16891
    #endif /* NO_SHA */
16892
    }
16893
16894
    if (secretSz != ssl->buffers.tls13CookieSecret.length) {
16895
        byte* newSecret;
16896
16897
        if (ssl->buffers.tls13CookieSecret.buffer != NULL) {
16898
            ForceZero(ssl->buffers.tls13CookieSecret.buffer,
16899
                      ssl->buffers.tls13CookieSecret.length);
16900
            XFREE(ssl->buffers.tls13CookieSecret.buffer,
16901
                  ssl->heap, DYNAMIC_TYPE_COOKIE_PWD);
16902
        }
16903
16904
        newSecret = (byte*)XMALLOC(secretSz, ssl->heap,
16905
                                   DYNAMIC_TYPE_COOKIE_PWD);
16906
        if (newSecret == NULL) {
16907
            ssl->buffers.tls13CookieSecret.buffer = NULL;
16908
            ssl->buffers.tls13CookieSecret.length = 0;
16909
            WOLFSSL_MSG("couldn't allocate new cookie secret");
16910
            return MEMORY_ERROR;
16911
        }
16912
        ssl->buffers.tls13CookieSecret.buffer = newSecret;
16913
        ssl->buffers.tls13CookieSecret.length = secretSz;
16914
    #ifdef WOLFSSL_CHECK_MEM_ZERO
16915
        wc_MemZero_Add("wolfSSL_send_hrr_cookie secret",
16916
            ssl->buffers.tls13CookieSecret.buffer,
16917
            ssl->buffers.tls13CookieSecret.length);
16918
    #endif
16919
    }
16920
16921
    /* If the supplied secret is NULL, randomly generate a new secret. */
16922
    if (secret == NULL) {
16923
        ret = wc_RNG_GenerateBlock(ssl->rng,
16924
                               ssl->buffers.tls13CookieSecret.buffer, secretSz);
16925
        if (ret < 0)
16926
            return ret;
16927
    }
16928
    else
16929
        XMEMCPY(ssl->buffers.tls13CookieSecret.buffer, secret, secretSz);
16930
16931
    ssl->options.sendCookie = 1;
16932
16933
    ret = WOLFSSL_SUCCESS;
16934
#else
16935
    (void)secret;
16936
    (void)secretSz;
16937
16938
    ret = SIDE_ERROR;
16939
#endif
16940
16941
    return ret;
16942
}
16943
16944
int wolfSSL_disable_hrr_cookie(WOLFSSL* ssl)
16945
{
16946
    if (ssl == NULL || !IsAtLeastTLSv1_3(ssl->version))
16947
        return BAD_FUNC_ARG;
16948
16949
#ifdef NO_WOLFSSL_SERVER
16950
    return SIDE_ERROR;
16951
#else
16952
    if (ssl->options.side == WOLFSSL_CLIENT_END)
16953
        return SIDE_ERROR;
16954
16955
    if (ssl->buffers.tls13CookieSecret.buffer != NULL) {
16956
        ForceZero(ssl->buffers.tls13CookieSecret.buffer,
16957
            ssl->buffers.tls13CookieSecret.length);
16958
        XFREE(ssl->buffers.tls13CookieSecret.buffer, ssl->heap,
16959
            DYNAMIC_TYPE_COOKIE_PWD);
16960
        ssl->buffers.tls13CookieSecret.buffer = NULL;
16961
        ssl->buffers.tls13CookieSecret.length = 0;
16962
    }
16963
16964
    if (ssl->buffers.tls13CookieSecretSecondary.buffer != NULL) {
16965
        ForceZero(ssl->buffers.tls13CookieSecretSecondary.buffer,
16966
            ssl->buffers.tls13CookieSecretSecondary.length);
16967
        XFREE(ssl->buffers.tls13CookieSecretSecondary.buffer, ssl->heap,
16968
            DYNAMIC_TYPE_COOKIE_PWD);
16969
        ssl->buffers.tls13CookieSecretSecondary.buffer = NULL;
16970
        ssl->buffers.tls13CookieSecretSecondary.length = 0;
16971
    }
16972
16973
    ssl->options.sendCookie = 0;
16974
    return WOLFSSL_SUCCESS;
16975
#endif /* NO_WOLFSSL_SERVER */
16976
}
16977
16978
/* Set a secondary HelloRetryRequest cookie secret used only when verifying a
16979
 * received cookie, and only if the primary secret (set by
16980
 * wolfSSL_send_hrr_cookie()) fails to verify it.
16981
 *
16982
 * This supports an application-driven cookie-secret rotation on a stateless
16983
 * DTLS 1.3 server: after rotating the primary secret, install the previous
16984
 * secret here so that cookies already issued under it are still accepted for
16985
 * an overlap window.  It is never used to issue cookies.
16986
 *
16987
 * This API is DTLS only - TLS 1.3 over a reliable transport does not operate
16988
 * statelessly across the HelloRetryRequest exchange, so a secondary cookie
16989
 * secret has no use there.
16990
 *
16991
 * ssl       SSL/TLS object.
16992
 * secret    Secondary secret to verify cookies against.  A value of NULL (or a
16993
 *           secretSz of 0) clears any previously set secondary secret.
16994
 * secretSz  Size of secret data in bytes.
16995
 * returns BAD_FUNC_ARG when ssl is NULL, not TLS v1.3 or not DTLS; SIDE_ERROR
16996
 * when called on a client; WOLFSSL_SUCCESS on success and otherwise failure.
16997
 */
16998
int wolfSSL_set_hrr_cookie_secret_secondary(WOLFSSL* ssl,
16999
    const unsigned char* secret, unsigned int secretSz)
17000
{
17001
    int ret;
17002
17003
    if (ssl == NULL || !IsAtLeastTLSv1_3(ssl->version))
17004
        return BAD_FUNC_ARG;
17005
#ifndef NO_WOLFSSL_SERVER
17006
    if (ssl->options.side == WOLFSSL_CLIENT_END)
17007
        return SIDE_ERROR;
17008
    /* DTLS only - TLS 1.3 does not verify cookies statelessly. */
17009
    if (!ssl->options.dtls) {
17010
        WOLFSSL_MSG("Secondary HRR cookie secret is DTLS only");
17011
        return BAD_FUNC_ARG;
17012
    }
17013
17014
    /* Clear any existing secondary secret. */
17015
    if (ssl->buffers.tls13CookieSecretSecondary.buffer != NULL) {
17016
        ForceZero(ssl->buffers.tls13CookieSecretSecondary.buffer,
17017
                  ssl->buffers.tls13CookieSecretSecondary.length);
17018
        XFREE(ssl->buffers.tls13CookieSecretSecondary.buffer, ssl->heap,
17019
              DYNAMIC_TYPE_COOKIE_PWD);
17020
        ssl->buffers.tls13CookieSecretSecondary.buffer = NULL;
17021
        ssl->buffers.tls13CookieSecretSecondary.length = 0;
17022
    }
17023
17024
    /* A NULL/empty secret just clears the secondary secret. */
17025
    if (secret == NULL || secretSz == 0) {
17026
        ret = WOLFSSL_SUCCESS;
17027
    }
17028
    else {
17029
        byte* newSecret = (byte*)XMALLOC(secretSz, ssl->heap,
17030
                                         DYNAMIC_TYPE_COOKIE_PWD);
17031
        if (newSecret == NULL) {
17032
            WOLFSSL_MSG("couldn't allocate secondary cookie secret");
17033
            ret = MEMORY_ERROR;
17034
        }
17035
        else {
17036
            XMEMCPY(newSecret, secret, secretSz);
17037
            ssl->buffers.tls13CookieSecretSecondary.buffer = newSecret;
17038
            ssl->buffers.tls13CookieSecretSecondary.length = secretSz;
17039
        #ifdef WOLFSSL_CHECK_MEM_ZERO
17040
            wc_MemZero_Add("wolfSSL_set_hrr_cookie_secret_secondary secret",
17041
                ssl->buffers.tls13CookieSecretSecondary.buffer,
17042
                ssl->buffers.tls13CookieSecretSecondary.length);
17043
        #endif
17044
            ret = WOLFSSL_SUCCESS;
17045
        }
17046
    }
17047
#else
17048
    (void)secret;
17049
    (void)secretSz;
17050
17051
    ret = SIDE_ERROR;
17052
#endif
17053
17054
    return ret;
17055
}
17056
17057
#endif /* defined(WOLFSSL_SEND_HRR_COOKIE) */
17058
17059
#ifdef HAVE_SUPPORTED_CURVES
17060
/* Create a key share entry from group.
17061
 * Generates a key pair.
17062
 *
17063
 * ssl    The SSL/TLS object.
17064
 * group  The named group.
17065
 * returns 0 on success, otherwise failure.
17066
 *   for async can return WC_PENDING_E and should be called again
17067
 */
17068
int wolfSSL_UseKeyShare(WOLFSSL* ssl, word16 group)
17069
0
{
17070
0
    int ret;
17071
17072
0
    if (ssl == NULL)
17073
0
        return BAD_FUNC_ARG;
17074
17075
#ifdef WOLFSSL_ASYNC_CRYPT
17076
    ret = wolfSSL_AsyncPop(ssl, NULL);
17077
    if (ret != WC_NO_ERR_TRACE(WC_NO_PENDING_E)) {
17078
        /* Check for error */
17079
        if (ret < 0)
17080
            return ret;
17081
    }
17082
#endif
17083
17084
0
#if defined(WOLFSSL_HAVE_MLKEM)
17085
0
    if (WOLFSSL_NAMED_GROUP_IS_PQC(group) ||
17086
0
        WOLFSSL_NAMED_GROUP_IS_PQC_HYBRID(group)) {
17087
17088
0
        if (!IsAtLeastTLSv1_3(ssl->version)) {
17089
0
            return BAD_FUNC_ARG;
17090
0
        }
17091
17092
0
        if (ssl->options.side == WOLFSSL_SERVER_END) {
17093
            /* If I am the server of a KEM connection, do not do keygen because
17094
             * I'm going to encapsulate with the client's public key. Note that
17095
             * I might be the client and ssl->option.side has not been properly
17096
             * set yet. In that case the KeyGen operation will be deferred to
17097
             * connection time. */
17098
0
            return WOLFSSL_SUCCESS;
17099
0
        }
17100
0
    }
17101
0
#endif
17102
#if defined(NO_TLS)
17103
    (void)ret;
17104
    (void)group;
17105
#else
17106
    /* Check if the group is supported. */
17107
0
    if (!TLSX_IsGroupSupported(group, ssl->options.side)) {
17108
0
        WOLFSSL_MSG("Group not supported.");
17109
0
        return BAD_FUNC_ARG;
17110
0
    }
17111
17112
0
    ret = TLSX_KeyShare_Use(ssl, group, 0, NULL, NULL, &ssl->extensions);
17113
0
    if (ret != 0)
17114
0
        return ret;
17115
0
#endif /* NO_TLS */
17116
0
    return WOLFSSL_SUCCESS;
17117
0
}
17118
17119
/* Send no key share entries - use HelloRetryRequest to negotiate shared group.
