Coverage Report

Created: 2026-09-20 06:33

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wolfssl-sp-math-all-8bit/wolfssl/internal.h
Line
Count
Source
1
/* internal.h
2
 *
3
 * Copyright (C) 2006-2026 wolfSSL Inc.
4
 *
5
 * This file is part of wolfSSL.
6
 *
7
 * wolfSSL is free software; you can redistribute it and/or modify
8
 * it under the terms of the GNU General Public License as published by
9
 * the Free Software Foundation; either version 3 of the License, or
10
 * (at your option) any later version.
11
 *
12
 * wolfSSL is distributed in the hope that it will be useful,
13
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
15
 * GNU General Public License for more details.
16
 *
17
 * You should have received a copy of the GNU General Public License
18
 * along with this program; if not, write to the Free Software
19
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335, USA
20
 */
21
22
23
24
#ifndef WOLFSSL_INT_H
25
#define WOLFSSL_INT_H
26
27
#include <wolfssl/wolfcrypt/types.h>
28
#include <wolfssl/ssl.h>
29
#include <wolfssl/wolfio.h>
30
#ifdef HAVE_CRL
31
    #include <wolfssl/crl.h>
32
#endif
33
#include <wolfssl/wolfcrypt/random.h>
34
#ifndef NO_DES3
35
    #include <wolfssl/wolfcrypt/des3.h>
36
#endif
37
#ifdef HAVE_CHACHA
38
    #include <wolfssl/wolfcrypt/chacha.h>
39
#endif
40
#ifndef NO_ASN
41
    #include <wolfssl/wolfcrypt/asn.h>
42
    #include <wolfssl/wolfcrypt/pkcs12.h>
43
#endif
44
#ifndef NO_MD5
45
    #include <wolfssl/wolfcrypt/md5.h>
46
#endif
47
#ifndef NO_SHA
48
    #include <wolfssl/wolfcrypt/sha.h>
49
#endif
50
#ifndef NO_AES
51
    #include <wolfssl/wolfcrypt/aes.h>
52
#endif
53
#ifdef HAVE_POLY1305
54
    #include <wolfssl/wolfcrypt/poly1305.h>
55
#endif
56
#if defined(HAVE_CHACHA) && defined(HAVE_POLY1305)
57
    /* Not OPENSSL_EXTRA-only: the TLS record layer calls the persistent-key
58
     * helpers wc_ChaCha20Poly1305_{Encrypt,Decrypt}_ex(), so this header has
59
     * to be visible whenever the ChaCha20-Poly1305 suites are built. */
60
    #include <wolfssl/wolfcrypt/chacha20_poly1305.h>
61
#endif
62
#ifdef HAVE_ARIA
63
    #include <wolfssl/wolfcrypt/port/aria/aria-crypt.h>
64
#endif
65
#ifdef HAVE_CAMELLIA
66
    #include <wolfssl/wolfcrypt/camellia.h>
67
#endif
68
#ifdef WOLFSSL_SM4
69
    #include <wolfssl/wolfcrypt/sm4.h>
70
#endif
71
#include <wolfssl/wolfcrypt/logging.h>
72
#ifndef NO_HMAC
73
    #include <wolfssl/wolfcrypt/hmac.h>
74
#endif
75
#ifndef NO_RC4
76
    #include <wolfssl/wolfcrypt/arc4.h>
77
#endif
78
#ifndef NO_SHA256
79
    #include <wolfssl/wolfcrypt/sha256.h>
80
#endif
81
#if defined(WOLFSSL_SHA384)
82
    #include <wolfssl/wolfcrypt/sha512.h>
83
#endif
84
#ifdef HAVE_OCSP
85
    #include <wolfssl/ocsp.h>
86
#endif
87
#ifdef WOLFSSL_QUIC
88
    #include <wolfssl/quic.h>
89
#endif
90
#ifdef WOLFSSL_SHA384
91
    #include <wolfssl/wolfcrypt/sha512.h>
92
#endif
93
#ifdef WOLFSSL_SHA512
94
    #include <wolfssl/wolfcrypt/sha512.h>
95
#endif
96
#ifdef WOLFSSL_SM3
97
    #include <wolfssl/wolfcrypt/sm3.h>
98
#endif
99
#ifdef HAVE_AESGCM
100
    #include <wolfssl/wolfcrypt/sha512.h>
101
#endif
102
#ifdef WOLFSSL_RIPEMD
103
    #include <wolfssl/wolfcrypt/ripemd.h>
104
#endif
105
#ifndef NO_RSA
106
    #include <wolfssl/wolfcrypt/rsa.h>
107
#endif
108
#ifdef HAVE_ECC
109
    #include <wolfssl/wolfcrypt/ecc.h>
110
#endif
111
#ifdef WOLFSSL_SM2
112
    #include <wolfssl/wolfcrypt/sm2.h>
113
#endif
114
#ifndef NO_DH
115
    #include <wolfssl/wolfcrypt/dh.h>
116
#endif
117
#ifdef HAVE_ED25519
118
    #include <wolfssl/wolfcrypt/ed25519.h>
119
#endif
120
#ifdef HAVE_CURVE25519
121
    #include <wolfssl/wolfcrypt/curve25519.h>
122
#endif
123
#ifdef HAVE_ED448
124
    #include <wolfssl/wolfcrypt/ed448.h>
125
#endif
126
#ifdef HAVE_CURVE448
127
    #include <wolfssl/wolfcrypt/curve448.h>
128
#endif
129
#ifdef HAVE_FALCON
130
    #include <wolfssl/wolfcrypt/falcon.h>
131
#endif
132
#ifdef WOLFSSL_HAVE_MLDSA
133
    #include <wolfssl/wolfcrypt/wc_mldsa.h>
134
#endif
135
#ifdef WOLFSSL_HAVE_SLHDSA
136
    #include <wolfssl/wolfcrypt/wc_slhdsa.h>
137
#endif
138
#ifdef HAVE_HKDF
139
    #include <wolfssl/wolfcrypt/kdf.h>
140
#endif
141
#ifndef WOLFSSL_NO_DEF_TICKET_ENC_CB
142
    #if defined(HAVE_CHACHA) && defined(HAVE_POLY1305) && \
143
        !defined(WOLFSSL_TICKET_ENC_AES128_GCM) && \
144
        !defined(WOLFSSL_TICKET_ENC_AES256_GCM)
145
        #include <wolfssl/wolfcrypt/chacha20_poly1305.h>
146
    #else
147
        #include <wolfssl/wolfcrypt/aes.h>
148
    #endif
149
#endif
150
151
#include <wolfssl/wolfcrypt/wc_encrypt.h>
152
#include <wolfssl/wolfcrypt/hash.h>
153
154
#if defined(WOLFSSL_CALLBACKS) || defined(OPENSSL_EXTRA)
155
    #include <wolfssl/callbacks.h>
156
#endif
157
#ifdef WOLFSSL_CALLBACKS
158
    #include <signal.h>
159
#endif
160
161
#ifdef WOLFSSL_APACHE_MYNEWT
162
    #if !defined(WOLFSSL_LWIP)
163
        void mynewt_ctx_clear(void *ctx);
164
        void* mynewt_ctx_new();
165
    #endif
166
#endif
167
168
#if !defined(WOLFCRYPT_ONLY) && !defined(INT_MAX)
169
    /* Needed for TLS/DTLS limit checking (Added in 91aad90c59 Jan 24, 2025) */
170
    #include <limits.h>
171
#endif
172
173
174
#ifdef HAVE_LIBZ
175
    #include "zlib.h"
176
#endif
177
178
#ifdef WOLFSSL_ASYNC_CRYPT
179
    #include <wolfssl/wolfcrypt/async.h>
180
#endif
181
182
#ifdef OPENSSL_EXTRA
183
    #ifdef WOLFCRYPT_HAVE_SRP
184
        #include <wolfssl/wolfcrypt/srp.h>
185
    #endif
186
#endif
187
188
#ifdef _MSC_VER
189
    /* 4996 warning to use MS extensions e.g., strcpy_s instead of strncpy */
190
    #pragma warning(disable: 4996)
191
#endif
192
193
#ifdef NO_SHA
194
    #define WC_SHA_DIGEST_SIZE 20
195
#endif
196
197
#ifdef NO_SHA256
198
    #define WC_SHA256_DIGEST_SIZE 32
199
#endif
200
201
#ifdef NO_MD5
202
    #define WC_MD5_DIGEST_SIZE 16
203
#endif
204
205
#ifdef WOLFSSL_IOTSAFE
206
    #include <wolfssl/wolfcrypt/port/iotsafe/iotsafe.h>
207
#endif
208
209
#if defined(WOLFSSL_RENESAS_TSIP_TLS)
210
    #include <wolfssl/wolfcrypt/port/Renesas/renesas_tsip_internal.h>
211
#endif
212
213
#include <wolfssl/wolfcrypt/hpke.h>
214
215
#if defined(WOLFSSL_SNIFFER) && defined(WOLFSSL_SNIFFER_KEYLOGFILE)
216
#include <wolfssl/sniffer.h>
217
#endif /* WOLFSSL_SNIFFER && WOLFSSL_SNIFFER_KEYLOGFILE */
218
219
#ifdef WOLFSSL_TEST_APPLE_NATIVE_CERT_VALIDATION
220
    #include <CoreFoundation/CoreFoundation.h>
221
#endif /* WOLFSSL_TEST_APPLE_NATIVE_CERT_VALIDATION */
222
223
#ifdef __cplusplus
224
    extern "C" {
225
#endif
226
227
/* ML-KEM client support requires generating a key pair (encapsulation key) and
228
 * decapsulating the server's ciphertext. */
229
#if defined(WOLFSSL_HAVE_MLKEM) && !defined(WOLFSSL_MLKEM_NO_MAKE_KEY) && \
230
     !defined(WOLFSSL_MLKEM_NO_DECAPSULATE)
231
    #define WOLFSSL_HAVE_MLKEM_CLIENT_SUPPORT
232
#endif
233
/* ML-KEM server support requires encapsulating to the client's key. */
234
#if defined(WOLFSSL_HAVE_MLKEM) && !defined(WOLFSSL_MLKEM_NO_ENCAPSULATE)
235
    #define WOLFSSL_HAVE_MLKEM_SERVER_SUPPORT
236
#endif
237
238
/* Define or comment out the cipher suites you'd like to be compiled in
239
   make sure to use at least one BUILD_SSL_xxx or BUILD_TLS_xxx is defined
240
241
   When adding cipher suites, add name to cipher_names, idx to cipher_name_idx
242
243
   Now that there is a maximum strength crypto build, the following BUILD_XXX
244
   flags need to be divided into two groups selected by WOLFSSL_MAX_STRENGTH.
245
   Those that do not use Perfect Forward Security and do not use AEAD ciphers
246
   need to be switched off. Allowed suites use (EC)DHE, AES-GCM|CCM, or
247
   CHACHA-POLY.
248
*/
249
250
/* Check that if WOLFSSL_MAX_STRENGTH is set that all the required options are
251
 * not turned off. */
252
#if defined(WOLFSSL_MAX_STRENGTH) && \
253
    ((!defined(HAVE_ECC) && (defined(NO_DH) || defined(NO_RSA))) || \
254
     (!defined(HAVE_AESGCM) && !defined(HAVE_AESCCM) && \
255
      (!defined(HAVE_POLY1305) || !defined(HAVE_CHACHA))) || \
256
     (defined(NO_SHA256) && !defined(WOLFSSL_SHA384)) || \
257
     !defined(NO_OLD_TLS))
258
259
    #error "You are trying to build max strength with requirements disabled."
260
#endif
261
262
#ifndef WOLFSSL_NO_TLS12
263
264
#ifndef WOLFSSL_MAX_STRENGTH
265
266
#ifdef WOLFSSL_AEAD_ONLY
267
    /* AES CBC ciphers are not allowed in AEAD only mode */
268
    #undef HAVE_AES_CBC
269
#endif
270
271
/* When adding new ciphersuites, make sure that they have appropriate
272
 * guards for WOLFSSL_HARDEN_TLS. */
273
#if defined(WOLFSSL_HARDEN_TLS) && \
274
    !defined(WOLFSSL_HARDEN_TLS_ALLOW_ALL_CIPHERSUITES)
275
/* Use a separate define (undef'ed later) to simplify macro logic. */
276
#define WSSL_HARDEN_TLS WOLFSSL_HARDEN_TLS
277
#define NO_TLS_DH
278
#endif
279
280
#ifndef WOLFSSL_AEAD_ONLY
281
    #if !defined(NO_RSA) && !defined(NO_RC4) && !defined(WSSL_HARDEN_TLS)
282
        /* MUST NOT negotiate RC4 cipher suites
283
         * https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
284
        #if defined(WOLFSSL_STATIC_RSA)
285
            #if !defined(NO_SHA)
286
                #define BUILD_SSL_RSA_WITH_RC4_128_SHA
287
            #endif
288
            #if !defined(NO_MD5)
289
                #define BUILD_SSL_RSA_WITH_RC4_128_MD5
290
            #endif
291
        #endif
292
    #endif
293
294
    #if !defined(NO_RSA) && !defined(NO_DES3) && !defined(NO_DES3_TLS_SUITES)
295
        #if !defined(NO_SHA)
296
            #if defined(WOLFSSL_STATIC_RSA)
297
                #define BUILD_SSL_RSA_WITH_3DES_EDE_CBC_SHA
298
            #endif
299
        #endif
300
    #endif
301
#endif /* !WOLFSSL_AEAD_ONLY */
302
303
    #if !defined(NO_RSA) && !defined(NO_AES) && !defined(NO_TLS)
304
        #if !defined(NO_SHA) && defined(HAVE_AES_CBC)
305
            #if defined(WOLFSSL_STATIC_RSA)
306
                #ifdef WOLFSSL_AES_128
307
                    #define BUILD_TLS_RSA_WITH_AES_128_CBC_SHA
308
                #endif
309
                #ifdef WOLFSSL_AES_256
310
                    #define BUILD_TLS_RSA_WITH_AES_256_CBC_SHA
311
                #endif
312
            #endif
313
        #endif
314
        #if defined(WOLFSSL_STATIC_RSA)
315
            #if !defined (NO_SHA256) && defined(HAVE_AES_CBC)
316
                #ifdef WOLFSSL_AES_128
317
                    #define BUILD_TLS_RSA_WITH_AES_128_CBC_SHA256
318
                #endif
319
                #ifdef WOLFSSL_AES_256
320
                    #define BUILD_TLS_RSA_WITH_AES_256_CBC_SHA256
321
                #endif
322
            #endif
323
            #if defined (HAVE_AESGCM)
324
                #ifdef WOLFSSL_AES_128
325
                    #define BUILD_TLS_RSA_WITH_AES_128_GCM_SHA256
326
                #endif
327
                #if defined (WOLFSSL_SHA384) && defined(WOLFSSL_AES_256)
328
                    #define BUILD_TLS_RSA_WITH_AES_256_GCM_SHA384
329
                #endif
330
            #endif
331
            #if defined (HAVE_AESCCM)
332
                #ifdef WOLFSSL_AES_128
333
                    #define BUILD_TLS_RSA_WITH_AES_128_CCM_8
334
                #endif
335
                #ifdef WOLFSSL_AES_256
336
                    #define BUILD_TLS_RSA_WITH_AES_256_CCM_8
337
                #endif
338
            #endif
339
        #endif
340
    #endif
341
342
    #if defined(HAVE_CAMELLIA) && !defined(NO_TLS) && !defined(NO_CAMELLIA_CBC)
343
        #ifndef NO_RSA
344
          #if defined(WOLFSSL_STATIC_RSA)
345
            #if !defined(NO_SHA)
346
                #define BUILD_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA
347
                #define BUILD_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA
348
            #endif
349
            #ifndef NO_SHA256
350
                #define BUILD_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256
351
                #define BUILD_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256
352
            #endif
353
          #endif
354
            #if !defined(NO_DH) && !defined(NO_TLS_DH)
355
              /* SHOULD NOT negotiate cipher suites based on ephemeral
356
               * finite-field Diffie-Hellman key agreement (i.e., "TLS_DHE_*"
357
               * suites). https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
358
              #if !defined(NO_SHA)
359
                #define BUILD_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA
360
                #define BUILD_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA
361
              #endif
362
                #ifndef NO_SHA256
363
                    #define BUILD_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256
364
                    #define BUILD_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256
365
                #endif
366
            #endif
367
        #endif
368
    #endif
369
370
#if defined(WOLFSSL_STATIC_PSK)
371
    #if !defined(NO_PSK) && !defined(NO_AES) && !defined(NO_TLS)
372
        #if !defined(NO_SHA)
373
            #ifdef WOLFSSL_AES_128
374
                #define BUILD_TLS_PSK_WITH_AES_128_CBC_SHA
375
            #endif
376
            #ifdef WOLFSSL_AES_256
377
                #define BUILD_TLS_PSK_WITH_AES_256_CBC_SHA
378
            #endif
379
        #endif
380
        #ifndef NO_SHA256
381
            #ifdef WOLFSSL_AES_128
382
                #ifdef HAVE_AES_CBC
383
                    #define BUILD_TLS_PSK_WITH_AES_128_CBC_SHA256
384
                #endif
385
                #ifdef HAVE_AESGCM
386
                    #define BUILD_TLS_PSK_WITH_AES_128_GCM_SHA256
387
                #endif
388
            #endif /* WOLFSSL_AES_128 */
389
            #ifdef HAVE_AESCCM
390
                #ifdef WOLFSSL_AES_128
391
                    #define BUILD_TLS_PSK_WITH_AES_128_CCM_8
392
                    #define BUILD_TLS_PSK_WITH_AES_128_CCM
393
                #endif
394
                #ifdef WOLFSSL_AES_256
395
                    #define BUILD_TLS_PSK_WITH_AES_256_CCM_8
396
                    #define BUILD_TLS_PSK_WITH_AES_256_CCM
397
                #endif
398
            #endif
399
        #endif
400
        #if defined(WOLFSSL_SHA384) && defined(WOLFSSL_AES_256)
401
            #ifdef HAVE_AES_CBC
402
                #define BUILD_TLS_PSK_WITH_AES_256_CBC_SHA384
403
            #endif
404
            #ifdef HAVE_AESGCM
405
                #define BUILD_TLS_PSK_WITH_AES_256_GCM_SHA384
406
            #endif
407
        #endif
408
    #endif
409
#endif
410
411
    #if !defined(NO_TLS) && defined(HAVE_NULL_CIPHER)
412
        #if !defined(NO_RSA)
413
            #if defined(WOLFSSL_STATIC_RSA)
414
                #ifndef NO_MD5
415
                    #define BUILD_TLS_RSA_WITH_NULL_MD5
416
                #endif
417
                #if !defined(NO_SHA)
418
                    #define BUILD_TLS_RSA_WITH_NULL_SHA
419
                #endif
420
                #ifndef NO_SHA256
421
                    #define BUILD_TLS_RSA_WITH_NULL_SHA256
422
                #endif
423
            #endif
424
        #endif
425
        #if !defined(NO_PSK) && defined(WOLFSSL_STATIC_PSK)
426
            #if !defined(NO_SHA)
427
                #define BUILD_TLS_PSK_WITH_NULL_SHA
428
            #endif
429
            #ifndef NO_SHA256
430
                #define BUILD_TLS_PSK_WITH_NULL_SHA256
431
            #endif
432
            #ifdef WOLFSSL_SHA384
433
                #define BUILD_TLS_PSK_WITH_NULL_SHA384
434
            #endif
435
        #endif
436
    #endif
437
438
    #if !defined(NO_DH) && !defined(NO_AES) && !defined(NO_TLS) && \
439
        !defined(NO_RSA) && !defined(NO_TLS_DH)
440
        /* SHOULD NOT negotiate cipher suites based on ephemeral
441
         * finite-field Diffie-Hellman key agreement (i.e., "TLS_DHE_*"
442
         * suites). https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
443
444
        #if !defined(NO_SHA)
445
            #if defined(WOLFSSL_AES_128) && defined(HAVE_AES_CBC)
446
                #define BUILD_TLS_DHE_RSA_WITH_AES_128_CBC_SHA
447
            #endif
448
            #if defined(WOLFSSL_AES_256) && defined(HAVE_AES_CBC)
449
                #define BUILD_TLS_DHE_RSA_WITH_AES_256_CBC_SHA
450
            #endif
451
            #if !defined(NO_DES3) && !defined(NO_DES3_TLS_SUITES)
452
                #define BUILD_TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA
453
            #endif
454
        #endif
455
        #if !defined(NO_SHA256) && defined(HAVE_AES_CBC)
456
            #ifdef WOLFSSL_AES_128
457
                #define BUILD_TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
458
            #endif
459
            #ifdef WOLFSSL_AES_256
460
                #define BUILD_TLS_DHE_RSA_WITH_AES_256_CBC_SHA256
461
            #endif
462
        #endif
463
    #endif
464
465
    #if defined(HAVE_ANON) && !defined(NO_TLS) && !defined(NO_DH) && \
466
        !defined(NO_AES)
467
        #if !defined(NO_SHA) && defined(HAVE_AES_CBC) && \
468
                defined(WOLFSSL_AES_128)
469
            #define BUILD_TLS_DH_anon_WITH_AES_128_CBC_SHA
470
        #endif
471
        #if defined(WOLFSSL_SHA384) && defined(HAVE_AESGCM) && \
472
                defined(WOLFSSL_AES_256)
473
            #define BUILD_TLS_DH_anon_WITH_AES_256_GCM_SHA384
474
        #endif
475
    #endif
476
477
    #if !defined(NO_DH) && !defined(NO_PSK) && !defined(NO_TLS) && \
478
        !defined(NO_TLS_DH)
479
        /* SHOULD NOT negotiate cipher suites based on ephemeral
480
         * finite-field Diffie-Hellman key agreement (i.e., "TLS_DHE_*"
481
         * suites). https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
482
        #ifndef NO_SHA256
483
            #if !defined(NO_AES) && defined(WOLFSSL_AES_128) && \
484
                                                           defined(HAVE_AES_CBC)
485
                #define BUILD_TLS_DHE_PSK_WITH_AES_128_CBC_SHA256
486
            #endif
487
            #ifdef HAVE_NULL_CIPHER
488
                #define BUILD_TLS_DHE_PSK_WITH_NULL_SHA256
489
            #endif
490
        #endif
491
        #ifdef WOLFSSL_SHA384
492
            #if !defined(NO_AES) && defined(WOLFSSL_AES_256) && \
493
                                                           defined(HAVE_AES_CBC)
494
                #define BUILD_TLS_DHE_PSK_WITH_AES_256_CBC_SHA384
495
            #endif
496
            #ifdef HAVE_NULL_CIPHER
497
                #define BUILD_TLS_DHE_PSK_WITH_NULL_SHA384
498
            #endif
499
        #endif
500
    #endif
501
502
    #if (defined(HAVE_ECC) || defined(HAVE_CURVE25519) || \
503
                                     defined(HAVE_CURVE448)) && !defined(NO_TLS)
504
        #if !defined(NO_AES)
505
            #if !defined(NO_SHA) && defined(HAVE_AES_CBC)
506
                #if !defined(NO_RSA)
507
                    #ifdef WOLFSSL_AES_128
508
                        #define BUILD_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
509
                    #endif
510
                    #ifdef WOLFSSL_AES_256
511
                        #define BUILD_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
512
                    #endif
513
                    #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
514
                        #ifdef WOLFSSL_AES_128
515
                            #define BUILD_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA
516
                        #endif
517
                        #ifdef WOLFSSL_AES_256
518
                            #define BUILD_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA
519
                        #endif
520
                    #endif
521
                #endif
522
523
                #if defined(HAVE_ECC) || \
524
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
525
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
526
                    #ifdef WOLFSSL_AES_128
527
                        #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
528
                    #endif
529
                    #ifdef WOLFSSL_AES_256
530
                        #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
531
                    #endif
532
                #endif
533
534
                #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
535
                    #ifdef WOLFSSL_AES_128
536
                        #define BUILD_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA
537
                    #endif
538
                    #ifdef WOLFSSL_AES_256
539
                        #define BUILD_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA
540
                    #endif
541
                #endif
542
            #endif /* NO_SHA */
543
            #if !defined(NO_SHA256) && defined(WOLFSSL_AES_128) && \
544
                                                           defined(HAVE_AES_CBC)
545
                #if !defined(NO_RSA)
546
                    #define BUILD_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
547
                    #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
548
                        #define BUILD_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256
549
                    #endif
550
                #endif
551
                #if defined(HAVE_ECC) || \
552
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
553
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
554
                    #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256
555
                #endif
556
                #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
557
                    #define BUILD_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256
558
                #endif
559
            #endif
560
561
            #if defined(WOLFSSL_SHA384) && defined(WOLFSSL_AES_256) && \
562
                                                           defined(HAVE_AES_CBC)
563
                #if !defined(NO_RSA)
564
                    #define BUILD_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
565
                    #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
566
                        #define BUILD_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384
567
                    #endif
568
                #endif
569
                #if defined(HAVE_ECC) || \
570
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
571
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
572
                    #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384
573
                #endif
574
                #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
575
                    #define BUILD_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384
576
                #endif
577
            #endif
578
579
            #if defined (HAVE_AESGCM)
580
                #if !defined(NO_RSA)
581
                    #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
582
                        #ifdef WOLFSSL_AES_128
583
                            #define BUILD_TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256
584
                        #endif
585
                    #endif
586
                    #if defined(WOLFSSL_SHA384)
587
                        #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
588
                            #ifdef WOLFSSL_AES_256
589
                                #define BUILD_TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384
590
                            #endif
591
                        #endif
592
                    #endif
593
                #endif
594
595
                #if defined(WOLFSSL_STATIC_DH) && defined(WOLFSSL_AES_128) && \
596
                                                               defined(HAVE_ECC)
597
                    #define BUILD_TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256
598
                #endif
599
600
                #if defined(WOLFSSL_SHA384)
601
                    #if defined(WOLFSSL_STATIC_DH) && \
602
                                   defined(WOLFSSL_AES_256) && defined(HAVE_ECC)
603
                        #define BUILD_TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384
604
                    #endif
605
                #endif
606
            #endif
607
        #endif /* NO_AES */
608
        #ifdef HAVE_ARIA
609
            #define BUILD_TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256
610
            #define BUILD_TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384
611
        #endif /* HAVE_ARIA */
612
        #if !defined(NO_RC4) && !defined(WSSL_HARDEN_TLS)
613
            /* MUST NOT negotiate RC4 cipher suites
614
             * https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
615
            #if !defined(NO_SHA)
616
                #if !defined(NO_RSA)
617
                    #ifndef WOLFSSL_AEAD_ONLY
618
                        #define BUILD_TLS_ECDHE_RSA_WITH_RC4_128_SHA
619
                    #endif
620
                    #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
621
                        #define BUILD_TLS_ECDH_RSA_WITH_RC4_128_SHA
622
                    #endif
623
                #endif
624
625
                #if defined(HAVE_ECC) || \
626
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
627
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
628
                    #ifndef WOLFSSL_AEAD_ONLY
629
                        #define BUILD_TLS_ECDHE_ECDSA_WITH_RC4_128_SHA
630
                    #endif
631
                #endif
632
                #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
633
                    #define BUILD_TLS_ECDH_ECDSA_WITH_RC4_128_SHA
634
                #endif
635
            #endif
636
        #endif
637
        #if !defined(NO_DES3) && !(defined(WSSL_HARDEN_TLS) && \
638
                                           WSSL_HARDEN_TLS > 112) && \
639
            !defined(NO_DES3_TLS_SUITES)
640
            /* 3DES offers only 112 bits of security.
641
             * Using guidance from section 5.6.1
642
             * https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf */
643
            #ifndef NO_SHA
644
                #if !defined(NO_RSA)
645
                    #define BUILD_TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA
646
                    #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
647
                        #define BUILD_TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA
648
                    #endif
649
                #endif
650
651
                #if defined(HAVE_ECC) || \
652
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
653
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
654
                    #define BUILD_TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA
655
                #endif
656
                #if defined(WOLFSSL_STATIC_DH) && defined(HAVE_ECC)
657
                    #define BUILD_TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA
658
                #endif
659
            #endif /* NO_SHA */
660
        #endif
661
        #if defined(HAVE_NULL_CIPHER)
662
            #if !defined(NO_SHA)
663
                #if defined(HAVE_ECC) || \
664
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
665
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
666
                    #define BUILD_TLS_ECDHE_ECDSA_WITH_NULL_SHA
667
                #endif
668
            #endif
669
            #if !defined(NO_PSK) && !defined(NO_SHA256)
670
                #define BUILD_TLS_ECDHE_PSK_WITH_NULL_SHA256
671
            #endif
672
        #endif
673
        #if !defined(NO_PSK) && !defined(NO_SHA256) && !defined(NO_AES) && \
674
            defined(WOLFSSL_AES_128) && defined(HAVE_AES_CBC)
675
            #define BUILD_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256
676
        #endif
677
        #if !defined(NO_PSK) && !defined(NO_SHA256) && !defined(NO_AES) && \
678
            defined(WOLFSSL_AES_128) && defined(HAVE_AESGCM)
679
            #define BUILD_TLS_ECDHE_PSK_WITH_AES_128_GCM_SHA256
680
        #endif
681
    #endif
682
    #if defined(HAVE_CHACHA) && defined(HAVE_POLY1305) && !defined(NO_SHA256)
683
        #if !defined(NO_OLD_POLY1305)
684
        #if defined(HAVE_ECC) || \
685
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
686
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
687
            #define BUILD_TLS_ECDHE_ECDSA_WITH_CHACHA20_OLD_POLY1305_SHA256
688
        #endif
689
        #if !defined(NO_RSA) && defined(HAVE_ECC)
690
            #define BUILD_TLS_ECDHE_RSA_WITH_CHACHA20_OLD_POLY1305_SHA256
691
        #endif
692
        #if !defined(NO_DH) && !defined(NO_RSA) && !defined(NO_TLS_DH)
693
            /* SHOULD NOT negotiate cipher suites based on ephemeral
694
             * finite-field Diffie-Hellman key agreement (i.e., "TLS_DHE_*"
695
             * suites). https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
696
            #define BUILD_TLS_DHE_RSA_WITH_CHACHA20_OLD_POLY1305_SHA256
697
        #endif
698
        #endif /* NO_OLD_POLY1305 */
699
        #if !defined(NO_PSK)
700
            #define BUILD_TLS_PSK_WITH_CHACHA20_POLY1305_SHA256
701
            #if defined(HAVE_ECC) || defined(HAVE_ED25519) || \
702
                                                             defined(HAVE_ED448)
703
                #define BUILD_TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256
704
            #endif
705
            #if !defined(NO_DH) && !defined(NO_TLS_DH)
706
                /* SHOULD NOT negotiate cipher suites based on ephemeral
707
                 * finite-field Diffie-Hellman key agreement (i.e., "TLS_DHE_*"
708
                 * suites). https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
709
                #define BUILD_TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256
710
            #endif
711
        #endif /* !NO_PSK */
712
    #endif
713
714
#endif /* !WOLFSSL_MAX_STRENGTH */
715
716
#if !defined(NO_DH) && !defined(NO_AES) && !defined(NO_TLS) && \
717
    !defined(NO_RSA) && defined(HAVE_AESGCM) && !defined(NO_TLS_DH)
718
    /* SHOULD NOT negotiate cipher suites based on ephemeral
719
     * finite-field Diffie-Hellman key agreement (i.e., "TLS_DHE_*"
720
     * suites). https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
721
722
    #if !defined(NO_SHA256) && defined(WOLFSSL_AES_128)
723
        #define BUILD_TLS_DHE_RSA_WITH_AES_128_GCM_SHA256
724
    #endif
725
726
    #if defined(WOLFSSL_SHA384) && defined(WOLFSSL_AES_256)
727
        #define BUILD_TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
728
    #endif
729
#endif
730
731
#if !defined(NO_DH) && !defined(NO_PSK) && !defined(NO_TLS) && \
732
    !defined(NO_TLS_DH)
733
    /* SHOULD NOT negotiate cipher suites based on ephemeral
734
     * finite-field Diffie-Hellman key agreement (i.e., "TLS_DHE_*"
735
     * suites). https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
736
    #ifndef NO_SHA256
737
        #if defined(HAVE_AESGCM) && defined(WOLFSSL_AES_128)
738
            #define BUILD_TLS_DHE_PSK_WITH_AES_128_GCM_SHA256
739
        #endif
740
        #ifdef HAVE_AESCCM
741
            #ifdef WOLFSSL_AES_128
742
                #define BUILD_TLS_DHE_PSK_WITH_AES_128_CCM
743
            #endif
744
            #ifdef WOLFSSL_AES_256
745
                #define BUILD_TLS_DHE_PSK_WITH_AES_256_CCM
746
            #endif
747
        #endif
748
    #endif
749
    #if defined(WOLFSSL_SHA384) && defined(HAVE_AESGCM) && \
750
        defined(WOLFSSL_AES_256)
751
        #define BUILD_TLS_DHE_PSK_WITH_AES_256_GCM_SHA384
752
    #endif
753
#endif
754
755
#if (defined(HAVE_ECC) || defined(HAVE_CURVE25519) || defined(HAVE_CURVE448)) \
756
                                         && !defined(NO_TLS) && !defined(NO_AES)
757
    #ifdef HAVE_AESGCM
758
        #if !defined(NO_SHA256) && defined(WOLFSSL_AES_128)
759
            #if defined(HAVE_ECC) || \
760
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
761
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
762
                #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
763
            #endif
764
            #ifndef NO_RSA
765
                #define BUILD_TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
766
            #endif
767
        #endif
768
        #if defined(WOLFSSL_SHA384) && defined(WOLFSSL_AES_256)
769
            #if defined(HAVE_ECC) || \
770
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
771
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
772
                #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
773
            #endif
774
            #ifndef NO_RSA
775
                #define BUILD_TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
776
            #endif
777
        #endif
778
    #endif
779
    #if defined(HAVE_AESCCM) && !defined(NO_SHA256)
780
        #if defined(HAVE_ECC) || \
781
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
782
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
783
            #ifdef WOLFSSL_AES_128
784
                #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CCM
785
                #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8
786
            #endif
787
            #ifdef WOLFSSL_AES_256
788
                #define BUILD_TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8
789
            #endif
790
        #endif
791
    #endif
792
#endif
793
794
#if defined(HAVE_CHACHA) && defined(HAVE_POLY1305) && !defined(NO_SHA256)
795
    #if defined(HAVE_ECC) || defined(HAVE_CURVE25519) || defined(HAVE_CURVE448)
796
        #if defined(HAVE_ECC) || \
797
                        (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) || \
798
                        (defined(HAVE_CURVE448) && defined(HAVE_ED448))
799
            #define BUILD_TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256
800
        #endif
801
        #ifndef NO_RSA
802
            #define BUILD_TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
803
        #endif
804
    #endif
805
    #if !defined(NO_DH) && !defined(NO_RSA) && !defined(NO_TLS_DH)
806
        /* SHOULD NOT negotiate cipher suites based on ephemeral
807
         * finite-field Diffie-Hellman key agreement (i.e., "TLS_DHE_*"
808
         * suites). https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
809
        #define BUILD_TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256
810
    #endif
811
#endif
812
813
    #if defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3)
814
        #ifdef WOLFSSL_SM4_CBC
815
            #define BUILD_TLS_ECDHE_ECDSA_WITH_SM4_CBC_SM3
816
        #endif
817
        #ifdef WOLFSSL_SM4_GCM
818
            #define BUILD_TLS_ECDHE_ECDSA_WITH_SM4_GCM_SM3
819
        #endif
820
        #ifdef WOLFSSL_SM4_CCM
821
            #define BUILD_TLS_ECDHE_ECDSA_WITH_SM4_CCM_SM3
822
        #endif
823
    #endif
824
#endif
825
826
#if defined(WOLFSSL_TLS13)
827
    #ifdef HAVE_AESGCM
828
        #if !defined(NO_SHA256) && defined(WOLFSSL_AES_128)
829
            #define BUILD_TLS_AES_128_GCM_SHA256
830
        #endif
831
        #if defined(WOLFSSL_SHA384) && defined(WOLFSSL_AES_256)
832
            #define BUILD_TLS_AES_256_GCM_SHA384
833
        #endif
834
    #endif
835
836
    #if defined(HAVE_CHACHA) && defined(HAVE_POLY1305)
837
        #ifndef NO_SHA256
838
            #define BUILD_TLS_CHACHA20_POLY1305_SHA256
839
        #endif
840
    #endif
841
842
    #ifdef HAVE_AESCCM
843
        #if !defined(NO_SHA256) && defined(WOLFSSL_AES_128)
844
            #define BUILD_TLS_AES_128_CCM_SHA256
845
            #define BUILD_TLS_AES_128_CCM_8_SHA256
846
        #endif
847
    #endif
848
    #ifdef HAVE_NULL_CIPHER
849
        #ifndef NO_SHA256
850
            #define BUILD_TLS_SHA256_SHA256
851
        #endif
852
        #ifdef WOLFSSL_SHA384
853
            #define BUILD_TLS_SHA384_SHA384
854
        #endif
855
    #endif
856
857
    #ifdef WOLFSSL_SM3
858
        #ifdef WOLFSSL_SM4_GCM
859
            #define BUILD_TLS_SM4_GCM_SM3
860
        #endif
861
862
        #ifdef WOLFSSL_SM4_CCM
863
            #define BUILD_TLS_SM4_CCM_SM3
864
        #endif
865
    #endif
866
#endif
867
868
#if !defined(WOLFCRYPT_ONLY) && defined(NO_PSK) && \
869
    (defined(NO_DH) || !defined(HAVE_ANON)) && \
870
    defined(NO_RSA) && !defined(HAVE_ECC) && \
871
    !defined(HAVE_ED25519) && !defined(HAVE_ED448) && \
872
    (!defined(WOLFSSL_TLS13) || \
873
     (!defined(HAVE_FALCON) && !defined(WOLFSSL_HAVE_MLDSA) && \
874
      !defined(WOLFSSL_HAVE_SLHDSA)))
875
   #error "No cipher suites available with this build"
876
#endif
877
878
#ifdef WOLFSSL_MULTICAST
879
    #if defined(HAVE_NULL_CIPHER) && !defined(NO_SHA256)
880
        #define BUILD_WDM_WITH_NULL_SHA256
881
    #endif
882
#endif
883
884
#if defined(BUILD_SSL_RSA_WITH_RC4_128_SHA) || \
885
    defined(BUILD_SSL_RSA_WITH_RC4_128_MD5)
886
    #define BUILD_ARC4
887
#endif
888
889
#if defined(BUILD_SSL_RSA_WITH_3DES_EDE_CBC_SHA)
890
    #define BUILD_DES3
891
#endif
892
893
#if defined(BUILD_TLS_RSA_WITH_AES_128_CBC_SHA) || \
894
    defined(BUILD_TLS_RSA_WITH_AES_256_CBC_SHA) || \
895
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256) || \
896
    defined(BUILD_TLS_DHE_PSK_WITH_AES_128_CBC_SHA256)
897
    #undef  BUILD_AES
898
    #define BUILD_AES
899
#endif
900
901
#if defined(BUILD_TLS_RSA_WITH_AES_128_GCM_SHA256) || \
902
    defined(BUILD_TLS_DHE_RSA_WITH_AES_128_GCM_SHA256) || \
903
    defined(BUILD_TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) || \
904
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256) || \
905
    defined(BUILD_TLS_PSK_WITH_AES_128_GCM_SHA256) || \
906
    defined(BUILD_TLS_DHE_PSK_WITH_AES_128_GCM_SHA256) || \
907
    defined(BUILD_TLS_RSA_WITH_AES_256_GCM_SHA384) || \
908
    defined(BUILD_TLS_DHE_RSA_WITH_AES_256_GCM_SHA384) || \
909
    defined(BUILD_TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) || \
910
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384) || \
911
    defined(BUILD_TLS_PSK_WITH_AES_256_GCM_SHA384) || \
912
    defined(BUILD_TLS_DHE_PSK_WITH_AES_256_GCM_SHA384) || \
913
    defined(BUILD_TLS_AES_128_GCM_SHA256) || \
914
    defined(BUILD_TLS_AES_256_GCM_SHA384)
915
    #define BUILD_AESGCM
916
#else
917
    /* No AES-GCM cipher suites available with build */
918
    #define NO_AESGCM_AEAD
919
#endif
920
921
#if defined(BUILD_TLS_RSA_WITH_AES_128_CCM_8) || \
922
    defined(BUILD_TLS_RSA_WITH_AES_256_CCM_8) || \
923
    defined(BUILD_TLS_PSK_WITH_AES_128_CCM_8) || \
924
    defined(BUILD_TLS_PSK_WITH_AES_128_CCM) || \
925
    defined(BUILD_TLS_PSK_WITH_AES_256_CCM_8) || \
926
    defined(BUILD_TLS_PSK_WITH_AES_256_CCM) || \
927
    defined(BUILD_TLS_DHE_PSK_WITH_AES_128_CCM) || \
928
    defined(BUILD_TLS_DHE_PSK_WITH_AES_256_CCM) || \
929
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CCM) || \
930
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8) || \
931
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8) || \
932
    defined(BUILD_TLS_AES_128_CCM_SHA256) || \
933
    defined(BUILD_TLS_AES_128_CCM_8_SHA256)
934
    #define BUILD_AESCCM
935
#else
936
    /* No AES-CCM cipher suites available with build */
937
    #define NO_AESCCM_AEAD
938
#endif
939
940
#if defined(BUILD_TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256) || \
941
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384)
942
    #define BUILD_ARIA
943
#endif
944
945
#if defined(BUILD_TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256) || \
946
    defined(BUILD_TLS_DHE_RSA_WITH_CHACHA20_OLD_POLY1305_SHA256) || \
947
    defined(BUILD_TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256) || \
948
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256) || \
949
    defined(BUILD_TLS_ECDHE_ECDSA_WITH_CHACHA20_OLD_POLY1305_SHA256) || \
950
    defined(BUILD_TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256) || \
951
    defined(BUILD_TLS_ECDHE_RSA_WITH_CHACHA20_OLD_POLY1305_SHA256) || \
952
    defined(BUILD_TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256) || \
953
    defined(BUILD_TLS_PSK_WITH_CHACHA20_POLY1305_SHA256) || \
954
    defined(BUILD_TLS_CHACHA20_POLY1305_SHA256)
955
    /* Have an available ChaCha Poly cipher suite */
956
#else
957
    /* No ChaCha Poly cipher suites available with build */
958
    #define NO_CHAPOL_AEAD
959
#endif
960
961
#ifdef NO_DES3
962
    #define DES_BLOCK_SIZE 8
963
#else
964
    #undef  BUILD_DES3
965
    #define BUILD_DES3
966
#endif
967
968
#if defined(NO_AES) || !defined(HAVE_AES_DECRYPT)
969
    #undef WC_AES_BLOCK_SIZE
970
    #define WC_AES_BLOCK_SIZE 16
971
    #undef  BUILD_AES
972
#else
973
    #undef  BUILD_AES
974
    #define BUILD_AES
975
#endif
976
977
#if !defined(NO_RC4) && !defined(WSSL_HARDEN_TLS)
978
    /* MUST NOT negotiate RC4 cipher suites
979
     * https://www.rfc-editor.org/rfc/rfc9325#section-4.1 */
980
    #undef  BUILD_ARC4
981
    #define BUILD_ARC4
982
#endif
983
984
#ifdef HAVE_CHACHA
985
0
    #define CHACHA20_BLOCK_SIZE 16
986
#endif
987
988
#if defined(WOLFSSL_MAX_STRENGTH) || \
989
    (defined(HAVE_AESGCM) && !defined(NO_AESGCM_AEAD)) || \
990
     defined(HAVE_AESCCM) || \
991
     defined(HAVE_ARIA) || \
992
    (defined(HAVE_CHACHA) && defined(HAVE_POLY1305) && \
993
     !defined(NO_CHAPOL_AEAD)) || \
994
    defined(WOLFSSL_SM4_GCM) || defined(WOLFSSL_SM4_CCM) || \
995
    (defined(WOLFSSL_TLS13) && defined(HAVE_NULL_CIPHER))
996
997
    #define HAVE_AEAD
998
#endif
999
1000
#if defined(WOLFSSL_MAX_STRENGTH) || \
1001
    defined(HAVE_ECC) || !defined(NO_DH)
1002
1003
    #define HAVE_PFS
1004
#endif
1005
1006
#ifdef WSSL_HARDEN_TLS
1007
    #ifdef HAVE_NULL_CIPHER
1008
        #error "NULL ciphers not allowed https://www.rfc-editor.org/rfc/rfc9325#section-4.1"
1009
    #endif
1010
    #ifdef WOLFSSL_STATIC_RSA
1011
        #error "Static RSA ciphers not allowed https://www.rfc-editor.org/rfc/rfc9325#section-4.1"
1012
    #endif
1013
    #ifdef WOLFSSL_STATIC_DH
1014
        #error "Static DH ciphers not allowed https://www.rfc-editor.org/rfc/rfc9325#section-4.1"
1015
    #endif
1016
    #ifdef HAVE_ANON
1017
        #error "At least the server side has to be authenticated"
1018
    #endif
1019
#endif
1020
1021
#undef WSSL_HARDEN_TLS
1022
1023
/* CA Names feature */
1024
#if !defined(WOLFSSL_NO_CA_NAMES) && defined(OPENSSL_EXTRA)
1025
    #define SSL_CLIENT_CA_NAMES(ssl) ((ssl)->client_ca_names != NULL ? \
1026
        (ssl)->client_ca_names : \
1027
        (ssl)->ctx->client_ca_names)
1028
    #define SSL_CA_NAMES(ssl) ((ssl)->ca_names != NULL ? \
1029
        (ssl)->ca_names : \
1030
        (ssl)->ctx->ca_names)
1031
    /* On the server, client_ca_names has priority over ca_names if both are
1032
     * set. This mimics OpenSSL's API:
1033
     * https://docs.openssl.org/3.6/man3/SSL_CTX_set0_CA_list/ */
1034
    #define SSL_PRIORITY_CA_NAMES(ssl) \
1035
        (((ssl)->options.side == WOLFSSL_SERVER_END && \
1036
        SSL_CLIENT_CA_NAMES(ssl) != NULL) ? \
1037
            SSL_CLIENT_CA_NAMES(ssl) : \
1038
            SSL_CA_NAMES(ssl))
1039
#else
1040
    #undef  WOLFSSL_NO_CA_NAMES
1041
    #define WOLFSSL_NO_CA_NAMES
1042
#endif
1043
1044
1045
/* actual cipher values, 2nd byte */
1046
enum {
1047
    TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA = 0x16,
1048
    TLS_DHE_RSA_WITH_AES_256_CBC_SHA  = 0x39,
1049
    TLS_DHE_RSA_WITH_AES_128_CBC_SHA  = 0x33,
1050
    TLS_DH_anon_WITH_AES_128_CBC_SHA  = 0x34,
1051
    TLS_RSA_WITH_AES_256_CBC_SHA      = 0x35,
1052
    TLS_RSA_WITH_AES_128_CBC_SHA      = 0x2F,
1053
    TLS_RSA_WITH_NULL_MD5             = 0x01,
1054
    TLS_RSA_WITH_NULL_SHA             = 0x02,
1055
    TLS_PSK_WITH_AES_256_CBC_SHA      = 0x8d,
1056
    TLS_PSK_WITH_AES_128_CBC_SHA256   = 0xae,
1057
    TLS_PSK_WITH_AES_256_CBC_SHA384   = 0xaf,
1058
    TLS_PSK_WITH_AES_128_CBC_SHA      = 0x8c,
1059
    TLS_PSK_WITH_NULL_SHA256          = 0xb0,
1060
    TLS_PSK_WITH_NULL_SHA384          = 0xb1,
1061
    TLS_PSK_WITH_NULL_SHA             = 0x2c,
1062
    SSL_RSA_WITH_RC4_128_SHA          = 0x05,
1063
    SSL_RSA_WITH_RC4_128_MD5          = 0x04,
1064
    SSL_RSA_WITH_3DES_EDE_CBC_SHA     = 0x0A,
1065
1066
    /* ECC suites, first byte is 0xC0 (ECC_BYTE) */
1067
    TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA    = 0x14,
1068
    TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA    = 0x13,
1069
    TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA  = 0x0A,
1070
    TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA  = 0x09,
1071
    TLS_ECDHE_RSA_WITH_RC4_128_SHA        = 0x11,
1072
    TLS_ECDHE_ECDSA_WITH_RC4_128_SHA      = 0x07,
1073
    TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA   = 0x12,
1074
    TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA = 0x08,
1075
    TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256   = 0x27,
1076
    TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 = 0x23,
1077
    TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384   = 0x28,
1078
    TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 = 0x24,
1079
    TLS_ECDHE_ECDSA_WITH_NULL_SHA           = 0x06,
1080
    TLS_ECDHE_PSK_WITH_NULL_SHA256          = 0x3a,
1081
    TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256   = 0x37,
1082
1083
    /* static ECDH, first byte is 0xC0 (ECC_BYTE) */
1084
    TLS_ECDH_RSA_WITH_AES_256_CBC_SHA    = 0x0F,
1085
    TLS_ECDH_RSA_WITH_AES_128_CBC_SHA    = 0x0E,
1086
    TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA  = 0x05,
1087
    TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA  = 0x04,
1088
    TLS_ECDH_RSA_WITH_RC4_128_SHA        = 0x0C,
1089
    TLS_ECDH_ECDSA_WITH_RC4_128_SHA      = 0x02,
1090
    TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA   = 0x0D,
1091
    TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA = 0x03,
1092
    TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256   = 0x29,
1093
    TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256 = 0x25,
1094
    TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384   = 0x2A,
1095
    TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384 = 0x26,
1096
1097
    WDM_WITH_NULL_SHA256          = 0xFE, /* wolfSSL DTLS Multicast */
1098
1099
    /* SHA256 */
1100
    TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 = 0x6b,
1101
    TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 = 0x67,
1102
    TLS_RSA_WITH_AES_256_CBC_SHA256     = 0x3d,
1103
    TLS_RSA_WITH_AES_128_CBC_SHA256     = 0x3c,
1104
    TLS_RSA_WITH_NULL_SHA256            = 0x3b,
1105
    TLS_DHE_PSK_WITH_AES_128_CBC_SHA256 = 0xb2,
1106
    TLS_DHE_PSK_WITH_NULL_SHA256        = 0xb4,
1107
1108
    /* SHA384 */
1109
    TLS_DHE_PSK_WITH_AES_256_CBC_SHA384 = 0xb3,
1110
    TLS_DHE_PSK_WITH_NULL_SHA384        = 0xb5,
1111
1112
    /* AES-GCM */
1113
    TLS_RSA_WITH_AES_128_GCM_SHA256          = 0x9c,
1114
    TLS_RSA_WITH_AES_256_GCM_SHA384          = 0x9d,
1115
    TLS_DHE_RSA_WITH_AES_128_GCM_SHA256      = 0x9e,
1116
    TLS_DHE_RSA_WITH_AES_256_GCM_SHA384      = 0x9f,
1117
    TLS_DH_anon_WITH_AES_256_GCM_SHA384      = 0xa7,
1118
    TLS_PSK_WITH_AES_128_GCM_SHA256          = 0xa8,
1119
    TLS_PSK_WITH_AES_256_GCM_SHA384          = 0xa9,
1120
    TLS_DHE_PSK_WITH_AES_128_GCM_SHA256      = 0xaa,
1121
    TLS_DHE_PSK_WITH_AES_256_GCM_SHA384      = 0xab,
1122
1123
    /* ECC AES-GCM, first byte is 0xC0 (ECC_BYTE) */
1124
    TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256  = 0x2b,
1125
    TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384  = 0x2c,
1126
    TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256   = 0x2d,
1127
    TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384   = 0x2e,
1128
    TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256    = 0x2f,
1129
    TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384    = 0x30,
1130
    TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256     = 0x31,
1131
    TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384     = 0x32,
1132
1133
    /* AES-CCM, first byte is 0xC0 but isn't ECC,
1134
     * also, in some of the other AES-CCM suites
1135
     * there will be second byte number conflicts
1136
     * with non-ECC AES-GCM */
1137
    TLS_RSA_WITH_AES_128_CCM_8         = 0xa0,
1138
    TLS_RSA_WITH_AES_256_CCM_8         = 0xa1,
1139
    TLS_ECDHE_ECDSA_WITH_AES_128_CCM   = 0xac,
1140
    TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8 = 0xae,
1141
    TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8 = 0xaf,
1142
    TLS_PSK_WITH_AES_128_CCM           = 0xa4,
1143
    TLS_PSK_WITH_AES_256_CCM           = 0xa5,
1144
    TLS_PSK_WITH_AES_128_CCM_8         = 0xa8,
1145
    TLS_PSK_WITH_AES_256_CCM_8         = 0xa9,
1146
    TLS_DHE_PSK_WITH_AES_128_CCM       = 0xa6,
1147
    TLS_DHE_PSK_WITH_AES_256_CCM       = 0xa7,
1148
1149
    /* Camellia */
1150
    TLS_RSA_WITH_CAMELLIA_128_CBC_SHA        = 0x41,
1151
    TLS_RSA_WITH_CAMELLIA_256_CBC_SHA        = 0x84,
1152
    TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256     = 0xba,
1153
    TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256     = 0xc0,
1154
    TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA    = 0x45,
1155
    TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA    = 0x88,
1156
    TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 = 0xbe,
1157
    TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256 = 0xc4,
1158
1159
    /* chacha20-poly1305 suites first byte is 0xCC (CHACHA_BYTE) */
1160
    TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256   = 0xa8,
1161
    TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 = 0xa9,
1162
    TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256     = 0xaa,
1163
    TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256   = 0xac,
1164
    TLS_PSK_WITH_CHACHA20_POLY1305_SHA256         = 0xab,
1165
    TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256     = 0xad,
1166
1167
    /* chacha20-poly1305 earlier version of nonce and padding (CHACHA_BYTE) */
1168
    TLS_ECDHE_RSA_WITH_CHACHA20_OLD_POLY1305_SHA256   = 0x13,
1169
    TLS_ECDHE_ECDSA_WITH_CHACHA20_OLD_POLY1305_SHA256 = 0x14,
1170
    TLS_DHE_RSA_WITH_CHACHA20_OLD_POLY1305_SHA256     = 0x15,
1171
1172
    /* ECDHE_PSK RFC8442, first byte is 0xD0 (EDHE_PSK_BYTE) */
1173
    TLS_ECDHE_PSK_WITH_AES_128_GCM_SHA256    = 0x01,
1174
1175
    /* TLS v1.3 cipher suites */
1176
    TLS_AES_128_GCM_SHA256       = 0x01,
1177
    TLS_AES_256_GCM_SHA384       = 0x02,
1178
    TLS_CHACHA20_POLY1305_SHA256 = 0x03,
1179
    TLS_AES_128_CCM_SHA256       = 0x04,
1180
    TLS_AES_128_CCM_8_SHA256     = 0x05,
1181
1182
    /* TLS v1.3 Integrity only cipher suites - 0xC0 (ECC) first byte */
1183
    TLS_SHA256_SHA256            = 0xB4,
1184
    TLS_SHA384_SHA384            = 0xB5,
1185
1186
    /* ARIA-GCM, first byte is 0xC0 (ECC_BYTE)
1187
    * See: https://www.rfc-editor.org/rfc/rfc6209.html#section-5
1188
    */
1189
    TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256   = 0x5c,
1190
    TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384   = 0x5d,
1191
1192
    /* TLS v1.3 SM cipher suites - 0x00 (CIPHER_BYTE) is first byte */
1193
    TLS_SM4_GCM_SM3              = 0xC6,
1194
    TLS_SM4_CCM_SM3              = 0xC7,
1195
1196
    /* TLS v1.2 SM cipher suites - 0xE0 (SM_BYTE) is first byte */
1197
    TLS_ECDHE_ECDSA_WITH_SM4_CBC_SM3 = 0x11,
1198
    TLS_ECDHE_ECDSA_WITH_SM4_GCM_SM3 = 0x51,
1199
    TLS_ECDHE_ECDSA_WITH_SM4_CCM_SM3 = 0x52,
1200
1201
    /* Fallback SCSV (Signaling Cipher Suite Value) */
1202
    TLS_FALLBACK_SCSV                        = 0x56,
1203
    /* Renegotiation Indication Extension Special Suite */
1204
    TLS_EMPTY_RENEGOTIATION_INFO_SCSV        = 0xff
1205
};
1206
1207
1208
#ifndef WOLFSSL_SESSION_TIMEOUT
1209
4.97k
    #define WOLFSSL_SESSION_TIMEOUT 500
1210
    /* default session resumption cache timeout in seconds */
1211
#endif
1212
1213
1214
#ifndef WOLFSSL_DTLS_WINDOW_WORDS
1215
    #define WOLFSSL_DTLS_WINDOW_WORDS 2
1216
#endif /* WOLFSSL_DTLS_WINDOW_WORDS */
1217
#define DTLS_WORD_BITS (sizeof(word32) * CHAR_BIT)
1218
#define DTLS_SEQ_BITS  (WOLFSSL_DTLS_WINDOW_WORDS * DTLS_WORD_BITS)
1219
#define DTLS_SEQ_SZ    (sizeof(word32) * WOLFSSL_DTLS_WINDOW_WORDS)
1220
1221
#ifndef WOLFSSL_MULTICAST
1222
    #define WOLFSSL_DTLS_PEERSEQ_SZ 1
1223
#else
1224
    #ifndef WOLFSSL_MULTICAST_PEERS
1225
        /* max allowed multicast group peers */
1226
        #define WOLFSSL_MULTICAST_PEERS 100
1227
    #endif
1228
    #define WOLFSSL_DTLS_PEERSEQ_SZ WOLFSSL_MULTICAST_PEERS
1229
#endif /* WOLFSSL_MULTICAST */
1230
1231
#ifndef WOLFSSL_MAX_MTU
1232
    /* 1500 - 100 bytes to account for UDP and IP headers */
1233
    #define WOLFSSL_MAX_MTU 1400
1234
#endif /* WOLFSSL_MAX_MTU */
1235
1236
#ifndef WOLFSSL_DTLS_MTU_ADDITIONAL_READ_BUFFER
1237
    #define WOLFSSL_DTLS_MTU_ADDITIONAL_READ_BUFFER 500
1238
#endif /* WOLFSSL_DTLS_MTU_ADDITIONAL_READ_BUFFER */
1239
1240
#ifndef WOLFSSL_DTLS_FRAG_POOL_SZ
1241
    #define WOLFSSL_DTLS_FRAG_POOL_SZ 10
1242
#endif
1243
1244
/* set minimum DH key size allowed */
1245
#ifndef WOLFSSL_MIN_DHKEY_BITS
1246
    #if defined(WOLFSSL_HARDEN_TLS) && !defined(WOLFSSL_HARDEN_TLS_NO_PKEY_CHECK)
1247
        /* Using guidance from section 5.6.1
1248
         * https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf */
1249
        #if WOLFSSL_HARDEN_TLS >= 128
1250
            #define WOLFSSL_MIN_DHKEY_BITS 3072
1251
        #elif WOLFSSL_HARDEN_TLS >= 112
1252
            #define WOLFSSL_MIN_DHKEY_BITS 2048
1253
        #endif
1254
    #else
1255
4.97k
        #define WOLFSSL_MIN_DHKEY_BITS DH_MIN_SIZE
1256
    #endif
1257
#endif
1258
#if defined(WOLFSSL_HARDEN_TLS) && WOLFSSL_MIN_DHKEY_BITS < 2048 && \
1259
    !defined(WOLFSSL_HARDEN_TLS_NO_PKEY_CHECK)
1260
    /* Implementations MUST NOT negotiate cipher suites offering less than
1261
     * 112 bits of security.
