Coverage Report

Created: 2026-09-20 06:33

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wolfssl-sp-math-all/src/keys.c
Line
Count
Source
1
/* keys.c
2
 *
3
 * Copyright (C) 2006-2026 wolfSSL Inc.
4
 *
5
 * This file is part of wolfSSL.
6
 *
7
 * wolfSSL is free software; you can redistribute it and/or modify
8
 * it under the terms of the GNU General Public License as published by
9
 * the Free Software Foundation; either version 3 of the License, or
10
 * (at your option) any later version.
11
 *
12
 * wolfSSL is distributed in the hope that it will be useful,
13
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
15
 * GNU General Public License for more details.
16
 *
17
 * You should have received a copy of the GNU General Public License
18
 * along with this program; if not, write to the Free Software
19
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335, USA
20
 */
21
22
23
/* Name change compatibility layer no longer needs to be included here */
24
25
#include <wolfssl/wolfcrypt/libwolfssl_sources.h>
26
27
#if !defined(WOLFCRYPT_ONLY) && !defined(NO_TLS)
28
29
#include <wolfssl/internal.h>
30
#include <wolfssl/error-ssl.h>
31
#if defined(SHOW_SECRETS) || defined(CHACHA_AEAD_TEST)
32
    #ifndef NO_STDIO_FILESYSTEM
33
        #include <stdio.h>
34
    #endif
35
#endif
36
#ifdef NO_INLINE
37
    #include <wolfssl/wolfcrypt/misc.h>
38
#else
39
    #define WOLFSSL_MISC_INCLUDED
40
    #include <wolfcrypt/src/misc.c>
41
#endif
42
43
#if defined(WOLFSSL_RENESAS_FSPSM_TLS) || defined(WOLFSSL_RENESAS_TSIP_TLS)
44
#include <wolfssl/wolfcrypt/port/Renesas/renesas_cmn.h>
45
#endif
46
47
int SetCipherSpecs(WOLFSSL* ssl)
48
0
{
49
0
    int ret = GetCipherSpec(ssl->options.side, ssl->options.cipherSuite0,
50
0
                                ssl->options.cipherSuite, &ssl->specs,
51
0
                                &ssl->options);
52
0
    if (ret == 0) {
53
    #ifdef WOLFSSL_ALLOW_SSLV3
54
         /* SSLv3 (RFC 6101) defines MAC algorithms as MD5 and SHA-1. SHA-256
55
          * was introduced in TLS 1.2 (RFC 5246). SSL_hmac for old SSLv3
56
          * connections can not handle newer cipher suites that use digest sizes
57
          * larger than SHA-1 */
58
        if (ssl->version.major == SSLv3_MAJOR &&
59
                    ssl->version.minor == SSLv3_MINOR &&
60
                    ssl->specs.hash_size > WC_SHA_DIGEST_SIZE) {
61
                WOLFSSL_MSG("SSLv3 does not support SHA-256 or higher MAC");
62
                WOLFSSL_ERROR_VERBOSE(UNSUPPORTED_SUITE);
63
                return UNSUPPORTED_SUITE;
64
        }
65
    #endif /* WOLFSSL_ALLOW_SSLV3 */
66
67
        /* set TLS if it hasn't been turned off */
68
0
        if (ssl->version.major == SSLv3_MAJOR &&
69
0
                ssl->version.minor >= TLSv1_MINOR) {
70
0
    #ifndef NO_TLS
71
0
            ssl->options.tls = 1;
72
0
        #if !defined(WOLFSSL_NO_TLS12) && !defined(WOLFSSL_AEAD_ONLY)
73
0
            #if !defined(WOLFSSL_RENESAS_FSPSM_TLS) && \
74
0
                !defined(WOLFSSL_RENESAS_TSIP_TLS)
75
0
            ssl->hmac = TLS_hmac;
76
            #else
77
            ssl->hmac = Renesas_cmn_TLS_hmac;
78
            #endif
79
0
        #endif
80
0
            if (ssl->version.minor >= TLSv1_1_MINOR) {
81
0
                ssl->options.tls1_1 = 1;
82
0
                if (ssl->version.minor >= TLSv1_3_MINOR)
83
0
                    ssl->options.tls1_3 = 1;
84
0
            }
85
0
    #endif
86
0
        }
87
88
0
    #if defined(HAVE_ENCRYPT_THEN_MAC) && !defined(WOLFSSL_AEAD_ONLY)
89
0
        if (IsAtLeastTLSv1_3(ssl->version) || ssl->specs.cipher_type != block)
90
0
           ssl->options.encThenMac = 0;
91
0
    #endif
92
93
    #ifdef HAVE_LIBZ
94
        /* TLS 1.3 removed record layer compression (RFC 8446 5.2).  A client
95
         * that asked for it may still land on 1.3, so drop the request rather
96
         * than compress records the peer will not decompress. */
97
        if (IsAtLeastTLSv1_3(ssl->version))
98
            ssl->options.usingCompression = 0;
99
    #endif
100
101
    #if defined(WOLFSSL_DTLS)
102
        if (ssl->options.dtls && ssl->version.major == DTLS_MAJOR) {
103
        #ifndef WOLFSSL_AEAD_ONLY
104
            #if !defined(WOLFSSL_RENESAS_FSPSM_TLS) && \
105
                !defined(WOLFSSL_RENESAS_TSIP_TLS)
106
            ssl->hmac = TLS_hmac;
107
            #else
108
            ssl->hmac = Renesas_cmn_TLS_hmac;
109
            #endif
110
        #endif
111
            ssl->options.tls = 1;
112
            ssl->options.tls1_1 = 1; /* DTLS 1.0 == TLS 1.1 */
113
        #ifdef WOLFSSL_DTLS13
114
            if (ssl->version.minor <= DTLSv1_3_MINOR)
115
                ssl->options.tls1_3 = 1;
116
        #endif
117
        }
118
    #endif
119
0
    }
120
0
    return ret;
121
0
}
122
123
/**
124
 * Populate specs with the specification of the chosen ciphersuite. If opts is
125
 * not NULL then the appropriate options will also be set.
126
 *
127
 * @param side         [in] WOLFSSL_SERVER_END or WOLFSSL_CLIENT_END
128
 * @param cipherSuite0 [in]
129
 * @param cipherSuite  [in]
130
 * @param specs        [out] CipherSpecs
131
 * @param opts         [in/out] Options can be NULL
132
 * @return int (less than 0 on fail, 0 on success)
133
 */
134
int GetCipherSpec(word16 side, byte cipherSuite0, byte cipherSuite,
135
                      CipherSpecs* specs, Options* opts)
136
0
{
137
0
    word16 havePSK = 0;
138
0
    (void)havePSK;
139
0
    (void)side;
140
#if defined(HAVE_SESSION_TICKET) || !defined(NO_PSK)
141
    if (opts != NULL)
142
        havePSK = opts->havePSK;
143
#endif
144
0
#ifndef NO_WOLFSSL_CLIENT
145
0
    if (side == WOLFSSL_CLIENT_END) {
146
        /* server side verified before SetCipherSpecs call */
147
0
        if (VerifyClientSuite(havePSK, cipherSuite0, cipherSuite) != 1) {
148
0
            WOLFSSL_MSG("SetCipherSpecs() client has an unusable suite");
149
0
            WOLFSSL_ERROR_VERBOSE(UNSUPPORTED_SUITE);
150
0
            return UNSUPPORTED_SUITE;
151
0
        }
152
0
    }
153
0
#endif /* NO_WOLFSSL_CLIENT */
154
155
    /* Initialize specs */
156
0
    XMEMSET(specs, 0, sizeof(CipherSpecs));
157
158
    /* Chacha extensions, 0xcc */
159
0
    if (cipherSuite0 == CHACHA_BYTE) {
160
161
0
    switch (cipherSuite) {
162
0
#ifdef BUILD_TLS_ECDHE_RSA_WITH_CHACHA20_OLD_POLY1305_SHA256
163
0
    case TLS_ECDHE_RSA_WITH_CHACHA20_OLD_POLY1305_SHA256:
164
0
        specs->bulk_cipher_algorithm = wolfssl_chacha;
165
0
        specs->cipher_type           = aead;
166
0
        specs->mac_algorithm         = sha256_mac;
167
0
        specs->kea                   = ecc_diffie_hellman_kea;
168
0
        specs->sig_algo              = rsa_sa_algo;
169
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
170
0
        specs->pad_size              = PAD_SHA;
171
0
        specs->static_ecdh           = 0;
172
0
        specs->key_size              = CHACHA20_256_KEY_SIZE;
173
0
        specs->block_size            = CHACHA20_BLOCK_SIZE;
174
0
        specs->iv_size               = CHACHA20_IV_SIZE;
175
0
        specs->aead_mac_size         = POLY1305_AUTH_SZ;
176
0
        if (opts != NULL)
177
0
            opts->oldPoly            = 1; /* use old poly1305 padding */
178
179
0
        break;
180
0
#endif
181
182
0
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_CHACHA20_OLD_POLY1305_SHA256
183
0
    case TLS_ECDHE_ECDSA_WITH_CHACHA20_OLD_POLY1305_SHA256:
184
0
        specs->bulk_cipher_algorithm = wolfssl_chacha;
185
0
        specs->cipher_type           = aead;
186
0
        specs->mac_algorithm         = sha256_mac;
187
0
        specs->kea                   = ecc_diffie_hellman_kea;
188
0
        specs->sig_algo              = ecc_dsa_sa_algo;
189
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
190
0
        specs->pad_size              = PAD_SHA;
191
0
        specs->static_ecdh           = 0;
192
0
        specs->key_size              = CHACHA20_256_KEY_SIZE;
193
0
        specs->block_size            = CHACHA20_BLOCK_SIZE;
194
0
        specs->iv_size               = CHACHA20_IV_SIZE;
195
0
        specs->aead_mac_size         = POLY1305_AUTH_SZ;
196
0
        if (opts != NULL)
197
0
            opts->oldPoly            = 1; /* use old poly1305 padding */
198
199
0
        break;
200
0
#endif
201
202
0
#ifdef BUILD_TLS_DHE_RSA_WITH_CHACHA20_OLD_POLY1305_SHA256
203
0
    case TLS_DHE_RSA_WITH_CHACHA20_OLD_POLY1305_SHA256:
204
0
        specs->bulk_cipher_algorithm = wolfssl_chacha;
205
0
        specs->cipher_type           = aead;
206
0
        specs->mac_algorithm         = sha256_mac;
207
0
        specs->kea                   = diffie_hellman_kea;
208
0
        specs->sig_algo              = rsa_sa_algo;
209
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
210
0
        specs->pad_size              = PAD_SHA;
211
0
        specs->static_ecdh           = 0;
212
0
        specs->key_size              = CHACHA20_256_KEY_SIZE;
213
0
        specs->block_size            = CHACHA20_BLOCK_SIZE;
214
0
        specs->iv_size               = CHACHA20_IV_SIZE;
215
0
        specs->aead_mac_size         = POLY1305_AUTH_SZ;
216
0
        if (opts != NULL)
217
0
            opts->oldPoly            = 1; /* use old poly1305 padding */
218
219
0
        break;
220
0
#endif
221
0
#ifdef BUILD_TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
222
0
    case TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256:
223
0
        specs->bulk_cipher_algorithm = wolfssl_chacha;
224
0
        specs->cipher_type           = aead;
225
0
        specs->mac_algorithm         = sha256_mac;
226
0
        specs->kea                   = ecc_diffie_hellman_kea;
227
0
        specs->sig_algo              = rsa_sa_algo;
228
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
229
0
        specs->pad_size              = PAD_SHA;
230
0
        specs->static_ecdh           = 0;
231
0
        specs->key_size              = CHACHA20_256_KEY_SIZE;
232
0
        specs->block_size            = CHACHA20_BLOCK_SIZE;
233
0
        specs->iv_size               = CHACHA20_IV_SIZE;
234
0
        specs->aead_mac_size         = POLY1305_AUTH_SZ;
235
0
        if (opts != NULL)
236
0
            opts->oldPoly            = 0; /* use recent padding RFC */
237
238
0
        break;
239
0
#endif
240
241
0
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256
242
0
    case TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256:
243
0
        specs->bulk_cipher_algorithm = wolfssl_chacha;
244
0
        specs->cipher_type           = aead;
245
0
        specs->mac_algorithm         = sha256_mac;
246
0
        specs->kea                   = ecc_diffie_hellman_kea;
247
0
        specs->sig_algo              = ecc_dsa_sa_algo;
248
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
249
0
        specs->pad_size              = PAD_SHA;
250
0
        specs->static_ecdh           = 0;
251
0
        specs->key_size              = CHACHA20_256_KEY_SIZE;
252
0
        specs->block_size            = CHACHA20_BLOCK_SIZE;
253
0
        specs->iv_size               = CHACHA20_IV_SIZE;
254
0
        specs->aead_mac_size         = POLY1305_AUTH_SZ;
255
0
        if (opts != NULL)
256
0
            opts->oldPoly            = 0; /* use recent padding RFC */
257
258
0
        break;
259
0
#endif
260
261
0
#ifdef BUILD_TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256
262
0
    case TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256:
263
0
        specs->bulk_cipher_algorithm = wolfssl_chacha;
264
0
        specs->cipher_type           = aead;
265
0
        specs->mac_algorithm         = sha256_mac;
266
0
        specs->kea                   = diffie_hellman_kea;
267
0
        specs->sig_algo              = rsa_sa_algo;
268
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
269
0
        specs->pad_size              = PAD_SHA;
270
0
        specs->static_ecdh           = 0;
271
0
        specs->key_size              = CHACHA20_256_KEY_SIZE;
272
0
        specs->block_size            = CHACHA20_BLOCK_SIZE;
273
0
        specs->iv_size               = CHACHA20_IV_SIZE;
274
0
        specs->aead_mac_size         = POLY1305_AUTH_SZ;
275
0
        if (opts != NULL)
276
0
            opts->oldPoly            = 0; /* use recent padding RFC */
277
278
0
        break;
279
0
#endif
280
281
#ifdef BUILD_TLS_PSK_WITH_CHACHA20_POLY1305_SHA256
282
    case TLS_PSK_WITH_CHACHA20_POLY1305_SHA256:
283
        specs->bulk_cipher_algorithm = wolfssl_chacha;
284
        specs->cipher_type           = aead;
285
        specs->mac_algorithm         = sha256_mac;
286
        specs->kea                   = psk_kea;
287
        specs->sig_algo              = anonymous_sa_algo;
288
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
289
        specs->pad_size              = PAD_SHA;
290
        specs->static_ecdh           = 0;
291
        specs->key_size              = CHACHA20_256_KEY_SIZE;
292
        specs->block_size            = CHACHA20_BLOCK_SIZE;
293
        specs->iv_size               = CHACHA20_IV_SIZE;
294
        specs->aead_mac_size         = POLY1305_AUTH_SZ;
295
296
        if (opts != NULL) {
297
            opts->oldPoly            = 0; /* use recent padding RFC */
298
            opts->usingPSK_cipher    = 1;
299
        }
300
        break;
301
#endif
302
303
#ifdef BUILD_TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256
304
    case TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256:
305
        specs->bulk_cipher_algorithm = wolfssl_chacha;
306
        specs->cipher_type           = aead;
307
        specs->mac_algorithm         = sha256_mac;
308
        specs->kea                   = ecdhe_psk_kea;
309
        specs->sig_algo              = anonymous_sa_algo;
310
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
311
        specs->pad_size              = PAD_SHA;
312
        specs->static_ecdh           = 0;
313
        specs->key_size              = CHACHA20_256_KEY_SIZE;
314
        specs->block_size            = CHACHA20_BLOCK_SIZE;
315
        specs->iv_size               = CHACHA20_IV_SIZE;
316
        specs->aead_mac_size         = POLY1305_AUTH_SZ;
317
318
        if (opts != NULL) {
319
            opts->oldPoly            = 0; /* use recent padding RFC */
320
            opts->usingPSK_cipher    = 1;
321
        }
322
        break;
323
#endif
324
325
#ifdef BUILD_TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256
326
    case TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256:
327
        specs->bulk_cipher_algorithm = wolfssl_chacha;
328
        specs->cipher_type           = aead;
329
        specs->mac_algorithm         = sha256_mac;
330
        specs->kea                   = dhe_psk_kea;
331
        specs->sig_algo              = anonymous_sa_algo;
332
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
333
        specs->pad_size              = PAD_SHA;
334
        specs->static_ecdh           = 0;
335
        specs->key_size              = CHACHA20_256_KEY_SIZE;
336
        specs->block_size            = CHACHA20_BLOCK_SIZE;
337
        specs->iv_size               = CHACHA20_IV_SIZE;
338
        specs->aead_mac_size         = POLY1305_AUTH_SZ;
339
340
        if (opts != NULL) {
341
            opts->oldPoly            = 0; /* use recent padding RFC */
342
            opts->usingPSK_cipher    = 1;
343
        }
344
        break;
345
#endif
346
0
    default:
347
0
        WOLFSSL_MSG("Unsupported cipher suite, SetCipherSpecs ChaCha");
348
0
        return UNSUPPORTED_SUITE;
349
0
    }
350
0
    }
351
352
    /* ECC extensions, AES-CCM or TLS 1.3 Integrity-only */
353
0
    if (cipherSuite0 == ECC_BYTE) {
354
355
0
    switch (cipherSuite) {
356
357
0
#if defined(HAVE_ECC) || defined(HAVE_CURVE25519) || defined(HAVE_CURVE448)
358
359
0
#ifdef BUILD_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
360
0
    case TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 :
361
0
        specs->bulk_cipher_algorithm = wolfssl_aes;
362
0
        specs->cipher_type           = block;
363
0
        specs->mac_algorithm         = sha256_mac;
364
0
        specs->kea                   = ecc_diffie_hellman_kea;
365
0
        specs->sig_algo              = rsa_sa_algo;
366
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
367
0
        specs->pad_size              = PAD_SHA;
368
0
        specs->static_ecdh           = 0;
369
0
        specs->key_size              = AES_128_KEY_SIZE;
370
0
        specs->iv_size               = AES_IV_SIZE;
371
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
372
373
0
        break;
374
0
#endif
375
376
0
#ifdef BUILD_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
377
0
    case TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 :
378
0
        specs->bulk_cipher_algorithm = wolfssl_aes;
379
0
        specs->cipher_type           = block;
380
0
        specs->mac_algorithm         = sha384_mac;
381
0
        specs->kea                   = ecc_diffie_hellman_kea;
382
0
        specs->sig_algo              = rsa_sa_algo;
383
0
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
384
0
        specs->pad_size              = PAD_SHA;
385
0
        specs->static_ecdh           = 0;
386
0
        specs->key_size              = AES_256_KEY_SIZE;
387
0
        specs->iv_size               = AES_IV_SIZE;
388
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
389
390
0
        break;
391
0
#endif
392
393
0
#ifdef BUILD_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
394
0
    case TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA :
395
0
        specs->bulk_cipher_algorithm = wolfssl_aes;
396
0
        specs->cipher_type           = block;
397
0
        specs->mac_algorithm         = sha_mac;
398
0
        specs->kea                   = ecc_diffie_hellman_kea;
399
0
        specs->sig_algo              = rsa_sa_algo;
400
0
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
401
0
        specs->pad_size              = PAD_SHA;
402
0
        specs->static_ecdh           = 0;
403
0
        specs->key_size              = AES_128_KEY_SIZE;
404
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
405
0
        specs->iv_size               = AES_IV_SIZE;
406
407
0
        break;
408
0
#endif
409
410
#ifdef BUILD_TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA
411
    case TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA :
412
        specs->bulk_cipher_algorithm = wolfssl_triple_des;
413
        specs->cipher_type           = block;
414
        specs->mac_algorithm         = sha_mac;
415
        specs->kea                   = ecc_diffie_hellman_kea;
416
        specs->sig_algo              = rsa_sa_algo;
417
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
418
        specs->pad_size              = PAD_SHA;
419
        specs->static_ecdh           = 0;
420
        specs->key_size              = DES3_KEY_SIZE;
421
        specs->block_size            = DES_BLOCK_SIZE;
422
/* DES_IV_SIZE is incorrectly 16 in FIPS v2. It should be 8, same as the
423
 * block size. */
424
#if defined(HAVE_FIPS) && defined(HAVE_FIPS_VERSION) && (HAVE_FIPS_VERSION == 2)
425
        specs->iv_size               = DES_BLOCK_SIZE;
426
#else
427
        specs->iv_size               = DES_IV_SIZE;
428
#endif
429
430
        break;
431
#endif
432
433
0
#ifdef BUILD_TLS_ECDHE_RSA_WITH_RC4_128_SHA
434
0
    case TLS_ECDHE_RSA_WITH_RC4_128_SHA :
435
0
        specs->bulk_cipher_algorithm = wolfssl_rc4;
436
0
        specs->cipher_type           = stream;
437
0
        specs->mac_algorithm         = sha_mac;
438
0
        specs->kea                   = ecc_diffie_hellman_kea;
439
0
        specs->sig_algo              = rsa_sa_algo;
440
0
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
441
0
        specs->pad_size              = PAD_SHA;
442
0
        specs->static_ecdh           = 0;
443
0
        specs->key_size              = RC4_KEY_SIZE;
444
0
        specs->iv_size               = 0;
445
0
        specs->block_size            = 0;
446
447
0
        break;
448
0
#endif
449
450
0
#ifdef BUILD_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
451
0
    case TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA :
452
0
        specs->bulk_cipher_algorithm = wolfssl_aes;
453
0
        specs->cipher_type           = block;
454
0
        specs->mac_algorithm         = sha_mac;
455
0
        specs->kea                   = ecc_diffie_hellman_kea;
456
0
        specs->sig_algo              = rsa_sa_algo;
457
0
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
458
0
        specs->pad_size              = PAD_SHA;
459
0
        specs->static_ecdh           = 0;
460
0
        specs->key_size              = AES_256_KEY_SIZE;
461
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
462
0
        specs->iv_size               = AES_IV_SIZE;
463
464
0
        break;
465
0
#endif
466
467
0
#ifdef BUILD_TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
468
0
    case TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 :
469
0
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
470
0
        specs->cipher_type           = aead;
471
0
        specs->mac_algorithm         = sha256_mac;
472
0
        specs->kea                   = ecc_diffie_hellman_kea;
473
0
        specs->sig_algo              = rsa_sa_algo;
474
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
475
0
        specs->pad_size              = PAD_SHA;
476
0
        specs->static_ecdh           = 0;
477
0
        specs->key_size              = AES_128_KEY_SIZE;
478
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
479
0
        specs->iv_size               = AESGCM_IMP_IV_SZ;
480
0
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
481
482
0
        break;
483
0
#endif
484
485
0
#ifdef BUILD_TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
486
0
    case TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 :
487
0
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
488
0
        specs->cipher_type           = aead;
489
0
        specs->mac_algorithm         = sha384_mac;
490
0
        specs->kea                   = ecc_diffie_hellman_kea;
491
0
        specs->sig_algo              = rsa_sa_algo;
492
0
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
493
0
        specs->pad_size              = PAD_SHA;
494
0
        specs->static_ecdh           = 0;
495
0
        specs->key_size              = AES_256_KEY_SIZE;
496
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
497
0
        specs->iv_size               = AESGCM_IMP_IV_SZ;
498
0
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
499
500
0
        break;
501
0
#endif
502
503
#ifdef BUILD_TLS_ECDHE_PSK_WITH_NULL_SHA256
504
    case TLS_ECDHE_PSK_WITH_NULL_SHA256 :
505
        specs->bulk_cipher_algorithm = wolfssl_cipher_null;
506
        specs->cipher_type           = stream;
507
        specs->mac_algorithm         = sha256_mac;
508
        specs->kea                   = ecdhe_psk_kea;