17120
 *
17121
 * ssl    The SSL/TLS object.
17122
 * returns 0 on success, otherwise failure.
17123
 */
17124
int wolfSSL_NoKeyShares(WOLFSSL* ssl)
17125
0
{
17126
0
    int ret;
17127
17128
0
    if (ssl == NULL)
17129
0
        return BAD_FUNC_ARG;
17130
0
    if (ssl->options.side == WOLFSSL_SERVER_END)
17131
0
        return SIDE_ERROR;
17132
#if defined(NO_TLS)
17133
    (void)ret;
17134
#else
17135
0
    ret = TLSX_KeyShare_Empty(ssl);
17136
0
    if (ret != 0)
17137
0
        return ret;
17138
0
#endif /* NO_TLS */
17139
0
    return WOLFSSL_SUCCESS;
17140
0
}
17141
#endif
17142
17143
#ifdef WOLFSSL_DUAL_ALG_CERTS
17144
int wolfSSL_UseCKS(WOLFSSL* ssl, byte *sigSpec, word16 sigSpecSz)
17145
{
17146
    if (ssl == NULL || !IsAtLeastTLSv1_3(ssl->ctx->method->version) ||
17147
        sigSpec == NULL || sigSpecSz == 0)
17148
        return BAD_FUNC_ARG;
17149
17150
    ssl->sigSpec = sigSpec;
17151
    ssl->sigSpecSz = sigSpecSz;
17152
    return WOLFSSL_SUCCESS;
17153
}
17154
17155
int wolfSSL_CTX_UseCKS(WOLFSSL_CTX* ctx, byte *sigSpec, word16 sigSpecSz)
17156
{
17157
    if (ctx == NULL || !IsAtLeastTLSv1_3(ctx->method->version) ||
17158
        sigSpec == NULL || sigSpecSz == 0)
17159
        return BAD_FUNC_ARG;
17160
17161
    ctx->sigSpec = sigSpec;
17162
    ctx->sigSpecSz = sigSpecSz;
17163
    return WOLFSSL_SUCCESS;
17164
}
17165
#endif /* WOLFSSL_DUAL_ALG_CERTS */
17166
17167
/* Do not send a ticket after TLS v1.3 handshake for resumption.
17168
 *
17169
 * ctx  The SSL/TLS CTX object.
17170
 * returns BAD_FUNC_ARG when ctx is NULL and 0 on success.
17171
 */
17172
int wolfSSL_CTX_no_ticket_TLSv13(WOLFSSL_CTX* ctx)
17173
0
{
17174
0
    if (ctx == NULL || !IsAtLeastTLSv1_3(ctx->method->version))
17175
0
        return BAD_FUNC_ARG;
17176
0
    if (ctx->method->side == WOLFSSL_CLIENT_END)
17177
0
        return SIDE_ERROR;
17178
17179
0
#ifdef HAVE_SESSION_TICKET
17180
0
    ctx->noTicketTls13 = 1;
17181
0
#endif
17182
17183
0
    return 0;
17184
0
}
17185
17186
/* Do not send a ticket after TLS v1.3 handshake for resumption.
17187
 *
17188
 * ssl  The SSL/TLS object.
17189
 * returns BAD_FUNC_ARG when ssl is NULL, not using TLS v1.3, or called on
17190
 * a client and 0 on success.
17191
 */
17192
int wolfSSL_no_ticket_TLSv13(WOLFSSL* ssl)
17193
0
{
17194
0
    if (ssl == NULL || !IsAtLeastTLSv1_3(ssl->version))
17195
0
        return BAD_FUNC_ARG;
17196
0
    if (ssl->options.side == WOLFSSL_CLIENT_END)
17197
0
        return SIDE_ERROR;
17198
17199
0
#ifdef HAVE_SESSION_TICKET
17200
0
    ssl->options.noTicketTls13 = 1;
17201
0
#endif
17202
17203
0
    return 0;
17204
0
}
17205
17206
/* Disallow (EC)DHE key exchange when using pre-shared keys.
17207
 *
17208
 * ctx  The SSL/TLS CTX object.
17209
 * returns BAD_FUNC_ARG when ctx is NULL and 0 on success.
17210
 */
17211
int wolfSSL_CTX_no_dhe_psk(WOLFSSL_CTX* ctx)
17212
0
{
17213
0
    if (ctx == NULL || !IsAtLeastTLSv1_3(ctx->method->version))
17214
0
        return BAD_FUNC_ARG;
17215
17216
0
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
17217
0
    ctx->noPskDheKe = 1;
17218
0
#endif
17219
17220
0
    return 0;
17221
0
}
17222
17223
/* Disallow (EC)DHE key exchange when using pre-shared keys.
17224
 *
17225
 * ssl  The SSL/TLS object.
17226
 * returns BAD_FUNC_ARG when ssl is NULL, or not using TLS v1.3 and 0 on
17227
 * success.
17228
 */
17229
int wolfSSL_no_dhe_psk(WOLFSSL* ssl)
17230
0
{
17231
0
    if (ssl == NULL || !IsAtLeastTLSv1_3(ssl->version))
17232
0
        return BAD_FUNC_ARG;
17233
17234
0
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
17235
0
    ssl->options.noPskDheKe = 1;
17236
0
    ssl->options.noPskDheKePolicy = 1;
17237
0
#endif
17238
17239
0
    return 0;
17240
0
}
17241
17242
#ifdef HAVE_SUPPORTED_CURVES
17243
/* Only allow (EC)DHE key exchange when using pre-shared keys.
17244
 *
17245
 * ctx  The SSL/TLS CTX object.
17246
 * returns BAD_FUNC_ARG when ctx is NULL and 0 on success.
17247
 */
17248
int wolfSSL_CTX_only_dhe_psk(WOLFSSL_CTX* ctx)
17249
0
{
17250
0
    if (ctx == NULL || !IsAtLeastTLSv1_3(ctx->method->version))
17251
0
        return BAD_FUNC_ARG;
17252
17253
0
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
17254
0
    ctx->onlyPskDheKe = 1;
17255
0
#endif
17256
17257
0
    return 0;
17258
0
}
17259
17260
/* Only allow (EC)DHE key exchange when using pre-shared keys.
17261
 *
17262
 * ssl  The SSL/TLS object.
17263
 * returns BAD_FUNC_ARG when ssl is NULL, or not using TLS v1.3 and 0 on
17264
 * success.
17265
 */
17266
int wolfSSL_only_dhe_psk(WOLFSSL* ssl)
17267
0
{
17268
0
    if (ssl == NULL || !IsAtLeastTLSv1_3(ssl->version))
17269
0
        return BAD_FUNC_ARG;
17270
17271
0
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
17272
0
    ssl->options.onlyPskDheKe = 1;
17273
0
#endif
17274
17275
0
    return 0;
17276
0
}
17277
#endif /* HAVE_SUPPORTED_CURVES */
17278
17279
/* Require that an external Pre-Shared Key is negotiated for the handshake to
17280
 * succeed. TLS 1.3 / DTLS 1.3 only - in (D)TLS 1.2 the use of a PSK is
17281
 * determined by the negotiated cipher suite, so a mandatory PSK is configured
17282
 * there by restricting the cipher suite list to PSK suites.
17283
 *
17284
 * ctx  The SSL/TLS CTX object.
17285
 * returns BAD_FUNC_ARG when ctx is NULL or not at least TLS v1.3, 0 on success.
17286
 */
17287
int wolfSSL_CTX_require_psk(WOLFSSL_CTX* ctx)
17288
0
{
17289
0
    if (ctx == NULL || !IsAtLeastTLSv1_3(ctx->method->version))
17290
0
        return BAD_FUNC_ARG;
17291
17292
0
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
17293
0
    ctx->failNoPSK = 1;
17294
    /* The requirement can only be enforced for (D)TLS 1.3, so keep it
17295
     * fail-closed by disabling a version downgrade. Otherwise a
17296
     * downgrade-capable context (e.g. from a v23 method) could silently fall
17297
     * back to (D)TLS 1.2 and complete without any PSK. */
17298
0
    ctx->method->downgrade = 0;
17299
0
#endif
17300
17301
0
    return 0;
17302
0
}
17303
17304
/* Require that an external Pre-Shared Key is negotiated for the handshake to
17305
 * succeed. See wolfSSL_CTX_require_psk().
17306
 *
17307
 * ssl  The SSL/TLS object.
17308
 * returns BAD_FUNC_ARG when ssl is NULL or not at least TLS v1.3, 0 on success.
17309
 */
17310
int wolfSSL_require_psk(WOLFSSL* ssl)
17311
0
{
17312
0
    if (ssl == NULL || !IsAtLeastTLSv1_3(ssl->version))
17313
0
        return BAD_FUNC_ARG;
17314
17315
0
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
17316
0
    ssl->options.failNoPSK = 1;
17317
    /* See wolfSSL_CTX_require_psk() - keep the requirement fail-closed by
17318
     * disabling a version downgrade to (D)TLS 1.2. */
17319
0
    ssl->options.downgrade = 0;
17320
0
#endif
17321
17322
0
    return 0;
17323
0
}
17324
17325
int Tls13UpdateKeys(WOLFSSL* ssl)
17326
0
{
17327
0
    if (ssl == NULL || !IsAtLeastTLSv1_3(ssl->version))
17328
0
        return BAD_FUNC_ARG;
17329
17330
#ifdef WOLFSSL_QUIC
17331
    /* RFC 9001 Section 6: a QUIC connection must not send a TLS KeyUpdate;
17332
     * key updates are handled at the QUIC packet-protection layer. */
17333
    if (WOLFSSL_IS_QUIC(ssl))
17334
        return BAD_FUNC_ARG;
17335
#endif
17336
17337
#ifdef WOLFSSL_DTLS13
17338
    /* we are already waiting for the ack of a sent key update message. We can't
17339
       send another one before receiving its ack. Either wolfSSL_update_keys()
17340
       was invoked multiple times over a short period of time or we replied to a
17341
       KeyUpdate with update request. We'll just ignore sending this
17342
       KeyUpdate. */
17343
    /* TODO: add WOLFSSL_ERROR_ALREADY_IN_PROGRESS type of error here */
17344
    if (ssl->options.dtls && ssl->dtls13WaitKeyUpdateAck)
17345
        return 0;
17346
#endif /* WOLFSSL_DTLS13 */
17347
17348
0
    return SendTls13KeyUpdate(ssl);
17349
0
}
17350
17351
/* Update the keys for encryption and decryption.
17352
 * If using non-blocking I/O and WOLFSSL_ERROR_WANT_WRITE is returned then
17353
 * calling wolfSSL_write() will have the message sent when ready.