1262
     * https://www.rfc-editor.org/rfc/rfc9325#section-4.1
1263
     * Using guidance from section 5.6.1
1264
     * https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf */
1265
    #error "For 112 bits of security DH needs at least 2048 bit keys"
1266
#endif
1267
#if (WOLFSSL_MIN_DHKEY_BITS % 8)
1268
    #error DH minimum bit size must be multiple of 8
1269
#endif
1270
#if (WOLFSSL_MIN_DHKEY_BITS > 16000)
1271
    #error DH minimum bit size must not be greater than 16000
1272
#endif
1273
#if (WOLFSSL_MIN_DHKEY_BITS < DH_MIN_SIZE)
1274
    /* The TLS-layer minimum must not be looser than the wolfCrypt DH primitive
1275
     * minimum (DH_MIN_SIZE), otherwise a key size accepted during negotiation
1276
     * is later rejected by wc_DhAgree with WC_KEY_SIZE_E. */
1277
    #error "WOLFSSL_MIN_DHKEY_BITS must be >= DH_MIN_SIZE"
1278
#endif
1279
4.97k
#define MIN_DHKEY_SZ (WOLFSSL_MIN_DHKEY_BITS / 8)
1280
/* set maximum DH key size allowed */
1281
#ifndef WOLFSSL_MAX_DHKEY_BITS
1282
    #if (defined(USE_FAST_MATH) && defined(FP_MAX_BITS) && FP_MAX_BITS >= 16384)
1283
        #define WOLFSSL_MAX_DHKEY_BITS  (FP_MAX_BITS / 2)
1284
    #elif (defined(WOLFSSL_SP_MATH_ALL) || defined(WOLFSSL_SP_MATH)) && \
1285
           defined(SP_INT_BITS)
1286
        /* SP implementation supports numbers of SP_INT_BITS bits. */
1287
4.97k
        #define WOLFSSL_MAX_DHKEY_BITS  WC_BITS_FULL_BYTES(SP_INT_BITS)
1288
    #else
1289
        #define WOLFSSL_MAX_DHKEY_BITS  4096
1290
    #endif
1291
#endif
1292
#if (WOLFSSL_MAX_DHKEY_BITS % 8)
1293
    #error DH maximum bit size must be multiple of 8
1294
#endif
1295
#if (WOLFSSL_MAX_DHKEY_BITS > 16384)
1296
    #error DH maximum bit size must not be greater than 16384
1297
#endif
1298
4.97k
#define MAX_DHKEY_SZ (WOLFSSL_MAX_DHKEY_BITS / 8)
1299
1300
#ifndef NO_DH
1301
#if WOLFSSL_MAX_DHKEY_BITS < WOLFSSL_MIN_DHKEY_BITS
1302
#error "WOLFSSL_MAX_DHKEY_BITS has to be greater than WOLFSSL_MIN_DHKEY_BITS"
1303
#endif
1304
#endif /* NO_DH */
1305
1306
#ifndef MAX_PSK_KEY_LEN
1307
    #define MAX_PSK_KEY_LEN 64
1308
#endif
1309
1310
#ifndef MAX_EARLY_DATA_SZ
1311
    /* maximum early data size */
1312
    #define MAX_EARLY_DATA_SZ  4096
1313
#endif
1314
1315
/* Anti-replay eviction keys off the ticket's session ID. */
1316
#if defined(WOLFSSL_EARLY_DATA) && defined(HAVE_SESSION_TICKET) && \
1317
    !defined(WOLFSSL_TICKET_HAVE_ID)
1318
    #define WOLFSSL_TICKET_HAVE_ID
1319
#endif
1320
1321
1322
#if !defined(NO_RSA) || !defined(NO_DH) || defined(HAVE_ECC)
1323
    /* MySQL wants to be able to use 8192-bit numbers. */
1324
    #if defined(USE_FAST_MATH) && defined(FP_MAX_BITS)
1325
        /* Use the FP size up to 8192-bit and down to a min of 1024-bit. */
1326
        #if FP_MAX_BITS >= 16384
1327
            #define ENCRYPT_BASE_BITS  8192
1328
        #elif defined(HAVE_ECC)
1329
            #if FP_MAX_BITS > 2224
1330
                #define ENCRYPT_BASE_BITS  (FP_MAX_BITS / 2)
1331
            #else
1332
                /* 521-bit ASN.1 signature - 3 + 2 * (2 + 66) bytes. */
1333
                #define ENCRYPT_BASE_BITS  1112
1334
            #endif
1335
        #else
1336
            #if FP_MAX_BITS > 2048
1337
                #define ENCRYPT_BASE_BITS  (FP_MAX_BITS / 2)
1338
            #else
1339
                #define ENCRYPT_BASE_BITS  1024
1340
            #endif
1341
        #endif
1342
1343
        /* Check MySQL size requirements met. */
1344
        #if defined(WOLFSSL_MYSQL_COMPATIBLE) && ENCRYPT_BASE_BITS < 8192
1345
            #error "MySQL needs FP_MAX_BITS at least at 16384"
1346
        #endif
1347
1348
        #if !defined(NO_RSA) && defined(WC_MAX_RSA_BITS) && \
1349
            WC_MAX_RSA_BITS > ENCRYPT_BASE_BITS
1350
            #error "FP_MAX_BITS too small for WC_MAX_RSA_BITS"
1351
        #endif
1352
    #elif defined(WOLFSSL_SP_MATH_ALL) || defined(WOLFSSL_SP_MATH)
1353
        /* Use the SP size up to 8192-bit and down to a min of 1024-bit. */
1354
        #if SP_INT_BITS >= 8192
1355
            #define ENCRYPT_BASE_BITS  8192
1356
        #elif defined(HAVE_ECC)
1357
            #if SP_INT_BITS > 1112
1358
                #define ENCRYPT_BASE_BITS  SP_INT_BITS
1359
            #else
1360
                /* 521-bit ASN.1 signature - 3 + 2 * (2 + 66) bytes. */
1361
                #define ENCRYPT_BASE_BITS  1112
1362
            #endif
1363
        #else
1364
            #if SP_INT_BITS > 1024
1365
                #define ENCRYPT_BASE_BITS  SP_INT_BITS
1366
            #else
1367
                #define ENCRYPT_BASE_BITS  1024
1368
            #endif
1369
        #endif
1370
1371
        /* Check MySQL size requirements met. */
1372
        #if defined(WOLFSSL_MYSQL_COMPATIBLE) && ENCRYPT_BASE_BITS < 8192
1373
            #error "MySQL needs SP_INT_BITS at least at 8192"
1374
        #endif
1375
1376
        #if !defined(NO_RSA) && defined(WC_MAX_RSA_BITS) && \
1377
            WC_MAX_RSA_BITS > SP_INT_BITS
1378
            #error "SP_INT_BITS too small for WC_MAX_RSA_BITS"
1379
        #endif
1380
    #else
1381
        /* Integer/heap maths - support 4096-bit. */
1382
        #define ENCRYPT_BASE_BITS  4096
1383
    #endif
1384
#elif defined(HAVE_CURVE448)
1385
    #define ENCRYPT_BASE_BITS    (456 * 2)
1386
#elif defined(HAVE_CURVE25519)
1387
    #define ENCRYPT_BASE_BITS    (256 * 2)
1388
#else
1389
    /* No secret from public key operation but PSK key plus length used. */
1390
    #define ENCRYPT_BASE_BITS  ((MAX_PSK_KEY_LEN + 2) * 8)
1391
#endif
1392
1393
#ifdef WOLFSSL_DTLS_CID
1394
#ifndef DTLS_CID_MAX_SIZE
1395
/* DTLS parsing code copies the record header in a static buffer to decrypt
1396
 * the record. Increasing the CID max size does increase also this buffer,
1397
 * impacting on per-session runtime memory footprint. */
1398
#define DTLS_CID_MAX_SIZE 10
1399
#endif
1400
#else
1401
#undef DTLS_CID_MAX_SIZE
1402
#define DTLS_CID_MAX_SIZE 0
1403
#endif /* WOLFSSL_DTLS_CID */
1404
1405
/* This bounds the CID that we ask to receive and, for DTLS 1.2, also the
1406
 * peer-chosen CID that we send.
1407
 * For DTLS 1.3 the CID that we send is chosen by the peer and this does not
1408
 * bound it, only the wire format does (RFC 9146 Section 3: the ConnectionId
1409
 * is an opaque<0..2^8-1>). */
1410
#if DTLS_CID_MAX_SIZE > 255
1411
#error "Max size for DTLS CID is 255 bytes"
1412
#endif
1413
1414
/* Record Payload Protection Section 5
1415
 *   https://www.rfc-editor.org/rfc/rfc9146.html#section-5 */
1416
#define WOLFSSL_TLS_HMAC_CID_INNER_SZ                               \
1417
           (8 +                 /* seq_num_placeholder */           \
1418
            1 +                 /* tls12_cid */                     \
1419
            1 +                 /* cid_length */                    \
1420
            1 +                 /* tls12_cid */                     \
1421
            2 +                 /* DTLSCiphertext.version */        \
1422
            2 +                 /* epoch */                         \
1423
            6 +                 /* sequence_number */               \
1424
            DTLS_CID_MAX_SIZE + /* cid */                           \
1425
            2)                  /* length_of_DTLSInnerPlaintext */
1426
1427
#define WOLFSSL_TLS_AEAD_CID_AAD_SZ                                 \
1428
           (8 +                 /* seq_num_placeholder */           \
1429
            1 +                 /* tls12_cid */                     \
1430
            1 +                 /* cid_length */                    \
1431
            1 +                 /* tls12_cid */                     \
1432
            2 +                 /* DTLSCiphertext.version */        \
1433
            2 +                 /* epoch */                         \
1434
            6 +                 /* sequence_number */               \
1435
            DTLS_CID_MAX_SIZE + /* cid */                           \
1436
            2)                  /* length_of_DTLSInnerPlaintext */
1437
1438
#ifndef MAX_TICKET_AGE_DIFF
1439
/* maximum ticket age difference in seconds, 10 seconds */
1440
#define MAX_TICKET_AGE_DIFF     10
1441
#endif
1442
#ifndef TLS13_MAX_TICKET_AGE
1443
/* max ticket age in seconds, 7 days */
1444
#define TLS13_MAX_TICKET_AGE    (7*24*60*60)
1445
#endif
1446
1447
1448
/* Limit is 2^24.5
1449
 * https://www.rfc-editor.org/rfc/rfc8446#section-5.5
1450
 * Without the fraction is 23726566 (0x016A09E6) */
1451
#define AEAD_AES_LIMIT                           w64From32(0, 0x016A09E6)
1452
/* Limit is 2^23
1453
 * https://www.rfc-editor.org/rfc/rfc9147.html#name-integrity-limits */
1454
#define DTLS_AEAD_AES_CCM_LIMIT                  w64From32(0, 1 << 22)
1455
1456
/* Limit is 2^36
1457
 * https://www.rfc-editor.org/rfc/rfc9147.html#name-aead-limits */
1458
#define DTLS_AEAD_AES_GCM_CHACHA_FAIL_LIMIT      w64From32(1 << 3, 0)
1459
#define DTLS_AEAD_AES_GCM_CHACHA_FAIL_KU_LIMIT   w64From32(1 << 2, 0)
1460
/* Limit is 2^7
1461
 * https://www.rfc-editor.org/rfc/rfc9147.html#name-limits-for-aead_aes_128_ccm */
1462
#define DTLS_AEAD_AES_CCM_8_FAIL_LIMIT           w64From32(0, 1 << 6)
1463
#define DTLS_AEAD_AES_CCM_8_FAIL_KU_LIMIT        w64From32(0, 1 << 5)
1464
/* Limit is 2^23.5.
1465
 * https://www.rfc-editor.org/rfc/rfc9147.html#name-integrity-limits
1466
 * Without the fraction is 11863283 (0x00B504F3)
1467
 * Half of this value is    5931641 (0x005A8279) */
1468
#define DTLS_AEAD_AES_CCM_FAIL_LIMIT             w64From32(0, 0x00B504F3)
1469
#define DTLS_AEAD_AES_CCM_FAIL_KU_LIMIT          w64From32(0, 0x005A8279)
1470
1471
/* Limit is (2^22 - 1) full messages [2^36 - 31 octets]
1472
 * https://www.rfc-editor.org/rfc/rfc8998.html#name-aead_sm4_gcm
1473
 */
1474
#define AEAD_SM4_GCM_LIMIT                       w64From32(0, (1 << 22) - 1)
1475
/* Limit is (2^10 - 1) full messages [2^24 - 1 octets]
1476
 * https://www.rfc-editor.org/rfc/rfc8998.html#name-aead_sm4_ccm
1477
 */
1478
#define AEAD_SM4_CCM_LIMIT                       w64From32(0, (1 << 10) - 1)
1479
1480
#ifndef WOLFSSL_COOKIE_LEN
1481
/* Maximum size for a DTLS cookie */
1482
#define WOLFSSL_COOKIE_LEN 32
1483
#endif
1484
1485
#if WOLFSSL_COOKIE_LEN > 255
1486
#error "WOLFSSL_COOKIE_LEN must be <= 255 per RFC 6347 (opaque<0..2^8-1>)"
1487
#endif
1488
1489
#if defined(WOLFSSL_TLS13) || !defined(NO_PSK)
1490
1491
#define TLS13_TICKET_NONCE_MAX_SZ 255
1492
1493
#if (defined(HAVE_FIPS) &&                                                     \
1494
    !(defined(FIPS_VERSION_GE) && FIPS_VERSION_GE(5,3))) &&                    \
1495
    defined(TLS13_TICKET_NONCE_STATIC_SZ)
1496
#error "TLS13_TICKET_NONCE_STATIC_SZ is not supported in this FIPS version"
1497
#endif
1498
1499
#ifndef TLS13_TICKET_NONCE_STATIC_SZ
1500
#define TLS13_TICKET_NONCE_STATIC_SZ 8
1501
#endif
1502
1503
#if TLS13_TICKET_NONCE_STATIC_SZ > TLS13_TICKET_NONCE_MAX_SZ
1504
#error "Max size for ticket nonce is 255 bytes"
1505
#endif
1506
1507
#endif /* WOLFSSL_TLS13 || !NO_PSK */
1508
1509
#ifdef WOLFSSL_TLS13
1510
/* The length of the certificate verification label - client and server. */
1511
374
#define CERT_VFY_LABEL_SZ    34
1512
/* The number of prefix bytes for signature data. */
1513
374
#define SIGNING_DATA_PREFIX_SZ     64
1514
/* Maximum length of the signature data. */
1515
#define MAX_SIG_DATA_SZ            (SIGNING_DATA_PREFIX_SZ + \
1516
                                    CERT_VFY_LABEL_SZ      + \
1517
                                    WC_MAX_DIGEST_SIZE)
1518
#endif /* WOLFSSL_TLS13 */
1519
1520
enum Misc {
1521
    CIPHER_BYTE    = 0x00,         /* Default ciphers */
1522
    ECC_BYTE       = 0xC0,         /* ECC first cipher suite byte */
1523
    CHACHA_BYTE    = 0xCC,         /* ChaCha first cipher suite */
1524
    TLS13_BYTE     = 0x13,         /* TLS v1.3 first byte of cipher suite */
1525
    ECDHE_PSK_BYTE = 0xD0,         /* RFC 8442 */
1526
    SM_BYTE        = 0xE0,         /* SM first byte - private range */
1527
1528
    SEND_CERT       = 1,
1529
    SEND_BLANK_CERT = 2,
1530
1531
    DTLS_MAJOR      = 0xfe,     /* DTLS major version number */
1532
    DTLS_MINOR      = 0xff,     /* DTLS minor version number */
1533
    DTLS_BOGUS_MINOR = 0xfe,    /* DTLS 0xfe was skipped, see RFC6347 Sec. 1 */
1534
    DTLSv1_2_MINOR  = 0xfd,     /* DTLS minor version number */
1535
    DTLSv1_3_MINOR  = 0xfc,     /* DTLS minor version number */
1536
    SSLv3_MAJOR     = 3,        /* SSLv3 and TLSv1+  major version number */
1537
    SSLv3_MINOR     = 0,        /* TLSv1   minor version number */
1538
    TLSv1_MINOR     = 1,        /* TLSv1   minor version number */
1539
    TLSv1_1_MINOR   = 2,        /* TLSv1_1 minor version number */
1540
    TLSv1_2_MINOR   = 3,        /* TLSv1_2 minor version number */
1541
    TLSv1_3_MINOR   = 4,        /* TLSv1_3 minor version number */
1542
    TLS_DRAFT_MAJOR = 0x7f,     /* Draft TLS major version number */
1543
    OLD_HELLO_ID    = 0x01,     /* SSLv2 Client Hello Indicator */
1544
    INVALID_BYTE    = 0xff,     /* Used to initialize cipher specs values */
1545
    NO_COMPRESSION  =  0,
1546
    ZLIB_COMPRESSION = 221,     /* wolfSSL zlib compression */
1547
    HELLO_EXT_SIG_ALGO = 13,    /* ID for the sig_algo hello extension */
1548
    HELLO_EXT_EXTMS = 0x0017,   /* ID for the extended master secret ext */
1549
    SECRET_LEN      = WOLFSSL_MAX_MASTER_KEY_LENGTH,
1550
                                /* pre RSA and all master */
1551
#if !defined(WOLFSSL_TLS13) || defined(WOLFSSL_32BIT_MILLI_TIME)
1552
    TIMESTAMP_LEN   = 4,        /* timestamp size in ticket */
1553
#else
1554
    TIMESTAMP_LEN   = 8,        /* timestamp size in ticket */
1555
#endif
1556
#ifdef WOLFSSL_TLS13
1557
    AGEADD_LEN      = 4,        /* ageAdd size in ticket */
1558
    NAMEDGROUP_LEN  = 2,        /* namedGroup size in ticket */
1559
#ifdef WOLFSSL_EARLY_DATA
1560
    MAXEARLYDATASZ_LEN = 4,     /* maxEarlyDataSz size in ticket */
1561
#endif
1562
#endif
1563
#ifndef NO_PSK
1564
    ENCRYPT_LEN     = (ENCRYPT_BASE_BITS / 8) + MAX_PSK_KEY_LEN + 2,
1565
#else
1566
    ENCRYPT_LEN     = (ENCRYPT_BASE_BITS / 8),
1567
#endif
1568
    SIZEOF_SENDER   =  4,       /* clnt or srvr           */
1569
    FINISHED_SZ     = 36,       /* WC_MD5_DIGEST_SIZE + WC_SHA_DIGEST_SIZE */
1570
    MAX_PLAINTEXT_SZ   = (1 << 14),        /* Max plaintext sz   */
1571
    MAX_TLS_CIPHER_SZ  = (1 << 14) + 2048, /* Max TLS encrypted data sz */
1572
#ifdef WOLFSSL_TLS13
1573
    MAX_TLS13_PLAIN_SZ = (1 << 14) + 1,    /* Max unencrypted data sz */
1574
    MAX_TLS13_ENC_SZ   = (1 << 14) + 256,  /* Max encrypted data sz   */
1575
#endif
1576
    MAX_MSG_EXTRA   = 38 + WC_MAX_DIGEST_SIZE,
1577
                                /* max added to msg, mac + pad  from */
1578
                                /* RECORD_HEADER_SZ + BLOCK_SZ (pad) + Max
1579
                                   digest sz + BLOC_SZ (iv) + pad byte (1) */
1580
    MAX_COMP_EXTRA  = 1024,     /* max compression extra */
1581
    MAX_MTU         = WOLFSSL_MAX_MTU,     /* max expected MTU */
1582
    MAX_UDP_SIZE    = 8192 - 100, /* was MAX_MTU - 100 */
1583
    MAX_DH_SZ       = (MAX_DHKEY_SZ * 3) + 12, /* DH_P, DH_G and DH_Pub */
1584
                                /* 4096 p, pub, g + 2 byte size for each */
1585
    MAX_STR_VERSION = 8,        /* string rep of protocol version */
1586
1587
    PAD_MD5        = 48,       /* pad length for finished */
1588
    PAD_SHA        = 40,       /* pad length for finished */
1589
    MAX_PAD_SIZE   = 256,      /* maximum length of padding */
1590
1591
    LENGTH_SZ      =  2,       /* length field for HMAC, data only */
1592
    VERSION_SZ     =  2,       /* length of proctocol version */
1593
    SEQ_SZ         =  8,       /* 64 bit sequence number  */
1594
    ALERT_SIZE     =  2,       /* level + description     */
1595
    VERIFY_HEADER  =  2,       /* always use 2 bytes      */
1596
    EXTS_SZ        =  2,       /* always use 2 bytes      */
1597
    EXT_ID_SZ      =  2,       /* always use 2 bytes      */
1598
    MAX_DH_SIZE    = MAX_DHKEY_SZ+1,
1599
                               /* Max size plus possible leading 0 */
1600
    MIN_FFHDE_GROUP = 0x100,   /* Named group minimum for FFDHE parameters  */
1601
    MAX_FFHDE_GROUP = 0x1FF,   /* Named group maximum for FFDHE parameters  */
1602
    SESSION_HINT_SZ = 4,       /* session timeout hint */
1603
    SESSION_ADD_SZ = 4,        /* session age add */
1604
    TICKET_NONCE_LEN_SZ = 1,   /* Ticket nonce length size */
1605
    DEF_TICKET_NONCE_SZ = 1,   /* Default ticket nonce size */
1606
#if defined(WOLFSSL_TLS13) || !defined(NO_PSK)
1607
    MAX_TICKET_NONCE_STATIC_SZ = TLS13_TICKET_NONCE_STATIC_SZ,
1608
                               /* maximum ticket nonce static size */
1609
#endif /* WOLFSSL_TLS13 || !NO_PSK */
1610
    MAX_LIFETIME   = 604800,   /* maximum ticket lifetime */
1611
1612
    RAN_LEN      = 32,         /* random length           */
1613
    SEED_LEN     = RAN_LEN * 2, /* tls prf seed length    */
1614
    ID_LEN       = 32,         /* session id length       */
1615
    COOKIE_SECRET_SZ = 14,     /* dtls cookie secret size */
1616
    MAX_COOKIE_LEN = WOLFSSL_COOKIE_LEN, /* max dtls cookie size */
1617
    COOKIE_SZ    = 20,         /* use a 20 byte cookie    */
1618
    SUITE_LEN    =  2,         /* cipher suite sz length  */
1619
    ENUM_LEN     =  1,         /* always a byte           */
1620
    OPAQUE8_LEN  =  1,         /* 1 byte                  */
1621
    OPAQUE16_LEN =  2,         /* 2 bytes                 */
1622
    OPAQUE24_LEN =  3,         /* 3 bytes                 */
1623
    OPAQUE32_LEN =  4,         /* 4 bytes                 */
1624
    OPAQUE64_LEN =  8,         /* 8 bytes                 */
1625
    COMP_LEN     =  1,         /* compression length      */
1626
    CURVE_LEN    =  2,         /* ecc named curve length  */
1627
    KE_GROUP_LEN =  2,         /* key exchange group length */
1628
#if defined(NO_SHA) && !defined(NO_SHA256)
1629
    SERVER_ID_LEN = WC_SHA256_DIGEST_SIZE,
1630
#else
1631
    SERVER_ID_LEN = WC_SHA_DIGEST_SIZE,
1632
#endif
1633
1634
    HANDSHAKE_HEADER_SZ   = 4,  /* type + length(3)        */
1635
    DTLS13_HANDSHAKE_HEADER_SZ   = 12, /* sizeof(Dtls13HandshakeHeader) */
1636
    RECORD_HEADER_SZ      = 5,  /* type + version + len(2) */
1637
    CERT_HEADER_SZ        = 3,  /* always 3 bytes          */
1638
    REQ_HEADER_SZ         = 2,  /* cert request header sz  */
1639
    HINT_LEN_SZ           = 2,  /* length of hint size field */
1640
    TRUNCATED_HMAC_SZ     = 10, /* length of hmac w/ truncated hmac extension */
1641
    HELLO_EXT_SZ          = 4,  /* base length of a hello extension */
1642
    HELLO_EXT_TYPE_SZ     = 2,  /* length of a hello extension type */
1643
    HELLO_EXT_SZ_SZ       = 2,  /* length of a hello extension size */
1644
    HELLO_EXT_SIGALGO_SZ  = 2,  /* length of number of items in sigalgo list */
1645
1646
    DTLS_HANDSHAKE_HEADER_SZ = 12, /* normal + seq(2) + offset(3) + length(3) */
1647
    DTLS_RECORD_HEADER_SZ    = 13, /* normal + epoch(2) + seq_num(6) */
1648
    DTLS12_CID_OFFSET        = 11,
1649
    DTLS_UNIFIED_HEADER_MIN_SZ = 2,
1650
    /* flags + seq_number(2) + length(2) + CID */
1651
    DTLS_RECVD_RL_HEADER_MAX_SZ = 5 + DTLS_CID_MAX_SIZE,
1652
    DTLS_RECORD_HEADER_MAX_SZ = 13,
1653
    DTLS_HANDSHAKE_EXTRA     = 8,  /* diff from normal */
1654
    DTLS_RECORD_EXTRA        = 8,  /* diff from normal */
1655
    DTLS_HANDSHAKE_SEQ_SZ    = 2,  /* handshake header sequence number */
1656
    DTLS_HANDSHAKE_FRAG_SZ   = 3,  /* fragment offset and length are 24 bit */
1657
    DTLS_POOL_SZ             = 20, /* allowed number of list items in TX and
1658
                                    * RX pool */
1659
    DTLS_FRAG_POOL_SZ        = WOLFSSL_DTLS_FRAG_POOL_SZ,
1660
                                   /* allowed number of fragments per msg */
1661
    DTLS_EXPORT_PRO          = 165,/* wolfSSL protocol for serialized session */
1662
    DTLS_EXPORT_STATE_PRO    = 166,/* wolfSSL protocol for serialized state */
1663
    TLS_EXPORT_PRO           = 167,/* wolfSSL protocol for serialized TLS */
1664
    DTLS_EXPORT_OPT_SZ       = 66, /* number of bytes used from Options */
1665
    DTLS_EXPORT_OPT_SZ_5     = 62, /* number of bytes used from Options */
1666
    DTLS_EXPORT_OPT_SZ_4     = 61, /* number of bytes used from Options */
1667
    TLS_EXPORT_OPT_SZ        = 66, /* number of bytes used from Options */
1668
    TLS_EXPORT_OPT_SZ_5      = 66, /* number of bytes used from Options */
1669
    TLS_EXPORT_OPT_SZ_4      = 65, /* number of bytes used from Options */
1670
    DTLS_EXPORT_OPT_SZ_3     = 60, /* number of bytes used from Options */
1671
    DTLS_EXPORT_KEY_SZ       = 325 + (DTLS_SEQ_SZ * 2),
1672
                                   /* max number of bytes used from Keys */
1673
    DTLS_EXPORT_MIN_KEY_SZ   = 85 + (DTLS_SEQ_SZ * 2),
1674
                                   /* min number of bytes used from Keys */
1675
    WOLFSSL_EXPORT_TLS       = 1,
1676
    WOLFSSL_EXPORT_DTLS      = 0,
1677
#ifndef WOLFSSL_EXPORT_SPC_SZ
1678
    WOLFSSL_EXPORT_SPC_SZ    = 16, /* number of bytes used from CipherSpecs */
1679
#endif
1680
    WOLFSSL_EXPORT_LEN       = 2,  /* 2 bytes for length and protocol */
1681
    WOLFSSL_EXPORT_VERSION   = 6,  /* wolfSSL version for serialized session */
1682
1683
    /* older export versions supported */
1684
    WOLFSSL_EXPORT_VERSION_5 = 5,  /* version before DTLS Encrypt-Then-MAC */
1685
    WOLFSSL_EXPORT_VERSION_4 = 4,  /* 5.6.4 release and before */
1686
    WOLFSSL_EXPORT_VERSION_3 = 3,  /* wolfSSL version before TLS 1.3 addition */
1687
1688
    MAX_EXPORT_IP            = 46, /* max ip size IPv4 mapped IPv6 */
1689
    DTLS_MTU_ADDITIONAL_READ_BUFFER = WOLFSSL_DTLS_MTU_ADDITIONAL_READ_BUFFER,
1690
                                   /* Additional bytes to read so that
1691
                                    * we can work with a peer that has
1692
                                    * a slightly different MTU than us. */
1693
    MAX_EXPORT_BUFFER        = 514, /* max size of buffer for exporting */
1694
    MAX_EXPORT_STATE_BUFFER  = (DTLS_EXPORT_MIN_KEY_SZ) + (3 * WOLFSSL_EXPORT_LEN),
1695
                                    /* max size of buffer for exporting state */
1696
    FINISHED_LABEL_SZ   = 15,  /* TLS finished label size */
1697
    TLS_FINISHED_SZ     = 12,  /* TLS has a shorter size  */
1698
    TLS_FINISHED_SZ_MAX = WC_MAX_DIGEST_SIZE,
1699
                            /* longest message digest size is SHA512, 64 */
1700
    EXT_MASTER_LABEL_SZ = 22,  /* TLS extended master secret label sz */
1701
    MASTER_LABEL_SZ     = 13,  /* TLS master secret label sz */
1702
    KEY_LABEL_SZ        = 13,  /* TLS key block expansion sz */
1703
    PROTOCOL_LABEL_SZ   = 9,   /* Length of the protocol label */
1704
    MAX_LABEL_SZ        = 34,  /* Maximum length of a label */
1705
    MAX_REQUEST_SZ      = 256, /* Maximum cert req len (no auth yet */
1706
    SESSION_FLUSH_COUNT = 256, /* Flush session cache unless user turns off */
1707
    TLS_MAX_PAD_SZ      = 255, /* Max padding in TLS */
1708
    MAX_EXT_DATA_LEN    = 65535,
1709
                          /* Max extension data length <0..2^16-1> RFC 8446
1710
                           * Section 4.2 */
1711
    MAX_SV_EXT_LEN      = 255,
1712
                          /* Max supported_versions extension length
1713
                           * <2..254> RFC 8446 Section 4.2.1.*/
1714
1715
#if defined(HAVE_NULL_CIPHER) && defined(WOLFSSL_TLS13)
1716
    #if defined(WOLFSSL_SHA384) && WC_MAX_SYM_KEY_SIZE < 48
1717
        MAX_SYM_KEY_SIZE    = WC_SHA384_DIGEST_SIZE,
1718
    #elif !defined(NO_SHA256) && WC_MAX_SYM_KEY_SIZE < 32
1719
        MAX_SYM_KEY_SIZE    = WC_SHA256_DIGEST_SIZE,
1720
    #else
1721
        MAX_SYM_KEY_SIZE    = WC_MAX_SYM_KEY_SIZE,
1722
    #endif
1723
#else
1724
    MAX_SYM_KEY_SIZE    = WC_MAX_SYM_KEY_SIZE,
1725
#endif
1726
1727
#if defined(HAVE_SELFTEST) && \
1728
    (!defined(HAVE_SELFTEST_VERSION) || (HAVE_SELFTEST_VERSION < 2))
1729
    #ifndef WOLFSSL_AES_KEY_SIZE_ENUM
1730
    #define WOLFSSL_AES_KEY_SIZE_ENUM
1731
    AES_IV_SIZE         = 16,
1732
    AES_128_KEY_SIZE    = 16,
1733
    AES_192_KEY_SIZE    = 24,
1734
    AES_256_KEY_SIZE    = 32,
1735
    #endif
1736
#endif
1737
1738
    MAX_IV_SZ           = WC_AES_BLOCK_SIZE,
1739
1740
    AEAD_SEQ_OFFSET     = 4,   /* Auth Data: Sequence number */
1741
    AEAD_TYPE_OFFSET    = 8,   /* Auth Data: Type            */
1742
    AEAD_VMAJ_OFFSET    = 9,   /* Auth Data: Major Version   */
1743
    AEAD_VMIN_OFFSET    = 10,  /* Auth Data: Minor Version   */
1744
    AEAD_LEN_OFFSET     = 11,  /* Auth Data: Length          */
1745
    AEAD_AUTH_DATA_SZ   = 13,  /* Size of the data to authenticate */
1746
    AEAD_NONCE_SZ       = 12,
1747
    AESGCM_IMP_IV_SZ    = 4,   /* Size of GCM AEAD implicit IV */
1748
    AESCCM_IMP_IV_SZ    = 4,   /* Size of CCM AEAD implicit IV */
1749
    AESGCM_EXP_IV_SZ    = 8,   /* Size of GCM/CCM AEAD explicit IV */
1750
    AESGCM_NONCE_SZ     = AESGCM_EXP_IV_SZ + AESGCM_IMP_IV_SZ,
1751
    GCM_IMP_IV_SZ       = 4,   /* Size of GCM AEAD implicit IV */
1752
    CCM_IMP_IV_SZ       = 4,   /* Size of CCM AEAD implicit IV */
1753
    GCM_EXP_IV_SZ       = 8,   /* Size of GCM/CCM AEAD explicit IV */
1754
    GCM_NONCE_SZ        = GCM_EXP_IV_SZ + GCM_IMP_IV_SZ,
1755
1756
    CHACHA20_IMP_IV_SZ  = 12,  /* Size of ChaCha20 AEAD implicit IV */
1757
    CHACHA20_NONCE_SZ   = 12,  /* Size of ChacCha20 nonce           */
1758
    CHACHA20_OLD_OFFSET = 4,   /* Offset for seq # in old poly1305  */
1759
    CHACHA20_OFFSET     = 4,   /* Offset for seq # in poly1305  */
1760
1761
    /* For any new implicit/explicit IV size adjust AEAD_MAX_***_SZ */
1762
1763
    AES_GCM_AUTH_SZ     = 16, /* AES-GCM Auth Tag length    */
1764
    AES_CCM_16_AUTH_SZ  = 16, /* AES-CCM-16 Auth Tag length */
1765
    AES_CCM_8_AUTH_SZ   = 8,  /* AES-CCM-8 Auth Tag Length  */
1766
    AESCCM_NONCE_SZ     = 12,
1767
1768
    SM4_GCM_AUTH_SZ     = 16, /* SM4-GCM Auth Tag length    */
1769
    SM4_GCM_NONCE_SZ    = 12, /* SM4 GCM Nonce length       */
1770
    SM4_CCM_AUTH_SZ     = 16, /* SM4-CCM Auth Tag length    */
1771
    SM4_CCM_NONCE_SZ    = 12, /* SM4 CCM Nonce length       */
1772
1773
    CAMELLIA_128_KEY_SIZE = 16, /* for 128 bit */
1774
    CAMELLIA_192_KEY_SIZE = 24, /* for 192 bit */
1775
    CAMELLIA_256_KEY_SIZE = 32, /* for 256 bit */
1776
    CAMELLIA_IV_SIZE      = 16, /* always block size */
1777
1778
    CHACHA20_256_KEY_SIZE = 32,  /* for 256 bit             */
1779
    CHACHA20_128_KEY_SIZE = 16,  /* for 128 bit             */
1780
    CHACHA20_IV_SIZE      = 12,  /* 96 bits for iv          */
1781
1782
    POLY1305_AUTH_SZ    = 16,  /* 128 bits                */
1783
1784
    HMAC_NONCE_SZ       = 12,  /* Size of HMAC nonce */
1785
1786
    EVP_SALT_SIZE       =  8,  /* evp salt size 64 bits   */
1787
1788
#ifndef ECDHE_SIZE /* allow this to be overridden at compile-time */
1789
    ECDHE_SIZE          = 32,  /* ECDHE server size defaults to 256 bit */
1790
#endif
1791
    MAX_EXPORT_ECC_SZ   = 256, /* Export ANSI X9.62 max future size */
1792
    MAX_CURVE_NAME_SZ   = 20,  /* Maximum size of curve name string */
1793
1794
    NEW_SA_MAJOR        = 8,   /* Most significant byte used with new sig algos */
1795
    RSA_PSS_RSAE_SHA256_MINOR = 0x04,
1796
    RSA_PSS_RSAE_SHA384_MINOR = 0x05,
1797
    RSA_PSS_RSAE_SHA512_MINOR = 0x06,
1798
    RSA_PSS_PSS_SHA256_MINOR = 0x09,
1799
    RSA_PSS_PSS_SHA384_MINOR = 0x0A,
1800
    RSA_PSS_PSS_SHA512_MINOR = 0x0B,
1801
    ECDSA_BRAINPOOLP256R1TLS13_SHA256_MINOR = 0x1A,
1802
    ECDSA_BRAINPOOLP384R1TLS13_SHA384_MINOR = 0x1B,
1803
    ECDSA_BRAINPOOLP512R1TLS13_SHA512_MINOR = 0x1C,
1804
1805
    ED25519_SA_MAJOR    = 8,   /* Most significant byte for ED25519 */
1806
    ED25519_SA_MINOR    = 7,   /* Least significant byte for ED25519 */
1807
    ED448_SA_MAJOR      = 8,   /* Most significant byte for ED448 */
1808
    ED448_SA_MINOR      = 8,   /* Least significant byte for ED448 */
1809
    SM2_SA_MAJOR        = 7,   /* Most significant byte for SM2 with SM3 */
1810
    SM2_SA_MINOR        = 8,   /* Least significant byte for SM2 with SM3 */
1811
1812
    FALCON_SA_MAJOR     = 0xFE,/* Most significant byte used with falcon sig algs */
1813
    MLDSA_SA_MAJOR      = 0x09,/* Most significant byte used with ML-DSA sig algs */
1814
1815
    /* These values for falcon match what OQS has defined. */
1816
    FALCON_LEVEL1_SA_MAJOR = 0xFE,
1817
    FALCON_LEVEL1_SA_MINOR = 0xD7,
1818
    FALCON_LEVEL5_SA_MAJOR = 0xFE,
1819
    FALCON_LEVEL5_SA_MINOR = 0xDA,
1820
1821
    /* These values for ML-DSA correspond to what is proposed in the IETF. */
1822
    MLDSA_44_SA_MAJOR = 0x09,
1823
    MLDSA_44_SA_MINOR = 0x04,
1824
    MLDSA_65_SA_MAJOR = 0x09,
1825
    MLDSA_65_SA_MINOR = 0x05,
1826
    MLDSA_87_SA_MAJOR = 0x09,
1827
    MLDSA_87_SA_MINOR = 0x06,
1828
1829
    /* These values for SLH-DSA correspond to the code points assigned in
1830
     * draft-reddy-tls-slhdsa (0x0911-0x091C) and match what oqs-provider uses.
1831
     * The major byte (0x09) is shared with ML-DSA. */
1832
    SLHDSA_SA_MAJOR             = 0x09,
1833
    SLHDSA_SHA2_128S_SA_MINOR   = 0x11,
1834
    SLHDSA_SHA2_128F_SA_MINOR   = 0x12,
1835
    SLHDSA_SHA2_192S_SA_MINOR   = 0x13,
1836
    SLHDSA_SHA2_192F_SA_MINOR   = 0x14,
1837
    SLHDSA_SHA2_256S_SA_MINOR   = 0x15,
1838
    SLHDSA_SHA2_256F_SA_MINOR   = 0x16,
1839
    SLHDSA_SHAKE_128S_SA_MINOR  = 0x17,
1840
    SLHDSA_SHAKE_128F_SA_MINOR  = 0x18,
1841
    SLHDSA_SHAKE_192S_SA_MINOR  = 0x19,
1842
    SLHDSA_SHAKE_192F_SA_MINOR  = 0x1A,
1843
    SLHDSA_SHAKE_256S_SA_MINOR  = 0x1B,
1844
    SLHDSA_SHAKE_256F_SA_MINOR  = 0x1C,
1845
1846
    MIN_RSA_SHA512_PSS_BITS = 512 * 2 + 8 * 8, /* Min key size */
1847
    MIN_RSA_SHA384_PSS_BITS = 384 * 2 + 8 * 8, /* Min key size */
1848
1849
    CLIENT_HELLO_FIRST =  35,  /* Protocol + RAN_LEN + sizeof(id_len) */
1850
    MAX_SUITE_NAME     =  48,  /* maximum length of cipher suite string */
1851
1852
    DTLS_TIMEOUT_INIT       =  1, /* default timeout init for DTLS receive  */
1853
    DTLS_TIMEOUT_MAX        = 64, /* default max timeout for DTLS receive */
1854
    DTLS_TIMEOUT_MULTIPLIER =  2, /* default timeout multiplier for DTLS recv */
1855
1856
    NULL_TERM_LEN        =   1,  /* length of null '\0' termination character */
1857
    MIN_PSK_ID_LEN       =   6,  /* min length of identities */
1858
    MIN_PSK_BINDERS_LEN  =  33,  /* min length of binders */
1859
1860
#ifndef MAX_WOLFSSL_FILE_SIZE
1861
    MAX_WOLFSSL_FILE_SIZE = 1024UL * 1024UL * 4,  /* 4 mb file size alloc limit */
1862
#endif
1863
#if defined(WOLFSSL_SYS_CRYPTO_POLICY)
1864
    MAX_WOLFSSL_CRYPTO_POLICY_SIZE = 1024UL, /* Crypto-policy file is one line.
1865
                                              * It should not be large. */
1866
    MIN_WOLFSSL_SEC_LEVEL = 0,
1867
    MAX_WOLFSSL_SEC_LEVEL = 5,
1868
#endif /* WOLFSSL_SYS_CRYPTO_POLICY */
1869
1870
    CERT_MIN_SIZE      =  256, /* min PEM cert size with header/footer */
1871
1872
    NO_SNIFF           =   0,  /* not sniffing */
1873
    SNIFF              =   1,  /* currently sniffing */
1874
1875
    HASH_SIG_SIZE      =   2,  /* default SHA1 RSA */
1876
1877
    NO_COPY            =   0,  /* should we copy static buffer for write */
1878
    COPY               =   1,  /* should we copy static buffer for write */
1879
1880
    INVALID_PEER_ID    = 0xFFFF, /* Initialize value for peer ID. */
1881
1882
    PREV_ORDER         = -1,   /* Sequence number is in previous epoch. */
1883
    PEER_ORDER         = 1,    /* Peer sequence number for verify. */
1884
    CUR_ORDER          = 0,    /* Current sequence number. */
1885
    WRITE_PROTO        = 1,    /* writing a protocol message */
1886
    READ_PROTO         = 0     /* reading a protocol message */
1887
};
1888
1889
1890
/* Size of the data to authenticate */
1891
#if defined(WOLFSSL_DTLS) && defined(WOLFSSL_DTLS_CID)
1892
#define AEAD_AUTH_DATA_SZ WOLFSSL_TLS_AEAD_CID_AAD_SZ
1893
#else
1894
#define AEAD_AUTH_DATA_SZ 13
1895
#endif
1896
1897
#define WOLFSSL_NAMED_GROUP_IS_FFDHE(group) \
1898
100k
    (WOLFSSL_FFDHE_START <= (group) && (group) <= WOLFSSL_FFDHE_END)
1899
#ifdef WOLFSSL_HAVE_MLKEM
1900
WOLFSSL_LOCAL int NamedGroupIsPqc(int group);
1901
WOLFSSL_LOCAL int NamedGroupIsPqcHybrid(int group);
1902
17.4k
#define WOLFSSL_NAMED_GROUP_IS_PQC(group) NamedGroupIsPqc(group)
1903
13.1k
#define WOLFSSL_NAMED_GROUP_IS_PQC_HYBRID(group) NamedGroupIsPqcHybrid(group)
1904
#else
1905
#define WOLFSSL_NAMED_GROUP_IS_PQC(group)        ((void)(group), 0)
1906
#define WOLFSSL_NAMED_GROUP_IS_PQC_HYBRID(group) ((void)(group), 0)
1907
#endif /* WOLFSSL_HAVE_MLKEM */
1908
1909
/* minimum Downgrade Minor version */
1910
#ifndef WOLFSSL_MIN_DOWNGRADE
1911
    #ifndef NO_OLD_TLS
1912
        #define WOLFSSL_MIN_DOWNGRADE TLSv1_MINOR
1913
    #else
1914
4.97k
        #define WOLFSSL_MIN_DOWNGRADE TLSv1_2_MINOR
1915
    #endif
1916
#endif
1917
1918
/* minimum DTLS Downgrade Minor version */
1919
#ifndef WOLFSSL_MIN_DTLS_DOWNGRADE
1920
#define WOLFSSL_MIN_DTLS_DOWNGRADE DTLS_MINOR;
1921
#endif
1922
1923
/* Set max implicit IV size for AEAD cipher suites */
1924
#if defined(WOLFSSL_TLS13) && defined(HAVE_NULL_CIPHER) && defined(WOLFSSL_SHA384)
1925
    /* Integrity-only cipher suites use IV size equal to hash output size */
1926
    #define AEAD_MAX_IMP_SZ 48
1927
#elif defined(WOLFSSL_TLS13) && defined(HAVE_NULL_CIPHER) && !defined(NO_SHA256)
1928
    /* Integrity-only cipher suites use IV size equal to hash output size */
1929
    #define AEAD_MAX_IMP_SZ 32
1930
#else
1931
    #define AEAD_MAX_IMP_SZ 12
1932
#endif
1933
1934
/* Set max explicit IV size for AEAD cipher suites */
1935
0
#define AEAD_MAX_EXP_SZ 8
1936
1937
1938
#ifndef WOLFSSL_MAX_SUITE_SZ
1939
19.9k
    #define WOLFSSL_MAX_SUITE_SZ 300
1940
    /* 150 suites for now! */
1941
#endif
1942
1943
/* InitSuites() haveNull value used when NULL suites are requested explicitly
1944
 * (cipher list "eNULL" keyword) rather than merely allowed by default (1). */
1945
0
#define SUITES_NULL_EXPLICIT 2
1946
1947
/* number of items in the signature algo list */
1948
#ifndef WOLFSSL_MAX_SIGALGO
1949
#if (defined(WOLFSSL_LEANPSK) || defined(WOLFSSL_LEANTLS)) && \
1950
    !defined(HAVE_FALCON) && !defined(WOLFSSL_HAVE_MLDSA) && \
1951
    !defined(WOLFSSL_HAVE_SLHDSA)
1952
    /* Lean builds keep the list small to minimize the memory footprint, unless
1953
     * they are post-quantum builds: those want to inter-op with OQS's OpenSSL
1954
     * that sends a lot more sigalgs, so they fall through to the larger default.
1955
     */
1956
    #define WOLFSSL_MAX_SIGALGO 44
1957
#else
1958
3.85k
    #define WOLFSSL_MAX_SIGALGO 128
1959
#endif
1960
#endif
1961
1962
1963
/* set minimum ECC key size allowed */
1964
#ifndef WOLFSSL_MIN_ECC_BITS
1965
    #ifdef WOLFSSL_MAX_STRENGTH
1966
        #define WOLFSSL_MIN_ECC_BITS  256
1967
    #else
1968
10.0k
        #define WOLFSSL_MIN_ECC_BITS 224
1969
    #endif
1970
#endif /* WOLFSSL_MIN_ECC_BITS */
1971
#if (WOLFSSL_MIN_ECC_BITS % 8)
1972
    /* Some ECC keys are not divisible by 8 such as prime239v1 or sect131r1.
1973
       In these cases round down to the nearest value divisible by 8. The
1974
       restriction of being divisible by 8 is in place to match wc_ecc_size
1975
       function from wolfSSL.
1976
     */
1977
    #error ECC minimum bit size must be a multiple of 8
1978
#endif
1979
10.0k
#define MIN_ECCKEY_SZ (WOLFSSL_MIN_ECC_BITS / 8)
1980
1981
#ifdef HAVE_FALCON
1982
#ifndef MIN_FALCONKEY_SZ
1983
    #define MIN_FALCONKEY_SZ    1281
1984
#endif
1985
#endif
1986
#ifdef WOLFSSL_HAVE_MLDSA
1987
#ifndef MIN_MLDSAKEY_SZ
1988
    #define MIN_MLDSAKEY_SZ    2528
1989
#endif
1990
#endif
1991
1992
/* set minimum RSA key size allowed */
1993
#ifndef WOLFSSL_MIN_RSA_BITS
1994
    #if defined(WOLFSSL_HARDEN_TLS) && !defined(WOLFSSL_HARDEN_TLS_NO_PKEY_CHECK)
1995
        /* Using guidance from section 5.6.1
1996
         * https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf */
1997
        #if WOLFSSL_HARDEN_TLS >= 128
1998
            #define WOLFSSL_MIN_RSA_BITS 3072
1999
        #elif WOLFSSL_HARDEN_TLS >= 112
2000
            #define WOLFSSL_MIN_RSA_BITS 2048
2001
        #endif
2002
    #elif defined(WOLFSSL_MAX_STRENGTH)
2003
        #define WOLFSSL_MIN_RSA_BITS 2048
2004
    #else
2005
10.0k
        #define WOLFSSL_MIN_RSA_BITS 1024
2006
    #endif
2007
#endif /* WOLFSSL_MIN_RSA_BITS */
2008
#if defined(WOLFSSL_HARDEN_TLS) && WOLFSSL_MIN_RSA_BITS < 2048 && \
2009
    !defined(WOLFSSL_HARDEN_TLS_NO_PKEY_CHECK)
2010
    /* Implementations MUST NOT negotiate cipher suites offering less than
2011
     * 112 bits of security.
2012
     * https://www.rfc-editor.org/rfc/rfc9325#section-4.1
2013
     * Using guidance from section 5.6.1
2014
     * https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf */
2015
    #error "For 112 bits of security RSA needs at least 2048 bit keys"
2016
#endif
2017
#if (WOLFSSL_MIN_RSA_BITS % 8)
2018
    /* This is to account for the example case of a min size of 2050 bits but
2019
       still allows 2049 bit key. So we need the measurement to be in bytes. */
2020
    #error RSA minimum bit size must be a multiple of 8
2021
#endif
2022
10.0k
#define MIN_RSAKEY_SZ (WOLFSSL_MIN_RSA_BITS / 8)
2023
2024
#ifdef SESSION_INDEX
2025
/* Shift values for making a session index */
2026
#define SESSIDX_ROW_SHIFT 4
2027
#define SESSIDX_IDX_MASK  0x0F
2028
#endif
2029
2030
/* Size of the static per-certificate slot in a cached session's chain. This is
2031
 * embedded by value MAX_CHAIN_DEPTH times in every WOLFSSL_SESSION, so it is
2032
 * deliberately not sized from a post-quantum signature: a certificate too
2033
 * large for a slot is simply not recorded in the chain. Use
2034
 * MAX_CERT_WIRE_SZ for anything bounding a certificate on the wire. */
2035
#ifndef MAX_X509_SIZE
2036
    /* 9 KB holds the largest ML-DSA certificate (ML-DSA-87: 4627 byte signature
2037
     * plus 2592 byte public key, ~7.6 KB in practice) and an ML-DSA-44 dual
2038
     * algorithm certificate, which carries a second key and signature. Not
2039
     * derived from the enabled parameter set: the slot holds any certificate in
2040
     * a peer's chain, so tying it to the local ML-DSA level would make a
2041
     * level-restricted build silently drop certificates a full build kept. */
2042
    #if defined(HAVE_FALCON) || defined(WOLFSSL_HAVE_MLDSA) || \
2043
        defined(WOLFSSL_HAVE_SLHDSA)
2044
        #define MAX_X509_SIZE   (9*1024) /* max static x509 buffer size; ML-DSA is big */
2045
    #elif defined(WOLFSSL_HAPROXY)
2046
        #define MAX_X509_SIZE   3072 /* max static x509 buffer size */
2047
    #else
2048
52.9k
        #define MAX_X509_SIZE   2048 /* max static x509 buffer size */
2049
    #endif
2050
#endif
2051
2052
/* Largest single certificate that may appear in a handshake message. A
2053
 * post-quantum certificate's DER size is dominated by the issuer signature
2054
 * embedded in it, whose length depends on the parameter sets compiled in, plus
2055
 * headroom for the subject public key (largest is ML-DSA-87 at 2592 bytes) and
2056
 * the rest of the TBSCertificate. A leaf may be signed by a root of a larger
2057
 * parameter set, so the signature maximum is taken family-wide. */
2058
#ifndef MAX_CERT_WIRE_SZ
2059
    #if defined(WOLFSSL_HAVE_SLHDSA) && \
2060
        ((WC_SLHDSA_MAX_SIG_LEN + 4096) > MAX_X509_SIZE)
2061
        #define MAX_CERT_WIRE_SZ    (WC_SLHDSA_MAX_SIG_LEN + 4096)
2062
    #elif defined(WOLFSSL_HAVE_MLDSA) && \
2063
        ((MLDSA_MAX_SIG_SIZE + 4096) > MAX_X509_SIZE)
2064
        #define MAX_CERT_WIRE_SZ    (MLDSA_MAX_SIG_SIZE + 4096)
2065
    #else
2066
52.9k
        #define MAX_CERT_WIRE_SZ    MAX_X509_SIZE
2067
    #endif
2068
#endif
2069
2070
/* max cert chain peer depth */
2071
#ifndef MAX_CHAIN_DEPTH
2072
57.9k
    #define MAX_CHAIN_DEPTH 9
2073
#endif
2074
2075
#if defined(HAVE_CERTIFICATE_STATUS_REQUEST) || \
2076
                    defined(HAVE_CERTIFICATE_STATUS_REQUEST_V2)
2077
    #if !defined(HAVE_OCSP)
2078
        #error OCSP Stapling and Stapling V2 needs OCSP. Please define HAVE_OCSP.
2079
    #endif
2080
#endif
2081
2082
/* Max certificate extensions in TLS1.3 */
2083
#if defined(HAVE_CERTIFICATE_STATUS_REQUEST)
2084
    /* Number of extensions to set each OCSP response */
2085
    #define MAX_CERT_EXTENSIONS (1 + MAX_CHAIN_DEPTH)
2086
#else
2087
    /* Only empty extensions */
2088
0
    #define MAX_CERT_EXTENSIONS 1
2089
#endif
2090
2091
/* Chain depth assumed when sizing the certificate message. Deliberately not
2092
 * MAX_CHAIN_DEPTH: that bounds how deep a chain may be verified, while this
2093
 * sizes a buffer an unauthenticated peer can make us allocate. Only reduced
2094
 * when a post-quantum certificate has inflated the per-certificate size, where
2095
 * the full verification depth would reserve hundreds of kilobytes and chains
2096
 * that deep are not realistic. Classic builds keep the historical depth, since
2097
 * the resulting buffer is small either way. Raise it for a deployment that
2098
 * presents deeper chains of post-quantum certificates. */
2099
#ifndef MAX_CERT_MSG_DEPTH
2100
    /* Trim only once a single certificate is large enough that the full
2101
     * verification depth would reserve an unreasonable amount for an
2102
     * unauthenticated peer. The threshold sits above any classic or ML-DSA
2103
     * certificate, so those builds keep the historical depth, and the test is
2104
     * on the size itself rather than on which macro produced it, so raising
2105
     * MAX_X509_SIZE cannot disengage the trim. */
2106
    #if (MAX_CERT_WIRE_SZ > (16*1024)) && (MAX_CHAIN_DEPTH > 5)
2107
        #define MAX_CERT_MSG_DEPTH 5
2108
    #else
2109
52.9k
        #define MAX_CERT_MSG_DEPTH MAX_CHAIN_DEPTH
2110
    #endif
2111
#endif
2112
2113
/* max size of a certificate message payload */
2114
/* assumes MAX_CERT_MSG_DEPTH certificates of MAX_CERT_WIRE_SZ each */
2115
#ifndef MAX_CERTIFICATE_SZ
2116
    #define MAX_CERTIFICATE_SZ \
2117
52.9k
                (CERT_HEADER_SZ + \
2118
52.9k
                (MAX_CERT_WIRE_SZ + CERT_HEADER_SZ) * MAX_CERT_MSG_DEPTH)
2119
#endif
2120
2121
/* max size of a handshake message, currently set to the certificate */
2122
#ifndef MAX_HANDSHAKE_SZ
2123
52.9k
    #define MAX_HANDSHAKE_SZ MAX_CERTIFICATE_SZ
2124
#endif
2125
2126
#ifndef PREALLOC_SESSION_TICKET_LEN
2127
    #define PREALLOC_SESSION_TICKET_LEN 512
2128
#endif
2129
2130
#ifndef PREALLOC_SESSION_TICKET_NONCE_LEN
2131
    #define PREALLOC_SESSION_TICKET_NONCE_LEN 32
2132
#endif
2133
2134
#ifndef SESSION_TICKET_HINT_DEFAULT
2135
    #define SESSION_TICKET_HINT_DEFAULT 300
2136
#endif
2137
2138
#if !defined(WOLFSSL_NO_DEF_TICKET_ENC_CB) && !defined(NO_WOLFSSL_SERVER)
2139
    /* Check chosen encryption is available. */
2140
    #if !(defined(HAVE_CHACHA) && defined(HAVE_POLY1305)) && \
2141
        defined(WOLFSSL_TICKET_ENC_CHACHA20_POLY1305)
2142
        #error "ChaCha20-Poly1305 not available for default ticket encryption"
2143
    #endif
2144
    #if !defined(HAVE_AESGCM) && (defined(WOLFSSL_TICKET_ENC_AES128_GCM) || \
2145
        defined(WOLFSSL_TICKET_ENC_AES256_GCM))
2146
        #error "AES-GCM not available for default ticket encryption"
2147
    #endif
2148
2149
    #ifndef WOLFSSL_TICKET_KEY_LIFETIME
2150
        /* Default lifetime is 1 hour from issue of first ticket with key. */
2151
        #define WOLFSSL_TICKET_KEY_LIFETIME       (60 * 60)
2152
    #endif
2153
    #if WOLFSSL_TICKET_KEY_LIFETIME <= SESSION_TICKET_HINT_DEFAULT
2154
        #error "Ticket Key lifetime must be longer than ticket life hint."