509
        specs->sig_algo              = anonymous_sa_algo;
510
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
511
        specs->pad_size              = PAD_SHA;
512
        specs->static_ecdh           = 0;
513
        specs->key_size              = 0;
514
        specs->block_size            = 0;
515
        specs->iv_size               = 0;
516
517
        if (opts != NULL)
518
            opts->usingPSK_cipher    = 1;
519
        break;
520
#endif
521
522
#ifdef BUILD_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256
523
    case TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256 :
524
        specs->bulk_cipher_algorithm = wolfssl_aes;
525
        specs->cipher_type           = block;
526
        specs->mac_algorithm         = sha256_mac;
527
        specs->kea                   = ecdhe_psk_kea;
528
        specs->sig_algo              = anonymous_sa_algo;
529
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
530
        specs->pad_size              = PAD_SHA;
531
        specs->static_ecdh           = 0;
532
        specs->key_size              = AES_128_KEY_SIZE;
533
        specs->block_size            = WC_AES_BLOCK_SIZE;
534
        specs->iv_size               = AES_IV_SIZE;
535
536
        if (opts != NULL)
537
            opts->usingPSK_cipher    = 1;
538
        break;
539
#endif
540
541
0
#endif /* HAVE_ECC || HAVE_CURVE25519 || HAVE_CURVE448 */
542
543
0
#if defined(HAVE_ECC) || (defined(HAVE_CURVE25519) && defined(HAVE_ED25519)) \
544
0
                      || (defined(HAVE_CURVE448) && defined(HAVE_ED448))
545
546
0
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256
547
0
    case TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 :
548
0
        specs->bulk_cipher_algorithm = wolfssl_aes;
549
0
        specs->cipher_type           = block;
550
0
        specs->mac_algorithm         = sha256_mac;
551
0
        specs->kea                   = ecc_diffie_hellman_kea;
552
0
        specs->sig_algo              = ecc_dsa_sa_algo;
553
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
554
0
        specs->pad_size              = PAD_SHA;
555
0
        specs->static_ecdh           = 0;
556
0
        specs->key_size              = AES_128_KEY_SIZE;
557
0
        specs->iv_size               = AES_IV_SIZE;
558
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
559
560
0
        break;
561
0
#endif
562
563
0
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384
564
0
    case TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 :
565
0
        specs->bulk_cipher_algorithm = wolfssl_aes;
566
0
        specs->cipher_type           = block;
567
0
        specs->mac_algorithm         = sha384_mac;
568
0
        specs->kea                   = ecc_diffie_hellman_kea;
569
0
        specs->sig_algo              = ecc_dsa_sa_algo;
570
0
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
571
0
        specs->pad_size              = PAD_SHA;
572
0
        specs->static_ecdh           = 0;
573
0
        specs->key_size              = AES_256_KEY_SIZE;
574
0
        specs->iv_size               = AES_IV_SIZE;
575
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
576
577
0
        break;
578
0
#endif
579
580
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA
581
    case TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA :
582
        specs->bulk_cipher_algorithm = wolfssl_triple_des;
583
        specs->cipher_type           = block;
584
        specs->mac_algorithm         = sha_mac;
585
        specs->kea                   = ecc_diffie_hellman_kea;
586
        specs->sig_algo              = ecc_dsa_sa_algo;
587
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
588
        specs->pad_size              = PAD_SHA;
589
        specs->static_ecdh           = 0;
590
        specs->key_size              = DES3_KEY_SIZE;
591
        specs->block_size            = DES_BLOCK_SIZE;
592
#if defined(HAVE_FIPS) && defined(HAVE_FIPS_VERSION) && (HAVE_FIPS_VERSION == 2)
593
        specs->iv_size               = DES_BLOCK_SIZE;
594
#else
595
        specs->iv_size               = DES_IV_SIZE;
596
#endif
597
598
        break;
599
#endif
600
601
0
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_RC4_128_SHA
602
0
    case TLS_ECDHE_ECDSA_WITH_RC4_128_SHA :
603
0
        specs->bulk_cipher_algorithm = wolfssl_rc4;
604
0
        specs->cipher_type           = stream;
605
0
        specs->mac_algorithm         = sha_mac;
606
0
        specs->kea                   = ecc_diffie_hellman_kea;
607
0
        specs->sig_algo              = ecc_dsa_sa_algo;
608
0
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
609
0
        specs->pad_size              = PAD_SHA;
610
0
        specs->static_ecdh           = 0;
611
0
        specs->key_size              = RC4_KEY_SIZE;
612
0
        specs->iv_size               = 0;
613
0
        specs->block_size            = 0;
614
615
0
        break;
616
0
#endif
617
618
0
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
619
0
    case TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA :
620
0
        specs->bulk_cipher_algorithm = wolfssl_aes;
621
0
        specs->cipher_type           = block;
622
0
        specs->mac_algorithm         = sha_mac;
623
0
        specs->kea                   = ecc_diffie_hellman_kea;
624
0
        specs->sig_algo              = ecc_dsa_sa_algo;
625
0
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
626
0
        specs->pad_size              = PAD_SHA;
627
0
        specs->static_ecdh           = 0;
628
0
        specs->key_size              = AES_128_KEY_SIZE;
629
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
630
0
        specs->iv_size               = AES_IV_SIZE;
631
632
0
        break;
633
0
#endif
634
635
0
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
636
0
    case TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA :
637
0
        specs->bulk_cipher_algorithm = wolfssl_aes;
638
0
        specs->cipher_type           = block;
639
0
        specs->mac_algorithm         = sha_mac;
640
0
        specs->kea                   = ecc_diffie_hellman_kea;
641
0
        specs->sig_algo              = ecc_dsa_sa_algo;
642
0
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
643
0
        specs->pad_size              = PAD_SHA;
644
0
        specs->static_ecdh           = 0;
645
0
        specs->key_size              = AES_256_KEY_SIZE;
646
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
647
0
        specs->iv_size               = AES_IV_SIZE;
648
649
0
        break;
650
0
#endif
651
652
0
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
653
0
    case TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 :
654
0
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
655
0
        specs->cipher_type           = aead;
656
0
        specs->mac_algorithm         = sha256_mac;
657
0
        specs->kea                   = ecc_diffie_hellman_kea;
658
0
        specs->sig_algo              = ecc_dsa_sa_algo;
659
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
660
0
        specs->pad_size              = PAD_SHA;
661
0
        specs->static_ecdh           = 0;
662
0
        specs->key_size              = AES_128_KEY_SIZE;
663
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
664
0
        specs->iv_size               = AESGCM_IMP_IV_SZ;
665
0
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
666
667
0
        break;
668
0
#endif
669
670
0
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
671
0
    case TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 :
672
0
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
673
0
        specs->cipher_type           = aead;
674
0
        specs->mac_algorithm         = sha384_mac;
675
0
        specs->kea                   = ecc_diffie_hellman_kea;
676
0
        specs->sig_algo              = ecc_dsa_sa_algo;
677
0
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
678
0
        specs->pad_size              = PAD_SHA;
679
0
        specs->static_ecdh           = 0;
680
0
        specs->key_size              = AES_256_KEY_SIZE;
681
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
682
0
        specs->iv_size               = AESGCM_IMP_IV_SZ;
683
0
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
684
685
0
        break;
686
0
#endif
687
688
0
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CCM
689
0
    case TLS_ECDHE_ECDSA_WITH_AES_128_CCM :
690
0
        specs->bulk_cipher_algorithm = wolfssl_aes_ccm;
691
0
        specs->cipher_type           = aead;
692
0
        specs->mac_algorithm         = sha256_mac;
693
0
        specs->kea                   = ecc_diffie_hellman_kea;
694
0
        specs->sig_algo              = ecc_dsa_sa_algo;
695
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
696
0
        specs->pad_size              = PAD_SHA;
697
0
        specs->static_ecdh           = 0;
698
0
        specs->key_size              = AES_128_KEY_SIZE;
699
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
700
0
        specs->iv_size               = AESCCM_IMP_IV_SZ;
701
0
        specs->aead_mac_size         = AES_CCM_16_AUTH_SZ;
702
703
0
        break;
704
0
#endif
705
706
0
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8
707
0
    case TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8 :
708
0
        specs->bulk_cipher_algorithm = wolfssl_aes_ccm;
709
0
        specs->cipher_type           = aead;
710
0
        specs->mac_algorithm         = sha256_mac;
711
0
        specs->kea                   = ecc_diffie_hellman_kea;
712
0
        specs->sig_algo              = ecc_dsa_sa_algo;
713
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
714
0
        specs->pad_size              = PAD_SHA;
715
0
        specs->static_ecdh           = 0;
716
0
        specs->key_size              = AES_128_KEY_SIZE;
717
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
718
0
        specs->iv_size               = AESCCM_IMP_IV_SZ;
719
0
        specs->aead_mac_size         = AES_CCM_8_AUTH_SZ;
720
721
0
        break;
722
0
#endif
723
724
0
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8
725
0
    case TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8 :
726
0
        specs->bulk_cipher_algorithm = wolfssl_aes_ccm;
727
0
        specs->cipher_type           = aead;
728
0
        specs->mac_algorithm         = sha256_mac;
729
0
        specs->kea                   = ecc_diffie_hellman_kea;
730
0
        specs->sig_algo              = ecc_dsa_sa_algo;
731
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
732
0
        specs->pad_size              = PAD_SHA;
733
0
        specs->static_ecdh           = 0;
734
0
        specs->key_size              = AES_256_KEY_SIZE;
735
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
736
0
        specs->iv_size               = AESCCM_IMP_IV_SZ;
737
0
        specs->aead_mac_size         = AES_CCM_8_AUTH_SZ;
738
739
0
        break;
740
0
#endif
741
742
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_NULL_SHA
743
    case TLS_ECDHE_ECDSA_WITH_NULL_SHA :
744
        specs->bulk_cipher_algorithm = wolfssl_cipher_null;
745
        specs->cipher_type           = stream;
746
        specs->mac_algorithm         = sha_mac;
747
        specs->kea                   = ecc_diffie_hellman_kea;
748
        specs->sig_algo              = ecc_dsa_sa_algo;
749
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
750
        specs->pad_size              = PAD_SHA;
751
        specs->static_ecdh           = 0;
752
        specs->key_size              = 0;
753
        specs->block_size            = 0;
754
        specs->iv_size               = 0;
755
756
    break;
757
#endif
758
759
0
#endif /* HAVE_ECC || (CURVE25519 && ED25519) || (CURVE448 && ED448) */
760
761
0
#if defined(HAVE_ECC)
762
763
#ifdef BUILD_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256
764
    case TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256 :
765
        specs->bulk_cipher_algorithm = wolfssl_aes;
766
        specs->cipher_type           = block;
767
        specs->mac_algorithm         = sha256_mac;
768
        specs->kea                   = ecc_diffie_hellman_kea;
769
        specs->sig_algo              = rsa_sa_algo;
770
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
771
        specs->pad_size              = PAD_SHA;
772
        specs->static_ecdh           = 1;
773
        specs->key_size              = AES_128_KEY_SIZE;
774
        specs->iv_size               = AES_IV_SIZE;
775
        specs->block_size            = WC_AES_BLOCK_SIZE;
776
777
        break;
778
#endif
779
780
#ifdef BUILD_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256
781
    case TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256 :
782
        specs->bulk_cipher_algorithm = wolfssl_aes;
783
        specs->cipher_type           = block;
784
        specs->mac_algorithm         = sha256_mac;
785
        specs->kea                   = ecc_diffie_hellman_kea;
786
        specs->sig_algo              = ecc_dsa_sa_algo;
787
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
788
        specs->pad_size              = PAD_SHA;
789
        specs->static_ecdh           = 1;
790
        specs->key_size              = AES_128_KEY_SIZE;
791
        specs->iv_size               = AES_IV_SIZE;
792
        specs->block_size            = WC_AES_BLOCK_SIZE;
793
794
        break;
795
#endif
796
797
#ifdef BUILD_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384
798
    case TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384 :
799
        specs->bulk_cipher_algorithm = wolfssl_aes;
800
        specs->cipher_type           = block;
801
        specs->mac_algorithm         = sha384_mac;
802
        specs->kea                   = ecc_diffie_hellman_kea;
803
        specs->sig_algo              = rsa_sa_algo;
804
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
805
        specs->pad_size              = PAD_SHA;
806
        specs->static_ecdh           = 1;
807
        specs->key_size              = AES_256_KEY_SIZE;
808
        specs->iv_size               = AES_IV_SIZE;
809
        specs->block_size            = WC_AES_BLOCK_SIZE;
810
811
        break;
812
#endif
813
814
#ifdef BUILD_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384
815
    case TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384 :
816
        specs->bulk_cipher_algorithm = wolfssl_aes;
817
        specs->cipher_type           = block;
818
        specs->mac_algorithm         = sha384_mac;
819
        specs->kea                   = ecc_diffie_hellman_kea;
820
        specs->sig_algo              = ecc_dsa_sa_algo;
821
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
822
        specs->pad_size              = PAD_SHA;
823
        specs->static_ecdh           = 1;
824
        specs->key_size              = AES_256_KEY_SIZE;
825
        specs->iv_size               = AES_IV_SIZE;
826
        specs->block_size            = WC_AES_BLOCK_SIZE;
827
828
        break;
829
#endif
830
831
#ifdef BUILD_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA
832
    case TLS_ECDH_RSA_WITH_AES_128_CBC_SHA :
833
        specs->bulk_cipher_algorithm = wolfssl_aes;
834
        specs->cipher_type           = block;
835
        specs->mac_algorithm         = sha_mac;
836
        specs->kea                   = ecc_diffie_hellman_kea;
837
        specs->sig_algo              = rsa_sa_algo;
838
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
839
        specs->pad_size              = PAD_SHA;
840
        specs->static_ecdh           = 1;
841
        specs->key_size              = AES_128_KEY_SIZE;
842
        specs->block_size            = WC_AES_BLOCK_SIZE;
843
        specs->iv_size               = AES_IV_SIZE;
844
845
        break;
846
#endif
847
848
#ifdef BUILD_TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA
849
    case TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA :
850
        specs->bulk_cipher_algorithm = wolfssl_triple_des;
851
        specs->cipher_type           = block;
852
        specs->mac_algorithm         = sha_mac;
853
        specs->kea                   = ecc_diffie_hellman_kea;
854
        specs->sig_algo              = rsa_sa_algo;
855
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
856
        specs->pad_size              = PAD_SHA;
857
        specs->static_ecdh           = 1;
858
        specs->key_size              = DES3_KEY_SIZE;
859
        specs->block_size            = DES_BLOCK_SIZE;
860
#if defined(HAVE_FIPS) && defined(HAVE_FIPS_VERSION) && (HAVE_FIPS_VERSION == 2)
861
        specs->iv_size               = DES_BLOCK_SIZE;
862
#else
863
        specs->iv_size               = DES_IV_SIZE;
864
#endif
865
866
        break;
867
#endif
868
869
#ifdef BUILD_TLS_ECDH_RSA_WITH_RC4_128_SHA
870
    case TLS_ECDH_RSA_WITH_RC4_128_SHA :
871
        specs->bulk_cipher_algorithm = wolfssl_rc4;
872
        specs->cipher_type           = stream;
873
        specs->mac_algorithm         = sha_mac;
874
        specs->kea                   = ecc_diffie_hellman_kea;
875
        specs->sig_algo              = rsa_sa_algo;
876
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
877
        specs->pad_size              = PAD_SHA;
878
        specs->static_ecdh           = 1;
879
        specs->key_size              = RC4_KEY_SIZE;
880
        specs->iv_size               = 0;
881
        specs->block_size            = 0;
882
883
        break;
884
#endif
885
886
#ifdef BUILD_TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA
887
    case TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA :
888
        specs->bulk_cipher_algorithm = wolfssl_triple_des;
889
        specs->cipher_type           = block;
890
        specs->mac_algorithm         = sha_mac;
891
        specs->kea                   = ecc_diffie_hellman_kea;
892
        specs->sig_algo              = ecc_dsa_sa_algo;
893
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
894
        specs->pad_size              = PAD_SHA;
895
        specs->static_ecdh           = 1;
896
        specs->key_size              = DES3_KEY_SIZE;
897
        specs->block_size            = DES_BLOCK_SIZE;
898
#if defined(HAVE_FIPS) && defined(HAVE_FIPS_VERSION) && (HAVE_FIPS_VERSION == 2)
899
        specs->iv_size               = DES_BLOCK_SIZE;
900
#else
901
        specs->iv_size               = DES_IV_SIZE;
902
#endif
903
904
        break;
905
#endif
906
907
#ifdef BUILD_TLS_ECDH_ECDSA_WITH_RC4_128_SHA
908
    case TLS_ECDH_ECDSA_WITH_RC4_128_SHA :
909
        specs->bulk_cipher_algorithm = wolfssl_rc4;
910
        specs->cipher_type           = stream;
911
        specs->mac_algorithm         = sha_mac;
912
        specs->kea                   = ecc_diffie_hellman_kea;
913
        specs->sig_algo              = ecc_dsa_sa_algo;
914
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
915
        specs->pad_size              = PAD_SHA;
916
        specs->static_ecdh           = 1;
917
        specs->key_size              = RC4_KEY_SIZE;
918
        specs->iv_size               = 0;
919
        specs->block_size            = 0;
920
921
        break;
922
#endif
923
924
#ifdef BUILD_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA
925
    case TLS_ECDH_RSA_WITH_AES_256_CBC_SHA :
926
        specs->bulk_cipher_algorithm = wolfssl_aes;
927
        specs->cipher_type           = block;
928
        specs->mac_algorithm         = sha_mac;
929
        specs->kea                   = ecc_diffie_hellman_kea;
930
        specs->sig_algo              = rsa_sa_algo;
931
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
932
        specs->pad_size              = PAD_SHA;
933
        specs->static_ecdh           = 1;
934
        specs->key_size              = AES_256_KEY_SIZE;
935
        specs->block_size            = WC_AES_BLOCK_SIZE;
936
        specs->iv_size               = AES_IV_SIZE;
937
938
        break;
939
#endif
940
941
#ifdef BUILD_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA
942
    case TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA :
943
        specs->bulk_cipher_algorithm = wolfssl_aes;
944
        specs->cipher_type           = block;
945
        specs->mac_algorithm         = sha_mac;
946
        specs->kea                   = ecc_diffie_hellman_kea;
947
        specs->sig_algo              = ecc_dsa_sa_algo;
948
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
949
        specs->pad_size              = PAD_SHA;
950
        specs->static_ecdh           = 1;
951
        specs->key_size              = AES_128_KEY_SIZE;
952
        specs->block_size            = WC_AES_BLOCK_SIZE;
953
        specs->iv_size               = AES_IV_SIZE;
954
955
        break;
956
#endif
957
958
#ifdef BUILD_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA
959
    case TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA :
960
        specs->bulk_cipher_algorithm = wolfssl_aes;
961
        specs->cipher_type           = block;
962
        specs->mac_algorithm         = sha_mac;
963
        specs->kea                   = ecc_diffie_hellman_kea;
964
        specs->sig_algo              = ecc_dsa_sa_algo;
965
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
966
        specs->pad_size              = PAD_SHA;
967
        specs->static_ecdh           = 1;
968
        specs->key_size              = AES_256_KEY_SIZE;
969
        specs->block_size            = WC_AES_BLOCK_SIZE;
970
        specs->iv_size               = AES_IV_SIZE;
971
972
        break;
973
#endif
974
975
#ifdef BUILD_TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256
976
    case TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256 :
977
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
978
        specs->cipher_type           = aead;
979
        specs->mac_algorithm         = sha256_mac;
980
        specs->kea                   = ecc_diffie_hellman_kea;
981
        specs->sig_algo              = rsa_sa_algo;
982
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
983
        specs->pad_size              = PAD_SHA;
984
        specs->static_ecdh           = 1;
985
        specs->key_size              = AES_128_KEY_SIZE;
986
        specs->block_size            = WC_AES_BLOCK_SIZE;
987
        specs->iv_size               = AESGCM_IMP_IV_SZ;
988
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
989
990
        break;
991
#endif
992
993
#ifdef BUILD_TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384
994
    case TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384 :
995
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
996
        specs->cipher_type           = aead;
997
        specs->mac_algorithm         = sha384_mac;
998
        specs->kea                   = ecc_diffie_hellman_kea;
999
        specs->sig_algo              = rsa_sa_algo;
1000
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
1001
        specs->pad_size              = PAD_SHA;
1002
        specs->static_ecdh           = 1;