17354
 *
17355
 * ssl  The SSL/TLS object.
17356
 * returns BAD_FUNC_ARG when ssl is NULL, not using TLS v1.3, or running over
17357
 * QUIC (RFC 9001 handles key updates at the QUIC packet-protection layer),
17358
 * WOLFSSL_ERROR_WANT_WRITE when non-blocking I/O is not ready to write,
17359
 * WOLFSSL_SUCCESS on success and otherwise failure.
17360
 */
17361
int wolfSSL_update_keys(WOLFSSL* ssl)
17362
0
{
17363
0
    int ret;
17364
0
    ret = Tls13UpdateKeys(ssl);
17365
0
    if (ret == WC_NO_ERR_TRACE(WANT_WRITE))
17366
0
        ret = WOLFSSL_ERROR_WANT_WRITE;
17367
0
    else if (ret == 0)
17368
0
        ret = WOLFSSL_SUCCESS;
17369
0
    return ret;
17370
0
}
17371
17372
/* Whether a response is waiting for key update request.
17373
 *
17374
 * ssl        The SSL/TLS object.
17375
 * required   0 when no key update response required.
17376
 *            1 when no key update response required.
17377
 * return  0 on success.
17378
 * return  BAD_FUNC_ARG when ssl is NULL or not using TLS v1.3
17379
 */
17380
int wolfSSL_key_update_response(WOLFSSL* ssl, int* required)
17381
0
{
17382
0
    if (required == NULL || ssl == NULL || !IsAtLeastTLSv1_3(ssl->version))
17383
0
        return BAD_FUNC_ARG;
17384
17385
0
    *required = ssl->keys.updateResponseReq;
17386
17387
0
    return 0;
17388
0
}
17389
17390
#if !defined(NO_CERTS) && defined(WOLFSSL_POST_HANDSHAKE_AUTH)
17391
/* Allow post-handshake authentication in TLS v1.3 connections.
17392
 *
17393
 * ctx  The SSL/TLS CTX object.
17394
 * returns BAD_FUNC_ARG when ctx is NULL, SIDE_ERROR when not a client and
17395
 * 0 on success.
17396
 */
17397
int wolfSSL_CTX_allow_post_handshake_auth(WOLFSSL_CTX* ctx)
17398
{
17399
    if (ctx == NULL || !IsAtLeastTLSv1_3(ctx->method->version))
17400
        return BAD_FUNC_ARG;
17401
    if (ctx->method->side == WOLFSSL_SERVER_END)
17402
        return SIDE_ERROR;
17403
17404
    ctx->postHandshakeAuth = 1;
17405
17406
    return 0;
17407
}
17408
17409
/* Allow post-handshake authentication in TLS v1.3 connection.
17410
 *
17411
 * ssl  The SSL/TLS object.
17412
 * returns BAD_FUNC_ARG when ssl is NULL, not using TLS v1.3, or running over
17413
 * QUIC, SIDE_ERROR when not a client, BAD_STATE_E when called after the
17414
 * handshake has started, and 0 on success.
17415
 *
17416
 * Must be called before wolfSSL_connect() so the post_handshake_auth
17417
 * extension can be included in the ClientHello.
17418
 */
17419
int wolfSSL_allow_post_handshake_auth(WOLFSSL* ssl)
17420
{
17421
    if (ssl == NULL || !IsAtLeastTLSv1_3(ssl->version))
17422
        return BAD_FUNC_ARG;
17423
#ifdef WOLFSSL_QUIC
17424
    if (WOLFSSL_IS_QUIC(ssl))
17425
        return BAD_FUNC_ARG;
17426
#endif
17427
    if (ssl->options.side == WOLFSSL_SERVER_END)
17428
        return SIDE_ERROR;
17429
    if (ssl->options.handShakeState != NULL_STATE)
17430
        return BAD_STATE_E;
17431
17432
    ssl->options.postHandshakeAuth = 1;
17433
17434
    return 0;
17435
}
17436
17437
/* Request a certificate of the client.
17438
 * Can be called any time after handshake completion.
17439
 * A maximum of 256 requests can be sent on a connection.
17440
 *
17441
 * ssl  SSL/TLS object.
17442
 */
17443
int wolfSSL_request_certificate(WOLFSSL* ssl)
17444
{
17445
    int         ret;
17446
#ifndef NO_WOLFSSL_SERVER
17447
    CertReqCtx* certReqCtx;
17448
#endif
17449
17450
    if (ssl == NULL || !IsAtLeastTLSv1_3(ssl->version))
17451
        return BAD_FUNC_ARG;
17452
#ifdef WOLFSSL_QUIC
17453
    if (WOLFSSL_IS_QUIC(ssl))
17454
        return BAD_FUNC_ARG;
17455
#endif
17456
#ifndef NO_WOLFSSL_SERVER
17457
    if (ssl->options.side == WOLFSSL_CLIENT_END)
17458
        return SIDE_ERROR;
17459
    if (ssl->options.handShakeState != HANDSHAKE_DONE)
17460
        return NOT_READY_ERROR;
17461
    if (!ssl->options.postHandshakeAuth)
17462
        return POST_HAND_AUTH_ERROR;
17463
    if (ssl->certReqCtx != NULL) {
17464
        if (ssl->certReqCtx->len != 1)
17465
            return BAD_STATE_E;
17466
        /* We support sending up to 255 certificate requests */
17467
        if (ssl->certReqCtx->ctx == 255)
17468
            return BAD_STATE_E;
17469
    }
17470
17471
    certReqCtx = (CertReqCtx*)XMALLOC(sizeof(CertReqCtx), ssl->heap,
17472
                                                       DYNAMIC_TYPE_TMP_BUFFER);
17473
    if (certReqCtx == NULL)
17474
        return MEMORY_E;
17475
    XMEMSET(certReqCtx, 0, sizeof(CertReqCtx));
17476
    certReqCtx->next = ssl->certReqCtx;
17477
    certReqCtx->len = 1;
17478
    if (certReqCtx->next != NULL)
17479
        certReqCtx->ctx = certReqCtx->next->ctx + 1;
17480
    ssl->certReqCtx = certReqCtx;
17481
17482
    ssl->msgsReceived.got_certificate = 0;
17483
    ssl->msgsReceived.got_certificate_verify = 0;
17484
    ssl->msgsReceived.got_finished = 0;
17485
    /* Each round must prove possession again; these are only ever set to 1. */
17486
    ssl->options.havePeerCert = 0;
17487
    ssl->options.havePeerVerify = 0;
17488
17489
    ret = SendTls13CertificateRequest(ssl, &certReqCtx->ctx, certReqCtx->len);
17490
    if (ret == WC_NO_ERR_TRACE(WANT_WRITE))
17491
        ret = WOLFSSL_ERROR_WANT_WRITE;
17492
    else if (ret == 0)
17493
        ret = WOLFSSL_SUCCESS;
17494
#else
17495
    ret = SIDE_ERROR;
17496
#endif
17497
17498
    return ret;
17499
}
17500
#endif /* !NO_CERTS && WOLFSSL_POST_HANDSHAKE_AUTH */
17501
17502
#if !defined(WOLFSSL_NO_SERVER_GROUPS_EXT)
17503
/* Get the preferred key exchange group.
17504
 *
17505
 * ssl  The SSL/TLS object.
17506
 * returns BAD_FUNC_ARG when ssl is NULL or not using TLS v1.3,
17507
 * SIDE_ERROR when not a client, NOT_READY_ERROR when handshake not complete
17508
 * and group number on success.
17509
 */
17510
int wolfSSL_preferred_group(WOLFSSL* ssl)
17511
0
{
17512
0
    if (ssl == NULL || !IsAtLeastTLSv1_3(ssl->version))
17513
0
        return BAD_FUNC_ARG;
17514
0
#ifndef NO_WOLFSSL_CLIENT
17515
0
    if (ssl->options.side == WOLFSSL_SERVER_END)
17516
0
        return SIDE_ERROR;
17517
0
    if (ssl->options.handShakeState != HANDSHAKE_DONE)
17518
0
        return NOT_READY_ERROR;
17519
17520
0
#ifdef HAVE_SUPPORTED_CURVES
17521
    /* Return supported groups only. */
17522
0
    return TLSX_SupportedCurve_Preferred(ssl, 1);
17523
#else
17524
    return 0;
17525
#endif
17526
#else
17527
    return SIDE_ERROR;
17528
#endif
17529
0
}
17530
#endif
17531
17532
#ifndef NO_PSK
17533
/* Set the PSK callback, that is passed the cipher suite, for a client to use
17534
 * against context object.
17535
 *
17536
 * @param [in, out] ctx  SSL/TLS context object.
17537
 * @param [in]      cb   Client PSK callback passed a cipher suite.
17538
 */
17539
void wolfSSL_CTX_set_psk_client_cs_callback(WOLFSSL_CTX* ctx,
17540
                                            wc_psk_client_cs_callback cb)
17541
{
17542
    WOLFSSL_ENTER("wolfSSL_CTX_set_psk_client_cs_callback");
17543
17544
    if (ctx == NULL)
17545
        return;
17546
17547
    ctx->havePSK = 1;
17548
    ctx->client_psk_cs_cb = cb;
17549
}
17550
17551
/* Set the PSK callback, that is passed the cipher suite, for a client to use
17552
 * against SSL object.
17553
 *
17554
 * @param [in, out] ssl  SSL/TLS object.
17555
 * @param [in]      cb   Client PSK callback passed a cipher suite.
17556
 */
17557
void wolfSSL_set_psk_client_cs_callback(WOLFSSL* ssl,
17558
                                        wc_psk_client_cs_callback cb)
17559
{
17560
    byte haveRSA = 1;
17561
    int  keySz   = 0;
17562
17563
    WOLFSSL_ENTER("wolfSSL_set_psk_client_cs_callback");
17564
17565
    if (ssl == NULL)
17566
        return;
17567
17568
    ssl->options.havePSK = 1;
17569
    ssl->options.client_psk_cs_cb = cb;
17570
17571
    #ifdef NO_RSA
17572
        haveRSA = 0;
17573
    #endif
17574
    #ifndef NO_CERTS
17575
        keySz = ssl->buffers.keySz;
17576
    #endif
17577
    if (AllocateSuites(ssl) != 0)
17578
        return;
17579
    InitSuites(ssl->suites, ssl->version, keySz, haveRSA, TRUE,
17580
               ssl->options.haveDH, ssl->options.haveECDSAsig,
17581
               ssl->options.haveECC, TRUE, ssl->options.haveStaticECC,
17582
               ssl->options.useAnon, TRUE, TRUE, TRUE, TRUE, ssl->options.side);
17583
}
17584
17585
/* Set the PSK callback that returns the cipher suite for a client to use
17586
 * against context object.