2155
    #endif
2156
#endif
2157
2158
0
#define MAX_ENCRYPT_SZ ENCRYPT_LEN
2159
2160
#define WOLFSSL_ASSERT_EQ(x, y) wc_static_assert((x) == (y))
2161
#define WOLFSSL_ASSERT_GE(x, y) wc_static_assert((x) >= (y))
2162
2163
0
#define WOLFSSL_ASSERT_SIZEOF_GE(x, y) wc_static_assert(sizeof(x) >= sizeof(y))
2164
#define WOLFSSL_ASSERT_SIZEOF_EQ(x, y) wc_static_assert(sizeof(x) == sizeof(y))
2165
2166
/* states. Adding state before HANDSHAKE_DONE will break session importing */
2167
enum states {
2168
    NULL_STATE = 0,
2169
2170
    SERVER_HELLOVERIFYREQUEST_COMPLETE,
2171
    SERVER_HELLO_RETRY_REQUEST_COMPLETE,
2172
    SERVER_HELLO_COMPLETE,
2173
    SERVER_ENCRYPTED_EXTENSIONS_COMPLETE,
2174
    SERVER_CERT_COMPLETE,
2175
    SERVER_CERT_VERIFY_COMPLETE,
2176
    SERVER_KEYEXCHANGE_COMPLETE,
2177
    SERVER_HELLODONE_COMPLETE,
2178
    SERVER_CHANGECIPHERSPEC_COMPLETE,
2179
    SERVER_FINISHED_COMPLETE,
2180
2181
    CLIENT_HELLO_RETRY,
2182
    CLIENT_HELLO_COMPLETE,
2183
    CLIENT_KEYEXCHANGE_COMPLETE,
2184
    CLIENT_CHANGECIPHERSPEC_COMPLETE,
2185
    CLIENT_FINISHED_COMPLETE,
2186
2187
    HANDSHAKE_DONE,
2188
2189
#ifdef WOLFSSL_DTLS13
2190
    SERVER_FINISHED_ACKED,
2191
#endif /* WOLFSSL_DTLS13 */
2192
    WOLF_ENUM_DUMMY_LAST_ELEMENT(states)
2193
};
2194
2195
/* SSL Version */
2196
typedef struct ProtocolVersion {
2197
    byte major;
2198
    byte minor;
2199
} WOLFSSL_PACK ProtocolVersion;
2200
2201
2202
WOLFSSL_LOCAL ProtocolVersion MakeSSLv3(void);
2203
WOLFSSL_LOCAL ProtocolVersion MakeTLSv1(void);
2204
WOLFSSL_LOCAL ProtocolVersion MakeTLSv1_1(void);
2205
WOLFSSL_LOCAL ProtocolVersion MakeTLSv1_2(void);
2206
WOLFSSL_LOCAL ProtocolVersion MakeTLSv1_3(void);
2207
2208
#ifdef WOLFSSL_DTLS
2209
    WOLFSSL_LOCAL ProtocolVersion MakeDTLSv1(void);
2210
    WOLFSSL_LOCAL ProtocolVersion MakeDTLSv1_2(void);
2211
2212
#ifdef WOLFSSL_DTLS13
2213
    WOLFSSL_LOCAL ProtocolVersion MakeDTLSv1_3(void);
2214
#endif /* WOLFSSL_DTLS13 */
2215
2216
#endif
2217
#ifdef WOLFSSL_SESSION_EXPORT
2218
WOLFSSL_LOCAL int wolfSSL_session_export_internal(WOLFSSL* ssl, byte* buf,
2219
        word32* sz, int type);
2220
WOLFSSL_LOCAL int wolfSSL_session_import_internal(WOLFSSL* ssl, const byte* buf,
2221
        word32 sz, int type);
2222
#ifdef WOLFSSL_DTLS
2223
    WOLFSSL_LOCAL int wolfSSL_dtls_export_state_internal(WOLFSSL* ssl,
2224
                                                          byte* buf, word32 sz);
2225
    WOLFSSL_LOCAL int wolfSSL_dtls_import_state_internal(WOLFSSL* ssl,
2226
                                                    const byte* buf, word32 sz);
2227
    WOLFSSL_LOCAL int wolfSSL_send_session(WOLFSSL* ssl);
2228
#endif
2229
#endif
2230
2231
struct WOLFSSL_BY_DIR_HASH {
2232
    unsigned long hash_value;
2233
    int last_suffix;
2234
};
2235
2236
struct WOLFSSL_BY_DIR_entry {
2237
    char*   dir_name;
2238
    int     dir_type;
2239
    WOLF_STACK_OF(WOLFSSL_BY_DIR_HASH) *hashes;
2240
};
2241
2242
struct WOLFSSL_BY_DIR {
2243
    WOLF_STACK_OF(WOLFSSL_BY_DIR_entry) *dir_entry;
2244
    wolfSSL_Mutex    lock; /* dir list lock */
2245
};
2246
2247
/* wolfSSL method type */
2248
struct WOLFSSL_METHOD {
2249
    ProtocolVersion version;
2250
    byte            side;         /* connection side, server or client */
2251
    byte            downgrade;    /* whether to downgrade version, default no */
2252
};
2253
2254
/* wolfSSL buffer type - internal uses "buffer" type */
2255
typedef WOLFSSL_BUFFER_INFO buffer;
2256
2257
typedef struct Suites Suites;
2258
2259
/* Declare opaque struct for API to use */
2260
#ifndef WOLFSSL_CLIENT_SESSION_DEFINED
2261
    typedef struct ClientSession ClientSession;
2262
    #define WOLFSSL_CLIENT_SESSION_DEFINED
2263
#endif
2264
2265
/* defaults to client */
2266
WOLFSSL_LOCAL void InitSSL_Method(WOLFSSL_METHOD* method, ProtocolVersion pv);
2267
2268
WOLFSSL_LOCAL void InitSSL_CTX_Suites(WOLFSSL_CTX* ctx);
2269
WOLFSSL_LOCAL int InitSSL_Suites(WOLFSSL* ssl);
2270
WOLFSSL_LOCAL int InitSSL_Side(WOLFSSL* ssl, word16 side);
2271
2272
2273
#if defined(HAVE_CURVE25519) && !defined(WOLFSSL_X25519_NO_MASK_PEER)
2274
WOLFSSL_LOCAL const byte* MaskCurve25519PeerKey(const byte* pub, word32 pubSz,
2275
                                               byte maskBuf[CURVE25519_KEYSIZE]);
2276
#endif
2277
2278
WOLFSSL_LOCAL int DoHandShakeMsgType(WOLFSSL* ssl, byte* input,
2279
        word32* inOutIdx, byte type, word32 size, word32 totalSz);
2280
/* for sniffer */
2281
WOLFSSL_LOCAL int DoFinished(WOLFSSL* ssl, const byte* input, word32* inOutIdx,
2282
                            word32 size, word32 totalSz, int sniff);
2283
#ifdef WOLFSSL_TLS13
2284
WOLFSSL_LOCAL int DoTls13Finished(WOLFSSL* ssl, const byte* input, word32* inOutIdx,
2285
                           word32 size, word32 totalSz, int sniff);
2286
#endif
2287
#ifdef WOLFSSL_API_PREFIX_MAP
2288
    #define DoApplicationData wolfSSL_DoApplicationData
2289
#endif
2290
WOLFSSL_TEST_VIS int DoApplicationData(WOLFSSL* ssl, byte* input, word32* inOutIdx,
2291
                                    int sniff);
2292
/* TLS v1.3 needs these */
2293
WOLFSSL_LOCAL int  HandleTlsResumption(WOLFSSL* ssl, Suites* clSuites);
2294
#ifdef WOLFSSL_TLS13
2295
WOLFSSL_LOCAL byte SuiteMac(const byte* suite);
2296
#endif
2297
WOLFSSL_LOCAL int  DoClientHello(WOLFSSL* ssl, const byte* input, word32* inOutIdx,
2298
                             word32 helloSz);
2299
#ifdef WOLFSSL_TLS13
2300
WOLFSSL_LOCAL int DoTls13ClientHello(WOLFSSL* ssl, const byte* input,
2301
                                     word32* inOutIdx, word32 helloSz);
2302
#endif
2303
WOLFSSL_LOCAL int  DoServerHello(WOLFSSL* ssl, const byte* input, word32* inOutIdx,
2304
                      word32 helloSz);
2305
WOLFSSL_LOCAL int  CompleteServerHello(WOLFSSL *ssl);
2306
WOLFSSL_LOCAL int  CheckVersion(WOLFSSL *ssl, ProtocolVersion pv);
2307
WOLFSSL_LOCAL int  PickHashSigAlgo(WOLFSSL* ssl, const byte* hashSigAlgo,
2308
                                   word32 hashSigAlgoSz, int matchSuites);
2309
#if defined(WOLF_PRIVATE_KEY_ID) && !defined(NO_CHECK_PRIVATE_KEY)
2310
/* slhParam is the enum SlhDsaParam for DYNAMIC_TYPE_SLHDSA, whose parameter
2311
 * set cannot be derived from a device-side identifier. Pass -1 otherwise. */
2312
WOLFSSL_LOCAL int  CreateDevPrivateKey(void** pkey, byte* data, word32 length,
2313
                                       int hsType, int label, int id,
2314
                                       void* heap, int devId, int slhParam);
2315
#endif
2316
#ifdef WOLFSSL_BLIND_PRIVATE_KEY
2317
WOLFSSL_LOCAL int wolfssl_priv_der_blind(WC_RNG* rng, DerBuffer* key,
2318
    DerBuffer** mask);
2319
WOLFSSL_LOCAL void wolfssl_priv_der_blind_toggle(DerBuffer* key,
2320
    const DerBuffer* mask);
2321
WOLFSSL_LOCAL WARN_UNUSED_RESULT DerBuffer *wolfssl_priv_der_unblind(
2322
    const DerBuffer* key, const DerBuffer* mask);
2323
WOLFSSL_LOCAL void wolfssl_priv_der_unblind_free(DerBuffer* key);
2324
#endif
2325
WOLFSSL_LOCAL int  DecodePrivateKey(WOLFSSL *ssl, word32* sigLen);
2326
#ifdef WOLFSSL_DUAL_ALG_CERTS
2327
WOLFSSL_LOCAL int  DecodeAltPrivateKey(WOLFSSL *ssl, word32* sigLen);
2328
#endif
2329
#if defined(WOLF_PRIVATE_KEY_ID) || defined(HAVE_PK_CALLBACKS)
2330
WOLFSSL_LOCAL int GetPrivateKeySigSize(WOLFSSL* ssl);
2331
#ifndef NO_ASN
2332
    WOLFSSL_LOCAL int  InitSigPkCb(WOLFSSL* ssl, SignatureCtx* sigCtx);
2333
#endif
2334
#endif
2335
WOLFSSL_LOCAL int CreateSigData(WOLFSSL* ssl, byte* sigData, word16* sigDataSz,
2336
                                int check);
2337
WOLFSSL_LOCAL int CreateRSAEncodedSig(byte* sig, byte* sigData, int sigDataSz,
2338
                                      int sigAlgo, int hashAlgo);
2339
#ifdef WOLFSSL_ASYNC_IO
2340
WOLFSSL_LOCAL void FreeAsyncCtx(WOLFSSL* ssl, byte freeAsync);
2341
#endif
2342
WOLFSSL_LOCAL void FreeKeyExchange(WOLFSSL* ssl);
2343
WOLFSSL_LOCAL void FreeSuites(WOLFSSL* ssl);
2344
WOLFSSL_LOCAL int  ProcessPeerCerts(WOLFSSL* ssl, byte* input, word32* inOutIdx, word32 totalSz);
2345
#ifdef WOLFSSL_API_PREFIX_MAP
2346
    #define MatchDomainName wolfSSL_MatchDomainName
2347
#endif
2348
WOLFSSL_TEST_VIS int  MatchDomainName(const char* pattern, int len,
2349
                                      const char* str, word32 strLen,
2350
                                      unsigned int flags);
2351
#if !defined(NO_CERTS) && !defined(NO_ASN)
2352
WOLFSSL_LOCAL int  CheckForAltNames(DecodedCert* dCert, const char* domain,
2353
                                    word32 domainLen, int* checkCN,
2354
                                    unsigned int flags, byte isIP);
2355
WOLFSSL_LOCAL int  CheckIPAddr(DecodedCert* dCert, const char* ipasc,
2356
                               size_t ipascLen);
2357
WOLFSSL_LOCAL void CopyDecodedName(WOLFSSL_X509_NAME* name, DecodedCert* dCert, int nameType);
2358
#endif
2359
WOLFSSL_LOCAL int  SetupTicket(WOLFSSL* ssl);
2360
WOLFSSL_LOCAL int  CreateTicket(WOLFSSL* ssl);
2361
WOLFSSL_LOCAL int  DefTicketHintTooLarge(WOLFSSL* ssl);
2362
WOLFSSL_LOCAL int  HashRaw(WOLFSSL* ssl, const byte* data, int sz);
2363
WOLFSSL_LOCAL int  HashOutput(WOLFSSL* ssl, const byte* output, int sz,
2364
                              int ivSz);
2365
WOLFSSL_LOCAL int  HashInput(WOLFSSL* ssl, const byte* input, int sz);
2366
2367
#ifdef HAVE_SNI
2368
#ifndef NO_WOLFSSL_SERVER
2369
WOLFSSL_LOCAL int SNI_Callback(WOLFSSL* ssl);
2370
#endif
2371
#endif
2372
2373
#ifdef HAVE_ALPN
2374
WOLFSSL_LOCAL int ALPN_Select(WOLFSSL* ssl);
2375
#endif
2376
2377
WOLFSSL_LOCAL int ChachaAEADEncrypt(WOLFSSL* ssl, byte* out, const byte* input,
2378
                              word16 sz, byte type); /* needed by sniffer */
2379
WOLFSSL_LOCAL int ChachaAEADDecrypt(WOLFSSL* ssl, byte* plain, const byte* input,
2380
                              word16 sz); /* needed by sniffer */
2381
2382
#ifdef WOLFSSL_TLS13
2383
WOLFSSL_LOCAL int  DecryptTls13(WOLFSSL* ssl, byte* output, const byte* input,
2384
                                word16 sz, const byte* aad, word16 aadSz);
2385
WOLFSSL_LOCAL int  DoTls13MsgDerives(WOLFSSL* ssl, byte type);
2386
/* A crypto/PK callback pending is finished by re-invoking the provider:
2387
 * wolfSSL_AsyncPoll() never runs a callback. Exported so tests compile in
2388
 * only where a callback pend is resumable. */
2389
#if defined(WOLFSSL_ASYNC_CRYPT) && \
2390
    (defined(WOLF_CRYPTO_CB) || defined(HAVE_PK_CALLBACKS)) && \
2391
    !defined(WOLFSSL_ASYNC_CRYPT_SW) && !defined(HAVE_INTEL_QA) && \
2392
    !defined(HAVE_CAVIUM)
2393
    #define WOLFSSL_ASYNC_REINVOKE
2394
#endif
2395
#if defined(WOLFSSL_ASYNC_REINVOKE) && !defined(NO_HMAC)
2396
WOLFSSL_LOCAL void Tls13FreeHsHmac(WOLFSSL* ssl);
2397
#endif
2398
WOLFSSL_LOCAL int  DoTls13HandShakeMsgType(WOLFSSL* ssl, byte* input,
2399
                                           word32* inOutIdx, byte type,
2400
                                           word32 size, word32 totalSz);
2401
WOLFSSL_LOCAL int  DoTls13HandShakeMsg(WOLFSSL* ssl, byte* input,
2402
                                       word32* inOutIdx, word32 totalSz);
2403
WOLFSSL_LOCAL int DoTls13ServerHello(WOLFSSL* ssl, const byte* input,
2404
                                     word32* inOutIdx, word32 helloSz,
2405
                                     byte* extMsgType);
2406
WOLFSSL_LOCAL int RestartHandshakeHash(WOLFSSL* ssl);
2407
2408
WOLFSSL_LOCAL int Tls13DeriveKey(WOLFSSL *ssl, byte *output, int outputLen,
2409
    const byte *secret, const byte *label, word32 labelLen, int hashAlgo,
2410
    int includeMsgs, int side);
2411
#endif
2412
int TimingPadVerify(WOLFSSL* ssl, const byte* input, int padLen, int macSz,
2413
                    int pLen, int content);
2414
2415
2416
enum {
2417
    FORCED_FREE = 1,
2418
    NO_FORCED_FREE = 0
2419
};
2420
2421
2422
/* only use compression extra if using compression */
2423
#ifdef HAVE_LIBZ
2424
    #define COMP_EXTRA MAX_COMP_EXTRA
2425
#else
2426
0
    #define COMP_EXTRA 0
2427
#endif
2428
2429
/* only the sniffer needs space in the buffer for extra MTU record(s) */
2430
#ifdef WOLFSSL_SNIFFER
2431
    #define MTU_EXTRA MAX_MTU * 3
2432
#else
2433
    #define MTU_EXTRA 0
2434
#endif
2435
2436
2437
/* embedded callbacks require large static buffers, make sure on */
2438
#ifdef WOLFSSL_CALLBACKS
2439
    #undef  LARGE_STATIC_BUFFERS
2440
    #define LARGE_STATIC_BUFFERS
2441
#endif
2442
2443
2444
/* determine maximum record size */
2445
0
#define MAX_RECORD_SIZE 16384  /* 2^14, max size by standard */
2446
2447
#ifdef RECORD_SIZE
2448
    /* user supplied value */
2449
    #if RECORD_SIZE < 128 || RECORD_SIZE > MAX_RECORD_SIZE
2450
        #error Invalid record size
2451
    #endif
2452
#else
2453
    /* give user option to use 16K static buffers */
2454
    #if defined(LARGE_STATIC_BUFFERS)
2455
        #define RECORD_SIZE     MAX_RECORD_SIZE
2456
    #else
2457
        #ifdef WOLFSSL_DTLS
2458
            #define RECORD_SIZE MAX_MTU
2459
        #else
2460
            #define RECORD_SIZE 128
2461
        #endif
2462
    #endif
2463
#endif
2464
2465
2466
/* user option to turn off 16K output option */
2467
/* if using small static buffers (default) and SSL_write tries to write data
2468
   larger than the record we have, dynamically get it, unless user says only
2469
   write in static buffer chunks  */
2470
#ifndef STATIC_CHUNKS_ONLY
2471
0
    #define OUTPUT_RECORD_SIZE MAX_RECORD_SIZE
2472
#else
2473
    #define OUTPUT_RECORD_SIZE RECORD_SIZE
2474
#endif
2475
2476
/* wolfSSL input buffer
2477
2478
   RFC 2246:
2479
2480
   length
2481
       The length (in bytes) of the following TLSPlaintext.fragment.
2482
       The length should not exceed 2^14.
2483
*/
2484
#ifdef STATIC_BUFFER_LEN
2485
    /* user supplied option */
2486
#elif defined(LARGE_STATIC_BUFFERS)
2487
    #define STATIC_BUFFER_LEN (RECORD_HEADER_SZ + RECORD_SIZE + COMP_EXTRA + \
2488
             MTU_EXTRA + MAX_MSG_EXTRA)
2489
#else
2490
    /* don't fragment memory from the record header */
2491
553k
    #define STATIC_BUFFER_LEN RECORD_HEADER_SZ
2492
#endif
2493
2494
/* RECORD_HEADER_SZ is an enum constant, so the preprocessor can't check
2495
 * this bound. */
2496
wc_static_assert(STATIC_BUFFER_LEN >= RECORD_HEADER_SZ);
2497
2498
/* Default read-ahead window: when read-ahead is enabled the record header read
2499
 * requests up to a full record's worth of data in a single recv() so the body
2500
 * (and possibly following records) can be pulled in without a second syscall.
2501
 * Sized to one maximum TLS record (MAX_RECORD_SIZE, not the buffer-sizing
2502
 * RECORD_SIZE which may be small) so the whole record is captured. Defined
2503
 * unconditionally so the setters and CTX init can reference it as the default
2504
 * window even when read-ahead I/O is not built. */
2505
#ifndef WOLFSSL_READ_AHEAD_SZ
2506
#define WOLFSSL_READ_AHEAD_SZ (RECORD_HEADER_SZ + MAX_RECORD_SIZE + \
2507
         COMP_EXTRA + MTU_EXTRA + MAX_MSG_EXTRA)
2508
#endif
2509
2510
/* Upper bound for a caller-configured read-ahead window
2511
 * (wolfSSL_CTX/SSL_set_default_read_buffer_len()). The window feeds signed int
2512
 * arithmetic in GetInputData_ex(); bounding it well below INT_MAX ensures a
2513
 * large caller-supplied size can never overflow that arithmetic to a negative
2514
 * value (which would skip GrowInputBuffer() and drive an oversized recv()).
2515
 * 16 MB is far above any realistic coalescing window. Defined unconditionally
2516
 * so the setters can clamp even when read-ahead I/O is not built. */
2517
#ifndef WOLFSSL_MAX_READ_AHEAD_SZ
2518
#define WOLFSSL_MAX_READ_AHEAD_SZ (16 * 1024 * 1024)
2519
#endif
2520
2521
typedef struct {
2522
    ALIGN16 byte staticBuffer[STATIC_BUFFER_LEN];
2523
    byte*  buffer;       /* place holder for static or dynamic buffer */
2524
    word32 length;       /* total buffer length used */
2525
    word32 idx;          /* idx to part of length already consumed */
2526
    word32 bufferSize;   /* current buffer size */
2527
    byte   dynamicFlag;  /* dynamic memory currently in use */
2528
    byte   offset;       /* alignment offset attempt */
2529
} bufferStatic;
2530
2531
/* Cipher Suites holder */
2532
struct Suites {
2533
    word16 suiteSz;                 /* suite length in bytes        */
2534
    word16 hashSigAlgoSz;           /* SigAlgo extension length in bytes */
2535
    byte   suites[WOLFSSL_MAX_SUITE_SZ];
2536
    byte   hashSigAlgo[WOLFSSL_MAX_SIGALGO]; /* sig/algo to offer */
2537
    byte   setSuites:1;             /* user set suites from default */
2538
};
2539
2540
typedef struct CipherSuite {
2541
    byte   cipherSuite0;
2542
    byte   cipherSuite;
2543
    word32 ecdhCurveOID;
2544
    struct KeyShareEntry* clientKSE;
2545
#if defined(WOLFSSL_TLS13) && defined(HAVE_SUPPORTED_CURVES)
2546
    int    doHelloRetry;
2547
#endif
2548
} CipherSuite;
2549
2550
#ifdef WOLFSSL_API_PREFIX_MAP
2551
    #define InitSuitesHashSigAlgo wolfSSL_InitSuitesHashSigAlgo
2552
#endif
2553
WOLFSSL_TEST_VIS void InitSuitesHashSigAlgo(byte* hashSigAlgo, int have,
2554
                                       int tls1_2, int tls1_3, int keySz,
2555
                                       word16* len);
2556
WOLFSSL_LOCAL int AllocateCtxSuites(WOLFSSL_CTX* ctx);
2557
WOLFSSL_LOCAL int InitCtxSuitesWithMutex(WOLFSSL_CTX* ctx);
2558
WOLFSSL_LOCAL int AllocateSuites(WOLFSSL* ssl);
2559
WOLFSSL_LOCAL void InitSuites(Suites* suites, ProtocolVersion pv, int keySz,
2560
                              word16 haveRSA, word16 havePSK, word16 haveDH,
2561
                              word16 haveECDSAsig, word16 haveECC,
2562
                              word16 haveStaticRSA, word16 haveStaticECC,
2563
                              word16 haveAnon, word16 haveNull,
2564
                              word16 haveAES128, word16 haveSHA1,
2565
                              word16 haveRC4, int side);
2566
2567
void refineSuites(const Suites* sslSuites, const Suites* peerSuites,
2568
        Suites* outSuites, byte useClientOrder);
2569
void sslRefineSuites(WOLFSSL* ssl, Suites* peerSuites);
2570
2571
typedef struct TLSX TLSX;
2572
WOLFSSL_LOCAL int MatchSuite_ex(const WOLFSSL* ssl, Suites* peerSuites,
2573
                                CipherSuite* cs, TLSX* extensions);
2574
WOLFSSL_LOCAL int  MatchSuite(WOLFSSL* ssl, Suites* peerSuites);
2575
WOLFSSL_LOCAL int  SetCipherList_ex(const WOLFSSL_CTX* ctx, const WOLFSSL* ssl,
2576
        Suites* suites, const char* list);
2577
WOLFSSL_LOCAL int  SetCipherList(const WOLFSSL_CTX* ctx, Suites* suites,
2578
                                 const char* list);
2579
WOLFSSL_LOCAL int  SetCipherListFromBytes(WOLFSSL_CTX* ctx, Suites* suites,
2580
                                          const byte* list, const int listSz);
2581
WOLFSSL_LOCAL int  SetSuitesHashSigAlgo(Suites* suites, const char* list);
2582
2583
#ifndef PSK_TYPES_DEFINED
2584
    typedef unsigned int (*wc_psk_client_callback)(WOLFSSL*, const char*, char*,
2585
                          unsigned int, unsigned char*, unsigned int);
2586
    typedef unsigned int (*wc_psk_server_callback)(WOLFSSL*, const char*,
2587
                          unsigned char*, unsigned int);
2588
#ifdef WOLFSSL_TLS13
2589
    typedef unsigned int (*wc_psk_client_cs_callback)(WOLFSSL*, const char*,
2590
                          char*, unsigned int, unsigned char*, unsigned int,
2591
                          const char* cipherName);
2592
    typedef unsigned int (*wc_psk_client_tls13_callback)(WOLFSSL*, const char*,
2593
                          char*, unsigned int, unsigned char*, unsigned int,
2594
                          const char** cipherName);
2595
    typedef unsigned int (*wc_psk_server_tls13_callback)(WOLFSSL*, const char*,
2596
                          unsigned char*, unsigned int,
2597
                          const char** cipherName);
2598
#endif
2599
#endif /* PSK_TYPES_DEFINED */
2600
#if defined(WOLFSSL_DTLS) && defined(WOLFSSL_SESSION_EXPORT) && \
2601
   !defined(WOLFSSL_DTLS_EXPORT_TYPES)
2602
    typedef int (*wc_dtls_export)(WOLFSSL* ssl,
2603
2604
#define WOLFSSL_DTLS_EXPORT_TYPES
2605
#endif /* WOLFSSL_DTLS_EXPORT_TYPES */
2606
2607
2608
#if defined(OPENSSL_ALL) || defined(WOLFSSL_QT)
2609
#define MAX_DESCRIPTION_SZ 255
2610
#endif
2611
struct WOLFSSL_CIPHER {
2612
    byte cipherSuite0;
2613
    byte cipherSuite;
2614
    const WOLFSSL* ssl;
2615
#if defined(OPENSSL_ALL) || defined(WOLFSSL_QT)
2616
    char description[MAX_DESCRIPTION_SZ];
2617
    unsigned long offset;
2618
    unsigned int in_stack; /* TRUE if added to stack in wolfSSL_get_ciphers_compat */
2619
    int bits;
2620
#endif
2621
};
2622
2623
2624
#ifdef NO_ASN
2625
    /* no_asn won't have */
2626
    typedef struct CertStatus CertStatus;
2627
#endif
2628
2629
#ifndef HAVE_OCSP
2630
    typedef struct WOLFSSL_OCSP WOLFSSL_OCSP;
2631
#endif
2632
2633
/* wolfSSL OCSP controller */
2634
#ifdef HAVE_OCSP
2635
struct WOLFSSL_OCSP {
2636
    WOLFSSL_CERT_MANAGER* cm;            /* pointer back to cert manager */
2637
    OcspEntry*            ocspList;      /* OCSP response list */
2638
    wolfSSL_Mutex         ocspLock;      /* OCSP list lock */
2639
    int                   error;
2640
    int(*statusCb)(WOLFSSL*, void*);
2641
    void*                 statusCbArg;
2642
};
2643
#endif
2644
2645
typedef struct CRL_Entry CRL_Entry;
2646
2647
#if defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3)
2648
    #define CRL_DIGEST_SIZE WC_SM3_DIGEST_SIZE
2649
#elif defined(NO_SHA)
2650
    #define CRL_DIGEST_SIZE WC_SHA256_DIGEST_SIZE
2651
#else
2652
    #define CRL_DIGEST_SIZE WC_SHA_DIGEST_SIZE
2653
#endif
2654
2655
#ifdef NO_ASN
2656
    typedef struct RevokedCert RevokedCert;
2657
#endif
2658
#ifdef CRL_STATIC_REVOKED_LIST
2659
    #ifndef CRL_MAX_REVOKED_CERTS
2660
        #define CRL_MAX_REVOKED_CERTS 4
2661
    #elif CRL_MAX_REVOKED_CERTS > 22000
2662
        #error CRL_MAX_REVOKED_CERTS too big, max is 22000
2663
    #endif
2664
#endif
2665
2666
#ifdef HAVE_CRL
2667
/* Complete CRL */
2668
struct CRL_Entry {
2669
    byte*   toBeSigned;
2670
    byte*   signature;
2671
#ifdef WC_RSA_PSS
2672
    byte*   sigParams;   /* buffer with signature parameters */
2673
#endif
2674
#if defined(OPENSSL_EXTRA)
2675
    WOLFSSL_X509_NAME*    issuer;     /* X509_NAME type issuer */
2676
#endif
2677
    CRL_Entry* next;                      /* next entry */
2678
#ifdef CRL_STATIC_REVOKED_LIST
2679
    RevokedCert certs[CRL_MAX_REVOKED_CERTS];
2680
#else
2681
    RevokedCert* certs;             /* revoked cert list  */
2682
#endif
2683
    wolfSSL_Mutex verifyMutex;
2684
    /* DupCRL_Entry bulk copies the data after the `verifyMutex` member, so
2685
     * only self-contained value data belongs below it. Anything holding a
2686
     * pointer goes above, where DupCRL_Entry copies it explicitly. Using the
2687
     * mutex as the marker because clang-tidy doesn't like taking the sizeof a
2688
     * pointer. */
2689
    char    crlNumber[CRL_MAX_NUM_HEX_STR_SZ];    /* CRL number extension */
2690
    byte    issuerHash[CRL_DIGEST_SIZE];  /* issuer hash                 */
2691
    /* byte    crlHash[CRL_DIGEST_SIZE];      raw crl data hash           */
2692
    /* restore the hash here if needed for optimized comparisons */
2693
    byte    lastDate[MAX_DATE_SIZE]; /* last date updated  */
2694
    byte    nextDate[MAX_DATE_SIZE]; /* next update date   */
2695
    byte    lastDateFormat;          /* last date format */
2696
    byte    nextDateFormat;          /* next date format */
2697
#if defined(OPENSSL_EXTRA)
2698
    WOLFSSL_ASN1_TIME lastDateAsn1;  /* last date updated  */
2699
    WOLFSSL_ASN1_TIME nextDateAsn1;  /* next update date   */
2700
#endif
2701
    int     totalCerts;             /* number on list     */
2702
    int     version;                /* version of certificate */
2703
    int     verified;
2704
    word32  tbsSz;
2705
    word32  signatureSz;
2706
#ifdef WC_RSA_PSS
2707
    word32  sigParamsSz; /* length of signature parameters   */
2708
#endif
2709
    word32  signatureOID;
2710
#if !defined(NO_SKID) && !defined(NO_ASN)
2711
    byte    extAuthKeyId[KEYID_SIZE];
2712
    byte    extAuthKeyIdSet:1;  /* Auth key identifier set indicator */
2713
#endif
2714
    byte    crlNumberSet:1;     /* CRL number set indicator */
2715
};
2716
2717
2718
#ifdef HAVE_CRL_MONITOR
2719
typedef struct CRL_Monitor CRL_Monitor;
2720
2721
/* CRL directory monitor */
2722
struct CRL_Monitor {
2723
    char* path;      /* full dir path, if valid pointer we're using */
2724
    int   type;      /* PEM or ASN1 type */
2725
};
2726
2727
2728
#if defined(HAVE_CRL) && defined(NO_FILESYSTEM)
2729
    #undef HAVE_CRL_MONITOR
2730
#endif
2731
2732
/* PEM and DER possible */
2733
#define WOLFSSL_CRL_MONITORS_LEN (2)
2734
2735
#if defined(__MACH__) || defined(__FreeBSD__) || defined(__linux__)
2736
typedef int    wolfSSL_CRL_mfd_t; /* monitor fd, -1 if no init yet */
2737
/* mfd for bsd is kqueue fd, eventfd for linux */
2738
#define WOLFSSL_CRL_MFD_INIT_VAL (-1)
2739
#elif defined(_MSC_VER)
2740
typedef HANDLE wolfSSL_CRL_mfd_t; /* monitor fd, INVALID_HANDLE_VALUE if
2741
                                   * no init yet */
2742
#define WOLFSSL_CRL_MFD_INIT_VAL (INVALID_HANDLE_VALUE)
2743
#endif
2744
#endif
2745
2746
/* wolfSSL CRL controller */
2747
struct WOLFSSL_CRL {
2748
    WOLFSSL_CERT_MANAGER* cm;            /* pointer back to cert manager */
2749
    CRL_Entry*            crlList;       /* our CRL list */
2750
#ifdef HAVE_CRL_IO
2751
    CbCrlIO               crlIOCb;
2752
#endif
2753
    wolfSSL_RwLock        crlLock;       /* CRL list lock */
2754
#ifdef HAVE_CRL_MONITOR
2755
    CRL_Monitor           monitors[WOLFSSL_CRL_MONITORS_LEN];
2756
    COND_TYPE             cond;          /* condition to signal setup */
2757
    THREAD_TYPE           tid;           /* monitoring thread */
2758
    wolfSSL_CRL_mfd_t     mfd;
2759
    int                   setup;         /* thread is setup predicate */
2760
#endif
2761
#ifdef OPENSSL_ALL
2762
    wolfSSL_Ref           ref;
2763
#endif
2764
#if defined(OPENSSL_EXTRA)
2765
    WOLFSSL_STACK*        revokedStack;  /* cached STACK_OF(X509_REVOKED) */
2766
#endif
2767
    void*                 heap;          /* heap hint for dynamic memory */
2768
};
2769
#endif
2770
2771
2772
#ifdef NO_ASN
2773
    typedef struct Signer Signer;
2774
#ifdef WOLFSSL_TRUST_PEER_CERT
2775
    typedef struct TrustedPeerCert TrustedPeerCert;
2776
#endif
2777
#endif
2778
2779
2780
#ifndef CA_TABLE_SIZE
2781
69.8k
    #define CA_TABLE_SIZE 11
2782
#endif
2783
#ifdef WOLFSSL_TRUST_PEER_CERT
2784
    #define TP_TABLE_SIZE 11
2785
#endif
2786
2787
/* wolfSSL Certificate Manager */
2788
struct WOLFSSL_CERT_MANAGER {
2789
    Signer*         caTable[CA_TABLE_SIZE]; /* the CA signer table */
2790
    void*           heap;                /* heap helper */
2791
#ifdef WOLFSSL_TRUST_PEER_CERT
2792
    TrustedPeerCert* tpTable[TP_TABLE_SIZE]; /* table of trusted peer certs */
2793
    wolfSSL_Mutex   tpLock;                  /* trusted peer list lock */
2794
#endif
2795
    WOLFSSL_CRL*    crl;                 /* CRL checker */
2796
    WOLFSSL_OCSP*   ocsp;                /* OCSP checker */
2797
#if !defined(NO_WOLFSSL_SERVER) && (defined(HAVE_CERTIFICATE_STATUS_REQUEST) \
2798
                               ||  defined(HAVE_CERTIFICATE_STATUS_REQUEST_V2))
2799
    WOLFSSL_OCSP*   ocsp_stapling;       /* OCSP checker for OCSP stapling */
2800
#endif
2801
    char*           ocspOverrideURL;     /* use this responder */
2802
    void*           ocspIOCtx;           /* I/O callback CTX */
2803
#ifndef NO_WOLFSSL_CM_VERIFY
2804
    VerifyCallback  verifyCallback;      /* Verify callback */
2805
#endif
2806
    CallbackCACache caCacheCallback;       /* CA cache addition callback */
2807
    CbMissingCRL    cbMissingCRL;          /* notify thru cb of missing crl */
2808
    crlErrorCb      crlCb;                 /* Allow user to override error */
2809
    void*           crlCbCtx;
2810
    CbOCSPIO        ocspIOCb;              /* I/O callback for OCSP lookup */
2811
    CbOCSPRespFree  ocspRespFreeCb;        /* Frees OCSP Response from IO Cb */
2812
    wolfSSL_Mutex   caLock;                /* CA list lock */
2813
    byte            crlEnabled:1;          /* is CRL on ? */
2814
    byte            crlCheckAll:1;         /* always leaf, but all ? */
2815
    byte            ocspEnabled:1;         /* is OCSP on ? */
2816
    byte            ocspCheckAll:1;        /* always leaf, but all ? */
2817
    byte            ocspFailIfNotSupported:1; /* refuse a cert that advertises
2818
                                              * no OCSP responder ? */
2819
    byte            ocspSendNonce:1;       /* send the OCSP nonce ? */
2820
    byte            ocspUseOverrideURL:1;  /* ignore cert responder, override */
2821
    byte            ocspStaplingEnabled:1; /* is OCSP Stapling on ? */
2822
#if defined(HAVE_CERTIFICATE_STATUS_REQUEST) \
2823
||  defined(HAVE_CERTIFICATE_STATUS_REQUEST_V2)
2824
    byte            ocspMustStaple:1;      /* server must respond with staple */
2825
#endif
2826
    /* Tracks which resources were successfully initialized so that
2827
     * DoCertManagerFree can dispose of them safely even when construction
2828
     * fails partway through. */
2829
    WC_BITFIELD     caLockInit:1;          /* caLock has been initialized */
2830
#ifdef WOLFSSL_TRUST_PEER_CERT
2831
    WC_BITFIELD     tpLockInit:1;          /* tpLock has been initialized */
2832
#endif
2833
    WC_BITFIELD     refInit:1;             /* ref has been initialized */
2834
2835
#ifndef NO_RSA
2836
    short           minRsaKeySz;         /* minimum allowed RSA key size */
2837
#endif
2838
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || defined(HAVE_ED448)
2839
    short           minEccKeySz;         /* minimum allowed ECC key size */
2840
#endif
2841
#if defined(OPENSSL_EXTRA) || defined(WOLFSSL_WPAS_SMALL)
2842
    WOLFSSL_X509_STORE  *x509_store_p;  /* a pointer back to CTX x509 store  */
2843
                                        /* CTX has ownership and free this   */
2844
                                        /* with CTX free.                    */
2845
#endif
2846
    wolfSSL_Ref     ref;
2847
#ifdef HAVE_FALCON
2848
    short           minFalconKeySz;     /* minimum allowed Falcon key size */
2849
#endif
2850
#ifdef WOLFSSL_HAVE_MLDSA
2851
    short           minMlDsaKeySz;      /* minimum allowed ML-DSA key size */
2852
#endif
2853
#ifdef WC_ASN_UNKNOWN_EXT_CB
2854
    wc_UnknownExtCallback unknownExtCallback;
2855
#if defined(HAVE_CRL)
2856
    wc_UnknownExtCallback   crlUnknownExtCallback;
2857
    wc_UnknownExtCallbackEx crlUnknownExtCallbackEx;
2858
    void*                   crlUnknownExtCallbackExCtx;
2859
#endif
2860
#endif
2861
#ifdef HAVE_CRL_UPDATE_CB
2862
    CbUpdateCRL    cbUpdateCRL; /* notify thru cb that crl has updated */
2863
#endif
2864
};
2865
2866
WOLFSSL_LOCAL int CM_SaveCertCache(WOLFSSL_CERT_MANAGER* cm,
2867
                                   const char* fname);
2868
WOLFSSL_LOCAL int CM_RestoreCertCache(WOLFSSL_CERT_MANAGER* cm,
2869
                                      const char* fname);
2870
WOLFSSL_LOCAL int CM_MemSaveCertCache(WOLFSSL_CERT_MANAGER* cm, void* mem,
2871
                                      int sz, int* used);
2872
WOLFSSL_LOCAL int CM_MemRestoreCertCache(WOLFSSL_CERT_MANAGER* cm,
2873
                                         const void* mem, int sz);
2874
WOLFSSL_LOCAL int CM_GetCertCacheMemSize(WOLFSSL_CERT_MANAGER* cm);
2875
WOLFSSL_LOCAL int CM_VerifyBuffer_ex(WOLFSSL_CERT_MANAGER* cm, const byte* buff,
2876
                                     long sz, int format, int prev_err);
2877
2878
2879
#ifndef NO_CERTS
2880
#if !defined(NO_WOLFSSL_CLIENT) || !defined(WOLFSSL_NO_CLIENT_AUTH)
2881
typedef struct ProcPeerCertArgs {
2882
    buffer*      certs;
2883
#ifdef WOLFSSL_TLS13
2884
    buffer*      exts; /* extensions */
2885
#endif
2886
#ifndef NO_ASN
2887
    DecodedCert* dCert;
2888
#endif
2889
    word32 idx;
2890
    word32 begin;
2891
    int    totalCerts; /* number of certs in certs buffer */
2892
    int    count;
2893
    int    certIdx;
2894
    int    lastErr;
2895
    int    leafVerifyErr;
2896
#ifdef WOLFSSL_TLS13
2897
    byte   ctxSz;
2898
#endif
2899
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
2900
    char   untrustedDepth;
2901
#endif
2902
    word16 fatal:1;
2903
    word16 verifyErr:1;
2904
    word16 dCertInit:1;
2905
#ifdef WOLFSSL_TRUST_PEER_CERT
2906
    word16 haveTrustPeer:1; /* was cert verified by loaded trusted peer cert */
2907
#endif
2908
} ProcPeerCertArgs;
2909
WOLFSSL_LOCAL int DoVerifyCallback(WOLFSSL_CERT_MANAGER* cm, WOLFSSL* ssl,
2910
        int cert_err, ProcPeerCertArgs* args);
2911
WOLFSSL_LOCAL void DoCrlCallback(WOLFSSL_CERT_MANAGER* cm, WOLFSSL* ssl,
2912
        ProcPeerCertArgs* args, int* outRet);
2913
2914
WOLFSSL_LOCAL int SetupStoreCtxCallback(WOLFSSL_X509_STORE_CTX** store_pt,
2915
        WOLFSSL* ssl, WOLFSSL_CERT_MANAGER* cm, ProcPeerCertArgs* args,
2916
        int cert_err, void* heap, int* x509Free);
2917
WOLFSSL_LOCAL void CleanupStoreCtxCallback(WOLFSSL_X509_STORE_CTX* store,
2918
        WOLFSSL* ssl, void* heap, int x509Free);
2919
#endif /* !defined(NO_WOLFSSL_CLIENT) || !defined(WOLFSSL_NO_CLIENT_AUTH) */
2920
WOLFSSL_LOCAL int X509StoreLoadCertBuffer(WOLFSSL_X509_STORE *str,
2921
                                        byte *buf, word32 bufLen, int type);
2922
WOLFSSL_LOCAL int X509StorePushCertsToCM(WOLFSSL_X509_STORE* store);
2923
#endif /* !defined NO_CERTS */
2924
2925
/* wolfSSL Sock Addr */
2926
struct WOLFSSL_SOCKADDR {
2927
    unsigned int sz; /* sockaddr size */
2928
    unsigned int bufSz; /* size of allocated buffer */
2929
    void*        sa; /* pointer to the sockaddr_in or sockaddr_in6 */
2930
};
2931
2932
#ifdef WOLFSSL_DTLS
2933
typedef struct WOLFSSL_DTLS_CTX {
2934
#ifdef WOLFSSL_RW_THREADED
2935
    /* Protect peer access after the handshake */
2936
    wolfSSL_RwLock peerLock;
2937
#endif
2938
    WOLFSSL_SOCKADDR peer;
2939
#ifdef WOLFSSL_DTLS_CID
2940
    WOLFSSL_SOCKADDR pendingPeer; /* When using CID's, we don't want to update
2941
                                   * the peer's address until we successfully
2942
                                   * de-protect the record. */
2943
#endif
2944
    int rfd;
2945
    int wfd;
2946
    WolfSSLRecvFrom recvfrom;
2947
    WolfSSLSento sendto;
2948
    byte userSet:1;
2949
    byte connected:1; /* When set indicates rfd and wfd sockets are
2950
                       * connected (connect() and bind() both called).
2951
                       * This means that sendto and recvfrom do not need to
2952
                       * specify and store the peer address. */
2953
    byte rfdIsDGram:1; /* whether rfd is a SOCK_DGRAM socket; probed with
2954
                        * getsockopt(SO_TYPE) where rfd is assigned to keep
2955
                        * the syscall out of the I/O callbacks. */
2956
    byte wfdIsDGram:1; /* as rfdIsDGram, for wfd; rfd and wfd may be
2957
                        * different sockets of different types. */
2958
#ifdef WOLFSSL_DTLS_CID
2959
    byte processingPendingRecord:1;
2960
#endif
2961
} WOLFSSL_DTLS_CTX;
2962
#endif
2963
2964
2965
typedef struct WOLFSSL_DTLS_PEERSEQ {
2966
    word32 window[WOLFSSL_DTLS_WINDOW_WORDS];
2967
                        /* Sliding window for current epoch    */
2968
    word16 nextEpoch;   /* Expected epoch in next record       */
2969
    word16 nextSeq_hi;  /* Expected sequence in next record    */
2970
    word32 nextSeq_lo;
2971
2972
    word32 prevWindow[WOLFSSL_DTLS_WINDOW_WORDS];
2973
                        /* Sliding window for old epoch        */
2974
    word32 prevSeq_lo;
2975
    word16 prevSeq_hi;  /* Next sequence in allowed old epoch  */
2976
2977
#ifdef WOLFSSL_MULTICAST
2978
    word16 peerId;
2979
    word32 highwaterMark;
2980
#endif
2981
} WOLFSSL_DTLS_PEERSEQ;
2982
2983
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
2984
struct WOLFSSL_BIO {
2985
    WOLFSSL_BUF_MEM* mem_buf;
2986
    WOLFSSL_BIO_METHOD* method;
2987
    WOLFSSL_BIO* prev;          /* previous in chain */
2988
    WOLFSSL_BIO* next;          /* next in chain */
2989
    WOLFSSL_BIO* pair;          /* BIO paired with */
2990
    void*        heap;          /* user heap hint */
2991
    union {
2992
        byte*    mem_buf_data;
2993
#ifndef WOLFCRYPT_ONLY
2994
        WOLFSSL* ssl;
2995
        WOLFSSL_EVP_MD_CTX* md_ctx;
2996
#endif
2997
#ifndef NO_FILESYSTEM
2998
        XFILE    fh;
2999
#endif
3000
    } ptr;
3001
    void*        usrCtx;        /* user set pointer */
3002
    char*        ip;            /* IP address for wolfIO_TcpConnect */
3003
    word16       port;          /* Port for wolfIO_TcpConnect */
3004
    char*        infoArg;       /* BIO callback argument */
3005
    wolf_bio_info_cb infoCb;    /* BIO callback */
3006
    int          wrSz;          /* write buffer size (mem) */
3007
    int          wrSzReset;     /* First buffer size (mem) - read ONLY data */
3008
    int          wrIdx;         /* current index for write buffer */
3009
    int          rdIdx;         /* current read index */
3010
    int          readRq;        /* read request */
3011
    union {
3012
        SOCKET_T fd;
3013
        size_t   length;
3014
    } num;
3015
    int          eof;           /* eof flag */
3016
    int          flags;
3017
    int          type;          /* method type */
3018
    byte         init:1;        /* bio has been initialized */
3019
    byte         shutdown:1;    /* close flag */
3020
    byte         connected:1;   /* connected state, for datagram BIOs -- as for
3021
                                 * struct WOLFSSL_DTLS_CTX, when set, sendto and
3022
                                 * recvfrom leave the peer_addr unchanged. */
3023
#ifdef WOLFSSL_HAVE_BIO_ADDR
3024
    union WOLFSSL_BIO_ADDR peer_addr; /* for datagram BIOs, the socket address stored
3025
                                       * with BIO_CTRL_DGRAM_CONNECT,
3026
                                       * BIO_CTRL_DGRAM_SET_CONNECTED, or
3027
                                       * BIO_CTRL_DGRAM_SET_PEER, or stored when a
3028
                                       * packet was received on an unconnected BIO. */
3029
#endif
3030
3031
#if defined(WORD64_AVAILABLE) && !defined(WOLFSSL_BIO_NO_FLOW_STATS)
3032
    #define WOLFSSL_BIO_HAVE_FLOW_STATS
3033
    word64       bytes_read;
3034
    word64       bytes_written;
3035
#endif
3036
3037
#ifdef HAVE_EX_DATA
3038
    WOLFSSL_CRYPTO_EX_DATA ex_data;
3039
#endif
3040
#if defined(OPENSSL_ALL) || defined(OPENSSL_EXTRA)
3041
    wolfSSL_Ref  ref;
3042
#endif
3043
};
3044
#endif /* OPENSSL_EXTRA || OPENSSL_EXTRA_X509_SMALL */
3045
3046
#if defined(WOLFSSL_HAVE_BIO_ADDR) && defined(OPENSSL_EXTRA)
3047
WOLFSSL_LOCAL socklen_t wolfSSL_BIO_ADDR_size(const WOLFSSL_BIO_ADDR *addr);
3048
#endif
3049
3050
#if defined(WOLFSSL_TLS13) && defined(HAVE_NULL_CIPHER) && defined(WOLFSSL_SHA384)
3051
    /* Integrity-only cipher suites use IV size equal to hash output size */
3052
    #define MAX_WRITE_IV_SZ 48
3053
#elif defined(WOLFSSL_TLS13) && defined(HAVE_NULL_CIPHER) && !defined(NO_SHA256)
3054
    /* Integrity-only cipher suites use IV size equal to hash output size */
3055
    #define MAX_WRITE_IV_SZ 32
3056
#else
3057
    #define MAX_WRITE_IV_SZ 16 /* max size of client/server write_IV */
3058
#endif
3059
3060
/* keys and secrets
3061
 * keep as a constant size (no additional ifdefs) for session export */
3062
typedef struct Keys {
3063
#if !defined(WOLFSSL_AEAD_ONLY) || defined(WOLFSSL_TLS13)
3064
    byte client_write_MAC_secret[WC_MAX_DIGEST_SIZE];   /* max sizes */
3065
    byte server_write_MAC_secret[WC_MAX_DIGEST_SIZE];
3066
#endif
3067
    byte client_write_key[MAX_SYM_KEY_SIZE];         /* max sizes */
3068
    byte server_write_key[MAX_SYM_KEY_SIZE];
3069
    byte client_write_IV[MAX_WRITE_IV_SZ];               /* max sizes */
3070
    byte server_write_IV[MAX_WRITE_IV_SZ];
3071
#if defined(HAVE_AEAD) || defined(WOLFSSL_SESSION_EXPORT)
3072
    byte aead_exp_IV[AEAD_MAX_EXP_SZ];
3073
    byte aead_enc_imp_IV[AEAD_MAX_IMP_SZ];
3074
    byte aead_dec_imp_IV[AEAD_MAX_IMP_SZ];
3075
#endif
3076
3077
#ifdef WOLFSSL_DTLS13
3078
    byte client_sn_key[MAX_SYM_KEY_SIZE];
3079
    byte server_sn_key[MAX_SYM_KEY_SIZE];
3080
#endif /* WOLFSSL_DTLS13 */
3081
3082
    word32 peer_sequence_number_hi;
3083
    word32 peer_sequence_number_lo;
3084
    word32 sequence_number_hi;
3085
    word32 sequence_number_lo;
3086
3087
#ifdef WOLFSSL_DTLS
3088
    word16 curEpoch;    /* Received epoch in current record    */
3089
    word16 curSeq_hi;   /* Received sequence in current record */
3090
    word32 curSeq_lo;
3091
3092
#ifdef WOLFSSL_DTLS13
3093
    w64wrapper curEpoch64;    /* Received epoch in current record    */
3094
    w64wrapper curSeq;
3095
#endif /* WOLFSSL_DTLS13 */
3096
3097
#ifdef WOLFSSL_MULTICAST
3098
    byte   curPeerId;   /* Received peer group ID in current record */
3099
#endif
3100
    WOLFSSL_DTLS_PEERSEQ peerSeq[WOLFSSL_DTLS_PEERSEQ_SZ];
3101
3102
    word16 dtls_peer_handshake_number;
3103
    word16 dtls_expected_peer_handshake_number;
3104
3105
    word16 dtls_epoch;                          /* Current epoch    */
3106
    word16 dtls_sequence_number_hi;             /* Current epoch */
3107
    word32 dtls_sequence_number_lo;
3108
    word16 dtls_prev_sequence_number_hi;        /* Previous epoch */
3109
    word32 dtls_prev_sequence_number_lo;
3110
    word16 dtls_handshake_number;               /* Current tx handshake seq */
3111
#endif
3112
3113
    word32 encryptSz;             /* last size of encrypted data   */
3114
    word32 padSz;                 /* how much to advance after decrypt part */
3115
    byte   encryptionOn;          /* true after change cipher spec */
3116
    byte   decryptedCur;          /* only decrypt current record once */
3117
#ifdef WOLFSSL_TLS13
3118
    byte   updateResponseReq;     /* KeyUpdate response from peer required. */
3119
    byte   keyUpdateRespond;      /* KeyUpdate is to be responded to. */
3120
    w64wrapper keyUpdateCount;    /* Sending key updates performed (RFC 9846). */
3121
#endif
3122
#ifdef WOLFSSL_RENESAS_TSIP_TLS
3123
3124
    tsip_hmac_sha_key_index_t tsip_client_write_MAC_secret;
3125
    tsip_hmac_sha_key_index_t tsip_server_write_MAC_secret;
3126
3127
#endif
3128
#ifdef WOLFSSL_RENESAS_FSPSM_TLS
3129
    FSPSM_HMAC_WKEY fspsm_client_write_MAC_secret;
3130
    FSPSM_HMAC_WKEY fspsm_server_write_MAC_secret;
3131
#endif
3132
} Keys;
3133
3134
/* RFC 9846 Section 4.7.3: a TLS 1.3 sender MUST NOT allow its number of key
3135
 * updates to exceed 2^48-1. Receivers MUST NOT enforce this. Expressed as the
3136
 * high and low 32-bit halves of a w64wrapper. */
3137
0
#define TLS13_KEY_UPDATE_MAX_HI32 0x0000FFFFU
3138
0
#define TLS13_KEY_UPDATE_MAX_LO32 0xFFFFFFFFU
3139
3140
/* Forward declare opaque pointer to make available for func def */
3141
typedef struct Options Options;
3142
3143
3144
/** TLS Extensions - RFC 6066 */
3145
#ifdef HAVE_TLS_EXTENSIONS
3146
3147
1.09k
#define TLSXT_SERVER_NAME                0x0000 /* a.k.a. SNI  */
3148
306
#define TLSXT_MAX_FRAGMENT_LENGTH        0x0001
3149
303
#define TLSXT_TRUSTED_CA_KEYS            0x0003
3150
631
#define TLSXT_TRUNCATED_HMAC             0x0004
3151
620
#define TLSXT_STATUS_REQUEST             0x0005 /* a.k.a. OCSP stapling   */
3152
9.29k
#define TLSXT_SUPPORTED_GROUPS           0x000a /* a.k.a. Supported Curves */
3153
1.51k
#define TLSXT_EC_POINT_FORMATS           0x000b
3154
6.38k
#define TLSXT_SIGNATURE_ALGORITHMS       0x000d /* HELLO_EXT_SIG_ALGO */
3155
281
#define TLSXT_USE_SRTP                   0x000e /* 14 */
3156
335
#define TLSXT_APPLICATION_LAYER_PROTOCOL 0x0010 /* a.k.a. ALPN */
3157
197
#define TLSXT_STATUS_REQUEST_V2          0x0011 /* a.k.a. OCSP stapling v2 */
3158
101
#define TLSXT_CLIENT_CERTIFICATE         0x0013 /* RFC8446 */
3159
65
#define TLSXT_SERVER_CERTIFICATE         0x0014 /* RFC8446 */
3160
1.96k
#define TLSXT_ENCRYPT_THEN_MAC           0x0016 /* RFC 7366 */
3161
#define TLSXT_EXTENDED_MASTER_SECRET     0x0017 /* HELLO_EXT_EXTMS */
3162
81
#define TLSXT_CERT_WITH_EXTERN_PSK       0x0021 /* RFC 9973 */
3163
1.57k
#define TLSXT_SESSION_TICKET             0x0023
3164
1.66k
#define TLSXT_PRE_SHARED_KEY             0x0029
3165
2.70k
#define TLSXT_EARLY_DATA                 0x002a
3166
#define TLSXT_SUPPORTED_VERSIONS         0x002b
3167
106
#define TLSXT_COOKIE                     0x002c
3168
1.43k
#define TLSXT_PSK_KEY_EXCHANGE_MODES     0x002d
3169
774
#define TLSXT_CERTIFICATE_AUTHORITIES    0x002f
3170
222
#define TLSXT_POST_HANDSHAKE_AUTH        0x0031
3171
241
#define TLSXT_SIGNATURE_ALGORITHMS_CERT  0x0032
3172
5.54k
#define TLSXT_KEY_SHARE                  0x0033
3173
131
#define TLSXT_CONNECTION_ID              0x0036
3174
#define TLSXT_KEY_QUIC_TP_PARAMS         0x0039 /* RFC 9001, ch. 8.2 */
3175
53
#define TLSXT_ECH                        0xfe0d /* RFC 9849 */
3176
#define TLSXT_ECH_OUTER_EXTENSIONS       0xfd00 /* RFC 9849 */
3177
/* The 0xFF section is experimental/custom/personal use */
3178
#define TLSXT_CKS                        0xff92 /* X9.146 */
3179
511
#define TLSXT_RENEGOTIATION_INFO         0xff01
3180
14
#define TLSXT_KEY_QUIC_TP_PARAMS_DRAFT   0xffa5 /* from */
3181
                                                /* draft-ietf-quic-tls-27 */
3182
3183
typedef enum {
3184
#ifdef HAVE_SNI
3185
    TLSX_SERVER_NAME                = TLSXT_SERVER_NAME,
3186
#endif
3187
    TLSX_MAX_FRAGMENT_LENGTH        = TLSXT_MAX_FRAGMENT_LENGTH,
3188
    TLSX_TRUSTED_CA_KEYS            = TLSXT_TRUSTED_CA_KEYS,
3189
    TLSX_TRUNCATED_HMAC             = TLSXT_TRUNCATED_HMAC,
3190
    TLSX_STATUS_REQUEST             = TLSXT_STATUS_REQUEST,
3191
    TLSX_SUPPORTED_GROUPS           = TLSXT_SUPPORTED_GROUPS,
3192
    TLSX_EC_POINT_FORMATS           = TLSXT_EC_POINT_FORMATS,
3193
#if !defined(NO_CERTS) && !defined(WOLFSSL_NO_SIGALG)
3194
    TLSX_SIGNATURE_ALGORITHMS       = TLSXT_SIGNATURE_ALGORITHMS,
3195
#endif
3196
#ifdef WOLFSSL_SRTP
3197
    TLSX_USE_SRTP                   = TLSXT_USE_SRTP,
3198
#endif
3199
    TLSX_APPLICATION_LAYER_PROTOCOL = TLSXT_APPLICATION_LAYER_PROTOCOL,
3200
    TLSX_STATUS_REQUEST_V2          = TLSXT_STATUS_REQUEST_V2,
3201
#ifdef HAVE_RPK
3202
    TLSX_CLIENT_CERTIFICATE_TYPE    = TLSXT_CLIENT_CERTIFICATE,
3203
    TLSX_SERVER_CERTIFICATE_TYPE    = TLSXT_SERVER_CERTIFICATE,
3204
#endif
3205
#if defined(HAVE_ENCRYPT_THEN_MAC) && !defined(WOLFSSL_AEAD_ONLY)
3206
    TLSX_ENCRYPT_THEN_MAC           = TLSXT_ENCRYPT_THEN_MAC,
3207
#endif
3208
    TLSX_EXTENDED_MASTER_SECRET     = TLSXT_EXTENDED_MASTER_SECRET,
3209
    TLSX_SESSION_TICKET             = TLSXT_SESSION_TICKET,
3210
#ifdef WOLFSSL_TLS13
3211
    #ifdef WOLFSSL_EARLY_DATA
3212
    TLSX_EARLY_DATA                 = TLSXT_EARLY_DATA,
3213
    #endif
3214
    TLSX_SUPPORTED_VERSIONS         = TLSXT_SUPPORTED_VERSIONS,
3215
    TLSX_COOKIE                     = TLSXT_COOKIE,
3216
    #if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
3217
    TLSX_PSK_KEY_EXCHANGE_MODES     = TLSXT_PSK_KEY_EXCHANGE_MODES,
3218
    #if defined(WOLFSSL_CERT_WITH_EXTERN_PSK)
3219
    TLSX_CERT_WITH_EXTERN_PSK       = TLSXT_CERT_WITH_EXTERN_PSK,
3220
    #endif
3221
    #endif
3222
    #if !defined(NO_CERTS) && !defined(WOLFSSL_NO_CA_NAMES)
3223
    TLSX_CERTIFICATE_AUTHORITIES    = TLSXT_CERTIFICATE_AUTHORITIES,
3224
    #endif
3225
    #ifdef WOLFSSL_POST_HANDSHAKE_AUTH
3226
    TLSX_POST_HANDSHAKE_AUTH        = TLSXT_POST_HANDSHAKE_AUTH,
3227
    #endif
3228
    #if !defined(NO_CERTS) && !defined(WOLFSSL_NO_SIGALG)
3229
    TLSX_SIGNATURE_ALGORITHMS_CERT  = TLSXT_SIGNATURE_ALGORITHMS_CERT,
3230
    #endif
3231
    #ifdef WOLFSSL_QUIC
3232
    TLSX_KEY_QUIC_TP_PARAMS         = TLSXT_KEY_QUIC_TP_PARAMS,
3233
    #endif
3234
    #ifdef HAVE_ECH
3235
    TLSX_ECH                        = TLSXT_ECH,
3236
    #endif
3237
#endif
3238
#if defined(WOLFSSL_DTLS_CID)
3239
    TLSX_CONNECTION_ID              = TLSXT_CONNECTION_ID,
3240
#endif /* defined(WOLFSSL_DTLS_CID) */
3241
#if defined(WOLFSSL_TLS13) || !defined(WOLFSSL_NO_TLS12) || !defined(NO_OLD_TLS)
3242
    #if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
3243
    TLSX_PRE_SHARED_KEY             = TLSXT_PRE_SHARED_KEY,
3244
    #endif
3245
    TLSX_KEY_SHARE                  = TLSXT_KEY_SHARE,
3246
#endif
3247
#if defined(WOLFSSL_TLS13) && defined(WOLFSSL_DUAL_ALG_CERTS)
3248
    TLSX_CKS                        = TLSXT_CKS,
3249
#endif
3250
#ifdef WOLFSSL_QUIC
3251
    TLSX_KEY_QUIC_TP_PARAMS_DRAFT   = TLSXT_KEY_QUIC_TP_PARAMS_DRAFT,
3252
#endif
3253
    TLSX_RENEGOTIATION_INFO         = TLSXT_RENEGOTIATION_INFO
3254
} TLSX_Type;
3255
3256
/* TLS Certificate type defined RFC7250
3257
 * https://www.iana.org/assignments/tls-extensiontype-values/tls-extensiontype-values.xhtml#tls-extensiontype-values-3
3258
 */
3259
#if defined(HAVE_RPK)
3260
/* WOLFSSL_MAX_RPK_PINS (default 4) is defined in the public header
3261
 * wolfssl/ssl.h, which this header includes, so applications can see and
3262
 * override it. The pin table is stored inline in RpkConfig (see below),
3263
 * costing WOLFSSL_MAX_RPK_PINS * WC_SHA256_DIGEST_SIZE bytes per WOLFSSL_CTX and
3264
 * WOLFSSL. Out-of-band RPK pinning needs SHA-256 (pins are stored as digests);
3265
 * under NO_SHA256 there is no in-library pinning and trust must be expressed
3266
 * through a verify callback instead. */
3267
3268
typedef struct RpkConfig {
3269
    /* user's preference */
3270
    byte preferred_ClientCertTypeCnt;
3271
    byte preferred_ClientCertTypes[MAX_CLIENT_CERT_TYPE_CNT];
3272
    byte preferred_ServerCertTypeCnt;
3273
    byte preferred_ServerCertTypes[MAX_CLIENT_CERT_TYPE_CNT];
3274
    /* reflect to client_certificate_type extension in xxxHello */
3275
#ifndef NO_SHA256
3276
    /* SHA-256 digests of the DER SubjectPublicKeyInfo(s) the peer is expected
3277
     * to present as a Raw Public Key (RFC 7250), pinned out of band via
3278
     * wolfSSL_set_expected_rpk()/wolfSSL_CTX_set_expected_rpk(). A received RPK
3279
     * whose SPKI digest matches one of these is treated as authenticated.