1003
        specs->key_size              = AES_256_KEY_SIZE;
1004
        specs->block_size            = WC_AES_BLOCK_SIZE;
1005
        specs->iv_size               = AESGCM_IMP_IV_SZ;
1006
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
1007
1008
        break;
1009
#endif
1010
1011
#ifdef BUILD_TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256
1012
    case TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256 :
1013
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
1014
        specs->cipher_type           = aead;
1015
        specs->mac_algorithm         = sha256_mac;
1016
        specs->kea                   = ecc_diffie_hellman_kea;
1017
        specs->sig_algo              = ecc_dsa_sa_algo;
1018
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1019
        specs->pad_size              = PAD_SHA;
1020
        specs->static_ecdh           = 1;
1021
        specs->key_size              = AES_128_KEY_SIZE;
1022
        specs->block_size            = WC_AES_BLOCK_SIZE;
1023
        specs->iv_size               = AESGCM_IMP_IV_SZ;
1024
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
1025
1026
        break;
1027
#endif
1028
1029
#ifdef BUILD_TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384
1030
    case TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384 :
1031
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
1032
        specs->cipher_type           = aead;
1033
        specs->mac_algorithm         = sha384_mac;
1034
        specs->kea                   = ecc_diffie_hellman_kea;
1035
        specs->sig_algo              = ecc_dsa_sa_algo;
1036
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
1037
        specs->pad_size              = PAD_SHA;
1038
        specs->static_ecdh           = 1;
1039
        specs->key_size              = AES_256_KEY_SIZE;
1040
        specs->block_size            = WC_AES_BLOCK_SIZE;
1041
        specs->iv_size               = AESGCM_IMP_IV_SZ;
1042
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
1043
1044
        break;
1045
#endif
1046
1047
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256
1048
    case TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256 :
1049
        specs->bulk_cipher_algorithm = wolfssl_aria_gcm;
1050
        specs->cipher_type           = aead;
1051
        specs->mac_algorithm         = sha256_mac;
1052
        specs->kea                   = ecc_diffie_hellman_kea;
1053
        specs->sig_algo              = ecc_dsa_sa_algo;
1054
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1055
        specs->pad_size              = PAD_SHA;
1056
        specs->static_ecdh           = 0;
1057
        specs->key_size              = ARIA_128_KEY_SIZE;
1058
        specs->block_size            = ARIA_BLOCK_SIZE;
1059
        specs->iv_size               = AESGCM_IMP_IV_SZ;
1060
        specs->aead_mac_size         = ARIA_GCM_AUTH_SZ;
1061
1062
        break;
1063
#endif
1064
1065
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384
1066
    case TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384 :
1067
        specs->bulk_cipher_algorithm = wolfssl_aria_gcm;
1068
        specs->cipher_type           = aead;
1069
        specs->mac_algorithm         = sha384_mac;
1070
        specs->kea                   = ecc_diffie_hellman_kea;
1071
        specs->sig_algo              = ecc_dsa_sa_algo;
1072
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
1073
        specs->pad_size              = PAD_SHA;
1074
        specs->static_ecdh           = 0;
1075
        specs->key_size              = ARIA_256_KEY_SIZE;
1076
        specs->block_size            = ARIA_BLOCK_SIZE;
1077
        specs->iv_size               = AESGCM_IMP_IV_SZ;
1078
        specs->aead_mac_size         = ARIA_GCM_AUTH_SZ;
1079
1080
        break;
1081
#endif
1082
1083
0
#endif /* HAVE_ECC */
1084
1085
#ifdef BUILD_TLS_RSA_WITH_AES_128_CCM_8
1086
    case TLS_RSA_WITH_AES_128_CCM_8 :
1087
        specs->bulk_cipher_algorithm = wolfssl_aes_ccm;
1088
        specs->cipher_type           = aead;
1089
        specs->mac_algorithm         = sha256_mac;
1090
        specs->kea                   = rsa_kea;
1091
        specs->sig_algo              = rsa_sa_algo;
1092
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1093
        specs->pad_size              = PAD_SHA;
1094
        specs->static_ecdh           = 0;
1095
        specs->key_size              = AES_128_KEY_SIZE;
1096
        specs->block_size            = WC_AES_BLOCK_SIZE;
1097
        specs->iv_size               = AESCCM_IMP_IV_SZ;
1098
        specs->aead_mac_size         = AES_CCM_8_AUTH_SZ;
1099
1100
        break;
1101
#endif
1102
1103
#ifdef BUILD_TLS_RSA_WITH_AES_256_CCM_8
1104
    case TLS_RSA_WITH_AES_256_CCM_8 :
1105
        specs->bulk_cipher_algorithm = wolfssl_aes_ccm;
1106
        specs->cipher_type           = aead;
1107
        specs->mac_algorithm         = sha256_mac;
1108
        specs->kea                   = rsa_kea;
1109
        specs->sig_algo              = rsa_sa_algo;
1110
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1111
        specs->pad_size              = PAD_SHA;
1112
        specs->static_ecdh           = 0;
1113
        specs->key_size              = AES_256_KEY_SIZE;
1114
        specs->block_size            = WC_AES_BLOCK_SIZE;
1115
        specs->iv_size               = AESCCM_IMP_IV_SZ;
1116
        specs->aead_mac_size         = AES_CCM_8_AUTH_SZ;
1117
1118
        break;
1119
#endif
1120
1121
#ifdef BUILD_TLS_PSK_WITH_AES_128_CCM_8
1122
    case TLS_PSK_WITH_AES_128_CCM_8 :
1123
        specs->bulk_cipher_algorithm = wolfssl_aes_ccm;
1124
        specs->cipher_type           = aead;
1125
        specs->mac_algorithm         = sha256_mac;
1126
        specs->kea                   = psk_kea;
1127
        specs->sig_algo              = anonymous_sa_algo;
1128
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1129
        specs->pad_size              = PAD_SHA;
1130
        specs->static_ecdh           = 0;
1131
        specs->key_size              = AES_128_KEY_SIZE;
1132
        specs->block_size            = WC_AES_BLOCK_SIZE;
1133
        specs->iv_size               = AESCCM_IMP_IV_SZ;
1134
        specs->aead_mac_size         = AES_CCM_8_AUTH_SZ;
1135
1136
        if (opts != NULL)
1137
            opts->usingPSK_cipher    = 1;
1138
        break;
1139
#endif
1140
1141
#ifdef BUILD_TLS_PSK_WITH_AES_256_CCM_8
1142
    case TLS_PSK_WITH_AES_256_CCM_8 :
1143
        specs->bulk_cipher_algorithm = wolfssl_aes_ccm;
1144
        specs->cipher_type           = aead;
1145
        specs->mac_algorithm         = sha256_mac;
1146
        specs->kea                   = psk_kea;
1147
        specs->sig_algo              = anonymous_sa_algo;
1148
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1149
        specs->pad_size              = PAD_SHA;
1150
        specs->static_ecdh           = 0;
1151
        specs->key_size              = AES_256_KEY_SIZE;
1152
        specs->block_size            = WC_AES_BLOCK_SIZE;
1153
        specs->iv_size               = AESCCM_IMP_IV_SZ;
1154
        specs->aead_mac_size         = AES_CCM_8_AUTH_SZ;
1155
1156
        if (opts != NULL)
1157
            opts->usingPSK_cipher    = 1;
1158
        break;
1159
#endif
1160
1161
#ifdef BUILD_TLS_PSK_WITH_AES_128_CCM
1162
    case TLS_PSK_WITH_AES_128_CCM :
1163
        specs->bulk_cipher_algorithm = wolfssl_aes_ccm;
1164
        specs->cipher_type           = aead;
1165
        specs->mac_algorithm         = sha256_mac;
1166
        specs->kea                   = psk_kea;
1167
        specs->sig_algo              = anonymous_sa_algo;
1168
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1169
        specs->pad_size              = PAD_SHA;
1170
        specs->static_ecdh           = 0;
1171
        specs->key_size              = AES_128_KEY_SIZE;
1172
        specs->block_size            = WC_AES_BLOCK_SIZE;
1173
        specs->iv_size               = AESCCM_IMP_IV_SZ;
1174
        specs->aead_mac_size         = AES_CCM_16_AUTH_SZ;
1175
1176
        if (opts != NULL)
1177
            opts->usingPSK_cipher    = 1;
1178
        break;
1179
#endif
1180
1181
#ifdef BUILD_TLS_PSK_WITH_AES_256_CCM
1182
    case TLS_PSK_WITH_AES_256_CCM :
1183
        specs->bulk_cipher_algorithm = wolfssl_aes_ccm;
1184
        specs->cipher_type           = aead;
1185
        specs->mac_algorithm         = sha256_mac;
1186
        specs->kea                   = psk_kea;
1187
        specs->sig_algo              = anonymous_sa_algo;
1188
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1189
        specs->pad_size              = PAD_SHA;
1190
        specs->static_ecdh           = 0;
1191
        specs->key_size              = AES_256_KEY_SIZE;
1192
        specs->block_size            = WC_AES_BLOCK_SIZE;
1193
        specs->iv_size               = AESCCM_IMP_IV_SZ;
1194
        specs->aead_mac_size         = AES_CCM_16_AUTH_SZ;
1195
1196
        if (opts != NULL)
1197
            opts->usingPSK_cipher    = 1;
1198
        break;
1199
#endif
1200
1201
#ifdef BUILD_TLS_DHE_PSK_WITH_AES_128_CCM
1202
    case TLS_DHE_PSK_WITH_AES_128_CCM :
1203
        specs->bulk_cipher_algorithm = wolfssl_aes_ccm;
1204
        specs->cipher_type           = aead;
1205
        specs->mac_algorithm         = sha256_mac;
1206
        specs->kea                   = dhe_psk_kea;
1207
        specs->sig_algo              = anonymous_sa_algo;
1208
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1209
        specs->pad_size              = PAD_SHA;
1210
        specs->static_ecdh           = 0;
1211
        specs->key_size              = AES_128_KEY_SIZE;
1212
        specs->block_size            = WC_AES_BLOCK_SIZE;
1213
        specs->iv_size               = AESCCM_IMP_IV_SZ;
1214
        specs->aead_mac_size         = AES_CCM_16_AUTH_SZ;
1215
1216
        if (opts != NULL)
1217
            opts->usingPSK_cipher    = 1;
1218
        break;
1219
#endif
1220
1221
#ifdef BUILD_TLS_DHE_PSK_WITH_AES_256_CCM
1222
    case TLS_DHE_PSK_WITH_AES_256_CCM :
1223
        specs->bulk_cipher_algorithm = wolfssl_aes_ccm;
1224
        specs->cipher_type           = aead;
1225
        specs->mac_algorithm         = sha256_mac;
1226
        specs->kea                   = dhe_psk_kea;
1227
        specs->sig_algo              = anonymous_sa_algo;
1228
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1229
        specs->pad_size              = PAD_SHA;
1230
        specs->static_ecdh           = 0;
1231
        specs->key_size              = AES_256_KEY_SIZE;
1232
        specs->block_size            = WC_AES_BLOCK_SIZE;
1233
        specs->iv_size               = AESCCM_IMP_IV_SZ;
1234
        specs->aead_mac_size         = AES_CCM_16_AUTH_SZ;
1235
1236
        if (opts != NULL)
1237
            opts->usingPSK_cipher    = 1;
1238
        break;
1239
#endif
1240
1241
#if defined(WOLFSSL_TLS13) && defined(HAVE_NULL_CIPHER)
1242
    #ifdef BUILD_TLS_SHA256_SHA256
1243
    case TLS_SHA256_SHA256 :
1244
        specs->bulk_cipher_algorithm = wolfssl_cipher_null;
1245
        specs->cipher_type           = aead;
1246
        specs->mac_algorithm         = sha256_mac;
1247
        specs->kea                   = any_kea;
1248
        specs->sig_algo              = any_sa_algo;
1249
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1250
        specs->pad_size              = PAD_SHA;
1251
        specs->static_ecdh           = 0;
1252
        specs->key_size              = WC_SHA256_DIGEST_SIZE;
1253
        specs->block_size            = 0;
1254
        specs->iv_size               = WC_SHA256_DIGEST_SIZE;
1255
        specs->aead_mac_size         = WC_SHA256_DIGEST_SIZE;
1256
1257
        break;
1258
    #endif
1259
1260
    #ifdef BUILD_TLS_SHA384_SHA384
1261
    case TLS_SHA384_SHA384 :
1262
        specs->bulk_cipher_algorithm = wolfssl_cipher_null;
1263
        specs->cipher_type           = aead;
1264
        specs->mac_algorithm         = sha384_mac;
1265
        specs->kea                   = any_kea;
1266
        specs->sig_algo              = any_sa_algo;
1267
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
1268
        specs->pad_size              = PAD_SHA;
1269
        specs->static_ecdh           = 0;
1270
        specs->key_size              = WC_SHA384_DIGEST_SIZE;
1271
        specs->block_size            = 0;
1272
        specs->iv_size               = WC_SHA384_DIGEST_SIZE;
1273
        specs->aead_mac_size         = WC_SHA384_DIGEST_SIZE;
1274
1275
        break;
1276
    #endif
1277
#endif
1278
1279
0
    default:
1280
0
        WOLFSSL_MSG("Unsupported cipher suite, SetCipherSpecs ECC");
1281
0
        return UNSUPPORTED_SUITE;
1282
0
    }   /* switch */
1283
0
    }   /* if     */
1284
1285
    /* TLSi v1.3 cipher suites, 0x13 */
1286
0
    if (cipherSuite0 == TLS13_BYTE) {
1287
0
        switch (cipherSuite) {
1288
1289
0
#ifdef WOLFSSL_TLS13
1290
0
    #ifdef BUILD_TLS_AES_128_GCM_SHA256
1291
0
        case TLS_AES_128_GCM_SHA256 :
1292
0
            specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
1293
0
            specs->cipher_type           = aead;
1294
0
            specs->mac_algorithm         = sha256_mac;
1295
0
            specs->kea                   = any_kea;
1296
0
            specs->sig_algo              = any_sa_algo;
1297
0
            specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1298
0
            specs->pad_size              = PAD_SHA;
1299
0
            specs->static_ecdh           = 0;
1300
0
            specs->key_size              = AES_128_KEY_SIZE;
1301
0
            specs->block_size            = WC_AES_BLOCK_SIZE;
1302
0
            specs->iv_size               = AESGCM_NONCE_SZ;
1303
0
            specs->aead_mac_size         = AES_GCM_AUTH_SZ;
1304
1305
0
            break;
1306
0
    #endif
1307
1308
0
    #ifdef BUILD_TLS_AES_256_GCM_SHA384
1309
0
        case TLS_AES_256_GCM_SHA384 :
1310
0
            specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
1311
0
            specs->cipher_type           = aead;
1312
0
            specs->mac_algorithm         = sha384_mac;
1313
0
            specs->kea                   = any_kea;
1314
0
            specs->sig_algo              = any_sa_algo;
1315
0
            specs->hash_size             = WC_SHA384_DIGEST_SIZE;
1316
0
            specs->pad_size              = PAD_SHA;
1317
0
            specs->static_ecdh           = 0;
1318
0
            specs->key_size              = AES_256_KEY_SIZE;
1319
0
            specs->block_size            = WC_AES_BLOCK_SIZE;
1320
0
            specs->iv_size               = AESGCM_NONCE_SZ;
1321
0
            specs->aead_mac_size         = AES_GCM_AUTH_SZ;
1322
1323
0
            break;
1324
0
    #endif
1325
1326
0
    #ifdef BUILD_TLS_CHACHA20_POLY1305_SHA256
1327
0
        case TLS_CHACHA20_POLY1305_SHA256 :
1328
0
            specs->bulk_cipher_algorithm = wolfssl_chacha;
1329
0
            specs->cipher_type           = aead;
1330
0
            specs->mac_algorithm         = sha256_mac;
1331
0
            specs->kea                   = any_kea;
1332
0
            specs->sig_algo              = any_sa_algo;
1333
0
            specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1334
0
            specs->pad_size              = PAD_SHA;
1335
0
            specs->static_ecdh           = 0;
1336
0
            specs->key_size              = CHACHA20_256_KEY_SIZE;
1337
0
            specs->block_size            = CHACHA20_BLOCK_SIZE;
1338
0
            specs->iv_size               = CHACHA20_IV_SIZE;
1339
0
            specs->aead_mac_size         = POLY1305_AUTH_SZ;
1340
0
            if (opts != NULL)
1341
0
                opts->oldPoly            = 0; /* use recent padding RFC */
1342
1343
0
            break;
1344
0
    #endif
1345
1346
0
    #ifdef BUILD_TLS_AES_128_CCM_SHA256
1347
0
        case TLS_AES_128_CCM_SHA256 :
1348
0
            specs->bulk_cipher_algorithm = wolfssl_aes_ccm;
1349
0
            specs->cipher_type           = aead;
1350
0
            specs->mac_algorithm         = sha256_mac;
1351
0
            specs->kea                   = any_kea;
1352
0
            specs->sig_algo              = any_sa_algo;
1353
0
            specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1354
0
            specs->pad_size              = PAD_SHA;
1355
0
            specs->static_ecdh           = 0;
1356
0
            specs->key_size              = AES_128_KEY_SIZE;
1357
0
            specs->block_size            = WC_AES_BLOCK_SIZE;
1358
0
            specs->iv_size               = AESCCM_NONCE_SZ;
1359
0
            specs->aead_mac_size         = AES_CCM_16_AUTH_SZ;
1360
1361
0
            break;
1362
0
    #endif
1363
1364
0
    #ifdef BUILD_TLS_AES_128_CCM_8_SHA256
1365
0
        case TLS_AES_128_CCM_8_SHA256 :
1366
0
            specs->bulk_cipher_algorithm = wolfssl_aes_ccm;
1367
0
            specs->cipher_type           = aead;
1368
0
            specs->mac_algorithm         = sha256_mac;
1369
0
            specs->kea                   = any_kea;
1370
0
            specs->sig_algo              = any_sa_algo;
1371
0
            specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1372
0
            specs->pad_size              = PAD_SHA;
1373
0
            specs->static_ecdh           = 0;
1374
0
            specs->key_size              = AES_128_KEY_SIZE;
1375
0
            specs->block_size            = WC_AES_BLOCK_SIZE;
1376
0
            specs->iv_size               = AESCCM_NONCE_SZ;
1377
0
            specs->aead_mac_size         = AES_CCM_8_AUTH_SZ;
1378
1379
0
            break;
1380
0
    #endif
1381
0
#endif /* WOLFSSL_TLS13 */
1382
0
        default:
1383
0
            WOLFSSL_MSG("Unsupported cipher suite, SetCipherSpecs TLS 1.3");
1384
0
            return UNSUPPORTED_SUITE;
1385
0
        }
1386
0
    }
1387
1388
0
    if (cipherSuite0 == ECDHE_PSK_BYTE) {
1389
1390
0
    switch (cipherSuite) {
1391
1392
0
#if defined(HAVE_ECC) || defined(HAVE_CURVE25519) || defined(HAVE_CURVE448)
1393
#ifdef BUILD_TLS_ECDHE_PSK_WITH_AES_128_GCM_SHA256
1394
    case TLS_ECDHE_PSK_WITH_AES_128_GCM_SHA256 :
1395
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
1396
        specs->cipher_type           = aead;
1397
        specs->mac_algorithm         = sha256_mac;
1398
        specs->kea                   = ecdhe_psk_kea;
1399
        specs->sig_algo              = anonymous_sa_algo;
1400
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1401
        specs->pad_size              = PAD_SHA;
1402
        specs->static_ecdh           = 0;
1403
        specs->key_size              = AES_128_KEY_SIZE;
1404
        specs->block_size            = WC_AES_BLOCK_SIZE;
1405
        specs->iv_size               = AESGCM_IMP_IV_SZ;
1406
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
1407
1408
        if (opts != NULL)
1409
            opts->usingPSK_cipher    = 1;
1410
        break;
1411
#endif
1412
0
#endif
1413
1414
0
    default:
1415
0
        WOLFSSL_MSG("Unsupported cipher suite, SetCipherSpecs ECDHE_PSK");
1416
0
        return UNSUPPORTED_SUITE;
1417
0
    }
1418
0
    }
1419
1420
0
    if (cipherSuite0 == SM_BYTE) {
1421
1422
0
    switch (cipherSuite) {
1423
0
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_SM4_CBC_SM3
1424
0
    case TLS_ECDHE_ECDSA_WITH_SM4_CBC_SM3 :
1425
0
        specs->bulk_cipher_algorithm = wolfssl_sm4_cbc;
1426
0
        specs->cipher_type           = block;
1427
0
        specs->mac_algorithm         = sm3_mac;
1428
0
        specs->kea                   = ecc_diffie_hellman_kea;
1429
0
        specs->sig_algo              = sm2_sa_algo;
1430
0
        specs->hash_size             = WC_SM3_DIGEST_SIZE;
1431
0
        specs->pad_size              = PAD_SHA;
1432
0
        specs->static_ecdh           = 0;
1433
0
        specs->key_size              = SM4_KEY_SIZE;
1434
0
        specs->iv_size               = SM4_IV_SIZE;
1435
0
        specs->block_size            = SM4_BLOCK_SIZE;
1436
1437
0
        break;
1438
0
#endif
1439
1440
0
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_SM4_GCM_SM3
1441
0
    case TLS_ECDHE_ECDSA_WITH_SM4_GCM_SM3 :
1442
0
        specs->bulk_cipher_algorithm = wolfssl_sm4_gcm;
1443
0
        specs->cipher_type           = aead;
1444
0
        specs->mac_algorithm         = sm3_mac;
1445
0
        specs->kea                   = ecc_diffie_hellman_kea;
1446
0
        specs->sig_algo              = sm2_sa_algo;
1447
0
        specs->hash_size             = WC_SM3_DIGEST_SIZE;
1448
0
        specs->pad_size              = PAD_SHA;
1449
0
        specs->static_ecdh           = 0;
1450
0
        specs->key_size              = SM4_KEY_SIZE;
1451
0
        specs->block_size            = SM4_BLOCK_SIZE;
1452
0
        specs->iv_size               = GCM_IMP_IV_SZ;
1453
0
        specs->aead_mac_size         = SM4_GCM_AUTH_SZ;
1454
1455
0
        break;
1456
0
#endif
1457
1458
0
#ifdef BUILD_TLS_ECDHE_ECDSA_WITH_SM4_CCM_SM3
1459
0
    case TLS_ECDHE_ECDSA_WITH_SM4_CCM_SM3 :
1460
0
        specs->bulk_cipher_algorithm = wolfssl_sm4_ccm;
1461
0
        specs->cipher_type           = aead;
1462
0
        specs->mac_algorithm         = sm3_mac;
1463
0
        specs->kea                   = ecc_diffie_hellman_kea;
1464
0
        specs->sig_algo              = sm2_sa_algo;
1465
0
        specs->hash_size             = WC_SM3_DIGEST_SIZE;
1466
0
        specs->pad_size              = PAD_SHA;
1467
0
        specs->static_ecdh           = 0;
1468
0
        specs->key_size              = SM4_KEY_SIZE;
1469
0
        specs->block_size            = SM4_BLOCK_SIZE;
1470
0
        specs->iv_size               = CCM_IMP_IV_SZ;
1471
0
        specs->aead_mac_size         = SM4_CCM_AUTH_SZ;
1472
1473
0
        break;
1474
0
#endif
1475
1476
0
    default:
1477
0
        WOLFSSL_MSG("Unsupported cipher suite, SetCipherSpecs SM");
1478
0
        return UNSUPPORTED_SUITE;
1479
0
    }
1480
0
    }
1481
1482
0
    if (cipherSuite0 != ECC_BYTE &&
1483
0
        cipherSuite0 != ECDHE_PSK_BYTE &&
1484
0
        cipherSuite0 != CHACHA_BYTE &&
1485
0
#if defined(WOLFSSL_SM2) && defined(WOLFSSL_SM3) && \
1486
0
    (defined(WOLFSSL_SM4_CBC) || defined(WOLFSSL_SM4_GCM) || \
1487
0
     defined(WOLFSSL_SM4_CCM))
1488
0
        cipherSuite0 != SM_BYTE &&
1489
0
#endif
1490
0
        cipherSuite0 != TLS13_BYTE) {   /* normal suites */
1491
0
    switch (cipherSuite) {
1492
1493
0
#ifdef BUILD_TLS_SM4_GCM_SM3
1494
0
    case TLS_SM4_GCM_SM3 :
1495
0
        specs->bulk_cipher_algorithm = wolfssl_sm4_gcm;
1496
0
        specs->cipher_type           = aead;
1497
0
        specs->mac_algorithm         = sm3_mac;
1498
0
        specs->kea                   = any_kea;
1499
0
        specs->sig_algo              = any_sa_algo;
1500
0
        specs->hash_size             = WC_SM3_DIGEST_SIZE;
1501
0
        specs->pad_size              = PAD_SHA;
1502
0
        specs->static_ecdh           = 0;
1503
0