17587
 *
17588
 * @param [in, out] ctx  SSL/TLS context object.
17589
 * @param [in]      cb   Client PSK callback returning cipher suite.
17590
 */
17591
void wolfSSL_CTX_set_psk_client_tls13_callback(WOLFSSL_CTX* ctx,
17592
                                               wc_psk_client_tls13_callback cb)
17593
{
17594
    WOLFSSL_ENTER("wolfSSL_CTX_set_psk_client_tls13_callback");
17595
17596
    if (ctx == NULL)
17597
        return;
17598
17599
    ctx->havePSK = 1;
17600
    ctx->client_psk_tls13_cb = cb;
17601
}
17602
17603
/* Set the PSK callback that returns the cipher suite for a client to use
17604
 * against SSL object.
17605
 *
17606
 * @param [in, out] ssl  SSL/TLS object.
17607
 * @param [in]      cb   Client PSK callback returning cipher suite.
17608
 */
17609
void wolfSSL_set_psk_client_tls13_callback(WOLFSSL* ssl,
17610
                                           wc_psk_client_tls13_callback cb)
17611
{
17612
    byte haveRSA = 1;
17613
    int  keySz   = 0;
17614
17615
    WOLFSSL_ENTER("wolfSSL_set_psk_client_tls13_callback");
17616
17617
    if (ssl == NULL)
17618
        return;
17619
17620
    ssl->options.havePSK = 1;
17621
    ssl->options.client_psk_tls13_cb = cb;
17622
17623
    #ifdef NO_RSA
17624
        haveRSA = 0;
17625
    #endif
17626
    #ifndef NO_CERTS
17627
        keySz = ssl->buffers.keySz;
17628
    #endif
17629
    if (AllocateSuites(ssl) != 0)
17630
        return;
17631
    InitSuites(ssl->suites, ssl->version, keySz, haveRSA, TRUE,
17632
               ssl->options.haveDH, ssl->options.haveECDSAsig,
17633
               ssl->options.haveECC, TRUE, ssl->options.haveStaticECC,
17634
               ssl->options.useAnon, TRUE, TRUE, TRUE, TRUE, ssl->options.side);
17635
}
17636
17637
/* Set the PSK callback that returns the cipher suite for a server to use
17638
 * against context object.
17639
 *
17640
 * @param [in, out] ctx  SSL/TLS context object.
17641
 * @param [in]      cb   Server PSK callback returning cipher suite.
17642
 */
17643
void wolfSSL_CTX_set_psk_server_tls13_callback(WOLFSSL_CTX* ctx,
17644
                                               wc_psk_server_tls13_callback cb)
17645
{
17646
    WOLFSSL_ENTER("wolfSSL_CTX_set_psk_server_tls13_callback");
17647
    if (ctx == NULL)
17648
        return;
17649
    ctx->havePSK = 1;
17650
    ctx->server_psk_tls13_cb = cb;
17651
}
17652
17653
/* Set the PSK callback that returns the cipher suite for a server to use
17654
 * against SSL object.
17655
 *
17656
 * @param [in, out] ssl  SSL/TLS object.
17657
 * @param [in]      cb   Server PSK callback returning cipher suite.
17658
 */
17659
void wolfSSL_set_psk_server_tls13_callback(WOLFSSL* ssl,
17660
                                           wc_psk_server_tls13_callback cb)
17661
{
17662
    byte haveRSA = 1;
17663
    int  keySz   = 0;
17664
17665
    WOLFSSL_ENTER("wolfSSL_set_psk_server_tls13_callback");
17666
    if (ssl == NULL)
17667
        return;
17668
17669
    ssl->options.havePSK = 1;
17670
    ssl->options.server_psk_tls13_cb = cb;
17671
17672
    #ifdef NO_RSA
17673
        haveRSA = 0;
17674
    #endif
17675
    #ifndef NO_CERTS
17676
        keySz = ssl->buffers.keySz;
17677
    #endif
17678
    if (AllocateSuites(ssl) != 0)
17679
        return;
17680
    InitSuites(ssl->suites, ssl->version, keySz, haveRSA, TRUE,
17681
               ssl->options.haveDH, ssl->options.haveECDSAsig,
17682
               ssl->options.haveECC, TRUE, ssl->options.haveStaticECC,
17683
               ssl->options.useAnon, TRUE, TRUE, TRUE, TRUE, ssl->options.side);
17684
}
17685
17686
/* Get name of first supported cipher suite that uses the hash indicated.
17687
 *
17688
 * @param [in] ssl   SSL/TLS object.
17689
 * @param [in] hash  Name of hash algorithm. e.g. "SHA256", "SHA384"
17690
 * @return  Name of cipher suite.
17691
 * @return  NULL on failure.
17692
 */
17693
const char* wolfSSL_get_cipher_name_by_hash(WOLFSSL* ssl, const char* hash)
17694
{
17695
    const char* name = NULL;
17696
    byte mac = no_mac;
17697
    int i;
17698
    const Suites* suites;
17699
17700
    if (hash == NULL || ssl == NULL ||
17701
        (ssl->suites == NULL && ssl->ctx == NULL))
17702
        return NULL;
17703
17704
    suites = WOLFSSL_SUITES(ssl);
17705
    if (suites == NULL)
17706
        return NULL;
17707
17708
    if (XSTRCMP(hash, "SHA256") == 0) {
17709
        mac = sha256_mac;
17710
    }
17711
    else if (XSTRCMP(hash, "SHA384") == 0) {
17712
        mac = sha384_mac;
17713
    }
17714
    if (mac != no_mac) {
17715
        for (i = 0; i < suites->suiteSz; i += 2) {
17716
            if (SuiteMac(suites->suites + i) == mac) {
17717
                name = GetCipherNameInternal(suites->suites[i + 0],
17718
                                             suites->suites[i + 1]);
17719
                break;
17720
            }
17721
        }
17722
    }
17723
    return name;
17724
}
17725
#endif /* !NO_PSK */
17726
17727
17728
#ifndef NO_WOLFSSL_SERVER
17729
17730
/* Send the RFC 8446 Appendix D.4 ChangeCipherSpec a server owes a client that
17731
 * offered a non-empty legacy_session_id.
17732
 *
17733
 * ssl    The SSL/TLS object.
17734
 * flush  Force the record out on its own. A HelloRetryRequest needs this
17735
 *        because SendTls13ServerHello has already sent it, unlike a
17736
 *        ServerHello, which waits for the rest of its flight.
17737
 * returns 0 on success.
17738
 */
17739
static int SendTls13ServerChangeCipher(WOLFSSL* ssl, int flush)
17740
0
{
17741
0
    int ret;
17742
17743
    /* DoTls13ClientHello clears tls13MiddleBoxCompat for a QUIC peer, so the
17744
     * check here is a local backstop, 0 when QUIC is not built. */
17745
0
    if (ssl->options.dtls || WOLFSSL_IS_QUIC(ssl)
17746
0
            || !ssl->options.tls13MiddleBoxCompat
17747
0
            || ssl->options.sentChangeCipher) {
17748
0
        return 0;
17749
0
    }
17750
17751
0
    ret = SendChangeCipher(ssl);
17752
    /* A short send leaves the record queued in the output buffer. Mark it sent
17753
     * anyway, or the resumed accept, which comes back in at the ServerHello
17754
     * case, puts a second record on the wire. */
17755
0
    if (ret == 0 || ret == WC_NO_ERR_TRACE(WANT_WRITE))
17756
0
        ssl->options.sentChangeCipher = 1;
17757
0
    if (ret == 0 && flush && ssl->options.groupMessages)
17758
0
        ret = SendBuffered(ssl);
17759
17760
0
    return ret;
17761
0
}
17762
17763
/* The server accepting a connection from a client.
17764
 * The protocol version is expecting to be TLS v1.3.
17765
 * If the client downgrades, and older versions of the protocol are compiled
17766
 * in, the server will fallback to wolfSSL_accept().
17767
 * Please see note at top of README if you get an error from accept.
17768
 *
17769
 * ssl  The SSL/TLS object.
17770
 * returns WOLFSSL_SUCCESS on successful handshake, WOLFSSL_FATAL_ERROR when
17771
 * unrecoverable error occurs and 0 otherwise.
17772
 * For more error information use wolfSSL_get_error().