3280
     * Stored inline (not a pointer) so the by-value RpkConfig copy from CTX to
3281
     * SSL needs no deep-copy or free handling. */
3282
    byte expectedRpkCnt;
3283
    byte expectedRpk[WOLFSSL_MAX_RPK_PINS][WC_SHA256_DIGEST_SIZE];
3284
#endif /* !NO_SHA256 */
3285
} RpkConfig;
3286
3287
typedef struct RpkState {
3288
    byte sending_ClientCertTypeCnt;
3289
    byte sending_ClientCertTypes[MAX_CLIENT_CERT_TYPE_CNT];
3290
    /* reflect to server_certificate_type extension in xxxHello */
3291
    byte sending_ServerCertTypeCnt;
3292
    byte sending_ServerCertTypes[MAX_SERVER_CERT_TYPE_CNT];
3293
    /* client_certificate_type extension in received yyyHello  */
3294
    byte received_ClientCertTypeCnt;
3295
    byte received_ClientCertTypes[MAX_CLIENT_CERT_TYPE_CNT];
3296
    /* server_certificate_type extension in received yyyHello  */
3297
    byte received_ServerCertTypeCnt;
3298
    byte received_ServerCertTypes[MAX_SERVER_CERT_TYPE_CNT];
3299
    /* set if Raw-public-key cert is loaded as own certificate */
3300
    int  isRPKLoaded;
3301
} RpkState;
3302
#endif /* HAVE_RPK */
3303
3304
#if defined(WOLFSSL_TLS13) && defined(HAVE_ECH)
3305
#define ECH_ACCEPT_CONFIRMATION_SZ 8
3306
#define ECH_PADDING_TO_32(length) (31 - (((length) - 1) % 32))
3307
3308
typedef enum {
3309
    ECH_TYPE_OUTER = 0,
3310
    ECH_TYPE_INNER = 1
3311
} EchType;
3312
3313
typedef enum {
3314
    ECH_WRITE_GREASE,
3315
    ECH_WRITE_REAL,
3316
    ECH_WRITE_RETRY_CONFIGS,
3317
    ECH_WRITE_NONE,
3318
    ECH_PARSED_INTERNAL,
3319
} EchState;
3320
3321
typedef struct EchCipherSuite {
3322
    word16 kdfId;
3323
    word16 aeadId;
3324
} EchCipherSuite;
3325
3326
typedef struct WOLFSSL_EchConfig {
3327
    byte* raw;
3328
    char* publicName;
3329
    void* receiverPrivkey;
3330
    struct WOLFSSL_EchConfig* next;
3331
    EchCipherSuite* cipherSuites;
3332
    word32 rawLen;
3333
    word16 kemId;
3334
    byte configId;
3335
    byte numCipherSuites;
3336
    byte receiverPubkey[HPKE_Npk_MAX];
3337
    byte maxNameLen;
3338
} WOLFSSL_EchConfig;
3339
3340
typedef struct WOLFSSL_ECH {
3341
    Hpke* hpke;
3342
    HpkeBaseContext* hpkeContext;
3343
    const byte* aad;
3344
    void* ephemeralKey;
3345
    WOLFSSL_EchConfig* echConfig;
3346
    byte* innerClientHello;
3347
    byte* outerClientPayload;
3348
    /* the 'public' extensions (i.e., the public SNI would be stored here) */
3349
    TLSX* extensions;
3350
    byte* confBuf;
3351
    EchCipherSuite cipherSuite;
3352
    word32 aadLen;
3353
    word32 innerClientHelloLen;
3354
    word16 paddingLen;
3355
    word16 kemId;
3356
    word16 encLen;
3357
    EchState state;
3358
    byte type;
3359
    byte configId;
3360
    byte enc[HPKE_Npk_MAX];
3361
    byte innerCount;
3362
    byte writeEncoded;
3363
} WOLFSSL_ECH;
3364
3365
WOLFSSL_LOCAL int EchConfigGetSupportedCipherSuite(WOLFSSL_EchConfig* config);
3366
3367
WOLFSSL_LOCAL int TLSX_FinalizeEch(WOLFSSL* ssl, WOLFSSL_ECH* ech, byte* aad,
3368
    word32 aadLen);
3369
3370
WOLFSSL_LOCAL int TLSX_EchReplaceExtensions(WOLFSSL* ssl, byte accepted);
3371
3372
#ifdef WOLFSSL_API_PREFIX_MAP
3373
    #define TLSX_EchSwapExtensions wolfSSL_TLSX_EchSwapExtensions
3374
#endif
3375
WOLFSSL_TEST_VIS int TLSX_EchSwapExtensions(TLSX** sslExts, TLSX** echExts,
3376
    word16* appended);
3377
3378
#ifdef WOLFSSL_API_PREFIX_MAP
3379
    #define TLSX_ServerECH_Use wolfSSL_TLSX_ServerECH_Use
3380
#endif
3381
WOLFSSL_TEST_VIS int TLSX_ServerECH_Use(TLSX** extensions, void* heap,
3382
    WOLFSSL_EchConfig* configs);
3383
3384
WOLFSSL_LOCAL int SetEchConfigsEx(WOLFSSL_EchConfig** outputConfigs, void* heap,
3385
    const byte* echConfigs, word32 echConfigsLen);
3386
3387
WOLFSSL_LOCAL int GetEchConfig(WOLFSSL_EchConfig* config, byte* output,
3388
    word32* outputLen);
3389
3390
WOLFSSL_LOCAL int GetEchConfigsEx(WOLFSSL_EchConfig* configs,
3391
    byte* output, word32* outputLen);
3392
3393
WOLFSSL_LOCAL void FreeEchConfigs(WOLFSSL_EchConfig* configs, void* heap);
3394
3395
WOLFSSL_LOCAL int SetRetryConfigs(WOLFSSL* ssl, const byte* echConfigs,
3396
    word32 echConfigsLen);
3397
#endif
3398
3399
struct TLSX {
3400
    TLSX_Type    type; /* Extension Type  */
3401
    void*        data; /* Extension Data  */
3402
    word32       val;  /* Extension Value */
3403
    byte         resp; /* IsResponse Flag */
3404
    struct TLSX* next; /* List Behavior   */
3405
};
3406
3407
#if defined(HAVE_TLS_EXTENSIONS) && defined(OPENSSL_EXTRA)
3408
/* OpenSSL-compatible custom (application-defined) TLS extension.
3409
 * Registered on a WOLFSSL_CTX via wolfSSL_CTX_add_client_custom_ext(). These
3410
 * extensions are not part of the TLSX framework but are processed in parallel
3411
 * for unknown extension types. Currently the client side for TLS 1.2 and below
3412
 * is supported, mirroring SSL_CTX_add_client_custom_ext(). */
3413
typedef struct WOLFSSL_CustomExt {
3414
    word16                      ext_type;  /* extension type on the wire     */
3415
    wolfSSL_custom_ext_add_cb   add_cb;    /* build outgoing extension data  */
3416
    wolfSSL_custom_ext_free_cb  free_cb;   /* free data produced by add_cb   */
3417
    wolfSSL_custom_ext_parse_cb parse_cb;  /* parse incoming extension data  */
3418
    void*                       add_arg;   /* opaque arg for add_cb/free_cb  */
3419
    void*                       parse_arg; /* opaque arg for parse_cb        */
3420
    struct WOLFSSL_CustomExt*   next;      /* list behaviour                 */
3421
} WOLFSSL_CustomExt;
3422
3423
WOLFSSL_LOCAL void TLSX_CustomExt_FreeAll(WOLFSSL_CustomExt* list, void* heap);
3424
#ifdef WOLFSSL_API_PREFIX_MAP
3425
    #define TLSX_CustomExt_BuildRequest wolfSSL_TLSX_CustomExt_BuildRequest
3426
#endif
3427
WOLFSSL_TEST_VIS int TLSX_CustomExt_BuildRequest(WOLFSSL* ssl, word16* pSz);
3428
WOLFSSL_LOCAL int  TLSX_CustomExt_Parse(WOLFSSL* ssl, byte msgType, word16 type,
3429
        const byte* input, word16 size, int* found);
3430
#endif /* HAVE_TLS_EXTENSIONS && OPENSSL_EXTRA */
3431
3432
#ifdef WOLFSSL_API_PREFIX_MAP
3433
    #define TLSX_Find wolfSSL_TLSX_Find
3434
#endif
3435
WOLFSSL_TEST_VIS TLSX* TLSX_Find(TLSX* list, TLSX_Type type);
3436
WOLFSSL_LOCAL void  TLSX_Remove(TLSX** list, TLSX_Type type, void* heap);
3437
WOLFSSL_LOCAL void  TLSX_FreeAll(TLSX* list, void* heap);
3438
WOLFSSL_LOCAL int   TLSX_SupportExtensions(WOLFSSL* ssl);
3439
WOLFSSL_LOCAL int   TLSX_PopulateExtensions(WOLFSSL* ssl, byte isRequest);
3440
3441
#if defined(WOLFSSL_TLS13) || !defined(NO_WOLFSSL_CLIENT)
3442
#ifdef WOLFSSL_API_PREFIX_MAP
3443
    #define TLSX_GetRequestSize wolfSSL_TLSX_GetRequestSize
3444
    #define TLSX_WriteRequest   wolfSSL_TLSX_WriteRequest
3445
#endif
3446
WOLFSSL_TEST_VIS int   TLSX_GetRequestSize(WOLFSSL* ssl, byte msgType,
3447
                                         word32* pLength);
3448
WOLFSSL_TEST_VIS int   TLSX_WriteRequest(WOLFSSL* ssl, byte* output,
3449
                                       byte msgType, word32* pOffset);
3450
#endif
3451
3452
#if defined(WOLFSSL_TLS13) || !defined(NO_WOLFSSL_SERVER)
3453
/* TLS 1.3 Certificate messages have extensions. */
3454
WOLFSSL_LOCAL int   TLSX_GetResponseSize(WOLFSSL* ssl, byte msgType,
3455
                                          word16* pLength);
3456
WOLFSSL_LOCAL int   TLSX_WriteResponse(WOLFSSL *ssl, byte* output, byte msgType,
3457
                                        word16* pOffset);
3458
#endif
3459
3460
WOLFSSL_LOCAL int   TLSX_ParseVersion(WOLFSSL* ssl, const byte* input,
3461
                                      word16 length, byte msgType, int* found);
3462
WOLFSSL_LOCAL int TLSX_SupportedVersions_Parse(const WOLFSSL* ssl,
3463
        const byte* input, word16 length, byte msgType, ProtocolVersion* pv,
3464
        Options* opts, TLSX** exts);
3465
#ifdef WOLFSSL_API_PREFIX_MAP
3466
    #define TLSX_Parse wolfSSL_TLSX_Parse
3467
#endif
3468
WOLFSSL_TEST_VIS int TLSX_Parse(WOLFSSL* ssl, const byte* input, word16 length,
3469
                               byte msgType, Suites *suites);
3470
WOLFSSL_LOCAL int TLSX_Push(TLSX** list, TLSX_Type type,
3471
                            const void* data, void* heap);
3472
WOLFSSL_LOCAL int TLSX_Append(TLSX** list, TLSX_Type type,
3473
                            const void* data, void* heap);
3474
3475
#elif defined(HAVE_SNI)                           \
3476
   || defined(HAVE_MAX_FRAGMENT)                  \
3477
   || defined(HAVE_TRUSTED_CA)                    \
3478
   || defined(HAVE_TRUNCATED_HMAC)                \
3479
   || defined(HAVE_CERTIFICATE_STATUS_REQUEST)    \
3480
   || defined(HAVE_CERTIFICATE_STATUS_REQUEST_V2) \
3481
   || defined(HAVE_SUPPORTED_CURVES)              \
3482
   || defined(HAVE_ALPN)                          \
3483
   || defined(HAVE_SESSION_TICKET)                \
3484
   || defined(HAVE_SECURE_RENEGOTIATION)          \
3485
   || defined(HAVE_SERVER_RENEGOTIATION_INFO)
3486
3487
#ifndef NO_TLS
3488
#error Using TLS extensions requires HAVE_TLS_EXTENSIONS to be defined.
3489
#endif
3490
#endif /* HAVE_TLS_EXTENSIONS */
3491
3492
/** Server Name Indication - RFC 6066 (session 3) */
3493
#ifdef HAVE_SNI
3494
3495
typedef struct SNI {
3496
    byte                       type;    /* SNI Type         */
3497
    union { char* host_name; } data;    /* SNI Data         */
3498
    struct SNI*                next;    /* List Behavior    */
3499
    byte                       status;  /* Matching result  */
3500
#ifndef NO_WOLFSSL_SERVER
3501
    byte                       options; /* Behavior options */
3502
#endif
3503
} SNI;
3504
3505
WOLFSSL_LOCAL int TLSX_UseSNI(TLSX** extensions, byte type, const void* data,
3506
                                                       word16 size, void* heap);
3507
WOLFSSL_LOCAL byte TLSX_SNI_Status(TLSX* extensions, byte type);
3508
#ifdef WOLFSSL_API_PREFIX_MAP
3509
    #define TLSX_SNI_GetRequest wolfSSL_TLSX_SNI_GetRequest
3510
#endif
3511
WOLFSSL_TEST_VIS word16 TLSX_SNI_GetRequest(TLSX* extensions, byte type,
3512
                                                void** data, byte ignoreStatus);
3513
#ifdef WOLFSSL_API_PREFIX_MAP
3514
    #define TLSX_SNI_GetSize wolfSSL_TLSX_SNI_GetSize
3515
#endif
3516
WOLFSSL_TEST_VIS word16 TLSX_SNI_GetSize(SNI* list);
3517
3518
#ifndef NO_WOLFSSL_SERVER
3519
WOLFSSL_LOCAL void   TLSX_SNI_SetOptions(TLSX* extensions, byte type,
3520
                                                                  byte options);
3521
WOLFSSL_LOCAL int    TLSX_SNI_GetFromBuffer(const byte* clientHello,
3522
                         word32 helloSz, byte type, byte* sni, word32* inOutSz);
3523
#endif
3524
3525
#endif /* HAVE_SNI */
3526
3527
/* Trusted CA Key Indication - RFC 6066 (section 6) */
3528
#ifdef HAVE_TRUSTED_CA
3529
3530
typedef struct TCA {
3531
    byte                       type;    /* TCA Type            */
3532
    byte*                      id;      /* TCA identifier      */
3533
    word16                     idSz;    /* TCA identifier size */
3534
    struct TCA*                next;    /* List Behavior       */
3535
} TCA;
3536
3537
WOLFSSL_LOCAL int TLSX_UseTrustedCA(TLSX** extensions, byte type,
3538
                    const byte* id, word16 idSz, void* heap);
3539
3540
#endif /* HAVE_TRUSTED_CA */
3541
3542
/* Application-Layer Protocol Negotiation - RFC 7301 */
3543
#ifdef HAVE_ALPN
3544
typedef struct ALPN {
3545
    char*        protocol_name; /* ALPN protocol name */
3546
    struct ALPN* next;          /* List Behavior      */
3547
    byte         options;       /* Behavior options */
3548
    byte         negotiated;    /* ALPN protocol negotiated or not */
3549
} ALPN;
3550
3551
WOLFSSL_LOCAL int TLSX_ALPN_GetRequest(TLSX* extensions,
3552
                                       void** data, word16 *dataSz);
3553
3554
WOLFSSL_LOCAL int TLSX_UseALPN(TLSX** extensions, const void* data,
3555
                               word16 size, byte options, void* heap);
3556
3557
WOLFSSL_LOCAL int TLSX_ALPN_SetOptions(TLSX** extensions, byte option);
3558
3559
#endif /* HAVE_ALPN */
3560
3561
/** Maximum Fragment Length Negotiation - RFC 6066 (session 4) */
3562
#ifdef HAVE_MAX_FRAGMENT
3563
3564
WOLFSSL_LOCAL int TLSX_UseMaxFragment(TLSX** extensions, byte mfl, void* heap);
3565
3566
#endif /* HAVE_MAX_FRAGMENT */
3567
3568
/** Truncated HMAC - RFC 6066 (session 7) */
3569
#ifdef HAVE_TRUNCATED_HMAC
3570
3571
WOLFSSL_LOCAL int TLSX_UseTruncatedHMAC(TLSX** extensions, void* heap);
3572
3573
#endif /* HAVE_TRUNCATED_HMAC */
3574
3575
/** Certificate Status Request - RFC 6066 (session 8) */
3576
#ifdef HAVE_CERTIFICATE_STATUS_REQUEST
3577
3578
typedef struct {
3579
    byte status_type;
3580
    byte options;
3581
    WOLFSSL* ssl;
3582
    union {
3583
        OcspRequest ocsp[MAX_CERT_EXTENSIONS];
3584
    } request;
3585
    word16 requests;
3586
#ifdef WOLFSSL_TLS13
3587
    buffer responses[MAX_CERT_EXTENSIONS];
3588
#endif
3589
} CertificateStatusRequest;
3590
3591
WOLFSSL_LOCAL int   TLSX_UseCertificateStatusRequest(TLSX** extensions,
3592
           byte status_type, byte options, WOLFSSL* ssl, void* heap, int devId);
3593
#ifndef NO_CERTS
3594
WOLFSSL_LOCAL int   TLSX_CSR_InitRequest(TLSX* extensions, DecodedCert* cert,
3595
                                                                    void* heap);
3596
WOLFSSL_LOCAL int   TLSX_CSR_InitRequest_ex(TLSX* extensions, DecodedCert* cert,
3597
                                            void* heap, int idx);
3598
#endif
3599
WOLFSSL_LOCAL void* TLSX_CSR_GetRequest(TLSX* extensions);
3600
WOLFSSL_LOCAL int   TLSX_CSR_ForceRequest(WOLFSSL* ssl);
3601
WOLFSSL_LOCAL word16 TLSX_CSR_GetSize_ex(CertificateStatusRequest* csr,
3602
                                        byte isRequest,
3603
                                        int idx);
3604
WOLFSSL_LOCAL int TLSX_CSR_Write_ex(CertificateStatusRequest* csr, byte* output,
3605
                          byte isRequest, int idx);
3606
WOLFSSL_LOCAL void* TLSX_CSR_GetRequest_ex(TLSX* extensions, int idx);
3607
3608
WOLFSSL_LOCAL int TLSX_CSR_SetResponseWithStatusCB(WOLFSSL *ssl);
3609
WOLFSSL_LOCAL int ProcessChainOCSPRequest(WOLFSSL* ssl);
3610
3611
#endif
3612
#if defined(HAVE_CERTIFICATE_STATUS_REQUEST) || \
3613
    defined(HAVE_CERTIFICATE_STATUS_REQUEST_V2)
3614
WOLFSSL_LOCAL int CreateOcspRequest(WOLFSSL* ssl, OcspRequest* request,
3615
                             DecodedCert* cert, byte* certData, word32 length);
3616
#endif
3617
/** Certificate Status Request v2 - RFC 6961 */
3618
#ifdef HAVE_CERTIFICATE_STATUS_REQUEST_V2
3619
3620
typedef struct CSRIv2 {
3621
    byte status_type;
3622
    byte options;
3623
    word16 requests;
3624
    union {
3625
        OcspRequest ocsp[1 + MAX_CHAIN_DEPTH];
3626
    } request;
3627
    struct CSRIv2* next;
3628
    Signer *pendingSigners;
3629
} CertificateStatusRequestItemV2;
3630
3631
WOLFSSL_LOCAL int   TLSX_UseCertificateStatusRequestV2(TLSX** extensions,
3632
                         byte status_type, byte options, void* heap, int devId);
3633
#ifndef NO_CERTS
3634
WOLFSSL_LOCAL int TLSX_CSR2_IsMulti(TLSX *extensions);
3635
WOLFSSL_LOCAL int TLSX_CSR2_AddPendingSigner(TLSX *extensions, Signer *s);
3636
WOLFSSL_LOCAL Signer* TLSX_CSR2_GetPendingSigners(TLSX *extensions);
3637
WOLFSSL_LOCAL int TLSX_CSR2_ClearPendingCA(WOLFSSL *ssl);
3638
WOLFSSL_LOCAL int TLSX_CSR2_MergePendingCA(WOLFSSL* ssl);
3639
WOLFSSL_LOCAL int   TLSX_CSR2_InitRequests(TLSX* extensions, DecodedCert* cert,
3640
                                                       byte isPeer, void* heap);
3641
#endif
3642
WOLFSSL_LOCAL void* TLSX_CSR2_GetRequest(TLSX* extensions, byte status_type,
3643
                                                                    byte idx);
3644
WOLFSSL_LOCAL int   TLSX_CSR2_ForceRequest(WOLFSSL* ssl);
3645
3646
#endif
3647
3648
#if defined(WOLFSSL_PUBLIC_ASN) && defined(HAVE_PK_CALLBACKS)
3649
/* Internal callback guarded by WOLFSSL_TEST_VIS because of DecodedCert. */
3650
typedef int (*CallbackProcessPeerCert)(WOLFSSL* ssl, DecodedCert* p_cert);
3651
WOLFSSL_TEST_VIS void wolfSSL_CTX_SetProcessPeerCertCb(WOLFSSL_CTX* ctx,
3652
       CallbackProcessPeerCert cb);
3653
#endif /* DecodedCert && HAVE_PK_CALLBACKS */
3654
3655
#if !defined(NO_CERTS) && !defined(WOLFSSL_NO_SIGALG)
3656
typedef struct SignatureAlgorithms {
3657
    /* Not const since it is modified in TLSX_SignatureAlgorithms_MapPss */
3658
    WOLFSSL*    ssl;
3659
    word16      hashSigAlgoSz; /* SigAlgo extension length in bytes */
3660
    /* Ignore "nonstandard extension used : zero-sized array in struct/union"
3661
     * MSVC warning */
3662
    #ifdef _MSC_VER
3663
    #pragma warning(disable: 4200)
3664
    #endif
3665
    /* sig/algo to offer */
3666
    byte        hashSigAlgo[WC_FLEXIBLE_ARRAY_SIZE];
3667
} SignatureAlgorithms;
3668
3669
WOLFSSL_LOCAL SignatureAlgorithms* TLSX_SignatureAlgorithms_New(
3670
        WOLFSSL* ssl, word16 hashSigAlgoSz, void* heap);
3671
WOLFSSL_LOCAL void TLSX_SignatureAlgorithms_FreeAll(SignatureAlgorithms* sa,
3672
                                                    void* heap);
3673
#endif
3674
3675
/** Supported Elliptic Curves - RFC 4492 (session 4) */
3676
#ifdef HAVE_SUPPORTED_CURVES
3677
3678
typedef struct SupportedCurve {
3679
    word16 name;                 /* Curve Names */
3680
    struct SupportedCurve* next; /* List Behavior */
3681
} SupportedCurve;
3682
3683
typedef struct PointFormat {
3684
    byte format;                /* PointFormat */
3685
    struct PointFormat* next;   /* List Behavior */
3686
} PointFormat;
3687
3688
WOLFSSL_LOCAL int TLSX_SupportedCurve_Copy(TLSX* src, TLSX** dst, void* heap);
3689
WOLFSSL_LOCAL int TLSX_UseSupportedCurve(TLSX** extensions, word16 name,
3690
                                                          void* heap, int side);
3691
3692
#ifdef WOLFSSL_API_PREFIX_MAP
3693
    #define TLSX_UsePointFormat wolfSSL_TLSX_UsePointFormat
3694
#endif
3695
/* WOLFSSL_TEST_VIS so the API tests can seed a client's ec_point_formats
3696
 * extension (the point-format negotiation has no public API). */
3697
WOLFSSL_TEST_VIS int TLSX_UsePointFormat(TLSX** extensions, byte point,
3698
                                                                    void* heap);
3699
WOLFSSL_LOCAL int TLSX_IsGroupSupported(int namedGroup, int side);
3700
3701
#ifndef NO_WOLFSSL_SERVER
3702
WOLFSSL_LOCAL int TLSX_ValidateSupportedCurves(const WOLFSSL* ssl, byte first,
3703
                                               byte second, word32* ecdhCurveOID);
3704
WOLFSSL_LOCAL int TLSX_SupportedCurve_CheckPriority(WOLFSSL* ssl);
3705
WOLFSSL_LOCAL int TLSX_SupportedFFDHE_Set(WOLFSSL* ssl);
3706
#endif
3707
WOLFSSL_LOCAL int TLSX_SupportedCurve_IsSupported(WOLFSSL* ssl, word16 name);
3708
WOLFSSL_LOCAL int TLSX_SupportedCurve_Preferred(WOLFSSL* ssl,
3709
                                                            int checkSupported);
3710
WOLFSSL_LOCAL int TLSX_SupportedCurve_Parse(const WOLFSSL* ssl,
3711
        const byte* input, word16 length, byte isRequest, TLSX** extensions);
3712
3713
#endif /* HAVE_SUPPORTED_CURVES */
3714
3715
/** Renegotiation Indication - RFC 5746 */
3716
#if defined(HAVE_SECURE_RENEGOTIATION) \
3717
 || defined(HAVE_SERVER_RENEGOTIATION_INFO)
3718
3719
enum key_cache_state {
3720
    SCR_CACHE_NULL   = 0,       /* empty / begin state */
3721
    SCR_CACHE_NEEDED,           /* need to cache keys */
3722
    SCR_CACHE_COPY,             /* we have a cached copy */
3723
    SCR_CACHE_PARTIAL,          /* partial restore to real keys */
3724
    SCR_CACHE_COMPLETE          /* complete restore to real keys */
3725
};
3726
3727
/* Additional Connection State according to rfc5746 section 3.1 */
3728
typedef struct SecureRenegotiation {
3729
   /* Single-bit flags grouped together so they pack into one storage unit. */
3730
   WC_BITFIELD          enabled:1;  /* secure_renegotiation flag in rfc */
3731
   WC_BITFIELD          verifySet:1;
3732
   WC_BITFIELD          startScr:1; /* server requested client to start scr */
3733
   WC_BITFIELD          renegInfoSeen:1; /* renegotiation_info ext seen this
3734
                                          * handshake (RFC 5746 3.7) */
3735
   WC_BITFIELD          subject_hash_set:1; /* if peer cert hash is set */
3736
#ifdef HAVE_SECURE_RENEGOTIATION
3737
   WC_BITFIELD          advertiseOnly:1; /* extension advertised for the RFC
3738
                                          * 5746 initial-handshake check only;
3739
                                          * refuse peer-initiated renegotiation */
3740
#endif
3741
   enum key_cache_state cache_status;  /* track key cache state */
3742
   byte                 client_verify_data[TLS_FINISHED_SZ];  /* cached */
3743
   byte                 server_verify_data[TLS_FINISHED_SZ];  /* cached */
3744
   byte                 subject_hash[KEYID_SIZE];  /* peer cert hash */
3745
   Keys                 tmp_keys;  /* can't overwrite real keys yet */
3746
} SecureRenegotiation;
3747
3748
WOLFSSL_LOCAL int TLSX_UseSecureRenegotiation(TLSX** extensions, void* heap);
3749
3750
#ifdef HAVE_SERVER_RENEGOTIATION_INFO
3751
WOLFSSL_LOCAL int TLSX_AddEmptyRenegotiationInfo(TLSX** extensions, void* heap);
3752
#endif
3753
3754
WOLFSSL_LOCAL int SetupClientSecureRenegotiation(WOLFSSL* ssl);
3755
3756
#endif /* HAVE_SECURE_RENEGOTIATION */
3757
3758
#ifdef HAVE_SESSION_TICKET
3759
/* Max peer cert size for ticket: 2KB is reasonable for most RSA/ECC certs */
3760
#ifndef MAX_TICKET_PEER_CERT_SZ
3761
#define MAX_TICKET_PEER_CERT_SZ 2048
3762
#endif
3763
#if defined(HAVE_SNI) || defined(HAVE_ALPN)
3764
/* Hash algorithm used for SNI/ALPN binding in session tickets.
3765
 * Pick the best available at compile time. */
3766
#ifndef TICKET_BINDING_HASH_TYPE
3767
    #if !defined(NO_SHA256)
3768
        #define TICKET_BINDING_HASH_TYPE WC_HASH_TYPE_SHA256
3769
        #define TICKET_BINDING_HASH_SZ   WC_SHA256_DIGEST_SIZE
3770
    #elif defined(WOLFSSL_SHA384)
3771
        #define TICKET_BINDING_HASH_TYPE WC_HASH_TYPE_SHA384
3772
        #define TICKET_BINDING_HASH_SZ   WC_SHA384_DIGEST_SIZE
3773
    #elif !defined(NO_SHA)
3774
        #define TICKET_BINDING_HASH_TYPE WC_HASH_TYPE_SHA
3775
        #define TICKET_BINDING_HASH_SZ   WC_SHA_DIGEST_SIZE
3776
    #else
3777
        #error "No hash algorithm available for ticket binding"
3778
    #endif
3779
#endif
3780
#endif
3781
3782
/* Our ticket format. All members need to be a byte or array of byte to
3783
 * avoid alignment issues */
3784
typedef struct InternalTicket {
3785
    ProtocolVersion pv;                    /* version when ticket created */
3786
    byte            suite[SUITE_LEN];      /* cipher suite when created */
3787
    byte            msecret[SECRET_LEN];   /* master secret */
3788
    byte            timestamp[TIMESTAMP_LEN];          /* born on */
3789
    byte            haveEMS;               /* have extended master secret */
3790
#ifdef WOLFSSL_TLS13
3791
    byte            ageAdd[AGEADD_LEN];    /* Obfuscation of age */
3792
    byte            namedGroup[NAMEDGROUP_LEN]; /* Named group used */
3793
    byte            ticketNonceLen;
3794
    byte            ticketNonce[MAX_TICKET_NONCE_STATIC_SZ];
3795
#ifdef WOLFSSL_EARLY_DATA
3796
    byte            maxEarlyDataSz[MAXEARLYDATASZ_LEN]; /* Max size of
3797
                                                         * early data */
3798
#endif
3799
#endif
3800
#ifdef WOLFSSL_TICKET_HAVE_ID
3801
    byte            id[ID_LEN];
3802
#endif
3803
#ifdef HAVE_SNI
3804
    byte            sniHash[TICKET_BINDING_HASH_SZ]; /* digest of server name
3805
                                                      * at ticket issue */
3806
#endif
3807
#ifdef HAVE_ALPN
3808
    byte            alpnHash[TICKET_BINDING_HASH_SZ]; /* digest of negotiated
3809
                                                       * ALPN at issue */
3810
#endif
3811
#ifdef OPENSSL_EXTRA
3812
    byte            sessionCtxSz;          /* sessionCtx length        */
3813
    byte            sessionCtx[ID_LEN];    /* app specific context id */
3814
#endif /* OPENSSL_EXTRA */
3815
#if defined(OPENSSL_ALL) && defined(KEEP_PEER_CERT) && \
3816
    !defined(NO_CERT_IN_TICKET)
3817
    byte            peerCertLen[OPAQUE16_LEN]; /* peer cert length */
3818
    byte            peerCert[]; /* peer certificate DER - variable length */
3819
#endif
3820
} InternalTicket;
3821
3822
/* Base size of InternalTicket without the variable-length peerCert field */
3823
#define WOLFSSL_INTERNAL_TICKET_BASE_SZ  (sizeof(InternalTicket))
3824
3825
/* Minimum internal ticket length (no peer cert) */
3826
#ifndef WOLFSSL_TICKET_ENC_CBC_HMAC
3827
    #define WOLFSSL_INTERNAL_TICKET_LEN     WOLFSSL_INTERNAL_TICKET_BASE_SZ
3828
#else
3829
    #define WOLFSSL_INTERNAL_TICKET_LEN     \
3830
        (((WOLFSSL_INTERNAL_TICKET_BASE_SZ + 15) / 16) * 16)
3831
#endif
3832
3833
/* Maximum internal ticket length (with max peer cert) */
3834
#if defined(OPENSSL_ALL) && defined(KEEP_PEER_CERT) && \
3835
    !defined(NO_CERT_IN_TICKET)
3836
    #define WOLFSSL_INTERNAL_TICKET_MAX_SZ  \
3837
        (WOLFSSL_INTERNAL_TICKET_BASE_SZ + MAX_TICKET_PEER_CERT_SZ)
3838
#else
3839
    #define WOLFSSL_INTERNAL_TICKET_MAX_SZ  WOLFSSL_INTERNAL_TICKET_BASE_SZ
3840
#endif
3841
3842
#ifndef WOLFSSL_TICKET_EXTRA_PADDING_SZ
3843
#define WOLFSSL_TICKET_EXTRA_PADDING_SZ 32
3844
#endif
3845
3846
/* Maximum encrypted ticket size */
3847
#define WOLFSSL_TICKET_ENC_SZ \
3848
    (WOLFSSL_INTERNAL_TICKET_MAX_SZ + WOLFSSL_TICKET_EXTRA_PADDING_SZ)
3849
3850
/* RFC 5077 defines this for session tickets. All members need to be a byte or
3851
 * array of byte to avoid alignment issues */
3852
typedef struct ExternalTicket {
3853
    byte key_name[WOLFSSL_TICKET_NAME_SZ];     /* key context name - 16 */
3854
    byte iv[WOLFSSL_TICKET_IV_SZ];             /* this ticket's iv - 16 */
3855
    byte enc_len[OPAQUE16_LEN];                /* encrypted length - 2 */
3856
    byte enc_ticket[WC_FLEXIBLE_ARRAY_SIZE];   /* encrypted ticket - var length
3857
                                                * + total mac - 32 */
3858
} ExternalTicket;
3859
3860
/* Fixed portion of external ticket (key_name + iv + enc_len) */
3861
#define WOLFSSL_TICKET_FIXED_SZ  \
3862
    (WOLFSSL_TICKET_NAME_SZ + WOLFSSL_TICKET_IV_SZ + OPAQUE16_LEN + \
3863
        WOLFSSL_TICKET_MAC_SZ)
3864
3865
/* Maximum session ticket length */
3866
#define SESSION_TICKET_LEN  \
3867
    ((int)(WOLFSSL_TICKET_FIXED_SZ + WOLFSSL_TICKET_ENC_SZ))
3868
3869
typedef struct SessionTicket {
3870
    word32 lifetime;
3871
#ifdef WOLFSSL_TLS13
3872
    word64 seen;
3873
    word32 ageAdd;
3874
#endif
3875
    byte*  data;
3876
    word16 size;
3877
} SessionTicket;
3878
3879
#if !defined(WOLFSSL_NO_DEF_TICKET_ENC_CB) && !defined(NO_WOLFSSL_SERVER)
3880
3881
/* Data passed to default SessionTicket enc/dec callback. */
3882
typedef struct TicketEncCbCtx {
3883
    /* Name for this context. */
3884
    byte name[WOLFSSL_TICKET_NAME_SZ];
3885
    /* Current keys - current and next. */
3886
    byte key[2][WOLFSSL_TICKET_KEY_SZ];
3887
    /* Expirary date of keys. */
3888
    word32 expirary[2];
3889
    /* Random number generator to use for generating name, keys and IV. */
3890
    WC_RNG rng;
3891
#ifndef SINGLE_THREADED
3892
    /* Mutex for access to changing keys. */
3893
    wolfSSL_Mutex mutex;
3894
#endif
3895
    /* Pointer back to SSL_CTX. */
3896
    WOLFSSL_CTX* ctx;
3897
} TicketEncCbCtx;
3898
3899
#endif /* !WOLFSSL_NO_DEF_TICKET_ENC_CB && !NO_WOLFSSL_SERVER */
3900
3901
#ifdef WOLFSSL_API_PREFIX_MAP
3902
    #define TLSX_UseSessionTicket     wolfSSL_TLSX_UseSessionTicket
3903
    #define TLSX_SessionTicket_Create wolfSSL_TLSX_SessionTicket_Create
3904
    #define TLSX_SessionTicket_Free   wolfSSL_TLSX_SessionTicket_Free
3905
#endif
3906
WOLFSSL_TEST_VIS int  TLSX_UseSessionTicket(TLSX** extensions,
3907
                                             SessionTicket* ticket, void* heap);
3908
WOLFSSL_TEST_VIS SessionTicket* TLSX_SessionTicket_Create(word32 lifetime,
3909
                                           byte* data, word16 size, void* heap);
3910
WOLFSSL_TEST_VIS void TLSX_SessionTicket_Free(SessionTicket* ticket, void* heap);
3911
3912
#endif /* HAVE_SESSION_TICKET */
3913
3914
#ifndef MAX_PSK_ID_LEN
3915
    /* max psk identity/hint supported */
3916
    #if defined(WOLFSSL_TLS13)
3917
        #ifdef SESSION_TICKET_LEN
3918
            #define MAX_PSK_ID_LEN SESSION_TICKET_LEN
3919
        #else
3920
            /* Previous value. Use as fallback for when tickets are disabled. */
3921
            #define MAX_PSK_ID_LEN 1536
3922
        #endif
3923
    #else
3924
        #define MAX_PSK_ID_LEN 128
3925
    #endif
3926
#endif
3927
3928
#if defined(HAVE_ENCRYPT_THEN_MAC) && !defined(WOLFSSL_AEAD_ONLY)
3929
int TLSX_EncryptThenMac_Respond(WOLFSSL* ssl);
3930
#endif
3931
3932
#ifdef WOLFSSL_TLS13
3933
3934
/* Cookie support is mandatory per RFC 8446 9.2 */
3935
#if !defined(NO_WOLFSSL_CLIENT) || defined(WOLFSSL_SEND_HRR_COOKIE)
3936
    #define WOLFSSL_TLS13_COOKIE
3937
#endif
3938
3939
/* Largest cookie a client stores from a HelloRetryRequest to echo back in the
3940
 * second ClientHello. RFC 8446 4.2.2 allows up to 2^16-1 bytes, but the cookie
3941
 * sits inside an extension body of that same size, so its own two byte length
3942
 * prefix leaves 65533. */
3943
#ifndef WOLFSSL_MAX_TLS13_COOKIE_SZ
3944
0
    #define WOLFSSL_MAX_TLS13_COOKIE_SZ 4096
3945
#endif
3946
#if WOLFSSL_MAX_TLS13_COOKIE_SZ > 65533
3947
    #error "WOLFSSL_MAX_TLS13_COOKIE_SZ must be <= 65533"
3948
#endif
3949
3950
/* Cookie extension information - cookie data. */
3951
typedef struct Cookie {
3952
    word16 len;
3953
    /* Ignore "nonstandard extension used : zero-sized array in struct/union"
3954
     * MSVC warning */
3955
    #ifdef _MSC_VER
3956
    #pragma warning(disable: 4200)
3957
    #endif
3958
    byte   data[WC_FLEXIBLE_ARRAY_SIZE];
3959
} Cookie;
3960
3961
WOLFSSL_LOCAL int TLSX_Cookie_Use(const WOLFSSL* ssl, const byte* data,
3962
        word16 len, byte* mac, byte macSz, int resp, TLSX** exts);
3963
WOLFSSL_LOCAL int TlsCheckCookie(const WOLFSSL* ssl, const byte* cookie,
3964
                                 word16 cookieSz);
3965
3966
3967
/* Key Share - TLS v1.3 Specification */
3968
3969
/* The KeyShare extension information - entry in a linked list. */
3970
typedef struct KeyShareEntry {
3971
    word16                group;     /* NamedGroup                        */
3972
    byte*                 ke;        /* Key exchange data                 */
3973
    word32                keLen;     /* Key exchange data length          */
3974
    void*                 key;       /* Key struct                        */
3975
    word32                keyLen;    /* Key size (bytes)                  */
3976
    byte*                 pubKey;    /* Public key                        */
3977
    word32                pubKeyLen; /* Public key length                 */
3978
#if !defined(NO_DH) || defined(WOLFSSL_HAVE_MLKEM)
3979
    byte*                 privKey;   /* Private key                       */
3980
    word32                privKeyLen;/* Private key length - PQC only     */
3981
#endif
3982
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
3983
    word16                session;   /* NamedGroup that was in session    */
3984
#endif
3985
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK) || \
3986
    defined(WOLFSSL_ASYNC_CRYPT)
3987
    /* Also under WOLFSSL_ASYNC_CRYPT: a pending operation retried on the
3988
     * same accept state re-enters the derive with the peer key freed, and
3989
     * this is the marker that stops the re-derive. */
3990
    word16                derived;   /* preMaster has been derived        */
3991
#endif
3992
#ifdef WOLFSSL_ASYNC_CRYPT
3993
    int                   lastRet;
3994
#endif
3995
    struct KeyShareEntry* next;      /* List pointer             */
3996
} KeyShareEntry;
3997
3998
WOLFSSL_LOCAL int TLSX_KeyShare_Use(const WOLFSSL* ssl, word16 group,
3999
        word16 len, byte* data, KeyShareEntry **kse, TLSX** extensions);
4000
WOLFSSL_LOCAL int TLSX_KeyShare_Empty(WOLFSSL* ssl);
4001
WOLFSSL_LOCAL int TLSX_KeyShare_SetSupported(const WOLFSSL* ssl,
4002
        TLSX** extensions);
4003
WOLFSSL_LOCAL int TLSX_KeyShare_GenKey(WOLFSSL *ssl, KeyShareEntry *kse);
4004
WOLFSSL_LOCAL int TLSX_KeyShare_Choose(const WOLFSSL *ssl, TLSX* extensions,
4005
        byte cipherSuite0, byte cipherSuite, KeyShareEntry** kse,
4006
        byte* searched);
4007
WOLFSSL_LOCAL int TLSX_KeyShare_Setup(WOLFSSL *ssl, KeyShareEntry* clientKSE);
4008
WOLFSSL_LOCAL int TLSX_KeyShare_Establish(WOLFSSL* ssl, int* doHelloRetry);
4009
WOLFSSL_LOCAL int TLSX_KeyShare_DeriveSecret(WOLFSSL* ssl);
4010
WOLFSSL_LOCAL int TLSX_KeyShare_Parse(WOLFSSL* ssl, const byte* input,
4011
        word16 length, byte msgType);
4012
WOLFSSL_LOCAL int TLSX_KeyShare_Parse_ClientHello(const WOLFSSL* ssl,
4013
        const byte* input, word16 length, TLSX** extensions);
4014
WOLFSSL_LOCAL int TLSX_KeyShare_HandlePqcHybridKeyServer(WOLFSSL* ssl,
4015
        KeyShareEntry* keyShareEntry, byte* data, word16 len);
4016
#ifdef WOLFSSL_DUAL_ALG_CERTS
4017
#ifdef WOLFSSL_API_PREFIX_MAP
4018
    #define TLSX_CKS_Parse wolfSSL_TLSX_CKS_Parse
4019
#endif
4020
WOLFSSL_TEST_VIS int TLSX_CKS_Parse(WOLFSSL* ssl, byte* input,
4021
                                 word16 length, TLSX** extensions);
4022
WOLFSSL_LOCAL int TLSX_CKS_Set(WOLFSSL* ssl, TLSX** extensions);
4023
#endif
4024
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
4025
4026
enum PskDecryptReturn {
4027
    PSK_DECRYPT_NONE = 0,
4028
    PSK_DECRYPT_OK,
4029
    PSK_DECRYPT_CREATE,
4030
    PSK_DECRYPT_FAIL
4031
};
4032
4033
#ifdef HAVE_SESSION_TICKET
4034
typedef struct psk_sess_free_cb_ctx {
4035
    word32 row;
4036
#ifdef HAVE_EXT_CACHE
4037
    int extCache;
4038
    int freeSess;
4039
#endif
4040
} psk_sess_free_cb_ctx;
4041
typedef void (psk_sess_free_cb)(const WOLFSSL* ssl, const WOLFSSL_SESSION* sess,
4042
        psk_sess_free_cb_ctx* freeCtx);
4043
#endif
4044
4045
/* The PreSharedKey extension information - entry in a linked list. */
4046
typedef struct PreSharedKey {
4047
    word16               identityLen;             /* Length of identity */
4048
    byte*                identity;                /* PSK identity       */
4049
    word32               ticketAge;               /* Age of the ticket  */
4050
    byte                 cipherSuite0;            /* Cipher Suite       */
4051
    byte                 cipherSuite;             /* Cipher Suite       */
4052
    word32               binderLen;               /* Length of HMAC     */
4053
    byte                 binder[WC_MAX_DIGEST_SIZE]; /* HMAC of handshake */
4054
    byte                 hmac;                    /* HMAC algorithm     */
4055
#ifdef HAVE_SESSION_TICKET
4056
    InternalTicket*      it;                      /* ptr to ticket      */
4057
    const WOLFSSL_SESSION* sess; /* ptr to session either from external cache or
4058
                                  * into SessionCache. Work around so that we
4059
                                  * don't call into the cache more than once */
4060
    psk_sess_free_cb* sess_free_cb;               /* callback to free sess */
4061
    psk_sess_free_cb_ctx sess_free_cb_ctx;        /* info for sess_free_cb */
4062
#endif
4063
    byte                 resumption:1;            /* Resumption PSK     */
4064
    byte                 chosen:1;                /* Server's choice    */
4065
    byte                 decryptRet:3;            /* Ticket decrypt return */
4066
    struct PreSharedKey* next;                    /* List pointer       */
4067
} PreSharedKey;
4068
4069
WOLFSSL_LOCAL int TLSX_PreSharedKey_WriteBinders(PreSharedKey* list,
4070
                                                 byte* output, byte msgType,
4071
                                                 word16* pSz);
4072
WOLFSSL_LOCAL int TLSX_PreSharedKey_GetSizeBinders(PreSharedKey* list,
4073
                                                   byte msgType, word16* pSz);
4074
WOLFSSL_LOCAL int TLSX_PreSharedKey_Use(TLSX** extensions, const byte* identity,
4075
                                        word16 len, word32 age, byte hmac,
4076
                                        byte cipherSuite0, byte cipherSuite,
4077
                                        byte resumption,
4078
                                        PreSharedKey **preSharedKey,
4079
                                        void* heap);
4080
WOLFSSL_LOCAL int TLSX_PreSharedKey_Parse_ClientHello(TLSX** extensions,
4081
                                  const byte* input, word16 length, void* heap);
4082
#if defined(WOLFSSL_CERT_WITH_EXTERN_PSK) && defined(WOLFSSL_TLS13)
4083
WOLFSSL_LOCAL int TLSX_CertWithExternPsk_Use(WOLFSSL* ssl);
4084
#endif
4085
4086
/* The possible Pre-Shared Key key exchange modes. */
4087
enum PskKeyExchangeMode {
4088
    PSK_KE,
4089
    PSK_DHE_KE
4090
};
4091
4092
/* User can define this. */
4093
#ifndef WOLFSSL_DEF_PSK_CIPHER
4094
#define WOLFSSL_DEF_PSK_CIPHER    TLS_AES_128_GCM_SHA256
4095
#endif
4096
4097
WOLFSSL_LOCAL int TLSX_PskKeyModes_Use(WOLFSSL* ssl, byte modes);
4098
WOLFSSL_LOCAL int TLSX_PskKeyModes_Parse_Modes(const byte* input, word16 length,
4099
                                              byte msgType, byte* modes);
4100
4101
#ifdef WOLFSSL_EARLY_DATA
4102
WOLFSSL_LOCAL int TLSX_EarlyData_Use(WOLFSSL* ssl, word32 max, int is_response);
4103
#endif
4104
#endif /* HAVE_SESSION_TICKET || !NO_PSK */
4105
4106
4107
/* The types of keys to derive for. */
4108
enum DeriveKeyType {
4109
    no_key,
4110
    early_data_key,
4111
    handshake_key,
4112
    traffic_key,
4113
    update_traffic_key
4114
};
4115
4116
WOLFSSL_LOCAL int DeriveEarlySecret(WOLFSSL* ssl);
4117
WOLFSSL_LOCAL int DeriveHandshakeSecret(WOLFSSL* ssl);
4118
#ifdef WOLFSSL_API_PREFIX_MAP
4119
    #define DeriveTls13Keys wolfSSL_DeriveTls13Keys
4120
#endif
4121
WOLFSSL_TEST_VIS int DeriveTls13Keys(WOLFSSL* ssl, int secret, int side, int store);
4122
WOLFSSL_LOCAL int DeriveMasterSecret(WOLFSSL* ssl);
4123
WOLFSSL_LOCAL int DeriveResumptionPSK(WOLFSSL* ssl, byte* nonce, byte nonceLen, byte* secret);
4124
WOLFSSL_LOCAL int DeriveResumptionSecret(WOLFSSL* ssl, byte* key);
4125
4126
WOLFSSL_LOCAL int Tls13_Exporter(WOLFSSL* ssl, unsigned char *out, size_t outLen,
4127
        const char *label, size_t labelLen,
4128
        const unsigned char *context, size_t contextLen);
4129
4130
/* The key update request values for KeyUpdate message. */
4131
enum KeyUpdateRequest {
4132
    update_not_requested,
4133
    update_requested
4134
};
4135
#endif /* WOLFSSL_TLS13 */
4136
4137
#ifdef WOLFSSL_DTLS_CID
4138
WOLFSSL_LOCAL void TLSX_ConnectionID_Free(byte* ext, void* heap);
4139
WOLFSSL_LOCAL word16 TLSX_ConnectionID_Write(byte* ext, byte* output);
4140
WOLFSSL_LOCAL word16 TLSX_ConnectionID_GetSize(byte* ext);
4141
WOLFSSL_LOCAL int TLSX_ConnectionID_Use(WOLFSSL* ssl);
4142
WOLFSSL_LOCAL int TLSX_ConnectionID_Parse(WOLFSSL* ssl, const byte* input,
4143
    word16 length, byte isRequest);
4144
WOLFSSL_LOCAL void DtlsCIDOnExtensionsParsed(WOLFSSL* ssl);
4145
WOLFSSL_LOCAL byte DtlsCIDIsNegotiated(WOLFSSL* ssl);
4146
WOLFSSL_LOCAL byte DtlsCIDCheck(WOLFSSL* ssl, const byte* input,
4147
    word16 inputSize);
4148
WOLFSSL_LOCAL int DtlsCidReplaceTx(WOLFSSL* ssl, const byte* cid, byte size);
4149
WOLFSSL_LOCAL int Dtls13UnifiedHeaderCIDPresent(byte flags);
4150
#endif /* WOLFSSL_DTLS_CID */
4151
WOLFSSL_LOCAL byte DtlsGetCidTxSize(WOLFSSL* ssl);
4152
WOLFSSL_LOCAL byte DtlsGetCidRxSize(WOLFSSL* ssl);
4153
4154
#ifdef OPENSSL_EXTRA
4155
enum SetCBIO {
4156
    WOLFSSL_CBIO_NONE = 0,
4157
    WOLFSSL_CBIO_RECV = 0x1,
4158
    WOLFSSL_CBIO_SEND = 0x2,
4159
};
4160
#endif
4161
4162
#ifdef WOLFSSL_STATIC_EPHEMERAL
4163
/* contains static ephemeral keys */
4164
typedef struct {
4165
#ifndef NO_DH
4166
    DerBuffer* dhKey;
4167
#endif
4168
#ifdef HAVE_ECC
4169
    DerBuffer* ecKey;
4170
#endif
4171
#ifdef HAVE_CURVE25519
4172
    DerBuffer* x25519Key;
4173
#endif
4174
#ifdef HAVE_CURVE448
4175
    DerBuffer* x448Key;
4176
#endif
4177
} StaticKeyExchangeInfo_t;
4178
#endif /* WOLFSSL_STATIC_EPHEMERAL */