        specs->key_size              = SM4_KEY_SIZE;
1504
0
        specs->block_size            = SM4_BLOCK_SIZE;
1505
0
        specs->iv_size               = SM4_GCM_NONCE_SZ;
1506
0
        specs->aead_mac_size         = SM4_GCM_AUTH_SZ;
1507
1508
0
        break;
1509
0
#endif
1510
1511
0
#ifdef BUILD_TLS_SM4_CCM_SM3
1512
0
    case TLS_SM4_CCM_SM3 :
1513
0
        specs->bulk_cipher_algorithm = wolfssl_sm4_ccm;
1514
0
        specs->cipher_type           = aead;
1515
0
        specs->mac_algorithm         = sm3_mac;
1516
0
        specs->kea                   = any_kea;
1517
0
        specs->sig_algo              = any_sa_algo;
1518
0
        specs->hash_size             = WC_SM3_DIGEST_SIZE;
1519
0
        specs->pad_size              = PAD_SHA;
1520
0
        specs->static_ecdh           = 0;
1521
0
        specs->key_size              = SM4_KEY_SIZE;
1522
0
        specs->block_size            = SM4_BLOCK_SIZE;
1523
0
        specs->iv_size               = SM4_CCM_NONCE_SZ;
1524
0
        specs->aead_mac_size         = SM4_CCM_AUTH_SZ;
1525
1526
0
        break;
1527
0
#endif
1528
1529
#ifdef BUILD_SSL_RSA_WITH_RC4_128_SHA
1530
    case SSL_RSA_WITH_RC4_128_SHA :
1531
        specs->bulk_cipher_algorithm = wolfssl_rc4;
1532
        specs->cipher_type           = stream;
1533
        specs->mac_algorithm         = sha_mac;
1534
        specs->kea                   = rsa_kea;
1535
        specs->sig_algo              = rsa_sa_algo;
1536
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
1537
        specs->pad_size              = PAD_SHA;
1538
        specs->static_ecdh           = 0;
1539
        specs->key_size              = RC4_KEY_SIZE;
1540
        specs->iv_size               = 0;
1541
        specs->block_size            = 0;
1542
1543
        break;
1544
#endif
1545
1546
#ifdef BUILD_SSL_RSA_WITH_RC4_128_MD5
1547
    case SSL_RSA_WITH_RC4_128_MD5 :
1548
        specs->bulk_cipher_algorithm = wolfssl_rc4;
1549
        specs->cipher_type           = stream;
1550
        specs->mac_algorithm         = md5_mac;
1551
        specs->kea                   = rsa_kea;
1552
        specs->sig_algo              = rsa_sa_algo;
1553
        specs->hash_size             = WC_MD5_DIGEST_SIZE;
1554
        specs->pad_size              = PAD_MD5;
1555
        specs->static_ecdh           = 0;
1556
        specs->key_size              = RC4_KEY_SIZE;
1557
        specs->iv_size               = 0;
1558
        specs->block_size            = 0;
1559
1560
        break;
1561
#endif
1562
1563
#ifdef BUILD_SSL_RSA_WITH_3DES_EDE_CBC_SHA
1564
    case SSL_RSA_WITH_3DES_EDE_CBC_SHA :
1565
        specs->bulk_cipher_algorithm = wolfssl_triple_des;
1566
        specs->cipher_type           = block;
1567
        specs->mac_algorithm         = sha_mac;
1568
        specs->kea                   = rsa_kea;
1569
        specs->sig_algo              = rsa_sa_algo;
1570
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
1571
        specs->pad_size              = PAD_SHA;
1572
        specs->static_ecdh           = 0;
1573
        specs->key_size              = DES3_KEY_SIZE;
1574
        specs->block_size            = DES_BLOCK_SIZE;
1575
#if defined(HAVE_FIPS) && defined(HAVE_FIPS_VERSION) && (HAVE_FIPS_VERSION == 2)
1576
        specs->iv_size               = DES_BLOCK_SIZE;
1577
#else
1578
        specs->iv_size               = DES_IV_SIZE;
1579
#endif
1580
1581
        break;
1582
#endif
1583
1584
#ifdef BUILD_TLS_RSA_WITH_AES_128_CBC_SHA
1585
    case TLS_RSA_WITH_AES_128_CBC_SHA :
1586
        specs->bulk_cipher_algorithm = wolfssl_aes;
1587
        specs->cipher_type           = block;
1588
        specs->mac_algorithm         = sha_mac;
1589
        specs->kea                   = rsa_kea;
1590
        specs->sig_algo              = rsa_sa_algo;
1591
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
1592
        specs->pad_size              = PAD_SHA;
1593
        specs->static_ecdh           = 0;
1594
        specs->key_size              = AES_128_KEY_SIZE;
1595
        specs->block_size            = WC_AES_BLOCK_SIZE;
1596
        specs->iv_size               = AES_IV_SIZE;
1597
1598
        break;
1599
#endif
1600
1601
#ifdef BUILD_TLS_RSA_WITH_AES_128_CBC_SHA256
1602
    case TLS_RSA_WITH_AES_128_CBC_SHA256 :
1603
        specs->bulk_cipher_algorithm = wolfssl_aes;
1604
        specs->cipher_type           = block;
1605
        specs->mac_algorithm         = sha256_mac;
1606
        specs->kea                   = rsa_kea;
1607
        specs->sig_algo              = rsa_sa_algo;
1608
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1609
        specs->pad_size              = PAD_SHA;
1610
        specs->static_ecdh           = 0;
1611
        specs->key_size              = AES_128_KEY_SIZE;
1612
        specs->block_size            = WC_AES_BLOCK_SIZE;
1613
        specs->iv_size               = AES_IV_SIZE;
1614
1615
        break;
1616
#endif
1617
1618
#ifdef BUILD_TLS_RSA_WITH_NULL_MD5
1619
    case TLS_RSA_WITH_NULL_MD5 :
1620
        specs->bulk_cipher_algorithm = wolfssl_cipher_null;
1621
        specs->cipher_type           = stream;
1622
        specs->mac_algorithm         = md5_mac;
1623
        specs->kea                   = rsa_kea;
1624
        specs->sig_algo              = rsa_sa_algo;
1625
        specs->hash_size             = WC_MD5_DIGEST_SIZE;
1626
        specs->pad_size              = PAD_MD5;
1627
        specs->static_ecdh           = 0;
1628
        specs->key_size              = 0;
1629
        specs->block_size            = 0;
1630
        specs->iv_size               = 0;
1631
1632
        break;
1633
#endif
1634
1635
#ifdef BUILD_TLS_RSA_WITH_NULL_SHA
1636
    case TLS_RSA_WITH_NULL_SHA :
1637
        specs->bulk_cipher_algorithm = wolfssl_cipher_null;
1638
        specs->cipher_type           = stream;
1639
        specs->mac_algorithm         = sha_mac;
1640
        specs->kea                   = rsa_kea;
1641
        specs->sig_algo              = rsa_sa_algo;
1642
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
1643
        specs->pad_size              = PAD_SHA;
1644
        specs->static_ecdh           = 0;
1645
        specs->key_size              = 0;
1646
        specs->block_size            = 0;
1647
        specs->iv_size               = 0;
1648
1649
        break;
1650
#endif
1651
1652
#ifdef BUILD_TLS_RSA_WITH_NULL_SHA256
1653
    case TLS_RSA_WITH_NULL_SHA256 :
1654
        specs->bulk_cipher_algorithm = wolfssl_cipher_null;
1655
        specs->cipher_type           = stream;
1656
        specs->mac_algorithm         = sha256_mac;
1657
        specs->kea                   = rsa_kea;
1658
        specs->sig_algo              = rsa_sa_algo;
1659
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1660
        specs->pad_size              = PAD_SHA;
1661
        specs->static_ecdh           = 0;
1662
        specs->key_size              = 0;
1663
        specs->block_size            = 0;
1664
        specs->iv_size               = 0;
1665
1666
        break;
1667
#endif
1668
1669
#ifdef BUILD_TLS_RSA_WITH_AES_256_CBC_SHA
1670
    case TLS_RSA_WITH_AES_256_CBC_SHA :
1671
        specs->bulk_cipher_algorithm = wolfssl_aes;
1672
        specs->cipher_type           = block;
1673
        specs->mac_algorithm         = sha_mac;
1674
        specs->kea                   = rsa_kea;
1675
        specs->sig_algo              = rsa_sa_algo;
1676
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
1677
        specs->pad_size              = PAD_SHA;
1678
        specs->static_ecdh           = 0;
1679
        specs->key_size              = AES_256_KEY_SIZE;
1680
        specs->block_size            = WC_AES_BLOCK_SIZE;
1681
        specs->iv_size               = AES_IV_SIZE;
1682
1683
        break;
1684
#endif
1685
1686
#ifdef BUILD_TLS_RSA_WITH_AES_256_CBC_SHA256
1687
    case TLS_RSA_WITH_AES_256_CBC_SHA256 :
1688
        specs->bulk_cipher_algorithm = wolfssl_aes;
1689
        specs->cipher_type           = block;
1690
        specs->mac_algorithm         = sha256_mac;
1691
        specs->kea                   = rsa_kea;
1692
        specs->sig_algo              = rsa_sa_algo;
1693
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1694
        specs->pad_size              = PAD_SHA;
1695
        specs->static_ecdh           = 0;
1696
        specs->key_size              = AES_256_KEY_SIZE;
1697
        specs->block_size            = WC_AES_BLOCK_SIZE;
1698
        specs->iv_size               = AES_IV_SIZE;
1699
1700
        break;
1701
#endif
1702
1703
#ifdef BUILD_TLS_PSK_WITH_AES_128_GCM_SHA256
1704
    case TLS_PSK_WITH_AES_128_GCM_SHA256 :
1705
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
1706
        specs->cipher_type           = aead;
1707
        specs->mac_algorithm         = sha256_mac;
1708
        specs->kea                   = psk_kea;
1709
        specs->sig_algo              = anonymous_sa_algo;
1710
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1711
        specs->pad_size              = PAD_SHA;
1712
        specs->static_ecdh           = 0;
1713
        specs->key_size              = AES_128_KEY_SIZE;
1714
        specs->block_size            = WC_AES_BLOCK_SIZE;
1715
        specs->iv_size               = AESGCM_IMP_IV_SZ;
1716
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
1717
1718
        if (opts != NULL)
1719
            opts->usingPSK_cipher    = 1;
1720
        break;
1721
#endif
1722
1723
#ifdef BUILD_TLS_PSK_WITH_AES_256_GCM_SHA384
1724
    case TLS_PSK_WITH_AES_256_GCM_SHA384 :
1725
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
1726
        specs->cipher_type           = aead;
1727
        specs->mac_algorithm         = sha384_mac;
1728
        specs->kea                   = psk_kea;
1729
        specs->sig_algo              = anonymous_sa_algo;
1730
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
1731
        specs->pad_size              = PAD_SHA;
1732
        specs->static_ecdh           = 0;
1733
        specs->key_size              = AES_256_KEY_SIZE;
1734
        specs->block_size            = WC_AES_BLOCK_SIZE;
1735
        specs->iv_size               = AESGCM_IMP_IV_SZ;
1736
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
1737
1738
        if (opts != NULL)
1739
            opts->usingPSK_cipher    = 1;
1740
        break;
1741
#endif
1742
1743
#ifdef BUILD_TLS_DH_anon_WITH_AES_256_GCM_SHA384
1744
    case TLS_DH_anon_WITH_AES_256_GCM_SHA384:
1745
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
1746
        specs->cipher_type           = aead;
1747
        specs->mac_algorithm         = sha384_mac;
1748
        specs->kea                   = diffie_hellman_kea;
1749
        specs->sig_algo              = anonymous_sa_algo;
1750
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
1751
        specs->pad_size              = PAD_SHA;
1752
        specs->static_ecdh           = 0;
1753
        specs->key_size              = AES_256_KEY_SIZE;
1754
        specs->block_size            = WC_AES_BLOCK_SIZE;
1755
        specs->iv_size               = AESGCM_IMP_IV_SZ;
1756
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
1757
1758
        if (opts != NULL)
1759
            opts->usingAnon_cipher   = 1;
1760
        break;
1761
#endif
1762
1763
#ifdef BUILD_TLS_DHE_PSK_WITH_AES_128_GCM_SHA256
1764
    case TLS_DHE_PSK_WITH_AES_128_GCM_SHA256 :
1765
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
1766
        specs->cipher_type           = aead;
1767
        specs->mac_algorithm         = sha256_mac;
1768
        specs->kea                   = dhe_psk_kea;
1769
        specs->sig_algo              = anonymous_sa_algo;
1770
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1771
        specs->pad_size              = PAD_SHA;
1772
        specs->static_ecdh           = 0;
1773
        specs->key_size              = AES_128_KEY_SIZE;
1774
        specs->block_size            = WC_AES_BLOCK_SIZE;
1775
        specs->iv_size               = AESGCM_IMP_IV_SZ;
1776
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
1777
1778
        if (opts != NULL)
1779
            opts->usingPSK_cipher    = 1;
1780
        break;
1781
#endif
1782
1783
#ifdef BUILD_TLS_DHE_PSK_WITH_AES_256_GCM_SHA384
1784
    case TLS_DHE_PSK_WITH_AES_256_GCM_SHA384 :
1785
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
1786
        specs->cipher_type           = aead;
1787
        specs->mac_algorithm         = sha384_mac;
1788
        specs->kea                   = dhe_psk_kea;
1789
        specs->sig_algo              = anonymous_sa_algo;
1790
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
1791
        specs->pad_size              = PAD_SHA;
1792
        specs->static_ecdh           = 0;
1793
        specs->key_size              = AES_256_KEY_SIZE;
1794
        specs->block_size            = WC_AES_BLOCK_SIZE;
1795
        specs->iv_size               = AESGCM_IMP_IV_SZ;
1796
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
1797
1798
        if (opts != NULL)
1799
            opts->usingPSK_cipher    = 1;
1800
        break;
1801
#endif
1802
1803
#ifdef BUILD_TLS_PSK_WITH_AES_128_CBC_SHA256
1804
    case TLS_PSK_WITH_AES_128_CBC_SHA256 :
1805
        specs->bulk_cipher_algorithm = wolfssl_aes;
1806
        specs->cipher_type           = block;
1807
        specs->mac_algorithm         = sha256_mac;
1808
        specs->kea                   = psk_kea;
1809
        specs->sig_algo              = anonymous_sa_algo;
1810
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1811
        specs->pad_size              = PAD_SHA;
1812
        specs->static_ecdh           = 0;
1813
        specs->key_size              = AES_128_KEY_SIZE;
1814
        specs->block_size            = WC_AES_BLOCK_SIZE;
1815
        specs->iv_size               = AES_IV_SIZE;
1816
1817
        if (opts != NULL)
1818
            opts->usingPSK_cipher    = 1;
1819
        break;
1820
#endif
1821
1822
#ifdef BUILD_TLS_PSK_WITH_AES_256_CBC_SHA384
1823
    case TLS_PSK_WITH_AES_256_CBC_SHA384 :
1824
        specs->bulk_cipher_algorithm = wolfssl_aes;
1825
        specs->cipher_type           = block;
1826
        specs->mac_algorithm         = sha384_mac;
1827
        specs->kea                   = psk_kea;
1828
        specs->sig_algo              = anonymous_sa_algo;
1829
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
1830
        specs->pad_size              = PAD_SHA;
1831
        specs->static_ecdh           = 0;
1832
        specs->key_size              = AES_256_KEY_SIZE;
1833
        specs->block_size            = WC_AES_BLOCK_SIZE;
1834
        specs->iv_size               = AES_IV_SIZE;
1835
1836
        if (opts != NULL)
1837
            opts->usingPSK_cipher    = 1;
1838
        break;
1839
#endif
1840
1841
#ifdef BUILD_TLS_DHE_PSK_WITH_AES_128_CBC_SHA256
1842
    case TLS_DHE_PSK_WITH_AES_128_CBC_SHA256 :
1843
        specs->bulk_cipher_algorithm = wolfssl_aes;
1844
        specs->cipher_type           = block;
1845
        specs->mac_algorithm         = sha256_mac;
1846
        specs->kea                   = dhe_psk_kea;
1847
        specs->sig_algo              = anonymous_sa_algo;
1848
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1849
        specs->pad_size              = PAD_SHA;
1850
        specs->static_ecdh           = 0;
1851
        specs->key_size              = AES_128_KEY_SIZE;
1852
        specs->block_size            = WC_AES_BLOCK_SIZE;
1853
        specs->iv_size               = AES_IV_SIZE;
1854
1855
        if (opts != NULL)
1856
            opts->usingPSK_cipher    = 1;
1857
        break;
1858
#endif
1859
1860
#ifdef BUILD_TLS_DHE_PSK_WITH_AES_256_CBC_SHA384
1861
    case TLS_DHE_PSK_WITH_AES_256_CBC_SHA384 :
1862
        specs->bulk_cipher_algorithm = wolfssl_aes;
1863
        specs->cipher_type           = block;
1864
        specs->mac_algorithm         = sha384_mac;
1865
        specs->kea                   = dhe_psk_kea;
1866
        specs->sig_algo              = anonymous_sa_algo;
1867
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
1868
        specs->pad_size              = PAD_SHA;
1869
        specs->static_ecdh           = 0;
1870
        specs->key_size              = AES_256_KEY_SIZE;
1871
        specs->block_size            = WC_AES_BLOCK_SIZE;
1872
        specs->iv_size               = AES_IV_SIZE;
1873
1874
        if (opts != NULL)
1875
            opts->usingPSK_cipher    = 1;
1876
        break;
1877
#endif
1878
1879
#ifdef BUILD_TLS_PSK_WITH_AES_128_CBC_SHA
1880
    case TLS_PSK_WITH_AES_128_CBC_SHA :
1881
        specs->bulk_cipher_algorithm = wolfssl_aes;
1882
        specs->cipher_type           = block;
1883
        specs->mac_algorithm         = sha_mac;
1884
        specs->kea                   = psk_kea;
1885
        specs->sig_algo              = anonymous_sa_algo;
1886
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
1887
        specs->pad_size              = PAD_SHA;
1888
        specs->static_ecdh           = 0;
1889
        specs->key_size              = AES_128_KEY_SIZE;
1890
        specs->block_size            = WC_AES_BLOCK_SIZE;
1891
        specs->iv_size               = AES_IV_SIZE;
1892
1893
        if (opts != NULL)
1894
            opts->usingPSK_cipher    = 1;
1895
        break;
1896
#endif
1897
1898
#ifdef BUILD_TLS_PSK_WITH_AES_256_CBC_SHA
1899
    case TLS_PSK_WITH_AES_256_CBC_SHA :
1900
        specs->bulk_cipher_algorithm = wolfssl_aes;
1901
        specs->cipher_type           = block;
1902
        specs->mac_algorithm         = sha_mac;
1903
        specs->kea                   = psk_kea;
1904
        specs->sig_algo              = anonymous_sa_algo;
1905
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
1906
        specs->pad_size              = PAD_SHA;
1907
        specs->static_ecdh           = 0;
1908
        specs->key_size              = AES_256_KEY_SIZE;
1909
        specs->block_size            = WC_AES_BLOCK_SIZE;
1910
        specs->iv_size               = AES_IV_SIZE;
1911
1912
        if (opts != NULL)
1913
            opts->usingPSK_cipher    = 1;
1914
        break;
1915
#endif
1916
1917
#ifdef BUILD_TLS_PSK_WITH_NULL_SHA256
1918
    case TLS_PSK_WITH_NULL_SHA256 :
1919
        specs->bulk_cipher_algorithm = wolfssl_cipher_null;
1920
        specs->cipher_type           = stream;
1921
        specs->mac_algorithm         = sha256_mac;
1922
        specs->kea                   = psk_kea;
1923
        specs->sig_algo              = anonymous_sa_algo;
1924
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1925
        specs->pad_size              = PAD_SHA;
1926
        specs->static_ecdh           = 0;
1927
        specs->key_size              = 0;
1928
        specs->block_size            = 0;
1929
        specs->iv_size               = 0;
1930
1931
        if (opts != NULL)
1932
            opts->usingPSK_cipher    = 1;
1933
        break;
1934
#endif
1935
1936
#ifdef BUILD_TLS_PSK_WITH_NULL_SHA384
1937
    case TLS_PSK_WITH_NULL_SHA384 :
1938
        specs->bulk_cipher_algorithm = wolfssl_cipher_null;
1939
        specs->cipher_type           = stream;
1940
        specs->mac_algorithm         = sha384_mac;
1941
        specs->kea                   = psk_kea;
1942
        specs->sig_algo              = anonymous_sa_algo;
1943
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
1944
        specs->pad_size              = PAD_SHA;
1945
        specs->static_ecdh           = 0;
1946
        specs->key_size              = 0;
1947
        specs->block_size            = 0;
1948
        specs->iv_size               = 0;
1949
1950
        if (opts != NULL)
1951
            opts->usingPSK_cipher    = 1;
1952
        break;
1953
#endif
1954
1955
#ifdef BUILD_TLS_PSK_WITH_NULL_SHA
1956
    case TLS_PSK_WITH_NULL_SHA :
1957
        specs->bulk_cipher_algorithm = wolfssl_cipher_null;
1958
        specs->cipher_type           = stream;
1959
        specs->mac_algorithm         = sha_mac;
1960
        specs->kea                   = psk_kea;
1961
        specs->sig_algo              = anonymous_sa_algo;
1962
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
1963
        specs->pad_size              = PAD_SHA;
1964
        specs->static_ecdh           = 0;
1965
        specs->key_size              = 0;
1966
        specs->block_size            = 0;
1967
        specs->iv_size               = 0;
1968
1969
        if (opts != NULL)
1970
            opts->usingPSK_cipher    = 1;
1971
        break;
1972
#endif
1973
1974
#ifdef BUILD_TLS_DHE_PSK_WITH_NULL_SHA256
1975
    case TLS_DHE_PSK_WITH_NULL_SHA256 :
1976
        specs->bulk_cipher_algorithm = wolfssl_cipher_null;
1977
        specs->cipher_type           = stream;
1978
        specs->mac_algorithm         = sha256_mac;
1979
        specs->kea                   = dhe_psk_kea;
1980
        specs->sig_algo              = anonymous_sa_algo;
1981
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
1982
        specs->pad_size              = PAD_SHA;
1983
        specs->static_ecdh           = 0;
1984
        specs->key_size              = 0;
1985
        specs->block_size            = 0;
1986
        specs->iv_size               = 0;
1987
1988
        if (opts != NULL)
1989
            opts->usingPSK_cipher    = 1;
1990
        break;
1991
#endif
1992
1993
#ifdef BUILD_TLS_DHE_PSK_WITH_NULL_SHA384
1994
    case TLS_DHE_PSK_WITH_NULL_SHA384 :
1995
        specs->bulk_cipher_algorithm = wolfssl_cipher_null;
1996
        specs->cipher_type           = stream;
1997
        specs->mac_algorithm         = sha384_mac;
1998
        specs->kea                   = dhe_psk_kea;
1999
        specs->sig_algo              = anonymous_sa_algo;
2000
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
2001
        specs->pad_size              = PAD_SHA;
2002
        specs->static_ecdh           = 0;
2003
        specs->key_size              = 0;
2004
        specs->block_size            = 0;
2005
        specs->iv_size               = 0;
2006
2007
        if (opts != NULL)
2008
            opts->usingPSK_cipher    = 1;
2009
        break;
2010
#endif
2011
2012
0
#ifdef BUILD_TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
2013
0
    case TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 :
2014
0
        specs->bulk_cipher_algorithm = wolfssl_aes;
2015
0
        specs->cipher_type           = block;
2016
0
        specs->mac_algorithm         = sha256_mac;
2017
0
        specs->kea                   = diffie_hellman_kea;
2018
0
        specs->sig_algo              = rsa_sa_algo;
2019
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
2020
0
        specs->pad_size              = PAD_SHA;
2021
0
        specs->static_ecdh           = 0;
2022
0
        specs->key_size              = AES_128_KEY_SIZE;
2023
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
2024
0
        specs->iv_size               = AES_IV_SIZE;
2025
2026
0
        break;
2027
0
#endif
2028
2029
#ifdef BUILD_TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA
2030
    case TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA :
2031
        specs->bulk_cipher_algorithm = wolfssl_triple_des;
2032
        specs->cipher_type           = block;
2033
        specs->mac_algorithm         = sha_mac;
2034
        specs->kea                   = diffie_hellman_kea;
2035
        specs->sig_algo              = rsa_sa_algo;
2036
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
2037
        specs->pad_size              = PAD_SHA;
2038
        specs->static_ecdh           = 0;
2039
        specs->key_size              = DES3_KEY_SIZE;
2040
        specs->block_size            = DES_BLOCK_SIZE;
2041
        specs->iv_size               = DES_IV_SIZE;
2042
2043
        break;
2044
#endif
2045
2046
0
#ifdef BUILD_TLS_DHE_RSA_WITH_AES_256_CBC_SHA256
2047
0
    case TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 :
2048
0
        specs->bulk_cipher_algorithm = wolfssl_aes;
2049
0
        specs->cipher_type           = block;
2050
0
        specs->mac_algorithm         = sha256_mac;
2051
0
        specs->kea                   = diffie_hellman_kea;
2052
0
        specs->sig_algo              = rsa_sa_algo;
2053
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
2054
0
        specs->pad_size              = PAD_SHA;
2055
0
        specs->static_ecdh           = 0;
2056
0
        specs->key_size              = AES_256_KEY_SIZE;
2057
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
2058
0
        specs->iv_size               = AES_IV_SIZE;
2059
2060
0
        break;
2061
0
#endif
2062
2063
0
#ifdef BUILD_TLS_DHE_RSA_WITH_AES_128_CBC_SHA
2064
0
    case TLS_DHE_RSA_WITH_AES_128_CBC_SHA :
2065
0
        specs->bulk_cipher_algorithm = wolfssl_aes;
2066
0
        specs->cipher_type           = block;
2067
0
        specs->mac_algorithm         = sha_mac;
2068
0
        specs->kea                   = diffie_hellman_kea;
2069
0
        specs->sig_algo              = rsa_sa_algo;
2070
0
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
2071
0
        specs->pad_size              = PAD_SHA;
2072
0
        specs->static_ecdh           = 0;
2073
0
        specs->key_size              = AES_128_KEY_SIZE;
2074
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
2075
0
        specs->iv_size               = AES_IV_SIZE;
2076
2077
0
        break;
2078
0
#endif
2079
2080
0
#ifdef BUILD_TLS_DHE_RSA_WITH_AES_256_CBC_SHA
2081
0
    case TLS_DHE_RSA_WITH_AES_256_CBC_SHA :
2082
0
        specs->bulk_cipher_algorithm = wolfssl_aes;
2083
0
        specs->cipher_type           = block;
2084
0
        specs->mac_algorithm         = sha_mac;
2085
0
        specs->kea                   = diffie_hellman_kea;
2086
0
        specs->sig_algo              = rsa_sa_algo;
2087
0
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
2088
0
        specs->pad_size              = PAD_SHA;
2089
0
        specs->static_ecdh           = 0;
2090
0
        specs->key_size              = AES_256_KEY_SIZE;
2091
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
2092
0
        specs->iv_size               = AES_IV_SIZE;
2093
2094
0
        break;
2095
0
#endif
2096
2097
#ifdef BUILD_TLS_RSA_WITH_AES_128_GCM_SHA256
2098
    case TLS_RSA_WITH_AES_128_GCM_SHA256 :
2099
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
2100
        specs->cipher_type           = aead;
2101
        specs->mac_algorithm         = sha256_mac;
2102
        specs->kea                   = rsa_kea;
2103
        specs->sig_algo              = rsa_sa_algo;
2104
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
2105
        specs->pad_size              = PAD_SHA;
2106
        specs->static_ecdh           = 0;
2107
        specs->key_size              = AES_128_KEY_SIZE;
2108
        specs->block_size            = WC_AES_BLOCK_SIZE;
2109
        specs->iv_size               = AESGCM_IMP_IV_SZ;
2110
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
2111
2112
        break;
2113
#endif
2114
2115
#ifdef BUILD_TLS_RSA_WITH_AES_256_GCM_SHA384
2116
    case TLS_RSA_WITH_AES_256_GCM_SHA384 :
2117
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
2118
        specs->cipher_type           = aead;
2119
        specs->mac_algorithm         = sha384_mac;
2120
        specs->kea                   = rsa_kea;
2121
        specs->sig_algo              = rsa_sa_algo;
2122
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
2123
        specs->pad_size              = PAD_SHA;
2124
        specs->static_ecdh           = 0;
2125
        specs->key_size              = AES_256_KEY_SIZE;
2126
        specs->block_size            = WC_AES_BLOCK_SIZE;
2127
        specs->iv_size               = AESGCM_IMP_IV_SZ;
2128
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
2129
2130
        break;
2131
#endif
2132
2133
0
#ifdef BUILD_TLS_DHE_RSA_WITH_AES_128_GCM_SHA256
2134
0
    case TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 :
2135
0
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
2136
0
        specs->cipher_type           = aead;
2137
0
        specs->mac_algorithm         = sha256_mac;
2138
0
        specs->kea                   = diffie_hellman_kea;
2139
0
        specs->sig_algo              = rsa_sa_algo;
2140
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
2141
0
        specs->pad_size              = PAD_SHA;
2142
0
        specs->static_ecdh           = 0;
2143
0
        specs->key_size              = AES_128_KEY_SIZE;
2144
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
2145
0
        specs->iv_size               = AESGCM_IMP_IV_SZ;
2146
0
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
2147
2148
0
        break;
2149
0
#endif
2150
2151
0
#ifdef BUILD_TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
2152
0
    case TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 :
2153
0
        specs->bulk_cipher_algorithm = wolfssl_aes_gcm;
2154
0
        specs->cipher_type           = aead;
2155
0
        specs->mac_algorithm         = sha384_mac;
2156
0
        specs->kea                   = diffie_hellman_kea;
2157
0
        specs->sig_algo              = rsa_sa_algo;
2158
0
        specs->hash_size             = WC_SHA384_DIGEST_SIZE;
2159
0
        specs->pad_size              = PAD_SHA;
2160
0
        specs->static_ecdh           = 0;
2161
0
        specs->key_size              = AES_256_KEY_SIZE;
2162
0
        specs->block_size            = WC_AES_BLOCK_SIZE;
2163
0
        specs->iv_size               = AESGCM_IMP_IV_SZ;
2164
0
        specs->aead_mac_size         = AES_GCM_AUTH_SZ;
2165
2166
0
        break;
2167
0
#endif
2168
2169
#ifdef BUILD_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA
2170
    case TLS_RSA_WITH_CAMELLIA_128_CBC_SHA :
2171
        specs->bulk_cipher_algorithm = wolfssl_camellia;
2172
        specs->cipher_type           = block;
2173
        specs->mac_algorithm         = sha_mac;
2174
        specs->kea                   = rsa_kea;
2175
        specs->sig_algo              = rsa_sa_algo;
2176
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
2177
        specs->pad_size              = PAD_SHA;
2178
        specs->static_ecdh           = 0;
2179
        specs->key_size              = CAMELLIA_128_KEY_SIZE;
2180
        specs->block_size            = WC_CAMELLIA_BLOCK_SIZE;
2181
        specs->iv_size               = CAMELLIA_IV_SIZE;
2182
2183
        break;
2184
#endif
2185
2186
#ifdef BUILD_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA
2187
    case TLS_RSA_WITH_CAMELLIA_256_CBC_SHA :
2188
        specs->bulk_cipher_algorithm = wolfssl_camellia;
2189
        specs->cipher_type           = block;
2190
        specs->mac_algorithm         = sha_mac;
2191
        specs->kea                   = rsa_kea;
2192
        specs->sig_algo              = rsa_sa_algo;
2193
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
2194
        specs->pad_size              = PAD_SHA;
2195
        specs->static_ecdh           = 0;
2196
        specs->key_size              = CAMELLIA_256_KEY_SIZE;
2197
        specs->block_size            = WC_CAMELLIA_BLOCK_SIZE;
2198
        specs->iv_size               = CAMELLIA_IV_SIZE;
2199
2200
        break;
2201
#endif
2202
2203
#ifdef BUILD_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256
2204
    case TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256 :
2205
        specs->bulk_cipher_algorithm = wolfssl_camellia;
2206
        specs->cipher_type           = block;
2207
        specs->mac_algorithm         = sha256_mac;
2208
        specs->kea                   = rsa_kea;
2209
        specs->sig_algo              = rsa_sa_algo;
2210
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
2211
        specs->pad_size              = PAD_SHA;
2212
        specs->static_ecdh           = 0;
2213
        specs->key_size              = CAMELLIA_128_KEY_SIZE;
2214
        specs->block_size            = WC_CAMELLIA_BLOCK_SIZE;
2215
        specs->iv_size               = CAMELLIA_IV_SIZE;
2216
2217
        break;
2218
#endif
2219
2220
#ifdef BUILD_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256
2221
    case TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256 :
2222
        specs->bulk_cipher_algorithm = wolfssl_camellia;
2223
        specs->cipher_type           = block;
2224
        specs->mac_algorithm         = sha256_mac;
2225
        specs->kea                   = rsa_kea;
2226
        specs->sig_algo              = rsa_sa_algo;
2227
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
2228
        specs->pad_size              = PAD_SHA;
2229
        specs->static_ecdh           = 0;
2230
        specs->key_size              = CAMELLIA_256_KEY_SIZE;
2231
        specs->block_size            = WC_CAMELLIA_BLOCK_SIZE;
2232
        specs->iv_size               = CAMELLIA_IV_SIZE;
2233
2234
        break;
2235
#endif
2236
2237
0
#ifdef BUILD_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA
2238
0
    case TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA :
2239
0
        specs->bulk_cipher_algorithm = wolfssl_camellia;
2240
0
        specs->cipher_type           = block;
2241
0
        specs->mac_algorithm         = sha_mac;
2242
0
        specs->kea                   = diffie_hellman_kea;
2243
0
        specs->sig_algo              = rsa_sa_algo;
2244
0
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
2245
0
        specs->pad_size              = PAD_SHA;
2246
0
        specs->static_ecdh           = 0;
2247
0
        specs->key_size              = CAMELLIA_128_KEY_SIZE;
2248
0
        specs->block_size            = WC_CAMELLIA_BLOCK_SIZE;
2249
0
        specs->iv_size               = CAMELLIA_IV_SIZE;
2250
2251
0
        break;
2252
0
#endif
2253
2254
0
#ifdef BUILD_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA
2255
0
    case TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA :
2256
0
        specs->bulk_cipher_algorithm = wolfssl_camellia;
2257
0
        specs->cipher_type           = block;
2258
0
        specs->mac_algorithm         = sha_mac;
2259
0
        specs->kea                   = diffie_hellman_kea;
2260
0
        specs->sig_algo              = rsa_sa_algo;
2261
0
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
2262
0
        specs->pad_size              = PAD_SHA;
2263
0
        specs->static_ecdh           = 0;
2264
0
        specs->key_size              = CAMELLIA_256_KEY_SIZE;
2265
0
        specs->block_size            = WC_CAMELLIA_BLOCK_SIZE;
2266
0
        specs->iv_size               = CAMELLIA_IV_SIZE;
2267
2268
0
        break;
2269
0
#endif
2270
2271
0
#ifdef BUILD_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256
2272
0
    case TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 :
2273
0
        specs->bulk_cipher_algorithm = wolfssl_camellia;
2274
0
        specs->cipher_type           = block;
2275
0
        specs->mac_algorithm         = sha256_mac;
2276
0
        specs->kea                   = diffie_hellman_kea;
2277
0
        specs->sig_algo              = rsa_sa_algo;
2278
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
2279
0
        specs->pad_size              = PAD_SHA;
2280
0
        specs->static_ecdh           = 0;
2281
0
        specs->key_size              = CAMELLIA_128_KEY_SIZE;
2282
0
        specs->block_size            = WC_CAMELLIA_BLOCK_SIZE;
2283
0
        specs->iv_size               = CAMELLIA_IV_SIZE;
2284
2285
0
        break;
2286
0
#endif
2287
2288
0
#ifdef BUILD_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256
2289
0
    case TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256 :
2290
0
        specs->bulk_cipher_algorithm = wolfssl_camellia;
2291
0
        specs->cipher_type           = block;
2292
0
        specs->mac_algorithm         = sha256_mac;
2293
0
        specs->kea                   = diffie_hellman_kea;
2294
0
        specs->sig_algo              = rsa_sa_algo;
2295
0
        specs->hash_size             = WC_SHA256_DIGEST_SIZE;
2296
0
        specs->pad_size              = PAD_SHA;
2297
0
        specs->static_ecdh           = 0;
2298
0
        specs->key_size              = CAMELLIA_256_KEY_SIZE;
2299
0
        specs->block_size            = WC_CAMELLIA_BLOCK_SIZE;
2300
0
        specs->iv_size               = CAMELLIA_IV_SIZE;
2301
2302
0
        break;
2303
0
#endif
2304
2305
#ifdef BUILD_TLS_DH_anon_WITH_AES_128_CBC_SHA
2306
    case TLS_DH_anon_WITH_AES_128_CBC_SHA :
2307
        specs->bulk_cipher_algorithm = wolfssl_aes;
2308
        specs->cipher_type           = block;
2309
        specs->mac_algorithm         = sha_mac;
2310
        specs->kea                   = diffie_hellman_kea;
2311
        specs->sig_algo              = anonymous_sa_algo;
2312
        specs->hash_size             = WC_SHA_DIGEST_SIZE;
2313
        specs->pad_size              = PAD_SHA;
2314
        specs->static_ecdh           = 0;
2315
        specs->key_size              = AES_128_KEY_SIZE;
2316
        specs->block_size            = WC_AES_BLOCK_SIZE;
2317
        specs->iv_size               = AES_IV_SIZE;
2318
2319
        if (opts != NULL)
2320
            opts->usingAnon_cipher   = 1;
2321
        break;
2322
#endif
2323
2324
#ifdef BUILD_WDM_WITH_NULL_SHA256
2325
        case WDM_WITH_NULL_SHA256 :
2326
            specs->bulk_cipher_algorithm = wolfssl_cipher_null;
2327
            specs->cipher_type           = stream;
2328
            specs->mac_algorithm         = sha256_mac;
2329
            specs->kea                   = no_kea;
2330
            specs->sig_algo              = anonymous_sa_algo;
2331
            specs->hash_size             = WC_SHA256_DIGEST_SIZE;
2332
            specs->pad_size              = PAD_SHA;
2333
2334
            break;
2335
#endif
2336
2337
0
    default:
2338
0
        WOLFSSL_MSG("Unsupported cipher suite, SetCipherSpecs");
2339
0
        WOLFSSL_ERROR_VERBOSE(UNSUPPORTED_SUITE);
2340
0
        return UNSUPPORTED_SUITE;
2341
0
    }  /* switch */
2342
0
    }  /* if ECC / Normal suites else */
2343
2344
0
    if (specs->sig_algo == anonymous_sa_algo && opts != NULL) {
2345
        /* CLIENT/SERVER: No peer authentication to be performed. */
2346
0
        opts->peerAuthGood = 1;
2347
0
    }
2348
2349
0
    return 0;
2350
0
}
2351
2352
2353
enum KeyStuff {
2354
    MASTER_ROUNDS = 3,
2355
    PREFIX        = 3,     /* up to three letters for master prefix */
2356
    KEY_PREFIX    = 9      /* up to 9 prefix letters for key rounds */
2357
2358
2359
};
2360
2361
#ifndef NO_OLD_TLS
2362
/* true or false, zero for error */
2363
static int SetPrefix(byte* sha_input, int idx)
2364
{
2365
    switch (idx) {
2366
    case 0:
2367
        XMEMCPY(sha_input, "A", 1);
2368
        break;
2369
    case 1:
2370
        XMEMCPY(sha_input, "BB", 2);
2371
        break;
2372
    case 2:
2373
        XMEMCPY(sha_input, "CCC", 3);
2374
        break;
2375
    case 3:
2376
        XMEMCPY(sha_input, "DDDD", 4);
2377
        break;
2378
    case 4:
2379
        XMEMCPY(sha_input, "EEEEE", 5);
2380
        break;
2381
    case 5:
2382
        XMEMCPY(sha_input, "FFFFFF", 6);
2383
        break;
2384
    case 6:
2385
        XMEMCPY(sha_input, "GGGGGGG", 7);
2386
        break;
2387
    case 7:
2388
        XMEMCPY(sha_input, "HHHHHHHH", 8);
2389
        break;
2390
    case 8:
2391
        XMEMCPY(sha_input, "IIIIIIIII", 9);
2392
        break;
2393
    default:
2394
        WOLFSSL_MSG("Set Prefix error, bad input");
2395
        return 0;
2396
    }
2397
    return 1;
2398
}
2399
#endif
2400
2401
2402
int SetKeys(Ciphers* enc, Ciphers* dec, Keys* keys, CipherSpecs* specs,
2403
                   int side, void* heap, int devId, WC_RNG* rng, int tls13)
2404
{
2405
    (void)rng;
2406
    (void)tls13;
2407
2408
#ifdef BUILD_ARC4
2409
    if (specs->bulk_cipher_algorithm == wolfssl_rc4) {
2410
        word32 sz = specs->key_size;
2411
        if (enc && enc->arc4 == NULL) {
2412
            enc->arc4 = (Arc4*)XMALLOC(sizeof(Arc4), heap, DYNAMIC_TYPE_CIPHER);
2413
            if (enc->arc4 == NULL)
2414
                 return MEMORY_E;
2415
        }
2416
        if (dec && dec->arc4 == NULL) {
2417
            dec->arc4 = (Arc4*)XMALLOC(sizeof(Arc4), heap, DYNAMIC_TYPE_CIPHER);
2418
            if (dec->arc4 == NULL)
2419
                return MEMORY_E;
2420
        }
2421
2422
        if (enc) {
2423
            if (wc_Arc4Init(enc->arc4, heap, devId) != 0) {
2424
                WOLFSSL_MSG("Arc4Init failed in SetKeys");
2425
                return ASYNC_INIT_E;
2426
            }
2427
        }
2428
        if (dec) {
2429
            if (wc_Arc4Init(dec->arc4, heap, devId) != 0) {
2430
                WOLFSSL_MSG("Arc4Init failed in SetKeys");
2431
                return ASYNC_INIT_E;
2432
            }
2433
        }
2434
2435
        if (side == WOLFSSL_CLIENT_END) {
2436
            if (enc)
2437
                wc_Arc4SetKey(enc->arc4, keys->client_write_key, sz);
2438
            if (dec)
2439
                wc_Arc4SetKey(dec->arc4, keys->server_write_key, sz);
2440
        }
2441
        else {
2442
            if (enc)
2443
                wc_Arc4SetKey(enc->arc4, keys->server_write_key, sz);
2444
            if (dec)
2445
                wc_Arc4SetKey(dec->arc4, keys->client_write_key, sz);
2446
        }
2447
        if (enc)
2448
            enc->setup = 1;
2449
        if (dec)
2450
            dec->setup = 1;
2451
    }
2452
#endif /* BUILD_ARC4 */
2453
2454
2455
#if defined(HAVE_CHACHA) && defined(HAVE_POLY1305) && !defined(NO_CHAPOL_AEAD)
2456
    /* Check that the max implicit iv size is sufficient */
2457
    #if (AEAD_MAX_IMP_SZ < 12) /* CHACHA20_IMP_IV_SZ */
2458
        #error AEAD_MAX_IMP_SZ is too small for ChaCha20
2459
    #endif
2460
    #if (MAX_WRITE_IV_SZ < 12) /* CHACHA20_IMP_IV_SZ */
2461
        #error MAX_WRITE_IV_SZ is too small for ChaCha20
2462
    #endif
2463
2464
    if (specs->bulk_cipher_algorithm == wolfssl_chacha) {
2465
        int chachaRet;
2466
        if (enc && enc->chacha == NULL)
2467
            enc->chacha =
2468
                    (ChaCha*)XMALLOC(sizeof(ChaCha), heap, DYNAMIC_TYPE_CIPHER);
2469
        if (enc && enc->chacha == NULL)
2470
            return MEMORY_E;
2471
    #ifdef WOLFSSL_CHECK_MEM_ZERO
2472
        if (enc) {
2473
            wc_MemZero_Add("SSL keys enc chacha", enc->chacha, sizeof(ChaCha));
2474
        }
2475
    #endif
2476
        if (dec && dec->chacha == NULL)
2477
            dec->chacha =
2478
                    (ChaCha*)XMALLOC(sizeof(ChaCha), heap, DYNAMIC_TYPE_CIPHER);
2479
        if (dec && dec->chacha == NULL)
2480
            return MEMORY_E;
2481
    #ifdef WOLFSSL_CHECK_MEM_ZERO
2482
        if (dec) {
2483
            wc_MemZero_Add("SSL keys dec chacha", dec->chacha, sizeof(ChaCha));
2484
        }
2485
    #endif
2486
        if (side == WOLFSSL_CLIENT_END) {
2487
            if (enc) {
2488
                chachaRet = wc_Chacha_SetKey(enc->chacha, keys->client_write_key,
2489
                                          specs->key_size);
2490
                XMEMCPY(keys->aead_enc_imp_IV, keys->client_write_IV,
2491
                        CHACHA20_IMP_IV_SZ);
2492
                if (chachaRet != 0) return chachaRet;
2493
            }
2494
            if (dec) {
2495
                chachaRet = wc_Chacha_SetKey(dec->chacha, keys->server_write_key,
2496
                                          specs->key_size);
2497
                XMEMCPY(keys->aead_dec_imp_IV, keys->server_write_IV,
2498
                        CHACHA20_IMP_IV_SZ);
2499
                if (chachaRet != 0) return chachaRet;
2500
            }
2501
        }
2502
        else {
2503
            if (enc) {
2504
                chachaRet = wc_Chacha_SetKey(enc->chacha, keys->server_write_key,
2505
                                          specs->key_size);
2506
                XMEMCPY(keys->aead_enc_imp_IV, keys->server_write_IV,
2507
                        CHACHA20_IMP_IV_SZ);
2508
                if (chachaRet != 0) return chachaRet;
2509
            }
2510
            if (dec) {
2511
                chachaRet = wc_Chacha_SetKey(dec->chacha, keys->client_write_key,
2512
                                          specs->key_size);
2513
                XMEMCPY(keys->aead_dec_imp_IV, keys->client_write_IV,
2514
                        CHACHA20_IMP_IV_SZ);
2515
                if (chachaRet != 0) return chachaRet;
2516
            }
2517
        }
2518
2519
        if (enc)
2520
            enc->setup = 1;
2521
        if (dec)
2522
            dec->setup = 1;
2523
    }
2524
#endif /* HAVE_CHACHA && HAVE_POLY1305 */
2525
2526
#ifdef BUILD_DES3
2527
    /* check that buffer sizes are sufficient */
2528
    #if (MAX_WRITE_IV_SZ < 8) /* DES_IV_SIZE */
2529
        #error MAX_WRITE_IV_SZ too small for 3DES
2530
    #endif
2531
2532
    if (specs->bulk_cipher_algorithm == wolfssl_triple_des) {
2533
        int desRet = 0;
2534
2535
        if (enc) {
2536
            if (enc->des3 == NULL)
2537
                enc->des3 = (Des3*)XMALLOC(sizeof(Des3), heap, DYNAMIC_TYPE_CIPHER);
2538
            if (enc->des3 == NULL)
2539
                return MEMORY_E;
2540
            XMEMSET(enc->des3, 0, sizeof(Des3));
2541
        }
2542
        if (dec) {
2543
            if (dec->des3 == NULL)
2544
                dec->des3 = (Des3*)XMALLOC(sizeof(Des3), heap, DYNAMIC_TYPE_CIPHER);
2545
            if (dec->des3 == NULL)
2546
                return MEMORY_E;
2547
            XMEMSET(dec->des3, 0, sizeof(Des3));
2548
        }
2549
2550
        if (enc) {
2551
            if (wc_Des3Init(enc->des3, heap, devId) != 0) {
2552
                WOLFSSL_MSG("Des3Init failed in SetKeys");
2553
                return ASYNC_INIT_E;
2554
            }
2555
        }
2556
        if (dec) {
2557
            if (wc_Des3Init(dec->des3, heap, devId) != 0) {
2558
                WOLFSSL_MSG("Des3Init failed in SetKeys");
2559
                return ASYNC_INIT_E;
2560
            }
2561
        }
2562
2563
        if (side == WOLFSSL_CLIENT_END) {
2564