17773
 */
17774
int wolfSSL_accept_TLSv13(WOLFSSL* ssl)
17775
{
17776
#if !defined(NO_CERTS) && (defined(HAVE_SESSION_TICKET) || !defined(NO_PSK))
17777
    word16 havePSK = 0;
17778
#endif
17779
    int ret = 0;
17780
17781
    WOLFSSL_ENTER("wolfSSL_accept_TLSv13");
17782
17783
#ifdef HAVE_ERRNO_H
17784
    errno = 0;
17785
#endif
17786
17787
    if (ssl == NULL)
17788
        return WOLFSSL_FATAL_ERROR;
17789
17790
#if !defined(NO_CERTS) && (defined(HAVE_SESSION_TICKET) || !defined(NO_PSK))
17791
    havePSK = ssl->options.havePSK;
17792
#endif
17793
17794
    if (ssl->options.side != WOLFSSL_SERVER_END) {
17795
        ssl->error = SIDE_ERROR;
17796
        WOLFSSL_ERROR(ssl->error);
17797
        return WOLFSSL_FATAL_ERROR;
17798
    }
17799
17800
    /* make sure this wolfSSL object has arrays and rng setup. Protects
17801
     * case where the WOLFSSL object is reused via wolfSSL_clear() */
17802
    if ((ret = ReinitSSL(ssl, ssl->ctx, 0)) != 0) {
17803
        return ret;
17804
    }
17805
17806
#ifdef WOLFSSL_DTLS
17807
    if (ssl->version.major == DTLS_MAJOR) {
17808
        ssl->options.dtls   = 1;
17809
        if (!IsDtlsNotSctpMode(ssl) || !ssl->options.sendCookie)
17810
            ssl->options.dtlsStateful = 1;
17811
    }
17812
#endif
17813
17814
#ifdef WOLFSSL_WOLFSENTRY_HOOKS
17815
    if ((ssl->AcceptFilter != NULL) &&
17816
            ((ssl->options.acceptState == TLS13_ACCEPT_BEGIN)
17817
#ifdef HAVE_SECURE_RENEGOTIATION
17818
             || (ssl->options.acceptState == TLS13_ACCEPT_BEGIN_RENEG)
17819
#endif
17820
                ))
17821
    {
17822
        wolfSSL_netfilter_decision_t res;
17823
        if ((ssl->AcceptFilter(ssl, ssl->AcceptFilter_arg, &res) ==
17824
             WOLFSSL_SUCCESS) &&
17825
            (res == WOLFSSL_NETFILTER_REJECT)) {
17826
            ssl->error = SOCKET_FILTERED_E;
17827
            WOLFSSL_ERROR(ssl->error);
17828
            return WOLFSSL_FATAL_ERROR;
17829
        }
17830
    }
17831
#endif /* WOLFSSL_WOLFSENTRY_HOOKS */
17832
17833
#ifndef NO_CERTS
17834
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
17835
    if (!havePSK)
17836
#endif
17837
    {
17838
    #if defined(OPENSSL_ALL) || defined(OPENSSL_EXTRA) || \
17839
        defined(WOLFSSL_NGINX) || defined (WOLFSSL_HAPROXY)
17840
        if (ssl->ctx->certSetupCb != NULL) {
17841
            WOLFSSL_MSG("CertSetupCb set. server cert and "
17842
                        "key not checked");
17843
        }
17844
        else
17845
    #endif
17846
        {
17847
            if (!ssl->buffers.certificate ||
17848
                !ssl->buffers.certificate->buffer) {
17849
17850
                WOLFSSL_MSG("accept error: server cert required");
17851
                ssl->error = NO_PRIVATE_KEY;
17852
                WOLFSSL_ERROR(ssl->error);
17853
                return WOLFSSL_FATAL_ERROR;
17854
            }
17855
17856
            if (!ssl->buffers.key || !ssl->buffers.key->buffer) {
17857
                /* allow no private key if using existing key */
17858
            #ifdef WOLF_PRIVATE_KEY_ID
17859
                if (ssl->devId != INVALID_DEVID
17860
                #ifdef HAVE_PK_CALLBACKS
17861
                    || wolfSSL_CTX_IsPrivatePkSet(ssl->ctx)
17862
                #endif
17863
                ) {
17864
                    WOLFSSL_MSG("Allowing no server private key (external)");
17865
                }
17866
                else
17867
            #endif
17868
                {
17869
                    WOLFSSL_MSG("accept error: server key required");
17870
                    ssl->error = NO_PRIVATE_KEY;
17871
                    WOLFSSL_ERROR(ssl->error);
17872
                    return WOLFSSL_FATAL_ERROR;
17873
                }
17874
            }
17875
        }
17876
    }
17877
#endif /* NO_CERTS */
17878
17879
    if (ssl->buffers.outputBuffer.length > 0
17880
    #ifdef WOLFSSL_ASYNC_CRYPT
17881
        /* do not send buffered or advance state if last error was an
17882
            async pending operation */
17883
        && ssl->error != WC_NO_ERR_TRACE(WC_PENDING_E)
17884
    #endif
17885
    ) {
17886
17887
        /* fragOffset is non-zero when sending fragments. On the last
17888
         * fragment, fragOffset is zero again, and the state can be
17889
         * advanced. */
17890
        int advanceState =
17891
            (ssl->options.acceptState == TLS13_ACCEPT_CLIENT_HELLO_DONE ||
17892
                ssl->options.acceptState ==
17893
                    TLS13_ACCEPT_HELLO_RETRY_REQUEST_DONE ||
17894
                ssl->options.acceptState == TLS13_ACCEPT_SECOND_REPLY_DONE ||
17895
                ssl->options.acceptState == TLS13_SERVER_HELLO_SENT ||
17896
                ssl->options.acceptState == TLS13_ACCEPT_THIRD_REPLY_DONE ||
17897
                ssl->options.acceptState == TLS13_SERVER_EXTENSIONS_SENT ||
17898
                ssl->options.acceptState == TLS13_CERT_REQ_SENT ||
17899
                ssl->options.acceptState == TLS13_CERT_SENT ||
17900
                ssl->options.acceptState == TLS13_CERT_VERIFY_SENT ||
17901
                ssl->options.acceptState == TLS13_ACCEPT_FINISHED_SENT ||
17902
                ssl->options.acceptState == TLS13_ACCEPT_FINISHED_DONE);
17903
17904
#ifdef WOLFSSL_DTLS13
17905
        if (ssl->options.dtls)
17906
            advanceState = advanceState && !ssl->dtls13SendingFragments
17907
                && !ssl->dtls13SendingAckOrRtx;
17908
#endif /* WOLFSSL_DTLS13 */
17909
17910
        ret = SendBuffered(ssl);
17911
        if (ret == 0) {
17912
            if (ssl->fragOffset == 0 && !ssl->options.buildingMsg) {
17913
                if (advanceState) {
17914
                    ssl->options.acceptState++;
17915
                    WOLFSSL_MSG("accept state: "
17916
                                "Advanced from last buffered fragment send");
17917
#ifdef WOLFSSL_ASYNC_IO
17918
                    FreeAsyncCtx(ssl, 0);
17919
#endif
17920
                }
17921
            }
17922
            else {
17923
                WOLFSSL_MSG("accept state: "
17924
                            "Not advanced, more fragments to send");
17925
            }
17926
17927
#ifdef WOLFSSL_DTLS13
17928
            if (ssl->options.dtls)
17929
                ssl->dtls13SendingAckOrRtx = 0;
17930
#endif /* WOLFSSL_DTLS13 */
17931
17932
        }
17933
        else {
17934
            ssl->error = ret;
17935
            WOLFSSL_ERROR(ssl->error);
17936
            return WOLFSSL_FATAL_ERROR;
17937
        }
17938
    }
17939
17940
    ret = RetrySendAlert(ssl);
17941
    if (ret != 0) {
17942
        ssl->error = ret;
17943
        WOLFSSL_ERROR(ssl->error);
17944
        return WOLFSSL_FATAL_ERROR;
17945
    }
17946
#ifdef WOLFSSL_DTLS13
17947
    if (ssl->options.dtls && ssl->dtls13SendingFragments) {
17948
        if ((ssl->error = Dtls13FragmentsContinue(ssl)) != 0) {
17949
                WOLFSSL_ERROR(ssl->error);
17950
                return WOLFSSL_FATAL_ERROR;
17951
        }
17952
17953
        /* we sent all the fragments. Advance state. */
17954
        ssl->options.acceptState++;
17955
    }
17956
#endif /* WOLFSSL_DTLS13 */
17957
17958
    switch (ssl->options.acceptState) {
17959
17960
#ifdef HAVE_SECURE_RENEGOTIATION
17961
        case TLS13_ACCEPT_BEGIN_RENEG:
17962
#endif
17963
        case TLS13_ACCEPT_BEGIN :
17964
            /* get client_hello */
17965
17966
            while (ssl->options.clientState < CLIENT_HELLO_COMPLETE) {
17967
                if ((ssl->error = ProcessReply(ssl)) < 0) {
17968
                    WOLFSSL_ERROR(ssl->error);
17969
                    return WOLFSSL_FATAL_ERROR;
17970
                }
17971
17972
#ifdef WOLFSSL_DTLS13
17973
                if (ssl->options.dtls) {
17974
                    if ((ssl->error = Dtls13DoScheduledWork(ssl)) < 0) {
17975
                        WOLFSSL_ERROR(ssl->error);
17976
                        return WOLFSSL_FATAL_ERROR;
17977
                    }
17978
                }
17979
#endif /* WOLFSSL_DTLS13 */
17980
17981
            }
17982
17983
            ssl->options.acceptState = TLS13_ACCEPT_CLIENT_HELLO_DONE;
17984
            WOLFSSL_MSG("accept state ACCEPT_CLIENT_HELLO_DONE");
17985
            if (!IsAtLeastTLSv1_3(ssl->version))
17986
                return wolfSSL_accept(ssl);
17987
            FALL_THROUGH;
17988
17989
        case TLS13_ACCEPT_CLIENT_HELLO_DONE :
17990
            if (ssl->options.serverState ==
17991
                                          SERVER_HELLO_RETRY_REQUEST_COMPLETE) {
17992
                if ((ssl->error = SendTls13ServerHello(ssl,
17993
                                                   hello_retry_request)) != 0) {
17994
                    WOLFSSL_ERROR(ssl->error);
17995
                    return WOLFSSL_FATAL_ERROR;
17996
                }
17997
            }
17998
17999
            ssl->options.acceptState = TLS13_ACCEPT_HELLO_RETRY_REQUEST_DONE;
18000
            WOLFSSL_MSG("accept state ACCEPT_HELLO_RETRY_REQUEST_DONE");
18001
            FALL_THROUGH;
18002
18003
        case TLS13_ACCEPT_HELLO_RETRY_REQUEST_DONE :
18004
            if (ssl->options.serverState ==
18005
                                          SERVER_HELLO_RETRY_REQUEST_COMPLETE) {
18006
                ssl->error = SendTls13ServerChangeCipher(ssl, 1);
18007
                if (ssl->error != 0) {
18008
                    WOLFSSL_ERROR(ssl->error);
18009
                    return WOLFSSL_FATAL_ERROR;
18010
                }
18011
            }
18012
            ssl->options.acceptState = TLS13_ACCEPT_FIRST_REPLY_DONE;
18013
            WOLFSSL_MSG("accept state ACCEPT_FIRST_REPLY_DONE");
18014
            FALL_THROUGH;
18015
18016
        case TLS13_ACCEPT_FIRST_REPLY_DONE :
18017
            if (ssl->options.serverState ==
18018
                                          SERVER_HELLO_RETRY_REQUEST_COMPLETE) {
18019
                ssl->options.clientState = CLIENT_HELLO_RETRY;
18020
                while (ssl->options.clientState < CLIENT_HELLO_COMPLETE) {
18021
                    if ((ssl->error = ProcessReply(ssl)) < 0) {
18022
                        WOLFSSL_ERROR(ssl->error);
18023
                        return WOLFSSL_FATAL_ERROR;
18024
                    }
18025
18026
#ifdef WOLFSSL_DTLS13
18027
                if (ssl->options.dtls) {
18028
                    if ((ssl->error = Dtls13DoScheduledWork(ssl)) < 0) {
18029
                        WOLFSSL_ERROR(ssl->error);
18030
                        return WOLFSSL_FATAL_ERROR;
18031
                    }
18032
                }
18033
#endif /* WOLFSSL_DTLS13 */
18034
18035
                }
18036
            }