4179
4180
4181
/* wolfSSL context type */
4182
struct WOLFSSL_CTX {
4183
    WOLFSSL_METHOD* method;
4184
#ifdef SINGLE_THREADED
4185
    WC_RNG*         rng;          /* to be shared with WOLFSSL w/o locking */
4186
#endif
4187
    wolfSSL_RefWithMutex ref;
4188
    int         err;              /* error code in case of mutex not created */
4189
#ifndef NO_DH
4190
    buffer      serverDH_P;
4191
    buffer      serverDH_G;
4192
#endif
4193
#ifndef NO_CERTS
4194
    DerBuffer*  certificate;
4195
    DerBuffer*  certChain;
4196
    int         certChainCnt;
4197
                 /* chain after self, in DER, with leading size for each cert */
4198
    #ifndef WOLFSSL_NO_CA_NAMES
4199
    WOLF_STACK_OF(WOLFSSL_X509_NAME)* client_ca_names;
4200
    WOLF_STACK_OF(WOLFSSL_X509_NAME)* ca_names;
4201
    #endif
4202
    #ifdef OPENSSL_EXTRA
4203
    WOLF_STACK_OF(WOLFSSL_X509)* x509Chain;
4204
    #endif
4205
#ifdef WOLFSSL_CERT_SETUP_CB
4206
#ifdef OPENSSL_EXTRA
4207
    client_cert_cb CBClientCert;  /* client certificate callback */
4208
#endif
4209
    CertSetupCallback  certSetupCb;
4210
    void*              certSetupCbArg;
4211
#endif
4212
    DerBuffer*  privateKey;
4213
#ifdef WOLFSSL_BLIND_PRIVATE_KEY
4214
    DerBuffer*  privateKeyMask;             /* Mask of private key DER. */
4215
#endif
4216
    byte        privateKeyType;
4217
    byte        privateKeyId:1;
4218
    byte        privateKeyLabel:1;
4219
    int         privateKeySz;
4220
    int         privateKeyDevId;
4221
4222
#ifdef WOLFSSL_DUAL_ALG_CERTS
4223
    DerBuffer*  altPrivateKey;
4224
#ifdef WOLFSSL_BLIND_PRIVATE_KEY
4225
    DerBuffer*  altPrivateKeyMask;          /* Mask of alt private key DER. */
4226
#endif
4227
    byte        altPrivateKeyType;
4228
    byte        altPrivateKeyId:1;
4229
    byte        altPrivateKeyLabel:1;
4230
    int         altPrivateKeySz;
4231
    int         altPrivateKeyDevId;
4232
#endif /* WOLFSSL_DUAL_ALG_CERTS */
4233
#ifdef OPENSSL_ALL
4234
    /* note it is the privateKeyPKey pointer that is volatile, not the object it
4235
     * points to:
4236
     */
4237
    WOLFSSL_EVP_PKEY* volatile privateKeyPKey;
4238
#endif
4239
    WOLFSSL_CERT_MANAGER* cm;      /* our cert manager, ctx owns SSL will use */
4240
#endif
4241
#ifdef KEEP_OUR_CERT
4242
    WOLFSSL_X509*    ourCert;     /* keep alive a X509 struct of cert */
4243
    int              ownOurCert;  /* Dispose of certificate if we own */
4244
#endif
4245
    Suites*     suites;           /* make dynamic, user may not need/set */
4246
    void*       heap;             /* for user memory overrides */
4247
    byte        verifyDepth;
4248
    byte        verifyPeer:1;
4249
    byte        verifyNone:1;
4250
    byte        failNoCert:1;
4251
    byte        failNoCertxPSK:1; /* fail if no cert with the exception of PSK*/
4252
    byte        failNoPSK:1;      /* fail if no PSK is negotiated */
4253
    byte        sessionCacheOff:1;
4254
    byte        sessionCacheFlushOff:1;
4255
#ifdef HAVE_EXT_CACHE
4256
    byte        internalCacheOff:1;
4257
    byte        internalCacheLookupOff:1;
4258
#endif
4259
    byte        sendVerify:2;     /* for client side (can not be single bit) */
4260
    byte        haveRSA:1;        /* RSA available */
4261
    byte        haveECC:1;        /* ECC available */
4262
    byte        haveDH:1;         /* server DH params set by user */
4263
    byte        haveECDSAsig:1;   /* server cert signed w/ ECDSA */
4264
    byte        haveFalconSig:1;  /* server cert signed w/ Falcon */
4265
    byte        haveMlDsaSig:1;   /* server cert signed w/ ML-DSA */
4266
    byte        haveSlhDsaSig:1;  /* server cert signed w/ SLH-DSA */
4267
    byte        haveStaticECC:1;  /* static server ECC private key */
4268
    byte        partialWrite:1;   /* only one msg per write call */
4269
    byte        autoRetry:1;      /* retry read/write on a WANT_{READ|WRITE} */
4270
    byte        quietShutdown:1;  /* don't send close notify */
4271
    byte        groupMessages:1;  /* group handshake messages before sending */
4272
    byte        minDowngrade;     /* minimum downgrade version */
4273
    byte        haveEMS:1;        /* have extended master secret extension */
4274
#ifdef HAVE_EXTENDED_MASTER
4275
    byte        disableEMS:1;     /* user disabled extended master secret,
4276
                                   * ignore peer's EMS request (server) and
4277
                                   * don't advertise it (client) */
4278
    byte        requireEMS:1;     /* user requires extended master secret,
4279
                                   * abort if EMS is not negotiated */
4280
#endif
4281
    byte        useClientOrder:1; /* Use client's cipher preference order */
4282
#if defined(HAVE_SESSION_TICKET)
4283
    byte        noTicketTls12:1;  /* TLS 1.2 server won't send ticket */
4284
#endif
4285
#ifdef WOLFSSL_TLS13
4286
    #if defined(HAVE_SESSION_TICKET) && !defined(NO_WOLFSSL_SERVER)
4287
    unsigned int maxTicketTls13;  /* maximum number of tickets to send */
4288
    #endif
4289
    byte        noTicketTls13:1;  /* TLS 1.3 Server won't create new Ticket */
4290
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
4291
    byte        noPskDheKe:1;     /* Don't use (EC)DHE with PSK */
4292
#ifdef HAVE_SUPPORTED_CURVES
4293
    byte        onlyPskDheKe:1;   /* Only use (EC)DHE with PSK */
4294
#endif
4295
#if defined(WOLFSSL_CERT_WITH_EXTERN_PSK)
4296
    byte        certWithExternPsk:1; /* Use tls_cert_with_extern_psk extension */
4297
#endif
4298
#endif
4299
#endif /* WOLFSSL_TLS13 */
4300
    byte        mutualAuth:1;     /* Mutual authentication required */
4301
#if defined(WOLFSSL_TLS13) && defined(WOLFSSL_POST_HANDSHAKE_AUTH)
4302
    byte        postHandshakeAuth:1;  /* Post-handshake auth supported. */
4303
    byte        verifyPostHandshake:1; /* Only send client cert req post
4304
                                        * handshake, not also during */
4305
#endif
4306
#ifndef NO_DH
4307
    #if !defined(WOLFSSL_OLD_PRIME_CHECK) && !defined(HAVE_FIPS) && \
4308
        !defined(HAVE_SELFTEST)
4309
    byte        dhKeyTested:1;   /* Set when key has been tested. */
4310
    #endif
4311
#endif
4312
#if defined(HAVE_SECURE_RENEGOTIATION) || defined(HAVE_SERVER_RENEGOTIATION_INFO)
4313
    byte        useSecureReneg:1; /* when set will set WOLFSSL objects generated to enable */
4314
#endif
4315
#if !defined(NO_WOLFSSL_CLIENT) && !defined(WOLFSSL_NO_TLS12) && \
4316
    defined(HAVE_SERVER_RENEGOTIATION_INFO) && \
4317
    !defined(WOLFSSL_HARDEN_TLS_NO_SCR_CHECK)
4318
    byte        scr_check_enabled:1; /* require server renegotiation_info on the
4319
                                      * initial handshake (RFC 5746/9325);
4320
                                      * inherited by WOLFSSL objects */
4321
#endif
4322
#ifdef HAVE_ENCRYPT_THEN_MAC
4323
    byte        disallowEncThenMac:1;  /* Don't do Encrypt-Then-MAC */
4324
#endif
4325
#ifdef WOLFSSL_STATIC_MEMORY
4326
    byte        onHeapHint:1; /* whether the ctx/method is put on heap hint */
4327
#endif
4328
#if defined(WOLFSSL_STATIC_EPHEMERAL) && !defined(SINGLE_THREADED)
4329
    byte        staticKELockInit:1;
4330
#endif
4331
#if defined(WOLFSSL_DTLS) && defined(WOLFSSL_SCTP)
4332
    byte        dtlsSctp:1;         /* DTLS-over-SCTP mode */
4333
#endif
4334
#if defined(WOLFSSL_TLS13) && defined(HAVE_ECH)
4335
    byte        disableECH:1;
4336
    byte        enableEchTrialDecrypt:1;  /* Trial decryption of the
4337
                                             inner hello */
4338
#endif
4339
    word16      minProto:1; /* sets min to min available */
4340
    word16      maxProto:1; /* sets max to max available */
4341
#if defined(HAVE_RPK)
4342
    RpkConfig   rpkConfig;
4343
    RpkState    rpkState;
4344
#endif /* HAVE_RPK */
4345
#ifdef WOLFSSL_SRTP
4346
    word16      dtlsSrtpProfiles;  /* DTLS-with-SRTP mode
4347
                                    * (list of selected profiles - up to 16) */
4348
#endif
4349
#if defined(WOLFSSL_DTLS) && defined(WOLFSSL_MULTICAST)
4350
    byte        haveMcast;        /* multicast requested */
4351
    byte        mcastID;          /* multicast group ID */
4352
#endif
4353
#if defined(WOLFSSL_DTLS) && \
4354
    (defined(WOLFSSL_SCTP) || defined(WOLFSSL_DTLS_MTU))
4355
    word16      dtlsMtuSz;        /* DTLS MTU size */
4356
#endif
4357
#ifndef NO_DH
4358
    word16      minDhKeySz;       /* minimum DH key size */
4359
    word16      maxDhKeySz;       /* maximum DH key size */
4360
#endif
4361
#ifndef NO_RSA
4362
    short       minRsaKeySz;      /* minimum RSA key size */
4363
#ifdef WC_RSA_PSS
4364
    word8       useRsaPss;        /* cert supports RSA-PSS */
4365
#endif
4366
#endif
4367
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || defined(HAVE_ED448)
4368
    short       minEccKeySz;      /* minimum ECC key size */
4369
#endif
4370
#ifdef HAVE_FALCON
4371
    short       minFalconKeySz;   /* minimum Falcon key size */
4372
#endif
4373
#ifdef WOLFSSL_HAVE_MLDSA
4374
    short       minMlDsaKeySz;    /* minimum ML-DSA key size */
4375
#endif
4376
    unsigned long     mask;             /* store SSL_OP_ flags */
4377
#if defined(OPENSSL_EXTRA) || defined(HAVE_CURL)
4378
    word32            disabledCurves;   /* curves disabled by user */
4379
#endif
4380
#ifdef WOLFSSL_SESSION_ID_CTX
4381
    byte              sessionCtx[ID_LEN]; /* app session context ID */
4382
    byte              sessionCtxSz;
4383
#endif
4384
#ifdef OPENSSL_EXTRA
4385
    const unsigned char *alpn_cli_protos;/* ALPN client protocol list */
4386
    unsigned int         alpn_cli_protos_len;
4387
    byte              cbioFlag;  /* WOLFSSL_CBIO_RECV/SEND: CBIORecv/Send is set */
4388
    CallbackInfoState* CBIS;      /* used to get info about SSL state */
4389
    WOLFSSL_X509_VERIFY_PARAM* param;    /* verification parameters*/
4390
#endif
4391
#ifdef WOLFSSL_WOLFSENTRY_HOOKS
4392
    NetworkFilterCallback_t AcceptFilter;
4393
    void *AcceptFilter_arg;
4394
    NetworkFilterCallback_t ConnectFilter;
4395
    void *ConnectFilter_arg;
4396
#endif /* WOLFSSL_WOLFSENTRY_HOOKS */
4397
    CallbackIORecv CBIORecv;
4398
    CallbackIOSend CBIOSend;
4399
#ifdef WOLFSSL_DTLS
4400
    CallbackGenCookie CBIOCookie;       /* gen cookie callback */
4401
#endif /* WOLFSSL_DTLS */
4402
#ifdef WOLFSSL_SESSION_EXPORT
4403
#ifdef WOLFSSL_DTLS
4404
    wc_dtls_export  dtls_export;        /* export function for DTLS session */
4405
#endif
4406
    CallbackGetPeer CBGetPeer;
4407
    CallbackSetPeer CBSetPeer;
4408
#endif
4409
    VerifyCallback  verifyCallback;     /* cert verification callback */
4410
    void*           verifyCbCtx;        /* cert verify callback user ctx*/
4411
#ifdef OPENSSL_ALL
4412
    CertVerifyCallback verifyCertCb;
4413
    void*              verifyCertCbArg;
4414
#endif /* OPENSSL_ALL */
4415
#ifdef OPENSSL_EXTRA
4416
    SSL_Msg_Cb      protoMsgCb;         /* inspect protocol message callback */
4417
    void*           protoMsgCtx;        /* user set context with msg callback */
4418
#endif
4419
    word32          timeout;            /* session timeout */
4420
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || defined(HAVE_CURVE25519) || \
4421
    defined(HAVE_ED448)
4422
    word32          ecdhCurveOID;       /* curve Ecc_Sum */
4423
#endif
4424
#ifdef HAVE_ECC
4425
    word16          eccTempKeySz;       /* in octets 20 - 66 */
4426
#endif
4427
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || defined(HAVE_ED448) || \
4428
    defined(HAVE_FALCON) || defined(WOLFSSL_HAVE_MLDSA) || \
4429
    defined(WOLFSSL_HAVE_SLHDSA)
4430
    word32          pkCurveOID;         /* curve Ecc_Sum */
4431
#endif
4432
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
4433
    byte        havePSK;                /* psk key set by user */
4434
    wc_psk_client_callback client_psk_cb;  /* client callback */
4435
    wc_psk_server_callback server_psk_cb;  /* server callback */
4436
#ifdef WOLFSSL_TLS13
4437
    wc_psk_client_cs_callback    client_psk_cs_cb;     /* client callback */
4438
    wc_psk_client_tls13_callback client_psk_tls13_cb;  /* client callback */
4439
    wc_psk_server_tls13_callback server_psk_tls13_cb;  /* server callback */
4440
#endif
4441
    void*       psk_ctx;
4442
    char        server_hint[MAX_PSK_ID_LEN + NULL_TERM_LEN];
4443
#endif /* HAVE_SESSION_TICKET || !NO_PSK */
4444
#ifdef WOLFSSL_TLS13
4445
    word16          group[WOLFSSL_MAX_GROUP_COUNT];
4446
    byte            numGroups;
4447
#endif
4448
#ifdef WOLFSSL_EARLY_DATA
4449
    word32          maxEarlyDataSz;
4450
#if defined(WOLFSSL_TLS13) && defined(HAVE_SESSION_TICKET) && !defined(NO_TLS)
4451
    /* RFC 8446 Section 8.2: reject 0-RTT for tickets minted before this
4452
     * context was created. */
4453
#ifdef WOLFSSL_32BIT_MILLI_TIME
4454
    word32          ticketStartTime;    /* Ctx creation time (ms) */
4455
#else
4456
    sword64         ticketStartTime;    /* Ctx creation time (ms) */
4457
#endif
4458
    byte            noFreshStartCheck:1; /* Skip the fresh start check */
4459
#endif
4460
#endif
4461
#ifdef HAVE_ANON
4462
    byte        useAnon;               /* User wants to allow Anon suites */
4463
#endif /* HAVE_ANON */
4464
#ifdef WOLFSSL_ENCRYPTED_KEYS
4465
    wc_pem_password_cb* passwd_cb;
4466
    void*               passwd_userdata;
4467
#endif
4468
#ifdef WOLFSSL_LOCAL_X509_STORE
4469
    WOLFSSL_X509_STORE x509_store; /* points to ctx->cm */
4470
    WOLFSSL_X509_STORE* x509_store_pt; /* take ownership of external store */
4471
#endif
4472
#if defined(OPENSSL_EXTRA) || defined(HAVE_WEBSERVER) || \
4473
    defined(WOLFSSL_WPAS_SMALL) || defined(WOLFSSL_TLS_READ_AHEAD)
4474
    byte            readAhead;
4475
#endif
4476
#if defined(OPENSSL_EXTRA) || defined(WOLFSSL_TLS_READ_AHEAD)
4477
    /* Read-ahead coalescing buffer size. 0 = use one record (default). See
4478
     * wolfSSL_CTX_set_default_read_buffer_len(). */
4479
    word32          readAheadSz;
4480
#endif
4481
#if defined(OPENSSL_EXTRA) || defined(HAVE_WEBSERVER) || defined(WOLFSSL_WPAS_SMALL)
4482
    void*           userPRFArg; /* passed to prf callback */
4483
#endif
4484
#ifdef HAVE_EX_DATA
4485
    WOLFSSL_CRYPTO_EX_DATA ex_data;
4486
#endif
4487
#if defined(HAVE_ALPN) && (defined(OPENSSL_ALL) || defined(WOLFSSL_NGINX) || \
4488
    defined(WOLFSSL_HAPROXY) || defined(HAVE_LIGHTY) || defined(WOLFSSL_QUIC))
4489
    CallbackALPNSelect alpnSelect;
4490
    void*              alpnSelectArg;
4491
#endif
4492
#ifdef HAVE_SNI
4493
    CallbackSniRecv sniRecvCb;
4494
    void*           sniRecvCbArg;
4495
#endif
4496
#if defined(WOLFSSL_MULTICAST) && defined(WOLFSSL_DTLS)
4497
    CallbackMcastHighwater mcastHwCb; /* Sequence number highwater callback */
4498
    word32      mcastFirstSeq;    /* first trigger level */
4499
    word32      mcastSecondSeq;   /* second trigger level */
4500
    word32      mcastMaxSeq;      /* max level */
4501
#endif
4502
#ifdef HAVE_OCSP
4503
    WOLFSSL_OCSP      ocsp;
4504
#endif
4505
    int             devId;              /* async device id to use */
4506
#ifdef HAVE_TLS_EXTENSIONS
4507
    TLSX* extensions;                  /* RFC 6066 TLS Extensions data */
4508
    #ifdef OPENSSL_EXTRA
4509
        WOLFSSL_CustomExt* customExt;  /* App-defined custom TLS extensions */
4510
    #endif
4511
    #ifndef NO_WOLFSSL_SERVER
4512
        #if defined(HAVE_CERTIFICATE_STATUS_REQUEST) \
4513
         || defined(HAVE_CERTIFICATE_STATUS_REQUEST_V2)
4514
            OcspRequest* certOcspRequest;
4515
            ocspVerifyStatusCb ocspStatusVerifyCb;
4516
            void* ocspStatusVerifyCbArg;
4517
        #endif
4518
        #if defined(HAVE_CERTIFICATE_STATUS_REQUEST_V2)
4519
            OcspRequest* chainOcspRequest[MAX_CHAIN_DEPTH];
4520
        #endif
4521
    #endif
4522
    #if defined(HAVE_SESSION_TICKET) && !defined(NO_WOLFSSL_SERVER)
4523
        SessionTicketEncCb ticketEncCb;   /* enc/dec session ticket Cb */
4524
        void*              ticketEncCtx;  /* session encrypt context */
4525
        #if defined(OPENSSL_ALL) || defined(WOLFSSL_NGINX) || defined(WOLFSSL_HAPROXY) \
4526
          || defined(OPENSSL_EXTRA) || defined(HAVE_LIGHTY)
4527
        ticketCompatCb     ticketEncWrapCb; /* callback for OpenSSL ticket key callback */
4528
        #endif
4529
        int                ticketHint;    /* ticket hint in seconds */
4530
        #ifndef WOLFSSL_NO_DEF_TICKET_ENC_CB
4531
            TicketEncCbCtx ticketKeyCtx;
4532
        #endif
4533
    #endif
4534
    #endif
4535
    #ifdef HAVE_SUPPORTED_CURVES
4536
        byte userCurves;                  /* indicates user called wolfSSL_CTX_UseSupportedCurve */
4537
    #endif
4538
#ifdef ATOMIC_USER
4539
    CallbackMacEncrypt    MacEncryptCb;    /* Atomic User Mac/Encrypt Cb */
4540
    CallbackDecryptVerify DecryptVerifyCb; /* Atomic User Decrypt/Verify Cb */
4541
    #ifdef HAVE_ENCRYPT_THEN_MAC
4542
        CallbackEncryptMac    EncryptMacCb;    /* Atomic User Mac/Enc Cb */
4543
        CallbackVerifyDecrypt VerifyDecryptCb; /* Atomic User Dec/Verify Cb */
4544
    #endif
4545
#endif
4546
#ifdef HAVE_PK_CALLBACKS
4547
    #ifdef HAVE_ECC
4548
        CallbackEccKeyGen EccKeyGenCb;  /* User EccKeyGen Callback Handler */
4549
        CallbackEccSign   EccSignCb;    /* User EccSign   Callback handler */
4550
        void*             EccSignCtx;   /* Ecc Sign       Callback Context */
4551
        CallbackEccVerify EccVerifyCb;  /* User EccVerify Callback handler */
4552
        CallbackEccSharedSecret EccSharedSecretCb; /* User EccVerify Callback handler */
4553
    #endif /* HAVE_ECC */
4554
    #ifdef HAVE_HKDF
4555
        CallbackHKDFExtract HkdfExtractCb; /* User hkdf Extract Callback handler */
4556
    #endif
4557
    #ifdef HAVE_ED25519
4558
        /* User Ed25519Sign   Callback handler */
4559
        CallbackEd25519Sign   Ed25519SignCb;
4560
        /* User Ed25519Verify Callback handler */
4561
        CallbackEd25519Verify Ed25519VerifyCb;
4562
    #endif
4563
    #ifdef HAVE_CURVE25519
4564
        /* User X25519 KeyGen Callback Handler */
4565
        CallbackX25519KeyGen X25519KeyGenCb;
4566
        /* User X25519 SharedSecret Callback handler */
4567
        CallbackX25519SharedSecret X25519SharedSecretCb;
4568
    #endif
4569
    #ifdef HAVE_ED448
4570
        /* User Ed448Sign   Callback handler */
4571
        CallbackEd448Sign   Ed448SignCb;
4572
        /* User Ed448Verify Callback handler */
4573
        CallbackEd448Verify Ed448VerifyCb;
4574
    #endif
4575
    #ifdef HAVE_CURVE448
4576
        /* User X448 KeyGen Callback Handler */
4577
        CallbackX448KeyGen X448KeyGenCb;
4578
        /* User X448 SharedSecret Callback handler */
4579
        CallbackX448SharedSecret X448SharedSecretCb;
4580
    #endif
4581
    #ifndef NO_DH
4582
        /* User DH KeyGen Callback handler*/
4583
        CallbackDhGenerateKeyPair DhGenerateKeyPairCb;
4584
        /* User DH Agree Callback handler */
4585
        CallbackDhAgree DhAgreeCb;
4586
    #endif
4587
    #ifndef NO_RSA
4588
        /* User RsaSign Callback handler (priv key) */
4589
        CallbackRsaSign   RsaSignCb;
4590
        /* User RsaVerify Callback handler (pub key) */
4591
        CallbackRsaVerify RsaVerifyCb;
4592
        /* User VerifyRsaSign Callback handler (priv key) */
4593
        CallbackRsaVerify RsaSignCheckCb;
4594
        #ifdef WC_RSA_PSS
4595
            /* User RsaSign (priv key) */
4596
            CallbackRsaPssSign   RsaPssSignCb;
4597
            /* User RsaVerify (pub key) */
4598
            CallbackRsaPssVerify RsaPssVerifyCb;
4599
            /* User VerifyRsaSign (priv key) */
4600
            CallbackRsaPssVerify RsaPssSignCheckCb;
4601
        #endif
4602
        CallbackRsaEnc    RsaEncCb;     /* User Rsa Public Encrypt  handler */
4603
        CallbackRsaDec    RsaDecCb;     /* User Rsa Private Decrypt handler */
4604
    #endif /* NO_RSA */
4605
4606
    /* User generate pre-master handler */
4607
    CallbackGenPreMaster        GenPreMasterCb;
4608
    /* User generate master secret handler */
4609
    CallbackGenMasterSecret     GenMasterCb;
4610
    /* User generate Extended master secret handler */
4611
    CallbackGenExtMasterSecret  GenExtMasterCb;
4612
    /* User generate session key handler */
4613
    CallbackGenSessionKey       GenSessionKeyCb;
4614
    /* User setting encrypt keys handler */
4615
    CallbackEncryptKeys         EncryptKeysCb;
4616
    /* User Tls finished handler */
4617
    CallbackTlsFinished         TlsFinishedCb;
4618
#if !defined(WOLFSSL_NO_TLS12) && !defined(WOLFSSL_AEAD_ONLY)
4619
    /* User Verify mac handler */
4620
    CallbackVerifyMac           VerifyMacCb;
4621
#endif
4622
#if defined(WOLFSSL_PUBLIC_ASN)
4623
    /* User handler to process a certificate */
4624
    CallbackProcessPeerCert ProcessPeerCertCb;
4625
#endif
4626
    /* User handler to process the server's key exchange public key */
4627
    CallbackProcessServerSigKex ProcessServerSigKexCb;
4628
    /* User handler to process the TLS record */
4629
    CallbackPerformTlsRecordProcessing PerformTlsRecordProcessingCb;
4630
    /* User handler to do HKDF expansions */
4631
    CallbackHKDFExpandLabel HKDFExpandLabelCb;
4632
4633
#endif /* HAVE_PK_CALLBACKS */
4634
#ifdef HAVE_WOLF_EVENT
4635
    WOLF_EVENT_QUEUE event_queue;
4636
#endif /* HAVE_WOLF_EVENT */
4637
#ifdef HAVE_EXT_CACHE
4638
    WOLFSSL_SESSION*(*get_sess_cb)(WOLFSSL*, const unsigned char*, int, int*);
4639
    int (*new_sess_cb)(WOLFSSL*, WOLFSSL_SESSION*);
4640
#endif
4641
#if defined(HAVE_EXT_CACHE) || defined(HAVE_EX_DATA)
4642
    Rem_Sess_Cb rem_sess_cb;
4643
#endif
4644
#if defined(OPENSSL_EXTRA) && defined(WOLFCRYPT_HAVE_SRP) && !defined(NO_SHA256)
4645
    Srp*  srp;  /* TLS Secure Remote Password Protocol*/
4646
    byte* srp_password;
4647
#endif
4648
#if defined(OPENSSL_EXTRA) && defined(HAVE_SECRET_CALLBACK)
4649
    wolfSSL_CTX_keylog_cb_func keyLogCb;
4650
#endif /* OPENSSL_EXTRA && HAVE_SECRET_CALLBACK */
4651
#ifdef WOLFSSL_STATIC_EPHEMERAL
4652
    StaticKeyExchangeInfo_t staticKE;
4653
    #ifndef SINGLE_THREADED
4654
    wolfSSL_Mutex staticKELock;
4655
    #endif
4656
#endif
4657
#ifdef WOLFSSL_QUIC
4658
    struct {
4659
        const WOLFSSL_QUIC_METHOD *method;
4660
    } quic;
4661
#endif
4662
#if defined(WOLFSSL_TLS13) && defined(HAVE_ECH)
4663
    WOLFSSL_EchConfig* echConfigs;
4664
#endif
4665
#if defined(__APPLE__) && defined(WOLFSSL_SYS_CA_CERTS)
4666
    byte doAppleNativeCertValidationFlag:1;
4667
#endif /* defined(__APPLE__) && defined(WOLFSSL_SYS_CA_CERTS) */
4668
#ifdef WOLFSSL_DUAL_ALG_CERTS
4669
    byte *sigSpec;
4670
    word16 sigSpecSz;
4671
#endif
4672
#if defined(WOLFSSL_SYS_CRYPTO_POLICY)
4673
    int secLevel; /* The security level of system-wide crypto policy. */
4674
#endif /* WOLFSSL_SYS_CRYPTO_POLICY */
4675
4676
#ifdef WOLFSSL_TEST_APPLE_NATIVE_CERT_VALIDATION
4677
    CFMutableArrayRef testTrustedCAs;
4678
#endif /* WOLFSSL_TEST_APPLE_NATIVE_CERT_VALIDATION */
4679
};
4680
4681
WOLFSSL_LOCAL
4682
int InitSSL_Ctx(WOLFSSL_CTX* ctx, WOLFSSL_METHOD* method, void* heap);
4683
WOLFSSL_LOCAL
4684
void FreeSSL_Ctx(WOLFSSL_CTX* ctx);
4685
WOLFSSL_LOCAL
4686
void SSL_CtxResourceFree(WOLFSSL_CTX* ctx);
4687
4688
#ifdef HAVE_EX_DATA_CLEANUP_HOOKS
4689
    #ifndef HAVE_EX_DATA
4690
        #error "HAVE_EX_DATA_CLEANUP_HOOKS requires HAVE_EX_DATA to be defined"
4691
    #endif
4692
void wolfSSL_CRYPTO_cleanup_ex_data(WOLFSSL_CRYPTO_EX_DATA* ex_data);
4693
#endif
4694
4695
WOLFSSL_LOCAL
4696
int DeriveTlsKeys(WOLFSSL* ssl);
4697
WOLFSSL_LOCAL
4698
int ProcessOldClientHello(WOLFSSL* ssl, const byte* input, word32* inOutIdx,
4699
                          word32 inSz, word16 sz);
4700
4701
#ifndef NO_CERTS
4702
    WOLFSSL_LOCAL int AddSigner(WOLFSSL_CERT_MANAGER* cm, Signer *s);
4703
    WOLFSSL_LOCAL
4704
    int AddCA(WOLFSSL_CERT_MANAGER* cm, DerBuffer** pDer, int type, int verify);
4705
    WOLFSSL_LOCAL int RemoveCA(WOLFSSL_CERT_MANAGER* cm, byte* hash, int type);
4706
    WOLFSSL_LOCAL int SetCAType(WOLFSSL_CERT_MANAGER* cm, byte* hash, int type);
4707
    WOLFSSL_LOCAL
4708
    int AlreadySigner(WOLFSSL_CERT_MANAGER* cm, byte* hash);
4709
#ifdef WOLFSSL_TRUST_PEER_CERT
4710
    WOLFSSL_LOCAL
4711
    int AddTrustedPeer(WOLFSSL_CERT_MANAGER* cm, DerBuffer** pDer, int verify);
4712
    WOLFSSL_LOCAL
4713
    int AlreadyTrustedPeer(WOLFSSL_CERT_MANAGER* cm, DecodedCert* cert);
4714
#endif
4715
#endif
4716
4717
#ifdef WOLFSSL_TEST_APPLE_NATIVE_CERT_VALIDATION
4718
    WOLFSSL_API
4719
    int wolfSSL_TestAppleNativeCertValidation_AppendCA(WOLFSSL_CTX* ctx,
4720
                                                    const byte* derCert,
4721
                                                    int derLen);
4722
#endif /* WOLFSSL_TEST_APPLE_NATIVE_CERT_VALIDATION */
4723
4724
/* All cipher suite related info
4725
 * Keep as a constant size (no ifdefs) for session export */
4726
typedef struct CipherSpecs {
4727
    word16 key_size;
4728
    word16 iv_size;
4729
    word16 block_size;
4730
    word16 aead_mac_size;
4731
    byte bulk_cipher_algorithm;
4732
    byte cipher_type;               /* block, stream, or aead */
4733
    byte mac_algorithm;
4734
    byte kea;                       /* key exchange algo */
4735
    byte sig_algo;
4736
    byte hash_size;
4737
    byte pad_size;
4738
    byte static_ecdh;
4739
} CipherSpecs;
4740
4741
4742
void InitCipherSpecs(CipherSpecs* cs);
4743
4744
4745
/* Supported Key Exchange Protocols */
4746
enum KeyExchangeAlgorithm {
4747
    no_kea,
4748
    rsa_kea,
4749
    diffie_hellman_kea,
4750
    fortezza_kea,
4751
    psk_kea,
4752
    dhe_psk_kea,
4753
    ecdhe_psk_kea,
4754
    ecc_diffie_hellman_kea,
4755
    ecc_static_diffie_hellman_kea,      /* for verify suite only */
4756
    any_kea
4757
};
4758
4759
/* Used with InitSuitesHashSigAlgo */
4760
0
#define SIG_ECDSA       0x01
4761
0
#define SIG_RSA         0x02
4762
0
#define SIG_SM2         0x04
4763
0
#define SIG_FALCON      0x08
4764
0
#define SIG_MLDSA       0x10
4765
#define SIG_ANON        0x20
4766
0
#define SIG_SLHDSA      0x40
4767
/* SIG_ANON is omitted by default */
4768
0
#define SIG_ALL         (SIG_ECDSA | SIG_RSA | SIG_SM2 | SIG_FALCON | \
4769
0
                         SIG_MLDSA | SIG_SLHDSA)
4770
4771
/* Supported Authentication Schemes */
4772
enum SignatureAlgorithm {
4773
    anonymous_sa_algo            = 0,
4774
    rsa_sa_algo                  = 1,
4775
    dsa_sa_algo                  = 2,
4776
    ecc_dsa_sa_algo              = 3,
4777
    rsa_pss_sa_algo              = 8,
4778
    ed25519_sa_algo              = 9,
4779
    rsa_pss_pss_algo             = 10,
4780
    ed448_sa_algo                = 11,
4781
    falcon_level1_sa_algo        = 12,
4782
    falcon_level5_sa_algo        = 13,
4783
    mldsa_44_sa_algo             = 14,
4784
    mldsa_65_sa_algo             = 15,
4785
    mldsa_87_sa_algo             = 16,
4786
    sm2_sa_algo                  = 17,
4787
    any_sa_algo                  = 18,
4788
    ecc_brainpool_sa_algo        = 19,
4789
    slhdsa_sha2_128s_sa_algo     = 20,
4790
    slhdsa_sha2_128f_sa_algo     = 21,
4791
    slhdsa_sha2_192s_sa_algo     = 22,
4792
    slhdsa_sha2_192f_sa_algo     = 23,
4793
    slhdsa_sha2_256s_sa_algo     = 24,
4794
    slhdsa_sha2_256f_sa_algo     = 25,
4795
    slhdsa_shake_128s_sa_algo    = 26,
4796
    slhdsa_shake_128f_sa_algo    = 27,
4797
    slhdsa_shake_192s_sa_algo    = 28,
4798
    slhdsa_shake_192f_sa_algo    = 29,
4799
    slhdsa_shake_256s_sa_algo    = 30,
4800
    slhdsa_shake_256f_sa_algo    = 31,
4801
    invalid_sa_algo              = 255
4802
};
4803
4804
#define PSS_RSAE_TO_PSS_PSS(macAlgo) \
4805
    ((macAlgo) + (pss_sha256 - sha256_mac))
4806
4807
#define PSS_PSS_HASH_TO_MAC(macAlgo) \
4808
    ((macAlgo) - (pss_sha256 - sha256_mac))
4809
4810
enum SigAlgRsaPss {
4811
    pss_sha256  = 0x09,
4812
    pss_sha384  = 0x0a,
4813
    pss_sha512  = 0x0b
4814
};
4815
4816
#ifdef WOLFSSL_SM2
4817
    /* Default SM2 signature ID. */
4818
0
    #define TLS12_SM2_SIG_ID        ((byte*)"1234567812345678")
4819
    /* Length of default SM2 signature ID. */
4820
0
    #define TLS12_SM2_SIG_ID_SZ     16
4821
4822
    /* https://www.rfc-editor.org/rfc/rfc8998.html#name-sm2-signature-scheme */
4823
    /* ID to use when signing/verifying TLS v1.3 data. */
4824
0
    #define TLS13_SM2_SIG_ID        ((byte*)"TLSv1.3+GM+Cipher+Suite")
4825
    /* Length of ID to use when signing/verifying TLS v1.3 data. */
4826
0
    #define TLS13_SM2_SIG_ID_SZ     23
4827
#endif
4828
4829
/* Supported ECC Curve Types */
4830
enum EccCurves {
4831
    named_curve = 3
4832
};
4833
4834
4835
/* Valid client certificate request types from page 27 */
4836
enum ClientCertificateType {
4837
    rsa_sign            = 1,
4838
    dss_sign            = 2,
4839
    rsa_fixed_dh        = 3,
4840
    dss_fixed_dh        = 4,
4841
    rsa_ephemeral_dh    = 5,
4842
    dss_ephemeral_dh    = 6,
4843
    fortezza_kea_cert   = 20,
4844
    ecdsa_sign          = 64,
4845
    rsa_fixed_ecdh      = 65,
4846
    ecdsa_fixed_ecdh    = 66,
4847
    falcon_sign         = 67,
4848
    mldsa_sign          = 68
4849
};
4850
4851
/* Maximum number of ClientCertificateType bytes the server emits in a
4852
 * CertificateRequest. Currently rsa_sign and ecdsa_sign. */
4853
#define MAX_CERT_REQ_CERT_TYPE_CNT 2
4854
4855
4856
#ifndef WOLFSSL_AEAD_ONLY
4857
enum CipherType { stream, block, aead };
4858
#else
4859
enum CipherType { aead };
4860
#endif
4861
4862
4863
#if defined(BUILD_AES) || defined(BUILD_AESGCM) || defined(HAVE_ARIA) || \
4864
        (defined(HAVE_CHACHA) && defined(HAVE_POLY1305)) || defined(WOLFSSL_TLS13)
4865
    #define CIPHER_NONCE
4866
#endif
4867
4868
#if defined(WOLFSSL_DTLS) && defined(HAVE_SECURE_RENEGOTIATION)
4869
enum CipherSrc {
4870
    KEYS_NOT_SET = 0,
4871
    KEYS,     /* keys from ssl->keys are loaded */
4872
    SCR       /* keys from ssl->secure_renegotiation->tmp_keys are loaded */
4873
};
4874
#endif
4875
4876
#ifdef WOLFSSL_CIPHER_TEXT_CHECK
4877
    #ifndef WOLFSSL_CIPHER_CHECK_SZ
4878
        /* 64-bits to confirm encrypt operation worked */
4879
        #define WOLFSSL_CIPHER_CHECK_SZ 8
4880
    #endif
4881
#endif
4882
4883
/* cipher for now */
4884
typedef struct Ciphers {
4885
#ifdef BUILD_ARC4
4886
    Arc4*   arc4;
4887
#endif
4888
#ifdef BUILD_DES3
4889
    Des3*   des3;
4890
#endif
4891
#if defined(BUILD_AES) || defined(BUILD_AESGCM)
4892
    Aes*    aes;
4893
#endif
4894
#if (defined(BUILD_AESGCM) || defined(HAVE_AESCCM)) && !defined(WOLFSSL_NO_TLS12)
4895
    byte* additional;
4896
#endif
4897
#ifdef HAVE_ARIA
4898
    wc_Aria* aria;
4899
#endif
4900
#ifdef CIPHER_NONCE
4901
    byte* nonce;
4902
#endif
4903
#ifdef HAVE_CAMELLIA
4904
    wc_Camellia* cam;
4905
#endif
4906
#ifdef HAVE_CHACHA
4907
    ChaCha*   chacha;
4908
#endif
4909
#ifdef WOLFSSL_SM4
4910
    wc_Sm4*   sm4;
4911
#endif
4912
#if defined(WOLFSSL_TLS13) && defined(HAVE_NULL_CIPHER) && !defined(NO_HMAC)
4913
    Hmac* hmac;
4914
#endif
4915
#ifdef WOLFSSL_CIPHER_TEXT_CHECK
4916
    word32 sanityCheck[WOLFSSL_CIPHER_CHECK_SZ/sizeof(word32)];
4917
#endif
4918
    byte    state;
4919
    byte    setup;       /* have we set it up flag for detection */
4920
#if defined(WOLFSSL_DTLS) && defined(HAVE_SECURE_RENEGOTIATION)
4921
    enum CipherSrc src;  /* DTLS uses this to determine which keys
4922
                          * are currently loaded */
4923
#endif
4924
} Ciphers;
4925
4926
#ifdef WOLFSSL_DTLS13
4927
typedef struct RecordNumberCiphers {
4928
#if defined(BUILD_AES) || defined(BUILD_AESGCM)
4929
        Aes *aes;
4930
#endif /*  BUILD_AES || BUILD_AESGCM */
4931
#ifdef HAVE_CHACHA
4932
        ChaCha *chacha;
4933
#endif
4934
} RecordNumberCiphers;
4935
#endif /* WOLFSSL_DTLS13 */
4936
4937
#ifdef HAVE_ONE_TIME_AUTH
4938
/* Ciphers for one time authentication such as poly1305 */
4939
typedef struct OneTimeAuth {
4940
#ifdef HAVE_POLY1305
4941
    Poly1305* poly1305;
4942
#endif
4943
    byte    setup;      /* flag for if a cipher has been set */
4944
4945
} OneTimeAuth;
4946
#endif
4947
4948
4949
WOLFSSL_LOCAL void InitCiphers(WOLFSSL* ssl);
4950
WOLFSSL_LOCAL void FreeCiphers(WOLFSSL* ssl);
4951
4952
4953
/* hashes type */
4954
typedef struct Hashes {
4955
    #if !defined(NO_MD5) && !defined(NO_OLD_TLS)
4956
        byte md5[WC_MD5_DIGEST_SIZE];
4957
    #endif
4958
    #if !defined(NO_SHA) && (!defined(NO_OLD_TLS) || \
4959
                              defined(WOLFSSL_ALLOW_TLS_SHA1))
4960
        byte sha[WC_SHA_DIGEST_SIZE];
4961
    #endif
4962
    #ifndef NO_SHA256
4963
        byte sha256[WC_SHA256_DIGEST_SIZE];
4964
    #endif
4965
    #ifdef WOLFSSL_SHA384
4966
        byte sha384[WC_SHA384_DIGEST_SIZE];
4967
    #endif
4968
    #ifdef WOLFSSL_SHA512
4969
        byte sha512[WC_SHA512_DIGEST_SIZE];
4970
    #endif
4971
    #ifdef WOLFSSL_SM3
4972
        byte sm3[WC_SM3_DIGEST_SIZE];
4973
    #endif
4974
} Hashes;
4975
4976
WOLFSSL_LOCAL int BuildCertHashes(const WOLFSSL* ssl, Hashes* hashes);
4977
4978
#ifdef WOLFSSL_TLS13
4979
typedef union Digest {
4980
#ifndef NO_SHA256
4981
    wc_Sha256 sha256;
4982
#endif
4983
#ifdef WOLFSSL_SHA384
4984
    wc_Sha384 sha384;
4985
#endif
4986
#ifdef WOLFSSL_SHA512
4987
    wc_Sha512 sha512;
4988
#endif
4989
#ifdef WOLFSSL_SM3
4990
    wc_Sm3    sm3;
4991
#endif
4992
} Digest;
4993
#endif
4994
4995
/* Static x509 buffer */
4996
typedef struct x509_buffer {
4997
    int  length;                  /* actual size */
4998
    byte buffer[MAX_X509_SIZE];   /* max static cert size */
4999
} x509_buffer;
5000
5001
5002
/* wolfSSL X509_CHAIN, for no dynamic memory SESSION_CACHE */
5003
struct WOLFSSL_X509_CHAIN {
5004
    int         count;                    /* total number in chain */
5005
    x509_buffer certs[MAX_CHAIN_DEPTH];   /* only allow max depth 4 for now */
5006
};
5007
5008
typedef enum WOLFSSL_SESSION_TYPE {
5009
    WOLFSSL_SESSION_TYPE_UNKNOWN,
5010
    WOLFSSL_SESSION_TYPE_SSL,    /* in ssl->session */
5011
    WOLFSSL_SESSION_TYPE_CACHE,  /* pointer to internal cache */
5012
    WOLFSSL_SESSION_TYPE_HEAP    /* allocated from heap SESSION_new */
5013
} WOLFSSL_SESSION_TYPE;
5014
5015
#ifdef WOLFSSL_QUIC
5016
typedef struct QuicRecord QuicRecord;
5017
typedef struct QuicRecord {
5018
    struct QuicRecord *next;
5019
    uint8_t *data;
5020
    word32 capacity;
5021
    word32 len;
5022
    word32 start;
5023
    word32 end;
5024
    WOLFSSL_ENCRYPTION_LEVEL level;
5025
    word32 rec_hdr_remain;
5026
} QuicEncData;
5027
5028
typedef struct QuicTransportParam QuicTransportParam;
5029
struct QuicTransportParam {
5030
    const uint8_t *data;
5031
    word16 len;
5032
};
5033
5034
WOLFSSL_LOCAL const QuicTransportParam *QuicTransportParam_new(const uint8_t *data, size_t len, void *heap);
5035
WOLFSSL_LOCAL const QuicTransportParam *QuicTransportParam_dup(const QuicTransportParam *tp, void *heap);
5036
WOLFSSL_LOCAL void QuicTransportParam_free(const QuicTransportParam *tp, void *heap);
5037
WOLFSSL_LOCAL int TLSX_QuicTP_Use(WOLFSSL* ssl, TLSX_Type ext_type, int is_response);
5038
WOLFSSL_LOCAL int wolfSSL_quic_add_transport_extensions(WOLFSSL *ssl, int msg_type);
5039
5040
#define QTP_FREE     QuicTransportParam_free
5041
5042
#endif /* WOLFSSL_QUIC */
5043
5044
/** Session Ticket - RFC 5077 (session 3.2) */
5045
#if defined(WOLFSSL_TLS13) && (defined(HAVE_SESSION_TICKET) || !defined(NO_PSK))
5046
/* Ticket nonce - for deriving PSK.
5047
   Length allowed to be: 1..255. Only support
5048
 * TLS13_TICKET_NONCE_STATIC_SZ length bytes.
5049
 */
5050
typedef struct TicketNonce {
5051
    byte len;
5052
#if defined(WOLFSSL_TICKET_NONCE_MALLOC) &&                                    \
5053
    (!defined(HAVE_FIPS) || (defined(FIPS_VERSION_GE) && FIPS_VERSION_GE(5,3)))
5054
    byte *data;
5055
    byte dataStatic[MAX_TICKET_NONCE_STATIC_SZ];
5056
#else
5057
    byte data[MAX_TICKET_NONCE_STATIC_SZ];
5058
#endif /* WOLFSSL_TICKET_NONCE_MALLOC  && FIPS_VERSION_GE(5,3) */
5059
} TicketNonce;
5060
#endif
5061
5062
/* wolfSSL session type */
5063
struct WOLFSSL_SESSION {
5064
    /* WARNING Do not add fields here. They will be ignored in
5065
     *         wolfSSL_DupSession. */
5066
    WOLFSSL_SESSION_TYPE type;
5067
#ifndef NO_SESSION_CACHE
5068
    int                cacheRow;          /* row in session cache     */
5069
#endif
5070
    wolfSSL_Ref        ref;
5071
    byte               altSessionID[ID_LEN];
5072
    byte               haveAltSessionID:1;
5073
#ifdef HAVE_EX_DATA
5074
    byte               ownExData:1;
5075
#endif
5076
#if defined(HAVE_EXT_CACHE) || defined(HAVE_EX_DATA)
5077
    Rem_Sess_Cb        rem_sess_cb;
5078
#endif
5079
    void*              heap;
5080
    /* WARNING The above fields (up to and including the heap) are not copied
5081
     *         in wolfSSL_DupSession. Place new fields after the heap
5082
     *         member */
5083
5084
    byte               side;              /* Either WOLFSSL_CLIENT_END or
5085
                                                    WOLFSSL_SERVER_END */
5086
5087
    word32             bornOn;            /* create time in seconds   */
5088
    word32             timeout;           /* timeout in seconds       */
5089
5090
    byte               sessionID[ID_LEN]; /* id for protocol or bogus
5091
                                           * ID for TLS 1.3           */
5092
    byte               sessionIDSz;
5093
5094
    byte               masterSecret[SECRET_LEN]; /* stored secret     */
5095
    word16             haveEMS;           /* ext master secret flag   */
5096
#if defined(SESSION_CERTS) && defined(OPENSSL_EXTRA)
5097
    WOLFSSL_X509*      peer;              /* peer cert */
5098
#endif
5099
    ProtocolVersion    version;           /* which version was used   */
5100
#if defined(SESSION_CERTS) || !defined(NO_RESUME_SUITE_CHECK) || \
5101
                        (defined(WOLFSSL_TLS13) && defined(HAVE_SESSION_TICKET))
5102
    byte               cipherSuite0;      /* first byte, normally 0   */
5103
    byte               cipherSuite;       /* 2nd byte, actual suite   */
5104
#endif
5105
#ifndef NO_CLIENT_CACHE
5106
    word16             idLen;             /* serverID length          */
5107
    byte               serverID[SERVER_ID_LEN]; /* for easier client lookup */
5108
#endif
5109
#ifdef WOLFSSL_SESSION_ID_CTX
5110
    byte               sessionCtxSz;      /* sessionCtx length        */
5111
    byte               sessionCtx[ID_LEN]; /* app specific context id */
5112
#endif /* WOLFSSL_SESSION_ID_CTX */
5113
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
5114
    byte               peerVerifyRet;     /* cert verify error */
5115
#endif
5116
#ifdef WOLFSSL_TLS13
5117
    word16             namedGroup;
5118
#endif
5119
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
5120
#ifdef WOLFSSL_TLS13
5121
#ifdef WOLFSSL_32BIT_MILLI_TIME
5122
    word32             ticketSeen;        /* Time ticket seen (ms) */
5123
#else
5124
    sword64            ticketSeen;        /* Time ticket seen (ms) */
5125
#endif
5126
    word32             ticketAdd;         /* Added by client */
5127
    TicketNonce        ticketNonce;       /* Nonce used to derive PSK */
5128
#endif
5129
#ifdef WOLFSSL_EARLY_DATA
5130
    word32             maxEarlyDataSz;
5131
#endif
5132
#endif
5133
#ifdef HAVE_SESSION_TICKET
5134
    byte               staticTicket[SESSION_TICKET_LEN];
5135
    byte*              ticket;
5136
    word16             ticketLen;
5137
    word16             ticketLenAlloc;    /* is dynamic */
5138
#ifdef HAVE_SNI
5139
    byte               sniHash[TICKET_BINDING_HASH_SZ];  /* SNI at issue */
5140
#endif
5141
#ifdef HAVE_ALPN
5142
    byte               alpnHash[TICKET_BINDING_HASH_SZ]; /* ALPN at issue */
5143
#endif
5144
#endif
5145
5146
#ifdef SESSION_CERTS
5147
    WOLFSSL_X509_CHAIN chain;             /* peer cert chain, static  */
5148
    #ifdef WOLFSSL_ALT_CERT_CHAINS
5149
    WOLFSSL_X509_CHAIN altChain;          /* peer alt cert chain, static */
5150
    #endif
5151
#endif
5152
#ifdef HAVE_EX_DATA
5153
    WOLFSSL_CRYPTO_EX_DATA ex_data;
5154
#endif
5155
#ifdef HAVE_MAX_FRAGMENT
5156
    byte               mfl; /* max fragment length negotiated i.e.