            if (enc) {
2565
                desRet = wc_Des3_SetKey(enc->des3, keys->client_write_key,
2566
                                     keys->client_write_IV, DES_ENCRYPTION);
2567
                if (desRet != 0) return desRet;
2568
            }
2569
            if (dec) {
2570
                desRet = wc_Des3_SetKey(dec->des3, keys->server_write_key,
2571
                                     keys->server_write_IV, DES_DECRYPTION);
2572
                if (desRet != 0) return desRet;
2573
            }
2574
        }
2575
        else {
2576
            if (enc) {
2577
                desRet = wc_Des3_SetKey(enc->des3, keys->server_write_key,
2578
                                     keys->server_write_IV, DES_ENCRYPTION);
2579
                if (desRet != 0) return desRet;
2580
            }
2581
            if (dec) {
2582
                desRet = wc_Des3_SetKey(dec->des3, keys->client_write_key,
2583
                                     keys->client_write_IV, DES_DECRYPTION);
2584
                if (desRet != 0) return desRet;
2585
            }
2586
        }
2587
        if (enc)
2588
            enc->setup = 1;
2589
        if (dec)
2590
            dec->setup = 1;
2591
    }
2592
#endif /* BUILD_DES3 */
2593
2594
#ifdef BUILD_AES
2595
    /* check that buffer sizes are sufficient */
2596
    #if (MAX_WRITE_IV_SZ < 16) /* AES_IV_SIZE */
2597
        #error MAX_WRITE_IV_SZ too small for AES
2598
    #endif
2599
2600
    if (specs->bulk_cipher_algorithm == wolfssl_aes) {
2601
        int aesRet = 0;
2602
2603
        if (enc) {
2604
            if (enc->aes == NULL) {
2605
                enc->aes = (Aes*)XMALLOC(sizeof(Aes), heap, DYNAMIC_TYPE_CIPHER);
2606
                if (enc->aes == NULL)
2607
                    return MEMORY_E;
2608
            } else {
2609
                wc_AesFree(enc->aes);
2610
            }
2611
2612
            XMEMSET(enc->aes, 0, sizeof(Aes));
2613
        }
2614
        if (dec) {
2615
            if (dec->aes == NULL) {
2616
                dec->aes = (Aes*)XMALLOC(sizeof(Aes), heap, DYNAMIC_TYPE_CIPHER);
2617
                if (dec->aes == NULL)
2618
                    return MEMORY_E;
2619
            } else {
2620
                wc_AesFree(dec->aes);
2621
            }
2622
2623
            XMEMSET(dec->aes, 0, sizeof(Aes));
2624
        }
2625
        if (enc) {
2626
            if (wc_AesInit(enc->aes, heap, devId) != 0) {
2627
                WOLFSSL_MSG("AesInit failed in SetKeys");
2628
                return ASYNC_INIT_E;
2629
            }
2630
        }
2631
        if (dec) {
2632
            if (wc_AesInit(dec->aes, heap, devId) != 0) {
2633
                WOLFSSL_MSG("AesInit failed in SetKeys");
2634
                return ASYNC_INIT_E;
2635
            }
2636
        }
2637
2638
        if (side == WOLFSSL_CLIENT_END) {
2639
            if (enc) {
2640
                aesRet = wc_AesSetKey(enc->aes, keys->client_write_key,
2641
                                   specs->key_size, keys->client_write_IV,
2642
                                   AES_ENCRYPTION);
2643
                if (aesRet != 0) return aesRet;
2644
            }
2645
            if (dec) {
2646
                aesRet = wc_AesSetKey(dec->aes, keys->server_write_key,
2647
                                   specs->key_size, keys->server_write_IV,
2648
                                   AES_DECRYPTION);
2649
                if (aesRet != 0) return aesRet;
2650
            }
2651
        }
2652
        else {
2653
            if (enc) {
2654
                aesRet = wc_AesSetKey(enc->aes, keys->server_write_key,
2655
                                   specs->key_size, keys->server_write_IV,
2656
                                   AES_ENCRYPTION);
2657
                if (aesRet != 0) return aesRet;
2658
            }
2659
            if (dec) {
2660
                aesRet = wc_AesSetKey(dec->aes, keys->client_write_key,
2661
                                   specs->key_size, keys->client_write_IV,
2662
                                   AES_DECRYPTION);
2663
                if (aesRet != 0) return aesRet;
2664
            }
2665
        }
2666
        if (enc)
2667
            enc->setup = 1;
2668
        if (dec)
2669
            dec->setup = 1;
2670
    }
2671
#endif /* BUILD_AES */
2672
2673
#ifdef BUILD_AESGCM
2674
    /* check that buffer sizes are sufficient */
2675
    #if (AEAD_MAX_IMP_SZ < 4) /* AESGCM_IMP_IV_SZ */
2676
        #error AEAD_MAX_IMP_SZ too small for AESGCM
2677
    #endif
2678
    #if (AEAD_MAX_EXP_SZ < 8) /* AESGCM_EXP_IV_SZ */
2679
        #error AEAD_MAX_EXP_SZ too small for AESGCM
2680
    #endif
2681
    #if (MAX_WRITE_IV_SZ < 4) /* AESGCM_IMP_IV_SZ */
2682
        #error MAX_WRITE_IV_SZ too small for AESGCM
2683
    #endif
2684
2685
    if (specs->bulk_cipher_algorithm == wolfssl_aes_gcm) {
2686
        int gcmRet;
2687
2688
        if (enc) {
2689
            if (enc->aes == NULL) {
2690
                enc->aes = (Aes*)XMALLOC(sizeof(Aes), heap, DYNAMIC_TYPE_CIPHER);
2691
                if (enc->aes == NULL)
2692
                    return MEMORY_E;
2693
            } else {
2694
                wc_AesFree(enc->aes);
2695
            }
2696
2697
            XMEMSET(enc->aes, 0, sizeof(Aes));
2698
        }
2699
        if (dec) {
2700
            if (dec->aes == NULL) {
2701
                dec->aes = (Aes*)XMALLOC(sizeof(Aes), heap, DYNAMIC_TYPE_CIPHER);
2702
                if (dec->aes == NULL)
2703
                    return MEMORY_E;
2704
            } else {
2705
                wc_AesFree(dec->aes);
2706
            }
2707
2708
            XMEMSET(dec->aes, 0, sizeof(Aes));
2709
        }
2710
2711
        if (enc) {
2712
            if (wc_AesInit(enc->aes, heap, devId) != 0) {
2713
                WOLFSSL_MSG("AesInit failed in SetKeys");
2714
                return ASYNC_INIT_E;
2715
            }
2716
        }
2717
        if (dec) {
2718
            if (wc_AesInit(dec->aes, heap, devId) != 0) {
2719
                WOLFSSL_MSG("AesInit failed in SetKeys");
2720
                return ASYNC_INIT_E;
2721
            }
2722
        }
2723
2724
        if (side == WOLFSSL_CLIENT_END) {
2725
            if (enc) {
2726
                gcmRet = wc_AesGcmSetKey(enc->aes, keys->client_write_key,
2727
                                      specs->key_size);
2728
                if (gcmRet != 0) return gcmRet;
2729
                XMEMCPY(keys->aead_enc_imp_IV, keys->client_write_IV,
2730
                        AEAD_MAX_IMP_SZ);
2731
#if !defined(NO_PUBLIC_GCM_SET_IV) && \
2732
    ((!defined(HAVE_FIPS) && !defined(HAVE_SELFTEST)) || \
2733
    (defined(HAVE_FIPS_VERSION) && (HAVE_FIPS_VERSION >= 2)))
2734
                if (!tls13) {
2735
                    gcmRet = wc_AesGcmSetIV(enc->aes, AESGCM_NONCE_SZ,
2736
                            keys->client_write_IV, AESGCM_IMP_IV_SZ, rng);
2737
                    if (gcmRet != 0) return gcmRet;
2738
                }
2739
#endif
2740
            }
2741
            if (dec) {
2742
                gcmRet = wc_AesGcmSetKey(dec->aes, keys->server_write_key,
2743
                                      specs->key_size);
2744
                if (gcmRet != 0) return gcmRet;
2745
                XMEMCPY(keys->aead_dec_imp_IV, keys->server_write_IV,
2746
                        AEAD_MAX_IMP_SZ);
2747
            }
2748
        }
2749
        else {
2750
            if (enc) {
2751
                gcmRet = wc_AesGcmSetKey(enc->aes, keys->server_write_key,
2752
                                      specs->key_size);
2753
                if (gcmRet != 0) return gcmRet;
2754
                XMEMCPY(keys->aead_enc_imp_IV, keys->server_write_IV,
2755
                        AEAD_MAX_IMP_SZ);
2756
#if !defined(NO_PUBLIC_GCM_SET_IV) && \
2757
    ((!defined(HAVE_FIPS) && !defined(HAVE_SELFTEST)) || \
2758
    (defined(HAVE_FIPS_VERSION) && (HAVE_FIPS_VERSION >= 2)))
2759
                if (!tls13) {
2760
                    gcmRet = wc_AesGcmSetIV(enc->aes, AESGCM_NONCE_SZ,
2761
                            keys->server_write_IV, AESGCM_IMP_IV_SZ, rng);
2762
                    if (gcmRet != 0) return gcmRet;
2763
                }
2764
#endif
2765
            }
2766
            if (dec) {
2767
                gcmRet = wc_AesGcmSetKey(dec->aes, keys->client_write_key,
2768
                                      specs->key_size);
2769
                if (gcmRet != 0) return gcmRet;
2770
                XMEMCPY(keys->aead_dec_imp_IV, keys->client_write_IV,
2771
                        AEAD_MAX_IMP_SZ);
2772
            }
2773
        }
2774
        if (enc)
2775
            enc->setup = 1;
2776
        if (dec)
2777
            dec->setup = 1;
2778
    }
2779
#endif /* BUILD_AESGCM */
2780
2781
#ifdef HAVE_AESCCM
2782
    /* check that buffer sizes are sufficient (CCM is same size as GCM) */
2783
    #if (AEAD_MAX_IMP_SZ < 4) /* AESGCM_IMP_IV_SZ */
2784
        #error AEAD_MAX_IMP_SZ too small for AESCCM
2785
    #endif
2786
    #if (AEAD_MAX_EXP_SZ < 8) /* AESGCM_EXP_IV_SZ */
2787
        #error AEAD_MAX_EXP_SZ too small for AESCCM
2788
    #endif
2789
    #if (MAX_WRITE_IV_SZ < 4) /* AESGCM_IMP_IV_SZ */
2790
        #error MAX_WRITE_IV_SZ too small for AESCCM
2791
    #endif
2792
2793
    if (specs->bulk_cipher_algorithm == wolfssl_aes_ccm) {
2794
        int CcmRet;
2795
2796
        if (enc) {
2797
            if (enc->aes == NULL) {
2798
                enc->aes = (Aes*)XMALLOC(sizeof(Aes), heap, DYNAMIC_TYPE_CIPHER);
2799
                if (enc->aes == NULL)
2800
                    return MEMORY_E;
2801
            } else {
2802
                wc_AesFree(enc->aes);
2803
            }
2804
2805
            XMEMSET(enc->aes, 0, sizeof(Aes));
2806
        }
2807
        if (dec) {
2808
            if (dec->aes == NULL) {
2809
                dec->aes = (Aes*)XMALLOC(sizeof(Aes), heap, DYNAMIC_TYPE_CIPHER);
2810
                if (dec->aes == NULL)
2811
                    return MEMORY_E;
2812
            } else {
2813
                wc_AesFree(dec->aes);
2814
            }
2815
            XMEMSET(dec->aes, 0, sizeof(Aes));
2816
        }
2817
2818
        if (enc) {
2819
            if (wc_AesInit(enc->aes, heap, devId) != 0) {
2820
                WOLFSSL_MSG("AesInit failed in SetKeys");
2821
                return ASYNC_INIT_E;
2822
            }
2823
        }
2824
        if (dec) {
2825
            if (wc_AesInit(dec->aes, heap, devId) != 0) {
2826
                WOLFSSL_MSG("AesInit failed in SetKeys");
2827
                return ASYNC_INIT_E;
2828
            }
2829
        }
2830
2831
        if (side == WOLFSSL_CLIENT_END) {
2832
            if (enc) {
2833
                CcmRet = wc_AesCcmSetKey(enc->aes, keys->client_write_key,
2834
                                         specs->key_size);
2835
                if (CcmRet != 0) {
2836
                    return CcmRet;
2837
                }
2838
                XMEMCPY(keys->aead_enc_imp_IV, keys->client_write_IV,
2839
                        AEAD_MAX_IMP_SZ);
2840
#if !defined(NO_PUBLIC_CCM_SET_NONCE) && \
2841
    ((!defined(HAVE_FIPS) && !defined(HAVE_SELFTEST)) || \
2842
    (defined(HAVE_FIPS_VERSION) && (HAVE_FIPS_VERSION >= 2)))
2843
                if (!tls13) {
2844
                    CcmRet = wc_AesCcmSetNonce(enc->aes, keys->client_write_IV,
2845
                            AEAD_NONCE_SZ);
2846
                    if (CcmRet != 0) return CcmRet;
2847
                }
2848
#endif
2849
            }
2850
            if (dec) {
2851
                CcmRet = wc_AesCcmSetKey(dec->aes, keys->server_write_key,
2852
                                         specs->key_size);
2853
                if (CcmRet != 0) {
2854
                    return CcmRet;
2855
                }
2856
                XMEMCPY(keys->aead_dec_imp_IV, keys->server_write_IV,
2857
                        AEAD_MAX_IMP_SZ);
2858
            }
2859
        }
2860
        else {
2861
            if (enc) {
2862
                CcmRet = wc_AesCcmSetKey(enc->aes, keys->server_write_key,
2863
                                         specs->key_size);
2864
                if (CcmRet != 0) {
2865
                    return CcmRet;
2866
                }
2867
                XMEMCPY(keys->aead_enc_imp_IV, keys->server_write_IV,
2868
                        AEAD_MAX_IMP_SZ);
2869
#if !defined(NO_PUBLIC_CCM_SET_NONCE) && \
2870
    ((!defined(HAVE_FIPS) && !defined(HAVE_SELFTEST)) || \
2871
    (defined(HAVE_FIPS_VERSION) && (HAVE_FIPS_VERSION >= 2)))
2872
                if (!tls13) {
2873
                    CcmRet = wc_AesCcmSetNonce(enc->aes, keys->server_write_IV,
2874
                            AEAD_NONCE_SZ);
2875
                    if (CcmRet != 0) return CcmRet;
2876
                }
2877
#endif
2878
            }
2879
            if (dec) {
2880
                CcmRet = wc_AesCcmSetKey(dec->aes, keys->client_write_key,
2881
                                         specs->key_size);
2882
                if (CcmRet != 0) {
2883
                    return CcmRet;
2884
                }
2885
                XMEMCPY(keys->aead_dec_imp_IV, keys->client_write_IV,
2886
                        AEAD_MAX_IMP_SZ);
2887
            }
2888
        }
2889
        if (enc)
2890
            enc->setup = 1;
2891
        if (dec)
2892
            dec->setup = 1;
2893
    }
2894
#endif /* HAVE_AESCCM */
2895
2896
#ifdef HAVE_ARIA
2897
    /* check that buffer sizes are sufficient */
2898
    #if (MAX_WRITE_IV_SZ < 16) /* AES_IV_SIZE */
2899
        #error MAX_WRITE_IV_SZ too small for AES
2900
    #endif
2901
2902
    if (specs->bulk_cipher_algorithm == wolfssl_aria_gcm) {
2903
        int ret = 0;
2904
        MC_ALGID algo;
2905
2906
        switch(specs->key_size) {
2907
            case ARIA_128_KEY_SIZE:
2908
                algo = MC_ALGID_ARIA_128BITKEY;
2909
                break;
2910
            case ARIA_192_KEY_SIZE:
2911
                algo = MC_ALGID_ARIA_192BITKEY;
2912
                break;
2913
            case ARIA_256_KEY_SIZE:
2914
                algo = MC_ALGID_ARIA_256BITKEY;
2915
                break;
2916
            default:
2917
                return WOLFSSL_NOT_IMPLEMENTED; /* This should never happen */
2918
        }
2919
2920
        if (enc) {
2921
            if (enc->aria == NULL) {
2922
                enc->aria = (wc_Aria*)XMALLOC(sizeof(wc_Aria), heap, DYNAMIC_TYPE_CIPHER);
2923
                if (enc->aria == NULL)
2924
                    return MEMORY_E;
2925
            } else {
2926
                wc_AriaFreeCrypt(enc->aria);
2927
            }
2928
2929
            XMEMSET(enc->aria, 0, sizeof(wc_Aria));
2930
            if (wc_AriaInitCrypt(enc->aria, algo) != 0) {
2931
                WOLFSSL_MSG("AriaInit failed in SetKeys");
2932
                return ASYNC_INIT_E;
2933
            }
2934
        }
2935
        if (dec) {
2936
            if (dec->aria == NULL) {
2937
                dec->aria = (wc_Aria*)XMALLOC(sizeof(wc_Aria), heap, DYNAMIC_TYPE_CIPHER);
2938
                if (dec->aria == NULL)
2939
                    return MEMORY_E;
2940
            } else {
2941
                wc_AriaFreeCrypt(dec->aria);
2942
            }
2943
2944
            XMEMSET(dec->aria, 0, sizeof(wc_Aria));
2945
            if (wc_AriaInitCrypt(dec->aria, algo) != 0) {
2946
                WOLFSSL_MSG("AriaInit failed in SetKeys");
2947
                return ASYNC_INIT_E;
2948
            }
2949
        }
2950
2951
        if (side == WOLFSSL_CLIENT_END) {
2952
            if (enc) {
2953
                ret = wc_AriaSetKey(enc->aria, keys->client_write_key);
2954
                if (ret != 0) return ret;
2955
                XMEMCPY(keys->aead_enc_imp_IV, keys->client_write_IV,
2956
                        AEAD_MAX_IMP_SZ);
2957
                if (!tls13) {
2958
                    ret = wc_AriaGcmSetIV(enc->aria, AESGCM_NONCE_SZ,
2959
                            keys->client_write_IV, AESGCM_IMP_IV_SZ, rng);
2960
                    if (ret != 0) return ret;
2961
                }
2962
            }
2963
            if (dec) {
2964
                ret = wc_AriaSetKey(dec->aria, keys->server_write_key);
2965
                if (ret != 0) return ret;
2966
                XMEMCPY(keys->aead_dec_imp_IV, keys->server_write_IV,
2967
                        AEAD_MAX_IMP_SZ);
2968
            }
2969
        }
2970
        else {
2971
            if (enc) {
2972
                ret = wc_AriaSetKey(enc->aria, keys->server_write_key);
2973
                if (ret != 0) return ret;
2974
                XMEMCPY(keys->aead_enc_imp_IV, keys->server_write_IV,
2975
                        AEAD_MAX_IMP_SZ);
2976
                if (!tls13) {
2977
                    ret = wc_AriaGcmSetIV(enc->aria, AESGCM_NONCE_SZ,
2978
                            keys->server_write_IV, AESGCM_IMP_IV_SZ, rng);
2979
                    if (ret != 0) return ret;
2980
                }
2981
            }
2982
            if (dec) {
2983
                ret = wc_AriaSetKey(dec->aria, keys->client_write_key);
2984
                if (ret != 0) return ret;
2985
                XMEMCPY(keys->aead_dec_imp_IV, keys->client_write_IV,
2986
                        AEAD_MAX_IMP_SZ);
2987
            }
2988
        }
2989
        if (enc)
2990
            enc->setup = 1;
2991
        if (dec)
2992
            dec->setup = 1;
2993
    }
2994
#endif /* HAVE_ARIA */
2995
2996
#ifdef HAVE_CAMELLIA
2997
    /* check that buffer sizes are sufficient */
2998
    #if (MAX_WRITE_IV_SZ < 16) /* CAMELLIA_IV_SIZE */
2999
        #error MAX_WRITE_IV_SZ too small for CAMELLIA
3000
    #endif
3001
3002
    if (specs->bulk_cipher_algorithm == wolfssl_camellia) {
3003
        int camRet;
3004
3005
        if (enc && enc->cam == NULL)
3006
            enc->cam =
3007
                (wc_Camellia*)XMALLOC(sizeof(wc_Camellia), heap, DYNAMIC_TYPE_CIPHER);
3008
        if (enc && enc->cam == NULL)
3009
            return MEMORY_E;
3010
3011
        if (dec && dec->cam == NULL)
3012
            dec->cam =
3013
                (wc_Camellia*)XMALLOC(sizeof(wc_Camellia), heap, DYNAMIC_TYPE_CIPHER);
3014
        if (dec && dec->cam == NULL)
3015
            return MEMORY_E;
3016
3017
        if (side == WOLFSSL_CLIENT_END) {
3018
            if (enc) {
3019
                camRet = wc_CamelliaSetKey(enc->cam, keys->client_write_key,
3020
                                        specs->key_size, keys->client_write_IV);
3021
                if (camRet != 0) return camRet;
3022
            }
3023
            if (dec) {
3024
                camRet = wc_CamelliaSetKey(dec->cam, keys->server_write_key,
3025
                                        specs->key_size, keys->server_write_IV);
3026
                if (camRet != 0) return camRet;
3027
            }
3028
        }
3029
        else {
3030
            if (enc) {
3031
                camRet = wc_CamelliaSetKey(enc->cam, keys->server_write_key,
3032
                                        specs->key_size, keys->server_write_IV);
3033
                if (camRet != 0) return camRet;
3034
            }
3035
            if (dec) {
3036
                camRet = wc_CamelliaSetKey(dec->cam, keys->client_write_key,
3037
                                        specs->key_size, keys->client_write_IV);
3038
                if (camRet != 0) return camRet;
3039
            }
3040
        }
3041
        if (enc)
3042
            enc->setup = 1;
3043
        if (dec)
3044
            dec->setup = 1;
3045
    }
3046
#endif /* HAVE_CAMELLIA */
3047
3048
#ifdef WOLFSSL_SM4_CBC
3049
    /* check that buffer sizes are sufficient */
3050
    #if (MAX_WRITE_IV_SZ < 16) /* AES_IV_SIZE */
3051
        #error MAX_WRITE_IV_SZ too small for SM4_CBC
3052
    #endif
3053
3054
    if (specs->bulk_cipher_algorithm == wolfssl_sm4_cbc) {
3055
        int sm4Ret = 0;
3056
3057
        if (enc) {
3058
            if (enc->sm4 == NULL) {
3059
                enc->sm4 = (wc_Sm4*)XMALLOC(sizeof(wc_Sm4), heap,
3060
                    DYNAMIC_TYPE_CIPHER);
3061
                if (enc->sm4 == NULL)
3062
                    return MEMORY_E;
3063
            }
3064
            else {
3065
                wc_Sm4Free(enc->sm4);
3066
            }
3067
3068
            XMEMSET(enc->sm4, 0, sizeof(wc_Sm4));
3069
        }
3070
        if (dec) {
3071
            if (dec->sm4 == NULL) {
3072
                dec->sm4 = (wc_Sm4*)XMALLOC(sizeof(wc_Sm4), heap,
3073
                    DYNAMIC_TYPE_CIPHER);
3074
                if (dec->sm4 == NULL)
3075
                    return MEMORY_E;
3076
            }
3077
            else {
3078
                wc_Sm4Free(dec->sm4);
3079
            }
3080
3081
            XMEMSET(dec->sm4, 0, sizeof(wc_Sm4));
3082
        }
3083
        if (enc) {
3084
            if (wc_Sm4Init(enc->sm4, heap, devId) != 0) {
3085
                WOLFSSL_MSG("Sm4Init failed in SetKeys");
3086
                return ASYNC_INIT_E;
3087
            }
3088
        }
3089
        if (dec) {
3090
            if (wc_Sm4Init(dec->sm4, heap, devId) != 0) {
3091
                WOLFSSL_MSG("Sm4Init failed in SetKeys");
3092
                return ASYNC_INIT_E;
3093
            }
3094
        }
3095
3096
        if (side == WOLFSSL_CLIENT_END) {
3097
            if (enc) {
3098
                sm4Ret = wc_Sm4SetKey(enc->sm4, keys->client_write_key,
3099
                    specs->key_size);
3100
                if (sm4Ret != 0) return sm4Ret;
3101
                sm4Ret = wc_Sm4SetIV(enc->sm4, keys->client_write_IV);
3102
                if (sm4Ret != 0) return sm4Ret;
3103
            }
3104
            if (dec) {
3105
                sm4Ret = wc_Sm4SetKey(dec->sm4, keys->server_write_key,
3106
                    specs->key_size);
3107
                if (sm4Ret != 0) return sm4Ret;
3108
                sm4Ret = wc_Sm4SetIV(dec->sm4, keys->server_write_IV);
3109
                if (sm4Ret != 0) return sm4Ret;
3110
            }
3111
        }
3112
        else {
3113
            if (enc) {
3114
                sm4Ret = wc_Sm4SetKey(enc->sm4, keys->server_write_key,
3115
                    specs->key_size);
3116
                if (sm4Ret != 0) return sm4Ret;
3117
                sm4Ret = wc_Sm4SetIV(enc->sm4, keys->server_write_IV);
3118
                if (sm4Ret != 0) return sm4Ret;
3119
            }
3120
            if (dec) {
3121
                sm4Ret = wc_Sm4SetKey(dec->sm4, keys->client_write_key,
3122
                    specs->key_size);
3123
                if (sm4Ret != 0) return sm4Ret;
3124
                sm4Ret = wc_Sm4SetIV(dec->sm4, keys->client_write_IV);
3125
                if (sm4Ret != 0) return sm4Ret;
3126
            }
3127
        }
3128
        if (enc)
3129
            enc->setup = 1;
3130
        if (dec)
3131
            dec->setup = 1;
3132
    }
3133
#endif /* WOLFSSL_SM4_CBC */
3134
3135
#ifdef WOLFSSL_SM4_GCM
3136
    /* check that buffer sizes are sufficient */
3137
    #if (AEAD_MAX_IMP_SZ < 4) /* SM4-GCM_IMP_IV_SZ */
3138