18037
18038
            ssl->options.acceptState = TLS13_ACCEPT_SECOND_REPLY_DONE;
18039
            WOLFSSL_MSG("accept state ACCEPT_SECOND_REPLY_DONE");
18040
            FALL_THROUGH;
18041
18042
        case TLS13_ACCEPT_SECOND_REPLY_DONE :
18043
            if (ssl->options.returnOnGoodCh) {
18044
                /* Higher level in stack wants us to return. Simulate a
18045
                 * WANT_WRITE to accomplish this. */
18046
                ssl->error = WANT_WRITE;
18047
                return WOLFSSL_FATAL_ERROR;
18048
            }
18049
18050
            if ((ssl->error = SendTls13ServerHello(ssl, server_hello)) != 0) {
18051
                WOLFSSL_ERROR(ssl->error);
18052
                return WOLFSSL_FATAL_ERROR;
18053
            }
18054
            ssl->options.acceptState = TLS13_SERVER_HELLO_SENT;
18055
            WOLFSSL_MSG("accept state SERVER_HELLO_SENT");
18056
            FALL_THROUGH;
18057
18058
        case TLS13_SERVER_HELLO_SENT :
18059
            ssl->error = SendTls13ServerChangeCipher(ssl, 0);
18060
            if (ssl->error != 0) {
18061
                WOLFSSL_ERROR(ssl->error);
18062
                return WOLFSSL_FATAL_ERROR;
18063
            }
18064
18065
            ssl->options.acceptState = TLS13_ACCEPT_THIRD_REPLY_DONE;
18066
            WOLFSSL_MSG("accept state ACCEPT_THIRD_REPLY_DONE");
18067
            FALL_THROUGH;
18068
18069
        case TLS13_ACCEPT_THIRD_REPLY_DONE :
18070
    #ifdef HAVE_SUPPORTED_CURVES
18071
        #if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
18072
            if (!ssl->options.noPskDheKe)
18073
        #endif
18074
            {
18075
                ssl->error = TLSX_KeyShare_DeriveSecret(ssl);
18076
                if (ssl->error != 0)
18077
                    return WOLFSSL_FATAL_ERROR;
18078
            }
18079
    #endif
18080
18081
            if ((ssl->error = SendTls13EncryptedExtensions(ssl)) != 0) {
18082
                WOLFSSL_ERROR(ssl->error);
18083
                return WOLFSSL_FATAL_ERROR;
18084
            }
18085
            ssl->options.acceptState = TLS13_SERVER_EXTENSIONS_SENT;
18086
            WOLFSSL_MSG("accept state SERVER_EXTENSIONS_SENT");
18087
            FALL_THROUGH;
18088
18089
        case TLS13_SERVER_EXTENSIONS_SENT :
18090
#ifndef NO_CERTS
18091
            if (!ssl->options.resuming) {
18092
                if (ssl->options.verifyPeer
18093
    #ifdef WOLFSSL_POST_HANDSHAKE_AUTH
18094
                    && !ssl->options.verifyPostHandshake
18095
    #endif
18096
                   ) {
18097
                    ssl->error = SendTls13CertificateRequest(ssl, NULL, 0);
18098
                    if (ssl->error != 0) {
18099
                        WOLFSSL_ERROR(ssl->error);
18100
                        return WOLFSSL_FATAL_ERROR;
18101
                    }
18102
                }
18103
                else {
18104
                    /* SERVER: Peer auth good if not verifying client. */
18105
                    ssl->options.peerAuthGood = 1;
18106
                }
18107
            }
18108
#endif
18109
            ssl->options.acceptState = TLS13_CERT_REQ_SENT;
18110
            WOLFSSL_MSG("accept state CERT_REQ_SENT");
18111
            FALL_THROUGH;
18112
18113
        case TLS13_CERT_REQ_SENT :
18114
#ifndef NO_CERTS
18115
            if (!ssl->options.resuming && ssl->options.sendVerify) {
18116
                if ((ssl->error = SendTls13Certificate(ssl)) != 0) {
18117
                    WOLFSSL_ERROR(ssl->error);
18118
                    return WOLFSSL_FATAL_ERROR;
18119
                }
18120
            }
18121
#endif
18122
            ssl->options.acceptState = TLS13_CERT_SENT;
18123
            WOLFSSL_MSG("accept state CERT_SENT");
18124
            FALL_THROUGH;
18125
18126
        case TLS13_CERT_SENT :
18127
#if !defined(NO_CERTS) && (!defined(NO_RSA) || defined(HAVE_ECC) || \
18128
     defined(HAVE_ED25519) || defined(HAVE_ED448) || defined(HAVE_FALCON) || \
18129
     defined(WOLFSSL_HAVE_MLDSA) || defined(WOLFSSL_HAVE_SLHDSA))
18130
            if (!ssl->options.resuming && ssl->options.sendVerify) {
18131
                if ((ssl->error = SendTls13CertificateVerify(ssl)) != 0) {
18132
                    WOLFSSL_ERROR(ssl->error);
18133
                    return WOLFSSL_FATAL_ERROR;
18134
                }
18135
            }
18136
#endif
18137
            ssl->options.acceptState = TLS13_CERT_VERIFY_SENT;
18138
            WOLFSSL_MSG("accept state CERT_VERIFY_SENT");
18139
            FALL_THROUGH;
18140
18141
        case TLS13_CERT_VERIFY_SENT :
18142
            if ((ssl->error = SendTls13Finished(ssl)) != 0) {
18143
                WOLFSSL_ERROR(ssl->error);
18144
                return WOLFSSL_FATAL_ERROR;
18145
            }
18146
18147
            ssl->options.acceptState = TLS13_ACCEPT_FINISHED_SENT;
18148
            WOLFSSL_MSG("accept state ACCEPT_FINISHED_SENT");
18149
            FALL_THROUGH;
18150
18151
        case TLS13_ACCEPT_FINISHED_SENT:
18152
#ifdef WOLFSSL_EARLY_DATA
18153
            if (ssl->earlyData != no_early_data &&
18154
                    ssl->options.handShakeState != SERVER_FINISHED_COMPLETE) {
18155
                ssl->options.handShakeState = SERVER_FINISHED_COMPLETE;
18156
                return WOLFSSL_SUCCESS;
18157
            }
18158
#endif
18159
#ifdef HAVE_SESSION_TICKET
18160
    #ifdef WOLFSSL_TLS13_TICKET_BEFORE_FINISHED
18161
            if (!ssl->options.verifyPeer && !ssl->options.noTicketTls13 &&
18162
                    ssl->ctx->ticketEncCb != NULL &&
18163
                    ssl->options.maxTicketTls13 > 0) {
18164
                if ((ssl->error = SendTls13NewSessionTicket(ssl)) != 0) {
18165
                    WOLFSSL_ERROR(ssl->error);
18166
                    return WOLFSSL_FATAL_ERROR;
18167
                }
18168
                ssl->options.ticketsSent = 1;
18169
            }
18170
    #endif
18171
#endif /* HAVE_SESSION_TICKET */
18172
            ssl->options.acceptState = TLS13_PRE_TICKET_SENT;
18173
            WOLFSSL_MSG("accept state  TICKET_SENT");
18174
            FALL_THROUGH;
18175
18176
        case TLS13_PRE_TICKET_SENT :
18177
            while (ssl->options.clientState < CLIENT_FINISHED_COMPLETE) {
18178
                if ( (ssl->error = ProcessReply(ssl)) < 0) {
18179
                        WOLFSSL_ERROR(ssl->error);
18180
                        return WOLFSSL_FATAL_ERROR;
18181
                    }
18182
18183
#ifdef WOLFSSL_DTLS13
18184
                if (ssl->options.dtls) {
18185
                    if ((ssl->error = Dtls13DoScheduledWork(ssl)) < 0) {
18186
                        WOLFSSL_ERROR(ssl->error);
18187
                        return WOLFSSL_FATAL_ERROR;
18188
                    }
18189
                }
18190
#endif /* WOLFSSL_DTLS13 */
18191
            }
18192
18193
            /* Finish a key schedule the Finished handler left pending:
18194
             * it must complete before this side's sends advance the
18195
             * transcript the traffic secrets hash. */
18196
            if (ssl->kdfMsgStep > 0) {
18197
                ssl->error = DoTls13MsgDerives(ssl, ssl->kdfMsgType);
18198
                if (ssl->error != 0) {
18199
                    WOLFSSL_ERROR(ssl->error);
18200
                    return WOLFSSL_FATAL_ERROR;
18201
                }
18202
            }
18203
18204
            ssl->options.acceptState = TLS13_ACCEPT_FINISHED_DONE;
18205
            WOLFSSL_MSG("accept state ACCEPT_FINISHED_DONE");
18206
            FALL_THROUGH;
18207
18208
        case TLS13_ACCEPT_FINISHED_DONE :
18209
            /* SERVER: When not resuming and verifying peer but no certificate
18210
             * received and not failing when not received then peer auth good.
18211
             */
18212
            if (!ssl->options.resuming && ssl->options.verifyPeer &&
18213
        #ifdef WOLFSSL_POST_HANDSHAKE_AUTH
18214
                !ssl->options.verifyPostHandshake &&
18215
        #endif
18216
                !ssl->options.havePeerCert && !ssl->options.failNoCert) {
18217
                ssl->options.peerAuthGood = 1;
18218
            }
18219
            /* SERVER: check peer authentication. */
18220
            if (!ssl->options.peerAuthGood) {
18221
                WOLFSSL_MSG("Client authentication did not happen");
18222
                return WOLFSSL_FATAL_ERROR;
18223
            }
18224
#ifdef HAVE_SESSION_TICKET
18225
            while (ssl->options.ticketsSent < ssl->options.maxTicketTls13) {
18226
                if (!ssl->options.noTicketTls13 && ssl->ctx->ticketEncCb
18227
                        != NULL) {
18228
                    if ((ssl->error = SendTls13NewSessionTicket(ssl)) != 0) {
18229
                        WOLFSSL_ERROR(ssl->error);
18230
                        return WOLFSSL_FATAL_ERROR;
18231
                    }
18232
                }
18233
                ssl->options.ticketsSent++;
18234
18235
                /* only one session ticket is sent on session resumption */
18236
                if (ssl->options.resuming) {
18237
                    break;
18238
                }
18239
            }
18240
#endif /* HAVE_SESSION_TICKET */
18241
            ssl->options.acceptState = TLS13_TICKET_SENT;
18242
            WOLFSSL_MSG("accept state TICKET_SENT");
18243
            FALL_THROUGH;
18244
18245
        case TLS13_TICKET_SENT :
18246
#ifndef NO_HANDSHAKE_DONE_CB
18247
            if (ssl->hsDoneCb) {
18248
                int cbret = ssl->hsDoneCb(ssl, ssl->hsDoneCtx);
18249
                if (cbret < 0) {
18250
                    ssl->error = cbret;
18251
                    WOLFSSL_MSG("HandShake Done Cb don't continue error");
18252
                    return WOLFSSL_FATAL_ERROR;
18253
                }
18254
            }
18255
#endif /* NO_HANDSHAKE_DONE_CB */
18256
18257
            if (!ssl->options.keepResources) {
18258
                FreeHandshakeResources(ssl);
18259
            }
18260
18261
#if defined(WOLFSSL_ASYNC_IO) && !defined(WOLFSSL_ASYNC_CRYPT)
18262
            /* Free the remaining async context if not using it for crypto */
18263
            FreeAsyncCtx(ssl, 1);
18264
#endif
18265
18266
            ssl->error = 0; /* clear the error */
18267
18268
            WOLFSSL_LEAVE("wolfSSL_accept", WOLFSSL_SUCCESS);
18269
            return WOLFSSL_SUCCESS;
18270
18271
        default:
18272
            WOLFSSL_MSG("Unknown accept state ERROR");
18273
            return WOLFSSL_FATAL_ERROR;
18274
    }
18275
}
18276
#endif
18277
18278
#if !defined(NO_WOLFSSL_SERVER) && defined(HAVE_SESSION_TICKET)
18279
/* Server sends a session ticket to the peer.