5157
                             * WOLFSSL_MFL_2_8  (6) */
5158
#endif
5159
    byte               isSetup:1;
5160
};
5161
5162
#if defined(WOLFSSL_TLS13) && defined(HAVE_SESSION_TICKET) &&                  \
5163
        defined(WOLFSSL_TICKET_NONCE_MALLOC) &&                                \
5164
    (!defined(HAVE_FIPS) || (defined(FIPS_VERSION_GE) && FIPS_VERSION_GE(5,3)))
5165
WOLFSSL_LOCAL int SessionTicketNoncePopulate(WOLFSSL_SESSION *session,
5166
    const byte* nonce, byte len);
5167
#endif /* WOLFSSL_TLS13 &&  */
5168
5169
WOLFSSL_LOCAL int wolfSSL_RAND_Init(void);
5170
5171
WOLFSSL_LOCAL WOLFSSL_SESSION* wolfSSL_NewSession(void* heap);
5172
WOLFSSL_LOCAL WOLFSSL_SESSION* wolfSSL_GetSession(
5173
    WOLFSSL* ssl, byte* masterSecret, byte restoreSessionCerts);
5174
WOLFSSL_LOCAL void SetupSession(WOLFSSL* ssl);
5175
WOLFSSL_LOCAL void AddSession(WOLFSSL* ssl);
5176
#ifdef WOLFSSL_API_PREFIX_MAP
5177
    #define AddSessionToCache wolfSSL_AddSessionToCache
5178
#endif
5179
WOLFSSL_TEST_VIS int AddSessionToCache(WOLFSSL_CTX* ctx,
5180
    WOLFSSL_SESSION* addSession, const byte* id, byte idSz, int* sessionIndex,
5181
    int side, word16 useTicket, ClientSession** clientCacheEntry);
5182
#ifndef NO_CLIENT_CACHE
5183
WOLFSSL_LOCAL ClientSession* AddSessionToClientCache(int side, int row, int idx,
5184
                      byte* serverID, word16 idLen, const byte* sessionID,
5185
                      word16 useTicket);
5186
#endif
5187
WOLFSSL_LOCAL
5188
WOLFSSL_SESSION* ClientSessionToSession(const WOLFSSL_SESSION* session);
5189
WOLFSSL_LOCAL void TlsSessionCacheUnlockRow(word32 row);
5190
WOLFSSL_LOCAL int TlsSessionCacheGetAndRdLock(const byte *id,
5191
    const WOLFSSL_SESSION **sess, word32 *lockedRow, byte side);
5192
WOLFSSL_LOCAL int TlsSessionCacheGetAndWrLock(const byte *id,
5193
    WOLFSSL_SESSION **sess, word32 *lockedRow, byte side);
5194
WOLFSSL_LOCAL void EvictSessionFromCache(WOLFSSL_SESSION* session);
5195
WOLFSSL_TEST_VIS int wolfSSL_GetSessionFromCache(WOLFSSL* ssl, WOLFSSL_SESSION* output);
5196
WOLFSSL_LOCAL int wolfSSL_SetSession(WOLFSSL* ssl, WOLFSSL_SESSION* session);
5197
WOLFSSL_LOCAL void wolfSSL_FreeSession(WOLFSSL_CTX* ctx,
5198
        WOLFSSL_SESSION* session);
5199
WOLFSSL_LOCAL int wolfSSL_DupSession(const WOLFSSL_SESSION* input,
5200
        WOLFSSL_SESSION* output, int avoidSysCalls);
5201
5202
5203
typedef int (*hmacfp) (WOLFSSL*, byte*, const byte*, word32, int, int, int, int);
5204
5205
#ifndef NO_CLIENT_CACHE
5206
    WOLFSSL_LOCAL WOLFSSL_SESSION* wolfSSL_GetSessionClient(
5207
        WOLFSSL* ssl, const byte* id, int len);
5208
#endif
5209
5210
/* client connect state for nonblocking restart */
5211
enum ConnectState {
5212
    CONNECT_BEGIN = 0,
5213
    CLIENT_HELLO_SENT,
5214
    HELLO_AGAIN,               /* HELLO_AGAIN s for DTLS case */
5215
    HELLO_AGAIN_REPLY,
5216
    FIRST_REPLY_DONE,
5217
    FIRST_REPLY_FIRST,
5218
    FIRST_REPLY_SECOND,
5219
    FIRST_REPLY_THIRD,
5220
    FIRST_REPLY_FOURTH,
5221
    FINISHED_DONE,
5222
    SECOND_REPLY_DONE,
5223
5224
#ifdef WOLFSSL_DTLS13
5225
    WAIT_FINISHED_ACK
5226
#endif /* WOLFSSL_DTLS13 */
5227
5228
};
5229
5230
5231
/* server accept state for nonblocking restart */
5232
enum AcceptState {
5233
    ACCEPT_BEGIN = 0,
5234
    ACCEPT_BEGIN_RENEG,
5235
    ACCEPT_CLIENT_HELLO_DONE,
5236
    ACCEPT_HELLO_RETRY_REQUEST_DONE,
5237
    ACCEPT_FIRST_REPLY_DONE,
5238
    SERVER_HELLO_SENT,
5239
    CERT_SENT,
5240
    CERT_VERIFY_SENT,
5241
    CERT_STATUS_SENT,
5242
    KEY_EXCHANGE_SENT,
5243
    CERT_REQ_SENT,
5244
    SERVER_HELLO_DONE,
5245
    ACCEPT_SECOND_REPLY_DONE,
5246
    TICKET_SENT,
5247
    CHANGE_CIPHER_SENT,
5248
    ACCEPT_FINISHED_DONE,
5249
    ACCEPT_THIRD_REPLY_DONE
5250
};
5251
5252
/* TLS 1.3 server accept state for nonblocking restart */
5253
enum AcceptStateTls13 {
5254
    TLS13_ACCEPT_BEGIN = 0,
5255
    TLS13_ACCEPT_BEGIN_RENEG,
5256
    TLS13_ACCEPT_CLIENT_HELLO_DONE,
5257
    TLS13_ACCEPT_HELLO_RETRY_REQUEST_DONE,
5258
    TLS13_ACCEPT_FIRST_REPLY_DONE,
5259
    TLS13_ACCEPT_SECOND_REPLY_DONE,
5260
    TLS13_SERVER_HELLO_SENT,
5261
    TLS13_ACCEPT_THIRD_REPLY_DONE,
5262
    TLS13_SERVER_EXTENSIONS_SENT,
5263
    TLS13_CERT_REQ_SENT,
5264
    TLS13_CERT_SENT,
5265
    TLS13_CERT_VERIFY_SENT,
5266
    TLS13_ACCEPT_FINISHED_SENT,
5267
    TLS13_PRE_TICKET_SENT,
5268
    TLS13_ACCEPT_FINISHED_DONE,
5269
    TLS13_TICKET_SENT
5270
};
5271
5272
#ifdef WOLFSSL_THREADED_CRYPT
5273
5274
#include <pthread.h>
5275
5276
typedef struct ThreadCrypt {
5277
    Ciphers encrypt;
5278
    bufferStatic buffer;
5279
    unsigned char nonce[AESGCM_NONCE_SZ];
5280
    unsigned char additional[AEAD_AUTH_DATA_SZ];
5281
    int init;
5282
    int offset;
5283
    int cryptLen;
5284
    int done;
5285
    int avail;
5286
    int stop;
5287
    WOLFSSL_THREAD_SIGNAL signal;
5288
    void*                 signalCtx;
5289
} ThreadCrypt;
5290
5291
#endif
5292
5293
/* Streamed TLS 1.3 CertificateVerify send. When the CertificateVerify body
5294
 * (the signature) does not fit in a single record - a post-quantum signature
5295
 * such as SLH-DSA or ML-DSA, or any signature under a small
5296
 * max_fragment_length - it is generated once into a connection-level buffer and
5297
 * emitted one record at a time, so the output buffer never has to hold the
5298
 * whole signature. The assembled body must be held at the connection level
5299
 * (not on the stack) because these signatures are randomized: a non-blocking
5300
 * WANT_WRITE can return control mid-send, and the records already sent are
5301
 * bound into the transcript, so the resumed send must continue emitting the
5302
 * exact same signature - it cannot be regenerated. This is algorithm-neutral;
5303
 * it applies to any signature scheme whose CertificateVerify can exceed a
5304
 * record. It is not used with WOLFSSL_ASYNC_CRYPT, whose record-AEAD pends are
5305
 * handled by the existing in-place fragmented path. */
5306
#if defined(WOLFSSL_TLS13) && !defined(WOLFSSL_ASYNC_CRYPT) && \
5307
    (defined(WOLFSSL_HAVE_SLHDSA) || defined(WOLFSSL_HAVE_MLDSA) || \
5308
     defined(HAVE_FALCON))
5309
    #define WOLFSSL_TLS13_STREAM_CERT_VERIFY
5310
#endif
5311
5312
/* buffers for struct WOLFSSL */
5313
typedef struct Buffers {
5314
    bufferStatic    inputBuffer;
5315
    bufferStatic    outputBuffer;
5316
#ifdef WOLFSSL_THREADED_CRYPT
5317
    ThreadCrypt     encrypt[WOLFSSL_THREADED_CRYPT_CNT];
5318
#endif
5319
    buffer          domainName;            /* for client check */
5320
    buffer          ipasc;                 /* for client IP SAN check */
5321
    buffer          clearOutputBuffer;
5322
    buffer          sig;                   /* signature data */
5323
    buffer          digest;                /* digest data */
5324
    word32          prevSent;              /* previous plain text bytes sent
5325
                                              when got WANT_WRITE            */
5326
    word32          plainSz;               /* plain text bytes in buffer to send
5327
                                              when got WANT_WRITE            */
5328
    byte            weOwnCert;             /* SSL own cert flag */
5329
    byte            weOwnCertChain;        /* SSL own cert chain flag */
5330
    byte            weOwnKey;              /* SSL own key flag */
5331
#ifdef WOLFSSL_DUAL_ALG_CERTS
5332
    byte            weOwnAltKey;           /* SSL own alt key flag */
5333
#endif
5334
    byte            weOwnDH;               /* SSL own dh (p,g)  flag */
5335
#ifndef NO_DH
5336
    /* SSL owns p and g when weOwnDH is set. Otherwise they point at the
5337
     * static parameters of a named group, which nothing owns. */
5338
    buffer          serverDH_P;
5339
    buffer          serverDH_G;
5340
    buffer          serverDH_Pub;
5341
    buffer          serverDH_Priv;
5342
    DhKey*          serverDH_Key;
5343
#endif
5344
#ifndef NO_CERTS
5345
    DerBuffer*      certificate;           /* WOLFSSL_CTX owns, unless we own */
5346
    DerBuffer*      key;                   /* WOLFSSL_CTX owns, unless we own */
5347
#ifdef WOLFSSL_BLIND_PRIVATE_KEY
5348
    DerBuffer*      keyMask;               /* Mask of private key DER. */
5349
#endif
5350
    byte            keyType;               /* Type of key */
5351
    byte            keyId:1;               /* Key data is an id not data */
5352
    byte            keyLabel:1;            /* Key data is a label not data */
5353
    int             keySz;                 /* Size of RSA key */
5354
    int             keyDevId;              /* Device Id for key */
5355
#ifdef WOLFSSL_DUAL_ALG_CERTS
5356
    DerBuffer*      altKey;                /* WOLFSSL_CTX owns, unless we own */
5357
#ifdef WOLFSSL_BLIND_PRIVATE_KEY
5358
    DerBuffer*      altKeyMask;            /* Mask of alt private key DER. */
5359
#endif
5360
    byte            altKeyType;            /* Type of alt key */
5361
    byte            altKeyId:1;            /* Key data is an id not data */
5362
    byte            altKeyLabel:1;         /* Key data is a label not data */
5363
    int             altKeySz;              /* Size of alt key */
5364
    int             altKeyDevId;           /* Device Id for alt key */
5365
#endif
5366
    DerBuffer*      certChain;             /* WOLFSSL_CTX owns, unless we own */
5367
                 /* chain after self, in DER, with leading size for each cert */
5368
    int             certChainCnt;
5369
#ifdef WOLFSSL_TLS13
5370
    DerBuffer*      certExts[MAX_CERT_EXTENSIONS];
5371
#endif
5372
#endif
5373
#ifdef WOLFSSL_SEND_HRR_COOKIE
5374
    buffer          tls13CookieSecret;     /* HRR cookie secret */
5375
    /* Secondary HRR cookie secret, used only when verifying a cookie if the
5376
     * primary secret fails.  Lets a stateless DTLS 1.3 server keep accepting
5377
     * cookies issued under the secret it had before an application-driven
5378
     * rotation.  DTLS only - never used to issue cookies. */
5379
    buffer          tls13CookieSecretSecondary;
5380
#endif
5381
#ifdef WOLFSSL_DTLS
5382
    WOLFSSL_DTLS_CTX dtlsCtx;              /* DTLS connection context */
5383
    #ifndef NO_WOLFSSL_SERVER
5384
        buffer       dtlsCookieSecret;     /* DTLS cookie secret */
5385
        /* Secondary DTLS 1.2 cookie secret, used only when verifying a
5386
         * received HelloVerifyRequest cookie if the primary secret fails.
5387
         * Lets a stateless server keep accepting cookies issued under the
5388
         * secret it had before an application-driven rotation.  Never used to
5389
         * issue cookies. */
5390
        buffer       dtlsCookieSecretSecondary;
5391
    #endif /* NO_WOLFSSL_SERVER */
5392
#endif
5393
#ifdef HAVE_PK_CALLBACKS
5394
    #ifdef HAVE_ECC
5395
        buffer peerEccDsaKey;              /* we own for Ecc Verify Callbacks */
5396
    #endif /* HAVE_ECC */
5397
    #ifdef HAVE_ED25519
5398
        buffer peerEd25519Key;             /* for Ed25519 Verify Callbacks */
5399
    #endif /* HAVE_ED25519 */
5400
    #ifdef HAVE_ED448
5401
        buffer peerEd448Key;             /* for Ed448 Verify Callbacks */
5402
    #endif /* HAVE_ED448 */
5403
    #ifndef NO_RSA
5404
        buffer peerRsaKey;                 /* we own for Rsa Verify Callbacks */
5405
    #endif /* NO_RSA */
5406
#endif /* HAVE_PK_CALLBACKS */
5407
#ifdef WOLFSSL_TLS13_STREAM_CERT_VERIFY
5408
    /* Assembled TLS 1.3 CertificateVerify body (sig-alg | length | signature)
5409
     * held across records while it is streamed, so a non-blocking WANT_WRITE
5410
     * can resume the send without recomputing the signature. NULL when idle;
5411
     * freed by wolfSSL_ResourceFree. See WOLFSSL_TLS13_STREAM_CERT_VERIFY. */
5412
    buffer          certVerifyMsg;
5413
#endif
5414
#ifdef HAVE_LIBZ
5415
    /* Plaintext of the application data record currently being decompressed.
5416
     * A compressed fragment expands to as much as MAX_RECORD_SIZE, so the
5417
     * result must not be written back over the record it came from: the input
5418
     * buffer is only sized for the wire (compressed) record and may already
5419
     * hold the records queued behind it.  Allocated on the first compressed
5420
     * record received, length is its fixed capacity, released by
5421
     * wolfSSL_ResourceFree(). */
5422
    buffer          decompBuffer;
5423
#endif
5424
} Buffers;
5425
5426
#ifndef NO_DH
5427
/* Give the SSL object its own copy of the context's DH parameters. They are
5428
 * not reference counted, so a session must not point at the context's. */
5429
WOLFSSL_LOCAL int CopySSL_CTX_DhParams(WOLFSSL* ssl, WOLFSSL_CTX* ctx);
5430
#endif
5431
5432
/* sub-states for send/do key share (key exchange) */
5433
enum asyncState {
5434
    TLS_ASYNC_BEGIN = 0,
5435
    TLS_ASYNC_BUILD,
5436
    TLS_ASYNC_DO,
5437
    TLS_ASYNC_VERIFY,
5438
    TLS_ASYNC_FINALIZE,
5439
    TLS_ASYNC_END
5440
};
5441
5442
/* sub-states for build message */
5443
enum buildMsgState {
5444
    BUILD_MSG_BEGIN = 0,
5445
    BUILD_MSG_SIZE,
5446
    BUILD_MSG_HASH,
5447
    BUILD_MSG_VERIFY_MAC,
5448
    BUILD_MSG_ENCRYPT,
5449
    BUILD_MSG_ENCRYPTED_VERIFY_MAC
5450
};
5451
5452
/* sub-states for cipher operations */
5453
enum cipherState {
5454
    CIPHER_STATE_BEGIN = 0,
5455
    CIPHER_STATE_DO,
5456
    CIPHER_STATE_END
5457
};
5458
5459
struct Options {
5460
#ifndef NO_PSK
5461
    wc_psk_client_callback client_psk_cb;
5462
    wc_psk_server_callback server_psk_cb;
5463
#ifdef OPENSSL_EXTRA
5464
    wc_psk_use_session_cb_func session_psk_cb;
5465
#endif
5466
#ifdef WOLFSSL_TLS13
5467
    wc_psk_client_cs_callback    client_psk_cs_cb;     /* client callback */
5468
    wc_psk_client_tls13_callback client_psk_tls13_cb;  /* client callback */
5469
    wc_psk_server_tls13_callback server_psk_tls13_cb;  /* server callback */
5470
#endif
5471
    void*             psk_ctx;
5472
#endif /* NO_PSK */
5473
    unsigned long     mask; /* store SSL_OP_ flags */
5474
#if defined(OPENSSL_EXTRA) || defined(HAVE_WEBSERVER) || defined(WOLFSSL_WPAS_SMALL)
5475
    word16            minProto:1; /* sets min to min available */
5476
    word16            maxProto:1; /* sets max to max available */
5477
#endif
5478
#if defined(HAVE_SESSION_TICKET) && defined(WOLFSSL_TLS13)
5479
    unsigned int      maxTicketTls13;  /* maximum number of tickets to send */
5480
    unsigned int      ticketsSent;     /* keep track of the total sent */
5481
#if !defined(NO_WOLFSSL_SERVER) && \
5482
    defined(WOLFSSL_TLS13_TICKET_CHECK_PSK_MODES)
5483
    byte              pskKeModes;      /* modes client advertised in CH */
5484
#endif
5485
#endif
5486
5487
    /* on/off or small bit flags, optimize layout */
5488
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
5489
    word16            havePSK:1;            /* psk key set by user */
5490
#endif /* HAVE_SESSION_TICKET || !NO_PSK */
5491
    word16            sendVerify:2;     /* false = 0, true = 1, sendBlank = 2 */
5492
    word16            sessionCacheOff:1;
5493
    word16            sessionCacheFlushOff:1;
5494
#ifdef HAVE_EXT_CACHE
5495
    word16            internalCacheOff:1;
5496
    word16            internalCacheLookupOff:1;
5497
#endif
5498
    word16            side:2;             /* client, server or neither end */
5499
    word16            verifyPeer:1;
5500
    word16            verifyNone:1;
5501
    word16            failNoCert:1;
5502
    word16            failNoCertxPSK:1;   /* fail for no cert except with PSK */
5503
    word16            failNoPSK:1;        /* fail if no PSK is negotiated */
5504
    word16            downgrade:1;        /* allow downgrade of versions */
5505
    word16            resuming:1;
5506
#ifdef HAVE_SECURE_RENEGOTIATION
5507
    word16            resumed:1;          /* resuming may be reset on SCR */
5508
#endif
5509
    word16            isPSK:1;
5510
    word16            haveSessionId:1;    /* server may not send */
5511
    word16            tls:1;              /* using TLS ? */
5512
    word16            tls1_1:1;           /* using TLSv1.1+ ? */
5513
    word16            tls1_3:1;           /* using TLSv1.3+ ? */
5514
    word16            dtls:1;             /* using datagrams ? */
5515
#ifdef WOLFSSL_DTLS
5516
    word16            dtlsStateful:1;     /* allow stateful processing ? */
5517
#endif
5518
    word16            connReset:1;        /* has the peer reset */
5519
    word16            isClosed:1;         /* if we consider conn closed */
5520
    word16            closeNotify:1;      /* we've received a close notify */
5521
    word16            sentNotify:1;       /* we've sent a close notify */
5522
    word16            usingCompression:1; /* are we using compression */
5523
    word16            haveRSA:1;          /* RSA available */
5524
    word16            haveECC:1;          /* ECC available */
5525
    word16            haveDH:1;           /* server DH params set by user */
5526
    word16            haveECDSAsig:1;     /* server ECDSA signed cert */
5527
    word16            haveStaticECC:1;    /* static server ECC private key */
5528
    word16            haveFalconSig:1;    /* server Falcon signed cert */
5529
    word16            haveMlDsaSig:1;     /* server ML-DSA signed cert */
5530
    word16            haveSlhDsaSig:1;    /* server SLH-DSA signed cert */
5531
    word16            havePeerCert:1;     /* do we have peer's cert */
5532
    word16            havePeerVerify:1;   /* and peer's cert verify */
5533
    word16            usingPSK_cipher:1;  /* are using psk as cipher */
5534
    word16            usingAnon_cipher:1; /* are we using an anon cipher */
5535
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
5536
    word16            noPskDheKe:1;       /* Don't use (EC)DHE with PSK */
5537
    /* noPskDheKe doubles as negotiated state - it is set when psk_ke is chosen
5538
     * and cleared on every certificate handshake. Decisions that must follow
5539
     * what the application configured use this copy, which is only written by
5540
     * the configuration APIs. */
5541
    word16            noPskDheKePolicy:1; /* Configured no (EC)DHE with PSK */
5542
#ifdef HAVE_SUPPORTED_CURVES
5543
    word16            onlyPskDheKe:1;     /* Only use (EC)DHE with PSK */
5544
#endif
5545
#if defined(WOLFSSL_CERT_WITH_EXTERN_PSK)
5546
    word16            certWithExternPsk:1; /* Cert auth with external PSK */
5547
#endif
5548
#endif
5549
    word16            partialWrite:1;     /* only one msg per write call */
5550
    word16            quietShutdown:1;    /* don't send close notify */
5551
    word16            quietShutdownRestore:1; /* wolfSSL_SendUserCanceled()
5552
                                           * turned quietShutdown off until
5553
                                           * its close_notify is flushed */
5554
    word16            certOnly:1;         /* stop once we get cert */
5555
    word16            groupMessages:1;    /* group handshake messages */
5556
    word16            saveArrays:1;       /* save array Memory for user get keys
5557
                                           or psk */
5558
    word16            weOwnRng:1;         /* will be true unless CTX owns */
5559
    word16            dontFreeDigest:1;   /* when true, we used SetDigest */
5560
    word16            haveEMS:1;          /* using extended master secret */
5561
#ifdef HAVE_EXTENDED_MASTER
5562
    word16            disableEMS:1;       /* user disabled extended master
5563
                                           * secret */
5564
    word16            requireEMS:1;       /* user requires extended master
5565
                                           * secret */
5566
#endif
5567
#ifdef HAVE_POLY1305
5568
    word16            oldPoly:1;        /* set when to use old rfc way of poly*/
5569
#endif
5570
    word16            useAnon:1;       /* User wants to allow Anon suites */
5571
#ifdef HAVE_SESSION_TICKET
5572
    word16            createTicket:1;     /* Server to create new Ticket */
5573
    word16            useTicket:1;        /* Use Ticket not session cache */
5574
    word16            rejectTicket:1;     /* Callback rejected ticket */
5575
    word16            noTicketTls12:1;    /* TLS 1.2 server won't send ticket */
5576
#ifdef WOLFSSL_TLS13
5577
    word16            noTicketTls13:1;    /* Server won't create new Ticket */
5578
#ifdef WOLFSSL_EARLY_DATA
5579
    word16            ticketPredatesCtx:1; /* PSK ticket minted before ctx */
5580
#endif
5581
#if !defined(NO_WOLFSSL_SERVER) && \
5582
    defined(WOLFSSL_TLS13_TICKET_CHECK_PSK_MODES)
5583
    word16            pskKeModesRecvd:1;  /* CH had psk_key_exchange_modes */
5584
#endif
5585
#endif
5586
#endif
5587
#ifdef WOLFSSL_DTLS
5588
#ifdef HAVE_SECURE_RENEGOTIATION
5589
    word16            dtlsDoSCR:1;        /* Enough packets were dropped. We
5590
                                           * need to re-key. */
5591
#endif
5592
    word16            dtlsUseNonblock:1;  /* are we using nonblocking socket */
5593
    word16            dtlsHsRetain:1;     /* DTLS retaining HS data */
5594
#ifdef WOLFSSL_SCTP
5595
    word16            dtlsSctp:1;         /* DTLS-over-SCTP mode */
5596
#endif
5597
#endif /* WOLFSSL_DTLS */
5598
#if defined(HAVE_TLS_EXTENSIONS) && defined(HAVE_SUPPORTED_CURVES)
5599
    word16            userCurves:1;       /* indicates user called wolfSSL_UseSupportedCurve */
5600
    word16            peerNoUncompPF:1;   /* peer sent ec_point_formats without
5601
                                           * the uncompressed (0) format */
5602
#endif
5603
    word16            keepResources:1;    /* Keep resources after handshake */
5604
    word16            useClientOrder:1;   /* Use client's cipher order */
5605
    word16            mutualAuth:1;       /* Mutual authentication is required */
5606
    word16            peerAuthGood:1;     /* Any required peer auth done */
5607
#if defined(WOLFSSL_TLS13) && (defined(HAVE_SESSION_TICKET) || !defined(NO_PSK))
5608
    word16            pskNegotiated:1;    /* Session Ticket/PSK negotiated. */
5609
#endif
5610
#if defined(WOLFSSL_TLS13) && defined(WOLFSSL_POST_HANDSHAKE_AUTH)
5611
    word16            postHandshakeAuth:1;/* Client send post_handshake_auth
5612
                                           * extension */
5613
    word16            verifyPostHandshake:1; /* Only send client cert req post
5614
                                              * handshake, not also during */
5615
#endif
5616
#if defined(WOLFSSL_TLS13) && !defined(NO_WOLFSSL_SERVER)
5617
    word16            sendCookie:1;       /* Server creates a Cookie in HRR */
5618
#endif
5619
#ifdef WOLFSSL_ALT_CERT_CHAINS
5620
    word16            usingAltCertChain:1;/* Alternate cert chain was used */
5621
#endif
5622
#ifdef WOLFSSL_TLS13
5623
    word16            sentChangeCipher:1; /* Change Cipher Spec sent */
5624
#endif
5625
#if !defined(WOLFSSL_NO_CLIENT_AUTH) && \
5626
               ((defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3)) || \
5627
                (defined(HAVE_ED25519) && !defined(NO_ED25519_CLIENT_AUTH)) || \
5628
                (defined(HAVE_ED448) && !defined(NO_ED448_CLIENT_AUTH)))
5629
    word16            cacheMessages:1;    /* Cache messages for sign/verify */
5630
#endif
5631
#ifndef NO_DH
5632
    #if !defined(WOLFSSL_OLD_PRIME_CHECK) && \
5633
        !defined(HAVE_FIPS) && !defined(HAVE_SELFTEST)
5634
        word16        dhDoKeyTest:1;      /* Need to do the DH Key prime test */
5635
        word16        dhKeyTested:1;      /* Set when key has been tested. */
5636
    #endif
5637
#endif
5638
#ifdef HAVE_ENCRYPT_THEN_MAC
5639
    word16            disallowEncThenMac:1;   /* Don't do Encrypt-Then-MAC */
5640
    word16            encThenMac:1;           /* Doing Encrypt-Then-MAC */
5641
    word16            startedETMRead:1;       /* Doing Encrypt-Then-MAC read */
5642
    word16            startedETMWrite:1;      /* Doing Encrypt-Then-MAC write */
5643
#endif
5644
#ifdef WOLFSSL_ASYNC_CRYPT
5645
    word16            buildArgsSet:1;         /* buildArgs are set and need to
5646
                                               * be free'd */
5647
#ifdef WOLFSSL_TLS13
5648
    word16            buildArgs13Set:1;       /* a TLS 1.3 record build is in
5649
                                               * progress and must resume,
5650
                                               * not restart */
5651
    word16            chHashInput:1;          /* current ClientHello already
5652
                                               * hashed into the transcript;
5653
                                               * a PSK-binder pend must not
5654
                                               * re-hash it on resume */
5655
    word16            asyncReplayMsg:1;       /* the next TLS 1.3 handshake
5656
                                               * message is a replay of one
5657
                                               * whose handler pended; skip
5658
                                               * its sanity check once */
5659
#endif
5660
#endif
5661
#ifdef WOLFSSL_DTLS13
5662
    word16            dtls13SendMoreAcks:1;  /* Send more acks during the
5663
                                              * handshake process */
5664
#ifdef WOLFSSL_DTLS13_NO_HRR_ON_RESUME
5665
    word16            dtls13NoHrrOnResume:1;
5666
#endif
5667
#ifdef WOLFSSL_DTLS_CH_FRAG
5668
    word16            dtls13ChFrag:1;
5669
#endif
5670
#endif
5671
#ifdef WOLFSSL_TLS13
5672
    word16            tls13MiddleBoxCompat:1; /* TLSv1.3 middlebox compatibility */
5673
#endif
5674
#ifdef WOLFSSL_DTLS_CID
5675
    word16            useDtlsCID:1;
5676
#ifdef WOLFSSL_DTLS13
5677
    word16            haveSupportedVersions:1; /* Current Hello's version
5678
                                                * pre-scan succeeded and found
5679
                                                * supported_versions. */
5680
#endif
5681
#endif /* WOLFSSL_DTLS_CID */
5682
#if defined(WOLFSSL_TLS13) && defined(HAVE_ECH)
5683
    word16            echAccepted:1;
5684
    word16            disableECH:1;             /* Did the user disable ech */
5685
    word16            echProcessingInner:1;     /* Processing the inner hello */
5686
    word16            echRetryConfigsAccepted:1;
5687
    word16            enableEchTrialDecrypt:1;  /* Trial decryption of the
5688
                                                   inner hello */
5689
#endif
5690
#ifdef WOLFSSL_SEND_HRR_COOKIE
5691
    word16            cookieGood:1;
5692
#endif
5693
#ifdef WOLFSSL_TLS13
5694
#ifdef WOLFSSL_TLS13_COOKIE
5695
    word16            hrrSentCookie:1;    /* HRR sent with cookie */
5696
#endif
5697
    word16            hrrSentKeyShare:1;  /* HRR sent with key share */
5698
    word16            shSentKeyShare:1;   /* SH sent with key share */
5699
#endif
5700
    word16            returnOnGoodCh:1;
5701
    word16            disableRead:1;
5702
#if defined(WOLFSSL_ASYNC_CRYPT) && defined(WOLFSSL_ASYNC_CERT_YIELD)
5703
    /* Opt-in (WOLFSSL_ASYNC_CERT_YIELD): set when we deliberately returned
5704
     * WC_PENDING_E between peer certificate verifies so a cooperative scheduler
5705
     * can run. Lives in (zero-initialized, persistent) ssl->options so the
5706
     * fresh-entry vs. resume decision in ProcessPeerCerts is reliable; the
5707
     * transient ProcPeerCertArgs scratch buffer is not zeroed on alloc. */
5708
    word16            certYieldPending:1;
5709
#endif
5710
5711
#ifdef WOLFSSL_EARLY_DATA
5712
    word16            clientInEarlyData:1; /* Client is in wolfSSL_read_early_data */
5713
#endif
5714
#if defined(WOLFSSL_TLS13) && !defined(NO_CERTS) && !defined(WOLFSSL_NO_SIGALG)
5715
    word16            peerSha1CertOk:1;   /* Peer advertised a SHA-1 signature
5716
                                           * scheme for certificates */
5717
#endif
5718
#ifdef WOLFSSL_DTLS
5719
    byte              haveMcast;          /* using multicast ? */
5720
#endif
5721
    byte              buildingMsg;        /* If set then we need to re-enter the
5722
                                           * handshake logic. */
5723
    byte              seenUnifiedHdr;     /* received msg with unified header */
5724
    byte              shutdownDone;       /* we've completed a shutdown */
5725
    byte              sendKeyUpdate;      /* Key Update to write */
5726
#if defined(HAVE_RPK)
5727
    RpkConfig         rpkConfig;
5728
    RpkState          rpkState;
5729
#endif /* HAVE_RPK */
5730
5731
    /* need full byte values for this section */
5732
    byte            processReply;           /* nonblocking resume */
5733
    byte            cipherSuite0;           /* first byte, normally 0 */
5734
    byte            cipherSuite;            /* second byte, actual suite */
5735
#ifdef WOLFSSL_TLS13
5736
    byte            hrrCipherSuite0;        /* first byte, normally 0 */
5737
    byte            hrrCipherSuite;         /* second byte, actual suite */
5738
#endif
5739
    byte            hashAlgo;               /* selected hash algorithm */
5740
    byte            sigAlgo;                /* selected sig algorithm */
5741
    byte            peerHashAlgo;           /* peer's chosen hash algo */
5742
    byte            peerSigAlgo;            /* peer's chosen sig algo */
5743
    byte            serverState;
5744
    byte            clientState;
5745
    byte            handShakeState;
5746
    byte            handShakeDone;      /* at least one handshake complete */
5747
    byte            minDowngrade;       /* minimum downgrade version */
5748
    byte            connectState;       /* nonblocking resume */
5749
    byte            acceptState;        /* nonblocking resume */
5750
    byte            asyncState;         /* sub-state for enum asyncState */
5751
    byte            buildMsgState;      /* sub-state for enum buildMsgState */
5752
    byte            alertCount;         /* detect warning dos attempt */
5753
    byte            emptyRecordCount;   /* detect empty record dos attempt */
5754
#ifdef WOLFSSL_MULTICAST
5755
    word16          mcastID;            /* Multicast group ID */
5756
#endif
5757
#ifndef NO_DH
5758
    word16          minDhKeySz;         /* minimum DH key size */
5759
    word16          maxDhKeySz;         /* minimum DH key size */
5760
    word16          dhKeySz;            /* actual DH key size */
5761
#endif
5762
#ifndef NO_RSA
5763
    short           minRsaKeySz;      /* minimum RSA key size */
5764
#endif
5765
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || defined(HAVE_ED448)
5766
    short           minEccKeySz;      /* minimum ECC key size */
5767
#endif
5768
#if defined(HAVE_FALCON)
5769
    short           minFalconKeySz;   /* minimum Falcon key size */
5770
#endif
5771
#if defined(WOLFSSL_HAVE_MLDSA)
5772
    short           minMlDsaKeySz;    /* minimum ML-DSA key size */
5773
#endif
5774
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
5775
    byte            verifyDepth;      /* maximum verification depth */
5776
#endif
5777
#ifdef WOLFSSL_EARLY_DATA
5778
    word16          pskIdIndex;
5779
    word32          maxEarlyDataSz;
5780
#endif
5781
#ifdef WOLFSSL_TLS13
5782
    byte            oldMinor;          /* client preferred version < TLS 1.3 */
5783
#endif
5784
};
5785
5786
typedef struct Arrays {
5787
    byte*           preMasterSecret;
5788
    word32          preMasterSz;        /* differs for DH, actual size */
5789
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
5790
    word32          psk_keySz;          /* actual size */
5791
    char            client_identity[MAX_PSK_ID_LEN + NULL_TERM_LEN];
5792
    char            server_hint[MAX_PSK_ID_LEN + NULL_TERM_LEN];
5793
    byte            psk_key[MAX_PSK_KEY_LEN];
5794
#endif
5795
    byte            clientRandom[RAN_LEN];
5796
#if defined(WOLFSSL_TLS13) && defined(HAVE_ECH)
5797
    byte            clientRandomInner[RAN_LEN];
5798
#endif
5799
    byte            serverRandom[RAN_LEN];
5800
    byte            sessionID[ID_LEN];
5801
    byte            sessionIDSz;
5802
#ifdef WOLFSSL_TLS13
5803
    byte            secret[SECRET_LEN];
5804
#endif
5805
#ifdef HAVE_KEYING_MATERIAL
5806
    byte            exporterSecret[WC_MAX_DIGEST_SIZE];
5807
#endif
5808
    byte            masterSecret[SECRET_LEN];
5809
#if defined(WOLFSSL_RENESAS_TSIP_TLS) && \
5810
   !defined(NO_WOLFSSL_RENESAS_TSIP_TLS_SESSION)
5811
    byte            tsip_masterSecret[TSIP_TLS_MASTERSECRET_SIZE];
5812
#endif
5813
#if defined(WOLFSSL_RENESAS_FSPSM_TLS)
5814
    byte            fspsm_masterSecret[FSPSM_TLS_MASTERSECRET_SIZE];
5815
#endif
5816
#ifdef WOLFSSL_DTLS
5817
    byte            cookie[MAX_COOKIE_LEN];
5818
    byte            cookieSz;
5819
#endif
5820
} Arrays;
5821
5822
#ifndef ASN_NAME_MAX
5823
    #ifndef NO_ASN
5824
        /* use value from asn.h */
5825
0
        #define ASN_NAME_MAX WC_ASN_NAME_MAX
5826
    #else
5827
        /* calculate for WOLFSSL_X509 */
5828
        #if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL) || \
5829
            defined(WOLFSSL_CERT_EXT)
5830
            #define ASN_NAME_MAX 330
5831
        #else
5832
            #define ASN_NAME_MAX 256
5833
        #endif
5834
    #endif
5835
#endif
5836
5837
typedef enum {
5838
    STACK_TYPE_X509               = 0,
5839
    STACK_TYPE_GEN_NAME           = 1,
5840
    STACK_TYPE_BIO                = 2,
5841
    STACK_TYPE_OBJ                = 3,
5842
    STACK_TYPE_STRING             = 4,
5843
    STACK_TYPE_CIPHER             = 5,
5844
    STACK_TYPE_ACCESS_DESCRIPTION = 6,
5845
    STACK_TYPE_X509_EXT           = 7,
5846
    STACK_TYPE_NULL               = 8,
5847
    STACK_TYPE_X509_NAME          = 9,
5848
    STACK_TYPE_CONF_VALUE         = 10,
5849
    STACK_TYPE_X509_INFO          = 11,
5850
    STACK_TYPE_BY_DIR_entry       = 12,
5851
    STACK_TYPE_BY_DIR_hash        = 13,
5852
    STACK_TYPE_X509_OBJ           = 14,
5853
    STACK_TYPE_DIST_POINT         = 15,
5854
    STACK_TYPE_X509_CRL           = 16,
5855
    STACK_TYPE_X509_NAME_ENTRY    = 17,
5856
    STACK_TYPE_X509_REQ_ATTR      = 18,
5857
    STACK_TYPE_GENERAL_SUBTREE    = 19,
5858
    STACK_TYPE_X509_REVOKED       = 20
5859
} WOLF_STACK_TYPE;
5860
5861
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
5862
5863
struct WOLFSSL_STACK {
5864
    unsigned long num; /* number of nodes in stack
5865
                        * (safety measure for freeing and shortcut for count) */
5866
    #if defined(OPENSSL_ALL)
5867
    wolf_sk_hash_cb hash_fn;
5868
    unsigned long hash;
5869
    #endif
5870
5871
    union {
5872
        WOLFSSL_X509*          x509;
5873
        WOLFSSL_X509_NAME*     name;
5874
        WOLFSSL_X509_NAME_ENTRY* name_entry;
5875
        WOLFSSL_X509_INFO*     info;
5876
        WOLFSSL_BIO*           bio;
5877
        WOLFSSL_ASN1_OBJECT*   obj;
5878
        WOLFSSL_CIPHER         cipher;
5879
        WOLFSSL_ACCESS_DESCRIPTION* access;
5880
        WOLFSSL_X509_EXTENSION* ext;
5881
#ifdef OPENSSL_EXTRA
5882
        WOLFSSL_CONF_VALUE*    conf;
5883
#endif
5884
        void*                  generic;
5885
        char*                  string;
5886
        WOLFSSL_GENERAL_NAME*  gn;
5887
        WOLFSSL_GENERAL_SUBTREE* subtree;
5888
        WOLFSSL_BY_DIR_entry*  dir_entry;
5889
        WOLFSSL_BY_DIR_HASH*   dir_hash;
5890
        WOLFSSL_X509_OBJECT*   x509_obj;
5891
        WOLFSSL_DIST_POINT*    dp;
5892
        WOLFSSL_X509_CRL*      crl;
5893
        WOLFSSL_X509_REVOKED*  revoked;
5894
    } data;
5895
    void* heap; /* memory heap hint */
5896
    WOLFSSL_STACK* next;
5897
    WOLF_STACK_TYPE type;     /* Identifies type of stack. */
5898
};
5899
5900
#endif /* OPENSSL_EXTRA || OPENSSL_EXTRA_X509_SMALL */
5901
5902
struct WOLFSSL_X509_NAME {
5903
    char  *name;
5904
    int   dynamicName;
5905
    int   sz;
5906
    char  staticName[ASN_NAME_MAX];
5907
#if (defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)) && \
5908
    !defined(NO_ASN)
5909
    DecodedName fullName;
5910
    int   entrySz; /* number of entries */
5911
    WOLFSSL_X509_NAME_ENTRY entry[MAX_NAME_ENTRIES]; /* all entries i.e. CN */
5912
    WOLFSSL_X509*           x509;   /* x509 that struct belongs to */
5913
#endif /* OPENSSL_EXTRA */
5914
#ifndef WOLFSSL_NO_CA_NAMES
5915
    byte  raw[ASN_NAME_MAX];
5916
    int   rawLen;
5917
5918
    WOLF_STACK_OF(WOLFSSL_X509_NAME_ENTRY)* entries;
5919
#endif
5920
    void* heap;
5921
};
5922
5923
#ifndef EXTERNAL_SERIAL_SIZE
5924
    #define EXTERNAL_SERIAL_SIZE 32
5925
#endif
5926
5927
#ifdef NO_ASN
5928
    typedef struct DNS_entry DNS_entry;
5929
    #ifndef IGNORE_NAME_CONSTRAINTS
5930
        typedef struct Base_entry Base_entry;
5931
    #endif
5932
#endif
5933
5934
#ifndef WOLFSSL_AIA_ENTRY_DEFINED
5935
#ifndef WOLFSSL_MAX_AIA_ENTRIES
5936
    #define WOLFSSL_MAX_AIA_ENTRIES 8
5937
#endif
5938
5939
#define WOLFSSL_AIA_ENTRY_DEFINED
5940
typedef struct WOLFSSL_AIA_ENTRY {
5941
    word32      method; /* AIA method OID sum (e.g., AIA_OCSP_OID). */
5942
    const byte* uri;    /* Pointer into cert DER for the URI. */
5943
    word32      uriSz;  /* Length of URI data. */
5944
} WOLFSSL_AIA_ENTRY;
5945
#endif /* WOLFSSL_AIA_ENTRY_DEFINED */
5946
5947
struct WOLFSSL_X509 {
5948
    int              version;
5949
    int              serialSz;
5950
#ifdef WOLFSSL_SEP
5951
    int              deviceTypeSz;
5952
    int              hwTypeSz;
5953
    byte             deviceType[EXTERNAL_SERIAL_SIZE];
5954
    byte             hwType[EXTERNAL_SERIAL_SIZE];
5955
    int              hwSerialNumSz;
5956
    byte             hwSerialNum[EXTERNAL_SERIAL_SIZE];
5957
    byte             certPolicySet;
5958
    byte             certPolicyCrit;
5959
#endif /* WOLFSSL_SEP */
5960
#if defined(WOLFSSL_QT) || defined(OPENSSL_ALL) || defined(OPENSSL_EXTRA)
5961
    WOLFSSL_STACK* ext_sk; /* Store X509_EXTENSIONS from wolfSSL_X509_get_ext */
5962
    WOLFSSL_STACK* ext_sk_full; /* Store X509_EXTENSIONS from wolfSSL_X509_get0_extensions */
5963
    WOLFSSL_STACK* ext_d2i;/* Store d2i extensions from wolfSSL_X509_get_ext_d2i */
5964
#endif /* WOLFSSL_QT || OPENSSL_ALL */
5965
#if defined(OPENSSL_EXTRA) || defined(WOLFSSL_WPAS_SMALL)
5966
    WOLFSSL_ASN1_INTEGER* serialNumber; /* Stores SN from wolfSSL_X509_get_serialNumber */
5967
#endif
5968
    WOLFSSL_ASN1_TIME notBefore;
5969
    WOLFSSL_ASN1_TIME notAfter;
5970
    buffer           sig;
5971
    int              sigOID;
5972
    DNS_entry*       altNames;                       /* alt names list */
5973
#ifndef IGNORE_NAME_CONSTRAINTS
5974
    Base_entry*      permittedNames;                 /* name constraints */
5975
    Base_entry*      excludedNames;
5976
    byte             nameConstraintCrit:1;
5977
#endif
5978
    buffer           pubKey;
5979
    int              pubKeyOID;
5980
    DNS_entry*       altNamesNext;                   /* hint for retrieval */
5981
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || defined(HAVE_ED448) || \
5982
    defined(HAVE_FALCON) || defined(WOLFSSL_HAVE_MLDSA) || \
5983
    defined(WOLFSSL_HAVE_SLHDSA)
5984
    word32       pkCurveOID;
5985
#endif
5986
#ifndef NO_CERTS
5987
    DerBuffer*   derCert;                            /* may need  */
5988
#endif
5989
    void*            heap;                           /* heap hint */
5990
    byte             dynamicMemory;                  /* dynamic memory flag */
5991
    byte             isCa:1;
5992
#ifdef WOLFSSL_CERT_EXT
5993
    char             certPolicies[MAX_CERTPOL_NB][MAX_CERTPOL_SZ];
5994
    int              certPoliciesNb;
5995
#endif /* WOLFSSL_CERT_EXT */
5996
#if defined(OPENSSL_EXTRA_X509_SMALL) || defined(OPENSSL_EXTRA)
5997
    wolfSSL_Ref      ref;
5998
#endif
5999
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
6000
#ifdef HAVE_EX_DATA
6001
    WOLFSSL_CRYPTO_EX_DATA ex_data;
6002
#endif
6003
    byte*            authKeyId; /* Points into authKeyIdSrc */
6004
    byte*            authKeyIdSrc;
6005
    byte*            subjKeyId;
6006
    WOLFSSL_ASN1_STRING* subjKeyIdStr;
6007
    byte*            extKeyUsageSrc;
6008
#ifdef OPENSSL_ALL
6009
    byte*            subjAltNameSrc;
6010
#endif
6011
    byte*            rawCRLInfo;
6012
    byte*            CRLInfo;
6013
    byte*            authInfo;
6014
#ifdef WOLFSSL_ASN_CA_ISSUER
6015
    byte*            authInfoCaIssuer;
6016
    int              authInfoCaIssuerSz;
6017
#endif
6018
    WOLFSSL_AIA_ENTRY authInfoList[WOLFSSL_MAX_AIA_ENTRIES];
6019
    byte             authInfoListSz:7;
6020
    byte             authInfoListOverflow:1;
6021
    word32           pathLength;
6022
    word16           keyUsage;
6023
    int              rawCRLInfoSz;
6024
    int              CRLInfoSz;
6025
    int              authInfoSz;
6026
    word32           authKeyIdSz;
6027
    word32           authKeyIdSrcSz;
6028
    word32           subjKeyIdSz;
6029
    byte             extKeyUsage;
6030
    word32           extKeyUsageSz;
6031
    word32           extKeyUsageCount;
6032
#ifndef IGNORE_NETSCAPE_CERT_TYPE
6033
    byte             nsCertType;
6034
#endif
6035
#ifdef OPENSSL_ALL
6036
    word32           subjAltNameSz;
6037
#endif
6038
6039
    byte             CRLdistSet:1;
6040
    byte             CRLdistCrit:1;
6041
    byte             authInfoSet:1;
6042
    byte             authInfoCrit:1;
6043
    byte             keyUsageSet:1;
6044
    byte             keyUsageCrit:1;
6045
    byte             extKeyUsageCrit:1;
6046
    byte             subjKeyIdSet:1;
6047
    byte             pathLengthSet:1;
6048
6049
    byte             subjKeyIdCrit:1;
6050
    byte             basicConstSet:1;
6051
    byte             basicConstCrit:1;
6052
    byte             basicConstPlSet:1;
6053
    byte             subjAltNameSet:1;
6054
    byte             subjAltNameCrit:1;
6055
    byte             authKeyIdSet:1;
6056
    byte             authKeyIdCrit:1;
6057
    byte             issuerSet:1;
6058
#ifdef WOLFSSL_CUSTOM_OID
6059
    CertExtension    custom_exts[NUM_CUSTOM_EXT];
6060
    int              customExtCount;
6061
#endif /* WOLFSSL_CUSTOM_OID */
6062
#endif /* OPENSSL_EXTRA || OPENSSL_EXTRA_X509_SMALL */
6063
#ifdef WOLFSSL_CERT_REQ
6064
    byte             isCSR:1;
6065
#endif
6066
    byte             serial[EXTERNAL_SERIAL_SIZE];
6067
    char             subjectCN[ASN_NAME_MAX];        /* common name short cut */
6068
#if defined(WOLFSSL_CERT_REQ) || defined(WOLFSSL_CERT_GEN)
6069
#if defined(OPENSSL_ALL) || defined(OPENSSL_EXTRA)
6070
    /* stack of CSR attributes */
6071
    WOLF_STACK_OF(WOLFSSL_X509_ATRIBUTE)* reqAttributes;
6072
#endif
6073
    #if defined(WOLFSSL_CERT_REQ)
6074
    char             challengePw[CTC_NAME_SIZE]; /* for REQ certs */
6075
    char             contentType[CTC_NAME_SIZE];
6076
    #endif
6077
#endif /* WOLFSSL_CERT_REQ || WOLFSSL_CERT_GEN */
6078
    WOLFSSL_X509_NAME issuer;
6079
    WOLFSSL_X509_NAME subject;
6080
#if defined(OPENSSL_ALL) || defined(OPENSSL_EXTRA) || \
6081
    defined(OPENSSL_EXTRA_X509_SMALL) || defined(WOLFSSL_APACHE_HTTPD) || \
6082
    defined(WOLFSSL_HAPROXY) || defined(WOLFSSL_WPAS)
6083
    WOLFSSL_X509_ALGOR algor;
6084
    WOLFSSL_X509_PUBKEY key;
6085
#endif
6086
#if defined(OPENSSL_EXTRA_X509_SMALL) || defined(OPENSSL_EXTRA) || \
6087
    defined(OPENSSL_ALL) || defined(KEEP_OUR_CERT) || \
6088
    defined(KEEP_PEER_CERT) || defined(SESSION_CERTS)
6089
    byte            notBeforeData[CTC_DATE_SIZE];
6090
    byte            notAfterData[CTC_DATE_SIZE];
6091
#endif
6092
#ifdef WOLFSSL_DUAL_ALG_CERTS
6093
    /* Subject Alternative Public Key Info */
6094
    byte *sapkiDer;
6095
    int sapkiLen;
6096
    /* Alternative Signature Algorithm */
6097
    byte *altSigAlgDer;
6098
    int altSigAlgLen;
6099
    /* Alternative Signature Value */
6100
    byte *altSigValDer;
6101
    int altSigValLen;
6102
6103
    byte sapkiCrit:1;
6104
    byte altSigAlgCrit:1;
6105
    byte altSigValCrit:1;
6106
#endif /* WOLFSSL_DUAL_ALG_CERTS */
6107
};
6108
6109
#if defined(WOLFSSL_ACERT)
6110
struct WOLFSSL_X509_ACERT {
6111
    int               version;
6112
    int               serialSz;
6113
    byte              serial[EXTERNAL_SERIAL_SIZE];
6114
    WOLFSSL_ASN1_TIME notBefore;
6115
    WOLFSSL_ASN1_TIME notAfter;
6116
    buffer            sig;
6117
    int               sigOID;
6118
#ifndef NO_CERTS
6119
    DerBuffer *       derCert;
6120
#endif
6121
    void *            heap;
6122
    int               dynamic; /* whether struct was dynamically allocated */
6123
    /* copy of raw Attributes field from */
6124
    byte              holderSerial[EXTERNAL_SERIAL_SIZE];
6125
    int               holderSerialSz;
6126
    DNS_entry *       holderEntityName;  /* Holder entityName from ACERT */
6127
    DNS_entry *       holderIssuerName;  /* issuerName from ACERT */
6128
    DNS_entry *       AttCertIssuerName; /* AttCertIssuer name from ACERT */
6129
    byte *            rawAttr;
6130
    word32            rawAttrLen;
6131
};
6132
#endif /* WOLFSSL_ACERT */
6133
6134
/* record layer header for PlainText, Compressed, and CipherText */
6135
typedef struct RecordLayerHeader {
6136
    byte            type;
6137
    byte            pvMajor;
6138
    byte            pvMinor;
6139
    byte            length[2];
6140
} RecordLayerHeader;
6141
6142
6143
/* record layer header for DTLS PlainText, Compressed, and CipherText */
6144
typedef struct DtlsRecordLayerHeader {
6145
    byte            type;
6146
    byte            pvMajor;
6147
    byte            pvMinor;
6148
    byte            sequence_number[8];   /* per record */
6149
    byte            length[2];
6150
} DtlsRecordLayerHeader;
6151
6152
typedef struct DtlsFragBucket {
6153
    /* m stands for meta */
6154
    union {
6155
        struct {
6156
            struct DtlsFragBucket* next;
6157
            word32 offset;
6158
            word32 sz;
6159
        } m;
6160
        /* Make sure we have at least DTLS_HANDSHAKE_HEADER_SZ bytes before the
6161
         * buf so that we can reconstruct the header in the allocated
6162
         * DtlsFragBucket buffer. */
6163
        byte padding[DTLS_HANDSHAKE_HEADER_SZ];
6164
    } m;
6165
/* Ignore "nonstandard extension used : zero-sized array in struct/union"
6166
 * MSVC warning */
6167
#ifdef _MSC_VER
6168
#pragma warning(disable: 4200)
6169
#endif
6170
    byte buf[WC_FLEXIBLE_ARRAY_SIZE];
6171
} DtlsFragBucket;
6172
6173
typedef struct DtlsMsg {
6174
    struct DtlsMsg* next;
6175
    byte*           raw;
6176
    byte*           fullMsg;   /* for TX fullMsg == raw. For RX this points to
6177
                                * the start of the message after headers. */
6178
    DtlsFragBucket* fragBucketList;
6179
    word32          bytesReceived;
6180
    word16          epoch;     /* Epoch that this message belongs to */
6181
    word32          seq;       /* Handshake sequence number    */
6182
    word32          sz;        /* Length of whole message      */
6183
    byte            type;
6184
    byte            fragBucketListCount;
6185
    byte            ready:1;