        #error AEAD_MAX_IMP_SZ too small for SM4-GCM
3139
    #endif
3140
    #if (AEAD_MAX_EXP_SZ < 8) /* SM4-GCM_EXP_IV_SZ */
3141
        #error AEAD_MAX_EXP_SZ too small for SM4-GCM
3142
    #endif
3143
    #if (MAX_WRITE_IV_SZ < 4) /* SM4-GCM_IMP_IV_SZ */
3144
        #error MAX_WRITE_IV_SZ too small for SM4-GCM
3145
    #endif
3146
3147
    if (specs->bulk_cipher_algorithm == wolfssl_sm4_gcm) {
3148
        int gcmRet;
3149
3150
        if (enc) {
3151
            if (enc->sm4 == NULL) {
3152
                enc->sm4 = (wc_Sm4*)XMALLOC(sizeof(wc_Sm4), heap,
3153
                                            DYNAMIC_TYPE_CIPHER);
3154
                if (enc->sm4 == NULL)
3155
                    return MEMORY_E;
3156
            } else {
3157
                wc_Sm4Free(enc->sm4);
3158
            }
3159
3160
            XMEMSET(enc->sm4, 0, sizeof(wc_Sm4));
3161
        }
3162
        if (dec) {
3163
            if (dec->sm4 == NULL) {
3164
                dec->sm4 = (wc_Sm4*)XMALLOC(sizeof(wc_Sm4), heap,
3165
                                            DYNAMIC_TYPE_CIPHER);
3166
                if (dec->sm4 == NULL)
3167
                    return MEMORY_E;
3168
            } else {
3169
                wc_Sm4Free(dec->sm4);
3170
            }
3171
3172
            XMEMSET(dec->sm4, 0, sizeof(wc_Sm4));
3173
        }
3174
3175
        if (enc) {
3176
            if (wc_Sm4Init(enc->sm4, heap, devId) != 0) {
3177
                WOLFSSL_MSG("Sm4Init failed in SetKeys");
3178
                return ASYNC_INIT_E;
3179
            }
3180
        }
3181
        if (dec) {
3182
            if (wc_Sm4Init(dec->sm4, heap, devId) != 0) {
3183
                WOLFSSL_MSG("Sm4Init failed in SetKeys");
3184
                return ASYNC_INIT_E;
3185
            }
3186
        }
3187
3188
        if (side == WOLFSSL_CLIENT_END) {
3189
            if (enc) {
3190
                gcmRet = wc_Sm4GcmSetKey(enc->sm4, keys->client_write_key,
3191
                                      specs->key_size);
3192
                if (gcmRet != 0) return gcmRet;
3193
                XMEMCPY(keys->aead_enc_imp_IV, keys->client_write_IV,
3194
                        AEAD_MAX_IMP_SZ);
3195
            }
3196
            if (dec) {
3197
                gcmRet = wc_Sm4GcmSetKey(dec->sm4, keys->server_write_key,
3198
                                      specs->key_size);
3199
                if (gcmRet != 0) return gcmRet;
3200
                XMEMCPY(keys->aead_dec_imp_IV, keys->server_write_IV,
3201
                        AEAD_MAX_IMP_SZ);
3202
            }
3203
        }
3204
        else {
3205
            if (enc) {
3206
                gcmRet = wc_Sm4GcmSetKey(enc->sm4, keys->server_write_key,
3207
                                      specs->key_size);
3208
                if (gcmRet != 0) return gcmRet;
3209
                XMEMCPY(keys->aead_enc_imp_IV, keys->server_write_IV,
3210
                        AEAD_MAX_IMP_SZ);
3211
            }
3212
            if (dec) {
3213
                gcmRet = wc_Sm4GcmSetKey(dec->sm4, keys->client_write_key,
3214
                                      specs->key_size);
3215
                if (gcmRet != 0) return gcmRet;
3216
                XMEMCPY(keys->aead_dec_imp_IV, keys->client_write_IV,
3217
                        AEAD_MAX_IMP_SZ);
3218
            }
3219
        }
3220
        if (enc)
3221
            enc->setup = 1;
3222
        if (dec)
3223
            dec->setup = 1;
3224
    }
3225
#endif /* WOLFSSL_SM4_GCM */
3226
3227
#ifdef WOLFSSL_SM4_CCM
3228
    /* check that buffer sizes are sufficient (CCM is same size as GCM) */
3229
    #if (AEAD_MAX_IMP_SZ < 4) /* SM4-CCM_IMP_IV_SZ */
3230
        #error AEAD_MAX_IMP_SZ too small for SM4-CCM
3231
    #endif
3232
    #if (AEAD_MAX_EXP_SZ < 8) /* SM4-CCM_EXP_IV_SZ */
3233
        #error AEAD_MAX_EXP_SZ too small for SM4-CCM
3234
    #endif
3235
    #if (MAX_WRITE_IV_SZ < 4) /* SM4-CCM_IMP_IV_SZ */
3236
        #error MAX_WRITE_IV_SZ too small for SM4-CCM
3237
    #endif
3238
3239
    if (specs->bulk_cipher_algorithm == wolfssl_sm4_ccm) {
3240
        int CcmRet;
3241
3242
        if (enc) {
3243
            if (enc->sm4 == NULL) {
3244
                enc->sm4 = (wc_Sm4*)XMALLOC(sizeof(wc_Sm4), heap,
3245
                                            DYNAMIC_TYPE_CIPHER);
3246
                if (enc->sm4 == NULL)
3247
                    return MEMORY_E;
3248
            } else {
3249
                wc_Sm4Free(enc->sm4);
3250
            }
3251
3252
            XMEMSET(enc->sm4, 0, sizeof(wc_Sm4));
3253
        }
3254
        if (dec) {
3255
            if (dec->sm4 == NULL) {
3256
                dec->sm4 = (wc_Sm4*)XMALLOC(sizeof(wc_Sm4), heap,
3257
                                            DYNAMIC_TYPE_CIPHER);
3258
                if (dec->sm4 == NULL)
3259
                    return MEMORY_E;
3260
            } else {
3261
                wc_Sm4Free(dec->sm4);
3262
            }
3263
            XMEMSET(dec->sm4, 0, sizeof(wc_Sm4));
3264
        }
3265
3266
        if (enc) {
3267
            if (wc_Sm4Init(enc->sm4, heap, devId) != 0) {
3268
                WOLFSSL_MSG("Sm4Init failed in SetKeys");
3269
                return ASYNC_INIT_E;
3270
            }
3271
        }
3272
        if (dec) {
3273
            if (wc_Sm4Init(dec->sm4, heap, devId) != 0) {
3274
                WOLFSSL_MSG("Sm4Init failed in SetKeys");
3275
                return ASYNC_INIT_E;
3276
            }
3277
        }
3278
3279
        if (side == WOLFSSL_CLIENT_END) {
3280
            if (enc) {
3281
                CcmRet = wc_Sm4SetKey(enc->sm4, keys->client_write_key,
3282
                                      specs->key_size);
3283
                if (CcmRet != 0) {
3284
                    return CcmRet;
3285
                }
3286
                XMEMCPY(keys->aead_enc_imp_IV, keys->client_write_IV,
3287
                        AEAD_MAX_IMP_SZ);
3288
            }
3289
            if (dec) {
3290
                CcmRet = wc_Sm4SetKey(dec->sm4, keys->server_write_key,
3291
                                      specs->key_size);
3292
                if (CcmRet != 0) {
3293
                    return CcmRet;
3294
                }
3295
                XMEMCPY(keys->aead_dec_imp_IV, keys->server_write_IV,
3296
                        AEAD_MAX_IMP_SZ);
3297
            }
3298
        }
3299
        else {
3300
            if (enc) {
3301
                CcmRet = wc_Sm4SetKey(enc->sm4, keys->server_write_key,
3302
                                      specs->key_size);
3303
                if (CcmRet != 0) {
3304
                    return CcmRet;
3305
                }
3306
                XMEMCPY(keys->aead_enc_imp_IV, keys->server_write_IV,
3307
                        AEAD_MAX_IMP_SZ);
3308
            }
3309
            if (dec) {
3310
                CcmRet = wc_Sm4SetKey(dec->sm4, keys->client_write_key,
3311
                                      specs->key_size);
3312
                if (CcmRet != 0) {
3313
                    return CcmRet;
3314
                }
3315
                XMEMCPY(keys->aead_dec_imp_IV, keys->client_write_IV,
3316
                        AEAD_MAX_IMP_SZ);
3317
            }
3318
        }
3319
        if (enc)
3320
            enc->setup = 1;
3321
        if (dec)
3322
            dec->setup = 1;
3323
    }
3324
#endif /* WOLFSSL_SM4_CCM */
3325
3326
#ifdef HAVE_NULL_CIPHER
3327
    if (specs->bulk_cipher_algorithm == wolfssl_cipher_null) {
3328
    #ifdef WOLFSSL_TLS13
3329
        if (tls13) {
3330
            int hmacRet;
3331
            int hashType = WC_HASH_TYPE_NONE;
3332
3333
            switch (specs->mac_algorithm) {
3334
                case sha256_mac:
3335
                    hashType = WC_SHA256;
3336
                    break;
3337
                case sha384_mac:
3338
                    hashType = WC_SHA384;
3339
                    break;
3340
                default:
3341
                    break;
3342
            }
3343
3344
            if (enc && enc->hmac == NULL) {
3345
                enc->hmac = (Hmac*)XMALLOC(sizeof(Hmac), heap,
3346
                                                           DYNAMIC_TYPE_CIPHER);
3347
                if (enc->hmac == NULL)
3348
                    return MEMORY_E;
3349
3350
                if (wc_HmacInit(enc->hmac, heap, devId) != 0) {
3351
                    WOLFSSL_MSG("HmacInit failed in SetKeys");
3352
                    XFREE(enc->hmac, heap, DYNAMIC_TYPE_CIPHER);
3353
                    enc->hmac = NULL;
3354
                    return ASYNC_INIT_E;
3355
                }
3356
            }
3357
3358
            if (dec && dec->hmac == NULL) {
3359
                dec->hmac = (Hmac*)XMALLOC(sizeof(Hmac), heap,
3360
                                                           DYNAMIC_TYPE_CIPHER);
3361
                if (dec->hmac == NULL)
3362
                    return MEMORY_E;
3363
3364
                if (wc_HmacInit(dec->hmac, heap, devId) != 0) {
3365
                    WOLFSSL_MSG("HmacInit failed in SetKeys");
3366
                    XFREE(dec->hmac, heap, DYNAMIC_TYPE_CIPHER);
3367
                    dec->hmac = NULL;
3368
                    return ASYNC_INIT_E;
3369
                }
3370
            }
3371
3372
            if (side == WOLFSSL_CLIENT_END) {
3373
                if (enc) {
3374
                    XMEMCPY(keys->aead_enc_imp_IV, keys->client_write_IV,
3375
                            specs->iv_size);
3376
                    hmacRet = wc_HmacSetKey(enc->hmac, hashType,
3377
                                       keys->client_write_key, specs->key_size);
3378
                    if (hmacRet != 0) return hmacRet;
3379
                }
3380
                if (dec) {
3381
                    XMEMCPY(keys->aead_dec_imp_IV, keys->server_write_IV,
3382
                            specs->iv_size);
3383
                    hmacRet = wc_HmacSetKey(dec->hmac, hashType,
3384
                                       keys->server_write_key, specs->key_size);
3385
                    if (hmacRet != 0) return hmacRet;
3386
                }
3387
            }
3388
            else {
3389
                if (enc) {
3390
                    XMEMCPY(keys->aead_enc_imp_IV, keys->server_write_IV,
3391
                            specs->iv_size);
3392
                    hmacRet = wc_HmacSetKey(enc->hmac, hashType,
3393
                                       keys->server_write_key, specs->key_size);
3394
                    if (hmacRet != 0) return hmacRet;
3395
                }
3396
                if (dec) {
3397
                    XMEMCPY(keys->aead_dec_imp_IV, keys->client_write_IV,
3398
                            specs->iv_size);
3399
                    hmacRet = wc_HmacSetKey(dec->hmac, hashType,
3400
                                       keys->client_write_key, specs->key_size);
3401
                    if (hmacRet != 0) return hmacRet;
3402
                }
3403
            }
3404
        }
3405
    #endif
3406
        if (enc)
3407
            enc->setup = 1;
3408
        if (dec)
3409
            dec->setup = 1;
3410
    }
3411
#endif
3412
3413
    if (enc) {
3414
        keys->sequence_number_hi      = 0;
3415
        keys->sequence_number_lo      = 0;
3416
    }
3417
    if (dec) {
3418
        keys->peer_sequence_number_hi = 0;
3419
        keys->peer_sequence_number_lo = 0;
3420
    }
3421
    (void)side;
3422
    (void)heap;
3423
    (void)enc;
3424
    (void)dec;
3425
    (void)specs;
3426
    (void)devId;
3427
3428
    return 0;
3429
}
3430
3431
3432
#ifdef HAVE_ONE_TIME_AUTH
3433
/* set one time authentication keys */
3434
static int SetAuthKeys(OneTimeAuth* authentication, Keys* keys,
3435
                       CipherSpecs* specs, void* heap, int devId)
3436
164
{
3437
3438
164
#ifdef HAVE_POLY1305
3439
        /* set up memory space for poly1305 */
3440
164
        if (authentication && authentication->poly1305 == NULL)
3441
164
            authentication->poly1305 =
3442
164
                (Poly1305*)XMALLOC(sizeof(Poly1305), heap, DYNAMIC_TYPE_CIPHER);
3443
164
        if (authentication && authentication->poly1305 == NULL)
3444
1
            return MEMORY_E;
3445
    #ifdef WOLFSSL_CHECK_MEM_ZERO
3446
        wc_MemZero_Add("SSL auth keys poly1305", authentication->poly1305,
3447
            sizeof(Poly1305));
3448
    #endif
3449
163
        if (authentication)
3450
163
            authentication->setup = 1;
3451
163
#endif
3452
163
        (void)authentication;
3453
163
        (void)heap;
3454
163
        (void)keys;
3455
163
        (void)specs;
3456
163
        (void)devId;
3457
3458
163
        return 0;
3459
164
}
3460
#endif /* HAVE_ONE_TIME_AUTH */
3461
3462
#ifdef HAVE_SECURE_RENEGOTIATION
3463
/* function name is for cache_status++
3464
 * This function was added because of error incrementing enum type when
3465
 * compiling with a C++ compiler.
3466
 */
3467
static void CacheStatusPP(SecureRenegotiation* cache)
3468
{
3469
    switch (cache->cache_status) {
3470
        case SCR_CACHE_NULL:
3471
            cache->cache_status = SCR_CACHE_NEEDED;
3472
            break;
3473
3474
        case SCR_CACHE_NEEDED:
3475
            cache->cache_status = SCR_CACHE_COPY;
3476
            break;
3477
3478
        case SCR_CACHE_COPY:
3479
            cache->cache_status = SCR_CACHE_PARTIAL;
3480
            break;
3481
3482
        case SCR_CACHE_PARTIAL:
3483
            cache->cache_status = SCR_CACHE_COMPLETE;
3484
            break;
3485
3486
        case SCR_CACHE_COMPLETE:
3487
            WOLFSSL_MSG("SCR Cache state Complete");
3488
            break;
3489
3490
        default:
3491
            WOLFSSL_MSG("Unknown cache state!!");
3492
    }
3493
}
3494
#endif /* HAVE_SECURE_RENEGOTIATION */
3495
3496
3497
/* Set wc_encrypt/wc_decrypt or both sides of key setup
3498
 * note: use wc_encrypt to avoid shadowing global encrypt
3499
 * declared in unistd.h
3500
 */
3501
int SetKeysSide(WOLFSSL* ssl, enum encrypt_side side)
3502
{
3503
    int ret, copy = 0;
3504
    Ciphers* wc_encrypt = NULL;
3505
    Ciphers* wc_decrypt = NULL;
3506
    Keys*    keys    = &ssl->keys;
3507
3508
    (void)copy;
3509
3510
    /* Cipher activation invalidates the cached AEAD record overhead. Covers
3511
     * TLS 1.2 / TLS 1.3 handshake completion, secure renegotiation, early
3512
     * data flips, and DTLS 1.3 epoch transitions (Dtls13SetEpochKeys() calls
3513
     * SetKeysSide() at the bottom). */
3514
    ssl->recordSzOverhead = 0;
3515
3516
#ifdef HAVE_SECURE_RENEGOTIATION
3517
    if (ssl->secure_renegotiation &&
3518
            ssl->secure_renegotiation->cache_status != SCR_CACHE_NULL) {
3519
        keys = &ssl->secure_renegotiation->tmp_keys;
3520
#ifdef WOLFSSL_DTLS
3521
        /* For DTLS, copy is done in StoreKeys */
3522
        if (!ssl->options.dtls)
3523
#endif
3524
            copy = 1;
3525
    }
3526
#endif /* HAVE_SECURE_RENEGOTIATION */
3527
3528
    switch (side) {
3529
        case ENCRYPT_SIDE_ONLY:
3530
#ifdef WOLFSSL_DEBUG_TLS
3531
            WOLFSSL_MSG("Provisioning ENCRYPT key");
3532
            if (ssl->options.side == WOLFSSL_CLIENT_END) {
3533
                WOLFSSL_BUFFER(keys->client_write_key, ssl->specs.key_size);
3534
            }
3535
            else {
3536
                WOLFSSL_BUFFER(keys->server_write_key, ssl->specs.key_size);
3537
            }
3538
#endif
3539
            wc_encrypt = &ssl->encrypt;
3540
            break;
3541
3542
        case DECRYPT_SIDE_ONLY:
3543
#ifdef WOLFSSL_DEBUG_TLS
3544
            WOLFSSL_MSG("Provisioning DECRYPT key");
3545
            if (ssl->options.side == WOLFSSL_CLIENT_END) {
3546
                WOLFSSL_BUFFER(keys->server_write_key, ssl->specs.key_size);
3547
            }
3548
            else {
3549
                WOLFSSL_BUFFER(keys->client_write_key, ssl->specs.key_size);
3550
            }
3551
#endif
3552
            wc_decrypt = &ssl->decrypt;
3553
            break;
3554
3555
        case ENCRYPT_AND_DECRYPT_SIDE:
3556
#ifdef WOLFSSL_DEBUG_TLS
3557
            WOLFSSL_MSG("Provisioning ENCRYPT key");
3558
            if (ssl->options.side == WOLFSSL_CLIENT_END) {
3559
                WOLFSSL_BUFFER(keys->client_write_key, ssl->specs.key_size);
3560
            }
3561
            else {
3562
                WOLFSSL_BUFFER(keys->server_write_key, ssl->specs.key_size);
3563
            }
3564
            WOLFSSL_MSG("Provisioning DECRYPT key");
3565
            if (ssl->options.side == WOLFSSL_CLIENT_END) {
3566
                WOLFSSL_BUFFER(keys->server_write_key, ssl->specs.key_size);
3567
            }
3568
            else {
3569
                WOLFSSL_BUFFER(keys->client_write_key, ssl->specs.key_size);
3570
            }
3571
#endif
3572
            wc_encrypt = &ssl->encrypt;
3573
            wc_decrypt = &ssl->decrypt;
3574
            break;
3575
3576
        default:
3577
            return BAD_FUNC_ARG;
3578
    }
3579
3580
#ifdef HAVE_ONE_TIME_AUTH
3581
    if (!ssl->auth.setup && ssl->specs.bulk_cipher_algorithm == wolfssl_chacha){
3582
        ret = SetAuthKeys(&ssl->auth, keys, &ssl->specs, ssl->heap, ssl->devId);
3583
        if (ret != 0)
3584
           return ret;
3585
    }
3586
#endif
3587
3588
#if !defined(NO_CERTS) && defined(HAVE_PK_CALLBACKS)
3589
    ret = WC_NO_ERR_TRACE(PROTOCOLCB_UNAVAILABLE);
3590
    if (ssl->ctx->EncryptKeysCb) {
3591
        void* ctx = wolfSSL_GetEncryptKeysCtx(ssl);
3592
        #if defined(WOLFSSL_RENESAS_FSPSM_TLS)
3593
            FSPSM_ST* cbInfo = (FSPSM_ST*)ctx;
3594
            cbInfo->internal->side = side;
3595
        #elif defined(WOLFSSL_RENESAS_TSIP_TLS)
3596
            TsipUserCtx* cbInfo = (TsipUserCtx*)ctx;
3597
            cbInfo->internal->key_side = side;
3598
        #endif
3599
        ret = ssl->ctx->EncryptKeysCb(ssl, ctx);
3600
    }
3601
    if (!ssl->ctx->EncryptKeysCb ||
3602
        ret == WC_NO_ERR_TRACE(PROTOCOLCB_UNAVAILABLE))
3603
#endif
3604
    {
3605
        ret = SetKeys(wc_encrypt, wc_decrypt, keys, &ssl->specs, ssl->options.side,
3606
                      ssl->heap, ssl->devId, ssl->rng, ssl->options.tls1_3);
3607
    }
3608
3609
    /* Zero the TLS-layer staging key buffers once the CryptoCB callback
3610
     * has imported the key into a Secure Element.
3611
     *
3612
     * Convention: after a successful wc_AesSetKey / wc_AesGcmSetKey where
3613
     * the CryptoCB handled the key import, the callback leaves
3614
     * aes->devCtx != NULL and the software key schedule (aes->key,
3615
     * aes->devKey, aes->gcm.H / aes->gcm.M0) is NOT populated.  The TLS
3616
     * layer may therefore destroy its staging copy of the traffic key.
3617
     *
3618
     * Only the key buffers (client_write_key / server_write_key) are
3619
     * zeroed.  The static IVs (client_write_IV / server_write_IV) and
3620
     * the AEAD implicit-IV copies (aead_{enc,dec}_imp_IV) are NOT
3621
     * zeroed: BuildTls13Nonce() in tls13.c reads keys->aead_*_imp_IV on
3622
     * every AEAD record to construct the per-record nonce
3623
     * (nonce = static_iv XOR seq_num, RFC 8446 Section 5.3).  Zeroing
3624
     * them would break the record path or, if applied symmetrically on
3625
     * both peers, silently degenerate the nonce to the bare sequence
3626
     * number and break interop with any unpatched peer.  The static_iv
3627
     * is not a confidentiality-critical secret in the same sense as
3628
     * the traffic key; losing it does not compromise plaintext.
3629
     *
3630
     * Scope:
3631
     *   - TLS 1.3 only.  TLS 1.2 additionally reads
3632
     *     keys->{client,server}_write_key for rehandshake/secure
3633
     *     renegotiation flows.
3634
     *   - Non-DTLS.  Dtls13EpochCopyKeys (called from Dtls13NewEpoch)
3635
     *     references keys->*_write_key for epoch switching; DTLS 1.3
3636
     *     needs separate analysis.
3637
     *   - Non-QUIC.  QUIC traffic secrets live outside these buffers
3638
     *     but the interaction with stack-installed QUIC handlers has
3639
     *     not been audited; exclude until it is.
3640
     *
3641
     * When called with ENCRYPT_SIDE_ONLY or DECRYPT_SIDE_ONLY, only the
3642
     * buffer consumed by this call is zeroed; the complementary buffer
3643
     * is written in a later SetKeysSide() from its own DeriveTls13Keys()
3644
     * and StoreKeys() pair (StoreKeys gates on PROVISION_CLIENT /
3645
     * PROVISION_SERVER so only the provisioned side is written).
3646
     *
3647
     * Ordering: this block must run AFTER SetKeys() (so offload has
3648
     * happened) and BEFORE Dtls13SetRecordNumberKeys() /
3649
     * wolfSSL_quic_keys_active() below, in case a future refactor in
3650
     * either starts reading keys->*_write_key.  The DTLS and QUIC gates
3651
     * in this block mean neither currently executes on the same ssl,
3652
     * but keep the order explicit. */
3653
#if defined(WOLF_CRYPTO_CB) && defined(WOLF_CRYPTO_CB_AES_SETKEY)
3654
    if (ret == 0 && ssl->options.tls1_3 && !ssl->options.dtls
3655
            && !WOLFSSL_IS_QUIC(ssl)) {
3656
        int encOffloaded = (wc_encrypt != NULL && wc_encrypt->aes != NULL &&
3657
                            wc_encrypt->aes->devCtx != NULL);
3658
        int decOffloaded = (wc_decrypt != NULL && wc_decrypt->aes != NULL &&
3659
                            wc_decrypt->aes->devCtx != NULL);
3660
3661
        if (encOffloaded || decOffloaded) {
3662
            if (ssl->options.side == WOLFSSL_CLIENT_END) {
3663
                if (encOffloaded)
3664
                    ForceZero(keys->client_write_key, ssl->specs.key_size);
3665
                if (decOffloaded)
3666
                    ForceZero(keys->server_write_key, ssl->specs.key_size);
3667
            }
3668
            else {
3669
                if (encOffloaded)
3670
                    ForceZero(keys->server_write_key, ssl->specs.key_size);
3671
                if (decOffloaded)
3672
                    ForceZero(keys->client_write_key, ssl->specs.key_size);
3673
            }
3674
        }
3675
    }
3676
#endif /* WOLF_CRYPTO_CB && WOLF_CRYPTO_CB_AES_SETKEY */
3677
3678
#ifdef WOLFSSL_DTLS13
3679
    if (ret == 0 && ssl->options.dtls && IsAtLeastTLSv1_3(ssl->version))
3680
        ret = Dtls13SetRecordNumberKeys(ssl, side);
3681
#endif /* WOLFSSL_DTLS13 */
3682
#ifdef WOLFSSL_QUIC
3683
    if (ret == 0 && WOLFSSL_IS_QUIC(ssl)) {
3684
        ret = wolfSSL_quic_keys_active(ssl, side);
3685
    }
3686
#endif /* WOLFSSL_QUIC */
3687
3688
#ifdef HAVE_SECURE_RENEGOTIATION
3689
#ifdef WOLFSSL_DTLS
3690
    if (ret == 0 && ssl->options.dtls && !ssl->options.tls1_3) {
3691
        if (wc_encrypt)
3692
            wc_encrypt->src = keys == &ssl->keys ? KEYS : SCR;
3693
        if (wc_decrypt)
3694
            wc_decrypt->src = keys == &ssl->keys ? KEYS : SCR;
3695
    }
3696
#endif
3697
3698
    if (copy) {
3699
        int clientCopy = 0;
3700
3701
        /* Sanity check that keys == ssl->secure_renegotiation->tmp_keys.