18280
 *
18281
 * RFC 8446, section 4.6.1, para 1.
18282
 *
18283
 * ssl  The SSL/TLS object.
18284
 * returns BAD_FUNC_ARG when ssl is NULL, or not using TLS v1.3,
18285
 *         SIDE_ERROR when not a server,
18286
 *         NOT_READY_ERROR when handshake not complete,
18287
 *         MISSING_HANDSHAKE_DATA when the ClientHello had no
18288
 *         psk_key_exchange_modes extension and
18289
 *         WOLFSSL_TLS13_TICKET_CHECK_PSK_MODES is defined,
18290
 *         PSK_KEY_ERROR when no advertised PSK key exchange mode is usable and
18291
 *         WOLFSSL_TLS13_TICKET_CHECK_PSK_MODES is defined,
18292
 *         WOLFSSL_FATAL_ERROR when creating or sending message fails, and
18293
 *         WOLFSSL_SUCCESS on success.
18294
 */
18295
int wolfSSL_send_SessionTicket(WOLFSSL* ssl)
18296
0
{
18297
0
    int ret;
18298
18299
0
    if (ssl == NULL || !IsAtLeastTLSv1_3(ssl->version))
18300
0
        return BAD_FUNC_ARG;
18301
0
    if (ssl->options.side == WOLFSSL_CLIENT_END)
18302
0
        return SIDE_ERROR;
18303
0
    if (ssl->options.handShakeState != HANDSHAKE_DONE)
18304
0
        return NOT_READY_ERROR;
18305
0
    ret = CheckTls13TicketPskModes(ssl);
18306
0
    if (ret != 0) {
18307
0
        WOLFSSL_ERROR_VERBOSE(ret);
18308
0
        return ret;
18309
0
    }
18310
18311
0
    if ((ssl->error = SendTls13NewSessionTicket(ssl)) != 0) {
18312
0
        WOLFSSL_ERROR(ssl->error);
18313
0
        return WOLFSSL_FATAL_ERROR;
18314
0
    }
18315
0
    ssl->options.ticketsSent++;
18316
18317
0
    return WOLFSSL_SUCCESS;
18318
0
}
18319
#endif
18320
18321
#ifdef WOLFSSL_EARLY_DATA
18322
/* Sets the maximum amount of early data that can be seen by server when using
18323
 * session tickets for resumption.
18324
 * A value of zero indicates no early data is to be sent by client using session
18325
 * tickets.
18326
 *
18327
 * The default value is zero: per RFC 8446 Appendix E.5, TLS implementations
18328
 * "MUST NOT enable 0-RTT (either sending or accepting) unless specifically
18329
 * requested by the application." Servers must explicitly opt in by calling
18330
 * this function (or the per-SSL equivalent) with a non-zero value.
18331
 *
18332
 * ctx  The SSL/TLS CTX object.
18333
 * sz   Maximum size of the early data.
18334
 * returns BAD_FUNC_ARG when ctx is NULL, SIDE_ERROR when not a server and
18335
 * 0 on success.
18336
 */
18337
int wolfSSL_CTX_set_max_early_data(WOLFSSL_CTX* ctx, unsigned int sz)
18338
{
18339
    if (ctx == NULL || !IsAtLeastTLSv1_3(ctx->method->version))
18340
        return BAD_FUNC_ARG;
18341
    if (ctx->method->side == WOLFSSL_CLIENT_END)
18342
        return SIDE_ERROR;
18343
18344
    ctx->maxEarlyDataSz = sz;
18345
18346
#if defined(OPENSSL_EXTRA) || defined(WOLFSSL_ERROR_CODE_OPENSSL)
18347
    /* 1 on success in OpenSSL*/
18348
    return WOLFSSL_SUCCESS;
18349
#else
18350
    return 0;
18351
#endif
18352
}
18353
18354
/* Disable the RFC 8446 Section 8.2 fresh start protection. Early data is
18355
 * then accepted for tickets minted before this ctx was created. Only use
18356
 * this when the anti-replay state reliably survives server restarts.
18357
 *
18358
 * The check needs TimeNowInMilliseconds() to be comparable across restarts.
18359
 * On ports where it counts from boot the check never fires for tickets
18360
 * minted before a reboot.
18361
 *
18362
 * ctx  The SSL/TLS CTX object.
18363
 * returns BAD_FUNC_ARG when ctx is NULL or not TLS v1.3, SIDE_ERROR when
18364
 * called with a client and 0 on success.
18365
 */
18366
int wolfSSL_CTX_no_early_data_fresh_start_check(WOLFSSL_CTX* ctx)
18367
{
18368
    if (ctx == NULL || !IsAtLeastTLSv1_3(ctx->method->version))
18369
        return BAD_FUNC_ARG;
18370
    if (ctx->method->side == WOLFSSL_CLIENT_END)
18371
        return SIDE_ERROR;
18372
18373
#ifdef HAVE_SESSION_TICKET
18374
    ctx->noFreshStartCheck = 1;
18375
#endif
18376
18377
    return 0;
18378
}
18379
18380
/* Sets the maximum amount of early data that a client or server would like
18381
 * to exchange. Servers will advertise this value in session tickets sent
18382
 * to a client.
18383
 * A value of zero indicates no early data will be sent by a client, or
18384
 * no early data is accepted by a server (and announced as such in send out
18385
 * session tickets).
18386
 *
18387
 * ssl  The SSL/TLS object.
18388
 * sz   Maximum size of the early data.
18389
 * returns BAD_FUNC_ARG when ssl is NULL, or not using TLS v1.3,
18390
 * and 0 on success.
18391
 */
18392
int wolfSSL_set_max_early_data(WOLFSSL* ssl, unsigned int sz)
18393
{
18394
    if (ssl == NULL || !IsAtLeastTLSv1_3(ssl->version))
18395
        return BAD_FUNC_ARG;
18396
18397
    ssl->options.maxEarlyDataSz = sz;
18398
#if defined(OPENSSL_EXTRA) || defined(WOLFSSL_ERROR_CODE_OPENSSL)
18399
    /* 1 on success in OpenSSL*/
18400
    return WOLFSSL_SUCCESS;
18401
#else
18402
    return 0;
18403
#endif
18404
}
18405
18406
/* Gets the maximum amount of early data that can be seen by server when using
18407
 * session tickets for resumption.
18408
 * A value of zero indicates no early data is to be sent by client using session
18409
 * tickets.
18410
 *
18411
 * ctx  The SSL/TLS CTX object.
18412
 * returns BAD_FUNC_ARG when ctx is NULL, SIDE_ERROR when not a server and
18413
 * returns the maximum amount of early data to be set
18414
 */
18415
int wolfSSL_CTX_get_max_early_data(WOLFSSL_CTX* ctx)
18416
{
18417
    if (ctx == NULL || !IsAtLeastTLSv1_3(ctx->method->version))
18418
        return BAD_FUNC_ARG;
18419
    if (ctx->method->side == WOLFSSL_CLIENT_END)
18420
        return SIDE_ERROR;
18421
18422
    return ctx->maxEarlyDataSz;
18423
}
18424
18425
/* Gets the maximum amount of early data that can be seen by server when using
18426
 * session tickets for resumption.
18427
 * A value of zero indicates no early data is to be sent by client using session
18428
 * tickets.
18429
 *
18430
 * ssl  The SSL/TLS object.
18431
 * returns BAD_FUNC_ARG when ssl is NULL, or not using TLS v1.3,
18432
 * SIDE_ERROR when not a server and
18433
 * returns the maximum amount of early data to be set
18434
 */
18435
int wolfSSL_get_max_early_data(WOLFSSL* ssl)
18436
{
18437
    if (ssl == NULL || !IsAtLeastTLSv1_3(ssl->version))
18438
        return BAD_FUNC_ARG;
18439
18440
    return ssl->options.maxEarlyDataSz;
18441
}
18442
18443
/* Write early data to the server.
18444
 *
18445
 * ssl    The SSL/TLS object.
18446
 * data   Early data to write
18447
 * sz     The size of the early data in bytes.
18448
 * outSz  The number of early data bytes written.
18449
 * returns BAD_FUNC_ARG when: ssl, data or outSz is NULL; sz is negative;
18450
 * or not using TLS v1.3. SIDE ERROR when not a server. BAD_STATE_E if invoked
18451
 * without a valid session or without a valid PSK CB.
18452
 * Otherwise the number of early data bytes written.
18453
 */
18454
int wolfSSL_write_early_data(WOLFSSL* ssl, const void* data, int sz, int* outSz)
18455
{
18456
    int ret = 0;
18457
18458
    WOLFSSL_ENTER("wolfSSL_write_early_data");
18459
18460
    if (ssl == NULL || data == NULL || sz < 0 || outSz == NULL)
18461
        return BAD_FUNC_ARG;
18462
    if (!IsAtLeastTLSv1_3(ssl->version))
18463
        return BAD_FUNC_ARG;
18464
18465
    *outSz = 0;
18466
18467
#ifndef NO_WOLFSSL_CLIENT
18468
    if (ssl->options.side == WOLFSSL_SERVER_END)
18469
        return SIDE_ERROR;
18470
18471
    /* Early data requires PSK or session resumption */
18472
    if (!EarlyDataPossible(ssl)) {
18473
        return BAD_STATE_E;
18474
    }
18475
18476
    if (ssl->options.handShakeState == NULL_STATE) {
18477
        /* avoid re-setting ssl->earlyData if we re-enter the function because
18478
         * of WC_PENDING_E, WANT_WRITE or WANT_READ */
18479
        if (ssl->error == 0)
18480
            ssl->earlyData = expecting_early_data;
18481
        ret = wolfSSL_connect_TLSv13(ssl);
18482
        if (ret != WOLFSSL_SUCCESS)
18483
            return WOLFSSL_FATAL_ERROR;
18484
        /* on client side, status is set to rejected        */
18485
        /* until sever accepts the early data extension.    */
18486
        ssl->earlyDataStatus = WOLFSSL_EARLY_DATA_REJECTED;
18487
    }
18488
    if (ssl->options.handShakeState == CLIENT_HELLO_COMPLETE) {
18489
#ifdef OPENSSL_EXTRA
18490
        /* when processed early data exceeds max size */
18491
        if (ssl->session->maxEarlyDataSz > 0 &&
18492
            (ssl->earlyDataSz + sz > ssl->session->maxEarlyDataSz)) {
18493
            ssl->error = TOO_MUCH_EARLY_DATA;
18494
            return WOLFSSL_FATAL_ERROR;
18495
        }
18496
#endif
18497
        ret = SendData(ssl, data, sz);
18498
        if (ret > 0) {
18499
            *outSz = ret;
18500
            /* store amount of processed early data from client */
18501
            ssl->earlyDataSz += ret;
18502
        }
18503
    }
18504
#else
18505
    return SIDE_ERROR;
18506
#endif
18507
18508
    WOLFSSL_LEAVE("wolfSSL_write_early_data", ret);
18509
18510
    if (ret < 0)
18511
        ret = WOLFSSL_FATAL_ERROR;
18512
    return ret;
18513
}
18514
18515
/* Read the any early data from the client.