6186
    byte            encrypted:1;
6187
} DtlsMsg;
6188
6189
6190
#ifdef HAVE_NETX
6191
6192
    /* NETX I/O Callback default */
6193
    typedef struct NetX_Ctx {
6194
        NX_TCP_SOCKET* nxTcpSocket; /* send/recv tcp socket handle */
6195
        NX_PACKET*     nxPacket;    /* incoming packet handle for short reads */
6196
        ULONG          nxOffset;    /* offset already read from nxPacket */
6197
        ULONG          nxWait;      /* wait option flag */
6198
/* WOLFSSL_NETX_DUO: requires ThreadX NetX Duo (NXD_ADDRESS, nxd_udp_socket_send) */
6199
#if defined(WOLFSSL_DTLS) && defined(WOLFSSL_NETX_DUO)
6200
        NX_UDP_SOCKET* nxUdpSocket; /* send/recv udp socket handle */
6201
        NXD_ADDRESS    nxdIp;       /* destination IP address for udp send */
6202
        USHORT         nxPort;      /* destination port for udp send */
6203
#endif /* WOLFSSL_DTLS && WOLFSSL_NETX_DUO */
6204
    } NetX_Ctx;
6205
6206
#endif
6207
6208
/* Handshake messages received from peer (plus change cipher */
6209
typedef struct MsgsReceived {
6210
    word16 got_hello_request:1;
6211
    word16 got_client_hello:2;
6212
    word16 got_server_hello:1;
6213
    word16 got_hello_verify_request:1;
6214
    word16 got_session_ticket:1;
6215
    word16 got_end_of_early_data:1;
6216
    word16 got_hello_retry_request:1;
6217
    word16 got_encrypted_extensions:1;
6218
    word16 got_certificate:1;
6219
    word16 got_certificate_status:1;
6220
    word16 got_server_key_exchange:1;
6221
    word16 got_certificate_request:1;
6222
    word16 got_server_hello_done:1;
6223
    word16 got_certificate_verify:1;
6224
    word16 got_client_key_exchange:1;
6225
    word16 got_finished:1;
6226
    word16 got_key_update:1;
6227
    word16 got_change_cipher:1;
6228
} MsgsReceived;
6229
6230
6231
/* configure and CMake refuse this; a user_settings.h build reaches neither
6232
 * and would fail with "no member named hashSha512" instead. */
6233
#if defined(WOLFSSL_TLS13_SHA512) && !defined(WOLFSSL_SHA512)
6234
    #error "WOLFSSL_TLS13_SHA512 requires WOLFSSL_SHA512"
6235
#endif
6236
6237
/* Hashed for the TLS 1.2 signature algorithms, and kept for TLS 1.3 when
6238
 * WOLFSSL_TLS13_SHA512 allows SHA-512 as its handshake hash. No suite selects
6239
 * SHA-512, so TLS 1.3 reaches it only for the HRR cookie HMAC. */
6240
#if defined(WOLFSSL_SHA512) && (!defined(WOLFSSL_NO_TLS12) || \
6241
                                defined(WOLFSSL_TLS13_SHA512))
6242
    #define WOLFSSL_HS_HASH_SHA512
6243
#endif
6244
6245
/* Handshake hashes */
6246
typedef struct HS_Hashes {
6247
#ifndef WOLFSSL_NO_TLS12
6248
    Hashes          verifyHashes;
6249
    Hashes          certHashes;         /* for cert verify */
6250
#endif
6251
#if !defined(NO_SHA) && (!defined(NO_OLD_TLS) || \
6252
                          defined(WOLFSSL_ALLOW_TLS_SHA1))
6253
    wc_Sha          hashSha;            /* sha hash of handshake msgs */
6254
#endif
6255
#if !defined(NO_MD5) && !defined(NO_OLD_TLS)
6256
    wc_Md5          hashMd5;            /* md5 hash of handshake msgs */
6257
#endif
6258
#ifndef NO_SHA256
6259
    wc_Sha256       hashSha256;         /* sha256 hash of handshake msgs */
6260
#endif
6261
#ifdef WOLFSSL_SHA384
6262
    wc_Sha384       hashSha384;         /* sha384 hash of handshake msgs */
6263
#endif
6264
#ifdef WOLFSSL_HS_HASH_SHA512
6265
    wc_Sha512       hashSha512;         /* sha512 hash of handshake msgs */
6266
#endif
6267
#ifdef WOLFSSL_SM3
6268
    wc_Sm3          hashSm3;            /* sm3 hash of handshake msgs */
6269
#endif
6270
#if (defined(HAVE_ED25519) || defined(HAVE_ED448) || \
6271
     (defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3))) && \
6272
    !defined(WOLFSSL_NO_CLIENT_AUTH)
6273
    byte*           messages;           /* handshake messages */
6274
    int             length;             /* length of handshake messages' data */
6275
    int             prevLen;            /* length of messages but last */
6276
#endif
6277
} HS_Hashes;
6278
6279
6280
#if !defined(WOLFSSL_NO_TLS12) || defined(WOLFSSL_TLS13)
6281
/* Persistable BuildMessage/BuildTls13Message arguments */
6282
typedef struct BuildMsgArgs {
6283
    word32 digestSz;
6284
    word32 sz;
6285
    word32 pad;
6286
    word32 idx;
6287
    word32 headerSz;
6288
    word16 size;
6289
    word32 ivSz;      /* TLSv1.1  IV */
6290
    byte   type;
6291
    byte*  iv;
6292
    ALIGN16 byte staticIvBuffer[MAX_IV_SZ];
6293
} BuildMsgArgs;
6294
#endif
6295
6296
#ifdef WOLFSSL_ASYNC_IO
6297
    #define MAX_ASYNC_ARGS 24
6298
    typedef void (*FreeArgsCb)(struct WOLFSSL* ssl, void* pArgs);
6299
6300
    struct WOLFSSL_ASYNC {
6301
#if defined(WOLFSSL_ASYNC_CRYPT) && \
6302
    (!defined(WOLFSSL_NO_TLS12) || defined(WOLFSSL_TLS13))
6303
        /* Record builder resume args, shared by BuildMessage() and
6304
         * BuildTls13Message(): a connection runs only one of them. */
6305
        BuildMsgArgs  buildArgs;
6306
#endif
6307
        FreeArgsCb    freeArgs; /* function pointer to cleanup args */
6308
#ifdef WC_NO_PTR_INT_CAST
6309
        max_align_t args[MAX_ASYNC_ARGS * sizeof(word32) / sizeof(max_align_t)]; /* holder for current args */
6310
#else
6311
        word32        args[MAX_ASYNC_ARGS]; /* holder for current args */
6312
#endif
6313
    };
6314
#endif
6315
6316
#ifdef HAVE_WRITE_DUP
6317
6318
    #define WRITE_DUP_SIDE 1
6319
    #define READ_DUP_SIDE 2
6320
6321
    typedef struct WriteDup {
6322
        wolfSSL_Mutex   dupMutex;       /* field access mutex */
6323
        int             dupCount;       /* reference count */
6324
        int             dupErr;         /* under dupMutex, pass to other side */
6325
#ifdef WOLFSSL_DTLS13
6326
        struct Dtls13RecordNumber* sendAckList; /* ownership transferred */
6327
        /* Key update ACK tracking: write side stores the (epoch, seq) of its
6328
         * in-flight KeyUpdate; read side sets keyUpdateAcked when the ACK for
6329
         * that exact record arrives.  Both epoch and seq are checked to avoid
6330
         * false positives from data records in the same epoch. */
6331
        w64wrapper keyUpdateEpoch;     /* epoch of the KeyUpdate */
6332
        w64wrapper keyUpdateSeq;       /* seq num of the KeyUpdate */
6333
#endif /* WOLFSSL_DTLS13 */
6334
#ifdef WOLFSSL_TLS13
6335
#ifdef WOLFSSL_POST_HANDSHAKE_AUTH
6336
        /* Post-handshake certificate request delegation: the read side received
6337
         * a CertificateRequest but cannot write; it saves state here and the
6338
         * write side sends Certificate+CertificateVerify+Finished. */
6339
        struct HS_Hashes* postHandshakeHashState;    /* transcript at CR time */
6340
        struct CertReqCtx* postHandshakeCertReqCtx; /* context from CR */
6341
        byte postHandshakeSendVerify;    /* ssl->options.sendVerify */
6342
        byte postHandshakeSigAlgo;       /* ssl->options.sigAlgo */
6343
        byte postHandshakeHashAlgo;      /* ssl->options.hashAlgo */
6344
#if !defined(NO_CERTS) && !defined(WOLFSSL_NO_SIGALG)
6345
        byte postHandshakeSha1CertOk;    /* ssl->options.peerSha1CertOk */
6346
#endif
6347
        /* After the write side sends the PHA response, it stores its updated
6348
         * transcript here so the read side can resume from it on the next
6349
         * CertificateRequest (keeps client/server transcript in sync). */
6350
        struct HS_Hashes* postHandshakeSyncedHashState;
6351
#endif /* WOLFSSL_POST_HANDSHAKE_AUTH */
6352
#endif /* WOLFSSL_TLS13 */
6353
6354
        /* Flags */
6355
#ifdef WOLFSSL_DTLS13
6356
        WC_BITFIELD keyUpdateWaiting:1; /* write side has an unACKed KeyUpdate */
6357
        WC_BITFIELD keyUpdateAcked:1;   /* read side confirmed the ACK arrived */
6358
        /* DTLS 1.3: read side cannot write, so it passes ACK work to the
6359
         * write side. */
6360
        WC_BITFIELD sendAcks:1;
6361
#endif /* WOLFSSL_DTLS13 */
6362
#ifdef WOLFSSL_TLS13
6363
        /* TLS 1.3 (and DTLS 1.3): read side received a KeyUpdate(update_requested)
6364
         * but cannot send the response; write side handles it. */
6365
        WC_BITFIELD keyUpdateRespond:1; /* write side must send a KeyUpdate response */
6366
#ifdef WOLFSSL_POST_HANDSHAKE_AUTH
6367
        WC_BITFIELD postHandshakeAuthPending:1; /* write side must respond */
6368
#endif /* WOLFSSL_POST_HANDSHAKE_AUTH */
6369
#endif /* WOLFSSL_TLS13 */
6370
    } WriteDup;
6371
6372
    WOLFSSL_LOCAL void FreeWriteDup(WOLFSSL* ssl);
6373
    WOLFSSL_LOCAL int  NotifyWriteSide(WOLFSSL* ssl, int err);
6374
#endif /* HAVE_WRITE_DUP */
6375
6376
#if defined(WOLFSSL_TLS13) && defined(WOLFSSL_POST_HANDSHAKE_AUTH)
6377
typedef struct CertReqCtx CertReqCtx;
6378
6379
struct CertReqCtx {
6380
    CertReqCtx* next;
6381
    byte        len;
6382
    byte        ctx;
6383
};
6384
#endif
6385
6386
#ifdef WOLFSSL_EARLY_DATA
6387
typedef enum EarlyDataState {
6388
    no_early_data,
6389
    early_data_ext,
6390
    expecting_early_data,
6391
    process_early_data,
6392
    done_early_data
6393
} EarlyDataState;
6394
#endif
6395
6396
#ifdef WOLFSSL_DTLS13
6397
6398
/* size of the mask used to encrypt/decrypt Record Number  */
6399
#define DTLS13_RN_MASK_SIZE 16
6400
6401
typedef struct Dtls13UnifiedHdrInfo {
6402
    word16 recordLength;
6403
    byte seqLo;
6404
    byte seqHi;
6405
    byte seqHiPresent:1;
6406
    byte epochBits;
6407
} Dtls13UnifiedHdrInfo;
6408
6409
enum  {
6410
    DTLS13_EPOCH_EARLYDATA = 1,
6411
    DTLS13_EPOCH_HANDSHAKE = 2,
6412
    DTLS13_EPOCH_TRAFFIC0 = 3
6413
};
6414
6415
/* Sender-side DTLS 1.3 epoch ceiling: we MUST NOT advance our own epoch past
6416
 * 2^48-1 (RFC 9147 Section 4.2.1). This gates only the sending epoch; receivers
6417
 * MUST NOT enforce it on the peer epoch (RFC 9147 Section 8). Expressed as the
6418
 * high/low 32-bit halves of a w64wrapper. */
6419
#define DTLS13_EPOCH_MAX_HI32 0x0000FFFFU
6420
#define DTLS13_EPOCH_MAX_LO32 0xFFFFFFFFU
6421
6422
/* 64-bit epoch + 64-bit sequence number */
6423
#define DTLS13_RN_SIZE (OPAQUE64_LEN + OPAQUE64_LEN)
6424
/* Maximum number of ACK records allowed in an ACK message */
6425
#ifndef DTLS13_ACK_MAX_RECORDS
6426
#define DTLS13_ACK_MAX_RECORDS 128
6427
#endif
6428
/* WOLFSSL_MAX_16BIT / DTLS13_RN_SIZE (0xffff / (OPAQUE64_LEN + OPAQUE64_LEN))
6429
 * Literals are used because OPAQUE64_LEN is an enum value, invisible to the
6430
 * preprocessor. */
6431
#if DTLS13_ACK_MAX_RECORDS > 0xffff / 16
6432
#error "DTLS13_ACK_MAX_RECORDS exceeds the maximum encodable in the word16 length field"
6433
#endif
6434
6435
6436
typedef struct Dtls13Epoch {
6437
    w64wrapper epochNumber;
6438
6439
    w64wrapper nextSeqNumber;
6440
    w64wrapper nextPeerSeqNumber;
6441
6442
#ifndef WOLFSSL_TLS13_IGNORE_AEAD_LIMITS
6443
    w64wrapper dropCount; /* Amount of records that failed decryption */
6444
#endif
6445
6446
    word32 window[WOLFSSL_DTLS_WINDOW_WORDS];
6447
6448
    /* key material for the epoch */
6449
    byte client_write_key[MAX_SYM_KEY_SIZE];
6450
    byte server_write_key[MAX_SYM_KEY_SIZE];
6451
    byte client_write_IV[MAX_WRITE_IV_SZ];
6452
    byte server_write_IV[MAX_WRITE_IV_SZ];
6453
6454
    byte aead_exp_IV[AEAD_MAX_EXP_SZ];
6455
    byte aead_enc_imp_IV[AEAD_MAX_IMP_SZ];
6456
    byte aead_dec_imp_IV[AEAD_MAX_IMP_SZ];
6457
6458
    byte client_sn_key[MAX_SYM_KEY_SIZE];
6459
    byte server_sn_key[MAX_SYM_KEY_SIZE];
6460
6461
    byte isValid;
6462
    byte side;
6463
} Dtls13Epoch;
6464
6465
#ifndef DTLS13_EPOCH_SIZE
6466
#define DTLS13_EPOCH_SIZE 4
6467
#endif
6468
6469
/* our epoch, peer epoch, peer epoch - 1 and a free slot for a new epoch */
6470
#if DTLS13_EPOCH_SIZE < 4
6471
#error "DTLS13_EPOCH_SIZE must be at least 4"
6472
#endif
6473
6474
#ifndef DTLS13_RETRANS_RN_SIZE
6475
#define DTLS13_RETRANS_RN_SIZE 3
6476
#endif
6477
6478
enum Dtls13RtxFsmState {
6479
    DTLS13_RTX_FSM_PREPARING = 0,
6480
    DTLS13_RTX_FSM_SENDING,
6481
    DTLS13_RTX_FSM_WAITING,
6482
    DTLS13_RTX_FSM_FINISHED
6483
};
6484
6485
typedef struct Dtls13RtxRecord {
6486
    struct Dtls13RtxRecord *next;
6487
    word16 length;
6488
    byte *data;
6489
    w64wrapper epoch;
6490
    w64wrapper seq[DTLS13_RETRANS_RN_SIZE];
6491
    byte rnIdx;
6492
    byte handshakeType;
6493
} Dtls13RtxRecord;
6494
6495
typedef struct Dtls13RecordNumber {
6496
    struct Dtls13RecordNumber *next;
6497
    w64wrapper epoch;
6498
    w64wrapper seq;
6499
} Dtls13RecordNumber;
6500
6501
typedef struct Dtls13Rtx {
6502
#ifdef WOLFSSL_RW_THREADED
6503
    wolfSSL_Mutex mutex;
6504
#endif
6505
    enum Dtls13RtxFsmState state; /* Unused? */
6506
    Dtls13RtxRecord *rtxRecords;
6507
    Dtls13RtxRecord **rtxRecordTailPtr;
6508
    Dtls13RecordNumber *seenRecords;
6509
    word16 seenRecordsCount;
6510
#ifdef WOLFSSL_32BIT_MILLI_TIME
6511
    word32 lastRtx;
6512
#else
6513
    sword64 lastRtx;
6514
#endif
6515
    byte triggeredRtxs; /* Unused? */
6516
    byte sendAcks;
6517
    byte retransmit;
6518
} Dtls13Rtx;
6519
6520
#endif /* WOLFSSL_DTLS13 */
6521
6522
#ifdef WOLFSSL_DTLS_CID
6523
typedef struct ConnectionID {
6524
    byte length;
6525
/* Ignore "nonstandard extension used : zero-sized array in struct/union"
6526
 * MSVC warning */
6527
#ifdef _MSC_VER
6528
#pragma warning(disable: 4200)
6529
#endif
6530
    byte id[];
6531
} ConnectionID;
6532
6533
typedef struct CIDInfo {
6534
    ConnectionID* tx;
6535
    ConnectionID* rx;
6536
    byte negotiated : 1;
6537
} CIDInfo;
6538
6539
/* ConnectionIdUsage of the NewConnectionId message (RFC 9147 Section 9) */
6540
enum ConnectionIdUsage {
6541
    cid_immediate = 0,
6542
    cid_spare     = 1
6543
};
6544
#endif /* WOLFSSL_DTLS_CID */
6545
6546
/* The idea is to reuse the context suites object whenever possible to save
6547
 * space. */
6548
#define WOLFSSL_SUITES(ssl) \
6549
41.3k
    ((const Suites*) ((ssl)->suites != NULL ? \
6550
41.3k
        (ssl)->suites : \
6551
41.3k
        (ssl)->ctx->suites))
6552
6553
/* wolfSSL ssl type */
6554
6555
/* TLS 1.3 key-schedule resume steps (kdfMsgStep/kdfDeriveStep). A value is
6556
 * recorded after its named operation completes ("step <= X" = X not done);
6557
 * 0 = sequence not entered or finished. Values repeat across sequences. */
6558
6559
/* Receive side (kdfMsgStep), driven by DoTls13MsgDerives(). */
6560
enum Tls13KdfMsgStep {
6561
    TLS13_MSG_KDF_NONE                    = 0,
6562
    /* client processing server_hello */
6563
    TLS13_MSG_KDF_SH_ENTERED              = 1,
6564
    TLS13_MSG_KDF_SH_EARLY_SECRET         = 2,
6565
    TLS13_MSG_KDF_SH_HS_SECRET            = 3,
6566
    TLS13_MSG_KDF_SH_HS_KEYS              = 4,
6567
    TLS13_MSG_KDF_SH_KEYS_SET             = 5,
6568
    TLS13_MSG_KDF_SH_DTLS_EPOCH           = 6,
6569
    /* client processing finished */
6570
    TLS13_MSG_KDF_FIN_ENTERED             = 1,
6571
    TLS13_MSG_KDF_FIN_MASTER_SECRET       = 2,
6572
    TLS13_MSG_KDF_FIN_QUIC_EARLY_KEYS     = 3,
6573
    TLS13_MSG_KDF_FIN_TRAFFIC_KEYS        = 4,
6574
    TLS13_MSG_KDF_FIN_TRAFFIC_DONE        = 5,
6575
    TLS13_MSG_KDF_FIN_KEYS_SET            = 6,
6576
    /* server processing finished (resumption secret for tickets) */
6577
    TLS13_MSG_KDF_SFIN_ENTERED            = 1,
6578
    TLS13_MSG_KDF_SFIN_RESUMPTION_SECRET  = 2
6579
};
6580
6581
/* Send side (kdfDeriveStep), inside the senders themselves. */
6582
enum Tls13KdfSendStep {
6583
    TLS13_SEND_KDF_NONE                   = 0,
6584
    /* SendTls13EncryptedExtensions() */
6585
    TLS13_SEND_KDF_EE_HS_SECRET           = 1,
6586
    TLS13_SEND_KDF_EE_HS_KEYS             = 2,
6587
    TLS13_SEND_KDF_EE_ENC_KEYS_SET        = 3,
6588
    TLS13_SEND_KDF_EE_KEYS_SET            = 4,
6589
    TLS13_SEND_KDF_EE_DTLS_EPOCH          = 5,
6590
    /* SendTls13Finished() */
6591
    TLS13_SEND_KDF_FIN_ENTERED            = 1,
6592
    TLS13_SEND_KDF_FIN_MASTER_SECRET      = 2,
6593
    TLS13_SEND_KDF_FIN_ENC_TRAFFIC_KEYS   = 3,
6594
    TLS13_SEND_KDF_FIN_TRAFFIC_KEYS       = 4,
6595
    TLS13_SEND_KDF_FIN_ENC_KEYS_SET       = 5,
6596
    TLS13_SEND_KDF_FIN_DTLS_TRAFFIC_EPOCH = 6,
6597
    TLS13_SEND_KDF_FIN_EARLY_ENC_KEYS     = 7,
6598
    TLS13_SEND_KDF_FIN_EARLY_KEYS_SET     = 8,
6599
    TLS13_SEND_KDF_FIN_RESUMPTION_SECRET  = 9,
6600
    TLS13_SEND_KDF_FIN_DTLS_EPOCH_SET     = 10
6601
};
6602
6603
6604
struct WOLFSSL {
6605
    WOLFSSL_CTX*    ctx;
6606
#if defined(WOLFSSL_HAPROXY)
6607
    WOLFSSL_CTX*    initial_ctx; /* preserve session key materials */
6608
#endif
6609
    Suites*         suites; /* Only need during handshake. Can be NULL when
6610
                             * reusing the context's object. When WOLFSSL
6611
                             * object needs separate instance of suites use
6612
                             * AllocateSuites(). */
6613
    Suites*         clSuites;
6614
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_ALL) || \
6615
    defined(WOLFSSL_NGINX) || defined(WOLFSSL_HAPROXY)
6616
    WOLF_STACK_OF(WOLFSSL_CIPHER)* suitesStack; /* stack of available cipher
6617
                                                 * suites */
6618
    WOLF_STACK_OF(WOLFSSL_CIPHER)* clSuitesStack; /* stack of client cipher
6619
                                                   * suites */
6620
#endif
6621
    Arrays*         arrays;
6622
    /* Buffer used to reassemble a handshake message that is fragmented across
6623
     * multiple records. Kept in WOLFSSL (not Arrays) so that post-handshake
6624
     * messages (e.g. a TLS 1.3 NewSessionTicket) can still be defragmented
6625
     * after the handshake arrays have been released by FreeArrays(). */
6626
    byte*           pendingMsg;         /* defrag buffer */
6627
    word32          pendingMsgSz;       /* defrag buffer size */
6628
    word32          pendingMsgOffset;   /* current offset into defrag buffer */
6629
    byte            pendingMsgType;     /* defrag buffer message type */
6630
#ifdef WOLFSSL_TLS13
6631
    byte            clientSecret[SECRET_LEN];
6632
    byte            serverSecret[SECRET_LEN];
6633
#endif
6634
    HS_Hashes*      hsHashes;
6635
#if defined(WOLFSSL_TLS13) && defined(HAVE_ECH)
6636
    HS_Hashes*      hsHashesEch;
6637
#endif
6638
    void*           IOCB_ReadCtx;
6639
    void*           IOCB_WriteCtx;
6640
    WC_RNG*         rng;
6641
    void*           verifyCbCtx;        /* cert verify callback user ctx*/
6642
    VerifyCallback  verifyCallback;     /* cert verification callback */
6643
    void*           heap;               /* for user overrides */
6644
#ifdef HAVE_WRITE_DUP
6645
    WriteDup*       dupWrite;           /* valid pointer indicates ON */
6646
             /* side that decrements dupCount to zero frees overall structure */
6647
    byte            dupSide;            /* write side or read side */
6648
#endif
6649
#ifdef OPENSSL_EXTRA
6650
    byte              cbioFlag;         /* WOLFSSL_CBIO_RECV/SEND:
6651
                                         * CBIORecv/Send is set */
6652
#endif
6653
#ifdef WOLFSSL_WOLFSENTRY_HOOKS
6654
    NetworkFilterCallback_t AcceptFilter;
6655
    void *AcceptFilter_arg;
6656
    NetworkFilterCallback_t ConnectFilter;
6657
    void *ConnectFilter_arg;
6658
#endif /* WOLFSSL_WOLFSENTRY_HOOKS */
6659
    CallbackIORecv  CBIORecv;
6660
    CallbackIOSend  CBIOSend;
6661
#ifdef WOLFSSL_STATIC_MEMORY
6662
    WOLFSSL_HEAP_HINT heap_hint;
6663
#endif
6664
#if defined(WOLFSSL_DTLS) && !defined(NO_WOLFSSL_SERVER)
6665
    ClientHelloGoodCb chGoodCb;        /* notify user we parsed a verified
6666
                                        * ClientHello that passed basic tests */
6667
    void*             chGoodCtx;       /* user ClientHello cb context  */
6668
#endif
6669
#ifndef NO_HANDSHAKE_DONE_CB
6670
    HandShakeDoneCb hsDoneCb;          /* notify user handshake done */
6671
    void*           hsDoneCtx;         /* user handshake cb context  */
6672
#endif
6673
#ifdef WOLFSSL_ASYNC_IO
6674
#ifdef WOLFSSL_ASYNC_CRYPT
6675
    WC_ASYNC_DEV* asyncDev;
6676
#endif
6677
    /* Message building context should be stored here for functions that expect
6678
     * to encounter encryption blocking or fragment the message. */
6679
    struct WOLFSSL_ASYNC* async;
6680
#endif
6681
    void*           hsKey;              /* Handshake key (RsaKey or ecc_key)
6682
                                         * allocated from heap */
6683
    word32          hsType;             /* Type of Handshake key (hsKey) */
6684
    WOLFSSL_CIPHER  cipher;
6685
#ifdef WOLFSSL_DUAL_ALG_CERTS
6686
    void*           hsAltKey;           /* Handshake key (ML-DSA, falcon)
6687
                                         * allocated from heap */
6688
    word32          hsAltType;          /* Type of Handshake key (hsAltKey) */
6689
#endif
6690
#ifndef WOLFSSL_AEAD_ONLY
6691
    hmacfp          hmac;
6692
#endif
6693
    Ciphers         encrypt;
6694
    Ciphers         decrypt;
6695
    Buffers         buffers;
6696
    WOLFSSL_SESSION* session;
6697
#ifndef NO_CLIENT_CACHE
6698
    ClientSession*  clientSession;
6699
#endif
6700
    WOLFSSL_ALERT_HISTORY alert_history;
6701
    WOLFSSL_ALERT   pendingAlert;
6702
    int             error;
6703
    int             rfd;                /* read  file descriptor */
6704
    int             wfd;                /* write file descriptor */
6705
    int             rflags;             /* user read  flags */
6706
    int             wflags;             /* user write flags */
6707
    word32          timeout;            /* session timeout */
6708
    word32          fragOffset;         /* fragment offset */
6709
    word16          curSize;
6710
    word32          curStartIdx;
6711
    byte            verifyDepth;
6712
    RecordLayerHeader curRL;
6713
    MsgsReceived    msgsReceived;       /* peer messages received */
6714
    ProtocolVersion version;            /* negotiated version */
6715
    ProtocolVersion chVersion;          /* client hello version */
6716
    CipherSpecs     specs;
6717
    Keys            keys;
6718
    Options         options;
6719
#ifdef WOLFSSL_SESSION_ID_CTX
6720
    byte             sessionCtx[ID_LEN]; /* app session context ID */
6721
    byte             sessionCtxSz;       /* size of sessionCtx stored */
6722
#endif
6723
#ifdef OPENSSL_EXTRA
6724
    CallbackInfoState* CBIS;             /* used to get info about SSL state */
6725
    int              cbmode;             /* read or write on info callback */
6726
    int              cbtype;             /* event type in info callback */
6727
    WOLFSSL_BIO*     biord;              /* socket bio read  to free/close */
6728
    WOLFSSL_BIO*     biowr;              /* socket bio write to free/close */
6729
    WOLFSSL_X509_VERIFY_PARAM* param;    /* verification parameters*/
6730
#endif
6731
#if defined(OPENSSL_EXTRA) || defined(HAVE_CURL)
6732
    word32            disabledCurves;   /* curves disabled by user */
6733
#endif
6734
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL) || \
6735
    defined(OPENSSL_ALL)
6736
    unsigned long    peerVerifyRet;
6737
#endif
6738
#if defined(OPENSSL_EXTRA) || defined(WOLFSSL_TLS_READ_AHEAD)
6739
    byte             readAhead;
6740
    /* Read-ahead coalescing buffer size; 0 = one record (default). */
6741
    word32           readAheadSz;
6742
#endif
6743
#ifdef OPENSSL_EXTRA
6744
#ifdef HAVE_PK_CALLBACKS
6745
    void*            loggingCtx;         /* logging callback argument */
6746
#endif
6747
    WOLFSSL_TLSEXT_DEBUG_CB tlsextDebugCb; /* TLS ext debug callback */
6748
    void*            tlsextDebugArg;     /* TLS ext debug callback argument */
6749
#endif /* OPENSSL_EXTRA */
6750
#ifndef NO_RSA
6751
    RsaKey*         peerRsaKey;
6752
#if defined(WOLFSSL_RENESAS_TSIP_TLS) || defined(WOLFSSL_RENESAS_FSPSM_TLS)
6753
    void*           RenesasUserCtx;
6754
    byte*           peerSceTsipEncRsaKeyIndex;
6755
#endif
6756
    byte            peerRsaKeyPresent;
6757
#ifdef WC_RSA_PSS
6758
    word8           useRsaPss;           /* cert supports RSA-PSS */
6759
#endif
6760
#endif
6761
#if defined(WOLFSSL_TLS13) || defined(HAVE_FFDHE)
6762
    word16          namedGroup;
6763
#endif
6764
#ifdef WOLFSSL_TLS13
6765
    word16          group[WOLFSSL_MAX_GROUP_COUNT];
6766
    byte            numGroups;
6767
#endif
6768
    word16          pssAlgo;
6769
#ifdef WOLFSSL_TLS13
6770
    word16          certHashSigAlgoSz;  /* SigAlgoCert ext length in bytes */
6771
    byte            certHashSigAlgo[WOLFSSL_MAX_SIGALGO]; /* cert sig/algo to
6772
                                                           * offer */
6773
#endif
6774
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || defined(HAVE_ED448)
6775
    int             eccVerifyRes;
6776
#endif
6777
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || defined(HAVE_CURVE25519) || \
6778
    defined(HAVE_ED448) || defined(HAVE_CURVE448)
6779
    word32          ecdhCurveOID;            /* curve Ecc_Sum     */
6780
    ecc_key*        eccTempKey;              /* private ECDHE key */
6781
    byte            eccTempKeyPresent;       /* also holds type */
6782
    byte            peerEccKeyPresent;
6783
#endif
6784
#ifdef HAVE_ECC
6785
    ecc_key*        peerEccKey;              /* peer's  ECDHE key */
6786
    ecc_key*        peerEccDsaKey;           /* peer's  ECDSA key */
6787
    word16          eccTempKeySz;            /* in octets 20 - 66 */
6788
    byte            peerEccDsaKeyPresent;
6789
#endif
6790
#if defined(HAVE_ECC) || defined(HAVE_ED25519) || \
6791
    defined(HAVE_CURVE448) || defined(HAVE_ED448) || \
6792
    defined(HAVE_FALCON) || defined(WOLFSSL_HAVE_MLDSA) || \
6793
    defined(WOLFSSL_HAVE_SLHDSA)
6794
    word32          pkCurveOID;              /* curve Ecc_Sum     */
6795
#endif
6796
#ifdef HAVE_ED25519
6797
    ed25519_key*    peerEd25519Key;
6798
    byte            peerEd25519KeyPresent;
6799
#endif
6800
#ifdef HAVE_CURVE25519
6801
    curve25519_key* peerX25519Key;
6802
    byte            peerX25519KeyPresent;
6803
#endif
6804
#ifdef HAVE_ED448
6805
    ed448_key*      peerEd448Key;
6806
    byte            peerEd448KeyPresent;
6807
#endif
6808
#ifdef HAVE_CURVE448
6809
    curve448_key*   peerX448Key;
6810
    byte            peerX448KeyPresent;
6811
#endif
6812
#ifdef HAVE_FALCON
6813
    falcon_key*     peerFalconKey;
6814
    byte            peerFalconKeyPresent;
6815
#endif
6816
#ifdef WOLFSSL_HAVE_MLDSA
6817
    wc_MlDsaKey*    peerMlDsaKey;
6818
    byte            peerMlDsaKeyPresent;
6819
#endif
6820
#ifdef WOLFSSL_HAVE_SLHDSA
6821
    SlhDsaKey*      peerSlhDsaKey;
6822
    byte            peerSlhDsaKeyPresent;
6823
#endif
6824
#ifdef HAVE_LIBZ
6825
    z_stream        c_stream;           /* compression   stream */
6826
    z_stream        d_stream;           /* decompression stream */
6827
    byte            didStreamInit;      /* for stream init and end */
6828
#endif
6829
#ifdef WOLFSSL_DTLS
6830
    int             dtls_timeout_init;  /* starting timeout value */
6831
    int             dtls_timeout_max;   /* maximum timeout value */
6832
    int             dtls_timeout;       /* current timeout value, changes */
6833
#ifndef NO_ASN_TIME
6834
    word32          dtls_start_timeout;
6835
#endif /* !NO_ASN_TIME */
6836
    word32          dtls_tx_msg_list_sz;
6837
    word32          dtls_rx_msg_list_sz;
6838
    DtlsMsg*        dtls_tx_msg_list;
6839
    DtlsMsg*        dtls_tx_msg;
6840
    DtlsMsg*        dtls_rx_msg_list;
6841
    void*           IOCB_CookieCtx;     /* gen cookie ctx */
6842
#ifdef WOLFSSL_SESSION_EXPORT
6843
    wc_dtls_export  dtls_export;        /* export function for session */
6844
#endif
6845
#if defined(WOLFSSL_SCTP) || defined(WOLFSSL_DTLS_MTU)
6846
    word16          dtlsMtuSz;
6847
#endif /* WOLFSSL_SCTP || WOLFSSL_DTLS_MTU */
6848
#ifdef WOLFSSL_MULTICAST
6849
    void*           mcastHwCbCtx;       /* Multicast highwater callback ctx */
6850
#endif /* WOLFSSL_MULTICAST */
6851
#ifdef WOLFSSL_DTLS_DROP_STATS
6852
    word32 macDropCount;
6853
    word32 replayDropCount;
6854
#endif /* WOLFSSL_DTLS_DROP_STATS */
6855
#ifdef WOLFSSL_SRTP
6856
    word16         dtlsSrtpProfiles;   /* DTLS-with-SRTP profiles list
6857
                                        * (selected profiles - up to 16) */
6858
    word16         dtlsSrtpId;         /* DTLS-with-SRTP profile ID selected */
6859
#endif
6860
#ifdef WOLFSSL_DTLS13
6861
    RecordNumberCiphers dtlsRecordNumberEncrypt;
6862
    RecordNumberCiphers dtlsRecordNumberDecrypt;
6863
    Dtls13Epoch dtls13Epochs[DTLS13_EPOCH_SIZE];
6864
    Dtls13Epoch *dtls13EncryptEpoch;
6865
    Dtls13Epoch *dtls13DecryptEpoch;
6866
    w64wrapper dtls13Epoch;
6867
    w64wrapper dtls13PeerEpoch;
6868
    w64wrapper dtls13InvalidateBefore;
6869
    byte dtls13CurRL[DTLS_RECVD_RL_HEADER_MAX_SZ];
6870
    word16 dtls13CurRlLength;
6871
6872
    /* used to store the message if it needs to be fragmented */
6873
    buffer dtls13FragmentsBuffer;
6874
    byte dtls13SendingFragments:1;
6875
    byte dtls13SendingAckOrRtx;
6876
    byte dtls13FastTimeout:1;
6877
#ifdef HAVE_WRITE_DUP
6878
    byte dtls13KeyUpdateAcked:1;
6879
#endif
6880
    byte dtls13WaitKeyUpdateAck;
6881
    byte dtls13DoKeyUpdate;
6882
    word32 dtls13MessageLength;
6883
    word32 dtls13FragOffset;
6884
    byte dtls13FragHandshakeType;
6885
    Dtls13Rtx dtls13Rtx;
6886
    byte *dtls13ClientHello;
6887
    word16 dtls13ClientHelloSz;
6888
6889
#endif /* WOLFSSL_DTLS13 */
6890
#ifdef WOLFSSL_DTLS_CID
6891
    CIDInfo *dtlsCidInfo;
6892
#endif /* WOLFSSL_DTLS_CID */
6893
6894
#endif /* WOLFSSL_DTLS */
6895
#ifdef WOLFSSL_CALLBACKS
6896
    TimeoutInfo     timeoutInfo;        /* info saved during handshake */
6897
    HandShakeInfo   handShakeInfo;      /* info saved during handshake */
6898
#endif
6899
#ifdef OPENSSL_EXTRA
6900
    SSL_Msg_Cb      protoMsgCb;         /* inspect protocol message callback */
6901
    void*           protoMsgCtx;        /* user set context with msg callback */
6902
#endif
6903
#if defined(WOLFSSL_CALLBACKS) || defined(OPENSSL_EXTRA)
6904
    byte            hsInfoOn;           /* track handshake info        */
6905
    byte            toInfoOn;           /* track timeout   info        */
6906
#endif
6907
#ifdef HAVE_FUZZER
6908
    CallbackFuzzer  fuzzerCb;           /* for testing with using fuzzer */
6909
    void*           fuzzerCtx;          /* user defined pointer */
6910
#endif
6911
#if defined(WOLFSSL_TLS13) && defined(WOLFSSL_POST_HANDSHAKE_AUTH)
6912
    CertReqCtx*     certReqCtx;
6913
#endif
6914
#ifdef WOLFSSL_LOCAL_X509_STORE
6915
    WOLFSSL_X509_STORE* x509_store_pt; /* take ownership of external store */
6916
#endif
6917
#ifdef KEEP_PEER_CERT
6918
    /* TODO put this on the heap so we can properly use the
6919
     * reference counter and not have to duplicate it. */
6920
    WOLFSSL_X509     peerCert;           /* X509 peer cert */
6921
#endif
6922
#ifdef KEEP_OUR_CERT
6923
    WOLFSSL_X509*    ourCert;            /* keep alive a X509 struct of cert.
6924
                                            points to ctx if not owned (owned
6925
                                            flag found in buffers.weOwnCert) */
6926
#endif
6927
    byte             keepCert;           /* keep certificate after handshake */
6928
#ifdef HAVE_EX_DATA
6929
    WOLFSSL_CRYPTO_EX_DATA ex_data; /* external data, for Fortress */
6930
#endif
6931
    int              devId;             /* async device id to use */
6932
#ifdef HAVE_ONE_TIME_AUTH
6933
    OneTimeAuth     auth;
6934
#endif
6935
#ifdef HAVE_TLS_EXTENSIONS
6936
    TLSX* extensions;                  /* RFC 6066 TLS Extensions data */
6937
    #ifdef OPENSSL_EXTRA
6938
        /* Pre-built wire bytes for app-defined custom extensions in the
6939
         * ClientHello. Produced in TLSX_GetRequestSize and consumed (then
6940
         * freed) in TLSX_WriteRequest. See WOLFSSL_CustomExt. */
6941
        byte*   customExtData;
6942
        word16  customExtSz;
6943
        /* Custom extension types actually emitted in the ClientHello, so an
6944
         * unsolicited type echoed by the server can be rejected. Rebuilt with
6945
         * customExtData; persists until the connection is freed. */
6946
        word16* customExtSent;
6947
        word16  customExtSentCnt;
6948
    #endif
6949
    #ifdef HAVE_MAX_FRAGMENT
6950
        word16 max_fragment;
6951
    #endif
6952
    #ifdef HAVE_TRUNCATED_HMAC
6953
        byte truncated_hmac;
6954
    #endif
6955
    #ifdef HAVE_CERTIFICATE_STATUS_REQUEST
6956
        byte status_request;
6957
    #endif
6958
    #ifdef HAVE_CERTIFICATE_STATUS_REQUEST_V2
6959
        byte status_request_v2;
6960
    #endif
6961
    #if defined(HAVE_SECURE_RENEGOTIATION) \
6962
        || defined(HAVE_SERVER_RENEGOTIATION_INFO)
6963
        int                  secure_rene_count;    /* how many times */
6964
        SecureRenegotiation* secure_renegotiation; /* valid pointer indicates */
6965
    #endif                                         /* user turned on */
6966
    #ifdef HAVE_ALPN
6967
        byte *alpn_peer_requested; /* the ALPN bytes requested by peer, sequence
6968
                                    * of length byte + chars */
6969
        word16 alpn_peer_requested_length; /* number of bytes total */
6970
        #if defined(OPENSSL_ALL) || defined(WOLFSSL_NGINX)  || \
6971
            defined(WOLFSSL_HAPROXY) || defined(WOLFSSL_QUIC)
6972
            CallbackALPNSelect alpnSelect;
6973
            void*              alpnSelectArg;
6974
        #endif
6975
    #endif                         /* of accepted protocols */
6976
    #if !defined(NO_WOLFSSL_CLIENT) && defined(HAVE_SESSION_TICKET)
6977
        CallbackSessionTicket session_ticket_cb;
6978
        void*                 session_ticket_ctx;
6979
        byte                  expect_session_ticket;
6980
    #endif
6981
        word16 hrr_keyshare_group;
6982
#endif /* HAVE_TLS_EXTENSIONS */
6983
#ifdef HAVE_OCSP
6984
        void*       ocspIOCtx;
6985
        byte ocspProducedDate[MAX_DATE_SIZE];
6986
        int ocspProducedDateFormat;
6987
        buffer      ocspCsrResp[1 + MAX_CHAIN_DEPTH];
6988
    #if defined(OPENSSL_ALL) || defined(WOLFSSL_NGINX) || defined(WOLFSSL_HAPROXY)
6989
        char*   url;
6990
    #endif
6991
#if defined(WOLFSSL_TLS13) && defined(HAVE_CERTIFICATE_STATUS_REQUEST)
6992
            word32 response_idx;
6993
#endif
6994
#endif
6995
#ifdef HAVE_NETX
6996
    NetX_Ctx        nxCtx;             /* NetX IO Context */
6997
#endif
6998
#if defined(WOLFSSL_APACHE_MYNEWT) && !defined(WOLFSSL_LWIP)
6999
    void*           mnCtx;             /* mynewt mn_socket IO Context */
7000
#endif /* defined(WOLFSSL_APACHE_MYNEWT) && !defined(WOLFSSL_LWIP) */
7001
#ifdef WOLFSSL_GNRC
7002
    struct gnrc_wolfssl_ctx *gnrcCtx;  /* Riot-OS GNRC UDP/IP context */
7003
#endif
7004
#ifdef SESSION_INDEX
7005
    int sessionIndex;                  /* Session's location in the cache. */
7006
#endif
7007
#ifdef ATOMIC_USER
7008
    void*    MacEncryptCtx;    /* Atomic User Mac/Encrypt Callback Context */
7009
    void*    DecryptVerifyCtx; /* Atomic User Decrypt/Verify Callback Context */
7010
    #ifdef HAVE_ENCRYPT_THEN_MAC
7011
        void*    EncryptMacCtx;    /* Atomic User Encrypt/Mac Callback Ctx */
7012
        void*    VerifyDecryptCtx; /* Atomic User Verify/Decrypt Callback Ctx */
7013
    #endif
7014
#endif
7015
#ifdef HAVE_PK_CALLBACKS
7016
    #ifdef HAVE_ECC
7017
        void* EccKeyGenCtx;          /* EccKeyGen  Callback Context */
7018
        void* EccSignCtx;            /* Ecc Sign   Callback Context */
7019
        void* EccVerifyCtx;          /* Ecc Verify Callback Context */
7020
        void* EccSharedSecretCtx;    /* Ecc Pms    Callback Context */
7021
    #endif /* HAVE_ECC */
7022
    #ifdef HAVE_HKDF
7023
        void* HkdfExtractCtx;       /* Hkdf extract callback context */
7024
    #endif
7025
    #ifdef HAVE_ED25519
7026
        void* Ed25519SignCtx;        /* ED25519 Sign   Callback Context */
7027
        void* Ed25519VerifyCtx;      /* ED25519 Verify Callback Context */
7028
    #endif
7029
    #ifdef HAVE_CURVE25519
7030
        void* X25519KeyGenCtx;       /* X25519 KeyGen Callback Context */
7031
        void* X25519SharedSecretCtx; /* X25519 Pms    Callback Context */
7032
    #endif
7033
    #ifdef HAVE_ED448
7034
        void* Ed448SignCtx;          /* ED448 Sign   Callback Context */
7035
        void* Ed448VerifyCtx;        /* ED448 Verify Callback Context */
7036
    #endif
7037
    #ifdef HAVE_CURVE448
7038
        void* X448KeyGenCtx;         /* X448 KeyGen Callback Context */
7039
        void* X448SharedSecretCtx;   /* X448 Pms    Callback Context */
7040
    #endif
7041
    #ifndef NO_DH
7042
        void* DhAgreeCtx; /* DH Pms Callback Context */
7043
    #endif /* !NO_DH */
7044
    #ifndef NO_RSA
7045
        void* RsaSignCtx;     /* Rsa Sign   Callback Context */
7046
        void* RsaVerifyCtx;   /* Rsa Verify Callback Context */
7047
        #ifdef WC_RSA_PSS
7048
            void* RsaPssSignCtx;     /* Rsa PSS Sign   Callback Context */
7049
            void* RsaPssVerifyCtx;   /* Rsa PSS Verify Callback Context */
7050
        #endif
7051
        void* RsaEncCtx;      /* Rsa Public  Encrypt   Callback Context */
7052
        void* RsaDecCtx;      /* Rsa Private Decrypt   Callback Context */
7053
    #endif /* NO_RSA */
7054
    void* GenPreMasterCtx;   /* Generate Premaster Callback Context */
7055
    void* GenMasterCtx;      /* Generate Master Callback Context */
7056
    void* GenExtMasterCtx;   /* Generate Extended Master Callback Context */
7057
    void* GenSessionKeyCtx;  /* Generate Session Key Callback Context */
7058
    void* EncryptKeysCtx;    /* Set Encrypt keys Callback Context */
7059
    void* TlsFinishedCtx;    /* Generate Tls Finished Callback Context */
7060
    void* VerifyMacCtx;      /* Verify mac Callback Context */
7061
#endif /* HAVE_PK_CALLBACKS */
7062
#ifdef HAVE_SECRET_CALLBACK
7063
        SessionSecretCb sessionSecretCb;
7064
        void*           sessionSecretCtx;
7065
        TicketParseCb   ticketParseCb;
7066
        void*           ticketParseCtx;
7067
        TlsSecretCb     tlsSecretCb;
7068
        void*           tlsSecretCtx;
7069
    #ifdef WOLFSSL_TLS13
7070
        Tls13SecretCb   tls13SecretCb;
7071
        void*           tls13SecretCtx;
7072
    #endif
7073
    #ifdef OPENSSL_EXTRA
7074
        SessionSecretCb keyLogCb;
7075
    #ifdef WOLFSSL_TLS13
7076
        Tls13SecretCb   tls13KeyLogCb;
7077
    #endif
7078
    #endif
7079
#endif /* HAVE_SECRET_CALLBACK */
7080
#ifdef WOLFSSL_JNI
7081
        void* jObjectRef;     /* reference to WolfSSLSession in JNI wrapper */
7082
#endif /* WOLFSSL_JNI */
7083
#ifdef WOLFSSL_EARLY_DATA
7084
    EarlyDataState earlyData;
7085
    word32 earlyDataSz;
7086
    byte earlyDataStatus;
7087
#endif
7088
#if defined(OPENSSL_EXTRA)
7089
    WOLFSSL_STACK* supportedCiphers; /* Used in wolfSSL_get_ciphers_compat */
7090
    WOLFSSL_STACK* peerCertChain;    /* Used in wolfSSL_get_peer_cert_chain */
7091
    WOLFSSL_STACK* verifiedChain;    /* peer cert chain to CA */
7092
#ifdef KEEP_OUR_CERT
7093
    WOLFSSL_STACK* ourCertChain;    /* Used in wolfSSL_add1_chain_cert */
7094
#endif
7095
#endif
7096
#ifdef WOLFSSL_STATIC_EPHEMERAL
7097
    StaticKeyExchangeInfo_t staticKE;
7098
#endif
7099
#ifdef WOLFSSL_MAXQ10XX_TLS
7100
    maxq_ssl_t maxq_ctx;
7101
#endif
7102
#ifdef WOLFSSL_HAVE_TLS_UNIQUE
7103
    /* Added in libest port: allow applications to get the 'tls-unique' Channel
7104
     * Binding Type (https://tools.ietf.org/html/rfc5929#section-3). This is
7105
     * used in the EST protocol to bind an enrollment to a TLS session through
7106
     * 'proof-of-possession' (https://tools.ietf.org/html/rfc7030#section-3.4
7107
     * and https://tools.ietf.org/html/rfc7030#section-3.5). */
7108
    byte clientFinished[TLS_FINISHED_SZ_MAX];
7109
    byte serverFinished[TLS_FINISHED_SZ_MAX];
7110
    byte clientFinished_len;
7111
    byte serverFinished_len;
7112
#endif
7113
#ifndef WOLFSSL_NO_CA_NAMES
7114
    WOLF_STACK_OF(WOLFSSL_X509_NAME)* client_ca_names; /* Used in *_set/get_client_CA_list
7115
                                                          (server only) */
7116
    WOLF_STACK_OF(WOLFSSL_X509_NAME)* ca_names;        /* Used in *_set0/get0_CA_list */
7117
    WOLF_STACK_OF(WOLFSSL_X509_NAME)* peer_ca_names;   /* Used in *_get0_peer_CA_list
7118
                                                          and (client only)
7119
                                                          wolfSSL_get_client_CA_list */
7120
#endif
7121
#if defined(WOLFSSL_IOTSAFE) && defined(HAVE_PK_CALLBACKS)
7122
    IOTSAFE iotsafe;
7123
#endif
7124
#ifdef WOLFSSL_LWIP_NATIVE
7125
    WOLFSSL_LWIP_NATIVE_STATE      lwipCtx; /* LwIP native socket IO Context */
7126
#endif
7127
#ifdef WOLFSSL_QUIC
7128
    struct {
7129
        const WOLFSSL_QUIC_METHOD* method;
7130
        WOLFSSL_ENCRYPTION_LEVEL enc_level_read;
7131
        WOLFSSL_ENCRYPTION_LEVEL enc_level_read_next;
7132
        WOLFSSL_ENCRYPTION_LEVEL enc_level_latest_recvd;
7133
        WOLFSSL_ENCRYPTION_LEVEL enc_level_write;
7134
        WOLFSSL_ENCRYPTION_LEVEL enc_level_write_next;
7135
        int transport_version;
7136
        const QuicTransportParam* transport_local;
7137
        const QuicTransportParam* transport_peer;
7138
        const QuicTransportParam* transport_peer_draft;
7139
        QuicRecord* input_head;          /* we own, data for handshake */
7140
        QuicRecord* input_tail;          /* points to last element for append */
7141
        QuicRecord* scratch;             /* we own, record construction */
7142
        enum wolfssl_encryption_level_t output_rec_level;
7143
                                         /* encryption level of current output record */
7144
        word32 output_rec_remain;        /* how many bytes of output TLS record
7145
                                          * content have not been handled yet by quic */
7146
    } quic;
7147
#endif /* WOLFSSL_QUIC */
7148
#if defined(WOLFSSL_TLS13) && defined(HAVE_ECH)
7149
    WOLFSSL_EchConfig* echConfigs;
7150
    WOLFSSL_EchConfig* echRetryConfigs;
7151
#endif
7152
#if defined(WOLFSSL_TLS13) && defined(HAVE_ECH) && defined(WOLFSSL_TEST_ECH)
7153
    /* Test-only hook: called on the client before ECH encryption, after the
7154
     * inner ClientHello body is fully constructed. The callback may modify
7155
     * innerCh in-place (length stays the same). */
7156
    int (*echInnerHelloCb)(byte* innerCh, word32 innerChLen);
7157
#endif
7158
7159
#if defined(WOLFSSL_SNIFFER) && defined(WOLFSSL_SNIFFER_KEYLOGFILE)
7160
    SSLSnifferSecretCb snifferSecretCb;
7161
#endif /* WOLFSSL_SNIFFER && WOLFSSL_SNIFFER_KEYLOGFILE */
7162
#ifdef WOLFSSL_DUAL_ALG_CERTS
7163
    byte *sigSpec;         /* This pointer never owns the memory. */
7164
    word16 sigSpecSz;
7165
    byte *peerSigSpec;     /* This pointer always owns the memory. */
7166
    word16 peerSigSpecSz;
7167
#endif
7168
#if defined(WOLFSSL_SYS_CRYPTO_POLICY)
7169
    int secLevel; /* The security level of system-wide crypto policy. */
7170
#endif /* WOLFSSL_SYS_CRYPTO_POLICY */
7171
#if !defined(NO_WOLFSSL_CLIENT) && !defined(WOLFSSL_NO_TLS12) && \
7172
    defined(HAVE_SERVER_RENEGOTIATION_INFO) && \
7173
    !defined(WOLFSSL_HARDEN_TLS_NO_SCR_CHECK)
7174
    WC_BITFIELD          scr_check_enabled:1;  /* enable/disable SCR check */
7175
#endif
7176
#ifdef HAVE_WRITE_DUP
7177
#ifdef WOLFSSL_TLS13
7178
#ifdef WOLFSSL_POST_HANDSHAKE_AUTH
7179
    WC_BITFIELD postHandshakeAuthPending:1;
7180
#endif
7181
#endif
7182
#endif
7183
    /* Cached BuildMessage(sizeOnly) overhead (recordSz - payloadSz) for AEAD
7184
     * ciphers; 0 means uncached and is never a valid AEAD overhead. EtM does
7185
     * not apply to AEAD. */
7186
    word32 recordSzOverhead;
7187
#ifdef WOLFSSL_ASYNC_CRYPT
7188
    /* Async device for the TLS 1.3 key schedule: HKDF has no key object
7189
     * to carry one. Event bookkeeping only, for the callback re-invoke
7190
     * path (never wolfAsync_DevCtxInit'd, no hardware context). */
7191
    WC_ASYNC_DEV kdfAsyncDev;
7192
#endif
7193
    /* Key-schedule resume steps: completed derives must not re-run (e.g.
7194
     * the extract is in place over preMasterSecret). Unconditional so the
7195
     * schedule needs no ifdefs; without async they stay 0. */
7196
    byte kdfDeriveStep;  /* enum Tls13KdfSendStep (send side) */
7197
    byte kdfMsgStep;     /* enum Tls13KdfMsgStep (receive side) */
7198
    byte kdfMsgType;     /* handshake type kdfMsgStep belongs to */
7199
#if defined(WOLFSSL_ASYNC_REINVOKE) && defined(WOLFSSL_TLS13) && \
7200
    !defined(NO_HMAC)
7201
    /* Transcript HMAC (Finished verify_data, PSK binders) held across a
7202
     * WC_PENDING_E so the retry re-invokes the same object and arguments,
7203
     * bound to its output buffer. */
7204
    Hmac* hsHmac;
7205
    byte* hsHmacOut;
7206
    byte  hsHmacStep;
7207
#endif
7208
};
7209
7210
#if defined(WOLFSSL_SYS_CRYPTO_POLICY)
7211
#define WOLFSSL_SECLEVEL_STR "@SECLEVEL="
7212
struct SystemCryptoPolicy {
7213
    int    enabled;
7214
    int    secLevel;
7215
    char   str[MAX_WOLFSSL_CRYPTO_POLICY_SIZE + 1]; /* + 1 for null term */
7216
};
7217
#endif /* WOLFSSL_SYS_CRYPTO_POLICY */
7218
7219
/*
7220
 * wolfSSL_PEM_read_bio_X509 pushes an ASN_NO_PEM_HEADER error
7221
 * to the error queue on file end. This should not be left
7222
 * for the caller to find so we clear the last error.
7223
 */
7224
#if defined(OPENSSL_EXTRA) && defined(WOLFSSL_HAVE_ERROR_QUEUE)
7225
#define CLEAR_ASN_NO_PEM_HEADER_ERROR(err)                                     \
7226
do {                                                                           \
7227
    (err) = wolfSSL_ERR_peek_last_error();                                     \
7228
    if (wolfSSL_ERR_GET_LIB(err) == WOLFSSL_ERR_LIB_PEM &&                     \
7229
        wolfSSL_ERR_GET_REASON(err) ==                                         \
7230
            -WC_NO_ERR_TRACE(WOLFSSL_PEM_R_NO_START_LINE_E)) {                 \
7231
        unsigned long peekErr;                                                 \
7232
        do {                                                                   \
7233
            wc_RemoveErrorNode(-1);                                            \
7234
            peekErr = wolfSSL_ERR_peek_last_error();                           \
7235
        } while (wolfSSL_ERR_GET_LIB(peekErr) == WOLFSSL_ERR_LIB_PEM &&        \
7236
                 wolfSSL_ERR_GET_REASON(peekErr) ==                            \
7237
                 -WC_NO_ERR_TRACE(WOLFSSL_PEM_R_NO_START_LINE_E));             \
7238
    }                                                                          \
7239
} while(0)
7240
#else
7241
0
#define CLEAR_ASN_NO_PEM_HEADER_ERROR(err) (void)(err);
7242
#endif
7243
7244
/*
7245
 * The SSL object may have its own certificate store. The below macros simplify
7246
 * logic for choosing which WOLFSSL_CERT_MANAGER and WOLFSSL_X509_STORE to use.
7247
 * Always use SSL specific objects when available and revert to CTX otherwise.