3702
         * Otherwise the memcpy calls would copy overlapping memory
3703
         * and cause UB. Fail early. */
3704
        if (keys == &ssl->keys)
3705
            return BAD_FUNC_ARG;
3706
3707
        if (ssl->options.side == WOLFSSL_CLIENT_END && wc_encrypt)
3708
            clientCopy = 1;
3709
        else if (ssl->options.side == WOLFSSL_SERVER_END && wc_decrypt)
3710
            clientCopy = 1;
3711
3712
        if (clientCopy) {
3713
    #ifndef WOLFSSL_AEAD_ONLY
3714
            XMEMCPY(ssl->keys.client_write_MAC_secret,
3715
                    keys->client_write_MAC_secret, WC_MAX_DIGEST_SIZE);
3716
    #endif
3717
            XMEMCPY(ssl->keys.client_write_key,
3718
                    keys->client_write_key, AES_256_KEY_SIZE);
3719
            XMEMCPY(ssl->keys.client_write_IV,
3720
                    keys->client_write_IV, MAX_WRITE_IV_SZ);
3721
        } else {
3722
    #ifndef WOLFSSL_AEAD_ONLY
3723
            XMEMCPY(ssl->keys.server_write_MAC_secret,
3724
                    keys->server_write_MAC_secret, WC_MAX_DIGEST_SIZE);
3725
    #endif
3726
            XMEMCPY(ssl->keys.server_write_key,
3727
                    keys->server_write_key, AES_256_KEY_SIZE);
3728
            XMEMCPY(ssl->keys.server_write_IV,
3729
                    keys->server_write_IV, MAX_WRITE_IV_SZ);
3730
        }
3731
        if (wc_encrypt) {
3732
            ssl->keys.sequence_number_hi = keys->sequence_number_hi;
3733
            ssl->keys.sequence_number_lo = keys->sequence_number_lo;
3734
            #ifdef HAVE_AEAD
3735
                if (ssl->specs.cipher_type == aead) {
3736
                    /* Initialize the AES-GCM/CCM explicit IV to a zero. */
3737
                    XMEMCPY(ssl->keys.aead_exp_IV, keys->aead_exp_IV,
3738
                            AEAD_MAX_EXP_SZ);
3739
3740
                    /* Initialize encrypt implicit IV by encrypt side */
3741
                    if (ssl->options.side == WOLFSSL_CLIENT_END) {
3742
                        XMEMCPY(ssl->keys.aead_enc_imp_IV,
3743
                                keys->client_write_IV, AEAD_MAX_IMP_SZ);
3744
                    } else {
3745
                        XMEMCPY(ssl->keys.aead_enc_imp_IV,
3746
                                keys->server_write_IV, AEAD_MAX_IMP_SZ);
3747
                    }
3748
                }
3749
            #endif
3750
        }
3751
        if (wc_decrypt) {
3752
            ssl->keys.peer_sequence_number_hi = keys->peer_sequence_number_hi;
3753
            ssl->keys.peer_sequence_number_lo = keys->peer_sequence_number_lo;
3754
            #ifdef HAVE_AEAD
3755
                if (ssl->specs.cipher_type == aead) {
3756
                    /* Initialize decrypt implicit IV by decrypt side */
3757
                    if (ssl->options.side == WOLFSSL_SERVER_END) {
3758
                        XMEMCPY(ssl->keys.aead_dec_imp_IV,
3759
                                keys->client_write_IV, AEAD_MAX_IMP_SZ);
3760
                    } else {
3761
                        XMEMCPY(ssl->keys.aead_dec_imp_IV,
3762
                                keys->server_write_IV, AEAD_MAX_IMP_SZ);
3763
                    }
3764
                }
3765
            #endif
3766
        }
3767
        CacheStatusPP(ssl->secure_renegotiation);
3768
    }
3769
#endif /* HAVE_SECURE_RENEGOTIATION */
3770
3771
    return ret;
3772
}
3773
3774
3775
/* TLS can call too */
3776
int StoreKeys(WOLFSSL* ssl, const byte* keyData, int side)
3777
0
{
3778
0
    size_t sz;
3779
0
    int i = 0;
3780
0
    Keys* keys = &ssl->keys;
3781
#ifdef WOLFSSL_DTLS
3782
    /* In case of DTLS, ssl->keys is updated here */
3783
    int scr_copy = 0;
3784
#endif
3785
3786
#ifdef HAVE_SECURE_RENEGOTIATION
3787
    if (ssl->secure_renegotiation &&
3788
            ssl->secure_renegotiation->cache_status == SCR_CACHE_NEEDED) {
3789
        keys = &ssl->secure_renegotiation->tmp_keys;
3790
#ifdef WOLFSSL_DTLS
3791
        if (ssl->options.dtls) {
3792
            /* epoch is incremented after StoreKeys is called */
3793
            ssl->secure_renegotiation->tmp_keys.dtls_epoch = ssl->keys.dtls_epoch + 1;
3794
            /* we only need to copy keys on second and future renegotiations */
3795
            if (ssl->keys.dtls_epoch > 1)
3796
                scr_copy = 1;
3797
            ssl->encrypt.src = KEYS_NOT_SET;
3798
            ssl->decrypt.src = KEYS_NOT_SET;
3799
        }
3800
#endif
3801
        CacheStatusPP(ssl->secure_renegotiation);
3802
    }
3803
#endif /* HAVE_SECURE_RENEGOTIATION */
3804
3805
#ifdef WOLFSSL_MULTICAST
3806
    if (ssl->options.haveMcast) {
3807
        /* Use the same keys for encrypt and decrypt. */
3808
        if (ssl->specs.cipher_type != aead) {
3809
            sz = ssl->specs.hash_size;
3810
    #ifndef WOLFSSL_AEAD_ONLY
3811
3812
    #ifdef WOLFSSL_DTLS
3813
            if (scr_copy) {
3814
                XMEMCPY(ssl->keys.client_write_MAC_secret,
3815
                        keys->client_write_MAC_secret, sz);
3816
                XMEMCPY(ssl->keys.server_write_MAC_secret,
3817
                        keys->server_write_MAC_secret, sz);
3818
            }
3819
    #endif
3820
            XMEMCPY(keys->client_write_MAC_secret,&keyData[i], sz);
3821
            XMEMCPY(keys->server_write_MAC_secret,&keyData[i], sz);
3822
    #endif
3823
            i += (int)sz;
3824
        }
3825
        sz = ssl->specs.key_size;
3826
    #ifdef WOLFSSL_DTLS
3827
        if (scr_copy) {
3828
            XMEMCPY(ssl->keys.client_write_key,
3829
                    keys->client_write_key, sz);
3830
            XMEMCPY(ssl->keys.server_write_key,
3831
                    keys->server_write_key, sz);
3832
        }
3833
    #endif
3834
        XMEMCPY(keys->client_write_key, &keyData[i], sz);
3835
        XMEMCPY(keys->server_write_key, &keyData[i], sz);
3836
        i += (int)sz;
3837
3838
        sz = ssl->specs.iv_size;
3839
    #ifdef WOLFSSL_DTLS
3840
        if (scr_copy) {
3841
            XMEMCPY(ssl->keys.client_write_IV,
3842
                    keys->client_write_IV, sz);
3843
            XMEMCPY(ssl->keys.server_write_IV,
3844
                    keys->server_write_IV, sz);
3845
        }
3846
    #endif
3847
        XMEMCPY(keys->client_write_IV, &keyData[i], sz);
3848
        XMEMCPY(keys->server_write_IV, &keyData[i], sz);
3849
3850
#ifdef HAVE_AEAD
3851
        if (ssl->specs.cipher_type == aead) {
3852
            /* Initialize the AES-GCM/CCM explicit IV to a zero. */
3853
        #ifdef WOLFSSL_DTLS
3854
            if (scr_copy) {
3855
                XMEMCPY(ssl->keys.aead_exp_IV,
3856
                        keys->aead_exp_IV, AEAD_MAX_EXP_SZ);
3857
            }
3858
        #endif
3859
            XMEMSET(keys->aead_exp_IV, 0, AEAD_MAX_EXP_SZ);
3860
        }
3861
#endif /* HAVE_AEAD */
3862
3863
        return 0;
3864
    }
3865
#endif /* WOLFSSL_MULTICAST */
3866
3867
0
    if (ssl->specs.cipher_type != aead) {
3868
0
        sz = ssl->specs.hash_size;
3869
0
        if (side & PROVISION_CLIENT) {
3870
0
    #ifndef WOLFSSL_AEAD_ONLY
3871
        #ifdef WOLFSSL_DTLS
3872
            if (scr_copy)
3873
                XMEMCPY(ssl->keys.client_write_MAC_secret,
3874
                        keys->client_write_MAC_secret, sz);
3875
        #endif
3876
0
            XMEMCPY(keys->client_write_MAC_secret,&keyData[i], sz);
3877
0
    #endif
3878
0
            i += (int)sz;
3879
0
        }
3880
0
        if (side & PROVISION_SERVER) {
3881
0
    #ifndef WOLFSSL_AEAD_ONLY
3882
        #ifdef WOLFSSL_DTLS
3883
            if (scr_copy)
3884
                XMEMCPY(ssl->keys.server_write_MAC_secret,
3885
                        keys->server_write_MAC_secret, sz);
3886
        #endif
3887
0
            XMEMCPY(keys->server_write_MAC_secret,&keyData[i], sz);
3888
0
    #endif
3889
0
            i += (int)sz;
3890
0
        }
3891
0
    }
3892
0
    sz = ssl->specs.key_size;
3893
0
    if (side & PROVISION_CLIENT) {
3894
    #ifdef WOLFSSL_DTLS
3895
        if (scr_copy)
3896
            XMEMCPY(ssl->keys.client_write_key,
3897
                    keys->client_write_key, sz);
3898
    #endif
3899
0
        XMEMCPY(keys->client_write_key, &keyData[i], sz);
3900
0
        i += (int)sz;
3901
0
    }
3902
0
    if (side & PROVISION_SERVER) {
3903
    #ifdef WOLFSSL_DTLS
3904
        if (scr_copy)
3905
            XMEMCPY(ssl->keys.server_write_key,
3906
                    keys->server_write_key, sz);
3907
    #endif
3908
0
        XMEMCPY(keys->server_write_key, &keyData[i], sz);
3909
0
        i += (int)sz;
3910
0
    }
3911
3912
0
    sz = ssl->specs.iv_size;
3913
0
    if (side & PROVISION_CLIENT) {
3914
    #ifdef WOLFSSL_DTLS
3915
        if (scr_copy)
3916
            XMEMCPY(ssl->keys.client_write_IV,
3917
                    keys->client_write_IV, sz);
3918
    #endif
3919
0
        XMEMCPY(keys->client_write_IV, &keyData[i], sz);
3920
0
        i += (int)sz;
3921
0
    }
3922
0
    if (side & PROVISION_SERVER) {
3923
    #ifdef WOLFSSL_DTLS
3924
        if (scr_copy)
3925
            XMEMCPY(ssl->keys.server_write_IV,
3926
                    keys->server_write_IV, sz);
3927
    #endif
3928
0
        XMEMCPY(keys->server_write_IV, &keyData[i], sz);
3929
0
    }
3930
3931
0
#ifdef HAVE_AEAD
3932
0
    if (ssl->specs.cipher_type == aead) {
3933
        /* Initialize the AES-GCM/CCM explicit IV to a zero. */
3934
    #ifdef WOLFSSL_DTLS
3935
        if (scr_copy)
3936
            XMEMMOVE(ssl->keys.aead_exp_IV,
3937
                    keys->aead_exp_IV, AEAD_MAX_EXP_SZ);
3938
    #endif
3939
0
        XMEMSET(keys->aead_exp_IV, 0, AEAD_MAX_EXP_SZ);
3940
0
    }
3941
0
#endif
3942
3943
0
    return 0;
3944
0
}
3945
3946
#if !defined(NO_OLD_TLS) || defined(HAVE_EXTENDED_MASTER)
3947
static void CleanPreMaster(WOLFSSL* ssl)
3948
115
{
3949
115
    int sz = (int)(ssl->arrays->preMasterSz);
3950
3951
#ifdef WOLFSSL_CHECK_MEM_ZERO
3952
    wc_MemZero_Add("CleanPreMaster preMasterSecret",
3953
                   ssl->arrays->preMasterSecret, sz);
3954
#endif
3955
3956
115
    ForceZero(ssl->arrays->preMasterSecret, sz);
3957
3958
#ifdef WOLFSSL_CHECK_MEM_ZERO
3959
    wc_MemZero_Check(ssl->arrays->preMasterSecret, sz);
3960
#endif
3961
3962
115
    XFREE(ssl->arrays->preMasterSecret, ssl->heap, DYNAMIC_TYPE_SECRET);
3963
    ssl->arrays->preMasterSecret = NULL;
3964
115
    ssl->arrays->preMasterSz = 0;
3965
115
}
3966
#endif /* !NO_OLD_TLS || HAVE_EXTENDED_MASTER */
3967
3968
#ifndef NO_OLD_TLS
3969
int DeriveKeys(WOLFSSL* ssl)
3970
{
3971
    int    length = 2 * ssl->specs.hash_size +
3972
                    2 * ssl->specs.key_size  +
3973
                    2 * ssl->specs.iv_size;
3974
    int    rounds = (length + WC_MD5_DIGEST_SIZE - 1 ) / WC_MD5_DIGEST_SIZE;
3975
    int    ret = 0;
3976
3977
#ifdef WOLFSSL_SMALL_STACK
3978
    byte*  shaOutput;
3979
    byte*  md5Input;
3980
    byte*  shaInput;
3981
    byte*  keyData;
3982
    wc_Md5* md5;
3983
    wc_Sha* sha;
3984
#else
3985
    byte   shaOutput[WC_SHA_DIGEST_SIZE];
3986
    byte   md5Input[SECRET_LEN + WC_SHA_DIGEST_SIZE];
3987
    byte   shaInput[KEY_PREFIX + SECRET_LEN + 2 * RAN_LEN];
3988
    byte   keyData[KEY_PREFIX * WC_MD5_DIGEST_SIZE];
3989
    wc_Md5 md5[1];
3990
    wc_Sha sha[1];
3991
#endif
3992
3993
#ifdef WOLFSSL_SMALL_STACK
3994
    shaOutput = (byte*)XMALLOC(WC_SHA_DIGEST_SIZE,
3995
                                            NULL, DYNAMIC_TYPE_TMP_BUFFER);
3996
    md5Input  = (byte*)XMALLOC(SECRET_LEN + WC_SHA_DIGEST_SIZE,
3997
                                            NULL, DYNAMIC_TYPE_TMP_BUFFER);
3998
    shaInput  = (byte*)XMALLOC(KEY_PREFIX + SECRET_LEN + 2 * RAN_LEN,
3999
                                            NULL, DYNAMIC_TYPE_TMP_BUFFER);
4000
    keyData   = (byte*)XMALLOC(KEY_PREFIX * WC_MD5_DIGEST_SIZE,
4001
                                            NULL, DYNAMIC_TYPE_TMP_BUFFER);
4002
    md5       =  (wc_Md5*)XMALLOC(sizeof(wc_Md5), NULL, DYNAMIC_TYPE_TMP_BUFFER);
4003
    sha       =  (wc_Sha*)XMALLOC(sizeof(wc_Sha), NULL, DYNAMIC_TYPE_TMP_BUFFER);
4004
4005
    if (shaOutput == NULL || md5Input == NULL || shaInput == NULL ||
4006
        keyData   == NULL || md5      == NULL || sha      == NULL) {
4007
        XFREE(shaOutput, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4008
        XFREE(md5Input, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4009
        XFREE(shaInput, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4010
        XFREE(keyData, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4011
        XFREE(md5, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4012
        XFREE(sha, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4013
4014
        return MEMORY_E;
4015
    }
4016
#endif
4017
4018
    XMEMSET(shaOutput, 0, WC_SHA_DIGEST_SIZE);
4019
    ret = wc_InitMd5(md5);
4020
    if (ret == 0) {
4021
        ret = wc_InitSha(sha);
4022
    }
4023
    if (ret == 0) {
4024
        int i;
4025
4026
        XMEMCPY(md5Input, ssl->arrays->masterSecret, SECRET_LEN);
4027
4028
        for (i = 0; i < rounds; ++i) {
4029
            int j   = i + 1;
4030
            int idx = j;
4031
4032
            if (!SetPrefix(shaInput, i)) {
4033
                ret = PREFIX_ERROR;
4034
                break;
4035
            }
4036
4037
            XMEMCPY(shaInput + idx, ssl->arrays->masterSecret, SECRET_LEN);
4038
            idx += SECRET_LEN;
4039
            XMEMCPY(shaInput + idx, ssl->arrays->serverRandom, RAN_LEN);
4040
            idx += RAN_LEN;
4041
            XMEMCPY(shaInput + idx, ssl->arrays->clientRandom, RAN_LEN);
4042
            if (ret == 0) {
4043
                ret = wc_ShaUpdate(sha, shaInput,
4044
                    (KEY_PREFIX + SECRET_LEN + 2 * RAN_LEN) - KEY_PREFIX +
4045
                        (word32)(j));
4046
            }
4047
            if (ret == 0) {
4048
                ret = wc_ShaFinal(sha, shaOutput);
4049
            }
4050
4051
            XMEMCPY(md5Input + SECRET_LEN, shaOutput, WC_SHA_DIGEST_SIZE);
4052
            if (ret == 0) {
4053
                ret = wc_Md5Update(md5, md5Input, SECRET_LEN + WC_SHA_DIGEST_SIZE);
4054
            }
4055
            if (ret == 0) {
4056
                ret = wc_Md5Final(md5, keyData + i * WC_MD5_DIGEST_SIZE);
4057
            }
4058
        }
4059
4060
        if (ret == 0)
4061
            ret = StoreKeys(ssl, keyData, PROVISION_CLIENT_SERVER);
4062
    }
4063
4064
#ifdef WOLFSSL_CHECK_MEM_ZERO
4065
    wc_MemZero_Add("DeriveKeys shaOutput", shaOutput, WC_SHA_DIGEST_SIZE);
4066
    wc_MemZero_Add("DeriveKeys md5Input", md5Input,
4067
                   SECRET_LEN + WC_SHA_DIGEST_SIZE);
4068
    wc_MemZero_Add("DeriveKeys shaInput", shaInput,
4069
                   KEY_PREFIX + SECRET_LEN + 2 * RAN_LEN);
4070
    wc_MemZero_Add("DeriveKeys keyData", keyData,
4071
                   KEY_PREFIX * WC_MD5_DIGEST_SIZE);
4072
#endif
4073
    ForceZero(shaOutput, WC_SHA_DIGEST_SIZE);
4074
    ForceZero(md5Input, SECRET_LEN + WC_SHA_DIGEST_SIZE);
4075
    ForceZero(shaInput, KEY_PREFIX + SECRET_LEN + 2 * RAN_LEN);
4076
    ForceZero(keyData, KEY_PREFIX * WC_MD5_DIGEST_SIZE);
4077
#ifdef WOLFSSL_CHECK_MEM_ZERO
4078
    wc_MemZero_Check(shaOutput, WC_SHA_DIGEST_SIZE);
4079
    wc_MemZero_Check(md5Input, SECRET_LEN + WC_SHA_DIGEST_SIZE);
4080
    wc_MemZero_Check(shaInput, KEY_PREFIX + SECRET_LEN + 2 * RAN_LEN);
4081
    wc_MemZero_Check(keyData, KEY_PREFIX * WC_MD5_DIGEST_SIZE);
4082
#endif
4083
4084
    WC_FREE_VAR_EX(shaOutput, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4085
    WC_FREE_VAR_EX(md5Input, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4086
    WC_FREE_VAR_EX(shaInput, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4087
    WC_FREE_VAR_EX(keyData, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4088
    WC_FREE_VAR_EX(md5, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4089
    WC_FREE_VAR_EX(sha, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4090
4091
    return ret;
4092
}
4093
4094
4095
/* Create and store the master secret see page 32, 6.1 */
4096
static int MakeSslMasterSecret(WOLFSSL* ssl)
4097
{
4098
    int    i, ret;
4099
    word32 idx;
4100
    word32 pmsSz = ssl->arrays->preMasterSz;
4101
4102
#ifdef WOLFSSL_SMALL_STACK
4103
    byte*  shaOutput;
4104
    byte*  md5Input;
4105
    byte*  shaInput;
4106
    wc_Md5* md5;
4107
    wc_Sha* sha;
4108
#else
4109
    byte   shaOutput[WC_SHA_DIGEST_SIZE];
4110
    byte   md5Input[ENCRYPT_LEN + WC_SHA_DIGEST_SIZE];
4111
    byte   shaInput[PREFIX + ENCRYPT_LEN + 2 * RAN_LEN];
4112
    wc_Md5 md5[1];
4113
    wc_Sha sha[1];
4114
#endif
4115
4116
    if (ssl->arrays->preMasterSecret == NULL) {
4117
        return BAD_FUNC_ARG;
4118
    }
4119
4120
#ifdef SHOW_SECRETS
4121
    {
4122
        word32 j;
4123
        printf("pre master secret: ");
4124
        for (j = 0; j < pmsSz; j++)
4125
            printf("%02x", ssl->arrays->preMasterSecret[j]);
4126
        printf("\n");
4127
    }
4128
#endif
4129
4130
#ifdef WOLFSSL_SMALL_STACK
4131
    shaOutput = (byte*)XMALLOC(WC_SHA_DIGEST_SIZE,
4132
                                            NULL, DYNAMIC_TYPE_TMP_BUFFER);
4133
    md5Input  = (byte*)XMALLOC(ENCRYPT_LEN + WC_SHA_DIGEST_SIZE,
4134
                                            NULL, DYNAMIC_TYPE_TMP_BUFFER);
4135
    shaInput  = (byte*)XMALLOC(PREFIX + ENCRYPT_LEN + 2 * RAN_LEN,
4136
                                            NULL, DYNAMIC_TYPE_TMP_BUFFER);
4137
    md5       =  (wc_Md5*)XMALLOC(sizeof(wc_Md5), NULL, DYNAMIC_TYPE_TMP_BUFFER);
4138
    sha       =  (wc_Sha*)XMALLOC(sizeof(wc_Sha), NULL, DYNAMIC_TYPE_TMP_BUFFER);
4139
4140
    if (shaOutput == NULL || md5Input == NULL || shaInput == NULL ||
4141
                             md5      == NULL || sha      == NULL) {
4142
        XFREE(shaOutput, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4143
        XFREE(md5Input, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4144
        XFREE(shaInput, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4145
        XFREE(md5, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4146
        XFREE(sha, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4147
4148
        return MEMORY_E;
4149
    }
4150
#endif
4151
#ifdef WOLFSSL_CHECK_MEM_ZERO
4152
    wc_MemZero_Add("MakeSslMasterSecret md5Input", md5Input,
4153
                   ENCRYPT_LEN + WC_SHA_DIGEST_SIZE);
4154
    wc_MemZero_Add("MakeSslMasterSecret shaInput", shaInput,
4155
                   PREFIX + ENCRYPT_LEN + 2 * RAN_LEN);
4156
    wc_MemZero_Add("MakeSslMasterSecret shaOutput", shaOutput,
4157
                   WC_SHA_DIGEST_SIZE);
4158
#endif
4159
4160
    XMEMSET(shaOutput, 0, WC_SHA_DIGEST_SIZE);
4161
4162
    ret = wc_InitMd5(md5);
4163
    if (ret == 0) {
4164
        ret = wc_InitSha(sha);
4165
    }
4166
    if (ret == 0) {
4167
        XMEMCPY(md5Input, ssl->arrays->preMasterSecret, pmsSz);
4168
4169
        for (i = 0; i < MASTER_ROUNDS; ++i) {
4170
            byte prefix[KEY_PREFIX];      /* only need PREFIX bytes but static */
4171
            if (!SetPrefix(prefix, i)) {  /* analysis thinks will overrun      */
4172
                ret = PREFIX_ERROR;
4173
                break;
4174
            }
4175
4176
            idx = 0;
4177
            XMEMCPY(shaInput, prefix, (size_t)(i + 1));
4178
            idx += (word32)(i + 1);
4179
4180
            XMEMCPY(shaInput + idx, ssl->arrays->preMasterSecret, pmsSz);
4181
            idx += pmsSz;
4182
            XMEMCPY(shaInput + idx, ssl->arrays->clientRandom, RAN_LEN);
4183
            idx += RAN_LEN;
4184
            XMEMCPY(shaInput + idx, ssl->arrays->serverRandom, RAN_LEN);
4185
            idx += RAN_LEN;
4186
            if (ret == 0) {
4187
                ret = wc_ShaUpdate(sha, shaInput, idx);
4188
            }
4189
            if (ret == 0) {
4190
                ret = wc_ShaFinal(sha, shaOutput);
4191
            }
4192
            idx = pmsSz;  /* preSz */
4193
            XMEMCPY(md5Input + idx, shaOutput, WC_SHA_DIGEST_SIZE);
4194
            idx += WC_SHA_DIGEST_SIZE;
4195
            if (ret == 0) {
4196
                ret = wc_Md5Update(md5, md5Input, idx);
4197
            }
4198
            if (ret == 0) {
4199
                ret = wc_Md5Final(md5,
4200
                            &ssl->arrays->masterSecret[i * WC_MD5_DIGEST_SIZE]);
4201
            }
4202
        }
4203
4204
#ifdef SHOW_SECRETS
4205
        {
4206
            word32 j;
4207
            printf("master secret: ");
4208
            for (j = 0; j < SECRET_LEN; j++)
4209
                printf("%02x", ssl->arrays->masterSecret[j]);
4210
            printf("\n");
4211
        }
4212
#endif
4213
4214
        if (ret == 0)
4215
            ret = DeriveKeys(ssl);
4216
    }
4217
4218
    ForceZero(md5Input, ENCRYPT_LEN + WC_SHA_DIGEST_SIZE);
4219
    ForceZero(shaInput, PREFIX + ENCRYPT_LEN + 2 * RAN_LEN);
4220
    ForceZero(shaOutput, WC_SHA_DIGEST_SIZE);
4221
#ifdef WOLFSSL_CHECK_MEM_ZERO
4222
    wc_MemZero_Check(md5Input, ENCRYPT_LEN + WC_SHA_DIGEST_SIZE);
4223
    wc_MemZero_Check(shaInput, PREFIX + ENCRYPT_LEN + 2 * RAN_LEN);
4224
    wc_MemZero_Check(shaOutput, WC_SHA_DIGEST_SIZE);
4225
#endif
4226
4227
    WC_FREE_VAR_EX(shaOutput, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4228
    WC_FREE_VAR_EX(md5Input, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4229
    WC_FREE_VAR_EX(shaInput, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4230
    WC_FREE_VAR_EX(md5, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4231
    WC_FREE_VAR_EX(sha, NULL, DYNAMIC_TYPE_TMP_BUFFER);
4232
4233
    CleanPreMaster(ssl);
4234
4235
    return ret;
4236
}
4237
#endif
4238
4239
4240
/* Master wrapper, doesn't use SSL stack space in TLS mode */
4241
int MakeMasterSecret(WOLFSSL* ssl)
4242
{
4243
#ifdef HAVE_EXTENDED_MASTER
4244
    /* User requires EMS but it was not negotiated: abort rather than derive
4245
     * a standard master secret (RFC 7627). */
4246
    if (ssl->options.requireEMS && !ssl->options.haveEMS) {
4247
        WOLFSSL_MSG("EMS required but not negotiated with peer");
4248
        SendAlert(ssl, alert_fatal, handshake_failure);
4249
        WOLFSSL_ERROR_VERBOSE(EXT_MASTER_SECRET_NEEDED_E);
4250
        if (ssl->arrays->preMasterSecret != NULL)
4251
            CleanPreMaster(ssl);
4252
        return EXT_MASTER_SECRET_NEEDED_E;
4253
    }
4254
#endif
4255
    /* append secret to premaster : premaster | SerSi | CliSi */
4256
#ifndef NO_OLD_TLS
4257
    if (ssl->options.tls) return MakeTlsMasterSecret(ssl);
4258
    return MakeSslMasterSecret(ssl);
4259
#elif !defined(WOLFSSL_NO_TLS12) && !defined(NO_TLS)
4260
    return MakeTlsMasterSecret(ssl);
4261
#else
4262
    (void)ssl;
4263
    return 0;
4264
#endif
4265
}
4266
4267
#endif /* !WOLFCRYPT_ONLY && !NO_TLS */