18516
 *
18517
 * ssl    The SSL/TLS object.
18518
 * data   Buffer to put the early data into.
18519
 * sz     The size of the buffer in bytes.
18520
 * outSz  The number of early data bytes read.
18521
 * returns BAD_FUNC_ARG when: ssl, data or outSz is NULL; sz is negative;
18522
 * or not using TLS v1.3. SIDE ERROR when not a server. Otherwise the number of
18523
 * early data bytes read.
18524
 */
18525
int wolfSSL_read_early_data(WOLFSSL* ssl, void* data, int sz, int* outSz)
18526
{
18527
    int ret = 0;
18528
18529
    WOLFSSL_ENTER("wolfSSL_read_early_data");
18530
18531
18532
    if (ssl == NULL || data == NULL || sz < 0 || outSz == NULL)
18533
        return BAD_FUNC_ARG;
18534
    if (!IsAtLeastTLSv1_3(ssl->version))
18535
        return BAD_FUNC_ARG;
18536
18537
    *outSz = 0;
18538
#ifndef NO_WOLFSSL_SERVER
18539
    if (ssl->options.side == WOLFSSL_CLIENT_END)
18540
        return SIDE_ERROR;
18541
18542
    if (ssl->options.handShakeState == NULL_STATE) {
18543
        /* the server flight can return WANT_WRITE and we re-enter here after
18544
         * setting ssl->earlyData = process_early_data, set earlyData to
18545
         * expecting_early_data just once */
18546
        if (ssl->earlyData < expecting_early_data)
18547
            ssl->earlyData = expecting_early_data;
18548
        /* this used to be: ret = wolfSSL_accept_TLSv13(ssl);
18549
         * However, wolfSSL_accept_TLSv13() expects a certificate to
18550
         * be installed already, which is not the case in servers
18551
         * such as HAProxy. They do it after inspecting the ClientHello.
18552
         * The common wolfssl_accept() allows that. */
18553
        ret = wolfSSL_accept(ssl);
18554
        if (ret <= 0)
18555
            return WOLFSSL_FATAL_ERROR;
18556
    }
18557
    if (ssl->options.handShakeState == SERVER_FINISHED_COMPLETE) {
18558
        ssl->options.clientInEarlyData = 1;
18559
        ret = ReceiveData(ssl, (byte*)data, (size_t)sz, FALSE);
18560
        ssl->options.clientInEarlyData = 0;
18561
        if (ret > 0)
18562
            *outSz = ret;
18563
        if (ssl->error == WC_NO_ERR_TRACE(APP_DATA_READY)) {
18564
            ret = 0;
18565
            ssl->error = WOLFSSL_ERROR_NONE;
18566
#ifdef WOLFSSL_DTLS13
18567
            if (ssl->options.dtls) {
18568
                ret = Dtls13DoScheduledWork(ssl);
18569
                if (ret  < 0) {
18570
                    ssl->error = ret;
18571
                    WOLFSSL_ERROR(ssl->error);
18572
                    return WOLFSSL_FATAL_ERROR;
18573
                }
18574
            }
18575
#endif /* WOLFSSL_DTLS13 */
18576
        }
18577
    }
18578
#ifdef WOLFSSL_DTLS13
18579
    else if (ssl->buffers.outputBuffer.length > 0 &&
18580
        ssl->options.dtls && ssl->dtls13SendingAckOrRtx) {
18581
        ret = SendBuffered(ssl);
18582
        if (ret == 0) {
18583
            ssl->dtls13SendingAckOrRtx = 0;
18584
        }
18585
        else {
18586
            ssl->error = ret;
18587
            WOLFSSL_ERROR(ssl->error);
18588
            return WOLFSSL_FATAL_ERROR;
18589
        }
18590
    }
18591
#endif /* WOLFSSL_DTLS13 */
18592
    else
18593
        ret = 0;
18594
#else
18595
    return SIDE_ERROR;
18596
#endif
18597
18598
    WOLFSSL_LEAVE("wolfSSL_read_early_data", ret);
18599
18600
    if (ret < 0)
18601
        ret = WOLFSSL_FATAL_ERROR;
18602
    return ret;
18603
}
18604
18605
/* Returns early data status
18606
 *
18607
 * ssl    The SSL/TLS object.
18608
 * returns WOLFSSL_EARLY_DATA_ACCEPTED if the data was accepted
18609
 *         WOLFSSL_EARLY_DATA_REJECTED if the data was rejected
18610
 *         WOLFSSL_EARLY_DATA_NOT_SENT if no early data was sent
18611
 */
18612
int wolfSSL_get_early_data_status(const WOLFSSL* ssl)
18613
{
18614
    if (ssl == NULL || !IsAtLeastTLSv1_3(ssl->version))
18615
        return BAD_FUNC_ARG;
18616
18617
    return ssl->earlyDataStatus;
18618
}
18619
#endif
18620
18621
#ifdef HAVE_SECRET_CALLBACK
18622
int wolfSSL_set_tls13_secret_cb(WOLFSSL* ssl, Tls13SecretCb cb, void* ctx)
18623
{
18624
    WOLFSSL_ENTER("wolfSSL_set_tls13_secret_cb");
18625
    if (ssl == NULL)
18626
        return WOLFSSL_FATAL_ERROR;
18627
18628
    ssl->tls13SecretCb = cb;
18629
    ssl->tls13SecretCtx = ctx;
18630
18631
    return WOLFSSL_SUCCESS;
18632
}
18633
18634
#if defined(SHOW_SECRETS) && defined(WOLFSSL_SSLKEYLOGFILE)
18635
int tls13ShowSecrets(WOLFSSL* ssl, int id, const unsigned char* secret,
18636
    int secretSz, void* ctx)
18637
{
18638
    int i;
18639
    const char* str = NULL;
18640
    byte clientRandom[RAN_LEN];
18641
    int clientRandomSz;
18642
    XFILE fp;
18643
#if defined(WOLFSSL_SSLKEYLOGFILE_OUTPUT) && defined(WOLFSSL_SSLKEYLOGFILE_USE_ENV)
18644
    const char* keyLogFile;
18645
#endif
18646
18647
    (void) ctx;
18648
#ifdef WOLFSSL_SSLKEYLOGFILE_OUTPUT
18649
#ifdef WOLFSSL_SSLKEYLOGFILE_USE_ENV
18650
    /* RFC 9850: prefer the SSLKEYLOGFILE environment variable so tools such as
18651
     * curl and Wireshark can share the path, else use the compile-time path.
18652
     * XGETENV resolves to NULL where environment access is unavailable. Opt-in
18653
     * so a build with the variable exported for other applications is not
18654
     * affected. */
18655
    keyLogFile = XGETENV("SSLKEYLOGFILE");
18656
    if (keyLogFile == NULL || keyLogFile[0] == '\0')
18657
        keyLogFile = WOLFSSL_SSLKEYLOGFILE_OUTPUT;
18658
    fp = XFOPEN(keyLogFile, "ab");
18659
#else
18660
    fp = XFOPEN(WOLFSSL_SSLKEYLOGFILE_OUTPUT, "ab");
18661
#endif
18662
    if (fp == XBADFILE) {
18663
        return BAD_FUNC_ARG;
18664
    }
18665
#else
18666
    fp = stderr;
18667
#endif
18668
18669
    clientRandomSz = (int)wolfSSL_get_client_random(ssl, clientRandom,
18670
        sizeof(clientRandom));
18671
18672
    if (clientRandomSz <= 0) {
18673
        printf("Error getting server random %d\n", clientRandomSz);
18674
        return BAD_FUNC_ARG;
18675
    }
18676
18677
#if 0
18678
    printf("TLS Server Secret CB: Rand %d, Secret %d\n",
18679
        serverRandomSz, secretSz);
18680
#endif
18681
18682
    switch (id) {
18683
        case CLIENT_EARLY_TRAFFIC_SECRET:
18684
            str = "CLIENT_EARLY_TRAFFIC_SECRET"; break;
18685
        case EARLY_EXPORTER_SECRET:
18686
            str = "EARLY_EXPORTER_SECRET"; break;
18687
        case CLIENT_HANDSHAKE_TRAFFIC_SECRET:
18688
            str = "CLIENT_HANDSHAKE_TRAFFIC_SECRET"; break;
18689
        case SERVER_HANDSHAKE_TRAFFIC_SECRET:
18690
            str = "SERVER_HANDSHAKE_TRAFFIC_SECRET"; break;
18691
        case CLIENT_TRAFFIC_SECRET:
18692
            str = "CLIENT_TRAFFIC_SECRET_0"; break;
18693
        case SERVER_TRAFFIC_SECRET:
18694
            str = "SERVER_TRAFFIC_SECRET_0"; break;
18695
        case EXPORTER_SECRET:
18696
            str = "EXPORTER_SECRET"; break;
18697
#ifdef HAVE_ECH
18698
        case ECH_SECRET:
18699
            str = "ECH_SECRET"; break;
18700
        case ECH_CONFIG:
18701
            str = "ECH_CONFIG"; break;
18702
#endif
18703
        default:
18704
#ifdef WOLFSSL_SSLKEYLOGFILE_OUTPUT
18705
            XFCLOSE(fp);
18706
#endif
18707
            return BAD_FUNC_ARG;
18708
            break;
18709
    }
18710
18711
    fprintf(fp, "%s ", str);
18712
    for (i = 0; i < (int)clientRandomSz; i++) {
18713
        fprintf(fp, "%02x", clientRandom[i]);
18714
    }
18715
    fprintf(fp, " ");
18716
    for (i = 0; i < secretSz; i++) {
18717
        fprintf(fp, "%02x", secret[i]);
18718
    }
18719
    fprintf(fp, "\n");
18720
18721
#ifdef WOLFSSL_SSLKEYLOGFILE_OUTPUT
18722
    XFCLOSE(fp);
18723
#endif
18724
18725
    return 0;
18726
}
18727
#endif
18728
#endif
18729
18730
#undef ERROR_OUT
18731
18732
#endif /* !WOLFCRYPT_ONLY */
18733
18734
#endif /* !NO_TLS && WOLFSSL_TLS13 */