7248
 */
7249
#ifdef WOLFSSL_LOCAL_X509_STORE
7250
#define SSL_CM(ssl) ((ssl)->x509_store_pt ? (ssl)->x509_store_pt->cm : \
7251
                     ((ssl)->ctx->x509_store_pt ? (ssl)->ctx->x509_store_pt->cm : \
7252
                                            (ssl)->ctx->cm))
7253
#define SSL_STORE(ssl) ((ssl)->x509_store_pt ? (ssl)->x509_store_pt : \
7254
                  ((ssl)->ctx->x509_store_pt ? (ssl)->ctx->x509_store_pt : \
7255
                                            &(ssl)->ctx->x509_store))
7256
#define CTX_STORE(ctx) ((ctx)->x509_store_pt ? (ctx)->x509_store_pt : \
7257
                                            &(ctx)->x509_store)
7258
#else
7259
0
#define SSL_CM(ssl) (ssl)->ctx->cm
7260
#endif
7261
/* Issue warning when we are modifying the overall context CM */
7262
#define SSL_CM_WARNING(ssl) \
7263
    do {                                                             \
7264
        if (SSL_CM( (ssl) ) == (ssl)->ctx->cm) {                     \
7265
            WOLFSSL_MSG("Modifying SSL_CTX CM not SSL specific CM"); \
7266
        }                                                            \
7267
    } while (0)
7268
7269
WOLFSSL_LOCAL int  SetSSL_CTX(WOLFSSL* ssl, WOLFSSL_CTX* ctx, int writeDup);
7270
WOLFSSL_LOCAL int  InitSSL(WOLFSSL* ssl, WOLFSSL_CTX* ctx, int writeDup);
7271
WOLFSSL_LOCAL int  ReinitSSL(WOLFSSL* ssl, WOLFSSL_CTX* ctx, int writeDup);
7272
WOLFSSL_LOCAL void FreeSSL(WOLFSSL* ssl, void* heap);
7273
WOLFSSL_TEST_VIS   void wolfSSL_ResourceFree(WOLFSSL* ssl);   /* Micrium uses */
7274
#ifndef OPENSSL_COEXIST
7275
#define SSL_ResourceFree wolfSSL_ResourceFree
7276
#endif
7277
7278
7279
#ifndef NO_CERTS
7280
7281
    WOLFSSL_LOCAL int ProcessBuffer(WOLFSSL_CTX* ctx, const unsigned char* buff,
7282
                                    long sz, int format, int type, WOLFSSL* ssl,
7283
                                    long* used, int userChain, int verify,
7284
                                    const char *source_name);
7285
    WOLFSSL_LOCAL int ProcessFile(WOLFSSL_CTX* ctx, const char* fname, int format,
7286
                                 int type, WOLFSSL* ssl, int userChain,
7287
                                WOLFSSL_CRL* crl, int verify);
7288
7289
    #ifndef NO_ASN
7290
    WOLFSSL_LOCAL int CheckHostName(DecodedCert* dCert, const char *domainName,
7291
                                    size_t domainNameLen, unsigned int flags,
7292
                                    byte isIP);
7293
    #endif
7294
#endif
7295
7296
7297
#if defined(WOLFSSL_CALLBACKS) || defined(OPENSSL_EXTRA)
7298
    WOLFSSL_LOCAL void InitHandShakeInfo(HandShakeInfo* info, WOLFSSL* ssl);
7299
    WOLFSSL_LOCAL void FinishHandShakeInfo(HandShakeInfo* info);
7300
    WOLFSSL_LOCAL void AddPacketName(WOLFSSL* ssl, const char* name);
7301
7302
    WOLFSSL_LOCAL void InitTimeoutInfo(TimeoutInfo* info);
7303
    WOLFSSL_LOCAL void FreeTimeoutInfo(TimeoutInfo* info, void* heap);
7304
    WOLFSSL_LOCAL int AddPacketInfo(WOLFSSL* ssl, const char* name, int type,
7305
                             const byte* data, int sz, int written, int lateRL,
7306
                             void* heap);
7307
    WOLFSSL_LOCAL void AddLateName(const char* name, TimeoutInfo* info);
7308
    WOLFSSL_LOCAL void AddLateRecordHeader(const RecordLayerHeader* rl,
7309
                                           TimeoutInfo* info);
7310
#endif
7311
7312
7313
/* Record Layer Header identifier from page 12 */
7314
enum ContentType {
7315
    no_type            = 0,
7316
    change_cipher_spec = 20,
7317
    alert              = 21,
7318
    handshake          = 22,
7319
    application_data   = 23,
7320
    dtls12_cid         = 25,
7321
#ifdef WOLFSSL_DTLS13
7322
    ack                = 26,
7323
#endif /* WOLFSSL_DTLS13 */
7324
    WOLF_ENUM_DUMMY_LAST_ELEMENT(ContentType)
7325
};
7326
7327
7328
/* handshake header, same for each message type, pgs 20/21 */
7329
typedef struct HandShakeHeader {
7330
    byte            type;
7331
    word24          length;
7332
} HandShakeHeader;
7333
7334
7335
/* DTLS handshake header, same for each message type */
7336
typedef struct DtlsHandShakeHeader {
7337
    byte            type;
7338
    word24          length;
7339
    byte            message_seq[2];    /* start at 0, retransmit gets same # */
7340
    word24          fragment_offset;   /* bytes in previous fragments */
7341
    word24          fragment_length;   /* length of this fragment */
7342
} DtlsHandShakeHeader;
7343
7344
7345
enum HandShakeType {
7346
    hello_request        =   0,
7347
    client_hello         =   1,
7348
    server_hello         =   2,
7349
    hello_verify_request =   3,    /* DTLS addition */
7350
    session_ticket       =   4,
7351
    end_of_early_data    =   5,
7352
    hello_retry_request  =   6,
7353
    encrypted_extensions =   8,
7354
    request_connection_id =  9,    /* DTLS v1.3 addition (RFC 9147) */
7355
    new_connection_id    =  10,    /* DTLS v1.3 addition (RFC 9147) */
7356
    certificate          =  11,
7357
    server_key_exchange  =  12,
7358
    certificate_request  =  13,
7359
    server_hello_done    =  14,
7360
    certificate_verify   =  15,
7361
    client_key_exchange  =  16,
7362
    finished             =  20,
7363
    certificate_status   =  22,
7364
    key_update           =  24,
7365
    change_cipher_hs     =  55,    /* simulate unique handshake type for sanity
7366
                                      checks.  record layer change_cipher
7367
                                      conflicts with handshake finished */
7368
    message_hash         = 254,    /* synthetic message type for TLS v1.3 */
7369
    no_shake             = 255     /* used to initialize the DtlsMsg record */
7370
};
7371
7372
enum ProvisionSide {
7373
    PROVISION_CLIENT = 1,
7374
    PROVISION_SERVER = 2,
7375
    PROVISION_CLIENT_SERVER = 3
7376
};
7377
7378
/* cipher requirements */
7379
enum {
7380
    REQUIRES_RSA,
7381
    REQUIRES_DHE,
7382
    REQUIRES_ECC,
7383
    REQUIRES_ECC_STATIC,
7384
    REQUIRES_PSK,
7385
    REQUIRES_RSA_SIG,
7386
    REQUIRES_AEAD
7387
};
7388
7389
static const byte kTlsClientStr[SIZEOF_SENDER+1] = { 0x43, 0x4C, 0x4E, 0x54, 0x00 }; /* CLNT */
7390
static const byte kTlsServerStr[SIZEOF_SENDER+1] = { 0x53, 0x52, 0x56, 0x52, 0x00 }; /* SRVR */
7391
7392
static const byte kTlsClientFinStr[FINISHED_LABEL_SZ + 1] = "client finished";
7393
static const byte kTlsServerFinStr[FINISHED_LABEL_SZ + 1] = "server finished";
7394
7395
#if defined(OPENSSL_EXTRA) || defined(WOLFSSL_WPAS_SMALL) || defined(HAVE_CURL)
7396
typedef struct {
7397
    int name_len;
7398
    const char *name;
7399
    int nid;
7400
    word16 curve;
7401
} WOLF_EC_NIST_NAME;
7402
extern const WOLF_EC_NIST_NAME kNistCurves[];
7403
WOLFSSL_LOCAL int set_curves_list(WOLFSSL* ssl, WOLFSSL_CTX *ctx,
7404
        const char* names, byte curves_only);
7405
#endif /* OPENSSL_EXTRA || WOLFSSL_WPAS_SMALL || HAVE_CURL */
7406
7407
/* internal functions */
7408
WOLFSSL_LOCAL int SendChangeCipher(WOLFSSL* ssl);
7409
WOLFSSL_LOCAL int SendTicket(WOLFSSL* ssl);
7410
#ifdef HAVE_SESSION_TICKET
7411
WOLFSSL_LOCAL int DoDecryptTicket(const WOLFSSL* ssl, const byte* input,
7412
        word32 len, InternalTicket **it);
7413
/* Return 0 when check successful. <0 on failure. */
7414
WOLFSSL_LOCAL void DoClientTicketFinalize(WOLFSSL* ssl, InternalTicket* it,
7415
                                          const WOLFSSL_SESSION* sess);
7416
7417
#ifdef WOLFSSL_TLS13
7418
WOLFSSL_LOCAL int DoClientTicketCheck(const WOLFSSL* ssl,
7419
        const PreSharedKey* psk, sword64 timeout, const byte* suite);
7420
WOLFSSL_LOCAL void CleanupClientTickets(PreSharedKey* psk);
7421
WOLFSSL_LOCAL int DoClientTicket_ex(const WOLFSSL* ssl, PreSharedKey* psk,
7422
                                    int retainSess);
7423
#endif
7424
7425
WOLFSSL_LOCAL int DoClientTicket(WOLFSSL* ssl, const byte* input, word32 len);
7426
/* TicketSniHash, TicketAlpnHash, and VerifyTicketBinding are defined in
7427
 * internal.c only when !NO_WOLFSSL_SERVER && !NO_TLS - gate the
7428
 * declarations to match so client-only or no-TLS builds don't compile in
7429
 * call sites that would fail to link. */
7430
#if !defined(NO_WOLFSSL_SERVER) && !defined(NO_TLS)
7431
#ifdef HAVE_SNI
7432
WOLFSSL_LOCAL int TicketSniHash(WOLFSSL* ssl, byte* dst);
7433
#endif
7434
#ifdef HAVE_ALPN
7435
WOLFSSL_LOCAL int TicketAlpnHash(WOLFSSL* ssl, byte* dst);
7436
#endif
7437
#if defined(HAVE_SNI) || defined(HAVE_ALPN)
7438
WOLFSSL_LOCAL int VerifyTicketBinding(WOLFSSL* ssl);
7439
#endif
7440
#endif /* !NO_WOLFSSL_SERVER && !NO_TLS */
7441
#endif /* HAVE_SESSION_TICKET */
7442
WOLFSSL_LOCAL int SendData(WOLFSSL* ssl, const void* data, size_t sz);
7443
#ifdef WOLFSSL_THREADED_CRYPT
7444
WOLFSSL_LOCAL int SendAsyncData(WOLFSSL* ssl);
7445
#endif
7446
#ifdef WOLFSSL_TLS13
7447
WOLFSSL_LOCAL int SendTls13ServerHello(WOLFSSL* ssl, byte extMsgType);
7448
#endif
7449
WOLFSSL_LOCAL int SendCertificate(WOLFSSL* ssl);
7450
WOLFSSL_LOCAL int SendCertificateRequest(WOLFSSL* ssl);
7451
#if defined(HAVE_CERTIFICATE_STATUS_REQUEST) \
7452
 || defined(HAVE_CERTIFICATE_STATUS_REQUEST_V2)
7453
WOLFSSL_LOCAL int CreateOcspResponse(WOLFSSL* ssl, OcspRequest** ocspRequest,
7454
                       buffer* response, byte* ctxOwnsRequest);
7455
#endif
7456
#if defined(HAVE_SECURE_RENEGOTIATION) && \
7457
    !defined(NO_WOLFSSL_SERVER)
7458
WOLFSSL_LOCAL int SendHelloRequest(WOLFSSL* ssl);
7459
#endif
7460
WOLFSSL_LOCAL int SendCertificateStatus(WOLFSSL* ssl);
7461
WOLFSSL_LOCAL int SendServerKeyExchange(WOLFSSL* ssl);
7462
WOLFSSL_LOCAL int SendBuffered(WOLFSSL* ssl);
7463
WOLFSSL_LOCAL int ReceiveData(WOLFSSL* ssl, byte* output, size_t sz, int peek);
7464
WOLFSSL_LOCAL int SendFinished(WOLFSSL* ssl);
7465
WOLFSSL_LOCAL int RetrySendAlert(WOLFSSL* ssl);
7466
WOLFSSL_LOCAL int SendAlert(WOLFSSL* ssl, int severity, int type);
7467
WOLFSSL_LOCAL int SendFatalAlertOnly(WOLFSSL *ssl, int error);
7468
WOLFSSL_LOCAL int ProcessReply(WOLFSSL* ssl);
7469
WOLFSSL_LOCAL int ProcessReplyEx(WOLFSSL* ssl, int allowSocketErr);
7470
7471
WOLFSSL_LOCAL const char* AlertTypeToString(int type);
7472
7473
WOLFSSL_LOCAL int SetCipherSpecs(WOLFSSL* ssl);
7474
WOLFSSL_LOCAL int GetCipherSpec(word16 side, byte cipherSuite0,
7475
        byte cipherSuite, CipherSpecs* specs, Options* opts);
7476
WOLFSSL_LOCAL int MakeMasterSecret(WOLFSSL* ssl);
7477
7478
WOLFSSL_LOCAL int DeriveKeys(WOLFSSL* ssl);
7479
WOLFSSL_LOCAL int StoreKeys(WOLFSSL* ssl, const byte* keyData, int side);
7480
7481
WOLFSSL_LOCAL int IsTLS(const WOLFSSL* ssl);
7482
WOLFSSL_LOCAL int IsTLS_ex(const ProtocolVersion pv);
7483
WOLFSSL_LOCAL int IsAtLeastTLSv1_2(const WOLFSSL* ssl);
7484
WOLFSSL_LOCAL int IsAtLeastTLSv1_3(const ProtocolVersion pv);
7485
WOLFSSL_LOCAL int IsEncryptionOn(const WOLFSSL* ssl, int isSend);
7486
WOLFSSL_LOCAL int TLSv1_3_Capable(WOLFSSL* ssl);
7487
7488
WOLFSSL_LOCAL void FreeHandshakeResources(WOLFSSL* ssl);
7489
WOLFSSL_LOCAL void ShrinkInputBuffer(WOLFSSL* ssl, int forcedFree);
7490
WOLFSSL_LOCAL void ShrinkOutputBuffer(WOLFSSL* ssl);
7491
WOLFSSL_LOCAL byte* GetOutputBuffer(WOLFSSL* ssl);
7492
7493
WOLFSSL_LOCAL int CipherRequires(byte first, byte second, int requirement);
7494
WOLFSSL_LOCAL int VerifyClientSuite(word16 havePSK, byte cipherSuite0,
7495
                                    byte cipherSuite);
7496
7497
WOLFSSL_LOCAL int SetTicket(WOLFSSL* ssl, const byte* ticket, word32 length);
7498
WOLFSSL_TEST_VIS int wolfssl_local_GetRecordSize(WOLFSSL *ssl, int payloadSz,
7499
        int isEncrypted);
7500
WOLFSSL_LOCAL int wolfssl_local_GetMaxPlaintextSize(WOLFSSL *ssl);
7501
WOLFSSL_LOCAL int wolfSSL_GetMaxFragSize(WOLFSSL* ssl);
7502
7503
#if defined(WOLFSSL_IOTSAFE) && defined(HAVE_PK_CALLBACKS)
7504
WOLFSSL_LOCAL IOTSAFE *wolfSSL_get_iotsafe_ctx(WOLFSSL *ssl);
7505
WOLFSSL_LOCAL int wolfSSL_set_iotsafe_ctx(WOLFSSL *ssl, IOTSAFE *iotsafe);
7506
#endif
7507
7508
#if (defined(OPENSSL_EXTRA) || defined(WOLFSSL_WPAS_SMALL)) && defined(HAVE_ECC)
7509
WOLFSSL_LOCAL int SetECKeyInternal(WOLFSSL_EC_KEY* eckey);
7510
WOLFSSL_LOCAL int SetECKeyExternal(WOLFSSL_EC_KEY* eckey);
7511
#endif
7512
7513
#if defined(OPENSSL_EXTRA) || defined(HAVE_CURL)
7514
WOLFSSL_LOCAL int wolfSSL_curve_is_disabled(const WOLFSSL* ssl,
7515
                                            word16 curve_id);
7516
#else
7517
static WC_INLINE int wolfSSL_curve_is_disabled(const WOLFSSL* ssl,
7518
                                               word16 curve_id)
7519
0
{
7520
0
    (void)ssl;
7521
0
    (void)curve_id;
7522
0
    return 0;
7523
0
}
Unexecuted instantiation: asn.c:wolfSSL_curve_is_disabled
Unexecuted instantiation: ssl.c:wolfSSL_curve_is_disabled
Unexecuted instantiation: tls.c:wolfSSL_curve_is_disabled
Unexecuted instantiation: tls13.c:wolfSSL_curve_is_disabled
Unexecuted instantiation: internal.c:wolfSSL_curve_is_disabled
Unexecuted instantiation: keys.c:wolfSSL_curve_is_disabled
Unexecuted instantiation: wolfio.c:wolfSSL_curve_is_disabled
7524
#endif
7525
7526
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
7527
WOLFSSL_LOCAL WC_RNG* WOLFSSL_RSA_GetRNG(WOLFSSL_RSA *rsa, WC_RNG **tmpRNG,
7528
                                         int *initTmpRng);
7529
#endif /* OPENSSL_EXTRA || OPENSSL_EXTRA_X509_SMALL */
7530
7531
    #ifndef NO_RSA
7532
        #ifdef WC_RSA_PSS
7533
            WOLFSSL_LOCAL int CheckRsaPssPadding(const byte* plain, word32 plainSz,
7534
                byte* out, word32 sigSz, enum wc_HashType hashType);
7535
            WOLFSSL_LOCAL int ConvertHashPss(int hashAlgo,
7536
                enum wc_HashType* hashType, int* mgf);
7537
        #endif
7538
        WOLFSSL_LOCAL int VerifyRsaSign(WOLFSSL* ssl, byte* verifySig,
7539
            word32 sigSz, const byte* plain, word32 plainSz, int sigAlgo,
7540
            int hashAlgo, RsaKey* key, DerBuffer* keyBufInfo);
7541
        WOLFSSL_LOCAL int RsaSign(WOLFSSL* ssl, const byte* in, word32 inSz,
7542
            byte* out, word32* outSz, int sigAlgo, int hashAlgo, RsaKey* key,
7543
            DerBuffer* keyBufInfo);
7544
        WOLFSSL_LOCAL int RsaVerify(WOLFSSL* ssl, byte* in, word32 inSz,
7545
            byte** out, int sigAlgo, int hashAlgo, RsaKey* key,
7546
            buffer* keyBufInfo);
7547
        WOLFSSL_LOCAL int RsaDec(WOLFSSL* ssl, byte* in, word32 inSz, byte** out,
7548
            word32* outSz, RsaKey* key, DerBuffer* keyBufInfo);
7549
        WOLFSSL_LOCAL int RsaEnc(WOLFSSL* ssl, const byte* in, word32 inSz, byte* out,
7550
            word32* outSz, RsaKey* key, buffer* keyBufInfo);
7551
    #endif /* !NO_RSA */
7552
7553
    #ifdef HAVE_ECC
7554
        WOLFSSL_LOCAL int EccSign(WOLFSSL* ssl, const byte* in, word32 inSz,
7555
            byte* out, word32* outSz, ecc_key* key, DerBuffer* keyBufInfo);
7556
        WOLFSSL_LOCAL int EccVerify(WOLFSSL* ssl, const byte* in, word32 inSz,
7557
            const byte* out, word32 outSz, ecc_key* key, buffer* keyBufInfo);
7558
        WOLFSSL_LOCAL int EccSharedSecret(WOLFSSL* ssl, ecc_key* priv_key,
7559
            ecc_key* pub_key, byte* pubKeyDer, word32* pubKeySz, byte* out,
7560
            word32* outlen, int side);
7561
    #endif /* HAVE_ECC */
7562
    #if defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3)
7563
        WOLFSSL_LOCAL int Sm2wSm3Sign(WOLFSSL* ssl, const byte* id, word32 idSz,
7564
            const byte* in, word32 inSz, byte* out, word32* outSz, ecc_key* key,
7565
            DerBuffer* keyBufInfo);
7566
        WOLFSSL_LOCAL int Sm2wSm3Verify(WOLFSSL* ssl, const byte* id,
7567
            word32 idSz, const byte* in, word32 inSz, const byte* out,
7568
            word32 outSz, ecc_key* key, buffer* keyBufInfo);
7569
    #endif /* WOLFSSL_SM2 && WOLFSSL_SM3 */
7570
    #ifdef HAVE_ED25519
7571
        WOLFSSL_LOCAL int Ed25519CheckPubKey(WOLFSSL* ssl);
7572
        WOLFSSL_LOCAL int Ed25519Sign(WOLFSSL* ssl, const byte* in, word32 inSz,
7573
            byte* out, word32* outSz, ed25519_key* key, DerBuffer* keyBufInfo);
7574
        WOLFSSL_LOCAL int Ed25519Verify(WOLFSSL* ssl, const byte* in,
7575
            word32 inSz, const byte* msg, word32 msgSz, ed25519_key* key,
7576
            buffer* keyBufInfo);
7577
    #endif /* HAVE_ED25519 */
7578
    #ifdef HAVE_ED448
7579
        WOLFSSL_LOCAL int Ed448CheckPubKey(WOLFSSL* ssl);
7580
        WOLFSSL_LOCAL int Ed448Sign(WOLFSSL* ssl, const byte* in, word32 inSz,
7581
            byte* out, word32* outSz, ed448_key* key, DerBuffer* keyBufInfo);
7582
        WOLFSSL_LOCAL int Ed448Verify(WOLFSSL* ssl, const byte* in,
7583
            word32 inSz, const byte* msg, word32 msgSz, ed448_key* key,
7584
            buffer* keyBufInfo);
7585
    #endif /* HAVE_ED448 */
7586
7587
#ifndef NO_CERTS
7588
    #ifdef WOLFSSL_TRUST_PEER_CERT
7589
7590
        /* options for searching hash table for a matching trusted peer cert */
7591
        #define WC_MATCH_SKID 0
7592
        #define WC_MATCH_NAME 1
7593
7594
        WOLFSSL_LOCAL TrustedPeerCert* GetTrustedPeer(void* vp, DecodedCert* cert);
7595
        WOLFSSL_LOCAL int MatchTrustedPeer(TrustedPeerCert* tp,
7596
                                                             DecodedCert* cert);
7597
    #endif
7598
7599
7600
    #ifndef GetCA
7601
        WOLFSSL_LOCAL Signer* GetCA(void* vp, byte* hash);
7602
    #endif
7603
    #if defined(WOLFSSL_AKID_NAME) && !defined(WC_SYM_RELOC_TABLES)
7604
        /* note WOLFSSL_API_PREFIX_MAPping is in asn.h, and if
7605
         * WC_SYM_RELOC_TABLES, the prototype is in the port layer
7606
         * (e.g. linuxkm_wc_port.h), to allow shimming.
7607
         */
7608
        WOLFSSL_TEST_VIS Signer* GetCAByAKID(void* vp, const byte* issuer,
7609
                word32 issuerSz, const byte* serial, word32 serialSz);
7610
    #endif
7611
    #if defined(HAVE_OCSP) && !defined(GetCAByKeyHash)
7612
        WOLFSSL_LOCAL Signer* GetCAByKeyHash(void* vp, const byte* keyHash);
7613
    #endif
7614
    #if !defined(NO_SKID) && !defined(GetCAByName)
7615
        WOLFSSL_LOCAL Signer* GetCAByName(void* vp, byte* hash);
7616
    #endif
7617
#endif /* !NO_CERTS */
7618
WOLFSSL_LOCAL int  BuildTlsHandshakeHash(WOLFSSL* ssl, byte* hash,
7619
                                   word32* hashLen);
7620
WOLFSSL_LOCAL int  BuildTlsFinished(WOLFSSL* ssl, Hashes* hashes,
7621
                                   const byte* sender);
7622
WOLFSSL_LOCAL void FreeArrays(WOLFSSL* ssl, int keep);
7623
WOLFSSL_LOCAL  int CheckAvailableSize(WOLFSSL *ssl, int size);
7624
WOLFSSL_LOCAL  int GrowInputBuffer(WOLFSSL* ssl, int size, int usedLength);
7625
WOLFSSL_LOCAL  int MsgCheckEncryption(WOLFSSL* ssl, byte type, byte encrypted);
7626
WOLFSSL_LOCAL  int EarlySanityCheckMsgReceived(WOLFSSL* ssl, byte type,
7627
        word32 msgSz);
7628
WOLFSSL_LOCAL int GetHandshakeHeader(WOLFSSL* ssl, const byte* input,
7629
        word32* inOutIdx, byte* type, word32* size, word32 totalSz);
7630
#if !defined(NO_WOLFSSL_CLIENT) || !defined(WOLFSSL_NO_CLIENT_AUTH)
7631
WOLFSSL_LOCAL void DoCertFatalAlert(WOLFSSL* ssl, int ret);
7632
#endif
7633
#ifndef NO_TLS
7634
    WOLFSSL_LOCAL int  MakeTlsMasterSecret(WOLFSSL* ssl);
7635
#ifndef WOLFSSL_AEAD_ONLY
7636
    WOLFSSL_LOCAL int  TLS_hmac(WOLFSSL* ssl, byte* digest, const byte* in,
7637
                                word32 sz, int padSz, int content, int verify, int epochOrder);
7638
#endif
7639
#endif
7640
7641
WOLFSSL_LOCAL int cipherExtraData(WOLFSSL* ssl);
7642
WOLFSSL_LOCAL word32 MacSize(const WOLFSSL* ssl);
7643
7644
#ifndef NO_WOLFSSL_CLIENT
7645
    WOLFSSL_LOCAL int HaveUniqueSessionObj(WOLFSSL* ssl);
7646
    WOLFSSL_LOCAL int SendClientHello(WOLFSSL* ssl);
7647
    WOLFSSL_LOCAL int DoHelloVerifyRequest(WOLFSSL* ssl, const byte* input, word32* inOutIdx,
7648
        word32 size);
7649
    #ifdef WOLFSSL_TLS13
7650
    WOLFSSL_LOCAL int SendTls13ClientHello(WOLFSSL* ssl);
7651
    #endif
7652
    WOLFSSL_LOCAL int SendClientKeyExchange(WOLFSSL* ssl);
7653
    WOLFSSL_LOCAL int SendCertificateVerify(WOLFSSL* ssl);
7654
#endif /* NO_WOLFSSL_CLIENT */
7655
7656
#ifndef NO_WOLFSSL_SERVER
7657
    WOLFSSL_LOCAL int SendServerHello(WOLFSSL* ssl);
7658
    WOLFSSL_LOCAL int SendServerHelloDone(WOLFSSL* ssl);
7659
#endif /* NO_WOLFSSL_SERVER */
7660
7661
#ifdef WOLFSSL_TLS13
7662
    WOLFSSL_LOCAL int SendTls13KeyUpdate(WOLFSSL* ssl);
7663
WOLFSSL_LOCAL int Tls13KeyUpdateLimitReached(WOLFSSL* ssl);
7664
#endif
7665
7666
#ifdef WOLFSSL_DTLS
7667
    #ifdef WOLFSSL_API_PREFIX_MAP
7668
        #define DtlsMsgListDelete wolfSSL_DtlsMsgListDelete
7669
        #define DtlsMsgFind wolfSSL_DtlsMsgFind
7670
        #define DtlsMsgStore wolfSSL_DtlsMsgStore
7671
    #endif /* WOLFSSL_API_PREFIX_MAP */
7672
    WOLFSSL_LOCAL DtlsMsg* DtlsMsgNew(word32 sz, byte tx, void* heap);
7673
    WOLFSSL_LOCAL void DtlsMsgDelete(DtlsMsg* item, void* heap);
7674
    WOLFSSL_TEST_VIS void DtlsMsgListDelete(DtlsMsg* head, void* heap);
7675
    WOLFSSL_LOCAL void DtlsTxMsgListClean(WOLFSSL* ssl);
7676
    WOLFSSL_LOCAL int  DtlsMsgSet(DtlsMsg* msg, word32 seq, word16 epoch,
7677
                                  const byte* data, byte type,
7678
                                  word32 fragOffset, word32 fragSz, void* heap,
7679
                                  word32 totalLen, byte encrypted);
7680
    WOLFSSL_TEST_VIS DtlsMsg* DtlsMsgFind(DtlsMsg* head, word16 epoch, word32 seq);
7681
7682
    WOLFSSL_TEST_VIS int DtlsMsgStore(WOLFSSL* ssl, word16 epoch, word32 seq,
7683
                                    const byte* data, word32 dataSz, byte type,
7684
                                    word32 fragOffset, word32 fragSz,
7685
                                    void* heap);
7686
    WOLFSSL_LOCAL DtlsMsg* DtlsMsgInsert(DtlsMsg* head, DtlsMsg* item);
7687
7688
    WOLFSSL_LOCAL int  DtlsMsgPoolSave(WOLFSSL* ssl, const byte* data,
7689
                                       word32 dataSz, enum HandShakeType type);
7690
    WOLFSSL_LOCAL int  DtlsMsgPoolTimeout(WOLFSSL* ssl);
7691
    WOLFSSL_LOCAL int  VerifyForDtlsMsgPoolSend(WOLFSSL* ssl, byte type,
7692
                                                word32 fragOffset);
7693
    WOLFSSL_LOCAL int  VerifyForTxDtlsMsgDelete(WOLFSSL* ssl, DtlsMsg* item);
7694
    WOLFSSL_LOCAL void DtlsMsgPoolReset(WOLFSSL* ssl);
7695
    WOLFSSL_LOCAL int  wolfssl_local_SockAddrSet(WOLFSSL_SOCKADDR* sockAddr,
7696
                                                 void* peer,
7697
                                                 unsigned int peerSz,
7698
                                                 void* heap);
7699
    WOLFSSL_LOCAL int  DtlsMsgPoolSend(WOLFSSL* ssl, int sendOnlyFirstPacket);
7700
    WOLFSSL_LOCAL void DtlsMsgDestroyFragBucket(DtlsFragBucket* fragBucket, void* heap);
7701
    WOLFSSL_LOCAL int GetDtlsHandShakeHeader(WOLFSSL *ssl, const byte *input,
7702
        word32 *inOutIdx, byte *type, word32 *size, word32 *fragOffset,
7703
        word32 *fragSz, word32 totalSz);
7704
    WOLFSSL_LOCAL int DtlsMsgDrain(WOLFSSL *ssl);
7705
    WOLFSSL_LOCAL int SendHelloVerifyRequest(WOLFSSL* ssl,
7706
        const byte* cookie, byte cookieSz);
7707
7708
#if !defined(NO_WOLFSSL_SERVER)
7709
    WOLFSSL_LOCAL int DoClientHelloStateless(WOLFSSL* ssl,
7710
            const byte* input, word32 helloSz, byte isFirstCHFrag, byte* tls13);
7711
#endif /* !defined(NO_WOLFSSL_SERVER) */
7712
#if !defined(WOLFCRYPT_ONLY) && !defined(WOLFSSL_NO_SOCK) && \
7713
    (defined(USE_WOLFSSL_IO) || defined(WOLFSSL_USER_IO))
7714
    WOLFSSL_LOCAL int sockAddrEqual(SOCKADDR_S *a, XSOCKLENT aLen,
7715
                                    SOCKADDR_S *b, XSOCKLENT bLen);
7716
#endif
7717
#endif /* WOLFSSL_DTLS */
7718
7719
#if defined(HAVE_SECURE_RENEGOTIATION) && defined(WOLFSSL_DTLS)
7720
    WOLFSSL_LOCAL int DtlsSCRKeysSet(WOLFSSL* ssl);
7721
    WOLFSSL_LOCAL int IsDtlsMsgSCRKeys(WOLFSSL* ssl);
7722
    WOLFSSL_LOCAL int DtlsUseSCRKeys(WOLFSSL* ssl);
7723
    WOLFSSL_LOCAL int DtlsCheckOrder(WOLFSSL* ssl, int order);
7724
#endif
7725
    WOLFSSL_LOCAL int IsSCR(WOLFSSL* ssl);
7726
    WOLFSSL_LOCAL int IsDtlsNotSctpMode(WOLFSSL* ssl);
7727
    WOLFSSL_LOCAL int IsDtlsNotSrtpMode(WOLFSSL* ssl);
7728
7729
    WOLFSSL_LOCAL void WriteSEQ(WOLFSSL* ssl, int verifyOrder, byte* out);
7730
7731
#if defined(WOLFSSL_TLS13) && (defined(HAVE_SESSION_TICKET) || \
7732
        !defined(NO_PSK) || defined(WOLFSSL_DTLS13))
7733
#ifdef WOLFSSL_32BIT_MILLI_TIME
7734
    WOLFSSL_LOCAL word32 TimeNowInMilliseconds(void);
7735
#else
7736
    WOLFSSL_LOCAL sword64 TimeNowInMilliseconds(void);
7737
#endif
7738
7739
#endif
7740
WOLFSSL_LOCAL word32  LowResTimer(void);
7741
7742
WOLFSSL_LOCAL int FindSuiteSSL(const WOLFSSL* ssl, byte* suite);
7743
WOLFSSL_LOCAL int FindSuite(const Suites* suites, byte first, byte second);
7744
7745
WOLFSSL_LOCAL void DecodeSigAlg(const byte* input, byte* hashAlgo,
7746
        byte* hsType);
7747
#ifdef WOLFSSL_HAVE_SLHDSA
7748
WOLFSSL_LOCAL byte SlhDsaSigMinorToType(byte minor);
7749
WOLFSSL_LOCAL int SlhDsaTypeToParam(byte hsType);
7750
WOLFSSL_LOCAL int IsSlhDsaSigAlgo(byte hsType);
7751
WOLFSSL_LOCAL byte SlhDsaParamToType(int param);
7752
#endif
7753
WOLFSSL_LOCAL enum wc_HashType HashAlgoToType(int hashAlgo);
7754
7755
#ifndef NO_CERTS
7756
    WOLFSSL_LOCAL void InitX509Name(WOLFSSL_X509_NAME* name, int dynamicFlag,
7757
                                    void* heap);
7758
    WOLFSSL_LOCAL void FreeX509Name(WOLFSSL_X509_NAME* name);
7759
    WOLFSSL_LOCAL void InitX509(WOLFSSL_X509* x509, int dynamicFlag,
7760
                                void* heap);
7761
    WOLFSSL_LOCAL void FreeX509(WOLFSSL_X509* x509);
7762
    WOLFSSL_LOCAL void ReinitX509(WOLFSSL_X509* x509);
7763
    #ifndef NO_ASN
7764
    WOLFSSL_LOCAL int  CopyDecodedToX509(WOLFSSL_X509* x509,
7765
                                         DecodedCert* dCert);
7766
    #endif
7767
#endif
7768
7769
#if defined(WOLFSSL_ACERT)
7770
    WOLFSSL_LOCAL int  CopyDecodedAcertToX509(WOLFSSL_X509_ACERT* x509,
7771
                                              DecodedAcert* dAcert);
7772
#endif /* WOLFSSL_ACERT */
7773
7774
7775
#ifndef MAX_CIPHER_NAME
7776
#define MAX_CIPHER_NAME 50
7777
#endif
7778
7779
#ifdef WOLFSSL_NAMES_STATIC
7780
typedef char cipher_name[MAX_CIPHER_NAME];
7781
#else
7782
typedef const char* cipher_name;
7783
#endif
7784
7785
typedef struct CipherSuiteInfo {
7786
    cipher_name name;
7787
#ifndef NO_ERROR_STRINGS
7788
    cipher_name name_iana;
7789
#endif
7790
    byte cipherSuite0;
7791
    byte cipherSuite;
7792
#if defined(OPENSSL_EXTRA) || defined(WOLFSSL_QT) || \
7793
    defined(WOLFSSL_HAPROXY) || defined(WOLFSSL_NGINX)
7794
    byte minor;
7795
    byte major;
7796
#endif
7797
    byte flags;
7798
} CipherSuiteInfo;
7799
7800
#ifdef WOLFSSL_API_PREFIX_MAP
7801
    #define GetCipherNames wolfSSL_GetCipherNames
7802
    #define GetCipherNamesSize wolfSSL_GetCipherNamesSize
7803
#endif
7804
WOLFSSL_TEST_VIS const CipherSuiteInfo* GetCipherNames(void);
7805
WOLFSSL_TEST_VIS int GetCipherNamesSize(void);
7806
WOLFSSL_LOCAL const char* GetCipherNameInternal(const byte cipherSuite0, const byte cipherSuite);
7807
#if defined(OPENSSL_ALL) || defined(WOLFSSL_QT)
7808
/* used in wolfSSL_sk_CIPHER_description */
7809
#define MAX_SEGMENTS    5
7810
#define MAX_SEGMENT_SZ 20
7811
WOLFSSL_LOCAL int wolfSSL_sk_CIPHER_description(WOLFSSL_CIPHER* cipher);
7812
WOLFSSL_LOCAL const char* GetCipherSegment(const WOLFSSL_CIPHER* cipher,
7813
                                           char n[][MAX_SEGMENT_SZ]);
7814
WOLFSSL_LOCAL const char* GetCipherProtocol(byte minor);
7815
WOLFSSL_LOCAL const char* GetCipherKeaStr(char n[][MAX_SEGMENT_SZ]);
7816
WOLFSSL_LOCAL const char* GetCipherAuthStr(char n[][MAX_SEGMENT_SZ]);
7817
WOLFSSL_LOCAL const char* GetCipherEncStr(char n[][MAX_SEGMENT_SZ]);
7818
WOLFSSL_LOCAL const char* GetCipherMacStr(char n[][MAX_SEGMENT_SZ]);
7819
WOLFSSL_LOCAL int SetCipherBits(const char* enc);
7820
WOLFSSL_LOCAL int IsCipherAEAD(char n[][MAX_SEGMENT_SZ]);
7821
#endif
7822
WOLFSSL_LOCAL const char* GetCipherNameIana(const byte cipherSuite0, const byte cipherSuite);
7823
WOLFSSL_LOCAL const char* wolfSSL_get_cipher_name_internal(WOLFSSL* ssl);
7824
WOLFSSL_LOCAL const char* wolfSSL_get_cipher_name_iana(WOLFSSL* ssl);
7825
WOLFSSL_LOCAL int GetCipherSuiteFromName(const char* name, byte* cipherSuite0,
7826
                       byte* cipherSuite, byte* major, byte* minor, int* flags);
7827
7828
7829
enum encrypt_side {
7830
    ENCRYPT_SIDE_ONLY = 1,
7831
    DECRYPT_SIDE_ONLY,
7832
    ENCRYPT_AND_DECRYPT_SIDE
7833
};
7834
7835
WOLFSSL_LOCAL int SetKeys(Ciphers* enc, Ciphers* dec, Keys* keys,
7836
    CipherSpecs* specs, int side, void* heap, int devId, WC_RNG* rng,
7837
    int tls13);
7838
WOLFSSL_LOCAL int SetKeysSide(WOLFSSL* ssl, enum encrypt_side side);
7839
7840
/* Set*Internal and Set*External functions */
7841
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
7842
WOLFSSL_LOCAL int SetDsaInternal(WOLFSSL_DSA* dsa);
7843
WOLFSSL_LOCAL int SetDsaExternal(WOLFSSL_DSA* dsa);
7844
WOLFSSL_LOCAL int SetRsaExternal(WOLFSSL_RSA* rsa);
7845
WOLFSSL_LOCAL int SetRsaInternal(WOLFSSL_RSA* rsa);
7846
7847
typedef enum elem_set {
7848
    ELEMENT_P   = 0x01,
7849
    ELEMENT_Q   = 0x02,
7850
    ELEMENT_G   = 0x04,
7851
    ELEMENT_PUB = 0x08,
7852
    ELEMENT_PRV = 0x10,
7853
} Element_Set;
7854
WOLFSSL_LOCAL int SetDhExternal_ex(WOLFSSL_DH *dh, int elm );
7855
WOLFSSL_LOCAL int SetDhInternal(WOLFSSL_DH* dh);
7856
WOLFSSL_LOCAL int SetDhExternal(WOLFSSL_DH *dh);
7857
#endif /* OPENSSL_EXTRA || OPENSSL_EXTRA_X509_SMALL */
7858
7859
#if !defined(NO_DH) && (!defined(NO_CERTS) || !defined(NO_PSK))
7860
    WOLFSSL_LOCAL int DhGenKeyPair(WOLFSSL* ssl, DhKey* dhKey,
7861
        byte* priv, word32* privSz,
7862
        byte* pub, word32* pubSz);
7863
    WOLFSSL_LOCAL int DhAgree(WOLFSSL* ssl, DhKey* dhKey,
7864
        const byte* priv, word32 privSz,
7865
        const byte* otherPub, word32 otherPubSz,
7866
        byte* agree, word32* agreeSz,
7867
        const byte* prime, word32 primeSz);
7868
#endif /* !NO_DH */
7869
7870
#ifdef HAVE_ECC
7871
    WOLFSSL_LOCAL int EccMakeKey(WOLFSSL* ssl, ecc_key* key, ecc_key* peer);
7872
    WOLFSSL_LOCAL word16 GetCurveByOID(int oidSum);
7873
#endif
7874
7875
WOLFSSL_LOCAL int InitHandshakeHashes(WOLFSSL* ssl);
7876
WOLFSSL_LOCAL void Free_HS_Hashes(HS_Hashes* hsHashes, void* heap);
7877
WOLFSSL_LOCAL void FreeHandshakeHashes(WOLFSSL* ssl);
7878
WOLFSSL_LOCAL int InitHandshakeHashesAndCopy(WOLFSSL* ssl, HS_Hashes* source,
7879
    HS_Hashes** destination);
7880
7881
7882
#ifndef WOLFSSL_NO_TLS12
7883
WOLFSSL_LOCAL void FreeBuildMsgArgs(WOLFSSL* ssl, BuildMsgArgs* args);
7884
#endif
7885
#ifdef WOLFSSL_API_PREFIX_MAP
7886
    #define BuildMessage wolfSSL_BuildMessage
7887
#endif
7888
WOLFSSL_TEST_VIS int BuildMessage(WOLFSSL* ssl, byte* output, int outSz,
7889
                        const byte* input, int inSz, int type, int hashOutput,
7890
                        int sizeOnly, int asyncOkay, int epochOrder);
7891
7892
#ifdef WOLFSSL_TLS13
7893
#ifdef WOLFSSL_API_PREFIX_MAP
7894
    #define BuildTls13Message wolfSSL_BuildTls13Message
7895
#endif
7896
WOLFSSL_TEST_VIS int BuildTls13Message(WOLFSSL* ssl, byte* output, int outSz, const byte* input,
7897
               int inSz, int type, int hashOutput, int sizeOnly, int asyncOkay);
7898
WOLFSSL_LOCAL int Tls13UpdateKeys(WOLFSSL* ssl);
7899
#endif
7900
7901
WOLFSSL_LOCAL int AllocKey(WOLFSSL* ssl, int type, void** pKey);
7902
WOLFSSL_LOCAL void FreeKey(WOLFSSL* ssl, int type, void** pKey);
7903
7904
#ifdef WOLFSSL_ASYNC_CRYPT
7905
    WOLFSSL_LOCAL int wolfSSL_AsyncInit(WOLFSSL* ssl, WC_ASYNC_DEV* asyncDev, word32 flags);
7906
    WOLFSSL_LOCAL int wolfSSL_AsyncPop(WOLFSSL* ssl, byte* state);
7907
    WOLFSSL_LOCAL int wolfSSL_AsyncPush(WOLFSSL* ssl, WC_ASYNC_DEV* asyncDev);
7908
#endif
7909
7910
#if defined(OPENSSL_ALL) && defined(WOLFSSL_CERT_GEN) && \
7911
    (defined(WOLFSSL_CERT_REQ) || defined(WOLFSSL_CERT_EXT)) && \
7912
    !defined(NO_FILESYSTEM) && !defined(NO_WOLFSSL_DIR)
7913
WOLFSSL_LOCAL int LoadCertByIssuer(WOLFSSL_X509_STORE* store,
7914
                                           X509_NAME* issuer, int Type);
7915
#endif
7916
#if defined(OPENSSL_ALL) && !defined(NO_FILESYSTEM) && !defined(NO_WOLFSSL_DIR)
7917
WOLFSSL_LOCAL WOLFSSL_BY_DIR_HASH* wolfSSL_BY_DIR_HASH_new(void);
7918
WOLFSSL_LOCAL void wolfSSL_BY_DIR_HASH_free(WOLFSSL_BY_DIR_HASH* dir_hash);
7919
WOLFSSL_LOCAL WOLFSSL_STACK* wolfSSL_sk_BY_DIR_HASH_new_null(void);
7920
WOLFSSL_LOCAL int wolfSSL_sk_BY_DIR_HASH_find(
7921
   WOLF_STACK_OF(WOLFSSL_BY_DIR_HASH)* sk, const WOLFSSL_BY_DIR_HASH* toFind);
7922
WOLFSSL_LOCAL int wolfSSL_sk_BY_DIR_HASH_num(const WOLF_STACK_OF(WOLFSSL_BY_DIR_HASH) *sk);
7923
WOLFSSL_LOCAL WOLFSSL_BY_DIR_HASH* wolfSSL_sk_BY_DIR_HASH_value(
7924
                        const WOLF_STACK_OF(WOLFSSL_BY_DIR_HASH) *sk, int i);
7925
WOLFSSL_LOCAL WOLFSSL_BY_DIR_HASH* wolfSSL_sk_BY_DIR_HASH_pop(
7926
                                WOLF_STACK_OF(WOLFSSL_BY_DIR_HASH)* sk);
7927
WOLFSSL_LOCAL void wolfSSL_sk_BY_DIR_HASH_pop_free(WOLF_STACK_OF(WOLFSSL_BY_DIR_HASH)* sk,
7928
    void (*f) (WOLFSSL_BY_DIR_HASH*));
7929
WOLFSSL_LOCAL void wolfSSL_sk_BY_DIR_HASH_free(WOLF_STACK_OF(WOLFSSL_BY_DIR_HASH) *sk);
7930
WOLFSSL_LOCAL int wolfSSL_sk_BY_DIR_HASH_push(WOLF_STACK_OF(WOLFSSL_BY_DIR_HASH)* sk,
7931
                                               WOLFSSL_BY_DIR_HASH* in);
7932
/* WOLFSSL_BY_DIR_entry stuff */
7933
WOLFSSL_LOCAL WOLFSSL_BY_DIR_entry* wolfSSL_BY_DIR_entry_new(void);
7934
WOLFSSL_LOCAL void wolfSSL_BY_DIR_entry_free(WOLFSSL_BY_DIR_entry* entry);
7935
WOLFSSL_LOCAL WOLFSSL_STACK* wolfSSL_sk_BY_DIR_entry_new_null(void);
7936
WOLFSSL_LOCAL int wolfSSL_sk_BY_DIR_entry_num(const WOLF_STACK_OF(WOLFSSL_BY_DIR_entry) *sk);
7937
WOLFSSL_LOCAL WOLFSSL_BY_DIR_entry* wolfSSL_sk_BY_DIR_entry_value(
7938
                        const WOLF_STACK_OF(WOLFSSL_BY_DIR_entry) *sk, int i);
7939
WOLFSSL_LOCAL WOLFSSL_BY_DIR_entry* wolfSSL_sk_BY_DIR_entry_pop(
7940
                                WOLF_STACK_OF(WOLFSSL_BY_DIR_entry)* sk);
7941
WOLFSSL_LOCAL void wolfSSL_sk_BY_DIR_entry_pop_free(WOLF_STACK_OF(wolfSSL_BY_DIR_entry)* sk,
7942
    void (*f) (WOLFSSL_BY_DIR_entry*));
7943
WOLFSSL_LOCAL void wolfSSL_sk_BY_DIR_entry_free(WOLF_STACK_OF(wolfSSL_BY_DIR_entry) *sk);
7944
WOLFSSL_LOCAL int wolfSSL_sk_BY_DIR_entry_push(WOLF_STACK_OF(wolfSSL_BY_DIR_entry)* sk,
7945
                                               WOLFSSL_BY_DIR_entry* in);
7946
#endif /* OPENSSL_ALL && !NO_FILESYSTEM && !NO_WOLFSSL_DIR */
7947
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
7948
WOLFSSL_LOCAL int oid2nid(word32 oid, int grp);
7949
WOLFSSL_LOCAL word32 nid2oid(int nid, int grp);
7950
WOLFSSL_LOCAL void wolfssl_object_info_slice_init(void);
7951
#endif
7952
7953
#ifdef WOLFSSL_DTLS
7954
WOLFSSL_TEST_VIS int wolfSSL_DtlsUpdateWindow(word16 cur_hi, word32 cur_lo,
7955
        word16* next_hi, word32* next_lo, word32 *window);
7956
WOLFSSL_LOCAL int DtlsUpdateWindow(WOLFSSL* ssl);
7957
WOLFSSL_LOCAL void DtlsResetState(WOLFSSL *ssl);
7958
WOLFSSL_LOCAL int DtlsIgnoreError(int err);
7959
WOLFSSL_LOCAL void DtlsSetSeqNumForReply(WOLFSSL* ssl);
7960
#endif
7961
7962
#ifdef WOLFSSL_DTLS13
7963
    #ifdef WOLFSSL_API_PREFIX_MAP
7964
        #define Dtls13GetEpoch wolfSSL_Dtls13GetEpoch
7965
        #define Dtls13NewEpoch wolfSSL_Dtls13NewEpoch
7966
        #define Dtls13CheckEpoch wolfSSL_Dtls13CheckEpoch
7967
        #define Dtls13HandshakeRecv wolfSSL_Dtls13HandshakeRecv
7968
        #define Dtls13WriteAckMessage wolfSSL_Dtls13WriteAckMessage
7969
        #define Dtls13RtxAddAck wolfSSL_Dtls13RtxAddAck
7970
        #define Dtls13DoScheduledWork wolfSSL_Dtls13DoScheduledWork
7971
    #endif
7972
7973
WOLFSSL_TEST_VIS struct Dtls13Epoch* Dtls13GetEpoch(WOLFSSL* ssl,
7974
    w64wrapper epochNumber);
7975
WOLFSSL_LOCAL void Dtls13SetOlderEpochSide(WOLFSSL* ssl, w64wrapper epochNumber,
7976
    int side);
7977
WOLFSSL_TEST_VIS int Dtls13NewEpoch(WOLFSSL* ssl, w64wrapper epochNumber,
7978
    int side);
7979
WOLFSSL_LOCAL int Dtls13SetEpochKeys(WOLFSSL* ssl, w64wrapper epochNumber,
7980
    enum encrypt_side side);
7981
WOLFSSL_LOCAL int Dtls13GetSeq(WOLFSSL* ssl, int order, word32* seq,
7982
    byte increment);
7983
WOLFSSL_LOCAL void Dtls13RtxRemoveRecord(WOLFSSL* ssl, w64wrapper epoch,
7984
    w64wrapper seq);
7985
WOLFSSL_TEST_VIS int Dtls13DoScheduledWork(WOLFSSL* ssl);
7986
WOLFSSL_LOCAL int Dtls13DeriveSnKeys(WOLFSSL* ssl, int provision);
7987
WOLFSSL_LOCAL int Dtls13SetRecordNumberKeys(WOLFSSL* ssl,
7988
    enum encrypt_side side);
7989
7990
WOLFSSL_LOCAL int Dtls13AddHeaders(byte* output, word32 length,
7991
    enum HandShakeType hs_type, WOLFSSL* ssl);
7992
WOLFSSL_LOCAL word16 Dtls13GetHeadersLength(WOLFSSL *ssl,
7993
    enum HandShakeType type);
7994
WOLFSSL_LOCAL word16 Dtls13GetRlHeaderLength(WOLFSSL *ssl, byte is_encrypted);
7995
WOLFSSL_LOCAL int Dtls13RlAddCiphertextHeader(WOLFSSL* ssl, byte* out,
7996
    word16 length);
7997
WOLFSSL_LOCAL int Dtls13RlAddPlaintextHeader(WOLFSSL* ssl, byte* out,
7998
    enum ContentType content_type, word16 length);
7999
WOLFSSL_LOCAL int Dtls13MinimumRecordLength(WOLFSSL* ssl);
8000
WOLFSSL_LOCAL int Dtls13EncryptRecordNumber(WOLFSSL* ssl, byte* hdr,
8001
    word16 recordLength);
8002
WOLFSSL_LOCAL int Dtls13IsUnifiedHeader(byte header_flags);
8003
WOLFSSL_LOCAL int Dtls13GetUnifiedHeaderSize(WOLFSSL* ssl, const byte input,
8004
    word16* size);
8005
WOLFSSL_LOCAL int Dtls13ParseUnifiedRecordLayer(WOLFSSL* ssl, const byte* input,
8006
    word16 input_size, Dtls13UnifiedHdrInfo* hdrInfo);
8007
WOLFSSL_LOCAL int Dtls13HandshakeSend(WOLFSSL* ssl, byte* output,
8008
    word16 output_size, word16 length, enum HandShakeType handshake_type,
8009
    int hash_output);
8010
WOLFSSL_LOCAL int Dtls13RecordRecvd(WOLFSSL* ssl);
8011
WOLFSSL_TEST_VIS int Dtls13CheckEpoch(WOLFSSL* ssl, enum HandShakeType type);
8012
WOLFSSL_TEST_VIS int Dtls13HandshakeRecv(WOLFSSL* ssl, byte* input,
8013
    word32* inOutIdx, word32 totalSz);
8014
WOLFSSL_LOCAL int Dtls13HandshakeAddHeader(WOLFSSL* ssl, byte* output,
8015
    enum HandShakeType msg_type, word32 length);
8016
#define EE_MASK (0x3)
8017
WOLFSSL_LOCAL int Dtls13FragmentsContinue(WOLFSSL* ssl);
8018
WOLFSSL_LOCAL int DoDtls13KeyUpdateAck(WOLFSSL* ssl);
8019
#ifdef WOLFSSL_DTLS_CID
8020
WOLFSSL_LOCAL int DoDtls13RequestConnectionId(WOLFSSL* ssl, const byte* input,
8021
    word32* inOutIdx, word32 size);
8022
WOLFSSL_LOCAL int DoDtls13NewConnectionId(WOLFSSL* ssl, const byte* input,
8023
    word32* inOutIdx, word32 size);
8024
#endif /* WOLFSSL_DTLS_CID */
8025
WOLFSSL_LOCAL int DoDtls13Ack(WOLFSSL* ssl, const byte* input, word32 inputSize,
8026
    word32* processedSize);
8027
WOLFSSL_LOCAL int Dtls13ReconstructEpochNumber(WOLFSSL* ssl, byte epochBits,
8028
    w64wrapper* epoch);
8029
WOLFSSL_LOCAL int Dtls13ReconstructSeqNumber(WOLFSSL* ssl,
8030
    Dtls13UnifiedHdrInfo* hdrInfo, w64wrapper* out);
8031
WOLFSSL_TEST_VIS int Dtls13WriteAckMessage(WOLFSSL* ssl,
8032
    Dtls13RecordNumber* recordNumberList, word16 recordsCount, word32* length);
8033
WOLFSSL_LOCAL int SendDtls13Ack(WOLFSSL* ssl);
8034
WOLFSSL_TEST_VIS int Dtls13RtxAddAck(WOLFSSL* ssl, w64wrapper epoch, w64wrapper seq);
8035
WOLFSSL_LOCAL int Dtls13RtxProcessingCertificate(WOLFSSL* ssl, byte* input,
8036
    word32 inputSize);
8037
WOLFSSL_LOCAL int Dtls13HashHandshake(WOLFSSL* ssl, const byte* input,
8038
    word16 length);
8039
WOLFSSL_LOCAL int Dtls13HashClientHello(const WOLFSSL* ssl, byte* hash,
8040
        int* hashSz, const byte* body, word32 length, CipherSpecs* specs);
8041
WOLFSSL_LOCAL void Dtls13FreeFsmResources(WOLFSSL* ssl);
8042
WOLFSSL_LOCAL void Dtls13RtxFlushBuffered(WOLFSSL* ssl,
8043
        byte keepNewSessionTicket);
8044
WOLFSSL_LOCAL int Dtls13RtxTimeout(WOLFSSL* ssl);
8045
WOLFSSL_LOCAL int Dtls13ProcessBufferedMessages(WOLFSSL* ssl);
8046
WOLFSSL_LOCAL int Dtls13CheckAEADFailLimit(WOLFSSL* ssl);
8047
WOLFSSL_LOCAL int Dtls13UpdateWindowRecordRecvd(WOLFSSL* ssl);
8048
#endif /* WOLFSSL_DTLS13 */
8049
8050
#ifdef WOLFSSL_STATIC_EPHEMERAL
8051
WOLFSSL_LOCAL int wolfSSL_StaticEphemeralKeyLoad(WOLFSSL* ssl, int keyAlgo, void* keyPtr);
8052
#endif
8053
8054
#ifndef NO_CERTS
8055
#if defined(OPENSSL_ALL) || defined(OPENSSL_EXTRA) || \
8056
    defined(OPENSSL_EXTRA_X509_SMALL)
8057
WOLFSSL_LOCAL int wolfSSL_ASN1_STRING_canon(WOLFSSL_ASN1_STRING* asn_out,
8058
    const WOLFSSL_ASN1_STRING* asn_in);
8059
#endif
8060
#ifdef OPENSSL_EXTRA
8061
WOLFSSL_LOCAL int GetX509Error(int e);
8062
#endif
8063
#endif
8064
8065
#ifdef HAVE_EX_DATA_CRYPTO
8066
typedef struct CRYPTO_EX_cb_ctx {
8067
    long ctx_l;
8068
    void *ctx_ptr;
8069
    WOLFSSL_CRYPTO_EX_new* new_func;
8070
    WOLFSSL_CRYPTO_EX_free* free_func;
8071
    WOLFSSL_CRYPTO_EX_dup* dup_func;
8072
    struct CRYPTO_EX_cb_ctx* next;
8073
} CRYPTO_EX_cb_ctx;
8074
8075
WOLFSSL_TEST_VIS extern CRYPTO_EX_cb_ctx* crypto_ex_cb_ctx_session;
8076
#ifdef WOLFSSL_API_PREFIX_MAP
8077
    #define crypto_ex_cb_free wolfSSL_crypto_ex_cb_free
8078
#endif
8079
WOLFSSL_TEST_VIS void crypto_ex_cb_free(CRYPTO_EX_cb_ctx* cb_ctx);
8080
WOLFSSL_LOCAL void crypto_ex_cb_setup_new_data(void *new_obj,
8081
        CRYPTO_EX_cb_ctx* cb_ctx, WOLFSSL_CRYPTO_EX_DATA* ex_data);
8082
WOLFSSL_LOCAL void crypto_ex_cb_free_data(void *obj, CRYPTO_EX_cb_ctx* cb_ctx,
8083
        WOLFSSL_CRYPTO_EX_DATA* ex_data);
8084
WOLFSSL_LOCAL int crypto_ex_cb_dup_data(const WOLFSSL_CRYPTO_EX_DATA *in,
8085
        WOLFSSL_CRYPTO_EX_DATA *out, CRYPTO_EX_cb_ctx* cb_ctx);
8086
WOLFSSL_LOCAL int wolfssl_local_get_ex_new_index(int class_index, long ctx_l,
8087
        void* ctx_ptr, WOLFSSL_CRYPTO_EX_new* new_func,
8088
        WOLFSSL_CRYPTO_EX_dup* dup_func, WOLFSSL_CRYPTO_EX_free* free_func);
8089
#endif /* HAVE_EX_DATA_CRYPTO */
8090
8091
WOLFSSL_LOCAL WC_RNG* wolfssl_get_global_rng(void);
8092
WOLFSSL_LOCAL WC_RNG* wolfssl_make_global_rng(void);
8093
8094
#if !defined(WOLFCRYPT_ONLY) && defined(OPENSSL_EXTRA)
8095
#if defined(WOLFSSL_KEY_GEN) && defined(WOLFSSL_PEM_TO_DER)
8096
WOLFSSL_LOCAL int EncryptDerKey(byte *der, int *derSz,
8097
    const WOLFSSL_EVP_CIPHER* cipher, unsigned char* passwd, int passwdSz,
8098
    byte **cipherInfo, int maxDerSz, int hashType);
8099
#endif
8100
#endif
8101
8102
#if !defined(NO_RSA) && defined(OPENSSL_EXTRA)
8103
WOLFSSL_LOCAL int wolfSSL_RSA_To_Der(WOLFSSL_RSA* rsa, byte** outBuf,
8104
    int publicKey, void* heap);
8105
#endif
8106
8107
#if defined(OPENSSL_ALL) || defined(WOLFSSL_NGINX) || defined(WOLFSSL_HAPROXY) \
8108
    || defined(OPENSSL_EXTRA) || defined(HAVE_LIGHTY) || defined(HAVE_SECRET_CALLBACK)
8109
WOLFSSL_LOCAL int wolfSSL_SSL_do_handshake_internal(WOLFSSL *s);
8110
#endif
8111
8112
#ifdef WOLFSSL_QUIC
8113
#define WOLFSSL_IS_QUIC(s)  (((s) != NULL) && ((s)->quic.method != NULL))
8114
WOLFSSL_LOCAL int wolfSSL_quic_receive(WOLFSSL* ssl, byte* buf, word32 sz);
8115
WOLFSSL_LOCAL int wolfSSL_quic_send(WOLFSSL* ssl);
8116
WOLFSSL_LOCAL void wolfSSL_quic_clear(WOLFSSL* ssl);
8117
WOLFSSL_LOCAL void wolfSSL_quic_free(WOLFSSL* ssl);
8118
WOLFSSL_LOCAL int wolfSSL_quic_forward_secrets(WOLFSSL *ssl,
8119
                                               int ktype, int side);
8120
WOLFSSL_LOCAL int wolfSSL_quic_keys_active(WOLFSSL* ssl, enum encrypt_side side);
8121
8122
#else
8123
0
#define WOLFSSL_IS_QUIC(s) 0
8124
#endif /* WOLFSSL_QUIC (else) */
8125
8126
#if defined(SHOW_SECRETS) && defined(WOLFSSL_SSLKEYLOGFILE)
8127
WOLFSSL_LOCAL int tls13ShowSecrets(WOLFSSL* ssl, int id, const unsigned char* secret,
8128
    int secretSz, void* ctx);
8129
#endif
8130
8131
#if defined(SHOW_SECRETS)
8132
WOLFSSL_LOCAL int tlsShowSecrets(WOLFSSL* ssl, void* secret,
8133
        int secretSz, void* ctx);
8134
#endif
8135
8136
/* Optional Pre-Master-Secret logging for Wireshark */
8137
#if !defined(NO_FILESYSTEM) && defined(WOLFSSL_SSLKEYLOGFILE)
8138
#ifndef WOLFSSL_SSLKEYLOGFILE_OUTPUT
8139
    #define WOLFSSL_SSLKEYLOGFILE_OUTPUT "sslkeylog.log"
8140
#endif
8141
#endif
8142
8143
#if defined(WOLFSSL_TLS13) && !defined(NO_PSK)
8144
WOLFSSL_LOCAL int FindPskSuite(const WOLFSSL* ssl, PreSharedKey* psk,
8145
        byte* psk_key, word32* psk_keySz, const byte* suite, int* found,
8146
        byte* foundSuite);
8147
#endif
8148
8149
WOLFSSL_LOCAL int wolfSSL_GetHmacType_ex(CipherSpecs* specs);
8150
8151
#if defined(WOLFSSL_SEND_HRR_COOKIE) && !defined(NO_WOLFSSL_SERVER)
8152
WOLFSSL_LOCAL int CreateCookieExt(const WOLFSSL* ssl, byte* hash,
8153
                                  word16 hashSz, TLSX** exts,
8154
                                  byte cipherSuite0, byte cipherSuite);
8155
#endif
8156
8157
WOLFSSL_LOCAL int TranslateErrorToAlert(int err);
8158
8159
#if defined(OPENSSL_EXTRA) || defined(WOLFSSL_WPAS_SMALL)
8160
WOLFSSL_LOCAL void* wolfssl_sk_pop_type(WOLFSSL_STACK* sk,
8161
                                        WOLF_STACK_TYPE type);
8162
WOLFSSL_LOCAL void* wolfSSL_sk_pop_node(WOLFSSL_STACK* sk, int idx);
8163
WOLFSSL_LOCAL WOLFSSL_STACK* wolfssl_sk_new_type(WOLF_STACK_TYPE type);
8164
WOLFSSL_LOCAL WOLFSSL_STACK* wolfssl_sk_new_type_ex(WOLF_STACK_TYPE type,
8165
        void* heap);
8166
8167
WOLFSSL_LOCAL int wolfssl_asn1_obj_set(WOLFSSL_ASN1_OBJECT* obj,
8168
        const byte* der, word32 len, int addHdr);
8169
#endif
8170
8171
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_EXTRA_X509_SMALL)
8172
WOLFSSL_LOCAL int pkcs8_encode(WOLFSSL_EVP_PKEY* pkey, byte* key,
8173
        word32* keySz);
8174
WOLFSSL_LOCAL int pkcs8_encrypt(WOLFSSL_EVP_PKEY* pkey,
8175
        const WOLFSSL_EVP_CIPHER* enc, char* passwd, int passwdSz, byte* key,
8176
        word32* keySz);
8177
#endif /* OPENSSL_EXTRA || OPENSSL_EXTRA_X509_SMALL */
8178
8179
#if (defined(OPENSSL_EXTRA) || defined(OPENSSL_ALL)) && !defined(NO_BIO)
8180
WOLFSSL_LOCAL int wolfSSL_PEM_X509_X509_CRL_X509_PKEY_read_bio(
8181
        WOLFSSL_BIO* bio, wc_pem_password_cb* cb, WOLFSSL_X509** x509,
8182
        WOLFSSL_X509_CRL** crl, WOLFSSL_X509_PKEY** x_pkey);
8183
#endif
8184
#if defined(OPENSSL_EXTRA) || defined(OPENSSL_ALL)
8185
WOLFSSL_LOCAL void wolfSSL_X509_PKEY_free(WOLFSSL_X509_PKEY* xPkey);
8186
#endif
8187
8188
WOLFSSL_LOCAL void wolfssl_local_MaybeCheckAlertOnErr(WOLFSSL* ssl, int err);
8189
8190
#ifdef __cplusplus
8191
    }  /* extern "C" */
8192
#endif
8193
8194
#endif /* wolfSSL_INT_H */